CORAA
CORAA University / P2P audit workbook

Procure to pay audit workbook

Generate an Excel/PDF workbook for P2P internal audit: vendor master, PR, PO, GRN, invoice three-way match, GST ITC, TDS, MSME ageing, payments, advances, reconciliations and ERP access controls.

Engagement profile
Select audit areas
10 RCM rows selected
AreaRiskControlTestEvidenceCadence
Vendor masterDuplicate, related-party, inactive, blacklisted or unverified vendors are created and used.Vendor KYC, maker-checker approval, bank validation and duplicate/related-party review.Match vendor master to PAN/GST/Udyam/bank evidence and review duplicate names, GSTINs and bank accounts.Vendor master, onboarding file, PAN/GST/Udyam, bank proof, approval workflow and change log.Monthly / Onboarding
Purchase requisitionPurchases are raised without need, budget, approved indent or authority, or are split to bypass limits.Approved PR workflow, budget check, delegation of authority and split-purchase review.Trace PR to budget and approval, review emergency PRs and scan same vendor/item/date splits.PR, budget, approval matrix, workflow log, exception report and purchase plan.Monthly
RFQ vendor selection POVendors are selected without quotation, rate contract, technical approval or objective evaluation.RFQ threshold policy, comparative statement, rate contract control and PO approval before commitment.Sample PO files for RFQ/comparative evidence, single-source justification, contract rate and backdated POs.RFQ, quotations, comparative statement, rate contract, PO, approval trail and exception approval.Monthly / Quarterly
GRN service acceptanceInvoices are booked for goods or services not received, short receipts, poor quality receipts or unsupported service completion.GRN/service entry, quality inspection, short/damage note and user acceptance sign-off.Match GRN to PO and invoice; review service entries, quality rejection and open GRN ageing.GRN, service entry, inspection note, delivery challan, measurement sheet, acceptance and rejection note.Monthly
Invoice three-way matchInvoices are duplicated, wrongly coded, booked without PO/GRN, booked to wrong period or mismatched to terms.Invoice capture, PO-GRN-invoice match, duplicate check and accounting code review.Reperform three-way match, search duplicate invoice fields, review non-PO invoices and test cut-off.Invoice, PO, GRN/service entry, match exception report, voucher, approval log and accrual.Monthly / Period close
GST TDS tax codingITC is claimed without valid invoice or supplier data, blocked credit is missed, TDS/RCM is not applied, or tax codes are wrong.GST invoice validation, GSTR-2B reconciliation, TDS code review and RCM/blocked-credit checklist.Match invoices to GSTIN and 2B, review blocked credit, test TDS/RCM coding and unpaid 180-day creditor list.Tax invoice, GSTIN master, 2B reconciliation, ITC register, TDS/RCM working and payment ageing.Monthly
Payment run bankUnauthorised, duplicate, early, round-sum or wrong-bank payments are released.Payment proposal review, maker-checker release, bank beneficiary validation and BRS review.Match payment run to approved invoices, review bank changes before payment, search duplicate payments and trace UTR to bank.Payment proposal, AP ageing, approval trail, beneficiary file, bank statement, UTR and BRS.Weekly / Monthly
Advances retention reconVendor advances, debit balances, retention money, security deposits or old open items remain unreconciled.Advance approval, ageing review, vendor confirmation and retention release checklist.Age advances/debit balances, match advances to PO/invoices, review retention release and vendor reconciliation.Advance request, PO, ledger, ageing, vendor statement, confirmation, retention terms and release approval.Monthly / Quarterly
MSME related high-risk vendorsMicro/small supplier dues, related-party purchases, consultant payments, labour contractors or high-risk vendors are not monitored.Udyam capture, MSME ageing, related-party approval and compliance-sensitive vendor checklist.Review micro/small ageing by acceptance date, related-party approvals, contractor compliance and high-risk vendor exceptions.Udyam record, acceptance support, MSME ageing, related-party register, approval support and contractor file.Monthly
ERP access SoDUsers can create vendors, change bank accounts, approve POs, post invoices or release payments without segregation or review.Role-based access, SoD conflict review, leaver access review and master-change monitoring.Review privileged P2P users, vendor-bank changes, leavers/shared IDs, SoD conflicts and override logs.User list, role matrix, HR exit list, vendor-change log, approval matrix, SoD report and access review.Monthly / Quarterly

Use this with the P2P internal audit checklist, the RCM builder and the monitoring rules repository.

How it works

P2P internal audit is strongest when purchase evidence, tax evidence, payment evidence and system access evidence are tested together. The workbook connects vendor master, purchase requisition, RFQ, PO, GRN, invoice booking, GST/TDS, MSME ageing, payment run, bank trail and ERP access.

The Excel export gives auditors separate sheets for engagement scope, RCM rows, vendor master testing, PO-GRN-invoice matching, GST/TDS/MSME review, payments/advances/reconciliations, access/SoD and monitoring exceptions.

Worked example

A CA firm is reviewing P2P controls for a company with inventory purchases, service vendors, GST ITC, MSME suppliers and weekly payment runs.

Inputs
ScopeVendor master, PR, PO, GRN, invoice, tax coding, MSME ageing, payment run and access controls
OutputExcel workbook plus PDF summary
Output
WorkbookRCM, vendor testing, PO-GRN-invoice match, GST/TDS/MSME review, payment testing, access review and monitoring exceptions

Common mistakes

Testing only invoices
P2P audit should begin at vendor onboarding and PR/PO approval, then move through receipt, invoice, tax coding, payment and reconciliation.
Ignoring master-data changes
Vendor bank changes just before payment, duplicate GSTINs, inactive vendor reactivation and related-party vendors are common high-value tests.
Mixing audit testing with legal conclusions
GST, TDS, MSME and related-party rules should be tested as evidence and exception logic; final positions require current legal review.

Frequently asked questions

What is included in a P2P audit workbook?+
It includes engagement scope, P2P RCM rows, vendor master testing, PO-GRN-invoice match testing, GST/TDS/MSME review, payment and advance reconciliation, access/SoD review and continuous monitoring exception rules.
Can I export the P2P workbook to Excel?+
Yes. The workbook exports a multi-sheet Excel file and a PDF summary so auditors can document samples, evidence, exceptions, reviewer notes and monitoring rules.
Which data should be requested first?+
Request vendor master, vendor change log, PR register, PO register, GRN/service entry register, invoice register, AP ageing, payment run, bank statements, GST 2B reconciliation, TDS workings, Udyam/MSME data and ERP user lists.

Authoritative sources

ICAI
ICAI IASB - Compendium of Standards on Internal AuditUse SIA planning, evidence, documentation, review, communication and reporting principles.
CBIC - CGST Act Section 16Use for ITC eligibility and documentation context where applicable.
CBIC - GST input tax credit rulesUse for ITC documentation and reversal context, including unpaid supplier review.
MSME SamadhaanUse for delayed payment context for micro and small enterprises.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
P2P internal audit checklistInternal audit resource hubInternal audit monitoring rules
Share this tool
Last reviewed: 2026-08-29 · For informational purposes only — not professional advice.