
How to Audit Procurement & Purchase-to-Pay
A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free
Organizations depend on suppliers and service providers for critical goods, services and systems. That dependence creates risk: unreliable suppliers, unverified bank details, weak contracts and outsourced services that nobody monitors. Vendor management audits help management understand whether these relationships are controlled across their full life cycle.
Auditors in this area typically review supplier selection and due diligence, vendor master data creation and changes, contract terms, service level agreements, performance monitoring, and the controls that apply when a relationship ends. For outsourced services, they also look at the assurance management receives from the provider.
Key risks include fictitious or duplicate vendors, bank-detail changes that are not independently verified, missing due diligence on high-risk suppliers, contracts without measurable service levels, and outsourced activities with no clear internal owner.
The resources below help you audit vendors from onboarding to performance monitoring. Use the vendor master data guide and checklist to test the supplier file, the due diligence template to document supplier reviews, and the third-party and SLA checklist to assess how outsourced services are governed.
6 free resources · No registration

A six-step approach to auditing purchase-to-pay — supplier onboarding and bank changes, approvals, three-way matching, and analytics for duplicates, split purchases and overrides.
PDF • 6 Pages • Free

Audit supplier creation and change controls — onboarding evidence, bank-account change verification, duplicate and dormant vendors, change logs and segregation of duties around master-data access.
PDF • 6 Pages • Free

Cover the key procurement controls: supplier due diligence and competitive sourcing, approved requisitions and POs, evidenced receipt, invoice matching, and monitoring for split spend, duplicates and bank changes.
PDF • 6 Pages • Free

Check supplier creation, changes and maintenance: sponsored and validated vendors, maker-checker approval, independently verified bank changes, complete change logs, blocked dormant vendors and employee/vendor overlaps.
PDF • 6 Pages • Free

Audit third-party arrangements: risk-based due diligence, contracts with data protection and audit rights, measurable and validated SLAs, applied penalties, continuity and exit plans, and dependency oversight.
PDF • 6 Pages • Free

Document vendor due diligence before onboarding: registration and beneficial ownership, conflicts, sanctions and adverse information, PEP and high-risk countries, bank verification, payment terms and risk classification.
PDF • 6 Pages • Free