top of page
Search

Using AI and the S.P.I.N. Method During a Procure-to-Pay Audit Walkthrough

Better Walkthroughs Begin with Better Questions—and Better Documentation

A procure-to-pay walkthrough can easily become a routine exercise.


The external auditor selects one purchase transaction, asks an employee to explain the process, follows the transaction from requisition through payment, and documents the controls encountered along the way.


That approach may satisfy the basic mechanics of a walkthrough. It does not necessarily give the auditor a complete understanding of how the process actually operates.


The strongest walkthroughs go beyond asking:

  • Who approved the purchase?

  • Was a purchase order created?

  • Was the invoice matched?

  • Who released the payment?


Those questions establish what happened to one transaction. They may not reveal:

  • How exceptions are handled

  • Where employees use manual workarounds

  • Which controls are frequently bypassed

  • Whether management can detect unauthorized activity

  • How system-generated information is validated

  • Where fraud or financial-reporting risk is concentrated

  • Whether the selected transaction reflects normal processing


A more effective approach combines three professional tools:

  1. The external auditor’s risk-and-control methodology

  2. The S.P.I.N. questioning method

  3. An approved artificial intelligence tool that records, transcribes, and summarizes the discussion


Used correctly, this combination can produce a deeper process understanding, more precise follow-up questions, and clearer audit workpapers.


Used carelessly, it can produce an impressive-looking summary that omits contradictory information, misstates what the client said, or creates confidentiality and documentation problems.


The AI tool should support the auditor.


It should never replace professional skepticism, corroborating evidence, or the auditor’s responsibility for the final workpaper.


Why the Procure-to-Pay Process Deserves a Strong Walkthrough

The procure-to-pay process connects purchasing decisions with the eventual disbursement of cash.


Depending on the organization, the process may include:

  1. Identification of a purchasing need

  2. Purchase requisition

  3. Budget verification

  4. Approval

  5. Vendor selection

  6. Purchase-order creation

  7. Receipt of goods or services

  8. Invoice receipt

  9. Matching and exception resolution

  10. Payment approval

  11. Payment execution

  12. General-ledger recording

  13. Reconciliation and monitoring


Weaknesses anywhere in that sequence may create exposure to:

  • Unauthorized purchases

  • Fictitious vendors

  • Conflicts of interest

  • Duplicate payments

  • Inflated invoices

  • Payments for goods not received

  • Fraudulent vendor-bank changes

  • Business email compromise

  • Improper expense classification

  • Management override

  • Cutoff errors

  • Unrecorded liabilities


The walkthrough therefore should not be treated merely as process documentation.


It is an important risk-assessment procedure.


PCAOB AS 2110 explains that walkthroughs may help an auditor understand the flow of transactions, evaluate control design, and determine whether controls have been implemented. The standard also emphasizes using probing questions that go beyond the single transaction selected for the walkthrough.


That requirement is where S.P.I.N. questioning becomes especially useful.


What Is the S.P.I.N. Questioning Method?

S.P.I.N. is commonly associated with consultative selling, but its structure is highly applicable to audit interviews and walkthroughs.


The four categories are:

  • Situation

  • Problem

  • Implication

  • Need-payoff


For auditors, the method provides a disciplined progression from understanding the process to identifying weaknesses, assessing consequences, and discussing what stronger control performance would accomplish.


It helps the auditor avoid two common walkthrough failures:

  • Asking only factual process questions

  • Jumping to a conclusion before understanding the condition and its implications


Situation Questions: Establish How Procure-to-Pay Operates

Situation questions provide the factual foundation.


During a procure-to-pay walkthrough, the auditor might ask:

  • How does an employee initiate a purchase?

  • Which purchases require a purchase requisition?

  • Who approves the requisition?

  • How are approval limits established?

  • Which system creates the purchase order?

  • Who can create or modify a vendor?

  • How are goods or services documented as received?

  • How does the system match purchase orders, receiving records, and invoices?

