procurea.Book a call
Supplier Intelligence

Why 40% of Your Supplier Database Goes Stale Every Year (And What to Do)

Supplier master data decays at roughly 40% per year. Here is why, broken into five decay vectors, and a 4-hour weekend triage that fixes the top 100 suppliers without a consultant.

4656
Pages read
472
Shortlisted
1053
Rejected with a reason
300
With an email

ALL 8 PUBLISHED CAMPAIGNS, SUMMED. THE FAILED ONES INCLUDED.

Where the 40% number actually comes from

Dun & Bradstreet's long-running commercial-data studies put B2B contact data decay at 30-40% per year. Gartner's supplier master data benchmarks land in the same range, roughly 25% of supplier records contain at least one material error after 12 months, and close to 40% after 24 months if no one refreshes them. Those numbers are not alarmist; they are the baseline the rest of business-to-business software is built around.

The 40% is not one big failure. It is five smaller ones compounding:

  • ~10%: M&A and ownership changes. The entity still exists, but its legal name, VAT number, or banking details have changed.
  • ~8%, deregistrations and insolvencies. The entity is gone but nobody told you.
  • ~12%, primary-contact email changes. LinkedIn data shows 25-30% of B2B decision-makers change roles every year. Half of those move companies.
  • ~5%, certification expirations. ISO 9001 cycles every three years; IATF 16949 every three years with annual surveillance. Miss the renewal and your "certified" supplier is not certified anymore.
  • ~5%, address, phone, or website changes without formal notification.

Add those up and you get 40%. Not every year is exactly 40%, a stable macro year might land at 32%, a crisis year (2020, 2022) hits 48%. The direction is the same.

40%
Annual decay rate
4
Ways a record goes stale
3 min
A VIES check per supplier
Continuous
Beats an annual audit

Supplier data freshness, monthly decay curve

Month 0100%
Month 392%
Month 682%
Month 970%
Month 1260%
Supplier data freshness over 12 months, ~40% of records go stale if untouched.
One query, five of twenty six
🇨🇳CHINESE二甲双胍原料药 GMP 生产商
🇩🇪GERMANMetformin Wirkstoff Hersteller GMP
🇯🇵JAPANESEメトホルミン 原薬 GMP 製造
🇸🇪SWEDISHmetformin API tillverkare GMP
🇮🇹ITALIANmetformina API produttore GMP
FIG. 01 · THE SAME BRIEF, DISPATCHED IN ITS MARKETS' OWN LANGUAGES

What stale supplier data actually costs you

Most procurement teams do not see the decay cost until it bites. Four places it shows up:

Failed RFQ campaigns. You send 40 RFQs for a new tooling round. 9 bounce (22%). 6 reach the wrong person who never forwards (15%). You get 12 responses from a supplier pool you thought was 40, that is a 30% effective reach rate on a list you were told was "clean." One buyer, one wasted week.

Compliance fines. CSRD, CSDDD, and VAT reverse-charge audits all require current supplier data. An auditor pulling your VAT documentation for a €180k invoice issued to a supplier whose VAT number was deregistered 14 months earlier will ask you to explain. The typical remediation bill from a finding like this is €20k-€80k depending on jurisdiction and how many invoices were involved.

Fake-continuity risk. A "supplier" with a valid record in your system but a dead website, an expired ISO, and a bounced email is a company that exists only on your invoice. The real risk is not that they scam you, it is that when you need them next (replacement part, warranty call, audit response), they are not there. You find out at exactly the wrong moment.

Negotiation leverage loss. Stale lists mean you are going back to the same six suppliers every year instead of refreshing the pool. We are not going to put a percentage on what that costs you, because we have not measured it and neither has anyone else in a way that would transfer to your category. What is true and checkable is the mechanism: a buyer with three quotes has less room than a buyer with ten, and a pool nobody has refreshed converges on three.

A missing certificate never drops a good maker. It lowers a score, and the score is a number you can argue with.

The 4-hour weekend triage (for the top 100 by spend)

The worst instinct when you inherit a 1500-row supplier master is to fix all 1500 rows. You will not finish. Pareto is brutal here: in almost every procurement org, the top 100 suppliers carry 75-85% of spend. Clean those 100. Everything else can wait for the ongoing-hygiene model below.

Budget a single Saturday. Four steps, about an hour each.

Hour 1: Bulk VAT and registry check. Export your top 100 suppliers with their VAT numbers. Run them through VIES for EU suppliers, Companies House for UK, local registries for the rest. Flag any that return "invalid" or "deregistered." Expect 3-8 hits on a 100-row sample. These are your priority investigations.

Hour 2: Email validation. Use any mail-check tool (NeverBounce, ZeroBounce, Hunter verifier) to bulk-validate the primary contact email on each record. Flag bounced and "risky." Expect 10-18 hits. For each, either re-enrich (find current contact) or archive the email and keep the company record.

Hour 3: Duplicate detection. Fuzzy-match company names. "Müller GmbH," "Mueller GMBH," and "Müller Group" are often the same entity entered three times over five years. Expect 4-12 duplicates. Critical: before merging, check your ERP Info Records, merging vendor IDs that have PO history breaks pricing conditions and audit trails.

Hour 4: Certification expiry sweep. For suppliers where you hold ISO/IATF/FDA data, check each certificate number against the issuing body's public registry (IAF CertSearch for most ISO/IATF). Flag expired certificates. Expect 5-9 expired out of 100. These suppliers are not disqualified, they need a new certificate request sent today.

At the end of four hours: about 25-40 records flagged, a handful of merges, a handful of archives. Not a full cleanup. A triage that protects your top-of-spend risk surface.

