,

How to Audit Procurement: Sourcing, Bidding and Contract Award, With a Worked Engagement

When we published our accounts payable audit guide, we covered the back end of purchase-to-pay — the place where invoices are matched and cash leaves. Procurement is the front end, and it is where the decisions that actually commit the money get made. By the time an invoice reaches AP, someone has already decided what to buy, from whom, at what price, under what contract. If those decisions were steered — by a rigged bid, a tailored spec, an unjustified sole-source award, or a buyer with an undisclosed interest — the three-way match downstream will pass perfectly. The invoice is legitimate. The award never was.

That is what makes procurement one of the richest audit territories in the plan: the controls are judgment-heavy, the fraud schemes are structural rather than transactional, and most audit functions test it far less often than AP because the data is messier. This guide covers the full front end — where the risk actually lives, a working risk map, bidding and evaluation integrity with the bid-rigging red-flag catalog, sole-source discipline, conflicts of interest, a complete test program, the analytics that find circumvention at full population, and how to write the findings without writing an accusation.

This guide was rewritten in September 2026 to add what the August version left out: how to size and sequence the engagement, a template for the sole-source justification memo that the audit keeps asking for and rarely finds, Brightwater Foods’ procurement audit test by test, and the links to the templates and the fraud-side guides that carry the work. The risk map, the bid-rigging red flags, the 14-test program and the analytics catalog are unchanged. Two things have moved since August. The ACFE’s Occupational Fraud 2026 report puts corruption, which is what steered procurement usually is, in 45 percent of its 2,402 cases with a median loss of 150,000 dollars, and the procurement fraud schemes guide now covers the scheme side of this process in the depth this guide gives the control side.

In this guide

Where procurement risk actually lives

Draw the boundary first, because procurement audits fail most often by drifting into AP territory and testing what was already tested. The front end runs from need to contract: requisition and business justification, sourcing strategy (compete it, or justify not competing it), specification writing, bid solicitation and receipt, evaluation and scoring, award approval, contract execution, and post-award change management. The handoff to AP happens at the purchase order; everything after that — receiving, matching, payment — belongs to the AP audit. The two audits share one artery worth naming: the vendor master file, where procurement decisions become payable counterparties, and which deserves its own engagement entirely.

Two structural facts shape everything you will test. First, procurement risk concentrates at thresholds. Policy creates cliffs — quotes required above one amount, formal competition above another, committee approval above a third — and every cliff creates an incentive to land just beneath it. Most of the analytics below are threshold geometry. Second, the record is adversarial by design. In AP, errors are mostly noise; in procurement, the interesting failures are engineered to look compliant — a rigged bid produces a beautiful bid file. So the audit tests less “was the paperwork present” and more “does the pattern across many awards make sense,” which is why full-population analytics matter more here than almost anywhere else in the plan.

The risk map

#RiskWhat it looks like in the file
R1Purchases without genuine business need — duplicate capability, gold-plating, year-end budget burnThin or recycled justifications; December requisition spikes; assets that duplicate existing capacity
R2Threshold circumvention — requisitions or POs split to dodge competition or approval levelsMultiple same-vendor, same-requester POs in a short window that sum over a threshold; amounts clustered just under cliffs
R3Bid rigging among vendors — rotation, bid suppression, complementary bidsThe same small field of bidders; losing bids priced in a tight band above the winner; winners subcontracting to losers
R4Bid tailoring and information leakage — specs written for a predetermined vendor, or one bidder briefed better than the restSpecifications matching one product’s brochure; short response windows; late bid from the eventual winner
R5Sole-source abuse — the exception process used to avoid competitionRising sole-source rate; “emergency” purchases that recur quarterly; justifications that assert rather than demonstrate uniqueness
R6Conflicts of interest — buyers or evaluators with undisclosed ties to vendorsUndeclared relationships surfacing in vendor-employee data matches; a buyer’s vendors winning at unusual rates
R7Award not following evaluation — criteria changed after bids opened, or contract terms differing from the winning bidScoring sheets edited after opening; award memos contradicting the score ranking; signed contract terms nobody bid
R8Change-order abuse — win low, grow the contract after awardContracts with early, large, or serial change orders; final spend far above awarded value on competitively won work

Notice that only R1 is about waste; R2 through R8 are about circumvention — defeating the control structure while producing compliant-looking records. That is the personality of this audit, and it is why the risk statements in your risk and control matrix for procurement should name the circumvention mechanism, not just the loss.

