Using AI and the S.P.I.N. Method During a Procure-to-Pay Audit Walkthrough
- John C. Blackshire, Jr.

- 2 hours ago
- 14 min read
Better Walkthroughs Begin with Better Questions—and Better Documentation
A procure-to-pay walkthrough can easily become a routine exercise.
The external auditor selects one purchase transaction, asks an employee to explain the process, follows the transaction from requisition through payment, and documents the controls encountered along the way.
That approach may satisfy the basic mechanics of a walkthrough. It does not necessarily give the auditor a complete understanding of how the process actually operates.
The strongest walkthroughs go beyond asking:
Who approved the purchase?
Was a purchase order created?
Was the invoice matched?
Who released the payment?
Those questions establish what happened to one transaction. They may not reveal:
How exceptions are handled
Where employees use manual workarounds
Which controls are frequently bypassed
Whether management can detect unauthorized activity
How system-generated information is validated
Where fraud or financial-reporting risk is concentrated
Whether the selected transaction reflects normal processing
A more effective approach combines three professional tools:
The external auditor’s risk-and-control methodology
The S.P.I.N. questioning method
An approved artificial intelligence tool that records, transcribes, and summarizes the discussion
Used correctly, this combination can produce a deeper process understanding, more precise follow-up questions, and clearer audit workpapers.
Used carelessly, it can produce an impressive-looking summary that omits contradictory information, misstates what the client said, or creates confidentiality and documentation problems.
The AI tool should support the auditor.
It should never replace professional skepticism, corroborating evidence, or the auditor’s responsibility for the final workpaper.
Why the Procure-to-Pay Process Deserves a Strong Walkthrough
The procure-to-pay process connects purchasing decisions with the eventual disbursement of cash.
Depending on the organization, the process may include:
Identification of a purchasing need
Purchase requisition
Budget verification
Approval
Vendor selection
Purchase-order creation
Receipt of goods or services
Invoice receipt
Matching and exception resolution
Payment approval
Payment execution
General-ledger recording
Reconciliation and monitoring
Weaknesses anywhere in that sequence may create exposure to:
Unauthorized purchases
Fictitious vendors
Conflicts of interest
Duplicate payments
Inflated invoices
Payments for goods not received
Fraudulent vendor-bank changes
Business email compromise
Improper expense classification
Management override
Cutoff errors
Unrecorded liabilities
The walkthrough therefore should not be treated merely as process documentation.
It is an important risk-assessment procedure.
PCAOB AS 2110 explains that walkthroughs may help an auditor understand the flow of transactions, evaluate control design, and determine whether controls have been implemented. The standard also emphasizes using probing questions that go beyond the single transaction selected for the walkthrough.
That requirement is where S.P.I.N. questioning becomes especially useful.
What Is the S.P.I.N. Questioning Method?
S.P.I.N. is commonly associated with consultative selling, but its structure is highly applicable to audit interviews and walkthroughs.
The four categories are:
Situation
Problem
Implication
Need-payoff
For auditors, the method provides a disciplined progression from understanding the process to identifying weaknesses, assessing consequences, and discussing what stronger control performance would accomplish.
It helps the auditor avoid two common walkthrough failures:
Asking only factual process questions
Jumping to a conclusion before understanding the condition and its implications
Situation Questions: Establish How Procure-to-Pay Operates
Situation questions provide the factual foundation.
During a procure-to-pay walkthrough, the auditor might ask:
How does an employee initiate a purchase?
Which purchases require a purchase requisition?
Who approves the requisition?
How are approval limits established?
Which system creates the purchase order?
Who can create or modify a vendor?
How are goods or services documented as received?
How does the system match purchase orders, receiving records, and invoices?
Who resolves matching exceptions?
How are payment files prepared and released?
Which reports does management review?
What changed in the process during the year?
These questions help the auditor understand:
Roles
Systems
Transaction flow
Control points
Evidence
Responsibility
Recent changes
However, the auditor should not spend the entire meeting gathering information already contained in policies, narratives, prior-year workpapers, or system documentation.
AI can assist before the meeting by reviewing available materials and identifying which facts are already documented and which matters still require clarification.
Problem Questions: Identify Where the Process Breaks Down
Problem questions move the walkthrough beyond the official process description.
Examples include:
Which purchasing steps create the most delays?
When are purchases made without a purchase order?
What types of matching exceptions occur most frequently?
Where do employees rely on manual workarounds?
