Home · Solutions · Procurement

Solution · Procurement

A new supplier gets its SAP number in days, with the evidence pack already on file

Supplier onboarding and due diligence in days, not weeks

Suppliers enter their data and documents once; robots read the certificates, query the registers and sanctions lists, score the file and create the vendor in SAP after an approval in Teams.

DepartmentalMicrosoft TeamsHuman in the loopAI where it earns its place
15working days pass between a buyer's request for a new supplier and the first purchase order at this illustrative company. The supplier's data is retyped three times.

Executive summary

Challenge

Stop losing three weeks and the compliance evidence every time a plant needs a new supplier.

What changes

The flow starts where the need starts: the buyer submits a short request in Microsoft Forms from Teams.

Business value

A complete supplier file moves from request to SAP number in two or three working days instead of three weeks; launches stop waiting for master data.

Systems involved

SAP S/4HANA (business partner with supplier role); SharePoint evidence library; Microsoft Lists onboarding tracker

Business problem

Supplier onboarding

A company cannot pay a counterparty it has not verified: that it exists and is represented by the people who signed, that its VAT status and bank account are the ones the tax office recognises, that it is on no sanctions list, that its insurance and quality certificates are valid. Each question belongs to a different department, so every new supplier becomes a small due-diligence case assembled by email.

The assembly is where the weeks go. Documents arrive in instalments, checks run in browser tabs, and the vendor is created from a questionnaire that may already be out of date. None of the checks leaves a record an auditor could see a year later. Meanwhile the plant waits, or the buyer orders against a temporary vendor.

Requalification makes the problem permanent: certificates expire, VAT registrations are withdrawn, representatives change, and nobody re-runs the checks unless an incident forces it. The tracker with the dates belongs to one person.

This site already shows the pattern from the other side, in the B2B client onboarding and KYC case. Supplier due diligence is its mirror image: the counterparty is paid rather than invoiced, the questions come from procurement, finance, quality and compliance, and the evidence has to satisfy the tax office and the OEM auditor.

How it works today

A buyer's email and one row in a spreadsheet set the whole file moving:

  1. PersonThe buyer emails the supplier a Word questionnaire and a list of required documents, and adds a row to the Excel tracker on SharePoint
  2. WaitingDocuments arrive in instalments over one to two weeks; the buyer reminds by phone
  3. PersonFinance checks the VAT white list, compliance searches the sanctions lists, quality reads the ISO and IATF certificates; each result stays in the checker's mailbox
  4. Risk of errorResults survive as screenshots or not at all; an expired insurance certificate or a wrong VAT identifier surfaces with the first invoice
  5. PersonMaster data retypes the supplier into SAP and asks the procurement director for approval by email
  6. WaitingThe approval waits for a business trip to end; the plant orders against a temporary vendor or moves the launch
  7. Risk of errorRequalification dates live in the tracker; when its owner changes, expiries are missed until an OEM audit asks
PersonWaitingRisk of error

Why the current process costs more than it appears

Time that disappears before anyone measures it.

  • The four and a half hours per file are split among five people who never see the total; the buyer's chasing time is the largest item and is recorded nowhere.
  • Waiting has a price in the plant: expedited freight from the incumbent, single-source premiums, launch dates moved because the tooling supplier had no vendor number.
  • A check done by hand is a check without evidence. When the auditor asks how the bank account was verified on the day of payment, the answer is a screenshot in a mailbox, if it still exists.
  • Requalification is the quiet cost: expired insurance, lapsed IATF certificates and VAT deregistrations are discovered by the incident they cause, not by the process.

Cost of inaction

Twelve months of chasing certificates≈ €56,700
Three years at 35 files a month≈ €170,100
If a third plant pushes it to 50 files a month (per year)≈ €81,000

A third plant does not change the process, only the number of people chasing documents. The queue keeps its shape: 35 files a month consume the modelled 158 hours across four departments, requalifications keep slipping behind new suppliers, and each OEM programme adds another batch to the same people.

The larger exposure sits outside the model. One payment above the statutory threshold to an account absent from the VAT white list, one supplier found on a sanctions list, or one lapsed insurance certificate at the moment of a damage claim costs more than a year of the manual work, and a process without evidence can neither prevent nor defend it.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

An automotive tier-1 supplier with two plants in Poland, 1,400 employees, SAP S/4HANA and Microsoft 365 E3; eight buyers, two master-data specialists, one compliance officer.

Volume

120 new suppliers and 300 requalifications a year, 35 files a month; about two thirds Polish companies, the rest mostly EU suppliers; six to ten documents per file.

