Ready or Not: How to prep for a Vendor Master File Audit
Ready or Not: How to prep for a Vendor Master File Audit
A vendor master file audit examines how your organization creates, changes, authenticates, and retires vendor records, and whether the controls around those records actually hold. Preparing means proving those controls work year-round: documented segregation of duties, authenticated vendor identities, a complete change-history audit trail, and regular review of the file itself.
The vendor master file is the quietest high-risk asset in finance. Every payment that leaves the building traces back to a record someone created, edited, or approved. When an auditor opens that file, they are testing something more basic than any single number on the balance sheet: whether the records behind your payments can be trusted. The teams that pass run the same controls every day, so the audit simply confirms what they already know.
That is the right way to think about preparation. The internal controls that satisfy an auditor are the same controls that stop fraud and payment errors the rest of the year. Build them once, run them constantly, and the audit stops being an event you brace for.
What a Vendor Master File Audit Examines
The audit looks past the data itself and into the process that produced it. Auditors want evidence that the file is accurate, that access is restricted, that changes are tracked, and that no record is entered into the system without proper review. They sample. They pull a set of vendor records and trace each one backward to its origin: who requested it, who approved it, what supporting documentation exists, and whether the banking and remittance details were independently confirmed.
Three findings tend to surface first. Duplicate vendor records, because they signal weak data governance and create an opening for double payment. Dormant or inactive vendors that still carry live banking details, because a forgotten record is an easy target. And bank account or remittance address changes with no documented approval, because that single gap is where most payment fraud lives.
The Fraud Your Vendor File Has to Stop
The threat to your payments comes from outside. An attacker impersonates someone you already trust, then rides your legitimate payment process straight to the bank. The FBI defines business email compromise as a scam aimed at organizations that work with suppliers and make regular wire, ACH, or check payments, carried out by compromising email and other channels. In plain terms, the attack targets the exact workflow your vendor master file sits at the center of.
It arrives in one of several recognizable shapes:
- Vendor impersonation: an attacker poses as a real supplier and requests a change to the remittance bank account or mailing address, so the next genuine invoice pays the criminal.
- Executive or CEO impersonation: a spoofed message from a senior leader pressures AP to set up a payee and release an urgent payment outside the normal checks.
- Compromised vendor email: a legitimate supplier's mailbox is taken over, and the fraudulent invoice or banking change arrives from the real, trusted address.
- Staged change requests: an attacker first submits a change to the vendor's contact information, then waits before submitting the banking or remittance change, so the later fraudulent request appears to come from an already-updated, trusted contact.
Each of these ends at the same place: a new payee record, an edited bank field, or an approved payment against a record no one challenged. The vendor master file is where these attacks either go through or get stopped, which makes the controls around it the difference between a blocked attempt and a wire you cannot recover.
Segregation of Duties Is the Control Auditors Trust Most
If there is one control an audit is built to find, it is segregation of duties. The principle is simple. The person who can create or change a vendor record cannot also approve payments to that vendor. One role sets up the payee, and a different role releases the money. No single employee owns the path from record to disbursement.
This matters because impersonation fraud succeeds when one deceived employee can carry a payment from start to finish. For example, a spoofed executive demands an urgent payment to a new payee. If the same person can edit the record and release the funds, that single point of trust is all the attacker needs. Split those duties, and the fraudulent change has to clear a second person and an independent check before any money moves, which is where most of these attempts fall apart.
Auditors test this by examining your access controls and role assignments. Who has permission to add a vendor? Who can edit banking fields? Who approves payment runs? They will look for overlap, and they will look for accounts with more access than the job requires. Least privilege is the standard: each user holds the narrowest set of permissions their work demands, and nothing more. Document who holds which role, review those assignments quarterly, and remove access the moment someone changes positions or leaves.
