Better practices for supplier risk management.

A structured library of better practices across the supplier lifecycle — from verifying identity at onboarding through to ongoing monitoring and incident response.

Verify the Legal Entity

Confirm the supplier is a genuinely registered legal entity by checking it against an official company or business registry, not just the documents the supplier has provided. Registry data is authoritative and far harder for a fraudster to fabricate convincingly.

Match Information Across Sources

Cross-check the supplier's name, registration number, and address across the registry, invoices, and banking details. Inconsistencies between sources are one of the earliest and cheapest signals of a shell company or spoofed entity.

Confirm the Supplier's Operating Presence

Look for evidence that the business actually operates, such as a trading address, website, or historical filings. An entity that exists only on paper with no operating footprint warrants closer scrutiny before onboarding.

Identify Ownership and Control

Establish who ultimately owns and controls the supplier, including any parent companies or beneficial owners. This is essential for spotting related-party relationships and satisfying anti-money-laundering obligations.

Confirm Authority to Act

Verify that the individual submitting onboarding information or requesting changes is actually authorised to act on the supplier's behalf. A title and email domain alone are not sufficient evidence of authority.

Use a Standard Onboarding Process

Route every new supplier through the same structured process regardless of urgency or relationship. Ad hoc exceptions are where weak or fraudulent suppliers most often slip through.

Separate Request, Verification and Approval

Ensure the person requesting a new supplier is not the same person who verifies or approves it. This separation of duties closes the most common path for internally facilitated fraud.

Collect Information Through a Controlled Channel

Gather onboarding details through a dedicated portal or form rather than ad hoc email threads. A controlled channel creates a consistent, auditable record and reduces the risk of tampered submissions.

Define Mandatory Onboarding Requirements

Set a minimum baseline of information and documentation every supplier must provide before activation, scaled to risk where appropriate. Optional or inconsistent requirements create gaps that get exploited over time.

Prevent Payment Before Approval

Configure systems so a supplier cannot be paid until onboarding verification and approval are fully complete. This closes the window where a request made under time pressure bypasses proper checks.

Retain Approval Evidence

Keep a durable record of who approved each supplier, when, and on what evidence. This record is what makes the control demonstrable to auditors and defensible after the fact.

Establish a Supplier Risk Classification

Score suppliers on factors such as payment value, industry, and geography so due diligence effort matches actual exposure. Treating every supplier identically wastes effort on low-risk relationships while under-scrutinising high-risk ones.

Define Clear Risk Tiers

Translate the risk score into a small number of defined tiers, each with its own documentation and verification requirements. Clear tiers make due diligence decisions consistent and easy to audit.

Escalate When Concerns Arise

Give staff a clear path to escalate a supplier for enhanced review when something looks inconsistent, even if it doesn't breach a hard rule. The people closest to the data are often the first to notice something is off.

Document Risk Acceptance

When a supplier is onboarded despite an identified risk, record who accepted that risk and why. Undocumented risk acceptance is indistinguishable from a missed control during an audit or investigation.

Review Risk When Circumstances Change

Reassess a supplier's risk tier when its ownership, payment volume, or country of operation changes materially. A supplier's risk profile at onboarding is a starting point, not a permanent rating.

Collect Banking Information Securely

Capture bank account details through a controlled, authenticated channel rather than email or phone, where instructions can be spoofed or intercepted. The channel itself is often the weakest link in payment fraud.

Validate Available Banking Information

Check submitted account and routing details against authoritative banking data sources to confirm they are structurally valid and belong to the named entity where possible. Basic format checks alone catch typos, not fraud.

Independently Confirm Banking Changes

Verify any change to existing bank details through a channel independent of the one that raised the request, such as a callback to a previously known number. Never confirm a bank change using contact details supplied in the same message that requested it.

Strengthen Approval for Bank Changes

Require a higher level of sign-off for bank detail changes than for routine transactions, given how frequently this specific action is the vector for fraud. Treat every bank change request as suspicious until proven otherwise.

Apply Additional Controls to Significant Payments

Introduce extra verification steps, such as dual approval or a cooling-off period, for payments above a defined threshold. The cost of an extra check is small relative to the cost of a large fraudulent payment.

