Customer onboarding and master data
Risk: Customers are created, edited or reactivated without KYC, GSTIN, credit terms, related-party screening or independent approval.
Controls
- Customer master approval
- GSTIN/PAN validation
- Related-party flag
- Dormant customer review
Tests
- Sample new and changed customers
- Check GSTIN/PAN and credit terms
- Review dormant/reactivated accounts
- Inspect related-party flags
Evidence
Customer master, onboarding form, GSTIN/PAN proof, credit application, approval trail and change log.
Credit limits and order release
Risk: Orders are accepted despite weak credit evaluation, expired limits, unauthorised overrides or overdue receivables.
Controls
- Credit limit approval
- Overdue block
- Override workflow
- Periodic limit review
Tests
- Review limit approvals and expiry
- Test orders released over limit
- Inspect overdue block overrides
- Check periodic limit revisions
Evidence
Credit assessment, limit approval, ageing, override log, sales order and release approval.
Sales order pricing and schemes
Risk: Sales orders use unauthorised prices, discounts, schemes, freebies or terms that are not supported by approved policy.
Controls
- Price master control
- Discount approval
- Scheme circular
- Order amendment log
Tests
- Compare order prices to approved list
- Review discount exceptions
- Test scheme/freebie eligibility
- Inspect order amendments
Evidence
Price list, scheme circular, sales order, discount approval, amendment log and customer agreement.
Dispatch, service delivery and acceptance
Risk: Invoices are raised without dispatch, delivery, milestone completion, service proof or customer acceptance.
Controls
- Dispatch release control
- POD/service proof match
- Milestone approval
- Delivery exception review
Tests
- Match invoices to dispatch/POD or service proof
- Review pending delivery exceptions
- Test milestone billing support
- Check cancelled/reversed dispatches
Evidence
Delivery challan, e-way bill, POD, service report, milestone certificate, dispatch register and exception log.
Invoicing, e-invoicing and GST reporting
Risk: Invoices are incomplete, duplicated, wrong-taxed, missing IRN/e-way bill or inconsistent with GSTR-1 and GSTR-3B.
Controls
- Invoice sequence control
- Tax-code review
- IRN/e-way bill validation
- GSTR reconciliation
Tests
- Review invoice gaps/duplicates
- Test tax codes and place of supply
- Match IRN/e-way bill where applicable
- Reconcile sales register to GST returns
Evidence
Invoice register, tax-code master, IRN data, e-way bill, GSTR-1, GSTR-3B and sales GL.
Receipts, collections and bank reconciliation
Risk: Receipts, UPI/card settlements, customer collections or write-offs are not matched to invoices and bank statements.
Controls
- Receipt matching
- Collection owner review
- Bank settlement reconciliation
- Unapplied receipt ageing
Tests
- Match receipts to invoices and bank
- Age unapplied/on-account receipts
- Review collection follow-up
- Test write-off approvals
Evidence
Customer ledger, bank statement, receipt register, settlement file, collection notes, write-off approval and ageing.
Credit notes, sales returns and claims
Risk: Credit notes, returns, rebates, rate differences or claims are used to mask collection issues or revenue errors.
Controls
- Credit-note approval
- Reason-code review
- Return gate control
- Claim settlement workflow
Tests
- Sample credit notes by value/reason/user
- Match returns to stock movement
- Review post-period credit notes
- Check claims against contract terms
Evidence
Credit-note register, return note, gate entry, customer claim, approval trail, stock adjustment and revised GST reporting.
Receivables ageing, ECL and dispute management
Risk: Old debts, disputed balances, unconfirmed balances, related-party dues or expected credit loss inputs are inaccurate.
Controls
- Ageing review
- Balance confirmation
- Dispute tracker
- Provision/ECL review
Tests
- Age overdue balances
- Review confirmations and disputes
- Test provision policy application
- Inspect collection promises and legal cases
Evidence
Debtors ageing, balance confirmations, dispute tracker, ECL/provision working, legal notices and collection MIS.
Revenue recognition and cut-off
Risk: Revenue is recognised before transfer of control/service completion, after period-end cut-off or inconsistent with Ind AS/AS policy.
Controls
- Revenue policy
- Cut-off testing
- Contract review
- Deferred revenue review
Tests
- Test invoices around period end
- Review contract terms and performance obligations
- Match revenue to delivery/service evidence
- Check deferred/unbilled revenue
Evidence
Revenue policy, customer contract, dispatch/POD, service acceptance, unbilled/deferred schedules and GL entries.
O2C system access and SoD
Risk: Users can create customers, change credit terms, override prices, raise invoices, issue credit notes or post receipts without segregation.
Controls
- Role-based access
- SoD review
- Master-change audit log
- Leaver access review
Tests
- Review users and roles
- Test conflicting access
- Inspect master and credit override logs
- Check leavers/shared IDs
Evidence
ERP/CRM user list, role matrix, SoD report, change log, override report, leaver list and access review.