When true segregation of duties is not possible—often the case on small teams—auditors look for compensating controls instead. Two are worth documenting. First, management review: a manager approves vendor additions and changes before they are accepted into the ERP. Second, independent review of pay-cycle reports before payments are released, with specific attention to any vendor that has had a recent remittance change. Document these compensating controls explicitly, because an auditor who finds SoD gaps will look for them next.
Authenticate Vendor Identity Before It Reaches the ERP
The strongest control is the one that runs before a record ever enters the ERP. Once a vendor sits in the master file, it carries an implicit trust. Invoices against it get paid, and banking details on it receive funds. So the question that decides everything is what happened at the front door. Was the vendor authenticated, or was it simply entered?
Authentication is more than a light check against a submitted form. It is a thorough process that confirms the entity is real, that the banking details belong to that entity, and, where payment is by check, that the remittance address belongs to the vendor. Strong programs match the tax identification number against IRS records, screen the entity against OFAC's sanctions lists, and confirm banking details through an independent channel rather than the contact information printed on the invoice. For check payments, verify the remittance address against the state where the vendor is registered. If the remittance address differs from the registered address, confirm it through an independent channel, the same way you confirm banking details. The point is to break the chain a fraudster relies on, where the same forged document supplies both the request and the proof.
Business email compromise does its damage when a vendor impersonator asks to update a bank account. If the change flows straight through, the next legitimate invoice pays a criminal. A genuine authentication step, including an out-of-band confirmation, using an independently sourced phone number (for both bank account and remittance address changes) closes that door. The result is a file of authenticated vendors and credentialed payees, each one confirmed before it could receive a payment. Auditors increasingly ask to see this front-door process, so document it as a written policy and keep the evidence.
Change Control and the Audit Trail
Vendor records are not static. Addresses move, banking details change, and contacts turn over. Every one of those changes is a risk event, and every one of them needs a trail. Change control is the discipline of treating each modification as a transaction that must be requested, approved, and logged.
A complete audit trail answers four questions for any field in the file: what changed, who changed it, when, and who approved it. Many accounting systems and ERPs also retain the before and after values for each edited field, and auditors will review them, so make sure your audit trail captures not just that a field changed but what it changed from and to.
That record cannot be edited by the same person who made the change. It has to be system-generated and tamper-resistant, because its entire value lies in being trustworthy after the fact. When an auditor samples a vendor record, this trail is what they follow. A clean history that shows authorized, documented changes passes quickly. A field that changed with no requester, no approver, and no date raises a flag that widens the scope of the review.
Banking changes deserve their own tier of control. A change to a remittance bank account is the single highest-risk modification in the file, and it should never be processed on the strength of an email alone. Route it through the same authentication you apply at onboarding. Confirm the request through an independent channel. Require a second approver. Flag it in the audit trail as a high-risk change. The frauds that hurt most are usually small: a quiet edit to a trusted record that no one was watching. Tight change control is how you catch it.
Remittance address changes for check payments also deserve scrutiny, and in some ways the exposure is worse. A criminal who intercepts a check can wash the original, produce counterfeit checks, and read the check stub and remittance advice to learn your invoice number format and typical invoice amounts, then submit fraudulent invoices that blend in with legitimate ones.
Keep the Master File Clean Between Audits
A master file decays on its own. Vendors merge, go out of business, or simply stop transacting, and their records linger with live payment data attached. Left alone, the file fills with duplicates, dead entries, and inconsistencies that an audit treats as evidence of weak governance. Routine maintenance keeps it honest.
Start with deduplication. Duplicate vendor records are a leading audit finding and a direct cause of double payments, where the same invoice is paid twice against two versions of the same vendor. Standardize naming conventions, run periodic matching to surface near-duplicates, and merge or retire them on a schedule.
Also document the valid reasons a genuine duplicate can exist in your system (different payment method, different bank account, or different currency, etc.) so you can quickly clear legitimate duplicates and focus on true ones. Check for duplicates at both the vendor header level (name, TIN) and the site or location level, since some systems tie multiple site IDs, addresses, and payment methods to a single vendor header.
