01Define scope and preserve source records
Identify each enterprise resource planning, procurement, accounts payable, marketplace, warehouse and payment system included, plus legal entities, business units and regions. Export record ID, status, created and changed dates, creator, legal and trade names, address, registration and tax fields, website or domain, contact, currency, purchasing organization, payment method and masked bank comparison attributes where authorized. Include blocked, dormant, one-time and recently merged records so duplicates are not hidden outside the active population. Record extraction time and source. Restrict sensitive data and tokenize bank fields for matching when possible. Do not alter the master during candidate generation. Keep original spelling, scripts and identifiers alongside normalized comparison values. Separate missing data from unequal data; two blank tax IDs are not a match.
02Generate candidates with explainable rules
Start with strong exact keys such as authoritative registration number or verified tax identifier within the relevant jurisdiction and entity type, then use layered name, address, domain, phone and beneficiary similarities. Normalize case, punctuation, common company suffixes, whitespace and approved transliteration without deleting meaningful legal words. Detect swapped address lines, former names, branch names, parent-company contacts and shared service centers. Compare creation timing and onboarding source. Use multiple signals and disclose why each pair was selected. A model score may prioritize review but should not merge records automatically. Test false positives using known separate subsidiaries and false negatives using known aliases. Track candidate rule version, threshold and reviewer outcome. Prevent an exact bank token from becoming public evidence; legitimate supplier groups may share treasury arrangements, while fraud can mimic a familiar name.
03Verify entity and business relationship
Confirm the legal person or organization, registration status where applicable, registered and operating addresses, ownership or parent relationship only from authorized evidence, and the contract or onboarding party. GLEIF's Global LEI Index can support identity and relationship research for entities that have an LEI, but absence of an LEI does not invalidate a supplier. Determine whether records represent separate legal entities, branches, remit-to sites, factories, agents, distributors, one-time payees or the same organization. Check supplier communications through trusted contact details. Validate tax and regulatory fields with qualified owners. Keep brand, factory and payee identities distinct. Record evidence date and limitations. Do not treat a website, email domain, marketplace page or bank account alone as legal-entity proof. Escalate conflicting registration, contact or beneficiary information before transaction migration.
04Map transactional and control dependencies
For every candidate ID, list open and historical purchase orders, acknowledgements, receipts, returns, invoices, credit notes, payments, refunds, deposits, rebates, disputes, contracts, price lists, product records, bank approvals, portal users and integrations. Identify which objects can be reassigned, which must retain the original supplier ID and which need a cross-reference. Check duplicate invoices and payments across the candidate pair before combining histories. Review segregation of duties, approval thresholds, tax reporting, currency, withholding, sanctions or other required controls with qualified owners. A record with no open balance may still support warranties, traceability, claims or historical audit. Freeze risky new activity when authorized, but do not cancel valid obligations simply because the identity review is open.
05Decide survivor, separation or remediation
Classify as confirmed duplicate, valid separate entity, valid separate site or payment arrangement, legacy record, suspicious or unresolved. For a duplicate, select the survivor from verified identity, completeness, active contracts, system reach and control history—not the lowest number by habit. Document field-level source of truth and prohibit automatic overwrite of bank, tax, currency or payment terms. For valid separation, add controlled relationship and differentiating labels without exposing sensitive data. For suspicious creation, involve security, finance and legal owners and preserve evidence; do not accuse individuals from similarity alone. Approve block, merge, cross-reference or correction through named authority. Prepare rollback or compensating steps before bulk migration. NIST control guidance supports separated duties, least privilege, audit records and controlled configuration changes.
06Execute the change with traceability
Stop new transactions on the retiring record at an agreed point, complete or remap open workflows deliberately and update integrations, portal access and reporting. Preserve the retired supplier ID, reason, effective time, approvers, survivor link and field history. Do not physically delete records required for financial, tax, quality, warranty or audit history. Revalidate beneficiary information through the normal bank-change control rather than copying it from the survivor. Test purchase order creation, receipt, invoice match, credit, payment proposal, withholding, currency, statement reconciliation and historical search. Confirm that open documents do not duplicate or disappear and that reporting can bridge old and new IDs. Communicate changed reference rules to authorized users and the supplier where appropriate.
07Monitor recreation and control quality
Search new and reactivated supplier records against retired aliases and authoritative identifiers. Alert on invoices, payment proposals, bank changes or purchase orders using a retired ID. Review candidate volume, confirmed-duplicate rate, false-positive rate, time to resolution, records created outside onboarding and duplicate payments spanning aliases. Sample decisions in both directions: confirmed duplicates back to evidence and separately retained look-alikes for correct distinction. Analyze causes such as decentralized onboarding, missing identifiers, rushed one-time setup, acquisition, transliteration, interface mapping or unauthorized creation. Improve required fields and matching rules without making entry impossible for legitimate suppliers lacking a particular identifier. Retain an exception route and periodically retest known duplicate and separate-entity cases.