
How to Audit Procurement & Purchase-to-Pay
A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free

Cover the key procurement controls: supplier due diligence and competitive sourcing, approved requisitions and POs, evidenced receipt, invoice matching, and monitoring for split spend, duplicates and bank changes.
Procurement controls often look sound on paper while exceptions quietly become normal practice: purchase orders raised after the invoice, single-source purchases without justification, or supplier bank changes nobody independently checked. This checklist is a fieldwork aid for finding where practice and procedure diverge.
Use it when preparing interviews, structuring testing and documenting the areas that need deeper evidence in a procurement or purchase-to-pay audit. It is organized in three groups of checks. Supplier and sourcing covers due diligence at onboarding, conflict-of-interest declarations, competitive sourcing and justification for single-source or emergency purchases. Purchase-to-pay covers requisition approval before commitment, approval limits against delegated authority, POs created before receipt or invoice, evidenced receipt of goods and services, and invoice matching and tolerance rules. Monitoring and red flags covers analysis of spend below approval thresholds for splitting, duplicate invoices and payments, PO changes after approval, independent verification of supplier bank changes, and reporting of repeated exceptions.
Each point is marked Done, Review or N/A, and a ticked box should mean the point was supported by evidence, not simply asked. Risk prompts push you to ask where one person can initiate, change and approve the same outcome, and which data patterns would show control bypass. The evidence-to-retain list and completion page help you close the work with a documented conclusion.
© Salih Ahmed Islam

A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free

Check supplier creation, changes and maintenance: sponsored and validated vendors, maker-checker approval, independently verified bank changes, complete change logs, blocked dormant vendors and employee/vendor overlaps.
PDF • 6 Pages • Free

Build a practical risk and control matrix that links each business objective and risk to its control, owner, frequency and evidence, then records the planned test and conclusion.
PDF • 6 Pages • Free

Match each risk to a practical data test, the fields it needs and whether it suits one-off audit work or continuous monitoring.
PDF • 6 Pages • Free