Back to Explore
📑

Procurement Anomalies

Vendor Creation Segregation of Duties

Detects users who both created or amended a vendor and processed payments to that vendor.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why segregation of duties is fundamental

When one user can both create or amend a vendor and process payments to that vendor, the core control of segregation of duties collapses and the door opens to ghost vendors and fraudulent payments, a scenario the COSO framework and the MFMA's internal-control requirements expressly guard against. This single combination of access underlies many of the largest public-sector frauds. AuditPro Core analyses vendor-maintenance and payment activity by user so toxic access combinations are surfaced and broken before they are exploited.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Users Reviewed

412

with SCM access

SoD Breaches

29

▲ 7

Value Under Breach

R 19.4m

exposed

New Vendor + Pay

13

highest risk

Segregation Breaches by Action Pair

Highest-Value SoD Breaches

UserVendorVendor ActionPaid (R'000)
User 21Vendor 612Created4820
User 47Vendor 644Bank change3110
User 63Vendor 671Reactivated2240

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

The toxic combination

Creating a vendor and paying it are deliberately split between roles so no single person can invent a payee and pay it. Where one user holds both, the fraud control no longer exists.

Ghost and shell vendors

A user with both rights can create a fictitious or shell vendor and route payments to it. Detection depends on linking the maintenance action to the subsequent payment by the same identity.

Amendments count too

Changing a vendor's banking details is as dangerous as creating the vendor, because it redirects legitimate payments. Segregation must cover amendments, not only initial creation.

Compensating controls

Where small entities cannot fully segregate, independent review of vendor changes and payments becomes the compensating control. The risk does not disappear; it must be managed and evidenced.

How AuditPro Core Bridges the Gap

  • Access reconciliation: links vendor-creation and amendment events to payments processed by the same user.
  • Exception workflow: detected combinations are escalated for access remediation and transaction review.
  • Traceability to source: ties each flag to the system audit log of who created, amended and paid.
  • Continuous monitoring: watches for the toxic combination as access and transactions change.

Key Takeaways

  • Creating a vendor and paying it must never sit with one user.
  • The combination is the classic enabler of ghost-vendor fraud.
  • Banking-detail amendments are as risky as vendor creation.
  • Where full segregation is impossible, evidence a compensating review.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.