,

How to Audit Inventory: Counts, Costing and Shrink, With a 14-Test Program

Inventory is the audit that turns auditors into counters, and counting is the part that matters least. A count tells you what is on the shelf on one day; it does not tell you why the system said something different, who adjusted the difference away, whether the stock is worth what the ledger says, or how much left the building between counts without anyone recording it. The money in an inventory audit is in those questions. Shrink, the polite word for the gap between what the records say and what exists, runs at roughly one and a half to two percent of sales in retail (the last National Retail Federation security survey, covering 2022, put it at 112 billion dollars and 1.6 percent of sales before the survey was retired over methodology concerns), and the causes split about evenly between external theft, employee theft and process failure. In a distributor or a manufacturer the process-failure share is larger, because inventory moves through receiving, transfers, production, picking and returns, and every handoff is a place where the record and the physical stock can part company. The ACFE’s Occupational Fraud 2026 report puts asset misappropriation in 90 percent of its 2,402 cases, and non-cash misappropriation, which is mostly inventory and equipment, is one of its most common forms.

This guide is the internal auditor’s version of the inventory audit: the flow from receipt to sale and where the risk concentrates, a starter risk and control matrix, a fourteen-test program with sample sizes, the analytics that find shrink before the count does, a worked engagement across MidState Beverage’s twelve depots with every test’s result, the findings that recur with wording that lands, and the scoping variants for a manufacturer with work in progress, a retailer, a distributor, and stock held by a third-party warehouse. It sits beside the accounts payable guide and the procurement guide, which cover the buying that puts inventory on the shelf, and the receivables guide, which covers what happens after it leaves.

In this guide

Know the terrain: receipt to sale, and where the record and the stock part company

Inventory has a life cycle with six handoffs: receiving (goods arrive and a receipt is posted, which is also the moment accounts payable’s three-way match depends on), put-away and storage (the stock is in a location the system knows about), transfers (between warehouses, depots or plants, with stock in transit that belongs to nobody for a day or a month), production or assembly (raw materials become work in progress become finished goods, and costs attach to them), picking and shipping (stock leaves and revenue is recognised), and returns and disposals (stock comes back, is damaged, expires, or is written off). The record can part company with the stock at every one of those handoffs, and the audit is organised around them rather than around the balance sheet caption. Four structural facts shape the work. The perpetual record is only as good as the discipline at the handoffs; a warehouse with excellent counts and sloppy receiving will always show variances, and the counts will be blamed. Adjustments are the universal solvent, as credit memos are in receivables: a stock adjustment can correct an honest count difference, conceal a theft, or move cost between periods, and who can post one, at what value, with what approval, is the central control question. Valuation is an estimate dressed as a fact: standard costs, average costs, overhead absorption, obsolescence reserves and the lower-of-cost-and-net-realisable-value test under ASC 330 (and IAS 2) all involve judgment, and judgment is where financial statement risk lives. And existence is asymmetric: it is easy to prove that stock the system lists is not there and hard to prove that stock on the floor is not in the system, which is why counts must go both ways, from the list to the floor and from the floor to the list.

Planning inputs worth an hour each: the inventory by location, category and age; the adjustment log for the year by reason code, poster and approver (the single most informative extract in the audit); shrink and write-offs for three years against sales; count results by location (variance rates before and after adjustment); negative on-hand quantities, which are impossible physically and always mean a process failure; stock in transit and its age; slow-moving and expired stock against the reserve; and the interfaces, meaning what system the warehouse runs (a warehouse management system, an ERP module, handhelds, spreadsheets) and how it reconciles to the general ledger. Walk one receipt, one transfer and one pick through the system with the warehouse manager, and stand in the warehouse for an hour watching what actually happens at the dock. The walkthrough tells you which controls exist as designed and which exist as a manager’s memory.

