CORAA
Resources - P2P Internal Audit

Procure to pay internal audit checklist.

P2P audit is where vendor risk, purchase discipline, tax evidence, payments and system access collide. A useful checklist must connect vendor master, PR, PO, GRN, invoice, GST/TDS, MSME ageing, payment run, bank trail and ERP access into one RCM.

Build P2P audit workbookOpen internal audit hub
RCM map

Ten P2P areas to test areas

Vendor onboarding and master data

Risk: Duplicate, related-party, inactive, blacklisted or unverified vendors are created and used for purchases or payments.

Controls
  • Vendor KYC checklist
  • Maker-checker master approval
  • Bank validation
  • Related-party and duplicate review
Tests
  • Match vendor master to PAN/GST/Udyam/bank evidence
  • Search duplicate names, GSTINs and bank accounts
  • Review new vendor approvals
  • Test related-party and employee-vendor flags
Evidence

Vendor master dump, onboarding file, PAN/GST/Udyam, bank proof, approval workflow, related-party list and change log.

Purchase requisition and budget control

Risk: Purchases are raised without need, budget, approved indent or authority, or are split to bypass approval limits.

Controls
  • Approved PR workflow
  • Budget availability check
  • Delegation of authority
  • Split-purchase exception review
Tests
  • Trace PR to budget and user approval
  • Review emergency/manual PRs
  • Scan same vendor/item/date splits
  • Compare PR timing with PO and receipt
Evidence

PR, budget file, approval matrix, workflow log, exception report and purchase plan.

RFQ, vendor selection and PO control

Risk: Vendors are selected without quotation, rate contract, technical approval or objective evaluation.

Controls
  • RFQ threshold policy
  • Comparative statement
  • Rate contract control
  • PO approval before commitment
Tests
  • Sample PO files for RFQ/comparative evidence
  • Check single-source justification
  • Match PO rate to contract
  • Review backdated or post-facto POs
Evidence

RFQ, quotations, comparative statement, negotiation note, rate contract, PO, approval trail and exception approval.

Goods receipt, service entry and acceptance

Risk: Invoices are booked for goods or services not received, poor quality receipts, short receipts or unsupported service completion.

Controls
  • GRN/service entry control
  • Quality inspection
  • Short/damage note
  • User acceptance sign-off
Tests
  • Match GRN to PO and invoice
  • Review service entries to completion evidence
  • Test quality rejection/short receipt adjustments
  • Check open GRN and pending invoice ageing
Evidence

GRN, service entry sheet, inspection note, delivery challan, weighbridge/measurement sheet, acceptance email and rejection note.

Invoice booking and three-way match

Risk: Invoices are duplicated, wrongly coded, booked without PO/GRN, booked to wrong period or mismatched to tax/commercial terms.

Controls
  • Invoice capture control
  • PO-GRN-invoice match
  • Duplicate invoice check
  • Accounting code review
Tests
  • Reperform three-way match
  • Search duplicate invoice number/amount/date/vendor
  • Review non-PO invoices
  • Test cut-off near period end
Evidence

Vendor invoice, PO, GRN/service entry, match exception report, accounting voucher, approval log and period-end accrual.

GST ITC, TDS and tax compliance

Risk: ITC is claimed without valid invoice or supplier data, blocked credit is missed, TDS/RCM is not applied, or tax codes are wrong.

Controls
  • GST invoice validation
  • GSTR-2B/ITC reconciliation
  • TDS code review
  • RCM and blocked-credit checklist
Tests
  • Match invoices to GSTIN, tax invoice and 2B availability
  • Review blocked-credit categories
  • Test TDS/RCM coding
  • Check 180-day unpaid creditor ITC reversal list
Evidence

Tax invoice, GSTIN master, 2B reconciliation, ITC register, blocked-credit review, TDS working, RCM working and payment ageing.

Payment run, bank controls and approvals

Risk: Unauthorised, duplicate, early, round-sum or wrong-bank payments are released without maker-checker and bank reconciliation.

