Accounts payable and payment controls
What Is a Vendor Master? AP Data Control Guide
Direct answer
A vendor master is the governed set of supplier records used by purchasing, invoicing, tax and payment processes. It usually connects legal identity, tax registrations, addresses, payment terms and validated bank instructions to a unique supplier. Strong controls separate requests, verification, entry and approval, because an incorrect or unauthorised change can redirect payments or create duplicate liabilities.
Also known as: supplier master, vendor master data.
Key takeaways
- The vendor master is shared control data, not a contact list owned only by accounts payable.
- Legal identity, tax registration, ordering details, payment terms and bank instructions need distinct evidence and ownership.
- Bank-detail changes deserve fresh independent verification; an email reply in the same thread is weak evidence.
- Duplicate, dormant and one-time records need periodic review as well as onboarding checks.
- An approved vendor record begins the procure-to-pay path before receipt, matching, payment approval and UTR reconciliation.
Why vendor-master data is a control point
One supplier record can influence where a purchase order is sent, which GSTIN appears in a match, which payment terms calculate the due date and which bank account receives money. That makes master data an upstream control: a wrong value can travel through otherwise correct transactions.
Operational guidance: assign a unique vendor identifier to the legal supplier and maintain site, tax and remittance attributes without creating unnecessary duplicates. Separate source evidence from normalized system values. RBI’s beneficiary account name look-up direction requires participating banks to offer remitters a name check for RTGS and NEFT; companies can use the displayed name as one payment pre-check, but it does not establish supplier ownership, contract authority or tax validity by itself.
Core vendor-master fields and evidence
| Field group | Typical fields | Evidence or owner |
|---|---|---|
| Legal identity | Legal name, entity type, registered address | Supplier documents and procurement or legal review |
| Tax | PAN, GSTIN, registration state, withholding attributes | Official records and tax team |
| Commercial | Category, buyer, currency, payment terms, order method | Approved contract or PO policy |
| Banking | Account holder name, account number, IFSC, bank and branch | Supplier evidence plus independent verification |
| Control | Status, risk tier, creation date, last review, maker and checker | System audit trail |
| Contact | Authorised commercial and remittance contacts | Validated onboarding channel |
Collect only data needed for a defined business purpose, restrict sensitive fields and retain evidence under the organisation’s privacy and records policy.
Controlled supplier onboarding
- Receive a request from an authorised business owner with the procurement purpose.
- Search normalized legal name, PAN, GSTIN, bank account and contact details for duplicates.
- Obtain identity, tax, commercial and bank evidence through an approved channel.
- Validate each attribute with the responsible owner; do not let one document prove unrelated facts.
- Enter the record by a designated maker and have an independent checker compare it with source evidence.
- Activate only after required approvals and preserve who changed each field and when.
- Communicate the approved vendor identifier to purchasing and AP.
- Schedule risk-based refreshes and deactivate records no longer needed.
This is a sample operating model, not a statutory onboarding checklist. Requirements depend on industry, contract, tax and data-protection obligations.
Bank-detail and sensitive-field change checklist
- Treat an email requesting new bank details as a trigger for verification, not as approval.
- Contact a previously validated supplier representative using a known number or channel, not details supplied only in the change message.
- Compare account-holder name through the bank’s available beneficiary-name facility and investigate differences.
- Require maker-checker approval and prevent the requester, maker and checker from collapsing into one person.
- Notify the existing contact and relevant buyer of the completed change.
- Apply a risk-based payment hold or enhanced review to the first payment under internal policy.
- Retain old and new values, request evidence, verification result, timestamps and identities.
- Report emergency overrides separately and review them after the event.
The RBI facility can reduce wrong credits and fraud, but the RBI also notes that account-number information is critical in RTGS processing. A displayed name should supplement, not replace, internal authority checks.
Multi-location consumer-brand example
Fictional example: RiverMint, a consumer brand with 18 locations, receives a bank-change email for carton supplier Pristine Packs. A data clerk finds a second inactive record with a similar trade name and the same PAN but a different bank account. Instead of creating a third record or overwriting the active one, the team pauses the request.
The buyer confirms the existing contract entity. The master-data analyst calls the previously registered finance contact, who says the email domain was spoofed and no bank change was authorised. The proposed account-holder name also does not align with the validated supplier identity. The checker rejects the change, records the attempted diversion, keeps the approved account unchanged and blocks the duplicate inactive record from transactions. The example shows why duplicate search and out-of-band confirmation operate together.
Vendor-master ownership and audit review
- Define who may request, verify, create, approve, pay and administer access.
- Review new vendors and sensitive changes by maker, checker, supplier, value and location.
- Search for shared PAN, GSTIN, bank account, address, phone or email across active records.
- Identify payments to dormant, blocked or recently changed suppliers.
- Compare access roles with job responsibilities and remove incompatible or stale privileges.
- Sample evidence for bank changes and confirm independent contact methods were used.
- Age records with no purchase or payment activity and deactivate them under policy.
- Reconcile master changes to first payments and investigate reversals, returns or rush approvals.
An audit checklist tests whether the company’s control design operated; it is not a substitute for a professional statutory-audit programme.
Frequently asked questions
Who should own the vendor master?
A named control owner should govern standards and access, while procurement, tax, AP, treasury and business owners validate the fields within their responsibility.
Can the same supplier have multiple vendor records?
Sometimes separate purchasing organisations or remittance sites require structure, but duplicates without a defined purpose fragment spend, weaken blocks and increase duplicate-payment risk.
How should bank changes be verified?
Use an independently known supplier contact or approved portal, compare reliable evidence, use available beneficiary-name checks, and require a separate checker before activation.
Does a beneficiary-name match prove the supplier owns the account?
No. It is a useful bank-provided signal, but the company must still verify supplier authority, legal identity and the change request through its own controls.
How often should vendor records be reviewed?
Use a risk-based cadence and event-driven review for sensitive changes. High-value, high-risk, dormant and recently changed records generally deserve closer monitoring under company policy.
Sources and further reading
- Reserve Bank of India: Introduction of beneficiary bank account name look-up facility for RTGS and NEFTVerified Jul 25, 2026
- Reserve Bank of India: Real Time Gross Settlement System FAQsVerified Jul 25, 2026
Educational disclaimer: This material is general information, not legal, tax, or accounting advice. Check current official guidance and your facts with a qualified professional.
From definition to workflow
Apply this concept with connected finance operations
Finnoto connects source records, approvals, reconciliation evidence, and exception ownership so teams can move from knowing the rule to operating the control.
Explore accounts payable controls