top of page
Search

Auditing Procure-to-Pay: Follow the Money From Purchase Request to Final Payment

The Procure-to-Pay cycle is one of the largest, most complicated and most fraud-prone business processes in most organizations.


It touches procurement, operations, receiving, accounts payable, treasury, accounting, information technology and third-party management. A control failure at any point can result in overpayments, duplicate payments, unauthorized purchases, vendor fraud, supply-chain disruption or financial-reporting errors.


Corporate Compliance Seminars’ Auditing Procure-to-Pay webinar gives internal auditors, accountants and compliance professionals a practical approach to evaluating the entire P2P cycle—from identifying a business need through issuing the final payment.


What Is the Procure-to-Pay Cycle?

Procure-to-Pay includes the connected activities used to purchase and pay for goods and services:

  1. Identifying the business requirement

  2. Selecting and approving the vendor

  3. Creating the purchase requisition

  4. Approving the purchase

  5. Issuing the purchase order

  6. Receiving the goods or services

  7. Reviewing the vendor invoice

  8. Matching supporting documents

  9. Approving the payment

  10. Disbursing the funds

  11. Recording the transaction

  12. Monitoring vendor performance


Auditors should evaluate the cycle as an integrated process. Reviewing procurement without examining accounts payable—or examining payments without understanding vendor onboarding—can leave serious risks undetected.


The Vendor Master File Is the Front Door

Many P2P frauds begin with the vendor master file.


If employees can create or change vendors without independent review, they may establish fictitious companies, redirect legitimate payments or conceal conflicts of interest.


Strong vendor-master controls should address:

  • Independent approval of new vendors

  • Verification of tax-identification information

  • Validation of addresses and banking instructions

  • Duplicate-vendor detection

  • Conflict-of-interest disclosures

  • Sanctions and exclusion screening

  • Beneficial-ownership information

  • Approval of banking changes

  • Periodic removal of inactive vendors

  • Audit trails for all additions and modifications


Vendor creation should be separated from invoice approval and payment processing. An employee who can create a vendor, enter an invoice and release a payment can commit and conceal fraud without assistance.


Vendor Banking Changes Require Special Attention

Business email compromise and payment-diversion fraud frequently involve fraudulent requests to change a vendor’s banking information.


A convincing email is not sufficient evidence.


Management should independently verify banking changes using previously established contact information—not the telephone number or email address contained in the change request.


Auditors should test whether:

  • Requests are authenticated independently

  • Changes require secondary approval

  • The system retains the former banking information

  • Notifications are sent to the vendor’s established contact

  • Payments to recently changed accounts receive additional review

  • Employees are trained to recognize social-engineering attempts


Weak vendor-change controls can convert an ordinary invoice into a major financial loss.


Purchase Orders and Unauthorized Commitments

Purchase orders establish what the organization agreed to buy, from whom, at what price and under what terms.


Auditors should look for:

  • Purchases made without purchase orders

  • Purchase orders created after invoices arrive

  • Repeated emergency purchases

  • Excessive use of blanket purchase orders

  • Purchases split to avoid approval limits

  • Approvals by employees without proper authority

  • Pricing that differs from contracts

  • Purchases outside preferred-vendor arrangements

  • Unused or overdue open purchase orders


A purchase order created after the goods have been received is not a preventive control. It is paperwork documenting a commitment that has already occurred.


Receiving Controls Matter

Organizations should pay only for goods and services they actually received.


Receiving controls should provide reliable evidence concerning:

  • The quantity received

  • The condition of the goods

  • The date of receipt

  • The person confirming receipt

  • Differences from the purchase order

  • Returned or rejected items

  • Services completed


Service invoices present a particular challenge because there may be no physical goods to count. The person approving a service invoice should understand the work performed and have evidence that contract requirements were met.


“Services rendered” is not adequate documentation for a significant payment.


Three-Way Matching

A traditional three-way match compares:

  1. The purchase order

  2. The receiving record

  3. The vendor invoice


The system should identify differences in quantity, price, terms, taxes, freight and other charges before payment.


Auditors should evaluate:

  • Matching tolerances

  • Who can approve exceptions

  • How often tolerances are overridden

  • Whether the same employee creates and resolves exceptions

  • Whether invoices below certain thresholds bypass matching

  • Whether system changes to match rules are authorized

  • Whether unmatched invoices remain unresolved


A matching control may exist in the system but still fail if tolerances are excessive or overrides are routine.


