Built for scrutiny

Governance, compliance and controls

Procurement is where governance either holds or leaks. This page collects what compliance, audit and finance teams ask us for — our registrations, our published policies, and the controls the platform itself enforces on every purchase.

Registered and verifiable

Both registrations are issued by Malaysian authorities and independently checkable — see why trust Lapasar for the full operational proof.

Ministry of Finance (MOF) registration

Lapasar is a registered supplier with Malaysia's Ministry of Finance — the registration required to supply goods and services to government bodies and government-linked companies. It is verified through supporting documents, not self-declared.

Registered Malaysian company

Lapasar Sdn Bhd (registration no. 1198228-D) is a Malaysian-incorporated company headquartered in Bandar Bukit Raja, Klang, Selangor — independently checkable with the Companies Commission of Malaysia (SSM).

Published policies

These are standing public documents — not statements drafted for a tender. Read them in full on this site, download the PDFs, redline them, send them to legal.

Anti-corruption aligned to Section 17A

Section 17A of the Malaysian Anti-Corruption Commission Act 2009 makes a commercial organisation liable for corruption committed by persons associated with it — unless it can show adequate procedures were in place. For corporate and GLC procurement teams, that exposure extends to the platforms and suppliers you transact through, which is why vendor questionnaires now ask for more than a signed declaration.

Lapasar’s framework is built to support its obligations and defences under Section 17A: a published Anti-Bribery & Anti-Corruption Policy with zero tolerance for bribes and kickbacks, and a board-approved Whistleblowing Policy — guided by the Guidelines on Adequate Procedures issued under Section 17A(5) and the principles of the Whistleblower Protection Act 2011 — with confidential, anonymous-capable reporting channels, protection against retaliation for good-faith reports, and board-level oversight of material matters.

One detail matters especially in procurement: the people most likely to see bid-rigging, kickbacks or falsified delivery records sit outside a company, not inside it. Lapasar’s reporting channels are explicitly open to external parties — suppliers, vendors, logistics partners, consultants and clients — not just employees.

Audit-defensible, by enforcement

An audit-defensible purchase is one whose full story can be reconstructed from records: who requested it, who approved it, what was ordered, what arrived, what was paid. A policy library proves intent — enforcement proves control. These controls run at the point of purchase, on every purchase — explore them in depth on the product features page.

Procurement policies

Company purchasing rules are encoded on the platform itself, so policy is enforced at the point of purchase — not audited after the fact.

Approval workflows

Multi-level, configurable approval chains route every requisition to the right approvers before money moves.

Budget controls

Departmental and project budgets are tracked against live spend, with limits applied before an order is placed.

Three-way matching

Purchase order, goods-received note and invoice are matched on-platform before payment is cleared.

Dynamic reporting

Order history, spend and approval records are reportable on demand — the paper trail your auditors ask for.

Order tracking & GRN

Every delivery is tracked and received against a goods-received note, closing the loop between ordering and payment.

Commercial terms with discipline

Every approved buyer on Lapasar purchases on company credit terms with consolidated invoicing — no personal cards, no expense-claim workarounds. Across the network, Lapasar extends RM300m+ in credit lines to customers yearly and pays suppliers RM100m+ in early payments yearly, as early as two days after delivery.

That discipline cuts both ways: buyers get predictable terms their finance teams can plan around, and suppliers get paid promptly — which keeps the supply side of the marketplace healthy and accountable.

The vendor due-diligence checklist, answered

The questions procurement, compliance and audit teams ask in vendor questionnaires — and where Lapasar answers each one, publicly.

What due-diligence teams askLapasar’s answer
Company registration & legal identityLapasar Sdn Bhd (registration no. 1198228-D) — independently verifiable with the Companies Commission of Malaysia (SSM).
Government-supplier registrationMinistry of Finance (MOF)-registered supplier. Supporting documents are shared on request during vendor onboarding.
Anti-bribery & anti-corruption policyPublished in full with a downloadable PDF — zero tolerance for bribes and kickbacks by anyone acting on Lapasar's behalf. Read the policy
Whistleblowing channelBoard-approved policy with confidential, anonymous-capable reporting channels open to employees and external parties, and protection against retaliation for good-faith reports. Read the policy
Section 17A adequate proceduresThe anti-bribery and whistleblowing framework is guided by the Guidelines on Adequate Procedures issued under Section 17A(5) of the MACC Act 2009 and supports Lapasar's obligations and defences under Section 17A — a published policy framework, not a certification.
Personal data protection (PDPA)Published Personal Data Protection Policy covering how personal data is collected, processed and protected. Read the policy
Supplier conduct termsPublished Vendor Terms & Conditions that every vendor supplying through the Lapasar Marketplace agrees to. Read the terms
Purchase controls & approvalsProcurement policies, multi-level approval workflows and budget controls enforced on the platform at the point of purchase. See the controls
Audit trailThree-way matching between purchase order, goods-received note and invoice, with the full document chain for any purchase reportable on demand. See the controls

Common questions

Is Lapasar registered with Malaysia's Ministry of Finance?

Yes. Lapasar is an MOF-registered supplier — the registration required to supply goods and services to Malaysian government bodies and government-linked companies. Lapasar Sdn Bhd (1198228-D) is also independently verifiable with the Companies Commission of Malaysia (SSM).

What governance controls does the Lapasar platform enforce?

Procurement policies, multi-level approval workflows, budget controls, three-way matching between purchase order, goods-received note and invoice, and on-demand reporting over order and approval history. Controls are enforced at the point of purchase, on the platform itself.

Does Lapasar have an anti-bribery and corruption policy?

Yes. Lapasar publishes its Anti-Bribery & Anti-Corruption Policy, alongside its Whistleblowing Policy, Vendor Terms & Conditions, LapasarMall Terms & Conditions and Personal Data Protection Policy. All five documents are publicly readable on this site and downloadable as PDFs.

Does Lapasar have a whistleblowing channel?

Yes. Lapasar's board-approved Whistleblowing Policy provides confidential channels — including anonymous reporting — open to employees and to external parties such as suppliers, vendors, logistics partners and clients, with protection against retaliation for good-faith reports. The policy supports Lapasar's obligations and defences under Section 17A of the Malaysian Anti-Corruption Commission Act 2009 and is guided by the principles of the Whistleblower Protection Act 2011.

Can Lapasar complete our vendor due-diligence questionnaire?

Yes. The usual checklist items are documented publicly: company registration (Lapasar Sdn Bhd, 1198228-D, verifiable with SSM), Ministry of Finance supplier registration, and published policies covering anti-bribery, whistleblowing, personal data protection and vendor conduct — each readable in full with a downloadable PDF. Supporting documents are shared on request during vendor onboarding.

Can our auditors get a purchase audit trail from Lapasar?

Yes. Because requisitions, approvals, purchase orders, goods-received notes and invoices all live on one platform, the full document chain for any purchase is reportable on demand through dynamic reporting.

Continue your due diligence

See the operational proof on why trust Lapasar, browse the client list, review the platform’s full feature set or read how Lapasar connects to your systems on the integrations hub.

Send us your vendor questionnaire

Book a demo and bring your compliance checklist — registrations, policies, controls and references. We’re happy to be verified.

Prefer to talk to a real person?

Our team replies fast on WhatsApp and email — no forms, no waiting.