Next, handle dormancy. Set a clear threshold, for example, no activity in eighteen to twenty-four months, and deactivate records that cross it. A deactivated vendor can be reactivated through the proper authentication if business resumes, which is far safer than leaving an open record that no one monitors. Treat a reactivation request like a new vendor. Collect the same required documents and run the same due diligence. If it passes and the Tax ID has not changed, reactivate the existing record rather than creating a new one.
Build in recurring data hygiene as well. Re-run TIN matching and sanctions screening on a defined cycle, not only at onboarding, because a vendor's status can change after it joins your file. Reconcile the master file against your ERP so the two never drift apart.
Watch for bank routing number changes as well. Vendors rarely report when their bank is acquired or merged, and the resulting routing number change surfaces as Notices of Change (NOCs) from the bank or as returned payments when routing numbers don't match, which can carry Nacha fines. Reconcile these proactively rather than discovering them at settlement.
None of this is glamorous work. It is the difference between a file you can defend and a file you have to explain. The organizations that handle it quarterly walk into the audit with nothing to clean up.
How to Prepare for a Vendor Master File Audit
Preparation for this audit is mostly a documentation exercise, assuming the controls already exist. Auditors expect proof: the policy, the evidence, and the trail behind each control. Pull these together before the request arrives.
Write down the policies. A vendor onboarding policy, a change-control policy, and an access-and-roles matrix should exist as living, written documents that the team maintains. Map each one to a recognized framework, so your approach is defensible. The COSO Internal Control Integrated Framework is the common reference for private organizations, and government finance teams should align with the GAO Green Book, the Standards for Internal Control in the Federal Government. Citing a framework signals that your controls follow an established standard rather than an ad hoc habit.
Then assemble the evidence that an auditor will sample. Be ready to show, for a given vendor, the original onboarding request, the authentication record, the approval, and the full change history. Run your own internal sample first. For example, pick ten records at random and trace each one yourself. If you cannot complete the trail, the auditor will not be able to either, and you would rather find the gap now. Confirm that segregation of duties holds in the live system, that no dormant records carry active banking details, and that recent bank changes each show independent confirmation.
The deeper point is that this audit rewards consistency. A file maintained under standing controls produces its own evidence as a byproduct of normal work. The trail is already there. The duplicates are already gone. The authentications are already on record. Readiness, in the end, is just the accumulated result of controls that ran all year, whether anyone was auditing or not.
Get Ready For Vendor Management Appreciation Day
Vendor Management Appreciation Day (VMAD) returns this year—and we’d love to have you join the celebration. There’s never a wrong time to recognize one of the most essential yet often overlooked functions in every organization: vendor management.
We’re already preparing for this year's festivities, and we want the entire community to be part of it. VMAD was created to bring vendor management professionals together, spotlight the innovation happening in the field, and give this important work the recognition it deserves.

As a reminder, throughout the year, we’re rolling out monthly gifts and resources to help elevate your vendor management practice. We’re also planning a series of events designed to spark connection, learning, and celebration across the profession.
So, while you wait for the big day, explore what’s new—and grab some free vendor management goodies.
Want Help Aligning Teams?
Explore our blogs below. They’re filled with action items you can implement right away.
Why Supplier Verification Is the First Line of Defense Against Risk
What Is Business Identity? Why It Matters, and How to Get It Right
The Supplier Risk Assessment Process: A Step-by-Step Framework
Why Supplier Lifecycle Management Is the New Frontline of Cybersecurity
Interested in More Tips?
Want Personalized Guidance?
A vendor master file audit is a review of how an organization creates, changes, authenticates, and retires the vendor records that drive its payments. Auditors test the controls around the file rather than just the data: segregation of duties, restricted access, change tracking, and identity authentication. They sample individual records and trace each one back to its origin, looking for duplicates, dormant entries, and undocumented banking changes that signal fraud or payment risk.
Let us show you how we can help
We’d love to walk through your process with you and talk about security, compliance, efficiency and sleeping better at night.
See How it Works