On this page

How to Conduct a Procurement Internal Audit in India (2026): 7-step checklist, Fraud Risks and Controls

Procurement internal audit in India showing purchase order review, supplier documentation, and procurement control assessment-MSNA ASSOCIATES
On this page

Which control would catch it first if a vendor started overcharging your company today? This guide is for internal audit teams, procurement heads, and CFOs in India, and it shows you how to plan the audit, run the key tests, and fix the gaps that matter. 

A procurement internal audit is an independent review of how your business selects suppliers, raises purchase orders, receives goods, and pays invoices. Its purpose is to surface leakage, fraud, and non-compliance before the statutory auditor does. 

This guide explains how to audit the procurement process under Indian rules in 2026. It includes a procurement internal audit checklist, the main risks, and the controls that address them. It is written for internal audit teams, procurement heads, and CFOs.

Key Takeaways

  • A procurement internal audit tests the whole purchase-to-pay chain: requisition, vendor selection, purchase order, receipt, invoice, and payment. Testing only the payment stage misses most of the risk.
  • Billing schemes rank among the most significant occupational fraud risks in the ACFE’s Occupational Fraud 2026 report, and more than half of all cases studied involved a lack of internal controls or an override of existing controls. 
  • From 1 April 2026, the MSME payment rule sits in Section 37(2)(g) of the Income-tax Act, 2025, which corresponds to Section 43B(h) of the 1961 Act. Overdue balances to micro and small suppliers are therefore a tax exposure as well as a relationship risk. 
  • Three-way match is necessary but not sufficient. It proves documents agree; it does not prove the vendor was genuine or the price fair.
  • Analyse 100% of transactions where data allows. Reserve sampling for evidence you must inspect physically.

What Does a Procurement Internal Audit Cover?

The scope runs from the moment someone needs something to the moment the ledger closes. Auditors test each stage against a specific risk.

Stage

Question the auditor asks

Typical evidence

Requisition

Was the need approved by the right authority?

Requisition, budget approval

Vendor selection

Was the choice competitive and documented?

Quotations, comparison sheet

Purchase order

Was it raised before the commitment?

PO, delegation of authority matrix

Receipt

Did goods or services actually arrive?

GRN, inspection report

Invoice and payment

Was the right amount paid once, to the right party?

Invoice, bank advice, vendor ledger

Why Does 2026 Change the Audit Agenda?

New fraud data, a rewritten Income-tax Act and stricter IIA standards all arrived within roughly 16 months of each other, so a procurement audit programme designed in 2024 is already out of date. 

  1. Fraud benchmarks are fresh. The ACFE’s Occupational Fraud 2026 report analysed 2,402 cases across 143 countries, with a median loss of $104,000 per case. 
  2. Tax law has moved. The Income-tax Act, 2025 came into force on 1 April 2026. For FY 2025-26, Section 43B(h) of the 1961 Act still applies. From Tax Year 2026-27, the same test runs under Section 37(2)(g).
  3. The standards have become more stringent. The IIA Global Internal Audit Standards (effective 9 January 2025) require that the audit plan be driven by risk and well-coordinated with other assurance providers.

Procurement audits that start from approved purchase orders miss the more revealing population: spend that never had one. We prefer to start from the general ledger and work backwards to the PO.

How to Audit the Procurement Process: 7 Steps

The seven steps run in the order fieldwork actually unfolds, from deciding which spend deserves attention to assigning an owner for every fix. 

Step 1: Scope the Audit Using a Risk Assessment

  • Rank spend categories by value, frequency, and supplier concentration. 
  • High-cost, single-source, and repeating classifications require further testing.  
  • Set out in writing the audit period, audit entities, and thresholds.

If you need a refresher on planning, see our guide on how an internal audit is conducted.

Step 2: Walk Through the Process and Map the Controls

Trace one transaction end to end. Interview requesters, buyers, store staff, and accounts payable. Compare what the policy says with what people actually do. That gap is usually where your first findings sit.

Step 3: Test Vendor Selection Controls and Supplier Due Diligence

Vendor selection controls

  • Are competitive quotes obtained above a defined threshold?
  • Is single-source buying justified in writing and approved by someone independent of the buyer?
  • Are evaluation criteria fixed before quotes are opened?

Supplier due diligence

  • Check GSTIN validity, PAN, bank account ownership and Udyam registration status.
  • Screen for related-party links. Compare vendor addresses, bank accounts and phone numbers with employee master data.
  • Confirm conflict-of-interest declarations exist for buyers and approvers.

