Vendor-master changes are low-volume events with high downstream consequence. This study focuses on identity, address, tax, and bank-detail changes during a defined period. The unit is one change event with a before value, after value, requester, confirmer, approver, and effective date.
Payables & Expenses
Vendor master changes: evidence for bank-detail and identity updates
Research on requests, independent confirmation, effective dates, and review evidence for vendor-master changes.
Published · 10 listed sourcesKey takeaways
- A request is not independent confirmation.
- Effective dates prevent old and new records from being conflated.
- Access to change data should be narrower than access to vendor history.
Research question
Evidence model
Preserve the original request, reason, supporting document, independent confirmation, approval, and system audit record. Independent confirmation should use a known contact or trusted record rather than the contact details supplied in the same change request. Record the old and new value without exposing unnecessary sensitive data in broad reports.
Review changes by count, field, vendor, requester, and time from change to first payment. A same-day change and payment is a review signal, not proof of impropriety. Compare the change log with payment activity and returned payments. Keep inactive vendors and reversals visible; deleting history destroys the context needed to investigate a later anomaly.
Handoff and limitations
Bookkeeping support can maintain evidence, perform duplicate checks, and report missing approvals. A designated owner should approve exceptions, determine trusted confirmation channels, and control access. This framework does not certify a vendor’s legal identity or bank account.
The conclusion is that a vendor record is safer to review when history, effective date, independent confirmation, and payment linkage are visible. The strongest control is not a form; it is separation of request, confirmation, change, and release where the organization can support it.
Source notes
The sources cover control, fraud risk, access, accounting, and record retention. They provide context rather than a universal procedure.
Evidence map
These notes connect bounded statements on this page to the listed public sources. They do not turn operational interpretations into empirical findings.
- The source list includes GAO, Standards for Internal Control as public guidance relevant to vendor evidence.
- COSO, Internal Control is listed to frame review questions about vendor master changes: evidence for bank-detail and identity updates.
- ACFE, Report to the Nations 2024 provides context; this report does not treat that source as proof that a staffing model causes an outcome.