Current process

Questionnaire and documents by email, checks in browser tabs by three departments, an Excel tracker for status and requalification dates, vendor creation in SAP from the questionnaire, approval by email.

Bottleneck

About 4.5 hours of work per file across four departments, spread over 15 working days of waiting; the requalification backlog grows every quarter because new suppliers come first.

Solution

Suppliers enter data and upload documents on a self-service page; UiPath Document Understanding reads them; robots run the register and sanctions checks, score the file and route it for approval in Microsoft Teams; the vendor is created in SAP with the evidence pack on SharePoint.

Potential outcome

In the modelled case, manual effort per file falls from about 4.5 hours to two approvals and the review of exceptions (modelled 30 to 45 minutes for amber files), cycle time for a complete file from three weeks to two or three working days, and every check leaves stored evidence. Modelled throughout, and offered as arithmetic rather than evidence.

Proposed solution

The flow starts where the need starts: the buyer submits a short request in Microsoft Forms from Teams. The supplier receives a link to an onboarding page built on Power Pages, fills in the questionnaire once and uploads its documents: registration extract, VAT confirmation, insurance certificate, ISO or IATF certificates, bank confirmation. Companies that would rather not run a supplier-facing page use a dedicated onboarding mailbox instead. Either way the file becomes one case in an Orchestrator queue.

UiPath Document Understanding reads the documents: the pre-trained Certificates of Incorporation model where the certificate matches it, Generative Extraction with a schema we define for KRS extracts, insurance policies and quality certificates. Robots compare the declared data with the Polish VAT white list, KRS or CEIDG, VIES and the EU consolidated sanctions list, and store every response with its request identifier and timestamp. A rule set written with your compliance officer turns the findings into a path: green when the file is complete and consistent; amber when a document is missing or a detail differs from the register; red for a sanctions match, an inactive VAT status or a bank account absent from the white list.

People appear at the decision, not at the typing. Green and amber files reach the procurement lead and finance as an approval in Microsoft Teams with a one-page summary and the evidence attached; red files become a compliance review task in UiPath Action Center, completed inside Teams. After approval a robot checks SAP for duplicates, creates the business partner with the supplier role and bank data, files the evidence pack on SharePoint and returns the SAP number to the buyer. Certificate validity dates start the requalification clock.

Machine learning appears in one place, reading documents; everything else is deterministic, which keeps the result auditable. Continuous screening of the whole supplier base between requalifications is a separate solution on this site.

Native capabilities used

UiPath Document Understanding (pre-trained Certificates of Incorporation model, Generative Extraction, validation actions in Action Center); UiPath Orchestrator; UiPath Integration Service connectors for Microsoft Outlook 365, Microsoft OneDrive & SharePoint and Microsoft Teams; Action Center tasks in Teams; Microsoft Teams Approvals app; Microsoft Forms; Power Pages on Dataverse

What we build

The intake, extraction schemas, register and sanctions checks with evidence storage, scoring rules and routing, approval and clarification flows, SAP business partner creation, the SharePoint evidence library, requalification scheduling and reporting

Custom integration

SAP S/4HANA business partner creation through UiPath SAP connectors (BAPI/OData); API clients for the VAT white list, VIES, KRS and CEIDG; sanctions-list matching; registers without an API through UI automation

How the automated process works

  1. AutomationThe buyer's Forms request opens the case in Orchestrator and sends the supplier its onboarding link
  2. SystemThe supplier completes the questionnaire and uploads documents on the Power Pages page, or emails them to the onboarding mailbox
  3. AutomationDocument Understanding reads the documents; low-confidence fields become a validation task in Action Center
  4. AutomationRobots query the VAT white list, VIES, KRS or CEIDG and the sanctions lists, compare declared and registered data and store every response with its request identifier
  5. AutomationMissing or expired documents trigger a clarification email to the supplier; the buyer sees the reason in Teams
  6. PersonThe procurement lead and finance approve green and amber files in the Teams Approvals app; compliance reviews red files in Action Center, inside Teams
  7. AutomationAfter approval the robot checks SAP for duplicates, creates the business partner, files the evidence pack on SharePoint and returns the SAP number
  8. AutomationCertificate dates schedule the requalification: renewed documents are requested before expiry and the checks re-run
AutomationSystemPerson

Human-in-the-loop model

Automation handles

  • Collecting the questionnaire and documents, with reminders to supplier and buyer
  • Reading extracts and certificates; all register, VAT and sanctions checks; comparison of declared and registered data
  • Scoring, routing, duplicate checks, business partner creation in SAP, the evidence pack and requalification requests