Step 4: Complete a Purchase Order Review

A purchase order review checks timing, authority and accuracy. Test for:

  • POs raised after the invoice date (retrospective approval)
  • Multiple POs to one vendor just below an approval limit (split ordering)
  • Approvers exceeding their delegated limits
  • Rates that differ from contract or last-paid prices

Step 5: Run a Three-Way Match Audit

A three-way match audit compares the purchase order, goods receipt note, and vendor invoice before payment. Auditors test whether:

  • The system enforces the match, or users can override it
  • Tolerances (for example, price variance) are defined and approved
  • Exceptions are cleared by someone independent of the buyer

Our view: Three-way match is table stakes. A fictitious vendor with a matching PO, GRN and invoice will pass it. Pair it with vendor master analytics.

Step 6: Test Contracts, Payments and MSME Compliance

  • Check invoice rates against contract terms and escalation clauses. 
  • Look for duplicate payments, meaning the same vendor, amount and date, or invoice numbers that are nearly identical. 
  • Match the input tax credit you claimed to what suppliers actually filed, and confirm the 180-day payment condition was met.

MSME dues need the closest look. Under Section 15 of the MSMED Act, 2006, payment to micro and small suppliers is due within 15 days of acceptance or deemed acceptance of goods or services where there is no written agreement. Where there is one, the agreed period applies, capped at 45 days. Most Section 43B items allow payment by the return due date. This one doesn’t 

Match the input tax credit you claimed to what suppliers actually filed, and confirm the 180-day payment condition under Section 16(2) of the CGST Act, 2017 was met. 

Worked example: 

A micro-enterprise supplier’s invoice is accepted on 1 March with no written agreement, so payment is due by 16 March. If it is still unpaid on 31 March, the expense is disallowed for that year and becomes deductible only in the year it is paid. 

The rule covers only micro and small suppliers. Medium enterprises fall outside it, and so do suppliers whose Udyam certificate shows trading activity only. Check the Udyam certificate before ageing a balance 

Step 7: Use Data Analytics, Report and Follow Up

Run full-population tests: Benford’s analysis, vendor concentration, weekend postings and round-sum invoices. Rate each finding by risk. Assign an owner and a date. Our note on internal audit reporting explains why reports without owners rarely change behaviour.

Which India-Specific Procurement Tests Do Generic Checklists Miss?

Three Indian checks are often missing from procurement audit programmes, and each can be run from ERP data.

1. Cash payments: Under Section 40A(3) of the Income-tax Act, 1961 (continued in the 2025 Act), a business expense paid in cash above ₹10,000 to one person in a day is disallowed in full. The limit is ₹35,000 for goods-carriage transporters. 

Test: total cash payments by vendor and date, and look for clusters just under the limit.

2. TDS on purchases: Section 194Q of the 1961 Act now sits in Section 393(1), Table Sl. No. 8(ii) of the 2025 Act. A buyer with prior-year turnover above ₹10 crore deducts 0.1% on purchases from one seller above ₹50 lakh in the year, on the excess only. 

Test: total purchases by seller, not by invoice, and confirm TDS was deducted once the threshold was crossed.

3. Related-party vendors: 

Test: match the vendor master (names, addresses, bank accounts, PAN) to director and employee records, then compare the rates paid with those from unrelated vendors.

Thresholds and section numbers change with each amendment. Confirm them against the current Act before applying them.

What Should a Procurement Audit Checklist Include?

Use this procurement audit checklist as a starting point and adapt it to your risk profile.

Area

Key check

Red flag

Policy

Approved procurement policy and delegation of authority

Policy older than the last restructuring

Vendor master

Change log reviewed independently

Same person creates vendors and approves payments

Vendor selection

Documented quotes and evaluation

Repeated single-source awards

Purchase orders

PO precedes invoice

High share of retrospective POs

Receipt

GRN by store, not buyer

Services paid without proof of delivery

Invoice match

Tolerances enforced

Manual override of match exceptions

Payments

Duplicate and split-payment tests

Payments to new vendors before onboarding checks

MSME and tax

Ageing of micro and small dues

Dues crossing 45 days at year-end

Audit trail

Audit trail enabled and unaltered, as Rule 3(1) of the Companies (Accounts) Rules, 2014 requires

Edit or delete logs disabled

e-Invoicing

Validate the IRN on supplier invoices above the e-invoice threshold

Invoices with no IRN or a mismatched IRN

ITC

Match purchase register to GSTR-2B

Credit claimed but missing from GSTR-2B

What Are the Procurement Fraud Risks Auditors Should Test For?

Understanding procurement fraud risks helps you design tests that find them. The ACFE data above shows that tips detect 43% of cases, and schemes that run more than five years cause median losses above $1.1 million. Speed of detection matters. 