Common Procure-to-Pay Fraud Schemes

The P2P cycle creates opportunities for both internal and external fraud.


Auditors should consider schemes involving:

  • Fictitious vendors

  • Conflicts of interest

  • Kickbacks and bribery

  • Duplicate invoices

  • Altered invoices

  • Inflated prices

  • Payments for goods not received

  • False service invoices

  • Personal purchases

  • Bid manipulation

  • Purchase splitting

  • Unauthorized vendor-bank changes

  • Shell companies

  • Employee-vendor address matches

  • Payments to former or inactive vendors

  • Collusion among employees and suppliers


Fraud risk increases when one employee controls several stages of the transaction or when a senior manager can override normal procedures without independent review.


Data Analytics for the Vendor Master File

Auditors should not limit their work to small judgmental samples. P2P data can be tested across the entire population.


Useful vendor-master tests include searches for:

  • Duplicate vendor names

  • Duplicate tax-identification numbers

  • Duplicate bank accounts

  • Vendors sharing employee addresses

  • Vendors sharing employee telephone numbers

  • Multiple vendors using the same mailing address

  • Post-office-box addresses

  • Vendors with incomplete tax information

  • Inactive vendors receiving new payments

  • Vendors created shortly before their first payment

  • Multiple changes to banking information

  • Changes made immediately before payment runs


These tests do not prove fraud. They identify transactions and relationships requiring investigation.


Accounts Payable Data Tests

Auditors can also analyze invoices and payments for:

  • Duplicate invoice numbers

  • Duplicate payment amounts

  • Invoices just below approval thresholds

  • Round-dollar payments

  • Weekend or holiday transactions

  • Payments without purchase orders

  • Manual checks

  • Rush payments

  • Repeated matching overrides

  • Payments made outside normal payment runs

  • Excessive credit memos

  • Sequential invoice numbers from the same vendor

  • Payments exceeding contract limits

  • Payments issued after vendor-bank changes

  • Unclaimed early-payment discounts


Patterns can reveal control failures that individual transaction testing will miss.


Supply-Chain and Third-Party Risk

Procurement is not solely responsible for obtaining the lowest price. It must also consider whether vendors can reliably, legally and securely provide the required goods or services.


Vendor risk assessments may address:

  • Financial condition

  • Operational capacity

  • Cybersecurity

  • Data privacy

  • Regulatory compliance

  • Geographic concentration

  • Sanctions exposure

  • Business continuity

  • Subcontractor dependence

  • Ethical sourcing

  • Insurance coverage

  • Contractual obligations


The lowest-cost vendor may become the most expensive choice if it cannot deliver, mishandles sensitive data or creates regulatory exposure.


P2P Auditing Should Improve the Business

A P2P audit should do more than identify policy violations. It should also identify opportunities to reduce administrative costs and improve processing speed.


Auditors should evaluate:

  • Purchase-order cycle time

  • Invoice-processing time

  • Percentage of spending under contract

  • Percentage of invoices processed automatically

  • Number of manual transactions

  • Frequency of matching exceptions

  • Duplicate-payment recoveries

  • Early-payment discounts captured

  • Vendor concentration

  • Cost per invoice

  • Number of vendors with minimal annual spending


World-class procurement functions standardize processes, consolidate appropriate spending, manage vendors actively and use automation without sacrificing control.


What Participants Will Learn

The Auditing Procure-to-Pay webinar addresses:

  • The complete P2P cycle

  • Procurement and accounts-payable controls

  • Purchase requisitions and purchase orders

  • Receiving and invoice approval

  • Three-way matching

  • Segregation of duties

  • Vendor onboarding and maintenance

  • Vendor-master-file auditing

  • Forensic vendor-data analysis

  • Supply-chain and third-party risk

  • Common P2P fraud schemes

  • Payment controls

  • Process improvement and cost reduction

  • An accounts-payable audit case study


The program is designed for internal auditors, accountants, compliance professionals, procurement personnel, accounts-payable leaders and finance managers.


Attend the Live Webinar


Auditing Procure-to-Pay


Available dates:

  • Friday, October 9, 2026

  • Friday, December 11, 2026

Time: 10:00 a.m.–2:30 p.m. Central Time


Private training may also be scheduled for groups of two or more attendees.



The organization’s money leaves through the P2P process. Internal auditors need to determine whether purchases are authorized, vendors are legitimate, goods and services are received, invoices are accurate and payments reach the correct parties. Anything less leaves the door open to waste, error and fraud.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page