Knowella

Supplier Master Data Setup

The recurring failure is not a supplier created badly. It is a supplier created correctly on day one and amended quietly on day four hundred. Approval was granted for one category at one site; a year later the record carries three categories, no purchase order requirement and terms nobody negotiated. Every amendment was small, none was reviewed, and the drift surfaces only when an auditor samples the ledger and asks who approved the scope.

KnowLogisticsRecordLOG-044Pinned in navigation50 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 9001 cl.7.5
Workspace
KnowLogistics
Form type
Record
Completed by
Master data, with procurement countersigning
Review trigger
New supplier, amendment, reactivation or deactivation

The short version

  • The setup record, not the approval record, is where a supplier control becomes enforceable. An approval never expressed as a scope restriction, a spend limit and a purchase order flag is advisory.
  • Segregation of duties is scored here for a reason. The person who requests the record and the person who enters it must be different people, or the requisition control collapses into one keyboard.
  • Amendments are the higher-risk transaction, not new suppliers. New suppliers attract scrutiny; amendments arrive as a two-line email and change bank details, terms or scope with no second signature.
  • A record not blocked for payment until setup completes is a supplier that can be paid before anyone has verified who owns the bank account.

What this is

What is supplier master data?

What is supplier master data?

Supplier master data is the set of standing attributes that make a supplier transactable: legal name, code, addresses, tax registration, currency, payment terms, bank details, purchase order requirement, category and approval scope. It is neither the contract nor the approval decision, but the machine-readable expression of that decision, which every purchase order, invoice and payment inherits from.

What is approval scope in a supplier record?

Approval scope is the boundary of what the supplier was actually approved to supply, and from where. A supplier approved for packaging at one site is not approved for ingredients at three. Scope is the field that turns an approval decision into an enforceable control, and it is the field most often widened by a helpful amendment rather than a fresh assessment.

What is a duplicate supplier check?

A duplicate supplier check is a search of the existing vendor file for the same legal entity under a different code, spelling, trading name or bank account before a new record is created. Duplicates split spend so it never crosses an approval threshold, and they open a second, unwatched channel into the same payment run.

Scope

When is a supplier master data setup required?

This template creates or amends the standing record itself. It sits after the approval decision and before the first purchase order, and is deliberately narrow: what was entered, who entered it, who checked it.

Use this template when

  • A new supplier has been approved and the record must be created before any order is raised
  • An existing supplier's terms, currency, addresses, tax registration or purchase order requirement are being amended
  • A dormant supplier is being reactivated and the standing data must be re-proved rather than assumed still valid
  • A supplier is being deactivated and the record blocked in a way that leaves transaction history intact
  • A periodic master data review has fallen due and the record needs re-checking against the approval on file

Do not use it for

  • Supplier Due Diligence and Screening, which decides whether the entity is acceptable at all. That judgement happens before a code is issued.
  • Supplier Bank Detail Verification, which is the independent callback on the account. This record only captures that it was done and carries its reference.
  • Supplier Approval Record, which is the technical and commercial decision. This template implements that decision; it does not make it.
  • Vendor and Contractor Register, which is the standing list of who is active. The register is a view of the population; this is the transaction that changes it.
  • Supplier Onboarding Checklist, which tracks the onboarding sequence to completion. Used in place of this record it loses the field-level evidence of what was entered.

Compliance mapping

Which ISO 9001 cl.7.5 requirements does this satisfy?

ISO 9001 cl.7.5 governs the documented information; cl.8.4 governs control of the provider it describes. This template is where the two meet.

ClauseRequirementWhere it lands
ISO 9001 cl.8.4.1Determine and apply criteria for the evaluation, selection and monitoring of external providers, and retain documented information of the resultsLinked records
ISO 9001 cl.8.4.2Ensure externally provided processes remain within the control of the quality management system, and define the controls applied to the providerControls
ISO 9001 cl.8.4.3Communicate to external providers the requirements for the processes, products and services to be provided, including approval requirementsCore data
ISO 9001 cl.7.5.2Ensure appropriate identification, description, format and review and approval for suitability of created documented informationHeader
ISO 9001 cl.7.5.3Control documented information so that it is available, adequately protected, and subject to control of changes and versionOutcome
ISO 37001 cl.8.2Conduct due diligence on business associates and transactions where the bribery risk assessment identifies more than a low riskLinked records

What it does not cover

  • A record entered and checked by the same person, which satisfies the field but not the control. Segregation of duties is a property of two people, and self-review is the condition under which invented suppliers survive.
  • Approval scope left at the system default, which is almost always unrestricted. An approval granted for one category and recorded as all categories is a widened approval, however it was intended.
  • A bank verification reference copied from an earlier record, which proves an account was once verified, not that this one was.
  • Tax registration captured as free text without validation, which produces a number that looks right and fails at the first cross-border invoice.
  • A supplier left unblocked while setup is in progress, which means the control holds only for as long as nobody raises an urgent payment against a half-built record.

