Supplier Onboarding for Singapore SMEs: The Checks That Stop a Wrong Payment
Every wrong payment your business will ever make was authorised by a supplier record someone created in thirty seconds. This guide covers what to collect before a supplier goes live, how to verify it using free Singapore registries, and the one field that needs a process of its own.
Singapore businesses lost $35.3 million to business email compromise scams in 2025. That was a good year — the figure had been $88.5 million in 2024, a fall of 60.1 per cent. Even after that drop, business email compromise remained one of the five costliest scam types in the country by total amount lost, in a year when scam losses overall came to $913.1 million.
The reason it stays near the top with relatively few cases is the size of each one. Nobody loses $200 to business email compromise. They lose an entire month's payment run, because the supplier record said the money should go to that account, and the supplier record was wrong.
We have written about what accounts payable automation does, how to approve supplier payments, and how three-way matching works. All three assume a supplier master you can trust. This guide is about building one. It is the payables mirror of the credit control process we described for customers — do the work before the money moves, not after.
The supplier master is a control, not an address book
Most SMEs treat the supplier list in Xero or their accounting system as contact storage. It is not. Every record in it silently authorises four things:
- That this is a real counterparty. A live entity that can be chased, sued, or reported if something goes wrong.
- That you can claim the GST back. Input tax on their invoices is only recoverable if they are genuinely GST-registered and the invoice meets IRAS requirements.
- Where the money goes. The bank account or PayNow identifier on the record is what your payment file will use, regardless of what any individual invoice says.
- When the money goes. The payment terms on the record decide whether the invoice sits for 30 days or gets paid on Friday.
Someone can create a record that does all four in under a minute, usually while under pressure to get an urgent invoice paid. That is the actual risk. Not sophisticated fraud — an ordinary Tuesday.
What to collect before a supplier goes live
Six things. Not twenty. A long form nobody fills in is worse than a short one everybody does.
| Field | Why it has to be right | Where it comes from |
|---|---|---|
| Legal entity name and UEN | The name on your payment must match the entity that owes you goods. Trading names are not entities | ACRA / the supplier's own invoice |
| GST registration number | Decides whether you can claim input tax at all | IRAS register, not the invoice footer |
| Bank account or PayNow Corporate | This is the field fraud targets. See below | Supplier's letterhead, verified by callback |
| Peppol ID, if they are on InvoiceNow | Lets invoices arrive structured instead of as PDFs | Peppol Directory |
| Payment terms and currency | Stops "urgent, pay today" from becoming the default | Your negotiation, in writing |
| A named contact and a phone number you obtained independently | This is the number you will call to verify changes. It must predate any change request | The contract, or the company's published main line |
Two of those deserve emphasis. The GST number should never be copied from the invoice you are trying to pay — that is the document you are supposed to be checking. And the verification phone number must be captured at onboarding, when nobody is trying to redirect anything, because a number supplied later is worthless.
Three checks, most of them free
Singapore makes supplier verification unusually cheap. Three registries cover almost everything an SME needs.
| Check | What it proves | Cost |
|---|---|---|
| ACRA BizFile search | The entity exists, its UEN, and whether it is live rather than struck off or in liquidation | Free for status; S$5.50 for the full business profile with directors and shareholders |
| IRAS GST Registered Business Search | Whether they are GST-registered, their GST number, and the dates that registration was active | Free, no Singpass or Corppass login needed |
| Peppol Directory | Whether they can receive and send InvoiceNow documents, and their participant ID | Free |
ACRA. The free search settles the basic question — is this a real, live company. Buy the S$5.50 profile when the exposure justifies it: a new supplier you will pay five figures to, a sole distributor you cannot easily replace, or anyone whose story does not quite add up. The profile shows directors and shareholders, which occasionally reveals that your "new" supplier is a company you already had a bad experience with under a different name.
IRAS. The GST register is the check most SMEs skip, and it is the one with a number attached. It confirms not just that a supplier is registered today, but the dates their registration was active — so you can check registration as at the invoice date, which is what actually matters.
Peppol. Search the directory using the 0195:SGUEN scheme followed by their UEN. If they are listed, ask them to send through InvoiceNow rather than email. Structured invoices arrive with the UEN and GST number already in fields, which removes an entire category of data-entry error. Our InvoiceNow setup guide covers getting yourself onto the network.
What the GST check is actually worth
IRAS requires a tax invoice to carry the supplier's name, address and GST registration number, the words "Tax Invoice", the GST rate and amount, and the total payable. Invoices above S$1,000 must be addressed to you. A simplified tax invoice is acceptable up to S$1,000. Suppliers have 30 days from the time of supply to issue one.
Miss a mandatory field, or claim against a supplier who was not registered on the supply date, and the input tax is not recoverable.
Put a number on it. A supplier you spend S$40,000 a year with, at 9 per cent GST, carries S$3,600 of input tax. If that supplier is not registered but has been printing a plausible-looking number on their invoices, you have been claiming S$3,600 a year you were never entitled to — and IRAS can look back further than one year. The GST record-keeping guide covers what has to survive a review; common GST data errors covers what automation catches.
One free search at onboarding. Re-run it annually, because registrations get cancelled.
Bank details need a process of their own
Every other field on the supplier record can be wrong and cost you an afternoon. This one can be wrong and cost you a payment run. Treat it differently.
At onboarding. Take bank details on the supplier's own letterhead or through a portal you control, never from an email body. Then call the contact number you captured independently and read the account number back to them. Record who called, who answered, and when.
After onboarding. Bank details do not change often. When they do, treat it as a new verification, not an edit.
