Back to Insights
Procurement audit hero
Procurement Research9 min readWhitepaper

How to Conduct a Procurement Audit: A Step-by-Step Guide for CFOs, CPOs, and Heads of Internal Audit

A practical framework for scoping, running and reporting a procurement audit — and for moving from periodic review to continuous assurance across the supplier lifecycle.

Reputeo · Sada Forensic Audit
Executive summary

A procurement audit is a structured examination of how an organization buys goods and services — testing whether contracts, purchase orders, invoices and payments align, and whether the controls around them are working as intended. It matters now because supplier portfolios have grown faster than the controls governing them: more suppliers, more amendments, more pricing schedules, and more documents spread across more systems than any manual process was designed to handle.

This guide sets out what a procurement audit is (and is not), when to run one, and a nine-step process for conducting it — from scoping and evidence collection through to quantifying leakage, reporting to the audit committee, and establishing continuous monitoring. It is written for leaders who are accountable for both financial control and the defensibility of the findings that support it.

What a procurement audit actually is

A procurement audit examines the full procure-to-pay chain: the commercial terms an organization agreed, the goods and services it received, the amounts it was invoiced, and the payments it released. Its purpose is to confirm that spend is authorized, priced correctly, compliant with contract, and supported by evidence — and to surface where that chain breaks down.

It is distinct from a financial audit. A financial audit provides assurance over whether the financial statements are fairly stated; a procurement audit looks behind the numbers at whether individual transactions honor the contracts and controls that govern them. An invoice can be correctly recorded in the general ledger — and therefore invisible to a financial audit — while still exceeding the agreed rate card.

It is also broader than a compliance review. A compliance review typically checks adherence to a defined policy or regulation; a procurement audit assesses commercial accuracy and value as well as compliance. The most useful audits answer three questions at once: were we allowed to spend this, did we pay the right amount, and can we prove it?

When to run one

Procurement audits are most valuable when something has changed the risk profile. A new CFO or CPO arriving and wanting an independent baseline of the spend they have inherited is one of the most common triggers. An ERP migration is another — data mapped between systems is a frequent source of duplicate and mis-priced invoices. Supplier consolidation after a merger, a period of rapid growth that outpaced controls, heightened regulatory pressure, or a specific suspicion of leakage all warrant a focused audit.

The common thread is that manual controls that were adequate at a smaller scale quietly stop keeping pace — and the audit is the mechanism that reveals by how much.

An invoice can match the general ledger perfectly and still breach the contract that governs it — which is precisely why procurement audits find what financial audits do not.

The step-by-step process

  1. 01
    Define scope and objectives

    Decide what the audit will and will not cover: which categories, which suppliers, which business units, and which period. Set clear objectives — recovering overpayments, testing controls, preparing for external audit, or assessing a specific supplier. A tightly scoped audit that finishes is worth more than an ambitious one that stalls.

  2. 02
    Assemble the team and governance

    Confirm who owns the audit, who provides evidence, and who receives the findings. Internal audit typically leads; procurement, finance, legal and accounts payable supply documentation and context. Agree the reporting line to the audit committee up front, so findings land with the right authority to act on them.

  3. 03
    Collect documentation

    Assemble the complete evidence base: master service agreements, statements of work, amendments, purchase orders, invoices, rate cards, delivery records and approval logs. Fragmentation is the first obstacle — contracts in one system, invoices in the ERP, amendments in email. Centralizing this evidence is often the single most time-consuming, and most valuable, step.

  4. 04
    Identify risk categories

    Group potential issues so testing is systematic rather than ad hoc. Four categories cover most procurement leakage: clause risks (missing audit rights, weakened record-keeping, absent data-protection terms); pricing and rate-card risks (invoices above agreed rates, expired schedules still applied); post-termination and expired-contract risks (invoices billed with no valid agreement in force); and duplicate or unauthorized invoicing (the same service billed twice, or work outside the approved scope).

  5. 05
    Choose sample vs. full-population review

    Sampling is practical and appropriate for a first pass, for very large populations, or where the objective is directional assurance. Full-population review is appropriate where leakage is suspected, where transaction volumes are high but automatable, or where the audit must withstand external scrutiny. The trade-off is coverage: sampling reveals whether a problem exists; full-population review reveals its full extent.

  6. 06
    Test the controls

    Assess whether the controls that should prevent errors are operating: two- and three-way matching between purchase order, receipt and invoice; segregation of duties between those who approve suppliers, raise orders and release payment; and approval thresholds that route higher-value spend to the right authority. A control that exists on paper but is routinely overridden is itself a finding.

  7. 07
    Analyze findings and quantify leakage

    Move from individual exceptions to quantified impact. Group findings by type, supplier and business unit; estimate the recoverable amount and the annualized exposure if the pattern continues. Distinguish one-off errors from systemic ones — a single mispriced invoice is a correction; the same error repeated across a supplier for a year is a control failure.