Risk

How it works

Audit test

Fictitious vendor

Fake supplier invoices are paid

Match vendor bank details to employee data

Kickbacks

Buyer favours a vendor for a personal payoff

Award concentration by buyer and vendor

Split orders

POs kept under approval limits

Clustered POs just below thresholds

Duplicate invoices

Same bill paid twice

Fuzzy match on invoice number, date, amount

Bid rigging

Suppliers coordinate quotes

Identical formats, typos or contact details across bids

Inflated pricing

Rates drift above contract

Price variance against contract and history

Kickbacks deserve special attention. As our vendor kickback case study explains, the money flow never reaches the books. Auditors rely on patterns, not single entries. For wider context, see our guide to fraud risks in internal audit.

Which Controls Prevent Procurement Fraud and Inefficiency?

Most of these controls work only when no single person can request, order, receive and pay for the same purchase, so the table separates what prevents a fraud from what merely detects it. 

Control

Type

What it prevents

Segregation of duties (request, order, receive, pay)

Preventive

Single-person fraud

Independent vendor master approvals

Preventive

Fictitious vendors

System-enforced three-way match

Preventive

Unmatched payments

Delegation of authority in the ERP

Preventive

Limit breaches

Monthly duplicate and split-PO analytics

Detective

Leakage and gaming

Anonymous whistleblower channel

Detective

Long-running schemes

Buyer rotation and annual conflict declarations

Preventive

Entrenched collusion

Two supporting points:

  • Fraud awareness training was associated with lower median losses: $84,000 where both staff and management were trained, against $150,000 where neither was. 
  • Manufacturers can pair these with the controls in our internal controls guide for manufacturing companies.

What Are The Common Mistakes in Procurement Audits?

These five mistakes recur in audits that look thorough on paper yet leave unapproved spend and fake vendors untouched. 

  • Sampling approved transactions only, so unapproved spend is never examined.
  • Treating a clean three-way match as proof of legitimacy.
  • Ignoring the vendor master until a fraud emerges.
  • Reporting findings without owners, dates or root causes.
  • Auditing once a year with no continuous monitoring in between.

When This Doesn’t Apply

A small business with few suppliers may not need an ERP-enforced three-way match. A documented two-way match (purchase order and invoice) plus a review by the business owner can be proportionate. What still applies is the core of the audit: keep buying, receiving and paying separate where you can, check new vendors before paying them, and age MSME dues. Our note on internal audit for SMEs covers a phased approach.

What Are The Recommendations for 2026 for Procurement Internal Audit ?

The table gives one action per role that can be scheduled this quarter, so the audit outcome doesn’t depend on a large system overhaul. 

Audience

Priority action

CFO

Add MSME ageing to the month-end close checklist

Procurement head

Publish quote thresholds and single-source approval rules

Internal audit team

Move from annual sampling to quarterly analytics on full data

Conclusion On Procurement Internal Audit

A procurement internal audit works best when it follows the money end to end, tests for override as well as design, and leaves each finding with an owner. Start with the risks above and build a repeatable programme around them. If you would like an independent view of how your purchase-to-pay controls work in practice, our  team of internal auditors can discuss scope with you. 

Strengthen Your Procurement Controls with an Independent Internal Audit

Identify procurement risks, review vendor controls, and improve purchase-to-pay compliance with independent internal audit support from MSNA & Associates LLP.

Frequently Asked Questions About Procurement Internal Audit

How often should a procurement internal audit be performed?

Frequency depends on spend, complexity and risk. Many organisations run a full review annually and analytics quarterly. High-risk categories may warrant more frequent checks.

Internal audit is mandatory for prescribed companies under Section 138 of the Companies Act, 2013, read with Rule 13 of the Companies (Accounts) Rules, 2014. The thresholds differ by company type: turnover and borrowings tests apply to private companies, while the paid-up capital test applies to certain public companies. 

It checks that the purchase order, goods receipt note and invoice agree in quantity, price and terms before payment is released.

In-house teams know the process well. An independent external view adds objectivity, especially where the internal team reports into finance or procurement.

A procurement audit examines your buying process and controls. A vendor audit examines a supplier’s own operations.


Discover more from MSNA & Associates LLP

Subscribe to get the latest posts sent to your email.

Found Valuable? Share it to peers

Why Trust MSNA

Get In Touch With Our Team Today

If you need any assistance in Internal Audit, Virtual CFO, Accounting/Bookkeeping for India, US & UAE, Financial Planning & Advisory, connect with our team today!

Talk To Our Team

Fill the form below, our team will connect with you shortly