CORAA

Vendor Management Internal Audit Checklist

Tests vendor onboarding and KYC, vendor master data controls, rate/price approval, and vendor concentration risk — distinct from the Procure-to-Pay RCM's transaction-level payment controls.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Distinct from
Procure-to-Pay RCM (transaction-level controls)
Key risk
Single-vendor concentration, unauthorised master changes
Cross-reference
Related-party vendors → Sec 188 process
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

VENDOR MANAGEMENT — INTERNAL AUDIT CHECKLIST

Entity: ___ · Period: ___

Scope: tests the vendor management function itself — onboarding, master data integrity, pricing governance and concentration risk. This is distinct from the Procure-to-Pay RCM, which tests transaction-level controls (PO approval, 3-way match, payment release) for a vendor already onboarded — see that template for the transaction cycle.

Conclusion

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

How is this different from the Procure-to-Pay Risk & Control Matrix?
The P2P RCM tests transaction-level controls once a vendor is already active — purchase approval, 3-way match, payment release. This checklist tests the VENDOR MANAGEMENT function itself: how vendors get onboarded and vetted in the first place, how the vendor master is maintained over time, and portfolio-level risks like concentration in a small number of vendors. Both are typically tested together for a complete P2P assurance, but they test different things.
Why does vendor concentration matter as an audit point, not just a commercial decision?
Beyond the commercial risk of supply disruption, heavy reliance on one or two vendors without a documented single-source justification can indicate weak competitive-bidding discipline, or in some cases signal an undisclosed related-party relationship or a kickback arrangement. It is a red flag worth flagging even where no specific transaction irregularity has been found.
What evidence should support a vendor master change-control test?
Look for a change log capturing who requested the change, who approved it, and when — ideally with system-enforced maker-checker so the person requesting a bank-account change cannot also approve it. Sample a set of actual changes made during the period and trace each to its approval evidence, rather than relying on a policy document alone.
Related templates

You might also need.

Procure-to-Pay (P2P) Risk & Control Matrix Template
Free Procure-to-Pay (P2P) internal audit RCM template. Risks, controls and control objectives for vendor onboa
Contract Management Internal Audit Checklist
Free contract management internal audit checklist. Tests approval authority, renewal tracking, SLA and penalty
Related Party Transactions Internal Audit Checklist
Free related party transactions internal audit checklist. Tests identification, board approval, Rule 15(3) thr