Control Intelligence

AI Analysis Results

Vendor Master & OnboardingProcure-to-Pay (Procurement & AP)

Back to Sub-Process
48
/ 100
Needs Improvement
Overall Sub-Process Rating
Needs ImprovementControl is partially in place or inconsistently operated.
1 control evaluated3 strengths identified3 gaps identified
Executive Summary

The Vendor Master & Onboarding process exhibits controls that are partially in place or inconsistently operated. Several gaps in design effectiveness and operating consistency were identified that, if left unaddressed, could elevate residual risk beyond the organization's tolerance. Prompt remediation is recommended.

Strengths
  • New vendors are independently validated before being added... has been partially implemented
  • Exception reporting is generated and reviewed timely
  • Training and awareness programs support control understanding
Gaps
  • Evidence of review lacks timestamp and reviewer identity
  • Monitoring controls are not formally documented or tested
  • Access recertification cadence does not meet policy requirements
Recommendations
  1. 1Implement a workflow tool that captures reviewer identity and timestamp for all approvals
  2. 2Automate exception detection and route alerts to control owners within 24 hours
  3. 3Establish a quarterly monitoring schedule with documented results and sign-off
Framework Mapping
COSO 2013
Principle P12Principle P8
SOX 404
ICFR.P2P.VM.01
IIA Standards 2024
IV.9.4

Control-Level Breakdown (1)

P2P-VM-01Needs ImprovementScore: 43/100
New vendors are independently validated before being added to the vendor master.
Key Finding

The control is partially implemented but operates inconsistently. New vendors are independently validated before being added to the vendor master. Gaps in execution or evidence retention reduce assurance over this area.

Recommendation

Redesign the control to address inconsistencies. Specifically: new vendors are independently validated before being added to the vendor master. Assign a control owner and establish a testing cadence.

Framework Tags
COSO P8COSO P12ICFR.P2P.VM.01IIA IV.9.4