Notify Established Supplier Contacts

When a bank detail change is processed, notify the supplier through a previously established contact point, separate from whoever submitted the change. This gives a legitimate supplier a chance to flag a change they did not request.

Define Required Documents by Supplier Type

Set out which documents — registration certificates, tax forms, insurance, licences — are required for each category and risk tier of supplier. A generic checklist tends to under-collect for high-risk suppliers and over-collect for low-risk ones.

Check Information Consistency

Compare names, addresses, and registration numbers across all submitted documents and against registry data. Small inconsistencies are frequently the first indicator of a fabricated or altered document.

Review for Signs of Alteration

Look for irregular fonts, misaligned fields, inconsistent formatting, or metadata anomalies that suggest a document has been edited. Fraudulent documents are increasingly convincing at a glance but rarely hold up under structured review.

Verify Critical Documents Independently

For high-value or high-risk suppliers, confirm key documents directly with the issuing authority or registry rather than relying solely on the copy provided. Self-supplied documents alone cannot be fully trusted for material decisions.

Monitor Expiry Dates

Track expiry dates on insurance certificates, licences, and compliance documents, and prompt for renewal before they lapse. An expired document that goes unnoticed quietly turns a compliant supplier into a non-compliant one.

Retain the Original Evidence

Keep the original submitted documents, not just a summary of the review outcome, for as long as required by policy and regulation. Without the underlying evidence, a review decision can't be reconstructed or defended later.

Restrict System Access

Limit who can create, edit, or approve changes to supplier master data to a small, defined group of authorised users. Broad access to master data is one of the most common enablers of internal fraud.

Separate Supplier Maintenance from Payment Approval

Ensure the people who can edit supplier records are not the same people who approve payments to those suppliers. Combined access removes the natural check each function provides on the other.

Require Approval for Sensitive Changes

Route changes to sensitive fields, particularly banking details, through a mandatory second approver before they take effect. Sensitive fields deserve a higher bar than routine data updates.

Maintain a Complete Audit Trail

Log every change to supplier master data, including who made it, when, and what the previous value was. A complete trail turns "something changed" into "we know exactly what changed and by whom."

Detect Duplicate Suppliers

Regularly scan for suppliers with matching bank accounts, tax IDs, or near-identical names entered under different records. Duplicates are used both to disguise fraud and to accidentally create control gaps.

Review Unusual Changes

Flag master data changes that fall outside normal patterns, such as edits made outside business hours or by an unexpected user, for manual review. Unusual timing or actors are a low-cost, high-value detection signal.

Deactivate Unused Suppliers

Deactivate suppliers with no recent activity rather than leaving dormant records live in the system. Dormant active suppliers are an easy target for reactivation and misuse.

Match Invoices to Supporting Records

Match each invoice against its purchase order and goods or services receipt before payment. An invoice with no corresponding PO or receipt is one of the simplest and most effective fraud indicators to catch.

Detect Duplicate Invoices

Screen for invoices with the same number, amount, or line items submitted more than once, including near-duplicates with minor formatting differences. Duplicate payments are often innocent errors, but they are also a known fraud technique.

Review Unusual Payment Behaviour

Monitor for changes in a supplier's typical invoicing pattern, such as a sudden jump in amount, frequency, or a new payment destination. A deviation from established behaviour is worth a second look even without a specific red flag.

Separate Payment Responsibilities

Divide invoice entry, approval, and payment execution among different people so no single individual controls a payment end to end. This is one of the oldest and most effective controls against both error and fraud.

Strengthen First-Payment Controls

Apply extra scrutiny to the first payment made to any supplier, since this is when banking details are least established and most likely to be manipulated. Later payments can rely more on the trust built at this first checkpoint.

Control Urgent and Manual Payments

Require the same approval standard for urgent or manually processed payments as for routine ones, rather than allowing urgency to justify a shortcut. Fraudsters rely on urgency specifically to get controls waived.

Review Threshold Avoidance

Watch for invoices split into amounts just below an approval threshold, which can indicate deliberate structuring to avoid scrutiny. This pattern is easy to detect with basic analysis and rarely has an innocent explanation.

