Which control would catch it first if a vendor started overcharging your company today? This guide is for internal audit teams, procurement heads, and CFOs in India, and it shows you how to plan the audit, run the key tests, and fix the gaps that matter.
A procurement internal audit is an independent review of how your business selects suppliers, raises purchase orders, receives goods, and pays invoices. Its purpose is to surface leakage, fraud, and non-compliance before the statutory auditor does.
This guide explains how to audit the procurement process under Indian rules in 2026. It includes a procurement internal audit checklist, the main risks, and the controls that address them. It is written for internal audit teams, procurement heads, and CFOs.
Key Takeaways
- A procurement internal audit tests the whole purchase-to-pay chain: requisition, vendor selection, purchase order, receipt, invoice, and payment. Testing only the payment stage misses most of the risk.
- Billing schemes rank among the most significant occupational fraud risks in the ACFE’s Occupational Fraud 2026 report, and more than half of all cases studied involved a lack of internal controls or an override of existing controls.
- From 1 April 2026, the MSME payment rule sits in Section 37(2)(g) of the Income-tax Act, 2025, which corresponds to Section 43B(h) of the 1961 Act. Overdue balances to micro and small suppliers are therefore a tax exposure as well as a relationship risk.
- Three-way match is necessary but not sufficient. It proves documents agree; it does not prove the vendor was genuine or the price fair.
- Analyse 100% of transactions where data allows. Reserve sampling for evidence you must inspect physically.
What Does a Procurement Internal Audit Cover?
The scope runs from the moment someone needs something to the moment the ledger closes. Auditors test each stage against a specific risk.
Stage | Question the auditor asks | Typical evidence |
Requisition | Was the need approved by the right authority? | Requisition, budget approval |
Vendor selection | Was the choice competitive and documented? | Quotations, comparison sheet |
Purchase order | Was it raised before the commitment? | PO, delegation of authority matrix |
Receipt | Did goods or services actually arrive? | GRN, inspection report |
Invoice and payment | Was the right amount paid once, to the right party? | Invoice, bank advice, vendor ledger |
Why Does 2026 Change the Audit Agenda?
New fraud data, a rewritten Income-tax Act and stricter IIA standards all arrived within roughly 16 months of each other, so a procurement audit programme designed in 2024 is already out of date.
- Fraud benchmarks are fresh. The ACFE’s Occupational Fraud 2026 report analysed 2,402 cases across 143 countries, with a median loss of $104,000 per case.
- Tax law has moved. The Income-tax Act, 2025 came into force on 1 April 2026. For FY 2025-26, Section 43B(h) of the 1961 Act still applies. From Tax Year 2026-27, the same test runs under Section 37(2)(g).
- The standards have become more stringent. The IIA Global Internal Audit Standards (effective 9 January 2025) require that the audit plan be driven by risk and well-coordinated with other assurance providers.
Procurement audits that start from approved purchase orders miss the more revealing population: spend that never had one. We prefer to start from the general ledger and work backwards to the PO.
How to Audit the Procurement Process: 7 Steps
The seven steps run in the order fieldwork actually unfolds, from deciding which spend deserves attention to assigning an owner for every fix.
Step 1: Scope the Audit Using a Risk Assessment
- Rank spend categories by value, frequency, and supplier concentration.
- High-cost, single-source, and repeating classifications require further testing.
- Set out in writing the audit period, audit entities, and thresholds.
If you need a refresher on planning, see our guide on how an internal audit is conducted.
Step 2: Walk Through the Process and Map the Controls
Trace one transaction end to end. Interview requesters, buyers, store staff, and accounts payable. Compare what the policy says with what people actually do. That gap is usually where your first findings sit.
Step 3: Test Vendor Selection Controls and Supplier Due Diligence
Vendor selection controls
- Are competitive quotes obtained above a defined threshold?
- Is single-source buying justified in writing and approved by someone independent of the buyer?
- Are evaluation criteria fixed before quotes are opened?
Supplier due diligence
- Check GSTIN validity, PAN, bank account ownership and Udyam registration status.
- Screen for related-party links. Compare vendor addresses, bank accounts and phone numbers with employee master data.
- Confirm conflict-of-interest declarations exist for buyers and approvers.
