Vendor risk: beyond the GSTR-2B reconciliation.
Most companies now check that their vendors have filed GST returns. Far fewer check whether those vendors could stop the plant, leak the data or bring a compliance problem through the door. A note on what a vendor risk audit should actually cover.
1. The reconciliation is done. Now what.
Over the last few years GST has taught Indian finance teams a habit that did not exist before: watching their vendors. Input tax credit depends on the supplier filing GSTR-1 and the credit appearing in the recipient's GSTR-2B. A vendor who does not file costs the company money. So companies built reconciliation processes, chased non-filers, and started holding back the GST component of payments until the credit showed up.
That is a good control. It is also a narrow one. It answers one question about a vendor: did they file. It does not answer whether the company could survive without them, whether they hold the company's data, whether they are who they say they are, or whether their conduct could become the company's problem.
Third-party risk is now near the top of most internal audit surveys globally, and for good reason. Companies have outsourced more than they realise, and the failures that hurt most in recent years, from cloud outages to logistics partner collapses to data breaches at vendors, all came through the supply chain rather than through the company's own walls.
2. Four kinds of vendor risk.
It helps to separate the risks, because they call for different tests.
Continuity risk. What happens if this vendor stops supplying tomorrow. A single-source supplier of a critical component, a sole logistics partner, the one firm that maintains the ERP. The question is not whether the vendor is good, but whether there is a second one.
Compliance risk. The vendor's non-compliance becomes the company's liability or loss. GST non-filing is the familiar example. Others include contract labour suppliers who do not deposit provident fund, MSME vendors whose payments exceed the 45-day limit and trigger the disallowance under section 43B(h) of the Income-tax Act, and vendors in regulated sectors operating without licences.
Information risk. The vendor holds or can access company or customer data. Payroll processors, cloud and software providers, call centres, marketing agencies with customer lists. Under the Digital Personal Data Protection Act, 2023 the company remains the data fiduciary and answerable for what its processors do.
Integrity risk. The vendor is not what it appears to be. Related parties routed through a third name, shell vendors created by an employee, vendors with the same bank account as an employee, or vendors whose only "service" is a percentage of another vendor's invoice.
The GSTR-2B match tells you the vendor exists on the GST portal. It does not tell you the vendor exists anywhere else.
3. Segmenting the vendor base.
A company with three thousand vendors cannot review each one in depth, and should not try. The first step in a vendor risk audit is to segment.
Pull the full vendor master and the twelve-month spend. Sort by spend, and separately flag vendors by the four risk types above regardless of spend. A software vendor with Rs 4 lakh of annual billing that hosts the entire customer database is high-risk. A stationery supplier with Rs 40 lakh of billing is not.
The result is usually a short list, perhaps 40 to 80 vendors, that carries most of the risk. Those get the full review. The remainder get the automated tests in the next section.
4. The tests.
Master-data integrity, full population. Duplicate PANs, duplicate bank accounts, bank accounts matching an employee, addresses matching an employee, vendors with no PAN or GSTIN above the thresholds where one is required, vendors created and paid within a few days, vendors created by a user who also approves payments. These run on the entire master, not a sample.
Existence and KYC. For the high-risk list, verify GSTIN status and filing history on the portal, check MCA records for companies and LLPs, confirm the bank account belongs to the vendor through a penny-drop or a bank letter, and check for MSME registration. Udyam status determines the payment timeline that applies.
Contract and terms. Is there a signed contract. Does it cover confidentiality, data protection, audit rights, service levels, exit and transition. For data processors under the DPDP Act, does it contain the obligations the company is required to pass down.
Concentration and continuity. For each critical input, how many approved suppliers exist, and how much of the last year's volume went to the top one. Where a single vendor supplies more than, say, 70 percent of a critical category, ask for the documented alternative and the switching time.
Performance and disputes. Rejection rates, delivery delays, credit notes, and open disputes by vendor. A pattern of credit notes after payment is a flag for both quality problems and manipulation.
Payment behaviour. Advances outstanding for long periods, payments ahead of due date without a discount, payments to MSMEs beyond the statutory period, and payments split to stay under approval limits.
Information security for data-holding vendors. Ask for the vendor's security certification or independent assurance report, confirm where data is hosted, and check that access granted to the vendor's staff is reviewed and revoked when their people leave.
5. Governance: making it stick.
A vendor risk audit produces a long list of findings once. The value comes from making three things permanent.
An owner for vendor risk. Usually procurement or finance, with IT for data-holding vendors. Not the internal auditor.
A gate at onboarding. No vendor is created in the ERP without a completed checklist covering PAN, GSTIN, bank verification, MSME status, contract and a risk classification. The checklist is short. It is also enforced by the system, not by goodwill.
An annual refresh. High-risk vendors reviewed every year. Everyone else re-screened by the automated tests. Results to the audit committee on one page: number of vendors by risk class, exceptions found, exceptions closed.
This article is general in nature and does not constitute professional advice. Readers should seek specific advice before acting on any matter described here.
This website is meant for information purposes only. The contents are made available on a pull basis and are not intended to solicit work or advertise.
Frequently asked
How is this different from a procurement audit?
A procurement audit tests the buying process: requisition, quotation, approval, purchase order, receipt, invoice, payment. A vendor risk audit looks at the counterparties themselves and the company's exposure to them. The two overlap and are often done together, but the vendor risk review asks questions the procurement audit does not, particularly around continuity, data and integrity.
Is any of this legally required?
Parts of it. GST compliance of suppliers directly affects input tax credit. Payment timelines to MSMEs are governed by the MSMED Act, 2006 and section 43B(h) of the Income-tax Act. Related-party transactions with vendors require approval under section 188 of the Companies Act, 2013 and, for listed entities, Regulation 23 of the SEBI LODR Regulations. Data processor obligations arise under the DPDP Act, 2023. The rest is good governance that the audit committee is entitled to expect under its responsibility for risk management and internal controls.
How often should the automated master-data tests run?
Monthly is a sensible default, with new-vendor tests run at the point of creation. The tests are cheap once built, and the exceptions are far easier to resolve when they are a week old rather than a year old.