Skip to content
automatizacion

Automating supplier onboarding and control

Onboarding a supplier looks like an administrative formality and is in fact a risk control. It is the moment an organisation decides who it is going to pay, and with what data. Automating it well shortens the formality and strengthens the control at the same time.

What follows: why onboarding drags, what automates well, what still requires judgement, and how the supplier master is kept current.

Almost every organisation has a supplier onboarding process. Very few have one that is fast and rigorous at once, because it is usually framed as a trade-off: either you control, or you move.

That dilemma is false. The slowness rarely comes from the control itself; it comes from the control being executed by hand, sequentially, with nobody able to say where the request currently sits.

Why onboarding drags

The first cause is document collection. The supplier sends what it believes was asked for, someone reviews, something is missing, it is requested again. That back-and-forth consumes most of the total time.

The second is verification. Checking legal existence, tax standing, bank details and background requires consulting several different sources, and doing it manually is slow and uneven: it depends on who does it.

The third is that nobody owns the process. Procurement waits for finance, finance waits for legal, and the request moves only when the supplier chases it.

What automates well

Structured capture. A form that validates as it goes — tax identification format, mandatory fields by supplier type, documents required by category — removes most of the back-and-forth, because it will not accept something incomplete.

Document validation. Checking that a document is current, belongs to the declared entity and is not about to expire is a rules-based check. Intelligent document processing extracts the data and the rules test it.

Approval routing. Which reviews a supplier requires depends on its category, its expected spend and its risk. That is a deterministic decision and therefore automatable, with escalation when something stalls.

Periodic review. The part almost always skipped. A supplier approved three years ago may hold expired documents or have changed standing. Recalculating validity and warning before expiry is repetitive, calendar-driven work — an ideal candidate.

What requires judgement

Deciding to accept a supplier with an open finding is a business call, not a system one. Automation can classify the finding and present it with context; approving in spite of it is a decision with an owner.

So is the definition of risk categories. What makes a supplier critical — access to data, criticality of the service, concentration — depends on the business and its tolerance, and is worth revisiting periodically.

And the handling of the legitimate exception. A sole supplier in its market, or a genuine operational urgency, calls for a different path that should exist inside the process and be recorded — not resolved outside it with a phone call.

What changes by country

The data identifying a supplier and its tax standing belong to each jurisdiction. In Colombia the relationship with the DIAN defines part of the information required; in Mexico invoicing is organised around the CFDI, with its own data structure.

An organisation operating in several countries needs a supplier master able to live with those differences without duplicating records of the same entity. Solving it late produces the classic problem: the same supplier onboarded three times with different data.

And if the supplier will process personal data, the obligations of Habeas Data (Ley 1581) in Colombia and of the LFPDPPP in Mexico extend to that relationship — worth verifying at onboarding rather than when an incident occurs.

How the supplier master is kept current

A supplier master degrades on its own. Legal representatives, bank accounts, addresses and tax standing change, and if nothing forces an update, quality falls month by month.

The mechanism that works is having the supplier maintain its own data, through a portal where it updates and attaches, with the organisation validating the change rather than capturing it.

A change of bank details deserves separate handling and reinforced control: it is the usual target of supplier impersonation fraud, and automating it without out-of-band verification is precisely what not to do.

What has to exist first

A written definition of which documents each supplier category requires, with an owner. A cleaned master, because automating on top of duplicates multiplies them. And an agreement between procurement, finance and legal about who decides what — the conversation the project usually uncovers.

With those, onboarding moves from days to a predictable formality. Without them, what gets automated is the waiting.

Can onboarding be automated without losing control?

Yes, and it normally strengthens it. Control weakens when it depends on each person reviewing alike; it strengthens when the rule is always applied and always recorded.

Which part delivers a result fastest?

Structured capture with validation as it goes. It removes the back-and-forth over incomplete documents, which is where most of the time goes.

How is bank-account change fraud avoided?

By treating that change as a special case: verification through a channel other than the one that originated the request, approval by a second owner, and a record of the verified contact. It is the point where optimising for speed is the wrong instinct.

How often should an active supplier be reviewed?

According to its risk category, with validity dates calculated by the system rather than by a general calendar. What matters is not the nominal frequency but that expiry warns before it happens.

Andrés Lozada
Andrés Lozada
LinkedIn

Explore more from SUMāTO

Enterprise AI Enterprise Transformation Strategic Consulting AI Agent AI Contact Center Cybersecurity