Global

Supplier Master Data Setup requirements by country

Master data is where tax and payment law actually bite, because downstream reporting draws from the standing record. Three regimes reach into these fields directly.

United Kingdom

Criminal Finances Act 2017, Part 3

Corporate offence of failing to prevent the facilitation of tax evasion, with a defence of reasonable prevention procedures.

Tax registration status and payment routing recorded here form part of those procedures. A record that lets an entity be paid without a verified registration weakens the defence, and the evidence relied on is the field-level trail this template holds.

European Union

Council Directive 2006/112/EC (VAT Directive), Articles 214 and 226

Identification of taxable persons and the particulars required on invoices, including a valid VAT identification number.

Tax Registration Recorded is the point at which the number enters every subsequent invoice. An unvalidated number is not merely a data quality problem; it puts the deductibility of input tax in question.

United States

Internal Revenue Code §3406 and Treasury Regulations on Form W-9 solicitation

Backup withholding where a payee has not furnished a correct taxpayer identification number.

A US-facing record created without a validated TIN shifts a withholding obligation onto the payer. Blocked For Payment Until Setup Complete is the practical control that stops a payment run reaching that supplier first.

How to complete it

How to complete a supplier master data setup, step by step

Four judgement calls decide whether this record stands up in a sample. None is about typing accuracy.

Deciding what 'approved scope' actually was

The Approval Scope Restricted To What Was Approved field compares an entered value against a decision made elsewhere. If the approval record is silent on scope, the honest answer is No, not Yes-by-default. Recording Yes against an approval that never stated a boundary manufactures a control that does not exist.

Whether N/A is legitimate or convenient

N/A leaves the denominator, so every N/A raises the score. Spend Limit Applied Where Used is genuinely N/A where the purchasing system holds no limit mechanism; it is not N/A because nobody knows what the limit should be. Otherwise Score Percent becomes a measure of how much you skipped.

Who counts as the second person

Second Person Reviewed The Record and Requester And Enterer Different People ask different questions. The second reviewer should be independent of the requesting function, not simply a second login in master data. Where the same team requests and enters, score the segregation question No and let the record show a known weakness rather than a fabricated strength.

Setting a data review date that means something

Data Review Due is the only forward-looking field and it is usually left at a default twelve months. Set it against the shortest expiring dependency instead: an insurance expiry, a certification expiry or a contract end recorded in Linked records. A review scheduled after the certificate lapses discovers a problem it should have prevented.

What auditors find

Most common supplier master data setup findings

These are what auditors and internal control reviews actually raise against supplier master data, and the field on this template that closes each one.

FindingClauseWhat fixes it
Supplier active for ordering before bank details were independently verifiedISO 9001 cl.8.4.1Make Active For Ordering conditional on Bank Details Independently Verified being Yes and a Bank Verification ID present, so the two cannot diverge.
Duplicate supplier codes for the same legal entity, splitting spend below approval thresholdsISO 9001 cl.8.4.1Require Duplicate Supplier Check Performed to name what was searched — legal name, tax number and bank account — not the code alone.
Payment terms in the system differ from the terms in the signed contractISO 9001 cl.8.4.3Score Payment Terms As Agreed against the contract reference held in Contract Referenced Where One Exists, not against the requester's email.
Approval scope in the system is broader than the scope on the approval recordISO 9001 cl.8.4.2Carry Approval Record ID into the Outcome section and reconcile scope before signing, treating any widening as a new approval.
Amendments to standing data carry no second signatureISO 9001 cl.7.5.3Require Signature and Second Signature for every Setup Type, and refuse submission where Master Data and Procurement resolve to the same user.
Insurance and certification expiries recorded once and never revisitedISO 9001 cl.8.4.1Drive Data Review Due from the earliest recorded expiry so the record re-presents itself before the evidence lapses.

Case in point

Case in point: the supplier that was approved for one thing and buying for another

A manufacturer approved a packaging converter for corrugated cases at a single site. The setup record was created correctly: category recorded, scope restricted, purchase order required, spend limit applied. Eleven months later the converter offered a favourable price on printed film. Procurement raised an amendment by email, master data added the second category, and the record went live the same afternoon with no approval reference and no second signature.

The film was supplied for fourteen months against a technical approval covering corrugated board only. It surfaced during a customer audit that asked to see the approval underlying the film specification and found the approval record predated the category by nearly a year. The remediation was everything downstream: specifications re-issued, a supplier audit brought forward, every purchase order in the period re-evidenced. The control that would have caught it existed on the original record and was simply not applied to the amendment.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

50fields
5 sections
Reference
LOG-044
Archetype
Record
Record ID
SMD-2026-000
Scoring
Set up correctly first time
Direction
High is good
Singleton
Yes
Basis
ISO 9001 cl.7.5
Links
Links Bank Verification, Vendor Register, Onboarding
Tags
Supplier, Master data
Sections
5
Fields
50
Follow up fields
3
Repeating sections
0
Links out
5
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Record ID*

Generated on save

Auto sequence. Format SMD-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Supplier Name*

Text

Supplier Code

Optional
Single Choice

Setup Type*

New supplier, amendment, reactivation, or deactivation.

