Auditing Procure-to-Pay: Follow the Money From Purchase Request to Final Payment
- John C. Blackshire, Jr.

- 1 day ago
- 5 min read
The Procure-to-Pay cycle is one of the largest, most complicated and most fraud-prone business processes in most organizations.
It touches procurement, operations, receiving, accounts payable, treasury, accounting, information technology and third-party management. A control failure at any point can result in overpayments, duplicate payments, unauthorized purchases, vendor fraud, supply-chain disruption or financial-reporting errors.
Corporate Compliance Seminars’ Auditing Procure-to-Pay webinar gives internal auditors, accountants and compliance professionals a practical approach to evaluating the entire P2P cycle—from identifying a business need through issuing the final payment.
What Is the Procure-to-Pay Cycle?
Procure-to-Pay includes the connected activities used to purchase and pay for goods and services:
Identifying the business requirement
Selecting and approving the vendor
Creating the purchase requisition
Approving the purchase
Issuing the purchase order
Receiving the goods or services
Reviewing the vendor invoice
Matching supporting documents
Approving the payment
Disbursing the funds
Recording the transaction
Monitoring vendor performance
Auditors should evaluate the cycle as an integrated process. Reviewing procurement without examining accounts payable—or examining payments without understanding vendor onboarding—can leave serious risks undetected.
The Vendor Master File Is the Front Door
Many P2P frauds begin with the vendor master file.
If employees can create or change vendors without independent review, they may establish fictitious companies, redirect legitimate payments or conceal conflicts of interest.
Strong vendor-master controls should address:
Independent approval of new vendors
Verification of tax-identification information
Validation of addresses and banking instructions
Duplicate-vendor detection
Conflict-of-interest disclosures
Sanctions and exclusion screening
Beneficial-ownership information
Approval of banking changes
Periodic removal of inactive vendors
Audit trails for all additions and modifications
Vendor creation should be separated from invoice approval and payment processing. An employee who can create a vendor, enter an invoice and release a payment can commit and conceal fraud without assistance.
Vendor Banking Changes Require Special Attention
Business email compromise and payment-diversion fraud frequently involve fraudulent requests to change a vendor’s banking information.
A convincing email is not sufficient evidence.
Management should independently verify banking changes using previously established contact information—not the telephone number or email address contained in the change request.
Auditors should test whether:
Requests are authenticated independently
Changes require secondary approval
The system retains the former banking information
Notifications are sent to the vendor’s established contact
Payments to recently changed accounts receive additional review
Employees are trained to recognize social-engineering attempts
Weak vendor-change controls can convert an ordinary invoice into a major financial loss.
Purchase Orders and Unauthorized Commitments
Purchase orders establish what the organization agreed to buy, from whom, at what price and under what terms.
Auditors should look for:
Purchases made without purchase orders
Purchase orders created after invoices arrive
Repeated emergency purchases
Excessive use of blanket purchase orders
Purchases split to avoid approval limits
Approvals by employees without proper authority
Pricing that differs from contracts
Purchases outside preferred-vendor arrangements
Unused or overdue open purchase orders
A purchase order created after the goods have been received is not a preventive control. It is paperwork documenting a commitment that has already occurred.
Receiving Controls Matter
Organizations should pay only for goods and services they actually received.
Receiving controls should provide reliable evidence concerning:
The quantity received
The condition of the goods
The date of receipt
The person confirming receipt
Differences from the purchase order
Returned or rejected items
Services completed
Service invoices present a particular challenge because there may be no physical goods to count. The person approving a service invoice should understand the work performed and have evidence that contract requirements were met.
“Services rendered” is not adequate documentation for a significant payment.
Three-Way Matching
A traditional three-way match compares:
The purchase order
The receiving record
The vendor invoice
The system should identify differences in quantity, price, terms, taxes, freight and other charges before payment.
Auditors should evaluate:
Matching tolerances
Who can approve exceptions
How often tolerances are overridden
Whether the same employee creates and resolves exceptions
Whether invoices below certain thresholds bypass matching
Whether system changes to match rules are authorized
Whether unmatched invoices remain unresolved
A matching control may exist in the system but still fail if tolerances are excessive or overrides are routine.
