
How to Audit Procurement & Purchase-to-Pay
A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free
Every internal audit should consider fraud, but few auditors have a practical method for doing it. Fraud rarely looks like fraud at first; it appears as an unusual payment, a supplier bank change nobody verified, or an employee whose access was never removed. The auditor's job is not to prove fraud, but to identify where the organization is exposed and whether controls would prevent or detect it.
Auditors reviewing fraud risk usually examine who can initiate, approve and conceal transactions, how management override is monitored, which processes involve cash or easily diverted payments, and how incidents and whistleblowing reports are handled. High-exposure areas include procurement, vendor master data, payroll, travel and expenses, inventory and retail operations.
Common weaknesses include fraud risk assessments that list generic risks without specific scenarios, controls that depend on one person, weak verification of bank-detail changes, and data analytics that are never used to look across whole populations for red flags.
The resources below bring fraud thinking into everyday audit work. Use the guides to assess fraud risk and audit high-exposure processes, the checklists to review scenarios, controls and red flags, and the templates to document fraud risk assessments and supplier due diligence. They are designed for practicing auditors, not specialist investigators.
18 free resources · No registration

A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free

How to audit travel and expenses beyond receipts — policy design, approval quality, spend analytics and behavior patterns such as split claims and unusual taxi or hotel usage.
PDF • 6 Pages • Free

Identify where opportunity, pressure and weak oversight create fraud exposure — mapping who can initiate, approve and conceal transactions, then testing the most plausible fraud scenarios.
PDF • 6 Pages • Free

Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free

Audit payroll from employee changes and time data to calculation and payment — testing joiners, leavers and one-off payments, reconciling to the ledger and analyzing ghost-employee indicators.
PDF • 6 Pages • Free

Cover the key procurement controls: supplier due diligence and competitive sourcing, approved requisitions and POs, evidenced receipt, invoice matching, and monitoring for split spend, duplicates and bank changes.
PDF • 6 Pages • Free

Check supplier creation, changes and maintenance: sponsored and validated vendors, maker-checker approval, independently verified bank changes, complete change logs, blocked dormant vendors and employee/vendor overlaps.
PDF • 6 Pages • Free

Review travel and expense controls end to end — realistic policy limits, pre-trip approval, complete receipts, substantive approver review, and analytics for duplicates, personal extensions and repeated overrides.
PDF • 6 Pages • Free

Check payroll from employee master data to payment: approved hires and changes, timely leaver removal, validated overtime and adjustments, reconciliations, independently approved payment files and reviewed system access.
PDF • 6 Pages • Free

Verify invoice processing and payment controls — controlled receipt, PO/receipt matching, justified non-PO invoices, independently reviewed payment runs, and analytics for duplicates, threshold payments and recent bank changes.
PDF • 6 Pages • Free

Check that fraud risk is assessed properly: schemes identified by process and asset, override and collusion considered, controls mapped to each scenario, and red-flag analytics, whistleblowing and investigation protocols in place.
PDF • 6 Pages • Free

Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.
PDF • 6 Pages • Free

Check inventory controls from receipt to write-off: matched receipts, physical security, authorized transfers, independent cycle counts, approved adjustments and destruction, and analytics on unusual movements.
PDF • 6 Pages • Free

Audit store operations on site: cash counts and deposits, POS access, refunds, voids and discounts, inventory and shrink controls, price accuracy, staffing records, security and incident handling.
PDF • 6 Pages • Free

Assess fraud scenarios process by process, recording who could commit them, incentive, pressure and opportunity, preventive and detective controls, gaps and override risk, and the audit response.
PDF • 6 Pages • Free

Document vendor due diligence before onboarding: registration and beneficial ownership, conflicts, sanctions and adverse information, PEP and high-risk countries, bank verification, payment terms and risk classification.
PDF • 6 Pages • Free

Review a trip end to end: business purpose, pre-approval and policy limits, hotel, flight, taxi and meal testing, receipts, duplicates and personal spend, exception value and recovery action.
PDF • 6 Pages • Free