Sizing and sequencing the engagement

Procurement audits are sized by two numbers: the count of competitive awards in the window, which drives the file work, and the count of policy cliffs, which drives the analytics. An organization with forty tenders and three thresholds can have every tender file read and every threshold histogrammed in a few hundred hours; an organization with four hundred tenders needs the analytics to choose which forty files get read. The ranges below assume the smaller case, an eighteen-month window, an ERP that holds requisitions, purchase orders and contracts in one place, and access to the tender files, which in many organizations live in a shared drive rather than a system and take longer to assemble than to read. Write the program to the five-element procedure standard in the work program guide, and record the selection decisions in the sampling memo, because a procurement sample that is not stratified toward high-value and flagged awards is a sample of the wrong things.

PhaseWhat happensHours
Planning and the boundaryFront-end scope agreed with the AP and vendor-master engagements; policy cliffs listed; the RCM drafted from the risk map30
WalkthroughOne purchase from requisition to signed contract, at head office and at one plant, because the plants are where the process as performed diverges20
AnalyticsSplit-PO, threshold clustering, sole-source trend, win rates, bid spreads, change-order ratios, employee-vendor match and bid timing on the full population60 to 100
Tender file reviewEvaluation integrity, solicitation and contract-versus-bid tests on every tender or the stratified sample the analytics chose80 to 120
Sole-source populationEvery award above threshold for justification quality and approval level; the market check re-performed on a sample40
Conflicts and change ordersDeclaration completeness against the real population of influence; change-order re-approval on the competitively won contracts40
Reporting and referralsFindings written to the pattern-and-control standard; any cluster around a person or vendor handed off under the protocol40
Total 310 to 390

Sequence the analytics before the files, for the reason the test program gives: they choose the sample. Sequence the walkthrough before the analytics, because the thresholds you histogram have to be the ones in force at the plants, not the ones in the policy document, and the two differ more often than not. And run the employee-vendor match and the bid-loser join early rather than late, because those are the two tests most likely to produce a referral, and a referral in week two costs the engagement nothing while a referral in the last week costs it the report date.

Bidding and evaluation integrity — with the bid-rigging red flags

Competitive bidding is the process’s central control, and it only works when three things hold. The competition is real: enough qualified bidders were genuinely solicited, given the same information, and given enough time — a three-day response window on a complex RFP is competition theater. The evaluation is pre-committed: criteria and weights are documented before bids are opened, scoring is performed independently by each evaluator against those criteria, and the file shows the math from scores to award. Criteria that shift after opening are R7 in motion. The award follows the evaluation: the contract goes to the scored winner at the bid terms, and any deviation — negotiated changes, a “best and final offer” round, an override of the ranking — carries a documented, approved rationale.

Against that baseline, these are the red flags worth training every auditor to recognize — individually explainable, damning in clusters:

  • Rotation: the same small group of vendors trades wins in a detectable sequence, especially within a category or region.
  • Complementary bidding: losing bids sit in a suspiciously tight band a few percent above the winner — priced to lose politely, not to win.
  • Bid suppression: qualified bidders repeatedly decline, withdraw late, or submit disqualifying paperwork errors — then appear as subcontractors to the winner.
  • Shared fingerprints: identical wording, formatting, unit-price patterns, or the same arithmetic error across supposedly independent bids.
  • Tailored specifications: requirements that mirror one vendor’s product sheet, or brand-name specs with “or equal” language never honored in evaluation.
  • Information asymmetry: the eventual winner asks no clarifying questions (they didn’t need to), or a late-submitted bid undercuts the field by a hair.
  • Post-award drift: the low bid that wins and then grows through change orders into the price the losers quoted (R8’s signature).

One calibration note: several of these patterns have innocent explanations — thin supplier markets rotate naturally, and niche categories produce similar bids. The red flags are selection criteria for deeper testing, not conclusions. What converts pattern into finding is the file: a rotation pattern plus evaluation records that were never independently scored is a control failure you can report today, whatever the explanation for the pattern.

Sole-source awards: the exception that becomes the rule

Sole-source awards are legitimate in three narrow situations: a genuinely unique supplier (patented technology, the only certified provider in the region), compatibility lock-in (parts or services that must integrate with an installed base), and true emergency (the plant is down, the flood is now). The control is the justification memo — and its quality bar should be evidential, not rhetorical: a claim of uniqueness demonstrates what market check was performed and why alternatives fail, names who verified it, and carries approval one level above the normal threshold authority. “Vendor X is the only supplier who can meet our needs” is an assertion; the memo should read like a finding — condition, criteria, evidence.