People decide

  • Whether to work with the supplier at all: the approval in Teams by procurement and finance, within the approval matrix
  • Red files: sanctions matches, inactive VAT status, a bank account absent from the white list, discrepancies with the registers
  • The rules themselves: score weights, mandatory documents per category and country, approval thresholds

Before and after

BeforeAfter
Cycle time from request to SAP numberabout 15 working daystwo or three working days for a complete file
Manual work per supplier fileabout 270 min across five peopleapprovals and exceptions (modelled 30 to 45 min for amber files)
Evidence of checksscreenshots in mailboxes, if anystored responses with request identifiers and timestamps
Certificate expiryExcel tracker, found at auditscheduled by the file, renewed before expiry
Data entrythree times: questionnaire, tracker, SAPonce, by the supplier

Systems and integrations

Where a rule suffices we do not use a model. Where judgement is needed, a person decides.

Inputs

  • Microsoft Forms request
  • Power Pages supplier page or onboarding mailbox
  • supplier documents
  • public registers and sanctions lists

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Document Understanding
  • UiPath Integration Service
  • UiPath Action Center

Target systems

  • SAP S/4HANA (business partner with supplier role)
  • SharePoint evidence library
  • Microsoft Lists onboarding tracker

Human touchpoints: Teams Approvals; Action Center tasks in Teams; clarification emails to the supplier; status tab in the procurement Teams channel

Microsoft Forms requestUiPath OrchestratorUiPath RobotsSAP S/4HANATeams Approvals

Technologies used

UiPath Document Understanding (IXP)

pre-trained Certificates of Incorporation model; Generative Extraction for KRS extracts, insurance and quality certificates

A
UiPath Robots + Orchestrator

queue each file, run checks and scoring rules, create the vendor in SAP, log every step

A
UiPath Integration Service (Microsoft Outlook 365, OneDrive & SharePoint, Teams connectors)

onboarding mailbox, evidence library, status posts in Teams

A
UiPath Action Center in Microsoft Teams

validation and compliance review tasks completed in Teams

A
Microsoft Teams Approvals app

supplier approval by procurement and finance, evidence attached

A
Microsoft Forms and Power Pages

buyer's request form; supplier self-service page on Dataverse

A
SAP S/4HANA (BAPI/OData via UiPath SAP connectors)

duplicate lookup; business partner creation with supplier role

A
VAT white list API, EU VIES, KRS and CEIDG APIs, EU consolidated sanctions list

official register and list checks; request identifiers stored as evidence

B
Averified product capability (vendor documentation)Bverified external source

Illustrative economic model

Start by questioning the assumptions.

Illustrative model
35 supplier files a month × 270 minutes of manual work≈ 158 h / month
157.5 h × €30 fully loaded hourly cost= €4,725 / month
× 12 months= €56,700 / year
Annual capacity released (illustrative)≈ €56,700

Swap in your own numbers; ours are illustrative ranges from procurement and master-data teams, not a client measurement. A file is a new supplier or a requalification; the 270 minutes sum the buyer's chasing, the finance, compliance and quality checks, the SAP entry and the tracker updates across several people; €30 is a blended fully loaded hourly cost for those roles in Central Europe. Capacity released, not headcount removed; plant waiting costs are not modelled.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • A complete supplier file moves from request to SAP number in two or three working days instead of three weeks; launches stop waiting for master data
  • Manual work per file falls from about 4.5 hours to two approvals and the review of exceptions; requalifications stop competing with new suppliers for the same people
  • Every check has evidence: white list response with request identifier, VIES consultation number, register data and sanctions result, stored next to the approval
  • Payments to accounts outside the white list, to deregistered VAT payers or to listed entities are blocked before the vendor exists in SAP
  • Suppliers enter their data once and hear the same day what is missing; certificates are renewed before expiry because the file remembers the date

The management view

  • The onboarding pipeline sits in one place: every file, its stage, its score and whose decision it is waiting for
  • Evidence complete and dated for every supplier, ready for a tax inspection or an OEM audit
  • Approval discipline enforced by the flow: no vendor number without the recorded approvals, no bank data without finance
  • Capacity that follows volume: a third plant adds files to a queue, not people to four departments

Board-level KPIs

cycle time from request to SAP numbershare of supplier files with complete, dated evidencerequalifications completed before certificate expirymanual hours per supplier file

Security and governance

Where the data sits and who can see it.

