Vendor Onboarding: PAN, GST, Bank and Conflict Checks
A vendor-master control covering legal identity, PAN, GST, bank, Udyam, beneficial relationship, approval and change management.
For broader context, see the GST Law & Practice Hub.
The purpose is to turn an operational issue into a measurable exposure, reconciled evidence, an accountable owner and a dated closure.
Vendor legal name, PAN, GSTIN, address, bank-account name and contract entity should align.
GST registration should be checked on the official portal.
Related or employee-connected vendors need conflict disclosure and independent approval.
Bank changes should not be accepted solely through the requesting email thread.
What management should understand
In practice: these four checks stop the two most common vendor-master frauds - a fake or altered vendor entirely (caught by identity/PAN/GST alignment and portal verification) and a genuine vendor’s bank details silently swapped via a compromised email (caught by independent bank verification and payment-approval segregation). Skipping any one check individually still leaves an exploitable gap even if the other three are followed.
- Cross-check that the legal name, PAN and GSTIN on the vendor record match the name on the bank account the payment will actually reach - not just the invoice letterhead.
- Look up the GSTIN directly on the GST portal rather than trusting a certificate copy the vendor supplies.
- Flag any vendor address, bank account or director that matches an employee’s own details, and route those through a second, independent approver.
- Treat every bank-account-change request as suspicious by default until verified through a channel OTHER than the email that raised it - a callback to a known number, for instance.
- Keep the person who can CREATE or EDIT a vendor record separate from the person who can RELEASE a payment to that vendor.
Use the Finin2min GST Services Rate Master to apply these points to your figures or facts.
The five-point control review
| Review | Management test |
|---|---|
| Scope | Entity, process, period and accountable owner. |
| Source | Contract, invoice, payroll, portal, bank or operational record. |
| Reconciliation | Book amount, external record and explained difference. |
| Decision | Approval, exception threshold and corrective action. |
| Closure | Live-system result, evidence, date and next review. |
For the connected rule, example or next step, see GST TDS Under Section 51: Government Contract Vendor Checklist.
Practical example
A supplier email asks for payment to a new account whose name differs slightly from the GST registration. The request was sent from a compromised mailbox.
Implementation workflow
1. Define the transaction and the decision
State precisely what is being measured or approved: a month-end balance, customer order, product cost, purchase, tax credit, payroll run, bank payment, investment or export document. Set the period, legal entity, business owner, reviewer and materiality. A control cannot work when the team is reviewing different transactions or dates.
2. Lock the source evidence
Collect the signed contract, approved master data, invoice, receipt, timesheet, inventory record, payroll file, portal statement, bank transaction or system log. Preserve the original version and document subsequent amendments. Official portals are important external records, but they do not replace the underlying commercial evidence or the books.
3. Reconcile value, quantity, date and identity
Match legal names, PAN or GSTIN where relevant, document numbers, quantity, amount, tax, due date, payment account and approval. Separate timing differences from errors and suspected fraud. An unexplained difference should remain open with an owner; it should not be forced into a suspense or miscellaneous account merely to complete the close.
4. Assess tax, payroll, cyber and contract boundaries
GST registration thresholds are not one universal number: the threshold for suppliers of goods can differ from services, and specified States can have lower limits. Compulsory-registration provisions, e-invoice history, e-way-bill rules, EPF or ESIC coverage and contract terms require separate analysis. Where insurance, guarantees or cyber cover are involved, the actual policy wording or instrument terms control the outcome.
5. Quantify the cash effect
Show the immediate payment or receipt, working-capital days, tax timing, finance cost and downside exposure. A transaction can be profitable in the accounts and still create a cash deficit. Use a base case and at least one stress case before accepting a large order, changing price, buying equipment or releasing a disputed payment.
6. Approve, execute and verify
The preparer should not be the only approver where master data, payment or statutory exposure is involved. Record the decision, exception reason and expiry. After execution, verify the live result in the bank, GST portal, payroll return, vendor master, inventory record or management report. A submitted request is not completion.
Action checklist
- Collect verified identity and tax records.
- Validate bank independently.
- Perform conflict declaration.
- Approve vendor master.
- Review inactive and changed vendors.
Evidence to keep
- PAN/GST verification
- Cancelled cheque or bank proof
- Contract and address
- Conflict declaration
- Vendor-master audit trail
Warning signs
- Name mismatch
- Free-email domain
- Employee connection undisclosed
- Urgent bank change
- Creator releases payment
Finin2min takeaway
Strong MSME controls do not require bureaucracy. They require clean source records, segregation for high-risk actions, fast reconciliation and visible exception ownership.
For the connected rule, example or next step, see GST ITC Reversal for Vendor Non-Compliance.
Frequently Asked Questions
Source and review trail
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
- Primary category
- GST & Indirect Tax
- Official starting point
- www.gst.gov.in
Page source links
Primary sources & related provisions
Statutory provisions referenced in this guide: