The review uses three public control and recordkeeping sources. None measures vendor-master fraud or tests this workflow.
Payables & Expenses
Vendor master change controls for bookkeeping teams
Research on approval, evidence, and segregation controls for vendor master data changes.
Published · 3 listed sourcesKey takeaways
- Verify sensitive vendor changes through a channel independent of the submitted request.
- Separate vendor-data maintenance from payment approval where the system and staffing model permit.
- Retain the request, authorization, change history, and reviewer disposition.
Evidence basis
What the evidence supports
The sources support documenting transactions, dividing incompatible responsibilities, limiting system privileges, recording auditable events, and retaining transaction support. Applied to vendor data, those concepts create review checkpoints between a change request, the system update, and payment authorization. They do not establish how much any control changes the probability of an unauthorized payment.
Control points
As a proposed local workflow, require a ticket or approved form, verify sensitive fields through a trusted channel independent of the request, limit edit permissions, and have an authorized reviewer disposition the change report after processing.
Methodology and limitations
This is a qualitative mapping of control concepts to a vendor-change workflow; it does not use transaction data, compare teams, or measure outcomes. The NIST material concerns information systems, the GAO standard concerns federal internal control, and IRS guidance concerns business records. A business should align the proposed controls to its systems, staffing, legal obligations, and risk assessment.
Source notes
The evidence map identifies the distinct role of every retained source: GAO for documented segregation, NIST for access and audit-record controls, and IRS for transaction-support retention. The independent verification step is an operating proposal, not a procedure prescribed by those sources.
Evidence map
These notes connect bounded statements on this page to the listed public sources. They do not turn operational interpretations into empirical findings.
- The GAO Green Book describes segregation of duties as dividing transaction responsibilities and calls for documentation of internal control and significant events; those concepts support separating request, entry, and authorization and retaining the change record.
- NIST SP 800-53 controls AC-5 and AC-6 address separation of duties and least privilege, while its AU family addresses auditable events and audit-record review; these are information-system control references for role design and change logging, not evidence of a fraud-reduction rate.
- IRS recordkeeping guidance says a business should keep supporting documents for purchases, expenses, and other transactions; it supports retaining vendor-change support but does not prescribe a vendor-master approval workflow.