Supplier Data Audit: 8 Checks You Can Run in an Afternoon


Most procurement teams have a rough sense that their supplier data isn't quite right. What's harder is knowing how wrong it is, which parts matter, and where to start.
A supplier data audit answers those questions. It's a structured review of your supplier records that finds the duplicates, missing company numbers, expired documents and unverified bank details sitting in your list right now.
Most teams can run a useful one in two to three hours with nothing more than a spreadsheet export.
The 8 checks at a glance
These are the checks we run at the start of every implementation, ordered so the quickest wins come first:
Count your active and dormant suppliers
Find duplicate supplier records
Check for company registration numbers
Confirm every supplier has a named owner
Time how long it takes to find a certificate
Review bank detail verification and change history
Work out which suppliers are critical
Locate contracts, renewal dates and notice periods
What do you need before you start?
You need an export of your supplier list and a spreadsheet. That's it!
Your finance system is usually the best source, because it holds everyone you've actually paid. Ask for every field available, even the ones that look irrelevant. Empty columns tell you as much as full ones. Save a working copy and leave the original untouched.
Then write down one number before you look at anything: how many active suppliers you think you have. Keep it visible. It's common for the real figure to be double the guess, and that gap alone is often enough to get a manager's attention.
1. How many suppliers do you actually have?
Count the rows, then count how many suppliers have been paid in the last twelve months. The difference is your dormant supplier list.
Dormant suppliers are records still marked active, still available for someone to raise a purchase order against, and still carrying whatever risk they carried when you last used them. Dormant suppliers aren't the end of the world, but they are clutter, and clutter makes every other check slower.
What good looks like: most active supplier records show activity within the last year.
2. How do you find duplicate supplier records?
Sort your list alphabetically by supplier name and read it. This sounds crude and it works better than anything clever.
Look for:
The same company entered as Ltd and Limited
Trading names sitting separately from legal entity names
Spelling variants, extra spaces, and "The" at the front of a name
The same organisation set up once per site or per department
Then sort by postcode, and by bank account number if you hold it. Two different names sharing a bank account are almost always the same supplier.
Duplicates matter because they quietly break everything downstream. Spend looks smaller than it is, so a strategic supplier can sit below the threshold where anyone reviews them. Compliance checks get completed against one record and not the other.
What good looks like: you can explain every near-match on the list.
3. Why do company registration numbers matter so much?
A company registration number is the key that lets you verify a supplier externally. Without one, you can't reliably check filed accounts, credit scores, directors, or whether the company still exists.
Count how many of your records hold one. This check takes two minutes and is usually the most revealing on the list.
Supplier names alone aren't dependable. Plenty of businesses share a name, and plenty trade under something different from their registered entity. If this field is mostly empty, you've found the thing to fix first, because everything else you might want to do with supplier data depends on it.
What good looks like: every limited company on your list has a company number recorded.
4. Does every supplier have a named owner?
Look for a named internal owner against each record, a person, rather than a department.
If the field doesn't exist, that's your answer. If it does, check how many are populated, and how many name someone who still works there.
Ownership turns a supplier record into a relationship somebody is accountable for.
Without it, the answer to "who knows what's going on with this supplier?" becomes a group email, and the follow-up questions land wherever people guess they should.
What good looks like: every supplier above your criticality threshold has a named, current owner.
5. How long does it take to find a supplier's insurance certificate?
Pick ten suppliers at random from your most important category. For each one, find their current insurance certificate and its expiry date. Time yourself.
The point of this check is the clock rather than the documents. If it takes ten minutes per supplier, answering a simple assurance question across your whole list is weeks of work, which means in practice it doesn't happen.
Then ask a second question: is the expiry date recorded somewhere searchable, or does it live inside a PDF? An expiry date you can't filter on can't warn you about anything.
What good looks like: you can list everything expiring next quarter in under a minute.
6. When were your suppliers' bank details last verified?
Find out two things: when each supplier's bank details were last checked, and who is able to change them.
Payment diversion fraud works precisely because this information is usually undocumented. A convincing email arrives, someone updates the record and afterwards nobody can say what the previous details were, or who approved the change.
If your system doesn't hold a change history for bank details, note it down. It's a small gap with a large worst case.
What good looks like: bank detail changes are logged, dated, and verified by someone other than the requester.
7. Which of your suppliers are critical?
Try to answer this from your data: if this supplier stopped trading tomorrow, how badly would it hurt?
Most lists can't answer it, because criticality usually isn't recorded. Spend gets used as a proxy, and spend is a poor one. Plenty of low-value suppliers are impossible to replace quickly, and plenty of high-value ones have three alternatives a phone call away.
You don't need a sophisticated model. Three tiers is enough to change how you spend your time.
What good looks like: you can produce your list of critical suppliers without holding a meeting.
8. Can you find the contract, the renewal date and the notice period?
Take the same ten suppliers from check five and try to locate all three for each.
Renewal dates are the ones worth noting. A contract that renews automatically while nobody's watching removes your ability to negotiate, and it does it silently.
What good looks like: renewal and notice dates sit in a field you can sort by.
What should you do with the results?
You'll finish with a list of gaps, and it will probably look bigger than you hoped. That's normal, and none of it appeared overnight or through anyone's carelessness. Supplier data degrades in every organisation that grows.
Three things help:
1. Fix the keys first.
Company numbers and deduplication unlock most of the other work. Do those before anything else, because everything you fix afterwards stays fixed.
2. Scope by tier.
Bringing every supplier up to a high standard isn't realistic. Bringing your critical suppliers up to it is, and it addresses most of the actual risk.
3. Show the numbers to someone.
The gap between the supplier count people assume and the one you found is the most persuasive thing in your audit. It makes an abstract problem specific, and specific problems get resourced.
An afternoon is a small investment for knowing exactly where you stand. Most teams find the picture is better than they feared in some places and worse in others, and either way it's a far more comfortable position than not knowing.
Frequently asked questions about supplier data audits
How often should you audit supplier data? A full audit once a year works for most organisations, with a lighter review of critical suppliers each quarter. If you've recently changed finance system, merged with another business, or grown quickly, do one sooner.
Who should run a supplier data audit? One person from procurement can complete the checks above. You'll need someone in finance to produce the supplier export, and you'll want a sponsor to take the findings to.
How long does a supplier data audit take? Two to three hours for the checks in this guide. A deeper audit covering every supplier record and document takes longer, which is why tiering your suppliers first is worth the effort.
What's the difference between supplier data cleansing and a supplier data audit? An audit tells you what's wrong and how much of it there is. Cleansing is the work of fixing it. Auditing first stops you spending effort on records you should be archiving.
Can you audit supplier data in a spreadsheet? Yes. Every check in this guide works with a spreadsheet export. Keeping the data accurate afterwards is where spreadsheets struggle, because nothing prompts you when a certificate expires or a supplier's details change.
How Canopy can help
The audit tells you where you stand today. Staying there is the harder part, because supplier data starts drifting again the moment you finish.
That's the job Canopy does. It holds supplier records, documents, company data and expiry dates in one place and keeps them current, so the checks in this guide run quietly in the background instead of once a year. The afternoon of spreadsheet work becomes a dashboard that already has the answers.
Book a demo if you'd like to walk through your findings with us, or sign up free to have a look around first.



