CORAA

Procure-to-Pay (P2P) Risk & Control Matrix Template

A ready risk-and-control matrix for the Procure-to-Pay cycle — vendor onboarding through payment release — mapped to risks, controls and control objectives under ICAI's SIA framework, with space for your own test results.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Standard
SIA 220 / SIA 330
Cycle
Procure-to-Pay (P2P)
Bridges to
Sec 143(3)(i) ICFR opinion
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

PROCURE-TO-PAY (P2P) RISK & CONTROL MATRIX

Entity: ___ · Period: ___

Scope: the Procure-to-Pay cycle from vendor onboarding through purchase approval, goods receipt, invoice processing and payment release. Prepared per SIA 220 (conducting the assignment) and SIA 330 (documentation) — the same risk-control evidence can support the entity's Sec 143(3)(i) internal financial controls conclusion under the Guidance Note on Audit of ICFR.

Risk & Control Matrix

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

What does a Procure-to-Pay (P2P) risk and control matrix cover?
It maps every sub-process from vendor onboarding through purchase approval, goods receipt, invoice matching and payment release — the specific risk at each point (e.g. a fictitious vendor, an unapproved purchase, payment for goods never received) and the control that should be operating to address it, with its control type and the assertion (control objective) it protects.
How does this RCM connect to the Sec 143(3)(i) internal financial controls opinion?
The same control evidence base serves two purposes: as an internal-audit working paper under SIA, and as supporting evidence for the statutory auditor's conclusion on internal financial controls over financial reporting under Section 143(3)(i). Building one RCM that both functions can rely on avoids duplicating the same control-testing effort twice.
Why is vendor master change control listed separately from vendor onboarding?
Onboarding controls verify a vendor when it's first created, but a common fraud pattern is changing an already-approved vendor's bank account details later to divert a payment. That needs its own independent-approval control point at the point of change, not just at creation — which is why it's tested as a distinct line in the matrix.
Related templates

You might also need.

Order-to-Cash (O2C) Risk & Control Matrix Template
Free Order-to-Cash (O2C) internal audit RCM template. Risks, controls and control objectives for credit approv
Internal Audit Risk Assessment Matrix — Impact × Likelihood
Free internal audit risk assessment matrix template. Impact × Likelihood scoring computed automatically across
ICFR Testing Working Paper — Sec 143(3)(i) Format
Free ICFR testing working paper for Sec 143(3)(i) — risk-control matrix (RCM), ITGC tests, deficiency vs signi