Research · Published:
Supplier-master duplicate detection as an evidence review
Research on identity fields, false positives, payment history, access boundaries, and authorized record decisions.
Methodology
This review asks what evidence supports review of possible duplicate supplier records without automating a merge decision. It applies public control guidance to a bounded accounts payable workflow; it does not provide legal, tax, accounting, cybersecurity, or fraud assurance and does not establish a universal benchmark.
Evidence and scope
The declared evidence population is supplier IDs, names, identifiers, addresses, contacts, bank-record references, documents, status history, invoices, payments, candidate rules, reviewer notes, and master-data events. Source records, operator observations, supplier statements, system events, reviewer analysis, and management decisions remain separate so their provenance can be inspected.
Key Stats
Method: declare match fields and thresholds, stratify exact and fuzzy candidates, retain nonmatches, blind a second reviewer to the first conclusion, and trace authorized outcomes. Selection rules are fixed before status cleanup. The test includes routine, incomplete, conflicting, corrected, urgent, and stopped cases, and a second reviewer attempts the classification from retained evidence alone.
Research-to-practice
The GAO Green Book frames documentation, quality information, responsibility, and monitoring. NIST SP 800-53 frames least privilege, attributable actions, and review. Additional cited sources narrow the operational question; none determines the outcome of a particular invoice or supplier record.
Implementation
Scope and limitations: shared addresses, trading names, group companies, recycled contacts, incomplete identifiers, localization, and stale records can produce both false positives and false negatives. Results apply only to the named entities, systems, period, sample, access, policy, and records available. Missing evidence remains visible as a finding or a declared exclusion rather than being inferred.
Key Takeaways
The supported conclusion is deliberately limited: candidate detection can organize review, but authorized owners must resolve identity, risk, retention, merge, and disablement decisions. Management still sets policy, materiality, access, retention, escalation, accounting treatment, approval, and payment authority, and should retest after workflow or system changes.
Turn the finding into a bounded AP handoff
Define sources, preparation steps, access, review timing, exception ownership, and decisions retained by employees before work begins.
Discuss an AP support scopeSources
These primary sources support the control principles and evidence boundaries in this report.
FAQs
Are the planning numbers benchmarks?
No. They describe a testable workflow shape and are not promises, market averages, or production targets.
What should an outsourced AP assistant own?
Repeatable preparation, documentation, status tracking, and follow-up within least-privilege access. Named finance owners retain approval and payment decisions.
When should an item be escalated?
When evidence is missing, a request changes payment details, a duplicate or fraud signal appears, or the item falls outside the written rule.