Providence, RI · Independent public-finance research & analytics
Fraud Prevention & Detection · Practice guide

Vendor Master File Hygiene: The Quiet Fraud Control

Most disbursement fraud starts with a record, not a payment. The vendor master file is where the control is cheapest and least often applied.

A payment can only go where a payee record permits. That makes the vendor master file the narrowest point in the disbursement process and therefore the most efficient place to control it — and yet it is routinely treated as reference data rather than as a control point. In a typical mid-sized entity the file contains three to five times more records than the entity has active vendors, includes duplicates, retains records for entities that dissolved years earlier, and permits changes by anyone in accounts payable.

The four routine tests

Duplicate detection

Exact duplicates are trivial. The useful tests are fuzzy: names differing by punctuation, abbreviation or legal suffix; identical tax identification numbers under different names; identical bank account details under different vendors; and identical addresses. Each has a legitimate explanation available — a company operating under multiple trade names, a payment agent, a shared office suite — but each also warrants confirmation.

Employee–vendor overlap

Compare vendor addresses, bank details and telephone numbers against the HR master. Matches are frequently legitimate: reimbursements, board stipends, an employee's genuinely competitive small business disclosed under conflict-of-interest policy. Undisclosed matches are the finding. This test should run quarterly and should compare current and historical addresses on both sides.

Address validity

Post office boxes are not inherently suspicious, but a payee receiving substantial sums at a mail drop, at a residential address, or at an address matching another vendor is worth verifying. Commercial mail receiving agency addresses are identifiable and are a reasonable screening criterion.

Dormancy

Records with no activity for a defined period — twenty-four months is a common threshold — should be deactivated rather than deleted. Deactivation preserves history for audit while removing the record as a viable payment destination. Reactivation should require the same approval as a new vendor.

The change most worth making

Separate the ability to create or amend a vendor record from the ability to process a payment, and require documented verification for bank detail changes through a channel independent of the request. Business email compromise targeting bank detail changes remains one of the most productive attacks against public entities, and it defeats every downstream control because the payment itself is entirely regular.

Bank detail change procedure

Because this is where the money actually goes, the procedure deserves stating in full:

  1. Change requests are accepted only on a standard form, never by email instruction alone.
  2. Verification is by outbound call to a telephone number held in the vendor record before the change request — never to a number supplied in the request.
  3. The verifier is not the person who entered the change.
  4. A confirmation notice is sent to the vendor's previously held address and email.
  5. The first payment after a bank change is flagged for review.
  6. The change, the verification, and the identity of both staff members are logged.

Every element of this procedure exists because its absence has been exploited. The outbound-call requirement in particular is defeated whenever the callback number is taken from the request document.

Onboarding standards

New vendor records should require: a completed tax form, verification of legal entity status against the relevant secretary of state registry, confirmation of the remittance address, a conflict-of-interest declaration where the entity's policy requires one, and — for vendors above a threshold — verification against federal and state exclusion and debarment lists. Screening against exclusion lists is a compliance requirement in any programme funded by federal awards and is frequently performed at contract award but never repeated, despite the lists changing continuously.

Governance and reporting

A quarterly report to the finance director and internal audit: records added, records amended by field, records deactivated, exceptions raised by each of the four tests, and dispositions. The report takes an hour to produce once queries exist and provides a documented trail that the file is being managed rather than merely maintained.

Data quality as a by-product

Everything above is framed as fraud prevention, but the operational return arrives first: fewer duplicate payments, fewer returned ACH transactions, cleaner spend analysis by vendor, and materially less effort at year end reconciling payables. Entities that struggle to justify the work on control grounds can usually justify it on the strength of duplicate payment recovery alone.


This publication is general information and is not legal, accounting, audit or financial advice. See our Disclaimer. Found an error? Write to [email protected] — we correct in place and note what changed.

Talk to us about your oversight programme

Walk through the platform with your own chart of accounts, or start with the research library. Both routes are free to begin.