Procurement Anomalies
Vendor Creation Segregation of Duties
Detects users who both created or amended a vendor and processed payments to that vendor.
Why segregation of duties is fundamental
When one user can both create or amend a vendor and process payments to that vendor, the core control of segregation of duties collapses and the door opens to ghost vendors and fraudulent payments, a scenario the COSO framework and the MFMA's internal-control requirements expressly guard against. This single combination of access underlies many of the largest public-sector frauds. AuditPro Core analyses vendor-maintenance and payment activity by user so toxic access combinations are surfaced and broken before they are exploited.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Users Reviewed
412
with SCM access
SoD Breaches
29
▲ 7
Value Under Breach
R 19.4m
exposed
New Vendor + Pay
13
highest risk
Segregation Breaches by Action Pair
Highest-Value SoD Breaches
| User | Vendor | Vendor Action | Paid (R'000) |
|---|---|---|---|
| User 21 | Vendor 612 | Created | 4820 |
| User 47 | Vendor 644 | Bank change | 3110 |
| User 63 | Vendor 671 | Reactivated | 2240 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
The toxic combination
Creating a vendor and paying it are deliberately split between roles so no single person can invent a payee and pay it. Where one user holds both, the fraud control no longer exists.
Ghost and shell vendors
A user with both rights can create a fictitious or shell vendor and route payments to it. Detection depends on linking the maintenance action to the subsequent payment by the same identity.
Amendments count too
Changing a vendor's banking details is as dangerous as creating the vendor, because it redirects legitimate payments. Segregation must cover amendments, not only initial creation.
Compensating controls
Where small entities cannot fully segregate, independent review of vendor changes and payments becomes the compensating control. The risk does not disappear; it must be managed and evidenced.
How AuditPro Core Bridges the Gap
- Access reconciliation: links vendor-creation and amendment events to payments processed by the same user.
- Exception workflow: detected combinations are escalated for access remediation and transaction review.
- Traceability to source: ties each flag to the system audit log of who created, amended and paid.
- Continuous monitoring: watches for the toxic combination as access and transactions change.
Key Takeaways
- Creating a vendor and paying it must never sit with one user.
- The combination is the classic enabler of ghost-vendor fraud.
- Banking-detail amendments are as risky as vendor creation.
- Where full segregation is impossible, evidence a compensating review.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