Delete, archive, or re-enrich? A decision framework

Once you have flagged records, the instinct to "just delete them" is wrong. Some flagged suppliers are strategic backups you keep dormant on purpose; some are historical vendors you still need for warranty or audit reasons. Three buckets:

Delete, only when all of: (a) no PO in the last 5 years, (b) entity is officially deregistered, (c) no open warranty or compliance obligation. These are genuinely dead. Deletion is safe because there is nothing to preserve. Expect 8-12% of your 100.

Archive (soft-delete), most flagged records land here. Keep the record for audit/historical reference but mark it inactive so it never surfaces in searches, RFQ distribution lists, or default supplier picks. Expect 25-35% of your 100 in a first triage.

Re-enrich, the record is still relevant; the data is just old. Find the current procurement email, update the VAT if the entity restructured, refresh the certificate number. Expect 15-25% needing re-enrichment. This is where automated enrichment tools pay back the fastest, re-enriching a name + country by hand takes 8-12 minutes; by tool, 30 seconds.

The mistake to avoid is a binary delete-or-keep choice. Archive is the workhorse. It preserves optionality (you can reactivate a dormant but viable supplier when a category reopens) while keeping your active base clean.

The ongoing-hygiene model that actually sticks

A one-off triage feels productive. It is not enough. Without a recurring cadence, you are back to 40% decay in 12 months. The pattern below is what sticks because each cadence is short enough to actually happen.

Monthly: 30 minutes. Sanity-check new additions from the previous month. Every new vendor created in the ERP gets: VAT validated in VIES, registry record linked, domain-based email verified, category code assigned. This is the cheapest hygiene layer, catching errors at entry is 10x cheaper than fixing them 18 months later.

Quarterly: 2 hours. Re-verify the top 100 by spend. VAT re-check (M&A happens mid-year), email re-validate (role turnover), certificate expiry check. Expect 10-20% of your top 100 to have moved since last quarter.

Annual: 1 day. Full-base sweep. Run the 4-hour triage against all 1500 rows, not just top 100. Build archive queue, delete queue, re-enrich queue. Document the result: "we refreshed X records, archived Y, deleted Z", and attach it to your annual procurement review.

Total ongoing cost: about 18 hours per year for a 1500-supplier base. A consultant doing the same work charges €8k-€20k. Your internal cost at €60/hour is about €1,100. Less than the cost of one failed RFQ campaign.

Five mistakes that kill a supplier data cleanup

1. Deleting based on "no activity." Some of your best strategic backups are inactive on purpose. A single-source chemical supplier you qualified three years ago as a crisis-only alternate will look dead in the data, until the primary fails and you need them in 48 hours. Archive beats delete for almost everything over a €10k historical spend.

2. Trusting supplier self-updates. You send a quarterly form asking suppliers to confirm their data. 15% return it. Of those, 30% have already out-of-date info because the person filling the form is not the person whose data changed. Self-attestation is a supplement, not a replacement for registry-based verification.

3. Merging duplicates without checking ERP Info Records. Merging vendor ID A into vendor ID B sounds clean. Then you realize A had three years of pricing conditions and a dozen open POs that do not transfer cleanly. SAP MDG and NetSuite both need the merge to happen in the ERP's native flow, not by CSV update.

4. Cleaning once and declaring victory. Without the monthly/quarterly/annual cadence, you are rebuilding the pile of bad data the moment you stop. A one-time cleanup has a half-life of about 18 months.

5. Ignoring the GDPR side of contact deletion. Supplier contacts are personal data. Deleting a supplier record after the legal retention period is not optional, it is required. Keeping a bounced contact's name and email "just in case" for five years past the last invoice is a GDPR exposure. Archive with redaction, or delete fully; do not retain indefinitely by accident.

Read the campaigns behind these numbers
All 8 campaigns, published unedited.

472 suppliers across 8 briefs, 1053 rejections still on the record with the reason each one was given.

Questions buyers ask about this

How often should a supplier master database be cleaned?
A light monthly sanity-check on new additions (30 minutes), a quarterly refresh on the top 100 by spend (2 hours), and an annual full-base sweep (1 day). Anything less frequent than annual means ~40% of your data will be stale before the next cleanup. Anything more frequent than monthly is overkill for mid-market bases under 2000 suppliers.
What is the typical decay rate for B2B supplier data?
Dun & Bradstreet and Gartner benchmarks put contact-level decay at 30-40% per year. Entity-level decay (VAT, legal name, registry status) is lower, roughly 15-20% per year. Certification data decays at whatever rate matches the cert cycle (3 years for most ISO standards). Combined, expect about 40% of records to have at least one material error after 12 months without refresh.
Can I automate supplier master data refresh?
Partially, and the partial is where the ROI is. VAT checks (VIES), registry lookups (KRS, Handelsregister, Companies House), email validation (MX + SMTP ping), and certificate expiry matching (IAF CertSearch) are all automatable end-to-end. Email re-discovery and contact refresh are AI-assisted but benefit from human review. The final delete-or-archive decision should stay human, too much downside risk in getting it wrong.
Should I clean my supplier database or start over?
Almost never start over. Your existing base contains PO history, pricing conditions, and audit context that are expensive to rebuild. Start-over is only rational when the legacy system is being decommissioned for unrelated reasons (ERP migration, M&A integration). Otherwise: triage the top 100, archive the clear dead, and run the ongoing-hygiene model. A 1500-row base gets to "clean enough" in about 6 weeks with that approach.
Does ERP master data management (MDG) replace this work?
Tools like SAP MDG, Oracle MDM, and NetSuite native dedupe help with consistency and governance inside the ERP, but they do not refresh external truth. None of them will tell you that a supplier deregistered last month or their ISO lapsed. ERP MDG is necessary for entity uniqueness and workflow; external verification (VIES, registries, IAF CertSearch) is necessary for freshness. You need both, not one or the other.