Back to Glossary

Entry · Business

Vendor Master Data Review

A vendor master data review checks whether supplier records used for orders and payments are accurate, current, authorised and free of unintended duplicates. It pays special attention to identities, payment details, tax data and inactive accounts.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A vendor master file is the reference list that procurement and finance use to identify suppliers, and errors can misroute payments or obscure duplicate invoices. A review tests records against reliable evidence and an approval trail.

Start by defining ownership, because procurement may validate commercial identity while finance controls payment fields, and a clear workflow prevents one person from both requesting and approving a sensitive change. Washington State Auditor guidance warns that vendor-master records can be exploited in payment fraud, and US GAO reports on payment-control weaknesses likewise show why authorisation and verification matter, though the exact control design depends on the organisation.

Review legal names, registration identifiers, addresses, contacts, payment terms, tax attributes and bank details as appropriate; different jurisdictions need different fields, and extra sensitive data should not be collected without purpose. Match the vendor to the correct legal entity and tax treatment, since a wrong currency or country can cause payment or reporting errors, and seek tax advice when the rules are material.

Duplicates are not always obvious, because abbreviations, transliteration, former names and branch addresses can mask one supplier, while similar names may belong to distinct entities. A fictional supplier changes its trading name but not its legal entity, and the team updates the display name without creating a second legal supplier by mistake; another fictional business notices a supplier invoicing through a different subsidiary and checks which entity is actually contracting and receiving payment.

A fictional analyst compares invoice numbers, legal IDs and bank details across suspected duplicate records and reconciles vendor statements with payment records, because duplicate master IDs can split history while merged records can conceal valid separate obligations, so investigate before altering live account links. Bank-detail changes deserve strong controls: verify using a known phone number or established secure channel, not the contact details supplied in the change request alone, and record who checked and approved it.

Review contact information separately from payment instructions, because a fraudulent request might change both at once to defeat callbacks, and a fictional AP clerk retrieves the contract's original contact rather than calling the number printed on a new invoice. Look for unusual changes shortly before a payment run, since new accounts, address changes and reopened inactive vendors may need extra review, and an anomaly is a reason to investigate, not proof of fraud, as when a fictional business pauses a suspicious bank change but pays an undisputed invoice to the previously verified account after review.

Check whether a vendor remains active, because old accounts can create confusion or become a route for unauthorised payments, and inactivation should preserve transaction history rather than delete evidence. Test access rights so that only authorised users can create, change and approve sensitive supplier fields, with logs showing who acted and when, since shared logins undermine accountability.

A periodic review can use risk tiers, with high-spend, high-risk or frequently changed vendors checked more often, as when a fictional AP function checks payment-field changes daily and lower-risk inactive records quarterly, because a fixed annual sweep alone may miss a dangerous change made yesterday. Document exceptions, since a supplier may need a temporary hold while its documents are verified and the process needs an owner and a way to avoid unjustified payment delays, and keep cleanups safe by maintaining the mapping and audit trail when duplicates are consolidated, never erasing invoices, credits or tax documents.

Measure unresolved duplicates, stale fields, unverified bank changes and aged exceptions, as when a fictional board sees ten records pending verification and asks when each will be resolved, and review the control process as well as the data, since a low duplicate count is not enough if approvals are weak. Train staff on impersonation and urgency cues, as when a fictional employee receiving a "pay today" request follows the standard verification steps despite the deadline, but do not rely on awareness alone, because technical restrictions, independent checks and reconciliation reinforce one another in what is ongoing control work, not a one-time deletion of duplicate names.

In practice

Real-world examples.

1

Example

AP verifies a new bank account independently.

2

Example

Procurement checks whether similar supplier names are the same legal entity.

3

Example

Finance inactivates an unused record while preserving history.

Formula

Calculation

Illustrative unverified-change rate = sensitive vendor changes lacking required independent verification / sensitive changes sampled x 100%. Worked example: a reviewer samples 50 sensitive vendor changes made during a quarter and finds that 4 lack the required independent verification. The unverified-change rate is 4 / 50 x 100% = 8%. The figure does not mean 4 frauds occurred; it identifies 4 records to check and a control gap to close.

Case study

Seen in the real world.

In this fictional case, Cedar Works sees two records for a familiar vendor and an emailed request for new bank details. Finance verifies the legal identities and calls the known contact from the existing contract. The team finds the two records refer to separate subsidiaries and rejects the unverified bank change. It documents both decisions and preserves payment history.

Watch out

Common mistakes.

  • Merging similar names without checking legal identity.
  • Accepting new bank details using only contact data from the request.
  • Deleting inactive records and losing the audit trail.

Questions

People also ask.

Is every similar name a duplicate?

No. Verify legal entity and transaction history.

How should bank changes be checked?

Independently through a previously trusted route and approval process.

Should old suppliers be deleted?

Usually preserve records and history; use controlled inactivation.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.