  • Who resolves matching exceptions?

  • How are payment files prepared and released?

  • Which reports does management review?

  • What changed in the process during the year?


These questions help the auditor understand:

  • Roles

  • Systems

  • Transaction flow

  • Control points

  • Evidence

  • Responsibility

  • Recent changes


However, the auditor should not spend the entire meeting gathering information already contained in policies, narratives, prior-year workpapers, or system documentation.


AI can assist before the meeting by reviewing available materials and identifying which facts are already documented and which matters still require clarification.


Problem Questions: Identify Where the Process Breaks Down

Problem questions move the walkthrough beyond the official process description.


Examples include:

  • Which purchasing steps create the most delays?

  • When are purchases made without a purchase order?

  • What types of matching exceptions occur most frequently?

  • Where do employees rely on manual workarounds?

  • Which vendor changes are most difficult to authenticate?

  • When can one employee perform more than one incompatible function?

  • Which reports are difficult to reconcile?

  • What happens when receiving information is incomplete?

  • Which control is most difficult to perform consistently?

  • Where does actual practice differ from written policy?

  • What problems occurred after the most recent system change?

  • Which transactions require management override?


These questions often reveal the real process.


A policy may require a three-way match.


The walkthrough may reveal that invoices for professional services are routinely processed without receiving records.


The system may require purchase orders.


The client may explain that emergency purchases are processed through email and entered after the fact.


The procedure may require independent vendor authentication.


Accounts Payable may explain that callbacks are skipped when a payment is urgent.


Those exceptions are not side issues.


They may represent the highest-risk parts of the process.


Implication Questions: Connect the Weakness to Audit Risk

New auditors frequently identify a control problem without exploring what it could mean.


Implication questions connect the process weakness to financial-reporting, fraud, compliance, and operational consequences.


Examples include:

  • What happens when an invoice is processed without a purchase order?

  • Could the same person create a vendor and approve a payment?

  • How could a fraudulent bank-account change remain undetected?

  • What prevents an invoice from being paid twice?

  • Could unmatched invoices remain outside the accounting records at period-end?

  • How would management identify purchases intentionally divided to avoid approval limits?

  • What happens when a receiving discrepancy is not resolved?

  • Could an employee approve an invoice for a related vendor?

  • How would a delayed invoice affect the completeness of accrued liabilities?

  • What is the potential effect if system access is not removed promptly?

  • Could management override the control without appearing on an exception report?


These questions help the auditor determine why the issue matters.


They also help connect the walkthrough to relevant assertions, including:

  • Occurrence

  • Completeness

  • Accuracy

  • Cutoff

  • Classification

  • Authorization


The objective is not to frighten the client or manufacture a finding during the meeting.


It is to understand the possible consequences well enough to design appropriate audit responses.


Need-Payoff Questions: Understand What Stronger Controls Would Achieve

The final S.P.I.N. category focuses on the benefit of improvement.


For an external auditor, this does not mean becoming responsible for designing management’s controls.


It means understanding management’s perspective, possible compensating controls, and the practical value of stronger control performance.


Questions might include:

  • How would automated duplicate-invoice detection improve the process?

  • Would independent vendor-change verification reduce the risk of fraudulent payments?

  • What information would help management identify unmatched invoices sooner?

  • How would a complete purchase-order exception report improve oversight?

  • Would clearer responsibility for receiving documentation reduce processing delays?

  • What control would help identify purchases divided below approval thresholds?

  • How would stronger access monitoring reduce segregation-of-duties risk?

  • What would management need to implement a more consistent review process?


These questions may reveal:

  • Existing corrective-action plans

  • Resource constraints

  • Alternative controls

  • Planned system improvements

  • Management’s understanding of the risk

  • Whether management considers the current exposure acceptable


The external auditor still evaluates whether the controls provide sufficient support for the planned audit approach.


Management remains responsible for the process and its controls.


Following One Transaction Is Not Enough

A walkthrough usually uses one or more transactions to trace the process.