Audit it in two directions. Per-award: sample sole-source justifications and re-perform the market check — twenty minutes of searching that finds three plausible alternative suppliers is a devastatingly simple workpaper. Per-program: trend the sole-source rate over time, by category and by buyer. A rate that climbs quietly year over year is the exception process becoming the default; “emergency” purchases from the same vendor every quarter are a standing arrangement wearing a costume. And check the loop-closer: policies usually require emergency awards to be followed by a competitive process for the ongoing need — test whether that follow-up competition ever actually happens.

The sole-source justification memo: a template that reads like a finding

The most common procurement finding on this site’s model reports is not a rigged bid but a justification memo that asserts what it should demonstrate. Management usually agrees with the finding and then asks what a good memo looks like, so give them one. The template below is written to the same condition, criteria, evidence structure the audit uses, which is not a coincidence: a sole-source award is a control exception, and the memo is the evidence that the exception was earned.

Sole-source justification. 1. Requirement: what is being bought, the estimated value over the contract life, and the competition threshold it exceeds. 2. Basis claimed: unique supplier, compatibility with an installed base, or emergency, one of the three, with the policy clause cited. 3. Market check performed: which alternative suppliers were identified, by whom, on what date, and why each fails the requirement, with the correspondence or search record attached; for an emergency, what the emergency was, when it began, and why the timeline excluded a compressed competition. 4. Price reasonableness: how the price was tested without competition, by comparison to the last competed price, a published index, a cost breakdown or an independent estimate. 5. Duration and exit: how long the award runs, and the date by which the ongoing need will be competed. 6. Conflicts: a statement by the requester and the approver that neither has an interest in the supplier, or the disclosure and recusal if one does. 7. Approval: the signature one level above the authority the value would normally require, dated before the purchase order.

Line 5 is the one that turns a memo into a control. Emergency and compatibility awards are nearly always followed by an ongoing need, and the loop-closer, the date by which the need will be competed, is what stops the exception from becoming the standing arrangement the trend analytic finds. When you test the memo, test line 5 against what happened afterward.

Conflicts of interest

COI is where procurement fraud usually begins — kickbacks, steering, and phantom vendors all require a person on the inside with influence over the decision. Three control layers, each testable. Disclosure: annual COI declarations from everyone with buying or evaluation influence — test completeness of the population (evaluators and requisitioners, not just the procurement team) and whether declared conflicts actually produced recusal. Structural separation: the person who writes the specification should not control the evaluation alone; the buyer should not be able to add a vendor to the master file — the SoD wiring that connects this audit to the vendor master. Detection: because disclosure only catches the honest, run the data: match employee addresses, bank accounts, phone numbers, and emergency-contact names against the vendor master; check officer registries for employee names behind awarded vendors; and compute win rates by buyer-vendor pair — a buyer whose favorite vendor wins 80% of their evaluations is a pattern the disclosure form will never surface. Gifts-and-entertainment registers, where they exist, complete the picture: cross-reference G&E entries from bidding vendors against award timing.

The test program

#TestRisk
1Walk one purchase end to end — requisition to signed contract — and reconcile the process as performed against policy; update the RCM before testingAll
2For a sample of competitive awards, verify criteria and weights were documented before bid opening, evaluators scored independently, and the award traces arithmetically to the scoresR7
3For the same sample, inspect solicitation evidence: number of qualified bidders invited, identical information provided, response window reasonable for complexityR3, R4
4Compare signed contract terms to the winning bid; investigate every material difference for documented, approved rationaleR7
5Test the full population of sole-source awards above threshold for justification quality and above-normal approval; re-perform the market check on a sampleR5
6Trend sole-source and emergency rates by category, buyer, and year; investigate outliers and recurring “emergencies”R5
7Run split-PO analytics on the full PO population (same vendor + requester within a window, summing over a threshold); test flagged clusters for circumventionR2
8Histogram award amounts against approval and competition thresholds; test the just-under populationR2
9Compute vendor win rates by buyer and category; inspect the bid files behind statistical outliers for the red-flag catalogR3, R6
10Match employee master data (addresses, bank details, phone, tax IDs) against the vendor master; investigate every hitR6
11Test COI declaration completeness against the population of evaluators and requisitioners; trace declared conflicts to recusal evidenceR6
12For competitively awarded contracts, compare final spend to awarded value; test contracts with early or serial change orders for re-approval at the correct authority levelR8
13Sample requisitions above a materiality floor for business-justification quality; flag year-end clusteringR1
14Inspect specification files for flagged awards for brand-tailoring and “or equal” language honored in evaluationR4

