
How to Audit Vendor Master Data
Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Check supplier creation, changes and maintenance: sponsored and validated vendors, maker-checker approval, independently verified bank changes, complete change logs, blocked dormant vendors and employee/vendor overlaps.
The vendor master file decides who can be paid and where payments go, which makes it a common route for payment diversion and fictitious suppliers. This checklist helps auditors test how vendors are created, changed and maintained.
Use it within a procurement or accounts payable audit, or after a suspicious bank-change request. Creation checks confirm vendor requests have a legitimate business sponsor, tax, registration and contact details are validated, duplicate-vendor checks happen before creation, maker-checker segregation exists, and high-risk vendors receive enhanced due diligence. Changes checks cover independent verification of bank-detail changes, authentication of change requests through a trusted channel, change logs that capture user, date, old value and new value, approval of sensitive changes before they take effect, and review of recent changes before large or unusual payments. Maintenance checks cover periodic blocking of dormant vendors, control of one-time vendors, analysis of employee and vendor address, bank or contact overlaps, restricted and reviewed vendor master access, and reporting of unusual change patterns.
Record each point as Done, Review or N/A with evidence, and use the risk prompts to find where one person can create, change and approve the same vendor. The completion page captures your conclusion.
© Salih Ahmed Islam

Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Document vendor due diligence before onboarding: registration and beneficial ownership, conflicts, sanctions and adverse information, PEP and high-risk countries, bank verification, payment terms and risk classification.
PDF • 6 Pages • Free

Match each risk to a practical data test, the fields it needs and whether it suits one-off audit work or continuous monitoring.
PDF • 6 Pages • Free

Verify invoice processing and payment controls — controlled receipt, PO/receipt matching, justified non-PO invoices, independently reviewed payment runs, and analytics for duplicates, threshold payments and recent bank changes.
PDF • 6 Pages • Free