When we published our accounts payable audit guide, we covered the back end of purchase-to-pay — the place where invoices are matched and cash leaves. Procurement is the front end, and it is where the decisions that actually commit the money get made. By the time an invoice reaches AP, someone has already decided what to buy, from whom, at what price, under what contract. If those decisions were steered — by a rigged bid, a tailored spec, an unjustified sole-source award, or a buyer with an undisclosed interest — the three-way match downstream will pass perfectly. The invoice is legitimate. The award never was.
That is what makes procurement one of the richest audit territories in the plan: the controls are judgment-heavy, the fraud schemes are structural rather than transactional, and most audit functions test it far less often than AP because the data is messier. This guide covers the full front end — where the risk actually lives, a working risk map, bidding and evaluation integrity with the bid-rigging red-flag catalog, sole-source discipline, conflicts of interest, a complete test program, the analytics that find circumvention at full population, and how to write the findings without writing an accusation.
This guide was rewritten in September 2026 to add what the August version left out: how to size and sequence the engagement, a template for the sole-source justification memo that the audit keeps asking for and rarely finds, Brightwater Foods’ procurement audit test by test, and the links to the templates and the fraud-side guides that carry the work. The risk map, the bid-rigging red flags, the 14-test program and the analytics catalog are unchanged. Two things have moved since August. The ACFE’s Occupational Fraud 2026 report puts corruption, which is what steered procurement usually is, in 45 percent of its 2,402 cases with a median loss of 150,000 dollars, and the procurement fraud schemes guide now covers the scheme side of this process in the depth this guide gives the control side.
In this guide
- Where procurement risk actually lives
- The risk map
- Sizing and sequencing the engagement
- Bidding and evaluation integrity — with the bid-rigging red flags
- Sole-source awards: the exception that becomes the rule
- The sole-source justification memo: a template that reads like a finding
- Conflicts of interest
- The test program
- The analytics catalog
- Worked example: Brightwater Foods’ procurement audit
- Writing the findings without writing an accusation
- Where to go next
Where procurement risk actually lives
Draw the boundary first, because procurement audits fail most often by drifting into AP territory and testing what was already tested. The front end runs from need to contract: requisition and business justification, sourcing strategy (compete it, or justify not competing it), specification writing, bid solicitation and receipt, evaluation and scoring, award approval, contract execution, and post-award change management. The handoff to AP happens at the purchase order; everything after that — receiving, matching, payment — belongs to the AP audit. The two audits share one artery worth naming: the vendor master file, where procurement decisions become payable counterparties, and which deserves its own engagement entirely.
Two structural facts shape everything you will test. First, procurement risk concentrates at thresholds. Policy creates cliffs — quotes required above one amount, formal competition above another, committee approval above a third — and every cliff creates an incentive to land just beneath it. Most of the analytics below are threshold geometry. Second, the record is adversarial by design. In AP, errors are mostly noise; in procurement, the interesting failures are engineered to look compliant — a rigged bid produces a beautiful bid file. So the audit tests less “was the paperwork present” and more “does the pattern across many awards make sense,” which is why full-population analytics matter more here than almost anywhere else in the plan.
The risk map
| # | Risk | What it looks like in the file |
|---|---|---|
| R1 | Purchases without genuine business need — duplicate capability, gold-plating, year-end budget burn | Thin or recycled justifications; December requisition spikes; assets that duplicate existing capacity |
| R2 | Threshold circumvention — requisitions or POs split to dodge competition or approval levels | Multiple same-vendor, same-requester POs in a short window that sum over a threshold; amounts clustered just under cliffs |
| R3 | Bid rigging among vendors — rotation, bid suppression, complementary bids | The same small field of bidders; losing bids priced in a tight band above the winner; winners subcontracting to losers |
| R4 | Bid tailoring and information leakage — specs written for a predetermined vendor, or one bidder briefed better than the rest | Specifications matching one product’s brochure; short response windows; late bid from the eventual winner |
| R5 | Sole-source abuse — the exception process used to avoid competition | Rising sole-source rate; “emergency” purchases that recur quarterly; justifications that assert rather than demonstrate uniqueness |
| R6 | Conflicts of interest — buyers or evaluators with undisclosed ties to vendors | Undeclared relationships surfacing in vendor-employee data matches; a buyer’s vendors winning at unusual rates |
| R7 | Award not following evaluation — criteria changed after bids opened, or contract terms differing from the winning bid | Scoring sheets edited after opening; award memos contradicting the score ranking; signed contract terms nobody bid |
| R8 | Change-order abuse — win low, grow the contract after award | Contracts with early, large, or serial change orders; final spend far above awarded value on competitively won work |
Notice that only R1 is about waste; R2 through R8 are about circumvention — defeating the control structure while producing compliant-looking records. That is the personality of this audit, and it is why the risk statements in your risk and control matrix for procurement should name the circumvention mechanism, not just the loss.
