Research · Published:
September 11 study: Vendor name aliases and the limits of automated matching
Research on legal names, trading names, payment descriptors, tax identifiers, master records, and uncertain supplier matches.
Methodology
Research question and scope: what evidence lets a reviewer connect an observed supplier name to a vendor record without merging distinct organizations. The scope is a declared accounts payable population and period. This report applies public control guidance to workflow design. It does not provide legal, tax, accounting, cybersecurity, or fraud assurance.
Evidence and scope
Evidence population: invoice headers, approved master records, legal and trading names, entity and address data, taxpayer information where authorized, bank descriptors, contracts, change history, match proposals, reviews, and rejected matches. Before sampling, record the entity, systems, cutoff, inclusion rules, exclusions, unavailable records, and source hierarchy. Keep system facts, document contents, operator notes, supplier claims, reviewer judgments, and management decisions distinct.
Key Stats
Methodology: build candidates from observed names; compare only approved fields; stratify exact, normalized, corroborated, conflicting, and unresolved matches; have a second reviewer replay every proposed merge or alias. Preserve the original chronology and have a second reviewer reproduce each classification from the same evidence. Counts and rates describe only the declared population.
Research-to-practice
Inference boundaries: name similarity alone does not establish legal identity, common ownership, tax status, bank ownership, or authority to change a vendor master. The GAO Green Book supplies a framework for responsibility, documentation, quality information, and monitoring. NIST SP 800-53 supplies relevant access and audit concepts. The remaining sources narrow the operating question but do not decide a case.
Implementation
Limitations: names vary by language and system; corporate events and shared addresses create ambiguity; taxpayer data may be restricted; rejected candidates may be under-recorded. Report absent evidence as missing or excluded rather than converting it into a positive or negative finding. Do not generalize results outside the tested policies, workflow, systems, access model, entities, and period.
Key Takeaways
Conclusion: an alias register is defensible when it retains the observed value, approved master identity, corroborating sources, conflicts, reviewer, effective dates, and revocation path. Management retains policy, access, materiality, accounting treatment, vendor-master approval, payment release, remediation, and the decision to retest.
Turn the study into a bounded AP routine
Name the population, approved sources, preparer access, reviewer, exception owner, retention rule, and retest trigger before assigning the work.
Discuss an AP support scopeSources
These primary sources support the control principles and evidence boundaries in this report.
FAQs
Are the planning numbers benchmarks?
No. They describe a testable workflow shape and are not promises, market averages, or production targets.
What should an outsourced AP assistant own?
Repeatable preparation, documentation, status tracking, and follow-up within least-privilege access. Named finance owners retain approval and payment decisions.
When should an item be escalated?
When evidence is missing, a request changes payment details, a duplicate or fraud signal appears, or the item falls outside the written rule.