That transaction is a vehicle for understanding the system. It is not necessarily representative of every transaction type.


PCAOB AS 2110 specifically recognizes the value of probing beyond the single transaction used in a walkthrough.


The auditor should therefore ask how the process differs for:

  • Purchase-order and non-purchase-order invoices

  • Goods and professional services

  • Routine and emergency purchases

  • Domestic and international vendors

  • Recurring payments

  • Employee reimbursements

  • Purchasing-card transactions

  • High-dollar transactions

  • Related-party vendors

  • Manual payments

  • Wire transfers and ACH payments

  • Vendor-bank changes


An AI-generated transcript can help identify where the discussion shifted among transaction types and whether the final workpaper adequately distinguishes them.


How an AI Tool Can Support the Walkthrough

With proper authorization and safeguards, an AI-enabled meeting tool may assist by:

  • Recording the walkthrough

  • Creating a time-stamped transcript

  • Identifying speakers

  • Summarizing the process

  • Extracting stated controls

  • Listing systems and reports discussed

  • Identifying control owners

  • Capturing exceptions and workarounds

  • Producing a preliminary action-item list

  • Drafting follow-up questions

  • Comparing the conversation with the process narrative

  • Preparing an initial workpaper outline


This can reduce the risk that the auditor misses an important statement while simultaneously taking notes, following the demonstration, and preparing the next question.


It can also help preserve the sequence of the walkthrough.


For example, the AI may organize the conversation into:

  1. Requisition and approval

  2. Vendor onboarding

  3. Purchase-order creation

  4. Receipt of goods

  5. Invoice matching

  6. Exception processing

  7. Payment authorization

  8. Payment release

  9. General-ledger posting

  10. Monitoring and reconciliation


That structure can make the auditor’s subsequent documentation more efficient.


But the transcript and summary are not automatically audit evidence.


The AI Transcript Is a Record of the Conversation—not Proof the Control Operated

An employee may state:

“All new vendor-bank accounts are independently verified.”

The AI tool can accurately record that statement.


The statement does not prove that the control operated.



The auditor may still need to:

  • Inspect vendor-change documentation

  • Observe the verification process

  • Review system workflow

  • Reperform selected procedures

  • Test a sample of changes

  • Evaluate relevant access rights

  • Inspect exception reports

  • Corroborate the explanation with other personnel


The AI transcript answers:

What did the person say?

The audit work must answer:

What does the evidence demonstrate?

Converting the AI Summary into an Audit Workpaper

The most effective use of AI is to create a preliminary draft that the auditor reviews, corrects, and supports with evidence.


A procure-to-pay walkthrough workpaper might include the following sections.


Purpose

Document the auditor’s understanding of the procure-to-pay transaction flow and evaluate the design and implementation of controls relevant to identified risks.


Participants

Identify:

  • Auditor

  • Process owner

  • Accounts Payable personnel

  • Purchasing personnel

  • Information technology personnel

  • Other attendees


Transaction Selected

Document:

  • Requisition number

  • Purchase-order number

  • Vendor

  • Invoice number

  • Payment number

  • Date

  • Amount

  • Selection rationale



Process Flow

Summarize each stage from initiation through general-ledger posting.


Systems and Reports

Identify:

  • ERP application

  • Purchasing application

  • Vendor-management system

  • Banking platform

  • Interfaces

  • Exception reports

  • Management review reports


Relevant Risks

Examples:

  • Unauthorized purchases

  • Fictitious vendors

  • Duplicate payments

  • Incorrect coding

  • Unrecorded liabilities

  • Improper cutoff

  • Fraudulent bank changes


Controls Identified

For each control, document:

  • Control owner

  • Frequency

  • Evidence

  • System dependency

  • Risk addressed

  • Whether the control is manual, automated, or IT-dependent


Exceptions and Workarounds

Document circumstances in which the normal process changes.


Evidence Inspected

Identify the actual records viewed during the walkthrough.