  8. 08
    Report to leadership

    The audit committee wants a small number of things stated plainly: the quantified exposure, the root causes, the recoverable amount, and clear recommendations with owners and dates. Lead with impact, support every material finding with its source evidence, and separate what requires a decision from what is already being remediated.

  9. 09
    Remediate and monitor continuously

    Recovering overpayments is only half the value; the other half is closing the gap that produced them. Assign remediation owners, update controls and rate-card governance, and — where volumes justify it — move the highest-risk checks into continuous monitoring so the next exception is caught before payment rather than at the next audit.

Best practice

Fix the scope in writing before you request a single document. Audits that begin with 'let's see what we find' tend to expand until they stall. A one-page scope — categories, suppliers, period, objective — is the difference between an audit that reports and one that quietly runs out of momentum.

Document collection checklist

Evidence to assemble before testing begins
  • Master service agreements and framework contracts for every in-scope supplier
  • Statements of work and all amendments, in their latest approved versions
  • Current and historical rate cards and pricing schedules
  • Purchase orders and goods-received / delivery records
  • Invoices, credit notes and payment records for the audit period
  • Approval logs and evidence of authorization thresholds
  • Renewal, notice-period and expiration dates for each agreement
  • Any prior audit findings or open remediation items for the same suppliers

Red flags to look for

Signals that warrant closer review
  • Invoiced rates above the signed rate card, or old rates applied after a renegotiation
  • Invoices dated after a contract's expiration with no valid extension on file
  • Duplicate invoices with slightly different numbers, dates or formatting
  • Charges for services outside the approved scope or above ordered quantities
  • Suppliers appearing under more than one legal name or vendor record
  • Missing or weakened audit-rights and record-keeping clauses
  • Approvals that bypass the expected threshold or segregation of duties
  • Spend that is consistently just below an approval limit

Common pitfalls

Over-relying on sampling. Sampling is a legitimate technique, but treating a clean sample as proof of a clean population is a mistake. When discrepancies are small and dispersed — which is how most procurement leakage behaves — sampling reliably understates the total.

Treating contracts as static. Rates are renegotiated, scopes expand and discounts evolve. Auditing an invoice against an outdated contract version produces both false comfort and false findings. Always test against the latest approved version, including amendments.

Validating the purchase order instead of the contract. Three-way matching confirms that an invoice agrees with the purchase order and receipt — not that it complies with the underlying contract. An invoice can pass matching cleanly while still exceeding contracted pricing or scope.

Keeping no evidence trail. A finding that cannot be traced to the exact clause, schedule or invoice line is difficult to defend and easy for a supplier to contest. Capture the supporting evidence as findings are raised, not afterwards.

Reporting activity instead of impact. Audit committees do not need the volume of documents reviewed; they need the quantified exposure, the root cause and the recommended action. An audit that cannot state its financial impact will struggle to secure remediation.

Common mistake

Confusing detection with recovery. Identifying an overpayment is not the same as preventing the next one. Audits that stop at recovery leave the control gap open; the ones that create lasting value close the process that produced the error.

From periodic audit to continuous assurance

The economics of procurement leakage explain why the workflow is shifting. World Commerce & Contracting estimates that poor contract management erodes value equivalent to roughly 9% of annual revenue on average, rising to 15% or more in complex industries, with the best performers holding it near 3%. Billing discrepancies are among the most visible forms of that leakage. The ACFE, in its 2024 Report to the Nations, separately estimates that organizations lose around 5% of revenue to occupational fraud each year — a conservative figure, since a typical scheme runs about twelve months before detection, and billing schemes rank among the higher-risk categories. Ranges, not single points — but each independently points to material, recurring exposure.

Periodic audits find these issues months after payment, when recovery is hardest. Document-intelligence tools change the cadence rather than the principle: by reading contracts, amendments, rate cards and invoices together, they let the same risk categories be tested across the full population continuously, surfacing exceptions before payment and linking each to its supporting evidence. The auditor's judgment still decides what matters — the technology decides what to look at first.

Conclusion

A procurement audit is not a one-off recovery exercise; it is a repeatable discipline for keeping contracts, invoices and payments aligned. Run well — tightly scoped, evidence-based, and reported in terms of quantified impact — it recovers real money and closes the control gaps that produced the loss. As supplier portfolios and document volumes continue to grow, the ability to review contractual and financial documentation efficiently, and increasingly continuously, is becoming a genuine source of financial control rather than an administrative afterthought.

See it on your own data

See how Sada surfaces these flags across your supplier portfolio.

From weeks of manual review to audit-ready findings in minutes — tested across your full population, cited to the source, and inside your own environment.

Request an audit demo