Sizing: tests 5, 7, 8, 9, 10, and 12 run at full population by construction — that is the point of them. The per-award file tests (2, 3, 4, 14) follow your sampling standard, stratified toward high-value and flagged awards rather than drawn flat. Sequence the analytics first: they choose the sample the file review deserves, which is the layered design this whole site keeps recommending for a reason — and the program itself should be written to the five-element procedure standard from our work program guide.

The analytics catalog

AnalyticHow it worksWhat a hit means
Split-PO detectionGroup POs by vendor + requester within a rolling window (e.g., 14 days); flag groups whose sum crosses a threshold no single PO crossesDeliberate splitting, or a legitimate blanket-order need being met badly — both are findings
Threshold clusteringHistogram PO and award amounts; measure density just below each policy cliff vs. just aboveA spike at “threshold minus a little” is circumvention’s population-level signature
Sole-source trendSole-source rate by quarter, category, buyerClimbing or buyer-concentrated rates: the exception process is being farmed
Win-rate concentrationWins per vendor per buyer vs. expected distributionBuyer-vendor pairs to inspect for steering or COI
Bid-spread analysisFor each competition, losing bids’ distance from winnerConsistently tight spreads above the winner suggest complementary bidding
Change-order ratioFinal contract spend ÷ awarded value, flagging early and serial modificationsLow-ball-and-grow (R8); also weak scoping upstream
Employee-vendor matchFuzzy-match employee master fields against vendor master fieldsUndisclosed COI or phantom-vendor risk — escalate carefully
Bid-timing forensicsSubmission timestamps vs. deadline; late winners and last-minute withdrawalsInformation leakage or suppression patterns worth a file review

Worked example: Brightwater Foods’ procurement audit

Brightwater Foods, the 180-million-dollar food manufacturer used across this site, has three plants, about 600 staff, and an internal audit function that its first chief audit executive rebuilt from a co-sourced arrangement. The co-sourced years produced the procure-to-pay analytics run over eighteen months of data, 22,400 invoices, 1,860 active vendors, 9,100 purchase orders and 41 tenders, which found two matters for referral and five control findings, all of them on the payment and vendor side of the boundary. The front end had never been audited. The rebuilt function’s procurement audit took the analytics results as its first layer and added the file work the run could not do, over the same eighteen months. Brightwater’s cliffs were a 10,000-dollar plant approval limit above which three written quotes were required, a formal tender above 100,000 dollars, and procurement committee approval above 500,000. The engagement took 340 hours, sixty of them the co-source specialist re-running the analytics on refreshed data.