Which vendor changes are most difficult to authenticate?
When can one employee perform more than one incompatible function?
Which reports are difficult to reconcile?
What happens when receiving information is incomplete?
Which control is most difficult to perform consistently?
Where does actual practice differ from written policy?
What problems occurred after the most recent system change?
Which transactions require management override?
These questions often reveal the real process.
A policy may require a three-way match.
The walkthrough may reveal that invoices for professional services are routinely processed without receiving records.
The system may require purchase orders.
The client may explain that emergency purchases are processed through email and entered after the fact.
The procedure may require independent vendor authentication.
Accounts Payable may explain that callbacks are skipped when a payment is urgent.
Those exceptions are not side issues.
They may represent the highest-risk parts of the process.
Implication Questions: Connect the Weakness to Audit Risk
New auditors frequently identify a control problem without exploring what it could mean.
Implication questions connect the process weakness to financial-reporting, fraud, compliance, and operational consequences.
Examples include:
What happens when an invoice is processed without a purchase order?
Could the same person create a vendor and approve a payment?
How could a fraudulent bank-account change remain undetected?
What prevents an invoice from being paid twice?
Could unmatched invoices remain outside the accounting records at period-end?
How would management identify purchases intentionally divided to avoid approval limits?
What happens when a receiving discrepancy is not resolved?
Could an employee approve an invoice for a related vendor?
How would a delayed invoice affect the completeness of accrued liabilities?
What is the potential effect if system access is not removed promptly?
Could management override the control without appearing on an exception report?
These questions help the auditor determine why the issue matters.
They also help connect the walkthrough to relevant assertions, including:
Occurrence
Completeness
Accuracy
Cutoff
Classification
Authorization
The objective is not to frighten the client or manufacture a finding during the meeting.
It is to understand the possible consequences well enough to design appropriate audit responses.
Need-Payoff Questions: Understand What Stronger Controls Would Achieve
The final S.P.I.N. category focuses on the benefit of improvement.
For an external auditor, this does not mean becoming responsible for designing management’s controls.
It means understanding management’s perspective, possible compensating controls, and the practical value of stronger control performance.
Questions might include:
How would automated duplicate-invoice detection improve the process?
Would independent vendor-change verification reduce the risk of fraudulent payments?
What information would help management identify unmatched invoices sooner?
How would a complete purchase-order exception report improve oversight?
Would clearer responsibility for receiving documentation reduce processing delays?
What control would help identify purchases divided below approval thresholds?
How would stronger access monitoring reduce segregation-of-duties risk?
What would management need to implement a more consistent review process?
These questions may reveal:
Existing corrective-action plans
Resource constraints
Alternative controls
Planned system improvements
Management’s understanding of the risk
Whether management considers the current exposure acceptable
The external auditor still evaluates whether the controls provide sufficient support for the planned audit approach.
Management remains responsible for the process and its controls.
Following One Transaction Is Not Enough
A walkthrough usually uses one or more transactions to trace the process.
That transaction is a vehicle for understanding the system. It is not necessarily representative of every transaction type.
PCAOB AS 2110 specifically recognizes the value of probing beyond the single transaction used in a walkthrough.
The auditor should therefore ask how the process differs for:
Purchase-order and non-purchase-order invoices
Goods and professional services
Routine and emergency purchases
Domestic and international vendors
Recurring payments
Employee reimbursements
Purchasing-card transactions
High-dollar transactions
Related-party vendors
Manual payments
Wire transfers and ACH payments
Vendor-bank changes
An AI-generated transcript can help identify where the discussion shifted among transaction types and whether the final workpaper adequately distinguishes them.
How an AI Tool Can Support the Walkthrough
With proper authorization and safeguards, an AI-enabled meeting tool may assist by:
Recording the walkthrough
Creating a time-stamped transcript
Identifying speakers
Summarizing the process
Extracting stated controls
Listing systems and reports discussed
Identifying control owners
Capturing exceptions and workarounds
Producing a preliminary action-item list
Drafting follow-up questions
Comparing the conversation with the process narrative
Preparing an initial workpaper outline
This can reduce the risk that the auditor misses an important statement while simultaneously taking notes, following the demonstration, and preparing the next question.
It can also help preserve the sequence of the walkthrough.
For example, the AI may organize the conversation into:
Requisition and approval
Vendor onboarding
Purchase-order creation
Receipt of goods
Invoice matching
Exception processing
Payment authorization
Payment release
General-ledger posting
Monitoring and reconciliation
That structure can make the auditor’s subsequent documentation more efficient.
