Finance playbook · AI Employee: Fin

Vendor Intake & Onboarding

Vendor onboarded in one week

The problem

Vendor onboarding is a slow-motion multi-team relay: legal reviews the contract, security reviews the questionnaire, finance sets up the payment record, IT provisions any SSO integration. The vendor waits weeks. Every hand-off risks a drop. Every drop is a purchase-order clock ticking.

At a glance
Trigger
Form
Approvals
Finance + security approval
What it does
Writes to your systems
Systems
NetSuite · Vanta · Ironclad · Bill
How it feels in production

An hour-by-hour walkthrough.

Monday. Priya (marketing) submits a new-vendor request: Acme Analytics, $60k / year, SaaS, needs SSO integration. Fin starts the intake: creates the vendor record, requests the standard docs (W-9, banking, insurance certificate, security questionnaire), assigns owners to each parallel workstream. Legal owner gets the redlined MSA in Ironclad; security owner gets the questionnaire flowing through Lex's questionnaire-response playbook; IT owner gets the SSO integration on the queue; finance sets up the payment record in NetSuite. Wednesday. Legal's redlines resolved (Ironclad tracked one turn). Security scored the questionnaire — high-risk on data residency, low on everything else — flagged for legal review of DPA. Fin routes a joint decision card to CFO + GC. Friday. Joint approval. Fin activates the vendor record in NetSuite, notifies AP for payment schedule, sends the countersigned MSA to Acme, opens the IT SSO integration ticket. Time from request to procurement-ready: 5 business days (vs. the usual 6-8 weeks). Every step logged. Any owner unresponsive past their SLA gets escalated to their manager automatically. Full audit trail for compliance review.
How it works

Step by step.

  1. 01

    Collect vendor info + docs

    Requester fills a form or DMs Fin: vendor name, use case, spend, contract terms. Fin auto-requests the standard doc pack: W-9, banking, insurance certificate, security questionnaire, data-processing addendum.

    Slack · Portal · Email
  2. 02

    Run risk + security check

    Legal (via Lex) reviews contract terms. Security (via Sig) scores the questionnaire and checks against your risk framework (data types, retention, sub-processors). Both scores + flags feed the joint decision card.

    Ironclad · Vanta · Drata
  3. 03

    Create vendor record

    On approval, create the vendor record in your ERP with tax-ID, banking details, payment terms, cost-centre. Vendor immediately available for PO creation.

    NetSuite · QuickBooks · SAP · Coupa
  4. 04

    Notify AP

    Accounts payable notified of the new vendor with payment terms and PO expectations. First invoice can be processed on receipt.

    Bill · Coupa · NetSuite
Systems and wiring

What you connect to make this run.

Ironclad · DocuSign

read+write

Contract lifecycle managed in Ironclad; DocuSign for signature. Redline tracking + counterparty response events fed into the vendor timeline.

Vanta · Drata

read

Security posture scored against your risk framework. High-risk flags require legal + security joint approval.

NetSuite · QuickBooks · Xero · SAP S/4HANA

write

Vendor-master write with tax ID, banking, payment terms. Zero-manual-entry once approval clears.

Bill · Coupa · SAP Concur · Zip

write

AP integration for payment scheduling. Vendor record synced from ERP.

What changes

Before and after, honestly.

Time from request to procurement-ready
Before
6-8 weeks across serial hand-offs
After
5-10 business days with parallel workstreams
Vendor requests stuck 'in review'
Before
20-40% of active queue at any time
After
Under 10%; SLA breaches escalated automatically
Duplicate vendor records
Before
5-15% of vendor master (multiple business units onboarding same vendor)
After
Under 1% (dedup check at intake)
Missed compliance items in audit
Before
Discovered during annual audit; remediated after the fact
After
Caught at intake; every vendor record complete
Frequently asked

Answers about this playbook.

What if the vendor is small — do they still need a full security review?

Risk-tiered. Vendors under $10k spend with no PII / financial-data access get a lighter review (basic security questionnaire, no DPA). Vendors above thresholds trigger the full review. Configurable per your risk framework.

How does dedup work across business units?

Fin checks the vendor master by tax ID + business name + domain before creating a new record. Match found → offers to link to the existing vendor with a new cost-centre association. Prevents the classic "three copies of Salesforce as a vendor" pattern.

What if legal and security disagree on approval?

Joint decision card routes to CFO + GC (or your policy-defined escalation). Both approvals required for high-risk vendors. Full context of both reviews attached to the decision.

Can we standardise contract terms?

Yes — your approved MSA template lives in Ironclad; Lex drafts starting from it. Counterparty-requested deviations tracked as redlines; standard responses drafted for common asks (indemnity caps, jurisdiction, notice periods).

How does this handle renewals?

The Contract-Renewal-Watcher playbook fires on approaching end dates. Same review flow re-runs with lighter defaults (existing risk posture, no new questionnaire unless changed).

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.