Controls
  • Payment proposal review
  • Maker-checker release
  • Bank beneficiary validation
  • BRS and payment exception review
Tests
  • Match payment run to approved invoices
  • Review changes to vendor bank before payment
  • Search duplicate payments
  • Trace payments to bank and BRS clearance
Evidence

Payment proposal, AP ageing, approval trail, bank beneficiary file, bank statement, UTR, BRS and duplicate-payment report.

Advances, retention and vendor reconciliations

Risk: Vendor advances, debit balances, retention money, security deposits or old open items remain unreconciled or misstated.

Controls
  • Advance approval
  • Ageing review
  • Vendor balance confirmation
  • Retention release checklist
Tests
  • Age advances and debit balances
  • Match advances to PO and subsequent invoices
  • Review retention release evidence
  • Obtain vendor reconciliations for top balances
Evidence

Advance request, PO, ledger, ageing, vendor statement, balance confirmation, retention terms and release approval.

MSME, related parties and compliance-sensitive vendors

Risk: Micro/small supplier dues, related-party purchases, consultant payments, labour contractors or high-risk vendors are not monitored.

Controls
  • Udyam status capture
  • MSME ageing review
  • Related-party approval
  • Compliance-sensitive vendor checklist
Tests
  • Review micro/small vendor ageing by acceptance date
  • Test Section 188-style approvals where applicable
  • Check labour/statutory evidence for contractors
  • Review high-risk vendor exceptions
Evidence

Udyam record, acceptance date support, MSME ageing, related-party register, board/audit committee support, contractor compliance file and exception log.

ERP access, change logs and monitoring

Risk: Users can create vendors, change bank accounts, approve POs, post invoices or release payments without segregation or review.

Controls
  • Role-based access
  • SoD conflict review
  • Leaver access review
  • Master-change monitoring
Tests
  • Review privileged P2P users
  • Test vendor-bank and approval-limit changes
  • Check leaver/shared IDs
  • Review SoD conflicts and override logs
Evidence

User list, role matrix, HR exit list, vendor-change log, approval matrix, SoD report, override log and access review.

Monitoring

Turn P2P testing into recurring checks rules

Duplicate invoice

Same vendor, invoice number, date, amount, GSTIN or bank reference appears more than once.

PO after invoice

PO date is later than invoice, GRN, service period or payment date.

Vendor bank change before payment

Vendor bank account changed within threshold days before a payment run.

Unpaid creditor 180-day watch

GST ITC invoices remain unpaid beyond the configured 180-day review threshold.

MSME ageing breach

Micro/small vendor invoice crosses agreed or statutory payment review window without escalation.

Non-PO invoice spike

Non-PO invoices exceed threshold by vendor, department, user or month.

Authority

Use with current standards and laws sources

Use ICAI Standards on Internal Audit for planning, evidence, documentation, supervision, communication and reporting. Verify GST, TDS, MSME, Companies Act, related-party and sector-specific positions from current official sources before finalising exceptions.

ICAI IASB - Compendium of Standards on Internal Audit ->ICAI IASB - Publications and generic internal audit guides ->CBIC - CGST Act Section 16 input tax credit ->CBIC - GST input tax credit rules ->MSME Samadhaan - delayed payment mechanism ->India Code - Companies Act, 2013 ->
FAQ

P2P audit FAQs questions

What is a P2P internal audit checklist?

A P2P internal audit checklist is a workpaper covering vendor onboarding, purchase requisitions, RFQ and PO controls, GRN or service entry, invoice booking, three-way match, GST ITC, TDS, payments, advances, MSME ageing, related parties and ERP access controls.

Which P2P tests are best for continuous monitoring?

High-value recurring checks include duplicate invoices, PO-after-invoice, vendor bank change before payment, non-PO invoice spikes, split purchases, GST ITC unpaid beyond 180 days, MSME ageing, debit-balance vendors and leaver access in AP/payment systems.

Should P2P audit cover GST and TDS?

Yes, but as audit evidence and exception testing. The auditor should test whether invoice, GSTIN, 2B, blocked credit, RCM, TDS and payment-ageing controls operate. Final tax positions must be verified against current law and client facts.

Is this checklist legal or tax advice?

No. It is an internal-audit workpaper starter. GST, TDS, MSME, Companies Act, related-party, labour and sector-specific compliance requirements must be verified for the entity, vendor type, transaction and audit period.