C
The Procurement Codex
The lifecycle, as a system · Free & open
⚞️

Fully autonomous project. The Procurement Codex is built, verified, and published end-to-end without manual authoring. Its core logic — the spine, the layer model, and the platform comparison rubric — is rebuilt and improved on every iteration for continuous method validation. Content is generated programmatically and refined each cycle: treat it as a directional learning aid, verify against primary sources, and send corrections — accuracy and fairness compound with each pass.

Episode 07 · Making the supplier real

Supplier Onboarding & Master Data

A signed contract is worthless until the supplier can actually be transacted with and paid. Onboarding is the disciplined intake of a supplier — registration, documents, bank and tax details, compliance and risk checks — turned into a clean, validated, governed record. Master data is what keeps that record a single golden truth across every system that touches it.

Below: the plain concept → how every platform registers, validates and governs supplier data (fair A vs B vs C) → then we stack process mining, AI validation & enrichment, orchestration and stewardship on top until you see why standalone is never enough.

L0 · The Concept

What it is

The path from "we chose this supplier" to "this supplier is live and payable": register → collect documents → validate bank / tax / identity → screen risk & compliance → approve → create golden record → sync to every system. Master data governs that record for its whole life, not just day one.

Why it exists

Because bad supplier data is where money and control quietly leak: duplicate vendors, wrong or fraudulent bank details, unscreened sanctioned parties, and records nobody owns. Onboarding is also the number-one target for payment fraud — a single unverified bank change can cost millions.

What good looks like

Self-service supplier portal · validated bank & tax IDs · sanctions / AML screening · duplicate detection · one golden supplier record · segmentation by risk & spend · segregation of duties on bank changes · synced cleanly to ERP, P2P, CLM and risk systems.

L1 · Platform-Native — A vs B vs C

Same rubric for every vendor, 1–5. We state explicitly what each is best and worst at. Toggle platforms to compare.

Platform Best at Watch-out

Scores are directional teaching aids based on typical deployments, not vendor benchmarks. Your mileage varies by configuration, module licensing, data quality, and integration maturity.

L2 · Best Practice

Design principles
  • Let the supplier do the data entry — a self-service portal where the supplier submits and maintains their own details beats re-keying from email, and puts accountability where the data lives.
  • Validate before you trust — verify bank accounts, tax IDs and identity against authoritative sources, and screen for sanctions / PEP before a record can be paid.
  • One golden record, deduplicated — fuzzy-match against the existing master so you never create the same vendor twice; a duplicate is a control gap and a reporting lie.
  • Segment on entry — risk- and spend-tier the supplier at onboarding so due diligence is proportionate: light-touch for a one-off, deep for a critical strategic vendor.
  • Segregation of duties on bank details — the person who requests a bank change must never be the one who approves it; this single control stops most payment-diversion fraud.
KPIs & failure modes
  • KPIs — onboarding cycle time, first-time-right data rate, duplicate-vendor rate, % suppliers self-service, % bank details validated, sanctions-screening coverage, records with a named steward.
  • Payment fraud — an unverified bank-change email diverts a real supplier's payment to a fraudster; the classic, expensive onboarding failure.
  • Duplicate vendors — the same supplier exists three times with different spellings, so spend is fragmented and controls are bypassed.
  • Onboarding drag — a supplier waits weeks to be set up, delaying the work and pushing the business to buy off-contract in the meantime.
  • Stale master data — addresses, contacts and certificates expire and nobody updates them, so payments bounce and compliance lapses.
  • Ownerless records — no data steward, so no one is accountable when a record is wrong, and errors compound downstream in every transaction.

The Layer Peeler — watch standalone become a system

Stack layers onto a plain supplier setup and watch the architecture — and the outcome metrics — change. This is the whole thesis of the Codex in one control.

Outcome at this stack level
Onboarding cycle time
First-time-right data
Duplicate vendors
Payment-fraud risk

L7 · The Synergy Composite

A real best-of-breed supplier onboarding & master-data architecture — no single vendor owns all of it. The value lives in the seams.

flowchart LR
CONTRACT[Signed supplier plus terms
from Ep06] --> REG[L1 Self-service registration
Ariba SLP / Coupa SM / Ivalua 360] REG --> VALID[L4 Validate and enrich
bank, tax, sanctions · D and B / Apex] VALID --> MDM[L1 and L4 Supplier golden record
HICX / SAP MDG-S] PM[L3 Process mining
Celonis / PM4Py] -.cycle lag and duplicates.-> MDM MDM --> SYNC{L5 Sync to ERP vendor master, P2P, CLM, risk} SYNC --> BUY[Ep08 · Requisitioning and Guided Buying] GOV[L6 Data steward and SoD governance] -.approval and dedup.-> MDM

Standalone, a supplier-management module captures a registration form and creates a vendor record — but on its own it does not verify that a bank account is real, it does not fuzzy-match against 40,000 existing vendors to stop a duplicate, and it does not keep the golden record in sync across a heterogeneous ERP estate. External validation and enrichment (Dun & Bradstreet, Apex Analytix) prove identity, tax and bank details and screen sanctions; a supplier MDM layer (HICX, SAP MDG-S) governs the golden record and dedupes; process mining exposes onboarding drag and rework; orchestration syncs the clean record into P2P, CLM and risk. No one tool registers, validates, dedupes, governs and syncs — the leverage is in wiring them together.

The Stack Builder — compose your own

Pick one from each column. The Codex assembles the composite and calls out where the seams need engineering. Shown here for onboarding & master data; the same engine powers every episode.

Cheat Sheet — Supplier Onboarding & Master Data

The 5-second definition

Turn a chosen supplier into a clean, validated, governed golden record that is compliant, payable and synced across every system.

KPIs that matter

Onboarding cycle time · first-time-right data · duplicate-vendor rate · % self-service · % bank details validated · sanctions coverage · records with a steward.

Scorecard in one line

Supplier self-serves data · validate before you trust · one deduplicated golden record · segment on entry · segregation of duties on bank changes.

Platforms in one line

Ariba SLP / Ivalua 360 / Coupa SM on suite-native onboarding · HICX on vendor-neutral MDM · SAP MDG-S on SAP golden record · Apex / D&B on validation.

The layers

L3 mining finds onboarding drag & rework · L4 validates bank/tax, screens sanctions & dedupes · L5 syncs the golden record to ERP/P2P · L6 stewardship & SoD.

The thesis

No single tool registers, validates, dedupes, governs and syncs supplier data. Value is in the seams.

Scenario Check

Question /