Require Conflict-of-Interest Declarations

Require employees involved in procurement or supplier management to formally declare any personal or financial interest in a supplier. A declared conflict can be managed; an undeclared one becomes a discovery during an investigation.

Refresh Declarations Regularly

Ask employees to reconfirm or update their conflict-of-interest declarations on a regular cycle, not just once at hiring. Circumstances and relationships change over the course of employment.

Compare Supplier and Employee Information

Periodically match supplier addresses, phone numbers, and bank details against employee records to surface undisclosed relationships. This is one of the most effective and underused detection techniques available.

Separate Procurement Responsibilities

Split supplier selection, contract negotiation, and ongoing management across different people or teams where practical. Concentrating all procurement decisions with one person increases both the risk and the potential scale of collusion.

Review Supplier Concentration

Monitor for an unusually high share of spend or approvals concentrated on one supplier, or approved disproportionately by one individual. Concentration alone isn't proof of a problem, but it is a pattern worth explaining.

Monitor Gifts and Benefits

Maintain a register of gifts, hospitality, or other benefits offered by suppliers and review it for patterns tied to particular relationships or decisions. Individually modest gifts can still signal a broader pattern of influence.

Provide Confidential Reporting Channels

Give employees a confidential, well-publicised way to report suspected conflicts or collusion without fear of retaliation. Whistleblower reports remain one of the most common ways internal fraud is first uncovered.

Investigate Patterns Over Time

Look beyond individual transactions to patterns across time, such as a supplier consistently winning close competitive bids or being repeatedly fast-tracked by the same approver. Collusion is often invisible at the transaction level and only apparent in aggregate.

Monitor Material Supplier Information

Continuously monitor key supplier attributes, such as registration status, ownership, and sanctions exposure, rather than checking them only at onboarding. A supplier that was clean a year ago is not guaranteed to be clean today.

Set Review Frequency by Risk

Set revalidation frequency according to each supplier's risk tier, reviewing high-risk suppliers more often than low-risk ones. Applying a single review cycle to every supplier wastes effort where it matters least.

Trigger Reviews After Significant Events

Trigger an immediate review when a significant event occurs, such as a change in ownership, an unusually large payment, or a sanctions list update. Waiting for the next scheduled cycle can leave a material change unaddressed for months.

Assign Alert Ownership

Assign clear ownership for who investigates and resolves monitoring alerts, with a defined timeframe for response. An alert that nobody owns is functionally the same as no monitoring at all.

Document Monitoring Outcomes

Record the outcome of every monitoring alert, including cases closed as false positives, along with the reasoning behind the decision. This record demonstrates the control is actually operating, not just generating noise.

Suspend Activity Where Necessary

Have a clear process to suspend payments or activity for a supplier pending review when monitoring surfaces a serious concern. The ability to pause quickly is what makes ongoing monitoring worth having.

Assign Clear Responsibilities

Name specific owners for each part of the supplier risk program, from onboarding through to monitoring and incident response. Shared ownership across a team, without an individual accountable, tends to result in gaps nobody notices until it is too late.

Maintain Documented Policies

Keep supplier risk policies and procedures current, approved, and accessible to everyone who needs to apply them. An undocumented control is difficult to apply consistently and hard to defend to an auditor.

Measure Control Performance

Track metrics such as onboarding turnaround, exception rates, and monitoring alert resolution times to understand whether controls are actually working. What isn't measured tends to quietly degrade.

Review Control Exceptions

Log and periodically review every instance where a control was overridden or an exception was granted. A rising pattern of exceptions is often the earliest sign that a control is failing in practice.

Test Control Effectiveness

Periodically test controls directly, for example by attempting a simulated bank-detail change, rather than assuming they work as designed. Controls that look sound on paper sometimes fail the moment they are actually exercised.

Prepare an Incident Response Process

Define in advance who is notified, what steps are taken, and how payments are frozen if a fraud attempt is discovered. Deciding this during an active incident costs valuable time.

Learn from Attempted Fraud

Treat every attempted or successful fraud, however it was caught, as an input to strengthening controls rather than a closed case. The details of a near miss are often the clearest evidence of where the next real loss will come from.