Procurement Audit Checklist: 20 Controls Auditors Check
Table of contents
Procurement Audit Checklist: 20 Controls CFOs and Auditors Look For

Procurement Audit Checklist: 20 Controls CFOs and Auditors Look For

Every company's money leaves through procurement. That single fact explains why internal audit, external auditors and the CFO's own team return to the function more often than to almost any other, and why a procurement audit checklist is less a compliance exercise than a description of how the company protects its cash.

This guide lists the 20 controls auditors actually test, grouped into six categories, then explains the findings that recur, why decentralized functions struggle more than centralized ones, and how to stop preparing for audits and start being ready for them.

Why Procurement Is a Top Audit-Risk Area

A procurement audit checklist is a structured list of the controls, records, and evidence an auditor examines to confirm that purchasing is authorized, competitive, contracted, received, and paid correctly. It typically covers policy compliance, approval workflows, supplier due diligence, contract compliance, savings validation, and segregation of duties.

Three things make procurement a standing audit priority. The money is large: it is the biggest controllable cost base in most companies. The decisions are discretionary: someone chooses the supplier, sets the price and approves the invoice, and each of those is a point where judgement can be wrong or bought. And the evidence is fragmented: request, approval, contract, order, receipt and invoice often live in different systems or none.

The Association of Certified Fraud Examiners’ 2026 Report to the Nations puts the median loss per occupational fraud case at about USD 104,000, with corruption schemes, which include bribery, kickbacks and conflicts of interest in purchasing, present in around 45 percent of cases.

The Association for Financial Professionals’ 2026 Payments Fraud and Control Survey found that 76 percent of US organizations faced attempted or actual payments fraud in 2025, and 74 percent were hit by business email compromise, the category that includes supplier bank-detail changes. Each of those schemes runs through a control on the list below.

The Six Categories Every Procurement Audit Covers

Auditors organize their work programme by control objective, and the six below appear in nearly every one.

CategoryControl objectiveWhat the auditor is really asking
Policy compliancePurchases follow the company’s procurement policyIs there a policy, does anyone follow it, and how would you know?
Approval workflowsEvery commitment is authorized at the right level before it is madeCan a purchase be made without approval, and has it been?
Supplier due diligenceSuppliers are vetted, approved and monitoredCould a fake or conflicted supplier get paid?
Contract compliancePurchases reference contracts and pay contracted pricesIs the company paying what it agreed, and buying from whom it agreed?
Savings validationReported savings are real and traceableWould finance recognize this saving in the P&L?
Segregation of dutiesNo one person controls request, approval, receipt and paymentCould one person buy, receive and pay without a second pair of eyes?

The 20-Item Procurement Audit Checklist

Each item is phrased as the auditor’s test. If the answer requires a search through email, count it as a finding.

Policy compliance

  • A current, approved procurement policy exists, with a version date and an owner.
  • Thresholds for competitive quotes and tenders are defined by value and applied.
  • Exceptions to policy are documented with a reason, an approver and a date.

Approval workflows

  • Every purchase order carries the approvals required for its value and category before issue.
  • Approval limits are configured in the system, not held in a spreadsheet.
  • Retroactive purchase orders, raised after the invoice, are measured and below an agreed rate.
  • Approval compliance above threshold is tested on the full population, not a sample.

Supplier due diligence

  • New suppliers pass a documented onboarding check: legal entity, ownership, sanctions, tax status.
  • Supplier bank details are verified out of band and changes require dual approval.
  • The supplier master is deduplicated and each record carries an active status.
  • Conflicts of interest are declared and reviewed for staff involved in supplier selection.

Contract compliance

  • Every purchase above threshold references a contract or a documented sourcing decision.
  • Invoice prices are matched to contract prices, with variances routed for review.
  • Contract expiry and renewal dates are tracked by the system and actioned before auto-renewal.

Savings validation

  • Each reported saving states its baseline, method and the transaction it is measured on.
  • Savings are reconciled with finance and recognized on the same basis finance uses.
  • Realized savings are distinguished from negotiated savings and from cost avoidance.

Segregation of duties

  • The person who raises a request cannot approve it.
  • The person who approves a purchase cannot confirm receipt or release payment for it.
  • System access rights enforce the separations above, and the access list is reviewed periodically.
Procurement audit checklist of 20 controls across six categories

Common Audit Findings and Their Root Causes

The findings repeat because their causes do. Most trace to three.

FindingUsual root causeWhat fixes it
Purchases without a PO, or PO raised after invoiceManual request path; PO seen as paperworkPO required by the system before commitment; no PO, no payment
Approvals missing or below required levelLimits in a document, not in the workflowThresholds configured in the system; email approvals not accepted
Supplier paid with no onboarding recordOnboarding done by whoever needed the supplierOnboarding workflow with mandatory checks before a supplier can receive a PO
Invoice price above contract priceNo link between contract and invoiceContract prices stored as data; automated price match at invoice
Savings unsupported by evidenceBaseline undefined; savings counted at negotiationSavings recorded against contract, PO and invoice; finance sign-off
One user with request, approve and receive rightsSmall team, roles combined for convenienceRole design enforced in system access; compensating review where headcount is thin
Exceptions undocumentedExceptions handled by phoneException workflow with reason and approver captured

The first cause is manual process: wherever a step happens in email, the record is optional. The second is exception handling: policies cover the normal case and are silent on the urgent one, so urgency becomes the bypass. The third is tail spend: small purchases across many suppliers, individually beneath notice, collectively the largest population of uncontrolled transactions.

“Every override is a liability. All the company’s money flows through procurement.”

Mauricio Dezen, VP Professional Services and Customer Success, APSentra, on the Behind Procurement LinkedIn Live

Audit Readiness in Centralized vs Decentralized Operating Models

The checklist is the same in both models. The difficulty is not.