But the transcript and summary are not automatically audit evidence.
The AI Transcript Is a Record of the Conversation—not Proof the Control Operated
An employee may state:
“All new vendor-bank accounts are independently verified.”
The AI tool can accurately record that statement.
The statement does not prove that the control operated.
The auditor may still need to:
Inspect vendor-change documentation
Observe the verification process
Review system workflow
Reperform selected procedures
Test a sample of changes
Evaluate relevant access rights
Inspect exception reports
Corroborate the explanation with other personnel
The AI transcript answers:
What did the person say?
The audit work must answer:
What does the evidence demonstrate?
Converting the AI Summary into an Audit Workpaper
The most effective use of AI is to create a preliminary draft that the auditor reviews, corrects, and supports with evidence.
A procure-to-pay walkthrough workpaper might include the following sections.
Purpose
Document the auditor’s understanding of the procure-to-pay transaction flow and evaluate the design and implementation of controls relevant to identified risks.
Participants
Identify:
Auditor
Process owner
Accounts Payable personnel
Purchasing personnel
Information technology personnel
Other attendees
Transaction Selected
Document:
Requisition number
Purchase-order number
Vendor
Invoice number
Payment number
Date
Amount
Selection rationale
Process Flow
Summarize each stage from initiation through general-ledger posting.
Systems and Reports
Identify:
ERP application
Purchasing application
Vendor-management system
Banking platform
Interfaces
Exception reports
Management review reports
Relevant Risks
Examples:
Unauthorized purchases
Fictitious vendors
Duplicate payments
Incorrect coding
Unrecorded liabilities
Improper cutoff
Fraudulent bank changes
Controls Identified
For each control, document:
Control owner
Frequency
Evidence
System dependency
Risk addressed
Whether the control is manual, automated, or IT-dependent
Exceptions and Workarounds
Document circumstances in which the normal process changes.
Evidence Inspected
Identify the actual records viewed during the walkthrough.
Contradictory Information
Document statements or evidence inconsistent with the auditor’s preliminary understanding or conclusion.
Preliminary Conclusion
State whether the walkthrough supports the auditor’s understanding of:
Transaction flow
Control design
Control implementation
Areas requiring additional procedures
A Practical AI Prompt for the Workpaper Draft
After the meeting, the auditor could provide the approved transcript to an authorized AI tool with an instruction such as:
Act as an experienced external auditor documenting a procure-to-pay walkthrough. Using only the attached transcript, prepare a draft workpaper containing: Meeting purpose Participants Process stages Systems and reports discussed Identified financial-reporting and fraud risks Controls described by management Control owners and frequencies Evidence viewed Exceptions and manual workarounds Contradictory or ambiguous statements Follow-up evidence requests Unresolved questions Clearly distinguish: Statements made by company personnel Evidence the auditor inspected Preliminary auditor observations Matters requiring corroboration Do not conclude that a control operated effectively based only on inquiry. Do not invent missing facts. Quote the transcript timestamp supporting each important point.
This prompt creates useful guardrails.
It tells the tool not to convert management’s statements into unsupported audit conclusions.
Use AI to Identify Missing Follow-Up Questions
The AI tool can also review the transcript for unanswered questions.
A useful instruction is:
Identify statements containing vague terms such as “usually,” “normally,” “generally,” “most of the time,” “automatically,” or “management reviews.” For each statement, prepare follow-up questions addressing control ownership, frequency, evidence, exceptions, monitoring, system dependency, and override.
This can expose language that requires further investigation.
For example:
Client statement
“The system automatically prevents duplicate invoices.”
AI-assisted follow-up questions
Which fields does the duplicate check compare?
Can users override the warning?
Are invoice-number formatting differences detected?
Does the control operate across business units?
Are credit memos included?
Is an override report reviewed?
Who can change the system configuration?
What evidence demonstrates that the control operated?
The auditor decides which questions are relevant and performs the necessary procedures.
Use AI to Compare the Interview with Existing Documentation
A valuable post-walkthrough procedure is comparing the transcript with:
Policies
Process narratives
Flowcharts
Risk-control matrices
Prior-year workpapers
System documentation
The AI tool can identify statements such as:
The policy requires two approvals, but the walkthrough describes one.
The narrative says all invoices use purchase orders, but the client describes a non-PO process.
The control matrix assigns vendor maintenance to Purchasing, while the walkthrough assigns it to Accounts Payable.
The prior-year workpaper describes a manual report that has since been automated.
The process owner describes an exception control not included in the control matrix.
These differences do not automatically represent deficiencies.
They indicate that the auditor’s understanding or the company’s documentation may require updating.
AI Output Must Be Verified Against the Source
Generative AI can:
Omit context
Combine separate statements
Assign a statement to the wrong speaker
Interpret uncertainty as fact
Produce a polished but unsupported conclusion
Fail to recognize sarcasm or correction
Misunderstand technical terminology
Drop contradictory information
The auditor should therefore reconcile the draft summary to:
The recording
The transcript
Notes
Documents viewed
Screenshots
System reports
Follow-up communications
PCAOB AS 1215 requires documentation to show the procedures performed, evidence obtained, conclusions reached, and the individuals who performed and reviewed the work. It also requires enough information for an experienced auditor with no prior connection to understand the work.
An unreviewed AI summary does not satisfy that responsibility.
The auditor owns the workpaper.
Do Not Let AI Remove Contradictory Evidence
AI summarization tools tend to create a clean, coherent narrative.
Audits are not always clean or coherent.
During a walkthrough:
Purchasing may say Accounts Payable validates vendors.
Accounts Payable may say Purchasing performs the validation.
The system administrator may say the process is automated.
The process owner may describe a manual spreadsheet.
The policy may assign responsibility to someone else entirely.
The final summary should not smooth these contradictions into a single description.
Contradictory evidence may identify:
Unclear control ownership
Inconsistent performance
Documentation gaps
Process changes
Potential control deficiencies
The AI prompt should specifically require preservation of inconsistent statements and attribution to the appropriate speaker.
Protect Client Confidentiality
A procure-to-pay walkthrough may include sensitive information, including:
Vendor names
Bank-account information
Pricing
Employee identities
Contract terms
System configurations
Access rights
Fraud concerns
Security procedures
Before recording or using an AI tool, the engagement team should:
Obtain express authorization
Follow the audit firm’s approved technology policy
Follow the client’s recording and confidentiality requirements
Use only authorized enterprise tools
Determine where recordings and transcripts are stored
Restrict access
Establish retention and deletion requirements
Redact unnecessary sensitive information
Consider applicable legal and contractual requirements
Address the use of third-party AI subprocessors
The fact that a meeting platform can record and summarize a discussion does not mean the auditor is authorized to use that capability.
Decide Whether the Recording Belongs in the Audit File
The engagement team should determine in advance:
Whether the recording will be retained
Whether only the verified transcript will be retained
Whether the final workpaper will replace the temporary AI draft
How long temporary files will exist
Who may access them
Whether they contain information outside the audit scope
Whether firm policy or legal requirements affect retention
Audit documentation may exist in electronic or other media, but its content and retention must remain controlled. PCAOB AS 1215 requires audit documentation to be retained for the applicable period and organized to provide clear support for the auditor’s conclusions.
Automatically retaining every recording indefinitely may create more risk than value.
The Workpaper Must Document What the Auditor Did
A transcript demonstrates that a conversation occurred.
It does not necessarily demonstrate that the auditor:
Evaluated the responses
Inspected the relevant evidence
Identified risks
Assessed control design
Followed up on contradictions
Reached an appropriate conclusion
The workpaper should therefore document the auditor’s work, not merely attach a recording.
PCAOB guidance emphasizes that an audit program or other record should not stand alone as the sole documentation that a procedure was performed and a conclusion reached. Clear documentation improves supervision, review, and audit quality.
The AI-generated materials are inputs.
The auditor’s analyzed and reviewed workpaper is the deliverable.
Example: Vendor-Bank Change Walkthrough
Consider a walkthrough involving a recent vendor-bank change.
Situation Questions
Who received the request?
How was it submitted?
Who entered the change?
Who approved it?
Which system retained the history?
When was the next payment issued?
Problem Questions
Are requests ever received by email?
What happens when the usual vendor contact is unavailable?
Can an urgent payment proceed before verification?
Can one employee enter and approve the change?
Are rejected or overridden changes monitored?
Implication Questions
Could a threat actor redirect a vendor payment?
Would the bank file identify that the account was newly changed?
How quickly would the organization detect the fraud?
Could similar weaknesses affect customer refunds or payroll changes?
What financial-statement accounts could be affected?
