Vendor Master Fraud: How Fake and Duplicate Suppliers Drain Growing Companies
The file nobody audits
Every company has a vendor master file — the list of suppliers you can pay. It grows for years, rarely gets cleaned, and almost never gets reviewed. That neglect makes it one of the most reliable places for money to leak, through both honest error and deliberate fraud.
The schemes to know
- Shell (fictitious) vendors. A fake supplier is added to the master file and paid for goods or services that never existed. Because the vendor looks legitimate in the system, the payments sail through.
- Vendor-employee overlap. A supplier shares a bank account, address, tax ID, or phone number with an employee — a conflict of interest at best and a self-dealing scheme at worst. This is one of the highest-signal fraud tests there is, and it’s invisible unless you cross-reference the two files.
- Duplicate vendors. The same supplier exists twice under slightly different names, so duplicate-payment blocks don’t fire and spend is impossible to see clearly.
- Bank-detail diversion. A fraudster — often through business email compromise — changes a real vendor’s bank details so the next legitimate payment routes to them. The invoice is real; the destination isn’t. This is one of the costliest and fastest-growing payment frauds.
- Dormant vendors reactivated. An old, inactive vendor suddenly starts receiving payments again — a common cover for fraud.
Why it’s so hard to catch manually
Each of these hides in data you rarely look at, and detection requires connecting files that don’t normally talk to each other — the vendor master, the payment history, the employee/HR records, and change logs. A person can’t reasonably cross-reference thousands of vendors against employee records or watch every bank-detail change in real time. So it doesn’t get done, and the schemes run for months.
How to shut it down
The controls are well understood; the challenge is running them continuously:
- De-duplicate the vendor master, including fuzzy matches (spacing, punctuation, abbreviations).
- Cross-reference vendors against employees on bank account, address, and tax ID.
- Alert on every bank-detail change and require independent verification before the next payment.
- Watch for dormant vendors reactivating and for new vendors that immediately receive large payments.
- Require approval and documentation to add or change a vendor at all.
Clean vendor data isn’t just a fraud control — it makes every other procure-to-pay check more reliable, because your duplicate-payment and price-variance tests are only as good as the vendor records underneath them.