Corporate Risk Mitigation • Procurement Risk • India • 2026

Vendor & Procurement Fraud Risk in India: Shell Vendors, Kickbacks, Inflated Pricing, Related Parties & Control Framework 2026

A corporate-standard framework for detecting and reducing procurement leakage through vendor due diligence, conflict checks, price analytics, approval controls, three-way matching and targeted investigations.

OnboardingKYC, ownership, bank, GST, PAN and conflict checks
Buying controlsPO, quotation, approval, rate and exception governance
Payment controlsGRN, invoice, bank-change verification and maker-checker
MonitoringDuplicate, related-party and concentration analytics

Procurement fraud rarely begins with an obviously fraudulent invoice. It usually develops through weak vendor onboarding, informal sourcing, repeated exceptions, undisclosed employee relationships, poor price benchmarking, split approvals, weak goods-receipt controls or unauthorised changes to vendor bank details.

A strong vendor-risk programme therefore examines the full transaction chain: who selected the vendor, who approved the price, who confirmed delivery, who changed master data, who approved the invoice, and where the money finally went.

Control principle: no single employee should be able to create a vendor, place the order, confirm receipt and approve payment without independent checks. Segregation of duties is one of the most effective anti-fraud controls.

1. The procurement fraud risk universe

Common schemes include fictitious vendors, employee-controlled vendors, collusive bidding, kickbacks, inflated rates, inferior goods billed at premium specification, duplicate invoices, false deliveries, inflated quantities, unauthorised freight or handling charges, backdated purchase orders, split transactions to avoid approval thresholds, and vendor bank-account substitution.

Related-party risk can be especially sensitive. Section 188 of the Companies Act, 2013 addresses specified related-party transactions and makes governance, approval and disclosure important where the statutory conditions apply.

2. Vendor onboarding due diligence

A corporate-standard onboarding process should capture legal name, constitution, registered address, PAN, GST registration where applicable, bank account, cancelled cheque or bank proof, beneficial ownership information where appropriate, contact persons, business references, conflict declarations and commercial justification for onboarding.

High-risk red flags include:

  • multiple vendors using the same address, phone number or email;
  • vendor bank account matching an employee or another vendor;
  • newly formed entities immediately receiving material business;
  • personal email domains for high-value suppliers without explanation;
  • vendor address matching employee residence or known related parties;
  • repeated vendor changes requested by the same employee;
  • bank details changed shortly before a large payment;
  • inactive GST or corporate status; and
  • vendors with no credible operational footprint for the contracted work.

3. Procurement analytics that reveal leakage

Test Potential issue Follow-up
Same bank account across vendors Common control / shell entities KYC, ownership and bank verification
Invoices just below approval limit PO splitting / threshold avoidance Aggregate by vendor, user and date
Price variance above peer vendors Inflated pricing Benchmark specification, quantity and terms
Repeated emergency purchase Bypass of competition Review urgency evidence and approval history
Duplicate invoice amount/date Duplicate payment Check invoice image, PO and payment reference
Vendor concentration with one buyer Conflict or steering risk Conflict declaration and sourcing rationale

4. Three-way matching: PO, receipt and invoice

One of the strongest controls is matching the purchase order, evidence of actual receipt or service completion, and the vendor invoice before payment. The process should verify quantity, specification, agreed rate, tax, delivery location, service period and approval.

For service vendors, the equivalent evidence may include timesheets, milestone certificates, deliverables, attendance, system logs, project acceptance or manager certification. A signed invoice alone is not proof that value was received.

5. Price and quotation manipulation

Three quotations do not create competition if the quotations are coordinated. Warning signs include identical formatting, sequential quotations, matching spelling errors, common metadata, same contact number, quotations arriving from the same email chain or recurring losing bidders that never win business.

For recurring categories, build a price benchmark by item, region, volume and contract term. Procurement should be able to explain deviations from benchmark, particularly where the same buyer repeatedly uses the same vendor.

6. Vendor-bank change fraud

Changes to vendor bank details should never be accepted solely through an email that appears to come from the vendor. A robust process may require independent callback verification using previously verified contact details, maker-checker approval, supporting bank proof and a cooling-off or heightened review for high-value payments immediately after a bank change.

Maintain an audit trail showing old and new bank data, request source, verification steps, approver and effective date.

7. Employee conflicts and related-party risk

Employees in procurement, finance, operations and vendor-management roles should periodically disclose relevant conflicts. A conflict does not automatically mean fraud, but undisclosed financial or family relationships can undermine sourcing integrity.

Useful checks can include vendor ownership, addresses, directors/partners, employee declarations and historical employment relationships. Any investigation must use lawfully obtained information and avoid speculative accusations based solely on surnames, social proximity or coincidence.

8. Investigation protocol where fraud is suspected

Preserve vendor master history, purchase requisitions, quotations, POs, approval trails, GRNs, invoices, payment files, bank-detail changes, emails and relevant employee communications before interviews begin. Data analytics should identify the transaction universe and exception pattern.

Interview neutral process owners first, then buyers/approvers and finally implicated personnel after the documentary record is understood. See Internal Investigation of Employee Misconduct in India.

9. Vendor risk-scoring matrix

Dimension Low risk High risk
Ownership transparency Clear and independently verifiable Opaque, recently changed, unexplained
Commercial dependence Competitive multi-vendor category Single-source without documented reason
Bank changes Rare and independently verified Frequent or immediately before payment
Pricing Within benchmark Persistent unexplained premium
Employee connection No identified conflict Undisclosed relationship / common identifiers

10. Procurement governance controls

  • approved vendor policy;
  • independent vendor KYC;
  • conflict-of-interest declarations;
  • segregation of vendor creation and payment approval;
  • documented sourcing thresholds;
  • exception approval register;
  • price benchmarking;
  • three-way matching;
  • bank-change verification;
  • periodic vendor re-KYC;
  • duplicate-vendor analytics;
  • supplier performance review; and
  • whistleblower escalation route.

11. Board reporting and remediation

The board does not need a list of every procurement exception. It needs visibility on material leakage, systemic override, senior-management involvement, high-risk vendor concentration, quantified financial exposure and overdue remediation.

A remediation plan should identify the control owner, implementation date, evidence of closure and validation method. Repeat findings should be escalated because unresolved recurrence indicates governance failure.

See the Corporate Risk Mitigation in India pillar for the broader enterprise framework.

12. Frequently asked questions

Does a common vendor bank account prove fraud?

No. It is a serious red flag requiring verification, not a conclusion by itself.

Are three quotations enough to show fair procurement?

Not necessarily. The quotations should be independent, comparable and supported by a genuine sourcing process.

Should every vendor receive the same due diligence?

Risk-based due diligence is more efficient. High-value, critical, sensitive or related-party vendors merit deeper checks.

Can a vendor be suspended during an investigation?

Potentially, subject to contract terms, business continuity, evidence and proportionality.

What is the most important procurement control?

No single control is sufficient, but segregation of duties plus independent three-way matching significantly reduces opportunity for abuse.

Authoritative references

Firm & Correspondence Information
Fastrack Legal Solutions LLP
Office: B1/32 Basement, Malviya Nagar, New Delhi – 110017
Telephone: +91 76976 71219
Email: advgovind@fastracklegalsolutions.com
Website: fastracklegalsolutions.com
Provided solely for identification and correspondence; not an advertisement or solicitation.
General corporate-risk information only. Procurement investigations, contractual action and fraud allegations require evidence-led, case-specific review.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *