Supplier approval: step-by-step process
See how to structure supplier approval step by step: document collection, parallel reviews, approval authority levels, creation in the ERP and periodic revalidation.
Supplier approval is the formal process that decides whether a company is fit to supply to yours, before it becomes master data in the ERP. Structuring it means defining the entry trigger, document collection, parallel reviews by each area, approval authority levels, the creation of the record in the ERP and revalidation with an expiration date.
What supplier approval is and where it begins and ends
Most of the broken processes we come across share the same root cause: registration, qualification and approval are treated as a single thing. They are three different things, with different owners and different exit criteria.
Registration, qualification and approval are not the same thing
- Registration is the master data record: legal name, tax ID, address, bank details, payment terms, purchasing group, tax data. It is an MDM activity, owned by the master data team.
- Qualification is the initial screening: does this supplier meet the technical and commercial needs of the category? It is a Procurement activity, usually tied to sourcing.
- Approval is the formal fitness decision, based on documentary evidence and on the opinions of tax, legal, technical, financial and occupational safety areas. It has an approval authority level, a recorded opinion and an expiration date.
When the three become a single step, the outcome is predictable: a supplier approved by email that never became a reliable record, or a record created in the ERP that never went through any review. In both cases, the company loses control over who can receive a purchase order.
The end point is the master data, not the approval email
The flow only ends when the approval decision is reflected in the ERP, in fields that the purchasing process can read: approval status, released categories, expiration date, usage restrictions. If the approval lives in a spreadsheet, an email or a shared folder, it blocks nothing. That is why we treat supplier approval as a supplier master data process, and not as a Procurement ritual. See how we organize data domains → to understand where the supplier fits in.
The complete flow, step by step
1. Request and justification from the requesting department
The process starts with a formal request, not with a buyer's contact. The request must include the purchasing category, estimated criticality, justification of the need and, where applicable, the reason why already approved suppliers do not meet it. This step is what prevents duplicate suppliers from entering and what defines, right from the start, whether the case goes to the simplified or to the complete flow.
2. Document collection
Here you define a closed list by requirement level: corporate documents, tax and labor clearance certificates, bank verification, licenses, technical certifications, occupational safety documentation for service providers on site. Any request for a document outside the list must be a recorded exception, not a habit. The practical rule: if no one reviews the document, it comes off the list.
3. Parallel reviews
Reviews run in parallel, not in a queue. Tax, legal, technical, financial and occupational safety receive the dossier at the same time and return their opinion within their own SLA. Deeper checks, such as background check, due diligence, supplier scoring and ESG criteria, come in here as a referenced step, with a clear rule for when they are mandatory.
4. Approval by authority level
The approval authority level must be defined by criticality and risk, not by purchase value alone. The approver does not review documents: they decide based on the opinions. If an opinion is unfavorable, the flow has two possible outcomes, rejection or approval with restriction, and both are recorded with justification.
5. Creation or update of master data in the ERP
Once approved, the master data team creates or updates the record in the ERP. Before that, a mandatory duplicate check and field standardization according to the company's business rules. A record created without this step is future debt, later resolved through data cleansing → at a much higher cost.
6. Periodic revalidation with an expiration date
Approval without an expiration date is eternal approval. Every supplier leaves the process with a date, and expiration triggers an automatic revalidation. Events also trigger reviews outside the calendar: change in ownership control, quality incident, expired clearance certificate, change in the scope of supply.
How to calibrate the process to your reality
Requirement levels by category criticality
Applying the complete flow to everything jams operations and makes the requesting department work around the process. Calibration starts by classifying purchasing categories.
| Level | Typical category profile | Documentation | Reviews | Approval authority | Revalidation |
|---|---|---|---|---|---|
| Simplified | Low-impact indirect material, one-off purchase | Corporate, tax and bank documents | Tax review and duplicate check | Procurement Coordination | Long cycle, defined in policy |
| Intermediate | Recurring service without site access, non-critical input | Simplified plus category certifications | Tax, legal and financial | Procurement Management | Medium cycle |
| Complete | Critical production supplier, service provider with people on site, supplier with access to personal data | Intermediate plus licenses, technical and occupational safety | All reviews, including due diligence and assessment of data processing under the LGPD | Committee or executive board | Short cycle, plus event-based triggers |
RACI matrix of the steps
| Step | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Request and justification | Requesting department | Procurement | — | Master data |
| Document collection | Procurement | — | Supplier | Reviewing areas |
| Parallel reviews | Tax, legal, financial, technical, OHS | — | Procurement | Requesting department |
| Approval decision | Procurement | Authority level defined by criticality | Reviewing areas | Requesting department |
| Creation in the ERP | Master data | Master data | Tax | Procurement |
| Revalidation | Master data | Procurement | Reviewing areas | Requesting department |
SLAs by step
An SLA is not policy decoration: it is what makes the flow enforceable. Define a specific SLA for each review, an SLA for the supplier's response during document collection and an escalation rule for when the deadline is missed. You calibrate the number itself using your operation's history, not an external benchmark. What cannot be missing is the clock running inside the workflow, with a record of who held things up and for how long.
Monitoring indicators
- Average approval time, broken down by requirement level and by step, to find the real bottleneck.
- Rejection rate by reason, which shows whether the initial screening is working.
- Active suppliers with expired documentation, the indicator that most exposes immediate risk.
- Volume of exceptions and of approvals outside the authority level.
- Duplicates detected before creation in the ERP.
Common mistakes that jam the process
- A single flow for every category, which pushes the requesting department toward the informal path.
- Reviews run sequentially when they could run in parallel.
- Documents requested and never read.
- Approval recorded outside the system that controls the master data.
- Approval with no expiration date and no event-based trigger.
Frequently asked questions
What is the difference between supplier registration and supplier approval?
Registration is the master data record in the ERP, with standardized tax, banking and purchasing data. Approval is the formal decision that the supplier is fit, supported by opinions from tax, legal, technical, financial and occupational safety areas. Registration is a consequence of approval, not a substitute for it.
Where does the approval process begin and where does it end?
It begins with a formal request from the requesting department, with the justification and category defined. It ends when the approval status, released categories and expiration date are recorded in the supplier's master data inside the ERP, ready to block or release a purchase order.
Does every supplier have to go through the complete flow?
No. The complete flow is for critical categories, service providers with people on site and suppliers that process personal data under the LGPD. The others go through the simplified or intermediate flow. The category classification is what decides, and it must be in the policy, not in the buyer's judgment.
How often should an approved supplier be revalidated?
The cycle varies by requirement level and you define it in the internal policy, based on the category's risk. What applies to all: every approval has an expiration date and event-based triggers, such as a change in ownership, a quality incident or an expired clearance certificate.
Can this be structured without a system?
You can design it, but you cannot sustain it. Without a workflow, the SLA is not measured, the opinion is not traceable and the decision never reaches the master data. We design the process first and only then take it into the system, because automating a poorly defined flow only speeds up the error. If you want to go deeper into the design, see our material on supplier approval →.