Contradictory Information

Document statements or evidence inconsistent with the auditor’s preliminary understanding or conclusion.



Preliminary Conclusion

State whether the walkthrough supports the auditor’s understanding of:

  • Transaction flow

  • Control design

  • Control implementation

  • Areas requiring additional procedures


A Practical AI Prompt for the Workpaper Draft

After the meeting, the auditor could provide the approved transcript to an authorized AI tool with an instruction such as:

Act as an experienced external auditor documenting a procure-to-pay walkthrough. Using only the attached transcript, prepare a draft workpaper containing: Meeting purpose Participants Process stages Systems and reports discussed Identified financial-reporting and fraud risks Controls described by management Control owners and frequencies Evidence viewed Exceptions and manual workarounds Contradictory or ambiguous statements Follow-up evidence requests Unresolved questions Clearly distinguish: Statements made by company personnel Evidence the auditor inspected Preliminary auditor observations Matters requiring corroboration Do not conclude that a control operated effectively based only on inquiry. Do not invent missing facts. Quote the transcript timestamp supporting each important point.

This prompt creates useful guardrails.


It tells the tool not to convert management’s statements into unsupported audit conclusions.


Use AI to Identify Missing Follow-Up Questions

The AI tool can also review the transcript for unanswered questions.


A useful instruction is:

Identify statements containing vague terms such as “usually,” “normally,” “generally,” “most of the time,” “automatically,” or “management reviews.” For each statement, prepare follow-up questions addressing control ownership, frequency, evidence, exceptions, monitoring, system dependency, and override.

This can expose language that requires further investigation.


For example:

Client statement

“The system automatically prevents duplicate invoices.”

AI-assisted follow-up questions

  • Which fields does the duplicate check compare?

  • Can users override the warning?

  • Are invoice-number formatting differences detected?

  • Does the control operate across business units?

  • Are credit memos included?

  • Is an override report reviewed?

  • Who can change the system configuration?

  • What evidence demonstrates that the control operated?


The auditor decides which questions are relevant and performs the necessary procedures.


Use AI to Compare the Interview with Existing Documentation

A valuable post-walkthrough procedure is comparing the transcript with:

  • Policies

  • Process narratives

  • Flowcharts

  • Risk-control matrices

  • Prior-year workpapers

  • System documentation


The AI tool can identify statements such as:

  • The policy requires two approvals, but the walkthrough describes one.

  • The narrative says all invoices use purchase orders, but the client describes a non-PO process.

  • The control matrix assigns vendor maintenance to Purchasing, while the walkthrough assigns it to Accounts Payable.

  • The prior-year workpaper describes a manual report that has since been automated.

  • The process owner describes an exception control not included in the control matrix.


These differences do not automatically represent deficiencies.


They indicate that the auditor’s understanding or the company’s documentation may require updating.


AI Output Must Be Verified Against the Source

Generative AI can:

  • Omit context

  • Combine separate statements

  • Assign a statement to the wrong speaker

  • Interpret uncertainty as fact

  • Produce a polished but unsupported conclusion

  • Fail to recognize sarcasm or correction

  • Misunderstand technical terminology

  • Drop contradictory information


The auditor should therefore reconcile the draft summary to:

  • The recording

  • The transcript

  • Notes

  • Documents viewed

  • Screenshots

  • System reports

  • Follow-up communications


PCAOB AS 1215 requires documentation to show the procedures performed, evidence obtained, conclusions reached, and the individuals who performed and reviewed the work. It also requires enough information for an experienced auditor with no prior connection to understand the work.


An unreviewed AI summary does not satisfy that responsibility.

The auditor owns the workpaper.


Do Not Let AI Remove Contradictory Evidence

AI summarization tools tend to create a clean, coherent narrative.


Audits are not always clean or coherent.


During a walkthrough:

  • Purchasing may say Accounts Payable validates vendors.

  • Accounts Payable may say Purchasing performs the validation.

  • The system administrator may say the process is automated.