Step 4: Complete a Purchase Order Review
A purchase order review checks timing, authority and accuracy. Test for:
- POs raised after the invoice date (retrospective approval)
- Multiple POs to one vendor just below an approval limit (split ordering)
- Approvers exceeding their delegated limits
- Rates that differ from contract or last-paid prices
Step 5: Run a Three-Way Match Audit
A three-way match audit compares the purchase order, goods receipt note, and vendor invoice before payment. Auditors test whether:
- The system enforces the match, or users can override it
- Tolerances (for example, price variance) are defined and approved
- Exceptions are cleared by someone independent of the buyer
Our view: Three-way match is table stakes. A fictitious vendor with a matching PO, GRN and invoice will pass it. Pair it with vendor master analytics.
Step 6: Test Contracts, Payments and MSME Compliance
- Check invoice rates against contract terms and escalation clauses.
- Look for duplicate payments, meaning the same vendor, amount and date, or invoice numbers that are nearly identical.
- Match the input tax credit you claimed to what suppliers actually filed, and confirm the 180-day payment condition was met.
MSME dues need the closest look. Under Section 15 of the MSMED Act, 2006, payment to micro and small suppliers is due within 15 days of acceptance or deemed acceptance of goods or services where there is no written agreement. Where there is one, the agreed period applies, capped at 45 days. Most Section 43B items allow payment by the return due date. This one doesn’t
Match the input tax credit you claimed to what suppliers actually filed, and confirm the 180-day payment condition under Section 16(2) of the CGST Act, 2017 was met.
Worked example:
A micro-enterprise supplier’s invoice is accepted on 1 March with no written agreement, so payment is due by 16 March. If it is still unpaid on 31 March, the expense is disallowed for that year and becomes deductible only in the year it is paid.
The rule covers only micro and small suppliers. Medium enterprises fall outside it, and so do suppliers whose Udyam certificate shows trading activity only. Check the Udyam certificate before ageing a balance
Step 7: Use Data Analytics, Report and Follow Up
Run full-population tests: Benford’s analysis, vendor concentration, weekend postings and round-sum invoices. Rate each finding by risk. Assign an owner and a date. Our note on internal audit reporting explains why reports without owners rarely change behaviour.
Which India-Specific Procurement Tests Do Generic Checklists Miss?
Three Indian checks are often missing from procurement audit programmes, and each can be run from ERP data.
1. Cash payments: Under Section 40A(3) of the Income-tax Act, 1961 (continued in the 2025 Act), a business expense paid in cash above ₹10,000 to one person in a day is disallowed in full. The limit is ₹35,000 for goods-carriage transporters.
Test: total cash payments by vendor and date, and look for clusters just under the limit.
2. TDS on purchases: Section 194Q of the 1961 Act now sits in Section 393(1), Table Sl. No. 8(ii) of the 2025 Act. A buyer with prior-year turnover above ₹10 crore deducts 0.1% on purchases from one seller above ₹50 lakh in the year, on the excess only.
Test: total purchases by seller, not by invoice, and confirm TDS was deducted once the threshold was crossed.
3. Related-party vendors:
Test: match the vendor master (names, addresses, bank accounts, PAN) to director and employee records, then compare the rates paid with those from unrelated vendors.
Thresholds and section numbers change with each amendment. Confirm them against the current Act before applying them.
What Should a Procurement Audit Checklist Include?
Use this procurement audit checklist as a starting point and adapt it to your risk profile.
Area | Key check | Red flag |
Policy | Approved procurement policy and delegation of authority | Policy older than the last restructuring |
Vendor master | Change log reviewed independently | Same person creates vendors and approves payments |
Vendor selection | Documented quotes and evaluation | Repeated single-source awards |
Purchase orders | PO precedes invoice | High share of retrospective POs |
Receipt | GRN by store, not buyer | Services paid without proof of delivery |
Invoice match | Tolerances enforced | Manual override of match exceptions |
Payments | Duplicate and split-payment tests | Payments to new vendors before onboarding checks |
MSME and tax | Ageing of micro and small dues | Dues crossing 45 days at year-end |
Audit trail | Audit trail enabled and unaltered, as Rule 3(1) of the Companies (Accounts) Rules, 2014 requires | Edit or delete logs disabled |
e-Invoicing | Validate the IRN on supplier invoices above the e-invoice threshold | Invoices with no IRN or a mismatched IRN |
ITC | Match purchase register to GSTR-2B | Credit claimed but missing from GSTR-2B |
What Are the Procurement Fraud Risks Auditors Should Test For?