  • Supplier files hold personal data and bank details; they stay in your Microsoft 365 tenant and the UiPath Automation Cloud EU region, in a library restricted to procurement, finance and compliance, with Microsoft Purview sensitivity and retention labels
  • Robots use service accounts: an SAP account limited to business partner creation, a permission scoped to the onboarding mailbox, API tokens in the Orchestrator credential store or Azure Key Vault; every action is logged
  • Segregation of duties is built into the flow: the requesting buyer cannot approve, finance approves bank data, compliance owns red files
  • Every check is stored with source, request identifier and timestamp; Teams approvals are audited in Microsoft Purview
  • Generative Extraction runs under the UiPath AI Trust Layer policies you set: allowed models, region routing, PII masking, audit

Why now

01

Four departments spend the modelled €4,725 a month on these files, and the plants carry the cost of suppliers they cannot yet order from

02

Tax and sanctions rules put the burden of proof on the paying company, and OEM customers pass supply-chain due-diligence obligations down to tier-1 suppliers; the VAT white list, VIES and the EU sanctions list are official, queryable sources

03

The building blocks are standard: a pre-trained Certificates of Incorporation model and Generative Extraction in UiPath Document Understanding, official APIs that return request identifiers, approvals with attachments in Teams

Relevant executive roles

Procurement Director

New suppliers are available to the plants in days; buyers source instead of chasing documents

CFO

Every vendor in SAP has a verified VAT status and bank account and a dated evidence pack behind it

Compliance Director

Sanctions and register checks run on every file and requalification, with evidence that stands up in an inspection

COO

Launches stop waiting for master data; expediting caused by suppliers without a vendor number falls away

Common questions and objections

Our suppliers are small workshops that will never use a portal.

They do not have to. The same robots read documents emailed to the onboarding mailbox, and the buyer can upload on the supplier's behalf; each document is sent once, and the answer about what is still missing comes the same day.

Compliance will not accept robots doing due diligence.

Robots collect and verify; people decide. Every check is stored with its request identifier, the rules are written and versioned by compliance, and every red file is reviewed by a person: more evidence, the same authority.

Half our suppliers are outside Poland, where there is no white list.

The rules state which checks apply per country: VIES and the sanctions lists for every EU supplier, the national register through its API or its website, and a task for a person where no register can be queried; the file records which checks ran automatically and which by hand.

When this is not the right solution

  • Fewer than about ten supplier files a month and no tax, OEM or audit pressure on evidence: a Microsoft Lists checklist and a Teams approval template are cheaper
  • No agreed acceptance criteria: if mandatory documents and approval paths differ from buyer to buyer, we start with a rules workshop, not with robots
  • A supplier portal with built-in verification and SAP integration already exists; then only the evidence library and requalification are worth adding

A question for the next management meeting

Between a buyer's request for a new supplier and the first purchase order, how many working days pass, and what do those days cost in expediting, single-sourcing and delayed launches?

Implementation approach

We start with one slice of the process and extend only once it is proven.

We deliver

  • Your last fifty supplier files, opened one by one: document types, check results, approval paths, where the days go
  • The intake: Forms request, Power Pages page or mailbox variant, and the clarification flow
  • Extraction schemas for extracts, certificates and bank confirmations, with validation tasks in Action Center
  • Register, VAT and sanctions check workflows with evidence storage, and the scoring rules agreed with compliance
  • Teams approvals, SAP business partner creation, the SharePoint evidence library and requalification scheduling
  • A runbook for procurement and master data, reporting and hypercare after go-live

We need from you

  • Your supplier questionnaire, the mandatory documents per category and country, and the approval matrix
  • Thirty to fifty recent supplier files with documents and the corresponding SAP records
  • Process owners in procurement, finance (bank data) and compliance (rules)
  • Technical accounts for SAP test and production, Microsoft 365 and the register APIs

Stages

Discovery

Recent files, document types, checks, approval paths and cycle times with the process owners

Design

Target flow, document set per category and country, scoring rules, approval thresholds, security

Build

Intake, extraction schemas, check workflows, Teams approvals, SAP creation, SharePoint library

Validation

Parallel run on real files, scores compared with past decisions, acceptance by the three departments

Go-live

Controlled start with one plant or category, hypercare, then the requalification backlog

Optimisation

Rule tuning, new document types and countries, dashboards, hand-over to continuous screening

Departmental. Effort depends on the number of countries and register types, the variety of certificates and whether a supplier portal already exists.

Fifteen working days from a buyer's request to the first purchase order.

Share your supplier questionnaire, the required-document list and last quarter's new vendors with request and creation dates. We come back with the mapped flow, the automatable share of the checks and a short read-out call.

Share last quarter's new vendors

The neighbouring process usually has the same problem

Industries we deliver this in most oftenManufacturing & industryRetail & e‑commerceServices & IT

Browse all 115 solutions