Master Data

The Duplicate Vendor Problem, and How to Actually Fix It

Duplicate supplier records are the most boring data problem in procurement and one of the most expensive. They split your spend, generate invoice exceptions, and quietly widen a fraud window. Here is how to clear them without breaking your ledger.

6 min read
Rows of labelled binder folders holding technical records on a shelf
Photo via Pexels

Open any vendor master that has been running for a decade and you will find the same company several times over. An abbreviation and a full legal name. A trading name and the entity that actually invoices. A record created when someone could not find the existing one and needed to raise an order before lunch.

It is nobody's fault in the ordinary sense. Every duplicate was created by someone solving a real problem under time pressure, using the path of least resistance available to them. That is exactly why exhortation does not fix it and why it comes back after every cleanup that does not change the path.

What duplicates actually cost

The damage is spread across four places, which is part of why it is under-prioritised — no single owner sees the whole bill.

Lost leverage
One supplier appearing as three, each below the threshold that triggers a category review or a contract. You negotiate as a small customer with somebody for whom you are a large one.
Invoice exceptions
The PO cites one record, the invoice arrives against another, matching fails, and someone spends fifteen minutes reconciling two rows that describe the same company.
Payment error
Duplicate payment risk rises sharply when the same invoice can legitimately be entered against two vendor records without tripping a duplicate check keyed on vendor plus invoice number.
Fraud exposure
The control most organisations rely on — noticing an unexpected new supplier — is far weaker when the master is already full of near-identical records. A fraudulent record hides best in a crowd of legitimate near-duplicates.

The last one is the reason this deserves attention beyond tidiness. Everything else costs money; that one has no ceiling.

Finding them

Name matching alone finds the easy cases and misses the ones that matter. "ABC Ltd" and "A.B.C. Limited" are trivially caught by normalising punctuation and legal suffixes. The expensive duplicates look nothing alike — a trading name against a registered entity, or a company that was acquired and renamed.

Match on several signals and score the combination:

  • Normalised name — strip punctuation, legal suffixes, and common word variants before comparing.
  • Bank account details. The strongest single signal available, and the one that catches renamed entities.
  • Tax registration number, where captured. Definitive when present, frequently absent.
  • Registered address, normalised. Catches trading-name cases.
  • Contact email domain. Weaker, but useful for confirming a candidate pair.

Merging without breaking anything

This is where cleanup projects cause damage. A merge is not a data edit; it rewrites the counterparty on historical transactions, and doing it carelessly breaks open orders, aged creditor reports and audit trails.

  1. Choose the survivor deliberately: the record with the current bank details, the live contract and the most recent activity — not the oldest, and not the one with the most transactions.
  2. Deal with open items first. Open POs, unpaid invoices and unapplied credits on a record being retired must be closed or reassigned before the merge, not during it.
  3. Retain the retired record's identifier as an alias on the survivor. Historical documents, statements and supplier correspondence still cite it, and without the alias every one of those becomes an unresolvable query.
  4. Block rather than delete. A blocked record preserves the audit trail; a deleted one leaves orphaned history and an auditor's question.
  5. Merge in waves, highest value first, and reconcile the creditors ledger after each wave rather than at the end.

The alias step is the one most often skipped and the one that generates the most support noise afterwards, because it is invisible until a supplier phones about a payment referencing a number that no longer exists.

Stopping it recurring

A cleanup with no change to the creation path buys eighteen months. The mechanism that generated the duplicates is still in place, and it is not carelessness — it is that finding an existing record is harder than creating a new one.

Three changes, in order of effect:

ChangeWhy it works
Fuzzy search on the creation screen, before the form opensAttacks the actual cause. If the existing record surfaces in two seconds from a partial name, nobody creates a second one.
Mandatory bank details and tax number at creationMakes the strongest duplicate signals available at the only moment checking is cheap.
A named owner for every creation request, with an SLARemoves the reason people work around the process. Requests answered same-day do not get bypassed; requests that sit for a week always do.

The third is the one organisations resist, because it sounds like adding a gatekeeper. In practice it removes one: an unowned request with no committed turnaround is what pushes people to create the record themselves.

The maintenance nobody owns

Beyond duplicates, a supplier master decays continuously. Companies change bank details, are acquired, change trading name, go into administration, or simply stop being used. None of that arrives as a notification.

  • Bank detail changes need verified callback to a known contact — never to a number supplied in the change request itself. This is the single highest-value control in the whole area.
  • Records with no activity for two years should be blocked, not left live. A dormant open record is an unnecessary attack surface.
  • Contact and remittance details should be refreshed on a cycle for active suppliers, because bounced remittance advice is how you find out, and by then a payment has failed.

This is unambiguously routine work: run the match report, investigate candidate pairs, prepare merges for approval, verify bank changes to a known contact, block dormant records, refresh contacts. It requires diligence and a documented procedure rather than institutional knowledge, and it needs doing every week rather than every eighteen months — which is precisely the shape of work that never survives inside a team with operational priorities.

Common questions

Why do duplicate supplier records keep appearing?

Because creating a record is faster than finding one. Every duplicate was made by somebody with a genuine need and a deadline, taking the path of least resistance. That is why a cleanup with no change to the creation path is undone within about eighteen months — the mechanism that generated the duplicates is untouched.

What do duplicate vendors actually cost?

Four things: lost negotiating leverage, because one supplier appears as three and each fragment falls below the threshold that triggers a contract review; invoice exceptions when the PO and invoice cite different records; duplicate payment risk, since duplicate checks keyed on vendor plus invoice number do not fire across two records; and weakened fraud detection, because a fraudulent record is much harder to spot in a master already full of near-identical entries.

How do you find duplicate suppliers reliably?

Not by name alone — the expensive duplicates look nothing alike. Score several signals together: normalised name with punctuation and legal suffixes stripped, bank account details, tax registration number, normalised registered address, and contact email domain. Bank details are the strongest single signal and the one that catches renamed or acquired entities.

What is the safe way to merge two supplier records?

Choose the survivor by current bank details, live contract and recent activity rather than by age or transaction count. Close or reassign open POs, unpaid invoices and unapplied credits before merging. Keep the retired record's identifier as an alias on the survivor, because historical documents still cite it. Block rather than delete, to preserve the audit trail. And merge in waves, reconciling the creditors ledger after each.

How do you stop supplier bank detail fraud?

Verify every bank detail change by callback to a contact you already hold — never to a phone number or email supplied within the change request itself. That single control is the highest-value item in supplier master maintenance, and it only works if the verification step is mandatory and evidenced rather than discretionary.

Want this run for you?

We take on the transactional half of procurement — invoices, purchase orders, supplier data and indirect spend — inside your own systems and under your approval rules. Start with a free spend audit: we measure your volumes, cycle times and exception rates, and the report is yours whether or not you go further.

Book a free spend audit