The five rules that matter:
- Never verify a change using contact details supplied in the change request. This is the whole attack. The email, the letterhead, the "new finance contact", and the phone number in the signature can all be controlled by the same person. Call the number you already had.
- The person who requests the change cannot be the person who approves it. Even in a two-person finance function.
- Keep the evidence with the record. Who verified, by what method, when. A change with no evidence attached should be reversible.
- Flag the first payment after a change. Prominently, in the payment batch, so whoever releases it sees that this account is new.
- Never let an invoice update the master. An invoice arriving with bank details that differ from the supplier record is an exception to investigate, not an instruction to follow. If your automation silently updates the master from invoice data, turn that off today.
Urgency is the tell. Genuine suppliers changing banks give notice and do not mind waiting a day. A request that combines a new account, a same-day deadline, and a reason you cannot verify is the pattern, and it does not need to be sophisticated to work — it only needs to arrive when your finance person is busy.
Who is allowed to do what
Supplier creation, invoice approval, and payment release are three different permissions. One person holding all three can pay an invented company and reconcile it themselves.
| Task | Who | Never also |
|---|---|---|
| Create or amend a supplier record | Finance admin | Releases payments |
| Verify bank details | A second person | The requester |
| Approve the invoice | Budget holder for that cost | Creates suppliers |
| Release the payment | Owner or finance lead, in the bank | Created the supplier or amended its bank details |
If you have two people in finance, you cannot split this four ways. Use compensating controls instead: the owner reviews every new supplier created in the last week as a standing five-minute item, the bank requires dual authorisation above a threshold, and bank alerts go to someone outside finance. That is weaker than proper segregation and considerably better than nothing. Our payment approval guide goes deeper on the authority matrix.
Cleaning up a master you inherited
Most SMEs are not starting fresh. They have 400 supplier records accumulated over eight years, and nobody knows which are real.
A first pass takes about ninety minutes:
- Export everything with last-transaction date, bank details, and GST number.
- Deactivate anything with no transaction in 24 months. Do not delete — deactivate, so history survives and the record cannot be used.
- Sort by bank account number and look for duplicates. Two supplier records sharing one account is either a duplicate you should merge or something you want to understand.
- Sort by supplier name and find the near-matches: "ABC Pte Ltd", "ABC Pte. Ltd.", "ABC". Merge them. Duplicate records are how the same invoice gets paid twice.
- List every record with no UEN. Those are the ones nobody verified. Fix them or deactivate them.
- Re-run the GST check on your top 20 suppliers by spend. That is where the recoverable money is.
Then set the rule that stops it recurring: no new supplier record without a UEN, and no payment to a record created in the last seven days without a second pair of eyes.
What to automate
Automation helps most at the edges of this process — the intake and the checking — and least in the middle, where a human judgement about whether to trust someone belongs.
Worth automating:
- A supplier intake form that validates the UEN format, requires the six fields, and creates a pending record that finance must approve before it can be paid.
- A GST register check at onboarding and on an annual cycle, flagging any supplier whose registration has lapsed.
- A bank-detail change alert that notifies a second person the moment the field is touched, with the old and new values in the message.
- A duplicate check on UEN and bank account at the point of creation, before the record is saved.
- A new-supplier flag on the payment batch for any record created or amended in the last 30 days.
- Structured invoice intake through InvoiceNow, so UEN and GST number arrive as fields rather than as text your team retypes.
Not worth automating:
- The verification callback. A person calls a person. If a bot could do it, so could the fraudster.
- The decision to trust a new supplier. Automate the evidence gathering, not the judgement.
The finance automation pillar covers where supplier onboarding sits relative to the rest of the stack.
Where this usually goes wrong
The urgent-invoice exception. A record gets created outside the process because the payment is urgent. Urgency is the condition under which fraud works, so it should trigger more scrutiny, not less. Make the exception path slower, not absent.
Trusting the invoice footer. The GST number on the invoice is a claim by the supplier. The IRAS register is a fact. They are not the same thing and only one is free to check.
Verifying once and never again. Companies get struck off. GST registrations get cancelled. Bank accounts change. An annual re-check of your top suppliers by spend catches almost all of it.
Letting sales onboard suppliers. Whoever wants the goods should not be the one who creates the record that pays for them.
No record of who verified. If you cannot show that someone checked, you cannot show the control exists — to your auditor, your insurer, or yourself after something goes wrong. Keep the evidence for as long as you keep the related invoices; the document retention guide has the timelines.
What good looks like
Six months in, you should be able to answer yes to all of these:
- Every active supplier record has a UEN
- Every GST-registered supplier was checked against the IRAS register, with a date
- No supplier record can be created and paid by the same person
- Bank details were verified by a callback to an independently obtained number, and the verification is recorded
- Any bank-detail change in the last 12 months has a second approver named against it
- Suppliers with no activity in 24 months are deactivated
- The payment batch visibly flags suppliers created or amended in the last 30 days
- Someone re-runs the top-20 checks annually and it is on a calendar
None of that requires new software. It requires deciding that the supplier master is a control and treating it like one.
The bottom line
Business email compromise works because the supplier record is the least-defended object in most finance functions and the most powerful. It sits between an invoice and a bank transfer, and almost nobody audits it.
The fix is unglamorous: six fields, three free registry checks, one phone call to a number you wrote down before anyone asked you to change anything, and a rule that the person who creates a supplier never releases its payments. That is a morning's work to set up and a few minutes per supplier thereafter.
The alternative is finding out how good your controls were on the day someone tests them.