Understanding procurement fraud risks helps you design tests that find them. The ACFE data above shows that tips detect 43% of cases, and schemes that run more than five years cause median losses above $1.1 million. Speed of detection matters.
Risk | How it works | Audit test |
Fictitious vendor | Fake supplier invoices are paid | Match vendor bank details to employee data |
Kickbacks | Buyer favours a vendor for a personal payoff | Award concentration by buyer and vendor |
Split orders | POs kept under approval limits | Clustered POs just below thresholds |
Duplicate invoices | Same bill paid twice | Fuzzy match on invoice number, date, amount |
Bid rigging | Suppliers coordinate quotes | Identical formats, typos or contact details across bids |
Inflated pricing | Rates drift above contract | Price variance against contract and history |
Kickbacks deserve special attention. As our vendor kickback case study explains, the money flow never reaches the books. Auditors rely on patterns, not single entries. For wider context, see our guide to fraud risks in internal audit.
Which Controls Prevent Procurement Fraud and Inefficiency?
Most of these controls work only when no single person can request, order, receive and pay for the same purchase, so the table separates what prevents a fraud from what merely detects it.
Control | Type | What it prevents |
Segregation of duties (request, order, receive, pay) | Preventive | Single-person fraud |
Independent vendor master approvals | Preventive | Fictitious vendors |
System-enforced three-way match | Preventive | Unmatched payments |
Delegation of authority in the ERP | Preventive | Limit breaches |
Monthly duplicate and split-PO analytics | Detective | Leakage and gaming |
Anonymous whistleblower channel | Detective | Long-running schemes |
Buyer rotation and annual conflict declarations | Preventive | Entrenched collusion |
Two supporting points:
- Fraud awareness training was associated with lower median losses: $84,000 where both staff and management were trained, against $150,000 where neither was.
- Manufacturers can pair these with the controls in our internal controls guide for manufacturing companies.
What Are The Common Mistakes in Procurement Audits?
These five mistakes recur in audits that look thorough on paper yet leave unapproved spend and fake vendors untouched.
- Sampling approved transactions only, so unapproved spend is never examined.
- Treating a clean three-way match as proof of legitimacy.
- Ignoring the vendor master until a fraud emerges.
- Reporting findings without owners, dates or root causes.
- Auditing once a year with no continuous monitoring in between.
When This Doesn’t Apply
A small business with few suppliers may not need an ERP-enforced three-way match. A documented two-way match (purchase order and invoice) plus a review by the business owner can be proportionate. What still applies is the core of the audit: keep buying, receiving and paying separate where you can, check new vendors before paying them, and age MSME dues. Our note on internal audit for SMEs covers a phased approach.
What Are The Recommendations for 2026 for Procurement Internal Audit ?
The table gives one action per role that can be scheduled this quarter, so the audit outcome doesn’t depend on a large system overhaul.
Audience | Priority action |
CFO | Add MSME ageing to the month-end close checklist |
Procurement head | Publish quote thresholds and single-source approval rules |
Internal audit team | Move from annual sampling to quarterly analytics on full data |
Conclusion On Procurement Internal Audit
A procurement internal audit works best when it follows the money end to end, tests for override as well as design, and leaves each finding with an owner. Start with the risks above and build a repeatable programme around them. If you would like an independent view of how your purchase-to-pay controls work in practice, our team of internal auditors can discuss scope with you.
Strengthen Your Procurement Controls with an Independent Internal Audit
Frequently Asked Questions About Procurement Internal Audit
How often should a procurement internal audit be performed?
Frequency depends on spend, complexity and risk. Many organisations run a full review annually and analytics quarterly. High-risk categories may warrant more frequent checks.
Is a procurement internal audit mandatory in India?
Internal audit is mandatory for prescribed companies under Section 138 of the Companies Act, 2013, read with Rule 13 of the Companies (Accounts) Rules, 2014. The thresholds differ by company type: turnover and borrowings tests apply to private companies, while the paid-up capital test applies to certain public companies.
What is a three-way match audit?
It checks that the purchase order, goods receipt note and invoice agree in quantity, price and terms before payment is released.
Should procurement be audited in-house or outsourced?
In-house teams know the process well. An independent external view adds objectivity, especially where the internal team reports into finance or procurement.
What is the difference between a procurement audit and a vendor audit?
A procurement audit examines your buying process and controls. A vendor audit examines a supplier’s own operations.
Related
Discover more from MSNA & Associates LLP
Subscribe to get the latest posts sent to your email.