  • The process owner may describe a manual spreadsheet.

  • The policy may assign responsibility to someone else entirely.


The final summary should not smooth these contradictions into a single description.


Contradictory evidence may identify:

  • Unclear control ownership

  • Inconsistent performance

  • Documentation gaps

  • Process changes

  • Potential control deficiencies


The AI prompt should specifically require preservation of inconsistent statements and attribution to the appropriate speaker.


Protect Client Confidentiality

A procure-to-pay walkthrough may include sensitive information, including:

  • Vendor names

  • Bank-account information

  • Pricing

  • Employee identities

  • Contract terms

  • System configurations

  • Access rights

  • Fraud concerns

  • Security procedures


Before recording or using an AI tool, the engagement team should:

  • Obtain express authorization

  • Follow the audit firm’s approved technology policy

  • Follow the client’s recording and confidentiality requirements

  • Use only authorized enterprise tools

  • Determine where recordings and transcripts are stored

  • Restrict access

  • Establish retention and deletion requirements

  • Redact unnecessary sensitive information

  • Consider applicable legal and contractual requirements

  • Address the use of third-party AI subprocessors


The fact that a meeting platform can record and summarize a discussion does not mean the auditor is authorized to use that capability.


Decide Whether the Recording Belongs in the Audit File

The engagement team should determine in advance:

  • Whether the recording will be retained

  • Whether only the verified transcript will be retained

  • Whether the final workpaper will replace the temporary AI draft

  • How long temporary files will exist

  • Who may access them

  • Whether they contain information outside the audit scope

  • Whether firm policy or legal requirements affect retention


Audit documentation may exist in electronic or other media, but its content and retention must remain controlled. PCAOB AS 1215 requires audit documentation to be retained for the applicable period and organized to provide clear support for the auditor’s conclusions.


Automatically retaining every recording indefinitely may create more risk than value.


The Workpaper Must Document What the Auditor Did

A transcript demonstrates that a conversation occurred.


It does not necessarily demonstrate that the auditor:

  • Evaluated the responses

  • Inspected the relevant evidence

  • Identified risks

  • Assessed control design

  • Followed up on contradictions

  • Reached an appropriate conclusion


The workpaper should therefore document the auditor’s work, not merely attach a recording.


PCAOB guidance emphasizes that an audit program or other record should not stand alone as the sole documentation that a procedure was performed and a conclusion reached. Clear documentation improves supervision, review, and audit quality.

The AI-generated materials are inputs.


The auditor’s analyzed and reviewed workpaper is the deliverable.


Example: Vendor-Bank Change Walkthrough

Consider a walkthrough involving a recent vendor-bank change.


Situation Questions

  • Who received the request?

  • How was it submitted?

  • Who entered the change?

  • Who approved it?

  • Which system retained the history?

  • When was the next payment issued?


Problem Questions

  • Are requests ever received by email?

  • What happens when the usual vendor contact is unavailable?

  • Can an urgent payment proceed before verification?

  • Can one employee enter and approve the change?

  • Are rejected or overridden changes monitored?


Implication Questions

  • Could a threat actor redirect a vendor payment?

  • Would the bank file identify that the account was newly changed?

  • How quickly would the organization detect the fraud?

  • Could similar weaknesses affect customer refunds or payroll changes?

  • What financial-statement accounts could be affected?


Need-Payoff Questions

  • How would a mandatory independent callback reduce the risk?

  • Would a payment hold after a bank change provide additional protection?

  • How would an exception dashboard improve management oversight?

  • What control would prevent verification using contact information contained in the request?


AI-Assisted Documentation

The AI transcript could identify:

  • The participants’ descriptions

  • The system screens demonstrated

  • The stated verification procedure

  • The manager’s acknowledgment of an emergency override

  • The evidence viewed

  • Follow-up items


The auditor would then inspect the records and determine whether the control was designed, implemented, and—when required by the engagement—operating effectively.


