Briefings · 17 November 2025

Vendor fee clauses hiding inside case-management workflows

Outsourced review, data enrichment, and after-hours escalation often bill per case. The fraud-monitoring application may be the only place those charges are born.

Colleagues discussing papers around a conference table

Procurement signs a schedule: a ringgit amount per alert reviewed, per case opened, or per after-hours escalation. Months later, finance sees a vendor invoice that cannot be tied to anything except a count the vendor produced. The fraud-monitoring application, meanwhile, has been creating the events that should have supported that invoice.

If the application does not stamp a stable event when a case is sent to the vendor, you will never reconstruct the bill. If it does stamp the event but nobody extracts it, you will pay on the vendor’s count. Both are financial-control failures, not “vendor management” in the abstract.

In a fee-and-hold review we read the contract first, then the workflow. We look for the moment a chargeable event is created, whether it can be reversed, and whether finance receives a file or only a PDF. Recalculation of a sample against the tariff usually finds either silent scope creep (events billed that the contract never named) or under-billing that nobody has noticed because the process is opaque.

For Malaysian entities, these costs often sit in a financial-crime cost centre and never meet a recovery. That may be the intended policy. It should still be reconcilable. An application that cannot emit the chargeable-event list is a poor place to hide a six-figure vendor schedule.

Before renewal, we now ask sponsors to add a contract clause: the vendor must support an extract of chargeable events with identifiers that match the application. It is a small schedule. It saves a long argument later.

Bring a similar question to the Kuala Lumpur desk