Need-Payoff Questions
How would a mandatory independent callback reduce the risk?
Would a payment hold after a bank change provide additional protection?
How would an exception dashboard improve management oversight?
What control would prevent verification using contact information contained in the request?
AI-Assisted Documentation
The AI transcript could identify:
The participants’ descriptions
The system screens demonstrated
The stated verification procedure
The manager’s acknowledgment of an emergency override
The evidence viewed
Follow-up items
The auditor would then inspect the records and determine whether the control was designed, implemented, and—when required by the engagement—operating effectively.
The Benefits of Combining S.P.I.N., Walkthroughs, and AI
When properly governed, this approach can help external auditors:
Ask more purposeful questions
Explore exception processing
Reduce incomplete meeting notes
Preserve the sequence of the walkthrough
Identify contradictory statements
Prepare clearer workpapers
Generate better follow-up requests
Connect process facts to financial-reporting risks
Improve reviewability
Spend more time listening and less time typing
The greatest benefit is not faster documentation.
It is a better understanding of the process.
Efficiency has value only when audit quality is preserved or improved.
Common Mistakes to Avoid
Treating the AI Summary as the Workpaper
The summary is a draft, not the final audit documentation.
Treating Client Statements as Control Evidence
Inquiry must be corroborated when the auditor is evaluating control effectiveness or financial-statement assertions.
Recording Without Authorization
The engagement team must follow firm, client, legal, contractual, and confidentiality requirements.
Failing to Identify the Walkthrough Transaction
The workpaper should identify the transaction and documents inspected.
Allowing AI to Resolve Contradictions
Conflicting statements should be retained and investigated.
Asking Only Situation Questions
A walkthrough that merely describes the process may fail to identify problems and implications.
Ignoring Exceptions
The process used for routine transactions may not apply to the highest-risk transactions.
Failing to Validate Reports
System-generated reports used during the walkthrough or subsequent testing must be evaluated for relevance and reliability. PCAOB standards require sufficient appropriate evidence, and recent amendments further emphasize evaluating electronic information used in the audit.
Better Questions Produce Better Audit Evidence
The purpose of a procure-to-pay walkthrough is not to prepare a perfect flowchart.
It is to understand:
How transactions enter the process
How they are authorized
How the organization prevents or detects error and fraud
How information reaches the accounting records
How exceptions and overrides are handled
Which controls are relevant to the audit
Where additional procedures are required
S.P.I.N. provides the questioning structure.
AI can provide recording, transcription, organization, and preliminary analysis.
The external auditor provides the essential elements that neither tool can replace:
Professional skepticism
Audit judgment
Evidence evaluation
Risk assessment
Accountability for the conclusion
The future of auditing will involve greater use of AI-assisted documentation.
But the principle will remain unchanged:
The auditor must get beyond what management says, determine what the evidence demonstrates, and prepare workpapers that clearly support the conclusion.
Frequently Asked Questions
Can an external auditor use AI to record a walkthrough?
An auditor may use an approved AI-enabled recording or transcription tool when authorized by the firm and client and permitted under applicable confidentiality, contractual, and legal requirements. The engagement team should establish access, storage, retention, and review procedures before recording.
Is an AI transcript audit evidence?
A transcript records statements made during the walkthrough and may support documentation of inquiry. It does not independently prove that a control operated or that a financial-statement assertion is correct. Inquiry generally requires corroboration through other audit procedures.
What does S.P.I.N. mean?
S.P.I.N. stands for Situation, Problem, Implication, and Need-payoff. The sequence helps auditors understand the process, identify control problems, explore their consequences, and discuss what stronger performance would accomplish.
Why use S.P.I.N. during a procure-to-pay walkthrough?
It prevents the walkthrough from becoming a narrow checklist exercise. S.P.I.N. helps the auditor explore exceptions, workarounds, management overrides, fraud risks, and the financial-reporting implications of control weaknesses.
What should the walkthrough workpaper contain?
It should identify the purpose, participants, transaction selected, documents inspected, process stages, systems, risks, controls, evidence, exceptions, unresolved questions, procedures performed, and preliminary conclusions. PCAOB documentation requirements emphasize enough detail for an experienced auditor to understand the work and conclusions.
Can the auditor place the AI summary directly into the workpapers?
Not without review. The auditor should verify it against the transcript, recording, notes, and inspected evidence; correct errors; preserve contradictory information; perform follow-up procedures; and document the auditor’s own conclusion.
Comments