Most payment fraud enters before the bank file—through a fake vendor, changed account or unsupported invoice.
Quick View
Procurement and finance controller
Per transaction, monthly review
Standardise vendor onboarding.
Vendor onboarding file.
Why It Matters
The process begins with an approved business need and ends with correct accounting and payment. Vendor onboarding, purchase order, goods or service receipt, invoice and payment should form one traceable chain.
Master-data changes require independent verification. An email requesting a new bank account should not be accepted solely because it appears to come from the vendor.
Tax, GST, TDS, MSME status, related-party status and contract terms need review before payment, not after the return is filed.
Control Framework
| Control | What it covers | Operating rule |
|---|---|---|
| Vendor master | Identity, tax and bank details are independently verified. | Use maker-checker approval. |
| Commitment | Purchase need, budget and authority are documented. | No retrospective purchase orders. |
| Invoice match | Order, receipt and invoice are compared. | Resolve quantity and price differences. |
| Payment | Approved liability is paid to verified account. | Review bank output independently. |
Action Checklist
- Standardise vendor onboarding.
- Require approved purchase orders.
- Capture receipt or service acceptance.
- Run invoice and tax validation.
- Verify bank changes outside email.
- Reconcile vendor ledger and payments.
Practical Example
Evidence to Keep
- Vendor onboarding file.
- Purchase order and contract.
- Goods receipt or service acceptance.
- Tax invoice and three-way match.
- Payment approval and bank file.
- Vendor statement reconciliation.
Warning Signs
- Creating vendors from invoice emails.
- Using retrospective purchase orders.
- Paying without service acceptance.
- Approving bank changes in the same workflow.
- Leaving debit balances unexplained.
Management Decision
Block urgent-payment pressure from bypassing master verification. True urgency should receive faster independent review, not fewer controls.
Analyse duplicate invoices, split purchases, manual payments and weekend master changes as fraud indicators.
Record the decision, owner, due date and evidence expected. A verbal explanation should become an approved working, board note, contract amendment, statutory filing or reconciliation before the item is treated as closed.
Rules, forms, thresholds and procedures can change. Use the latest official source and the actual company facts rather than copying a prior-year control or another entity’s legal position.
Exception Review
Classify every exception as a timing difference, data error, missing document, legal non-compliance, control-design gap or control-operating failure. This prevents management from treating fundamentally different problems as one ageing list.
The exception file should show amount or exposure, root cause, immediate correction, preventive action, owner and board-escalation threshold. Repeated low-value issues can become material when they reveal weak systems or management override.
Close the item only after the evidence agrees across source documents, books, portal data and management reporting. A screenshot or email promise is not equivalent to a completed filing, lender waiver, signed contract or reconciled ledger.
Board Escalation
The control should operate across the full transaction population, not only the samples management expects a reviewer to inspect. For this topic, the key stages are vendor master, commitment, invoice match, payment. Each stage should identify the source system, preparer, reviewer, deadline and evidence retained.
A useful management review asks whether the legal document, accounting entry, bank movement, tax treatment and public filing describe the same event. Differences may be valid, but they should be reconciled through a dated working rather than explained from memory during audit or diligence.
Materiality should determine escalation, not whether the company keeps a record. Repeated small exceptions can show weak master data, unclear authority, system bypass or management override. Root cause and preventive action should therefore be documented separately from the immediate correction.
Control evidence should show operation, not merely design. A policy document proves what management intended; a reconciliation, access review, approval log or exception report proves whether the control actually worked during the period.
Manual journals, spreadsheet uploads, administrator access and post-close changes deserve additional scrutiny because they can bypass automated workflows. The reviewer should assess both the entry and the reason normal processing was not used.
Common Questions
Is three-way matching always possible?
Service and low-value processes may use tailored controls, but order, receipt and invoice evidence should still align.
Who verifies bank details?
A person independent of the request and entry should confirm through trusted vendor contact details.
Can tax review wait until return filing?
No. Tax treatment affects the amount and timing of payment.
What closes the transaction?
Correct ledger posting, payment, tax treatment and supplier reconciliation.
Official Sources
Use the latest official law, rule, portal instruction and executed company document before filing, issuing, remitting, recognising or taking a board position.