The inventory risk map

#RiskWhere it livesError or fraud?
R1Existence: recorded stock is not physically there (theft, unrecorded shipments, phantom receipts)All handoffs; concealed at the countBoth
R2Completeness: stock on hand is not in the records (unrecorded receipts, returns not booked, consignment stock)Receiving, returnsError; enables theft of the unrecorded stock
R3Receiving integrity: receipts posted before goods arrive, for the wrong quantity, or by the person who ordered themReceiving dockBoth (feeds AP fraud)
R4Adjustment abuse: count variances and write-offs posted without approval, used to conceal theft or to move cost between periodsAdjustment postingBoth
R5Transfers and stock in transit: stock leaves one location and never arrives at the other, or sits “in transit” for monthsInter-location transfersBoth
R6Valuation: standard costs stale, overhead absorption wrong, average cost distorted by bad receipts; lower-of-cost-and-NRV not appliedCosting and period-endError or earnings management
R7Obsolescence and expiry: slow-moving, expired or damaged stock carried at full value; reserve estimated by habitPeriod-end estimateError or earnings management
R8Cut-off: goods received or shipped around period-end recorded in the wrong period; stock counted and also shippedPeriod-endError (or manipulation)
R9Count integrity: counts performed by the custodian, count sheets altered, second counts skipped, variances “resolved” by recount until they disappearCount processBoth
R10Segregation failures: one person can receive, adjust, count and shipAccess model and staffingEnabler of everything above

Use the map to argue scope. R1, R4, R9 and R10 are the theft chain and are tested together through adjustments, count integrity and the access model; R2, R3 and R5 are the handoff failures that analytics find across the whole population; R6, R7 and R8 are shared ground with the external auditor and matter most at year-end. A distributor’s audit leans toward the handoffs and the adjustments; a manufacturer’s leans toward valuation; a retailer’s leans toward shrink and count integrity.

The starter RCM: ten controls that carry the process

CtrlControl (condensed)Type / frequencyAnswers risk
C1Receipts are posted only against an open purchase order, by a receiver independent of the buyer, from a physical count or scan at the dock; quantity over the PO tolerance is blockedPreventive / each receiptR2, R3
C2Every location, bin and SKU exists in the system before stock is put away; stock cannot be stored in an unrecorded location; negative on-hand quantities are blocked or reported dailyPreventive-detective / continuous, dailyR2, R1
C3Transfers are shipped and received in the system by different users at each location; in-transit balances are aged and reconciled weekly; items in transit over seven days are investigatedDetective / weeklyR5
C4Cycle counts run on a documented schedule by value class (A items monthly, B quarterly, C annually), performed by counters independent of the custodian, blind (no system quantity shown), with second counts on variances over toleranceDetective / per scheduleR1, R9
C5Count variances and adjustments require investigation, a reason code, and approval independent of the warehouse; adjustments above a threshold require finance approval; the adjustment log is reviewed monthly by reason, poster and locationPreventive-detective / each adjustment, monthlyR4, R1
C6Picking and shipping are confirmed by scan against the sales order; shipped quantities relieve inventory at shipment; no shipment leaves without a system documentPreventive / each shipmentR1, R8
C7Returns and damaged stock are received into a quarantine location, inspected, and dispositioned (restock, rework, scrap) with approval; scrap is witnessed and documentedPreventive / each returnR2, R4
C8Standard costs are reviewed and updated at least annually with variance analysis; period-end costing (average cost, overhead absorption) is reconciled to the ledger and reviewed by financeDetective / annual, monthlyR6
C9Slow-moving, expired and damaged stock is identified from system aging monthly; the obsolescence reserve is recalculated quarterly on a documented method with specific provisions and reviewed by the controllerDetective / monthly, quarterlyR7
C10Roles for receiving, adjusting, counting and shipping are segregated in the system; physical access to the warehouse is restricted and logged; period-end cut-off is controlled by document sequence and a receiving and shipping logPreventive / continuous, period-endR10, R8

This is a starter matrix. In a warehouse management system, C1, C2, C3 and C6 are configuration and are tested once as configuration plus a test of one per scenario; in a spreadsheet-run depot they are people, and they get samples. Load it into the RCM Workbench and rebuild it against the walkthrough, following the RCM template guide. The map from risk to control to test is the audit.

