Vendor onboarding and master data
Risk: Duplicate, related-party, inactive, blacklisted or unverified vendors are created and used for purchases or payments.
Controls
- Vendor KYC checklist
- Maker-checker master approval
- Bank validation
- Related-party and duplicate review
Tests
- Match vendor master to PAN/GST/Udyam/bank evidence
- Search duplicate names, GSTINs and bank accounts
- Review new vendor approvals
- Test related-party and employee-vendor flags
Evidence
Vendor master dump, onboarding file, PAN/GST/Udyam, bank proof, approval workflow, related-party list and change log.
Purchase requisition and budget control
Risk: Purchases are raised without need, budget, approved indent or authority, or are split to bypass approval limits.
Controls
- Approved PR workflow
- Budget availability check
- Delegation of authority
- Split-purchase exception review
Tests
- Trace PR to budget and user approval
- Review emergency/manual PRs
- Scan same vendor/item/date splits
- Compare PR timing with PO and receipt
Evidence
PR, budget file, approval matrix, workflow log, exception report and purchase plan.
RFQ, vendor selection and PO control
Risk: Vendors are selected without quotation, rate contract, technical approval or objective evaluation.
Controls
- RFQ threshold policy
- Comparative statement
- Rate contract control
- PO approval before commitment
Tests
- Sample PO files for RFQ/comparative evidence
- Check single-source justification
- Match PO rate to contract
- Review backdated or post-facto POs
Evidence
RFQ, quotations, comparative statement, negotiation note, rate contract, PO, approval trail and exception approval.
Goods receipt, service entry and acceptance
Risk: Invoices are booked for goods or services not received, poor quality receipts, short receipts or unsupported service completion.
Controls
- GRN/service entry control
- Quality inspection
- Short/damage note
- User acceptance sign-off
Tests
- Match GRN to PO and invoice
- Review service entries to completion evidence
- Test quality rejection/short receipt adjustments
- Check open GRN and pending invoice ageing
Evidence
GRN, service entry sheet, inspection note, delivery challan, weighbridge/measurement sheet, acceptance email and rejection note.
Invoice booking and three-way match
Risk: Invoices are duplicated, wrongly coded, booked without PO/GRN, booked to wrong period or mismatched to tax/commercial terms.
Controls
- Invoice capture control
- PO-GRN-invoice match
- Duplicate invoice check
- Accounting code review
Tests
- Reperform three-way match
- Search duplicate invoice number/amount/date/vendor
- Review non-PO invoices
- Test cut-off near period end
Evidence
Vendor invoice, PO, GRN/service entry, match exception report, accounting voucher, approval log and period-end accrual.
GST ITC, TDS and tax compliance
Risk: ITC is claimed without valid invoice or supplier data, blocked credit is missed, TDS/RCM is not applied, or tax codes are wrong.
Controls
- GST invoice validation
- GSTR-2B/ITC reconciliation
- TDS code review
- RCM and blocked-credit checklist
Tests
- Match invoices to GSTIN, tax invoice and 2B availability
- Review blocked-credit categories
- Test TDS/RCM coding
- Check 180-day unpaid creditor ITC reversal list
Evidence
Tax invoice, GSTIN master, 2B reconciliation, ITC register, blocked-credit review, TDS working, RCM working and payment ageing.
Payment run, bank controls and approvals
Risk: Unauthorised, duplicate, early, round-sum or wrong-bank payments are released without maker-checker and bank reconciliation.
Controls
- Payment proposal review
- Maker-checker release
- Bank beneficiary validation
- BRS and payment exception review
Tests
- Match payment run to approved invoices
- Review changes to vendor bank before payment
- Search duplicate payments
- Trace payments to bank and BRS clearance
Evidence
Payment proposal, AP ageing, approval trail, bank beneficiary file, bank statement, UTR, BRS and duplicate-payment report.
Advances, retention and vendor reconciliations
Risk: Vendor advances, debit balances, retention money, security deposits or old open items remain unreconciled or misstated.
Controls
- Advance approval
- Ageing review
- Vendor balance confirmation
- Retention release checklist
Tests
- Age advances and debit balances
- Match advances to PO and subsequent invoices
- Review retention release evidence
- Obtain vendor reconciliations for top balances
Evidence
Advance request, PO, ledger, ageing, vendor statement, balance confirmation, retention terms and release approval.
MSME, related parties and compliance-sensitive vendors
Risk: Micro/small supplier dues, related-party purchases, consultant payments, labour contractors or high-risk vendors are not monitored.
Controls
- Udyam status capture
- MSME ageing review
- Related-party approval
- Compliance-sensitive vendor checklist
Tests
- Review micro/small vendor ageing by acceptance date
- Test Section 188-style approvals where applicable
- Check labour/statutory evidence for contractors
- Review high-risk vendor exceptions
Evidence
Udyam record, acceptance date support, MSME ageing, related-party register, board/audit committee support, contractor compliance file and exception log.
ERP access, change logs and monitoring
Risk: Users can create vendors, change bank accounts, approve POs, post invoices or release payments without segregation or review.
Controls
- Role-based access
- SoD conflict review
- Leaver access review
- Master-change monitoring
Tests
- Review privileged P2P users
- Test vendor-bank and approval-limit changes
- Check leaver/shared IDs
- Review SoD conflicts and override logs
Evidence
User list, role matrix, HR exit list, vendor-change log, approval matrix, SoD report, override log and access review.