Sizing and sequencing the engagement
Procurement audits are sized by two numbers: the count of competitive awards in the window, which drives the file work, and the count of policy cliffs, which drives the analytics. An organization with forty tenders and three thresholds can have every tender file read and every threshold histogrammed in a few hundred hours; an organization with four hundred tenders needs the analytics to choose which forty files get read. The ranges below assume the smaller case, an eighteen-month window, an ERP that holds requisitions, purchase orders and contracts in one place, and access to the tender files, which in many organizations live in a shared drive rather than a system and take longer to assemble than to read. Write the program to the five-element procedure standard in the work program guide, and record the selection decisions in the sampling memo, because a procurement sample that is not stratified toward high-value and flagged awards is a sample of the wrong things.
| Phase | What happens | Hours |
|---|---|---|
| Planning and the boundary | Front-end scope agreed with the AP and vendor-master engagements; policy cliffs listed; the RCM drafted from the risk map | 30 |
| Walkthrough | One purchase from requisition to signed contract, at head office and at one plant, because the plants are where the process as performed diverges | 20 |
| Analytics | Split-PO, threshold clustering, sole-source trend, win rates, bid spreads, change-order ratios, employee-vendor match and bid timing on the full population | 60 to 100 |
| Tender file review | Evaluation integrity, solicitation and contract-versus-bid tests on every tender or the stratified sample the analytics chose | 80 to 120 |
| Sole-source population | Every award above threshold for justification quality and approval level; the market check re-performed on a sample | 40 |
| Conflicts and change orders | Declaration completeness against the real population of influence; change-order re-approval on the competitively won contracts | 40 |
| Reporting and referrals | Findings written to the pattern-and-control standard; any cluster around a person or vendor handed off under the protocol | 40 |
| Total | 310 to 390 |
Sequence the analytics before the files, for the reason the test program gives: they choose the sample. Sequence the walkthrough before the analytics, because the thresholds you histogram have to be the ones in force at the plants, not the ones in the policy document, and the two differ more often than not. And run the employee-vendor match and the bid-loser join early rather than late, because those are the two tests most likely to produce a referral, and a referral in week two costs the engagement nothing while a referral in the last week costs it the report date.
Bidding and evaluation integrity — with the bid-rigging red flags
Competitive bidding is the process’s central control, and it only works when three things hold. The competition is real: enough qualified bidders were genuinely solicited, given the same information, and given enough time — a three-day response window on a complex RFP is competition theater. The evaluation is pre-committed: criteria and weights are documented before bids are opened, scoring is performed independently by each evaluator against those criteria, and the file shows the math from scores to award. Criteria that shift after opening are R7 in motion. The award follows the evaluation: the contract goes to the scored winner at the bid terms, and any deviation — negotiated changes, a “best and final offer” round, an override of the ranking — carries a documented, approved rationale.
Against that baseline, these are the red flags worth training every auditor to recognize — individually explainable, damning in clusters:
- Rotation: the same small group of vendors trades wins in a detectable sequence, especially within a category or region.
- Complementary bidding: losing bids sit in a suspiciously tight band a few percent above the winner — priced to lose politely, not to win.
- Bid suppression: qualified bidders repeatedly decline, withdraw late, or submit disqualifying paperwork errors — then appear as subcontractors to the winner.
- Shared fingerprints: identical wording, formatting, unit-price patterns, or the same arithmetic error across supposedly independent bids.
