
Supplier onboarding has received twenty years of process attention. Supplier offboarding has received almost none. Most mid-market vendor masters carry 15 to 30 per cent of records that are dormant, where no invoice has been processed in the prior twelve months. These records sit alongside active ones, available to receive payment, accept bank-detail changes and pass standard checks. Dormant supplier records are quiet fraud surface, and an offboarding policy is the control that addresses them.
The three offboarding modes
Suppliers leave a buyer's vendor master for three structurally different reasons. The mode matters because the offboarding control should match it.
End of contract. The supplier relationship has run its commercial course. Both sides agree to part. The data hygiene work is the dominant requirement. The fraud risk is low if the offboarding is timely. This is the mirror image of the work in supplier onboarding is broken, and most teams under-invest in it for the same reasons.
Supplier failure. The supplier ceases trading, enters administration, or otherwise becomes operationally incapable of fulfilling the relationship. The control requirement is around outstanding obligations, beneficial-owner clarity and avoidance of payment to the wrong successor entity.
Suspected fraud. The supplier has been flagged for behavioural anomaly, identity inconsistency or direct fraud evidence. The offboarding requirement is to remove the record from the master in a way that preserves the audit trail and signals to other buyers where appropriate.
Most offboarding policies do not distinguish between the three. The same lightweight process applies in each case. The fraud and supplier failure cases require more.
The data hygiene problem
A dormant supplier record is a fraud surface for three reasons.
Identity decay. The supplier's beneficial ownership, registered office and trading status can all change without the buyer noticing. The record looks the same. The underlying entity has moved. This is the same drift that the supplier identity graph is designed to keep current.
Bank-detail vulnerability. A dormant supplier whose bank details have not been verified for years presents an easy target. An attacker can submit a bank-detail change request against the dormant record with low likelihood of internal challenge. The next invoice routes to the new account. This is the same attack class set out in why AP fraud will explode in the AI era.
Verification gap. Standard sample audits prioritise active suppliers. Dormant suppliers are usually excluded from the sample by design. The dormant record therefore receives less scrutiny precisely where it needs more.
The pattern is well-documented in case studies. The dominant fraud cases that hit dormant suppliers involve attackers who identify a record that has not been touched recently, submit a bank-detail change with low-friction supporting documentation, and extract one or two payments before any internal trigger fires.
What good looks like
Three offboarding states should be available, not one.
Archival. The supplier record is preserved with full history but marked as dormant. Payments cannot be processed against it without explicit reactivation. Bank-detail changes are blocked. The record remains available for audit, reporting and historical reference.
Deactivation. The record is preserved but actively disabled. Reactivation requires the same controls as onboarding a new supplier. This is the right state for end-of-contract suppliers who may return.
Purge. The record is removed, with appropriate retention of historical data for statutory and audit purposes. This is appropriate for suspected fraud cases and for suppliers where the entity has irreversibly ceased to exist.
The choice between the three should be driven by the offboarding mode, not by which one is easiest to execute.
The network layer: offboarding as a signal
A supplier offboarded for suspected fraud on one buyer's instance is a signal to other buyers of the same supplier. The network layer can carry that signal across the contributor base in defined ways. Pairing this with the broader pattern in the sub-£10k invoice problem makes the case for cross-buyer signals.
Where the offboarding is end-of-contract or amicable, no signal is appropriate. The network treats the offboarding as a routine commercial event.
Where the offboarding is supplier failure, the signal is informational. Other buyers should know the supplier is operationally compromised, but the signal does not imply fraud.
Where the offboarding is suspected fraud, the signal carries weight. Other buyers should review the supplier on their own instance, with the option to take their own action. The signal is not an automatic block; it is a high-confidence reason to look.
The signal pattern requires governance. Contributors should know what is shared, when, and on what evidence threshold. The framework sits inside the cooperative data model rather than as a one-off product feature.
A pragmatic offboarding policy template
Three components cover most mid-market requirements.
An annual sweep. Every supplier with no invoice activity in the prior twelve months is reviewed for state. The sweep produces three outputs per supplier: archive, deactivate, purge.
An event-driven trigger. Bank-detail changes on dormant suppliers, supplier-initiated reactivation requests, and beneficial-owner changes on dormant suppliers all trigger immediate review.
A fraud-mode protocol. Suppliers offboarded for suspected fraud trigger network-level signal sharing where the cooperative governance allows, with documented evidence preserved for contestation.
None of these is operationally heavy. Together, they close the dormant-supplier fraud surface that most mid-market vendor masters carry by default.
.jpg)