The 14-test program

Each test names its objective, population and core attributes. Sample sizes follow the standard attribute conventions; selections go in the sampling memo. Tests marked with a triangle are full-population analytics and run first, because their hits become the judgmental selections for the count and the adjustment tests.

  1. Receiving integrity. Sample 25 receipts. Attributes: open PO existed; receiver independent of the buyer; quantity posted equals the delivery note and the dock count; posted on the day of arrival; over-receipts blocked or approved. Then run the analytic for receipts posted before the carrier’s delivery timestamp.
  2. ▲ Negative on-hand and phantom locations. Full population: SKUs with negative quantities at any point in the period, stock in locations not on the location master, and receipts into locations with no capacity. Every hit is a handoff failure; count the causes.
  3. Transfers and stock in transit. Sample 25 transfers plus the full in-transit aging at three month-ends. Attributes: shipped and received by different users; received within the expected days; quantity received equals quantity shipped or the variance investigated; nothing in transit over 30 days without an explanation.
  4. Cycle count design and coverage. Inspect the schedule against the value classification. Attributes: A items counted at the required frequency; every location covered in the year; counters independent of custodians; blind counts; second counts on variances; results recorded before adjustment.
  5. Count observation. Attend at least two counts (one announced, one not) at locations chosen from the analytics, not from the schedule; the section below says how. Attributes: floor-to-list and list-to-floor test counts of 40 items each; count sheets controlled; movement frozen or logged; variances resolved by investigation, not by recounting until they disappear.
  6. ▲ Adjustment analytics. Full population of stock adjustments: by reason code, poster, approver, location, value and timing (period-end clusters, adjustments within days of a count, offsetting adjustments in the same SKU, adjustments posted by the custodian of the location). Hits are your judgmental picks for test 7.
  7. Adjustment approval. Sample 25 adjustments from the analytics hits plus all above the finance threshold. Attributes: investigation documented; reason code valid; approver independent of the warehouse; finance approval above threshold; adjustment agrees to the count record it claims to correct.
  8. Shipping and relief. Sample 25 shipments. Attributes: picked and confirmed by scan; inventory relieved on shipment; shipping document sequence complete; no shipment without a sales order; carrier proof of delivery obtainable.
  9. Returns and scrap. Sample 25 returns and all scrap disposals above threshold. Attributes: quarantined on receipt; inspected and dispositioned with approval; scrap witnessed by someone independent and documented (photograph, weight ticket, recycler receipt); restocked items counted back in.
  10. Cut-off. Ten receipts and ten shipments either side of period-end. Attributes: recorded in the period of physical movement; the receiving and shipping logs agree to the last document numbers; goods counted were not also shipped, and goods received after the count were not included.
  11. Costing. Inspect the standard cost review and one period-end costing run. Attributes: standards updated within the year with documented variance analysis; overhead absorption rates supported; average-cost anomalies (unit costs outside a band) investigated; costing reconciled to the ledger.
  12. Obsolescence and expiry. Inspect the aging and the reserve calculation for one quarter and reperform it. Attributes: slow-moving definition consistent with the business; expired and damaged stock identified and provided for; specific provisions for known write-downs; movements explained; consistent with ASC 330’s lower-of-cost-and-net-realisable-value requirement.
  13. Segregation and physical access. Pull actual system roles and the physical access list. For every person who can receive and adjust, adjust and count, or count and ship, test whether a compensating review actually covered their transactions, following the segregation of duties guide; walk the perimeter and the after-hours access log.
  14. Reconciliation discipline. The perpetual record reconciled to the general ledger monthly, by location; the warehouse system to the ERP daily if separate. Attributes: timely, reviewed, differences explained and cleared, not plugged. Structure the file like the model workpaper.