- Tailored specifications: requirements that mirror one vendor’s product sheet, or brand-name specs with “or equal” language never honored in evaluation.
- Information asymmetry: the eventual winner asks no clarifying questions (they didn’t need to), or a late-submitted bid undercuts the field by a hair.
- Post-award drift: the low bid that wins and then grows through change orders into the price the losers quoted (R8’s signature).
One calibration note: several of these patterns have innocent explanations — thin supplier markets rotate naturally, and niche categories produce similar bids. The red flags are selection criteria for deeper testing, not conclusions. What converts pattern into finding is the file: a rotation pattern plus evaluation records that were never independently scored is a control failure you can report today, whatever the explanation for the pattern.
Sole-source awards: the exception that becomes the rule
Sole-source awards are legitimate in three narrow situations: a genuinely unique supplier (patented technology, the only certified provider in the region), compatibility lock-in (parts or services that must integrate with an installed base), and true emergency (the plant is down, the flood is now). The control is the justification memo — and its quality bar should be evidential, not rhetorical: a claim of uniqueness demonstrates what market check was performed and why alternatives fail, names who verified it, and carries approval one level above the normal threshold authority. “Vendor X is the only supplier who can meet our needs” is an assertion; the memo should read like a finding — condition, criteria, evidence.
Audit it in two directions. Per-award: sample sole-source justifications and re-perform the market check — twenty minutes of searching that finds three plausible alternative suppliers is a devastatingly simple workpaper. Per-program: trend the sole-source rate over time, by category and by buyer. A rate that climbs quietly year over year is the exception process becoming the default; “emergency” purchases from the same vendor every quarter are a standing arrangement wearing a costume. And check the loop-closer: policies usually require emergency awards to be followed by a competitive process for the ongoing need — test whether that follow-up competition ever actually happens.
The sole-source justification memo: a template that reads like a finding
The most common procurement finding on this site’s model reports is not a rigged bid but a justification memo that asserts what it should demonstrate. Management usually agrees with the finding and then asks what a good memo looks like, so give them one. The template below is written to the same condition, criteria, evidence structure the audit uses, which is not a coincidence: a sole-source award is a control exception, and the memo is the evidence that the exception was earned.
Sole-source justification. 1. Requirement: what is being bought, the estimated value over the contract life, and the competition threshold it exceeds. 2. Basis claimed: unique supplier, compatibility with an installed base, or emergency, one of the three, with the policy clause cited. 3. Market check performed: which alternative suppliers were identified, by whom, on what date, and why each fails the requirement, with the correspondence or search record attached; for an emergency, what the emergency was, when it began, and why the timeline excluded a compressed competition. 4. Price reasonableness: how the price was tested without competition, by comparison to the last competed price, a published index, a cost breakdown or an independent estimate. 5. Duration and exit: how long the award runs, and the date by which the ongoing need will be competed. 6. Conflicts: a statement by the requester and the approver that neither has an interest in the supplier, or the disclosure and recusal if one does. 7. Approval: the signature one level above the authority the value would normally require, dated before the purchase order.
Line 5 is the one that turns a memo into a control. Emergency and compatibility awards are nearly always followed by an ongoing need, and the loop-closer, the date by which the need will be competed, is what stops the exception from becoming the standing arrangement the trend analytic finds. When you test the memo, test line 5 against what happened afterward.
Conflicts of interest
COI is where procurement fraud usually begins — kickbacks, steering, and phantom vendors all require a person on the inside with influence over the decision. Three control layers, each testable. Disclosure: annual COI declarations from everyone with buying or evaluation influence — test completeness of the population (evaluators and requisitioners, not just the procurement team) and whether declared conflicts actually produced recusal. Structural separation: the person who writes the specification should not control the evaluation alone; the buyer should not be able to add a vendor to the master file — the SoD wiring that connects this audit to the vendor master. Detection: because disclosure only catches the honest, run the data: match employee addresses, bank accounts, phone numbers, and emergency-contact names against the vendor master; check officer registries for employee names behind awarded vendors; and compute win rates by buyer-vendor pair — a buyer whose favorite vendor wins 80% of their evaluations is a pattern the disclosure form will never surface. Gifts-and-entertainment registers, where they exist, complete the picture: cross-reference G&E entries from bidding vendors against award timing.