Common Procure-to-Pay Fraud Schemes
The P2P cycle creates opportunities for both internal and external fraud.
Auditors should consider schemes involving:
Fictitious vendors
Conflicts of interest
Kickbacks and bribery
Duplicate invoices
Altered invoices
Inflated prices
Payments for goods not received
False service invoices
Personal purchases
Bid manipulation
Purchase splitting
Unauthorized vendor-bank changes
Shell companies
Employee-vendor address matches
Payments to former or inactive vendors
Collusion among employees and suppliers
Fraud risk increases when one employee controls several stages of the transaction or when a senior manager can override normal procedures without independent review.
Data Analytics for the Vendor Master File
Auditors should not limit their work to small judgmental samples. P2P data can be tested across the entire population.
Useful vendor-master tests include searches for:
Duplicate vendor names
Duplicate tax-identification numbers
Duplicate bank accounts
Vendors sharing employee addresses
Vendors sharing employee telephone numbers
Multiple vendors using the same mailing address
Post-office-box addresses
Vendors with incomplete tax information
Inactive vendors receiving new payments
Vendors created shortly before their first payment
Multiple changes to banking information
Changes made immediately before payment runs
These tests do not prove fraud. They identify transactions and relationships requiring investigation.
Accounts Payable Data Tests
Auditors can also analyze invoices and payments for:
Duplicate invoice numbers
Duplicate payment amounts
Invoices just below approval thresholds
Round-dollar payments
Weekend or holiday transactions
Payments without purchase orders
Manual checks
Rush payments
Repeated matching overrides
Payments made outside normal payment runs
Excessive credit memos
Sequential invoice numbers from the same vendor
Payments exceeding contract limits
Payments issued after vendor-bank changes
Unclaimed early-payment discounts
Patterns can reveal control failures that individual transaction testing will miss.
Supply-Chain and Third-Party Risk
Procurement is not solely responsible for obtaining the lowest price. It must also consider whether vendors can reliably, legally and securely provide the required goods or services.
Vendor risk assessments may address:
Financial condition
Operational capacity
Cybersecurity
Data privacy
Regulatory compliance
Geographic concentration
Sanctions exposure
Business continuity
Subcontractor dependence
Ethical sourcing
Insurance coverage
Contractual obligations
The lowest-cost vendor may become the most expensive choice if it cannot deliver, mishandles sensitive data or creates regulatory exposure.
P2P Auditing Should Improve the Business
A P2P audit should do more than identify policy violations. It should also identify opportunities to reduce administrative costs and improve processing speed.
Auditors should evaluate:
Purchase-order cycle time
Invoice-processing time
Percentage of spending under contract
Percentage of invoices processed automatically
Number of manual transactions
Frequency of matching exceptions
Duplicate-payment recoveries
Early-payment discounts captured
Vendor concentration
Cost per invoice
Number of vendors with minimal annual spending
World-class procurement functions standardize processes, consolidate appropriate spending, manage vendors actively and use automation without sacrificing control.
What Participants Will Learn
The Auditing Procure-to-Pay webinar addresses:
The complete P2P cycle
Procurement and accounts-payable controls
Purchase requisitions and purchase orders
Receiving and invoice approval
Three-way matching
Segregation of duties
Vendor onboarding and maintenance
Vendor-master-file auditing
Forensic vendor-data analysis
Supply-chain and third-party risk
Common P2P fraud schemes
Payment controls
Process improvement and cost reduction
An accounts-payable audit case study
The program is designed for internal auditors, accountants, compliance professionals, procurement personnel, accounts-payable leaders and finance managers.
Attend the Live Webinar
Auditing Procure-to-Pay
Available dates:
Friday, October 9, 2026
Friday, December 11, 2026
Time: 10:00 a.m.–2:30 p.m. Central Time
Private training may also be scheduled for groups of two or more attendees.
The organization’s money leaves through the P2P process. Internal auditors need to determine whether purchases are authorized, vendors are legitimate, goods and services are received, invoices are accurate and payments reach the correct parties. Anything less leaves the door open to waste, error and fraud.
Comments