A centralized function has one policy, one system and one set of thresholds, so a control either exists or does not. Findings tend to be about coverage: the tail, the subsidiaries, the categories that bypass procurement.

A decentralized function has several of everything. The auditor tests the same control in each unit and finds it enforced in some, documented in others and absent in the rest. Findings tend to be about consistency, and the remediation is harder because it means aligning entities that chose their own processes for reasons that seemed good at the time.

Deloitte’s 2025 Global Chief Procurement Officer Survey found that 57 percent of CPOs cite siloed ways of working as their leading barrier to delivering value. From an audit perspective, a silo is a place where a control can differ, and every difference is a test the function may fail.

The practical answer for decentralized groups is a shared control layer over local execution: one approval framework, one supplier onboarding standard and one savings definition, applied through a system that each entity uses, with local flexibility on categories and suppliers. Our analysis of CFO-CPO alignment covers why finance usually has to sponsor that layer.

How to Stay Audit-Ready Year-Round

Preparing for an audit is what functions do when the record is not already there. Being ready is a property of the process.

Make the record a by-product, not a task. If the request, approval, order, receipt and invoice are created in one system as the work happens, the audit trail exists without anyone assembling it. If any step lives in email, someone will be reconstructing it in the week before the audit.

Test controls on the full population, continuously. Retroactive PO rate, approval compliance above threshold, invoices without a contract reference and supplier records without an onboarding check can all be measured every month on every transaction. An auditor sampling 30 transactions finds what the function should have found first.

Close exceptions inside the workflow. Urgent purchases will happen. The control is not to forbid them but to route them through an exception path that records the reason, the approver and the follow-up, so that the exception is a documented decision rather than a gap.

Reconcile savings with finance quarterly. A savings figure that finance first sees at audit time will be challenged at audit time. Agree the definition and the evidence once, then report on that basis every quarter.

Our analysis of why procurement ROI fails CFO scrutiny covers the savings side in detail; the rest of the checklist follows the same logic. The control that exists in the system needs no preparation.

Audit-prepared versus audit-ready procurement: reconstructed records versus records created in the workflow

The Role of Governance Software in a Live Audit Trail

Most of the 20 items reduce to one requirement: the control and the evidence of the control must be produced by the same action. A source-to-pay platform does this when it is configured to.

Approval thresholds enforced at request block the unauthorized commitment and log the authorized one. Supplier onboarding workflows refuse a PO to a supplier that has not passed the checks, and record who passed them. Contract prices held as data allow the invoice match that catches overbilling. Role-based access enforces segregation of duties without a manager remembering to. And selection rationale captured at award answers the auditor’s most common question, why this supplier, without a search.

The pattern across APSentra client cases is that the audit conversation changes shape once this is in place: from “can you find it” to “show me the exceptions”, which is the conversation a function wants to be having. Where the platform is not yet in place, our comparison of when a team needs a consultant and when it needs a better system helps decide the order.

APSentra audit trail showing approval history, supplier selection rationale and exception log

Turn the checklist into a standing control.

APSentra enforces key controls in the workflow, creating the audit trail as work happens.
Book a Demo

    Don’t miss an article

    Get the latest procurement and spend management insights in your inbox.
    By submitting your information, you agree to our Terms of Service and Privacy Policy.
    Written by:
    Aps entra
    Eugene Ponomarov
    [email protected] Former procurement leader at Vodafone with extensive experience in strategic sourcing and enterprise procurement transformation. Drives APSentra's product strategy, combining deep procurement expertise with practical industry insight. Works closely with customers and partners to ensure the platform evolves around real business needs and emerging procurement trends.

    FAQs

    01.

    What should be included in a procurement audit checklist?

    Controls across six categories: policy compliance, approval workflows, supplier due diligence, contract compliance, savings validation and segregation of duties. For each control, the checklist should state the test, the evidence that satisfies it and the population it applies to. A checklist that lists controls without evidence requirements produces a tick-box exercise rather than an audit.

    02.

    What are the most common procurement audit findings?

    Purchases without a purchase order or with one raised after the invoice, approvals missing or below the required level, suppliers paid without an onboarding record, invoice prices above contract prices, savings claims without a baseline, and a single user holding request, approval and receipt rights. Almost all trace back to manual steps, undocumented exceptions or unmanaged tail spend.

    03.

    How often should a procurement audit be conducted?

    A full internal audit annually is the common standard, with external audit coverage as part of the financial statement audit. The more useful cadence is continuous monitoring of the measurable controls, monthly, with the annual audit confirming that the monitoring works. Functions that only test controls annually discover a year’s worth of exceptions at once.

    04.

    What is the difference between a procurement audit and a compliance review?

    A compliance review checks whether a specific policy or regulation was followed, often narrowly and in response to a trigger. A procurement audit tests the full control framework, including whether the policies themselves are adequate and whether the evidence supports the reported results, especially savings. A function can pass a compliance review and fail an audit on savings validation or segregation of duties.

    05.

    How can procurement stay audit-ready year-round?

    Create the record in the workflow rather than assembling it afterwards, measure the key controls on every transaction every month, route urgent purchases through a documented exception path, and reconcile savings with finance quarterly. If the audit trail is a by-product of doing the work in one system, audit preparation stops being a project.

    06.

    What documentation do auditors typically request for procurement?

    The procurement policy with its approval history, the delegation of authority matrix, a full purchase order listing with approvals, supplier onboarding records and bank-detail change logs, contracts with pricing schedules, invoice-to-PO-to-receipt matching results, the savings register with baselines and finance sign-off, the exception log, and the system access list showing who can request, approve, receive and pay.