The test program
| # | Test | Risk |
|---|---|---|
| 1 | Walk one purchase end to end — requisition to signed contract — and reconcile the process as performed against policy; update the RCM before testing | All |
| 2 | For a sample of competitive awards, verify criteria and weights were documented before bid opening, evaluators scored independently, and the award traces arithmetically to the scores | R7 |
| 3 | For the same sample, inspect solicitation evidence: number of qualified bidders invited, identical information provided, response window reasonable for complexity | R3, R4 |
| 4 | Compare signed contract terms to the winning bid; investigate every material difference for documented, approved rationale | R7 |
| 5 | Test the full population of sole-source awards above threshold for justification quality and above-normal approval; re-perform the market check on a sample | R5 |
| 6 | Trend sole-source and emergency rates by category, buyer, and year; investigate outliers and recurring “emergencies” | R5 |
| 7 | Run split-PO analytics on the full PO population (same vendor + requester within a window, summing over a threshold); test flagged clusters for circumvention | R2 |
| 8 | Histogram award amounts against approval and competition thresholds; test the just-under population | R2 |
| 9 | Compute vendor win rates by buyer and category; inspect the bid files behind statistical outliers for the red-flag catalog | R3, R6 |
| 10 | Match employee master data (addresses, bank details, phone, tax IDs) against the vendor master; investigate every hit | R6 |
| 11 | Test COI declaration completeness against the population of evaluators and requisitioners; trace declared conflicts to recusal evidence | R6 |
| 12 | For competitively awarded contracts, compare final spend to awarded value; test contracts with early or serial change orders for re-approval at the correct authority level | R8 |
| 13 | Sample requisitions above a materiality floor for business-justification quality; flag year-end clustering | R1 |
| 14 | Inspect specification files for flagged awards for brand-tailoring and “or equal” language honored in evaluation | R4 |
Sizing: tests 5, 7, 8, 9, 10, and 12 run at full population by construction — that is the point of them. The per-award file tests (2, 3, 4, 14) follow your sampling standard, stratified toward high-value and flagged awards rather than drawn flat. Sequence the analytics first: they choose the sample the file review deserves, which is the layered design this whole site keeps recommending for a reason — and the program itself should be written to the five-element procedure standard from our work program guide.
The analytics catalog
| Analytic | How it works | What a hit means |
|---|---|---|
| Split-PO detection | Group POs by vendor + requester within a rolling window (e.g., 14 days); flag groups whose sum crosses a threshold no single PO crosses | Deliberate splitting, or a legitimate blanket-order need being met badly — both are findings |
| Threshold clustering | Histogram PO and award amounts; measure density just below each policy cliff vs. just above | A spike at “threshold minus a little” is circumvention’s population-level signature |
| Sole-source trend | Sole-source rate by quarter, category, buyer | Climbing or buyer-concentrated rates: the exception process is being farmed |
| Win-rate concentration | Wins per vendor per buyer vs. expected distribution | Buyer-vendor pairs to inspect for steering or COI |
| Bid-spread analysis | For each competition, losing bids’ distance from winner | Consistently tight spreads above the winner suggest complementary bidding |
| Change-order ratio | Final contract spend ÷ awarded value, flagging early and serial modifications | Low-ball-and-grow (R8); also weak scoping upstream |
| Employee-vendor match | Fuzzy-match employee master fields against vendor master fields | Undisclosed COI or phantom-vendor risk — escalate carefully |
| Bid-timing forensics | Submission timestamps vs. deadline; late winners and last-minute withdrawals | Information leakage or suppression patterns worth a file review |
Worked example: Brightwater Foods’ procurement audit
Brightwater Foods, the 180-million-dollar food manufacturer used across this site, has three plants, about 600 staff, and an internal audit function that its first chief audit executive rebuilt from a co-sourced arrangement. The co-sourced years produced the procure-to-pay analytics run over eighteen months of data, 22,400 invoices, 1,860 active vendors, 9,100 purchase orders and 41 tenders, which found two matters for referral and five control findings, all of them on the payment and vendor side of the boundary. The front end had never been audited. The rebuilt function’s procurement audit took the analytics results as its first layer and added the file work the run could not do, over the same eighteen months. Brightwater’s cliffs were a 10,000-dollar plant approval limit above which three written quotes were required, a formal tender above 100,000 dollars, and procurement committee approval above 500,000. The engagement took 340 hours, sixty of them the co-source specialist re-running the analytics on refreshed data.
