Money leaves the company when a supplier charges more than you agreed. Master Data finds it. Your supplier, customer and employee records checked so each is complete, none is the same thing twice, and no supplier is also one of your people.
What it checks
- Duplicate supplier. No two supplier records share a tax id, a bank account, or a name and address that closely match.
- Duplicate customer. No two customer records share a tax id, or a name and address that closely match.
- Supplier is not an employee. No supplier shares a bank account, address, phone or tax id with an employee.
- Record complete. Every active supplier has a tax id, address and bank account on file, and every customer an address and billing contact.
- Dormant then reactivated. A supplier with no activity for twelve months that is paid again is flagged before the payment clears.
- Bank details changed. Every change to a supplier's bank details is logged with who changed it and when, and flagged.
- Cross-reference agrees. The same supplier or customer carries the same id in every connected system, or a match you have confirmed.
A finding, in its own words
Supplier 'Northwind Supply' and supplier 'Northwind Supply Co' share the same tax id and are paid to the same account. They are one supplier under two records. Tell me which to keep and I will propose the merge.
Supplier 'Ridgeway Services' has the same mailing address as employee E-023 and is paid to the same account. That may be known; if so, add it to context and I will record it.
What it may ask you
- What must every supplier record have? For example tax id, address, bank account. Unless you say otherwise: tax id, address and bank account for suppliers; address and billing contact for customers.
- After how many days without activity is a supplier 'dormant'? Unless you say otherwise: 365.
- Is anyone on your team also a supplier on purpose? Name them.
- Does the same supplier have different ids in Xero and your bank? Give both.
What it draws on
- Each supplier and customer exists once. COSO Control Activities, principle 11; SOX: Master data integrity.
- Suppliers are not employees in disguise, and dormant suppliers do not wake up quietly. COSO Control Environment, principle 1; SOX: Vendor master fraud risk.
- Related parties are identified. COSO Control Environment, principle 1; SOX: Related-party transaction identification.
- Master records have what a payment needs. COSO Control Activities, principle 11; SOX: Master data completeness.
- Changes to master data are controlled. COSO Control Activities, principle 11; SOX: Master file maintenance controls.
What it needs
- your supplier and customer lists, from your accounting system or as a spreadsheet
- your employee list, with addresses and payment details, so a supplier can be checked against it
- Connections, optional: QuickBooks or Xero for suppliers and customers, your payroll provider for employees, and your bank for who is actually paid. Two lists are enough to start.