Observing a count properly: what to do before, during and after

Auditors observe counts badly because they treat them as attendance. Before the count, obtain the count instructions and read them against the design attributes in test 4; get the frozen system listing for the location (or, for a blind count, confirm that counters will not see it); choose your own test-count items from the analytics, the high-value classes, the SKUs with the most adjustments and the locations with negative quantities, not from the first rack you see; and agree with the warehouse manager how movement will be handled during the count, because a warehouse that keeps shipping while counting cannot be counted. During the count, do two things in equal measure: list-to-floor, taking items from the system listing and finding them (existence), and floor-to-list, picking items from the shelf and finding them in the listing (completeness); forty each is a defensible number for a location, more where the walkthrough suggested trouble. Watch the counters rather than only the stock: are they counting or reading labels, are second counts really independent, are count sheets or handhelds controlled, are damaged and expired items being counted as good. Note the last receiving and shipping document numbers for cut-off. After the count, obtain the variance report before any adjustment is posted and trace your test counts into it; then follow the variances to their resolution and confirm that “resolved” means investigated, not recounted until the number matched. The count you attend is a sample of one; what makes it evidence is the design test around it and the adjustment analytics after it.

The analytics that find shrink before the count does

Inventory systems record every movement with a user, a timestamp and a document, and the analytics below read those movements for the shapes that counts cannot see. Four extracts carry them: the movement history (receipts, transfers, picks, adjustments, with user and time), the on-hand snapshot by location at several dates, the adjustment log with reason codes and approvals, and the item master with cost, class and shelf life. Prove completeness first by reconciling the movement history to the change in on-hand value and the on-hand value to the ledger, as the IPE testing guide describes.

AnalyticLogicWhat a hit means
Adjustment concentrationAdjustments by poster, location and reason; share posted by the location’s custodian; clusters in the last five days of a period; offsetting adjustments on the same SKU within daysCustodians writing off their own variances; period-end cost management; a count “resolved” by adjustment
Negative on-hand historyAny SKU-location that went negative during the period, how long, and what movement restored itReceipts posted late or not at all; sales recorded before stock existed; a phantom-location problem
Transfer aging and one-sided transfersTransfers shipped but never received, received but never shipped, or in transit beyond the expected days; by route pairStock lost between locations, or a receiving discipline gap at one site
Receipt before arrivalReceipt timestamp earlier than the carrier’s delivery scan or the gate log; receipts posted by the buyerReceiving on paper to release payment; the AP three-way match compromised
Shrink by location and categoryNet adjustment value as a share of throughput, by location and product family, ranked and trendedThe three locations that account for most of the shrink; the category being taken
Expired and slow-moving stockOn-hand quantities with best-before dates past or within thirty days; items with no movement in 180 days; both against the reserveStock carried at full value that should be provided for or destroyed
Count variance persistenceSKUs and locations whose count variances exceed tolerance in three consecutive cyclesEither a process failure the counts keep finding, or a theft nobody has investigated
Returnable containersKegs, pallets, totes and crates: units issued to customers less returns less on hand, against the deposit liabilityContainers that have quietly become someone else’s assets; a deposit liability that is wrong
After-hours movementsPicks, adjustments and shipments posted outside operating hours, by userUnsupervised activity, or a batch job the warehouse forgot it had

Worked example: MidState Beverage’s warehouse inventory audit

MidState Beverage is the three-state drinks distributor used across this site: twelve depots, three hundred routes, a 2013 ERP with a route-accounting module, two acquired distributors integrated for revenue but not for controls, and a six-person internal audit function. Warehouse inventory was engagement four of the FY27 plan written out in the audit plan guide, budgeted at 650 hours, and it was in the plan because FY26 had ended with a shrink write-off of 410,000 dollars that nobody could allocate to a cause. The population: about 2,600 SKUs, 16.4 million dollars of stock at cost across the twelve depots, handheld scanning at nine depots and spreadsheet stock records at three (the two acquired distributors’ depots and one older site), 5,900 stock adjustments in the year netting to a 612,000-dollar write-down, and a returnable-container float of kegs and pallets carried against a 1.2-million-dollar deposit liability. The audit manager led it with a senior and the analytics auditor; the walkthrough took four days across four depots, the analytics ran before any count was scheduled, and the counts observed were chosen from the analytics rather than from the schedule. It closed at 640 hours.