| Test | Population | What it found | Disposition |
|---|---|---|---|
| 1. Walkthrough | One award at head office, one at a plant | The process as performed at the plants let each plant’s buyer source anything under 100,000 dollars without central procurement, against a policy that involved procurement above 25,000; the RCM was redrawn to the process that existed. | Finding, Low: the procurement involvement threshold is not enforced at the plants |
| 2. Evaluation integrity | All 41 tenders | Criteria and weights documented before opening in 29; in 12 the scoring sheet’s file metadata post-dated bid opening, nine of them at one plant. Independent scoring by more than one evaluator in 22; a single evaluator in 19. The award traced arithmetically to the scores in 36; five award memos contradicted the ranking, two with a rationale. | Finding, High: evaluation integrity |
| 3. Solicitation | All 41 tenders | A median of four bidders invited and a median eleven-day window; six tenders with windows under five days, four of them won by the incumbent. | Finding, Medium: competition theater on short-window tenders |
| 4. Contract versus bid | All 41 signed contracts | Seven material differences in price or scope between the winning bid and the signed contract; three carried a documented, approved rationale. | Finding, Medium: award not following evaluation |
| 5. Sole-source justification | All 57 awards above 10,000 dollars, 2.9 million in total | 31 justified on compatibility, 14 on uniqueness, 12 as emergencies; the market check re-performed on 15 found plausible alternatives for six within twenty minutes each; approval one level above the normal authority in 40 of 57. | Finding, High: the sole-source program |
| 6. Sole-source trend | Six quarters by category, buyer and plant | The rate rose from 9 to 16 percent of award value across the window; a sanitation chemicals emergency recurred in five consecutive quarters from the same supplier with no follow-up competition. | Inside finding 5; the standing arrangement was competed |
| 7. Split purchase orders | 9,100 purchase orders | The run’s nine clusters at one plant, one buyer and one packaging vendor confirmed; after the threshold logic change made in remediation, no clusters in the final quarter. | Remediation verified; no new finding |
| 8. Threshold clustering | Award and purchase order amounts against the three cliffs | Density just under 10,000 dollars at 2.2 times the density just above it, at the same plant; no clustering under the 100,000 and 500,000 cliffs. | Inside finding 7’s remediation; monitored quarterly |
| 9. Win-rate concentration | Wins by buyer and vendor pair | One maintenance contractor won six of the seven tenders its buyer ran; losing bids sat 2 to 4 percent above the winner in five of them. The file review found single-evaluator scoring on all six and nothing conclusive on the bids. | Inside finding 2, with the pair flagged for the next run |
| 10. Employee-vendor match | Employee master against the vendor master | The run’s two bank matches re-performed: the disclosed family business and the plant supervisor’s spouse’s cleaning contractor, 61,200 dollars, already handled through HR and legal; no new hits after the vendor-master screening control was introduced. | Remediation verified |
| 11. Conflict declarations | 84 people with buying or evaluation influence | 51 had current declarations; 33, mostly plant evaluators, had never been asked; four declared conflicts, one with recusal evidence. | Finding, Medium: the declaration population |
| 12. Change orders | 23 competitively awarded contracts above 100,000 dollars | Final spend exceeded the award by more than 10 percent on eight; a plant refrigeration upgrade awarded at 640,000 dollars closed at 912,000 through eleven change orders, none re-approved at committee level. | Finding, High: change-order governance |
| 13. Business justification | 60 requisitions above 25,000 dollars | Fourteen with justification text recycled from earlier requisitions; December requisitions at 2.4 times the monthly average at one plant. | Finding, Low |
| 14. Specification tailoring | The twelve tenders flagged by tests 2, 3 and 9 | Three specifications mirrored one vendor’s product sheet with or-equal language that the evaluation never applied. | Finding, Medium: specification control |
The report carried nine findings, three High, four Medium and two Low, an overall rating of Needs Improvement, and no new referrals: the two the analytics run had produced were already with counsel, and nothing in the file work moved a pattern past the threshold the protocol sets. Three things about the engagement generalize. The most expensive finding, the refrigeration contract, was invisible to every analytic except the change-order ratio and invisible to the tender file, which was clean; the contract grew after the file closed. The evaluation finding was about plants, not people: nineteen single-evaluator tenders and twelve post-dated scoring sheets describe a process that head office wrote and the plants never adopted, which is why the remediation was a plant procurement lead rather than a policy revision. And the sole-source program was the finding management argued with hardest and accepted fastest once the six re-performed market checks were on the table, twenty minutes each, three alternative suppliers apiece, which is the simplest workpaper in the file and the one the audit committee asked to see.