The Benefits of Combining S.P.I.N., Walkthroughs, and AI

When properly governed, this approach can help external auditors:

  • Ask more purposeful questions

  • Explore exception processing

  • Reduce incomplete meeting notes

  • Preserve the sequence of the walkthrough

  • Identify contradictory statements

  • Prepare clearer workpapers

  • Generate better follow-up requests

  • Connect process facts to financial-reporting risks

  • Improve reviewability

  • Spend more time listening and less time typing


The greatest benefit is not faster documentation.


It is a better understanding of the process.


Efficiency has value only when audit quality is preserved or improved.


Common Mistakes to Avoid

Treating the AI Summary as the Workpaper

The summary is a draft, not the final audit documentation.


Treating Client Statements as Control Evidence

Inquiry must be corroborated when the auditor is evaluating control effectiveness or financial-statement assertions.


Recording Without Authorization

The engagement team must follow firm, client, legal, contractual, and confidentiality requirements.


Failing to Identify the Walkthrough Transaction

The workpaper should identify the transaction and documents inspected.


Allowing AI to Resolve Contradictions

Conflicting statements should be retained and investigated.


Asking Only Situation Questions

A walkthrough that merely describes the process may fail to identify problems and implications.


Ignoring Exceptions

The process used for routine transactions may not apply to the highest-risk transactions.


Failing to Validate Reports

System-generated reports used during the walkthrough or subsequent testing must be evaluated for relevance and reliability. PCAOB standards require sufficient appropriate evidence, and recent amendments further emphasize evaluating electronic information used in the audit.


Better Questions Produce Better Audit Evidence

The purpose of a procure-to-pay walkthrough is not to prepare a perfect flowchart.


It is to understand:

  • How transactions enter the process

  • How they are authorized

  • How the organization prevents or detects error and fraud

  • How information reaches the accounting records

  • How exceptions and overrides are handled

  • Which controls are relevant to the audit

  • Where additional procedures are required


S.P.I.N. provides the questioning structure.


AI can provide recording, transcription, organization, and preliminary analysis.


The external auditor provides the essential elements that neither tool can replace:

  • Professional skepticism

  • Audit judgment

  • Evidence evaluation

  • Risk assessment

  • Accountability for the conclusion


The future of auditing will involve greater use of AI-assisted documentation.


But the principle will remain unchanged:

The auditor must get beyond what management says, determine what the evidence demonstrates, and prepare workpapers that clearly support the conclusion.

Frequently Asked Questions

Can an external auditor use AI to record a walkthrough?

An auditor may use an approved AI-enabled recording or transcription tool when authorized by the firm and client and permitted under applicable confidentiality, contractual, and legal requirements. The engagement team should establish access, storage, retention, and review procedures before recording.


Is an AI transcript audit evidence?

A transcript records statements made during the walkthrough and may support documentation of inquiry. It does not independently prove that a control operated or that a financial-statement assertion is correct. Inquiry generally requires corroboration through other audit procedures.


What does S.P.I.N. mean?

S.P.I.N. stands for Situation, Problem, Implication, and Need-payoff. The sequence helps auditors understand the process, identify control problems, explore their consequences, and discuss what stronger performance would accomplish.


Why use S.P.I.N. during a procure-to-pay walkthrough?

It prevents the walkthrough from becoming a narrow checklist exercise. S.P.I.N. helps the auditor explore exceptions, workarounds, management overrides, fraud risks, and the financial-reporting implications of control weaknesses.


What should the walkthrough workpaper contain?

It should identify the purpose, participants, transaction selected, documents inspected, process stages, systems, risks, controls, evidence, exceptions, unresolved questions, procedures performed, and preliminary conclusions. PCAOB documentation requirements emphasize enough detail for an experienced auditor to understand the work and conclusions.


Can the auditor place the AI summary directly into the workpapers?

Not without review. The auditor should verify it against the transcript, recording, notes, and inspected evidence; correct errors; preserve contradictory information; perform follow-up procedures; and document the auditor’s own conclusion.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page