New supplierAmendmentReactivationDeactivation
Users

Requested By*

Users

Entered By*

Single Choice

Requester And Enterer Different People*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Info

Wrong Terms Bypass Controls For Years

A supplier created with the wrong approval scope, the wrong payment terms or no purchase order requirement quietly sidesteps every control you built, and nobody notices until an audit samples it.

Core data

6 fields
Single Choice

Legal Name Matches Registration*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Trading Address Correct*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Tax Registration Recorded*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Payment Terms As Agreed*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Currency Correct*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Purchase Order Requirement Set*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator

Controls

6 fields
Single Choice

Bank Details Independently Verified*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Approval Scope Restricted To What Was Approved*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Spend Limit Applied Where Used*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Duplicate Supplier Check Performed*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Blocked For Payment Until Setup Complete*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Second Person Reviewed The Record*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator

Linked records

6 fields
Single Choice

Approval Record Referenced*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Due Diligence Referenced*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Insurance Expiry Recorded*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Certification Expiry Recorded*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Contract Referenced Where One Exists*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Category And Risk Tier Recorded*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator

Outcome

19 fields
Single Choice

Setup Complete*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Active For Ordering*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Text

Bank Verification ID

OptionalLinked

Links to LOG-043 Verification ID

Text

Approval Record ID

OptionalLinked

Links to QUA-038 Approval ID

Text

Vendor ID

OptionalLinked

Links to FDN-005 Vendor ID

Date & Time

Data Review Due*

Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Master Data*

Signature

Signature*

Users

Procurement*

Signature

Second Signature*

LOG-044 · record IDs look like SMD-2026-000 · Links Bank Verification, Vendor Register, Onboarding

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

Setup is a five-minute transaction with a multi-year tail. What slips is not the entry but the re-checking, the expiry chasing and the reconciliation of what was approved against what was entered.

KnowLogistics

Holds the setup and amendment history, keeps scope and terms reconciled against the approval on file, and re-presents each record when its data review falls due.

KnowComply

Watches segregation of duties, spend limits, purchase order requirements and tax registration validity, and flags amendments that widened scope without a matching approval reference.

KnowQuality

Links the record to the approval, questionnaire, audit and scorecard evidence, so a scope question is answered from the quality file rather than reconstructed.

Ella
Ella

Coordinates the crew, surfaces records where entry and review resolve to the same person or expiries fall before the next review, and holds every write for your approval.

This template lives in KnowLogistics — supply chain execution. Inbound, outbound, inventory, yard, claims, supplier lifecycle and customs.

Glossary

Supplier Master Data Setup definitions and key terms

Master data
Standing reference data that transactions inherit from. It changes rarely and affects everything downstream when it does.
Segregation of duties
Allocation of request, entry and approval to different people so no individual can complete a payable transaction unobserved.
Purchase order requirement
A flag forcing invoices to match a raised order before payment. Removing it turns a three-way match into a trust exercise.
Approval scope
The categories, sites and ranges the supplier was assessed and approved for. Anything ordered outside it is unapproved supply.
Blocked for payment
A state in which a supplier record exists and can be referenced but cannot be paid, holding new or amended records until verification completes.

FAQ

Frequently asked questions about supplier master data setup

Should a supplier record be created before approval is granted?+

It can be created, but it must be blocked for payment and inactive for ordering. Creating the shell early speeds up onboarding; leaving it transactable removes the point of approval. The Blocked For Payment Until Setup Complete and Active For Ordering fields keep those two states separate.

Does this template replace our ERP change log?+

No. The ERP log records that a field changed and who changed it, not why, what was checked, or who reviewed it. This record holds the judgement and the evidence; the ERP log corroborates the timing.

How should a reactivation be treated?+

As a new setup with the previous history attached. Bank details, tax registration, insurance and certification all move on during dormancy, so every Controls and Linked records field should be re-evidenced rather than carried forward.

What if the supplier is a sole trader with no tax registration?+

Record the position explicitly rather than marking the field N/A. Suppliers below a registration threshold are legitimate; the record should show which threshold applies, because that changes what their invoices may lawfully carry.

Why is the score direction 'high is good' when most risk templates invert it?+

Because the questions ask whether a control was applied, not whether a hazard was present. Every Yes is a control in place, so a rising percentage means a better-built record. Items marked N/A leave the denominator, which is why N/A discipline matters more here than on a hazard form.

Who should hold the second signature?+

Someone with authority over the commercial relationship but no ability to enter master data — typically procurement, as the template assumes. Finance is an acceptable alternative where procurement raised the request, because the requester should never countersign.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 9001:2015 cl.7.5 and cl.8.4 — Documented information; control of externally provided processes, products and services
  • ISO 37001:2016 cl.8.2 — Due diligence on business associates
  • Criminal Finances Act 2017 (UK), Part 3 — Corporate offences of failure to prevent facilitation of tax evasion
  • Council Directive 2006/112/EC, Articles 214 and 226 — VAT identification and invoice particulars

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.