Writing the findings without writing an accusation
Procurement findings carry a hazard the rest of the plan mostly doesn’t: the underlying behavior might be fraud, and fraud is a legal conclusion auditors should not publish as a control observation. The discipline is to report the control failure and the pattern, not the motive. Condition: “14 of 61 purchase orders to Vendor A were issued by the same requester within rolling 14-day windows in amounts that individually fell below, and collectively exceeded, the $50,000 competitive-bid threshold.” Criteria: the policy. Consequence: purchases totaling $X avoided competitive sourcing, and the pricing obtained cannot be demonstrated to be market-based. Cause: the split-detection control does not exist. That structure — straight from the 5 C’s — says everything decision-relevant without the word “fraud” appearing once. In parallel, when indicators cluster around a person or vendor, stop expanding scope quietly and invoke your fraud-escalation protocol: investigation is a different discipline with different evidence-handling rules, and an enthusiastic auditor interviewing the suspect first is how prosecutable cases die. The audit report handles the control; the referral handles the rest.
Where to go next
Procurement is the audit where the paperwork is most likely to be perfect and the decision most likely to be wrong, which is exactly why it rewards the analytics-first, pattern-then-file approach this program is built on. With this guide, the accounts payable guide and the vendor master guide, the purchase-to-pay cycle is covered end to end: need to contract, vendor to counterparty, invoice to cash. Build the engagement’s matrix in the structure of the RCM template, sequence the analytics before the file reviews, and let the thresholds tell you where to look; they always know. When the pattern clusters around a person or a vendor, the first 48 hours protocol takes over from the audit program, and the procurement fraud schemes guide explains what the pattern is likely to be.
Related guides
- Procurement fraud schemes — bid rigging, kickbacks and phantom vendors, with Brightwater’s run mapped to the scheme families
- The P2P fraud analytics catalog — the cross-stage tests and Brightwater’s eighteen-month run test by test
- How to audit accounts payable — the back end of the cycle, with a 14-test program and a worked engagement
- How to audit the vendor master file — the artery the two audits share
- The accounts payable analytics catalog — the single-table tests the front-end analytics build on
- How to audit travel and expense — where gifts and entertainment to vendors usually surface first
- The Third-Party Topical Requirement — the program-level baseline for supplier oversight since September 2026
- How to run a fraud risk assessment — where procurement schemes sit in the register
- The ACFE fraud tree explained — the corruption branch, with its controls and analytics
- When internal audit finds fraud: the first 48 hours — what changes when a pattern becomes a referral
- The fraud red flags library — the purchasing cycle’s indicators, organized for triage
- The risk and control matrix template — where the procurement RCM lives
- Writing the audit work program — the five-element procedure standard the 14 tests follow
- Segregation of duties beyond the ERP — specification, evaluation and vendor creation kept apart
- Audit sample sizes demystified — stratifying the tender sample toward value and flags
- The sampling memo template — recording why the sample landed where it did
- Annotated workpaper examples — the disposition grid the tender review is recorded in
- The 5 C’s of audit findings — the structure that reports the pattern without the accusation
- Internal audit report examples — model reports, including a procurement finding written the right way
- The finding and issue log template — tracking nine findings through remediation
- Your first 90 days as chief audit executive — how Brightwater’s function was rebuilt around engagements like this one
- Fieldwork and testing guides and fraud risk guides — the full collections
Leave a Reply