Supplier master data is the core governed record used to identify a supplier and control transactions across business systems. It connects purchasing, invoicing, payment, tax and reporting to the correct legal entity.
Which fields are commonly included?
- Legal name and registration identifiers
- Addresses and tax information
- Contacts and communication preferences
- Payment terms and currency
- Verified bank details
- Status, category and risk flags
Why is master data a control point?
A false or incorrect supplier record can redirect orders and payments. Duplicate records can hide spend, bypass controls and create reconciliation problems.
How should a new supplier be created?
Use documented onboarding, identity and tax validation, duplicate search, bank verification and independent approval. Preserve the evidence and creator-approver trail.
How should changes be managed?
Apply effective dates, reason codes and risk-based reapproval. Bank-detail changes should be confirmed through a trusted channel separate from the request.
What should be monitored?
Review inactive, duplicate, incomplete and high-risk records; expired documents; recent changes; and transactions soon after changes. Restrict who can create or edit the master.