TestPopulationWhat it foundDisposition
1. WalkthroughOne award at head office, one at a plantThe process as performed at the plants let each plant’s buyer source anything under 100,000 dollars without central procurement, against a policy that involved procurement above 25,000; the RCM was redrawn to the process that existed.Finding, Low: the procurement involvement threshold is not enforced at the plants
2. Evaluation integrityAll 41 tendersCriteria and weights documented before opening in 29; in 12 the scoring sheet’s file metadata post-dated bid opening, nine of them at one plant. Independent scoring by more than one evaluator in 22; a single evaluator in 19. The award traced arithmetically to the scores in 36; five award memos contradicted the ranking, two with a rationale.Finding, High: evaluation integrity
3. SolicitationAll 41 tendersA median of four bidders invited and a median eleven-day window; six tenders with windows under five days, four of them won by the incumbent.Finding, Medium: competition theater on short-window tenders
4. Contract versus bidAll 41 signed contractsSeven material differences in price or scope between the winning bid and the signed contract; three carried a documented, approved rationale.Finding, Medium: award not following evaluation
5. Sole-source justificationAll 57 awards above 10,000 dollars, 2.9 million in total31 justified on compatibility, 14 on uniqueness, 12 as emergencies; the market check re-performed on 15 found plausible alternatives for six within twenty minutes each; approval one level above the normal authority in 40 of 57.Finding, High: the sole-source program
6. Sole-source trendSix quarters by category, buyer and plantThe rate rose from 9 to 16 percent of award value across the window; a sanitation chemicals emergency recurred in five consecutive quarters from the same supplier with no follow-up competition.Inside finding 5; the standing arrangement was competed
7. Split purchase orders9,100 purchase ordersThe run’s nine clusters at one plant, one buyer and one packaging vendor confirmed; after the threshold logic change made in remediation, no clusters in the final quarter.Remediation verified; no new finding
8. Threshold clusteringAward and purchase order amounts against the three cliffsDensity just under 10,000 dollars at 2.2 times the density just above it, at the same plant; no clustering under the 100,000 and 500,000 cliffs.Inside finding 7’s remediation; monitored quarterly
9. Win-rate concentrationWins by buyer and vendor pairOne maintenance contractor won six of the seven tenders its buyer ran; losing bids sat 2 to 4 percent above the winner in five of them. The file review found single-evaluator scoring on all six and nothing conclusive on the bids.Inside finding 2, with the pair flagged for the next run
10. Employee-vendor matchEmployee master against the vendor masterThe run’s two bank matches re-performed: the disclosed family business and the plant supervisor’s spouse’s cleaning contractor, 61,200 dollars, already handled through HR and legal; no new hits after the vendor-master screening control was introduced.Remediation verified
11. Conflict declarations84 people with buying or evaluation influence51 had current declarations; 33, mostly plant evaluators, had never been asked; four declared conflicts, one with recusal evidence.Finding, Medium: the declaration population
12. Change orders23 competitively awarded contracts above 100,000 dollarsFinal spend exceeded the award by more than 10 percent on eight; a plant refrigeration upgrade awarded at 640,000 dollars closed at 912,000 through eleven change orders, none re-approved at committee level.Finding, High: change-order governance
13. Business justification60 requisitions above 25,000 dollarsFourteen with justification text recycled from earlier requisitions; December requisitions at 2.4 times the monthly average at one plant.Finding, Low
14. Specification tailoringThe twelve tenders flagged by tests 2, 3 and 9Three specifications mirrored one vendor’s product sheet with or-equal language that the evaluation never applied.Finding, Medium: specification control

The report carried nine findings, three High, four Medium and two Low, an overall rating of Needs Improvement, and no new referrals: the two the analytics run had produced were already with counsel, and nothing in the file work moved a pattern past the threshold the protocol sets. Three things about the engagement generalize. The most expensive finding, the refrigeration contract, was invisible to every analytic except the change-order ratio and invisible to the tender file, which was clean; the contract grew after the file closed. The evaluation finding was about plants, not people: nineteen single-evaluator tenders and twelve post-dated scoring sheets describe a process that head office wrote and the plants never adopted, which is why the remediation was a plant procurement lead rather than a policy revision. And the sole-source program was the finding management argued with hardest and accepted fastest once the six re-performed market checks were on the table, twenty minutes each, three alternative suppliers apiece, which is the simplest workpaper in the file and the one the audit committee asked to see.

Writing the findings without writing an accusation

Procurement findings carry a hazard the rest of the plan mostly doesn’t: the underlying behavior might be fraud, and fraud is a legal conclusion auditors should not publish as a control observation. The discipline is to report the control failure and the pattern, not the motive. Condition: “14 of 61 purchase orders to Vendor A were issued by the same requester within rolling 14-day windows in amounts that individually fell below, and collectively exceeded, the $50,000 competitive-bid threshold.” Criteria: the policy. Consequence: purchases totaling $X avoided competitive sourcing, and the pricing obtained cannot be demonstrated to be market-based. Cause: the split-detection control does not exist. That structure — straight from the 5 C’s — says everything decision-relevant without the word “fraud” appearing once. In parallel, when indicators cluster around a person or vendor, stop expanding scope quietly and invoke your fraud-escalation protocol: investigation is a different discipline with different evidence-handling rules, and an enthusiastic auditor interviewing the suspect first is how prosecutable cases die. The audit report handles the control; the referral handles the rest.

Where to go next

Procurement is the audit where the paperwork is most likely to be perfect and the decision most likely to be wrong, which is exactly why it rewards the analytics-first, pattern-then-file approach this program is built on. With this guide, the accounts payable guide and the vendor master guide, the purchase-to-pay cycle is covered end to end: need to contract, vendor to counterparty, invoice to cash. Build the engagement’s matrix in the structure of the RCM template, sequence the analytics before the file reviews, and let the thresholds tell you where to look; they always know. When the pattern clusters around a person or a vendor, the first 48 hours protocol takes over from the audit program, and the procurement fraud schemes guide explains what the pattern is likely to be.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading