CORAA
Internal audit programme - P2P audit programme

Procure to Pay Internal Audit Programme programme.

A P2P internal audit programme converts procure-to-pay risks into fieldwork procedures covering vendor onboarding, purchase approval, GRN or service acceptance, invoice booking, tax checks, payment release, vendor reconciliation and ERP access.

Download Excel/PDF workbookOpen detailed checklist
Why this cycle matters

P2P is a high-leakage cycle because master data, procurement, stores, accounts payable, tax and banking controls meet in one flow. The audit programme must prove that the population is complete before testing invoices and payments.

Fictitious, duplicate or related-party vendors
Post-facto POs and split purchases
Invoices booked without receipt or service evidence
GST ITC/TDS/MSME exceptions
Duplicate or wrong-bank payments
AP users with conflicting master, posting and payment rights
Fieldwork programme

Audit procedures, evidence and sample basis procedures

Vendor master and onboarding

Objective: Only valid, approved and independently verified vendors are active.

Procedure steps
  • Reconcile vendor master to new-vendor and change logs.
  • Test PAN, GSTIN, Udyam, bank proof and approval evidence.
  • Search duplicate GSTIN, PAN, bank account, address and contact fields.
Evidence

Vendor master, change log, KYC pack, approval workflow, related-party list.

Sample basis

New vendors and master changes during the period, plus high-value active vendors.

PR, RFQ and PO approval

Objective: Purchases are approved before commitment and within delegated authority.

Procedure steps
  • Trace selected PRs to budget, RFQ, comparative statement and PO.
  • Identify PO-after-invoice, PO-after-GRN and split-purchase exceptions.
  • Test single-source and emergency purchase approvals.
Evidence

PR, budget file, RFQ, comparative, PO, approval matrix, exception log.

Sample basis

Risk-based PO sample, all high-value/emergency items.

GRN, service entry and invoice match

Objective: Invoices are booked only for accepted goods or services.

Procedure steps
  • Reperform PO-GRN-invoice match.
  • Trace service invoices to completion or user acceptance.
  • Review open GRN, unmatched invoice and quality rejection reports.
Evidence

GRN, service entry, invoice, quality note, match exception report.

Sample basis

Sample across goods, services, non-PO and period-end items.

GST, TDS, MSME and payment release

Objective: Tax and payment controls operate before cash leaves the company.

Procedure steps
  • Match invoice GSTIN, tax invoice and ITC support.
  • Test TDS/RCM coding and MSME ageing review.
  • Trace payment run to invoice approval, bank authorisation and BRS clearance.
Evidence

Tax invoice, GSTR-2B/recon, TDS working, MSME ageing, payment file, UTR, BRS.

Sample basis

High-value tax-coded invoices, MSME suppliers and payment runs.

Data requests

  • Vendor master with PAN/GSTIN/Udyam/bank fields and change log
  • PR, PO, GRN/service entry and invoice dump
  • Payment register with UTR and approver fields
  • GSTR-2B/ITC, TDS, RCM and MSME ageing workings

Analytics to run

  • Duplicate vendor bank accounts
  • Duplicate invoice number/date/amount/vendor
  • PO date after invoice or receipt date
  • Vendor bank change within threshold days before payment
  • MSME invoices beyond payment window

Red flags

  • Round-sum payments to new vendors
  • Repeated non-PO invoices
  • Manual vendor bank changes by AP users
  • Debit-balance vendors not followed up
  • Payment splits just below approval limit
Execution workflow

Build a defensible file RCM to evidence.

Use this cycle programme after the SOW, data request list and RCM are aligned. The Excel workbook should carry sample rationale, extraction filters, preparer sign-off, reviewer sign-off and observation references.

Authority

Use current standards and entity facts sources

ICAI IASB lists the Compendium of Standards on Internal Audit as on February 2026 as applicable from 1 April 2026. Use this page as a practical workpaper starter, then verify the latest standard, law, regulation, ERP report and client fact pattern before concluding.

FAQ

P2P audit programme questions answers

What should a P2P audit programme cover?

It should cover vendor master, purchase requisition, RFQ, PO, GRN or service entry, invoice booking, GST/TDS/MSME review, payments, vendor reconciliations and ERP access.

Is this P2P programme a substitute for professional judgement?

No. It is a fieldwork starter. The internal auditor must tailor it to the approved scope, ERP, delegation matrix, locations, volumes, materiality, prior findings and current legal position.

Can I download a P2P audit programme in Excel?

Yes. Use the linked CORAA workbook for the cycle. It contains editable RCM, testing, evidence and monitoring sheets that can be used as a fieldwork base.

Build PBC listBuild RCMSee Internal Audit module