TestPopulation and sampleWhat it foundWhere it went
1. Receiving integritySample 25 receipts across 6 depots; receipt-before-arrival analytic on all 41,000 receiptsTwenty-two of 25 posted on the day of arrival from a dock count; 1,140 receipts across the year posted before the carrier’s delivery scan, 830 of them at the three spreadsheet depots where the depot manager posted receipts from the purchase order.Finding, High (receiving on paper; combined with test 13)
2. Negative on-hand and phantom locationsFull populationFourteen percent of SKUs at one acquired depot went negative at some point in the year; 41 bins in use at two depots did not exist in the location master.Finding, Medium
3. Transfers and in transitSample 25; in-transit aging at three month-ends620,000 dollars in transit at year-end, 38 percent older than 30 days; two depot pairs had 90-day-old transfers that turned out to be stock that had never left and stock that had never arrived, in equal measure.Finding, Medium
4. Cycle count designSchedule against value classesThree depots had skipped A-item counts for two consecutive quarters; counts were not blind at seven depots because the handheld showed the expected quantity.Finding, Medium
5. Count observationTwo depots chosen from the analytics; 40 list-to-floor and 40 floor-to-list at eachList-to-floor: two pallets of a premium line missing at one depot, later traced to a breakage write-off posted three weeks after the count. Floor-to-list: 190 kegs on the yard at the other depot not on the system at all.Evidence for findings on adjustments and containers
6. Adjustment analyticsAll 5,900 adjustmentsSixty-one percent of adjustment value was posted by depot managers on their own depots’ stock with no independent approval; four depots showed period-end clusters; three depots accounted for 62 percent of the year’s net write-down.Finding, High
7. Adjustment approval25 from the hits plus all 31 above 5,000 dollarsInvestigation documented for 9 of 31 large adjustments; reason code “count variance” used for 70 percent of everything; two adjustments reversed a count variance at one depot and re-posted it a month later as breakage.Finding, High (with test 6)
8. Shipping and reliefSample 25All relieved on shipment; two route loads at a spreadsheet depot left on a handwritten load sheet keyed the next morning.Observation folded into test 13
9. Returns and scrap25 returns; all scrap above thresholdBreakage and out-of-date destruction witnessed at nine depots; at three, the depot manager certified his own scrap. Returned product restocked without inspection at two depots.Finding, Medium
10. Cut-offTen receipts and ten shipments either side of year-endClean; the receiving and shipping logs agreed to the last document numbers.No finding
11. CostingStandard cost review; one period-end runStandards updated in the year; average-cost anomalies on 14 SKUs traced to over-receipts at one depot.Observation
12. Obsolescence and expiryAging and reserve for one quarter, reperformed118,000 dollars of date-coded stock past its best-before date at five depots, not reserved and not blocked from picking; the reserve a flat percentage unchanged for three years.Finding, Medium
13. Segregation and physical accessActual roles; access lists; after-hours logAt the three spreadsheet depots the depot manager received, adjusted, counted and shipped; after-hours movements at one depot by a user whose badge was not on site.Finding, High (with test 1)
14. Reconciliations12 months, by depotPerpetual to ledger reconciled monthly in total, not by depot; the three spreadsheet depots plugged to the ledger figure.Finding, Low

The report carried nine findings, three High, five Medium and one Low, and an overall rating of Needs Improvement. Its most useful page was not a finding but an allocation: the 410,000-dollar FY26 write-off nobody could explain was, on the FY27 evidence, roughly a third receiving-on-paper at the spreadsheet depots (stock paid for and never physically confirmed), a third self-approved adjustments concentrated at three depots, and a third containers and expired stock that had never been counted at all, with a residual that looked like theft at one depot and was referred under the function’s allegation protocol. The 190 kegs on the yard and 1,900 kegs the container analytic could not account for, worth about 150,000 dollars, became a finding of their own, because the deposit liability had been carried against a float nobody had reconciled since the acquisitions. The after-hours movements by a badge that was not on site went to the protocol as well; it was a shared login. Three things generalise. Choose the counts you observe from the analytics, because the two depots the analytics chose produced the evidence and the schedule would have sent the team to the best-run site. Test adjustments as a population before you test counts, because at MidState the adjustments were where the shrink was being disposed of. And separate the spreadsheet sites in the report, because the controls at the nine handheld depots were mostly effective, and a single rating that averaged the two hid the actual problem, which was an integration decision made two years earlier.

