Stop Rogue Payments to Unknown Vendors: Approve Every New Supplier
Shadow suppliers slip into your vendor master and payments walk out the door. See how a core business system gates every new supplier on parallel approval. Read how.
A purchasing clerk at a mid-size maker needs steel bar stock fast. A supplier cold-emails a price list that looks reasonable. The clerk adds the company to the vendor master that afternoon, opens a purchase order, and routes an invoice for payment three weeks later. Nobody in credit, nobody in legal, and nobody in security has ever heard of this supplier. By the time the bank transfer clears, the supplier has gone quiet, and the goods never quite matched the spec on the order. This is not a rare story. It is the single most common shape of internal-control failure that auditors flag in mid-size Japanese manufacturers, and the loss from one bad supplier can run into the tens of millions of yen.
The root cause is not a bad employee. The root cause is a vendor master that anyone can write to, paired with a payment process that trusts whatever bank account the master holds. Fixing it does not mean buying more software. It means moving new supplier onboarding into the same core business system that already runs your approvals, so that a new vendor cannot exist, cannot receive a purchase order, and cannot be paid until credit, legal, and security have all cleared it.
Why an Open Vendor Master Quietly Bleeds Money
A vendor master looks like a harmless list. In reality it is one of the most sensitive records in any ERP, because every line in it is a potential cash exit. When the master is open, three categories of loss follow.
The first is outright fraud. A staff member who can both create a vendor and approve a payment has everything they need to set up a shell company, route a few invoices through it, and walk the money out. Auditors call this a segregation-of-duties breakdown, and it is one of the most commonly cited internal-control weaknesses in occupational-fraud cases worldwide. One ghost vendor is enough to wipe out a year of efficiency savings.
The second is un-vetted risk. A supplier might have a valid tax ID and a polished website and still carry a bankrupt parent, a sanctioned beneficial owner, or a data-handling practice that would never pass a security review. Onboarding that supplier without a credit check, a legal review of the master agreement, and a security review of how they handle your drawings and customer data imports risk that you will only discover after a shipment is late, a quality claim escalates, or a regulator asks questions.
The third is silent drift. Even honest suppliers change. They change bank accounts, they change legal entity, they change ownership. When onboarding is a free-for-all, those changes also become a free-for-all, and a payment that used to go to the real supplier starts going somewhere else. Internal-control frameworks, from J-SOX to the Committee of Sponsoring Organizations guidance, all land on the same answer: changes to the vendor master must be authorized, reviewed, and logged. An open master is none of those things.
The Control That Actually Stops the Leak
The fix is a gate. A new supplier cannot enter the vendor master until a defined set of approvals has all cleared, and those approvals run in parallel rather than one after another. Credit checks the financial health. Legal reviews the contract and the entity. Security reviews the data exposure. None of them can sign for the others, and the supplier does not exist in the master until every one of them has said yes.
This is not a hypothetical design. The workflow engine inside a modern core business system runs parallel approval as a first-class mode, the kind of mode that requires all named approvers to clear before a request advances. A new vendor request opens with the supplier's legal name, registration number, bank details, beneficial owners, and intended purchase category. The moment it is submitted, three separate approval tasks fan out. Credit gets one, legal gets one, security gets one. Each works at their own pace, in their own queue. The supplier is blocked until the last of the three signs off.
-> Related: The 60 Approval Workflows a Manufacturer Runs, and the ROI of Moving Them Into One ERP
The reason parallel matters is speed without shortcuts. If credit, legal, and security had to approve in a fixed sequence, a vendor onboarding could take weeks because each reviewer waits for the one before. Run them in parallel and the total elapsed time is roughly the slowest of the three, not the sum. The vendor still gets vetted. The vendor just gets vetted quickly. For a purchasing team that needs bar stock this month rather than next quarter, that is the difference between a control that staff respect and a control that staff route around.
What the Approval Captures, and Why That Record Matters
When the last approver signs, the system does not just flip a status. It freezes a snapshot of exactly what was approved: the supplier name at the moment of approval, the bank account that was vetted, the beneficial-owner list that legal reviewed, the security notes that were attached. That snapshot is the audit trail. If anyone later edits the bank account, the change is its own new request, with its own approvals, layered on top of the original record.
This is the record an auditor wants to see during a J-SOX review or an internal-control walkthrough. The question they always ask is whether a new vendor was properly authorized before any money moved. With a frozen approval snapshot tied to the vendor record, the answer is yes, and you can prove it in seconds rather than digging through a shared drive for an email thread. For a mid-size manufacturer that is growing into formal internal control, this is one of the highest-value controls you can build, because vendor master changes are exactly where segregation-of-duties failures tend to hide.
-> Related: Audit-Ready Approval Workflows for J-SOX and Internal Control
A Scenario: The Precision Parts Maker in Shizuoka
Consider a precision parts manufacturer in Shizuoka, about 280 staff, supplying automotive OEMs across Japan. Their purchasing team adds roughly 120 new suppliers a year, a mix of material vendors, tooling shops, outside processors, and maintenance contractors. Before they gated onboarding, a buyer could add a vendor in the afternoon and issue a purchase order the same day. Credit, legal, and security found out weeks later, if at all, usually because something had already gone wrong.
In the new flow, the buyer opens a new-supplier request in the same core business system they already use for purchase orders and expense reimbursement. They attach the supplier's registration certificate, the draft master agreement, and the bank account form. The request fans out to three reviewers in parallel. The credit analyst pulls the supplier's financials and checks against the company's exposure limits. The legal reviewer reads the master agreement and confirms the entity matches the registration. The security reviewer confirms how drawings and customer data will be handled. Each signs in their own queue, on their own schedule. The total elapsed time is a few business days, not a few weeks, because the three reviews run together.
When the last of the three clears, the supplier is approved. At that point the buyer can open a purchase order against it. Before that point, the purchase order is blocked, because the system knows the vendor is not yet cleared. A payment cannot run against an un-cleared vendor either, because the payment workflow reads the same approval state. The gate is one control that protects both the master and the cash.
Over the first year, the company catches two suppliers that would have been problems. One has a beneficial owner on a sanctions list that the security reviewer flags during onboarding. Another is a thinly capitalized shell whose financials fail the credit check. Neither ever enters the master, and neither ever receives a payment. The cost of running the control is the few hours each reviewer spends per supplier, a fraction of what a single bad payment would have cost.
What Is Built Today, and What Is on the Roadmap
Being precise about the boundary matters more than overselling. What is built today is the approval gate itself: the new-supplier request, the parallel fan-out to credit, legal, and security, the requirement that all three clear before the request advances, the frozen snapshot of what was approved, and the audit trail that ties it back to the vendor record. That control is live now, and it is the part that actually stops rogue payments. A supplier cannot be cleared as approved until the gate has done its work.
What is on the roadmap, and not yet built, is the automatic writeback into the vendor master. Today, once the parallel approval clears, the approved supplier is confirmed as cleared inside the workflow, and the master record is created or updated through the normal ERP flow by the team that owns the master. The fully automatic push, where approval completion directly writes the new vendor into the master with no manual step, is coming. The honest way to say it is that the approval control is live today, and the automatic vendor-master update is on the roadmap. The control that prevents the fraud is the part you already get.
This honesty is worth pausing on. A surprising number of vendors in the market sell approval software that promises full automation and then quietly depends on a spreadsheet and an email to finish the job. The cleaner story is that the gate is real and enforced now, and the last inch of automation is a roadmap item with a clear scope. For a buyer evaluating tools, that clarity is more useful than a slide that promises everything.
-> Related: Purchase Orders and AP in One Core Business System
Frequently Asked Questions
Will parallel approval slow down every purchase?
No, because parallel approval runs only on new suppliers and on material changes to existing ones, not on every routine purchase order. Once a supplier is in the master and cleared, buying against it is fast. The gate sits in front of the cash exit, not in front of every transaction. The reviewers also work in parallel, so the elapsed time is the slowest reviewer, not the sum of all three.
What happens when a reviewer is traveling or out of office?
The workflow engine supports safe delegation, so an approver can hand their queue to a deputy for the days they are away. For high-risk items, the system can require that the original approver re-confirm after they return, so delegation never becomes a quiet way to bypass the gate. The control survives vacations and business trips, which is exactly when paper approvals tend to break.
How do we handle suppliers we need urgently?
Urgency is real, and a rigid gate that ignores it will get routed around. The practical answer is that the gate runs on business-day deadlines, so each reviewer has a defined window rather than an open-ended one. If a supplier genuinely cannot wait, the request can be escalated, but it still requires the clearances before the master is updated. The goal is to make the right way the fast way, not to make the right way impossible.
Does this replace our credit and legal teams?
No, and it should not. The control exists because credit, legal, and security each see something the others do not. The workflow routes the work to the right people and enforces that all of them clear. It does not do their analysis for them. What it removes is the manual chasing, the lost emails, and the gaps where a supplier slipped in because nobody was sure whose turn it was.
Key Takeaway
The vendor master is a cash exit, and an open vendor master is an unguarded cash exit. The control that closes it is a parallel approval gate: credit, legal, and security must all clear before a new supplier enters the master or receives a payment. That gate is built and live today. The automatic writeback into the vendor master is on the roadmap. The fraud-prevention part, which is the part that matters, you already get.
Get Started With Kikan System
If you have ever discovered a supplier in your master that nobody remembers approving, look at Kikan System. The workflow engine runs the parallel new-vendor approval, freezes a snapshot of what was cleared, and blocks purchase orders and payments against un-cleared suppliers. You can start on the free plan with up to 2 users, no credit card required. Begin at /#get-started.
Related articles
Stop Double Payments: Payment-Execution Approval
The same invoice paid twice costs millions. See how a core business system gates payments behind multi-step approval and segregation of duties.
Read more→Stop Silent Master Edits: Approve Price and BOM Changes
Silent edits to unit prices, BOM lines, and customer records corrupt invoices and inventory. See how an ERP approval workflow governs every master change.
Read more→Issue and Revoke System Access by Workflow: No Orphan Accounts
Manual provisioning leaves orphan accounts when staff leave. See how an ERP request-and-approve workflow governs access grants and stops lingering access.
Read more→Ready to Get Started?
Start free with up to two users and no credit card. Bring your biggest month-end headache, and we'll show you what the first 30 days look like on Kikan System.
Start free