
How to Audit Vendor Master Data
Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Document vendor due diligence before onboarding: registration and beneficial ownership, conflicts, sanctions and adverse information, PEP and high-risk countries, bank verification, payment terms and risk classification.
© Salih Ahmed Islam

Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Check supplier creation, changes and maintenance: sponsored and validated vendors, maker-checker approval, independently verified bank changes, complete change logs, blocked dormant vendors and employee/vendor overlaps.
PDF • 6 Pages • Free

Audit third-party arrangements: risk-based due diligence, contracts with data protection and audit rights, measurable and validated SLAs, applied penalties, continuity and exit plans, and dependency oversight.
PDF • 6 Pages • Free

Identify where opportunity, pressure and weak oversight create fraud exposure — mapping who can initiate, approve and conceal transactions, then testing the most plausible fraud scenarios.
PDF • 6 Pages • Free