The findings that recur, and wording that lands

Six findings account for most inventory reports, and each lands only with a numerator, a denominator and a named criterion, in five-Cs form. Self-approved adjustments (“61 percent of the year’s 612,000 dollars of net stock adjustments were posted by depot managers on their own depots’ stock without independent approval; the inventory policy requires finance approval above 5,000 dollars, and investigation was documented for 9 of the 31 adjustments above that threshold”). Receiving on paper (“1,140 receipts were posted before the carrier’s delivery scan, 830 of them at three depots where the depot manager posts receipts from the purchase order; the three-way match those receipts release therefore confirms nothing”). Stock in transit (“620,000 dollars was recorded in transit at year-end, 38 percent for more than 30 days; two depot pairs carried 90-day-old transfers representing stock that had not left and stock that had not arrived”). Count design (“A-item counts were skipped at three depots for two consecutive quarters, and counts were not blind at seven depots because the handheld displays the expected quantity”). Expired stock (“118,000 dollars of product past its best-before date was on hand at five depots, available to pick, and not reserved; the reserve is a flat percentage unchanged since 2024, which is not consistent with the lower-of-cost-and-net-realisable-value requirement of ASC 330”). Returnable containers (“1,900 kegs, about 150,000 dollars, cannot be accounted for against the 1.2-million-dollar deposit liability, which has not been reconciled to a physical float since the acquisitions”). Write the cause as the decision that produced the condition (the integration that left three depots on spreadsheets; the handheld configuration that shows expected quantities) rather than as a training gap, and follow the root cause guide for the step between the two.

Scoping variants: manufacturer, retailer, distributor, third-party warehouse

Manufacturer with work in progress: valuation takes the weight. Add tests on bills of materials and routings (do standards reflect the actual process), on the absorption of overhead (is the rate supported and applied consistently), on production reporting (are completions and scrap recorded at the right quantities), and on WIP existence (a partially built unit is hard to count and easy to overstate); coordinate closely with the external auditor, whose year-end work overlaps here. Retailer: shrink and count integrity take the weight, and the population is stores; choose store visits from shrink analytics rather than geography, add point-of-sale controls (voids, refunds, price overrides, sweethearting at the till) and the receiving-from-distribution-centre reconciliation, and treat the shrink number itself as the finding to be decomposed. Distributor: the handoffs and the containers take the weight, as at MidState; add route-load reconciliation (what left the depot against what was sold and what came back) and the returnable-container float. Stock held by a third-party warehouse or 3PL: the program applies, with a third-party layer on top: the provider’s SOC 1 report (does it cover inventory custody and counts, or only their systems), the complementary user controls you must operate, your right to count and to audit in the contract, and an independent confirmation and count at the provider at least annually; the SOC 1 review guide covers the reading, and the third-party risk management guide the oversight. Consignment stock, in either direction, needs a separate reconciliation because it is on somebody’s floor and somebody else’s books.

Where to go next

Audit inventory around the handoffs rather than the caption: receiving first, adjustments second, transfers and containers third, the counts as evidence rather than as the audit, and valuation last with the external auditor in the loop. The program above is a complete starting position; tune it with the walkthrough, size it with the sampling grid, build the file like the model workpaper, and report it with the report template. The buying side of the same flow is in how to audit procurement and how to audit accounts payable; the selling side in how to audit accounts receivable; and the question of what a control test proves, which the count observation raises in its sharpest form, is the subject of walkthrough versus test of controls.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading