Four guides on this site take procure-to-pay apart one stage at a time: procurement for how the deal is struck, the vendor master file for who gets paid, accounts payable for how the invoice becomes a liability, and payment operations for how the money leaves. Each of those audits is worth running, and each has a blind spot that is the same blind spot: the handoff. A procurement audit stops at the purchase order. An AP audit starts at the invoice. A vendor master audit tests the record and not the payment that trusts it. The frauds and the leakage that survive four clean stage audits live in the gaps between them, which is why the integrated procure-to-pay audit exists: it tests the chain as a chain, from the requisition that starts it to the reconciliation that closes it, and it tests the five handoffs where one function’s output becomes another function’s unexamined input.
This guide is the integrated version. It covers the terrain and the five handoffs, a risk map of the risks that live between stages, a twelve-control starter matrix for the chain, how to size and sequence the engagement, a 14-test program that reaches across every stage, the analytics that join the stages’ tables, Brightwater Foods’ year-two integrated engagement with every test’s result, the findings that recur with wording that lands, and how to scope the audit for plants, shared service centers, ERP migrations and small organizations. The ACFE’s Occupational Fraud 2026 report puts corruption, which is what a steered purchase usually is, in 45 percent of its 2,402 cases with a median loss of 150,000 dollars, and billing schemes, which are what a phantom vendor usually is, among the most common asset misappropriations; both are chain frauds, and both pass every single-stage test when the chain is not tested as one.
In this guide
- Know the terrain: the chain and its five handoffs
- The integrated risk map: risks that live between stages
- The starter RCM for the chain: twelve controls
- Sizing and sequencing the engagement
- The 14-test program
- Analytics across the chain
- Worked example: Brightwater Foods’ integrated P2P audit, year two
- The findings that recur, and wording that lands
- Scoping variants: plants, shared services, migrations, small organizations
- Where to go next
Know the terrain: the chain and its five handoffs
Procure-to-pay is a chain of seven links: a need is identified and a requisition raised; sourcing decides whether to compete it; a purchase order commits the organization; goods or services are received; an invoice arrives and is matched; the vendor master supplies the counterparty and the bank account; a payment run releases the money and the general ledger records it. Every link has a control and every control leaves a record, which is the good news. The bad news is that the links are owned by different functions, procurement, the requesting department, the warehouse, accounts payable, master data, treasury and the controller, and each function’s controls assume the previous function did its job. The three-way match assumes the purchase order was legitimately awarded. The award assumes the requisition described a real need. The payment assumes the master record is the vendor’s. Nobody’s control checks the assumption, and the assumption is where the integrated audit works.
The five handoffs below are the points where one function’s output becomes the next function’s input without examination. Each stage audit on this site tests the controls inside its stage; the integrated audit adds a test at each handoff, and the handoff tests are the ones that find what the stage audits cannot.
| Handoff | What the receiving function assumes | What breaks there | The integrated test |
|---|---|---|---|
| 1. Requisition to purchase order | Procurement assumes the requester’s need is real and correctly described | Gold-plating, year-end budget burn, specifications written for a predetermined vendor, needs split to stay under a cliff | Trace a stratified sample of purchase orders back past the requisition to the evidence of need and the budget line, and histogram requisition amounts against the cliffs |
| 2. Purchase order to receipt | The warehouse or the requester assumes what arrives is what was ordered at the quantity ordered | Short shipments received in full, services signed off without delivery, receiving in a system outside the ERP that never reconciles | Match the receiving log to purchase orders at line level for the year; test the interface reconciliation where receiving lives outside the ERP |
| 3. Receipt to invoice | Accounts payable assumes the match proves the purchase was legitimate | The perfect match on a steered award; tolerances wider than the policy says; overrides concentrated in one clerk or one vendor | Inspect the tolerance configuration, analyze the override log in full, and test that flagged awards from the procurement analytics were paid without any AP control noticing |
| 4. Vendor master to payment | The payment run assumes the bank account on the record belongs to the vendor | Bank-detail changes without an independent call-back; dormant records reactivated; payment within days of a change | Join the change log to the payment file and pull the verification record for every change followed by a payment within ten days |
| 5. Payment to ledger | The controller assumes the payment file matched what was approved and the liability was recorded in the right period | Manual payments outside the run, cut-off errors, unrecorded liabilities, suspense balances nobody clears | Reconcile three payment runs to the bank and the ledger; test cut-off and accruals at period end; age the suspense and clearing accounts |
The integrated risk map: risks that live between stages
The stage guides carry their own risk maps, and those risks remain in scope. The map below is the set that only appears when the chain is looked at whole, which is the set an integrated audit’s risk and control matrix should be built around. Each risk names a mechanism rather than a loss, for the reason the procurement guide gives: in this process the interesting failures are engineered to produce compliant records, and a risk statement that names the mechanism tells the tester what shape to look for.
| # | Cross-stage risk | Why the stage audits miss it | What it looks like in the data |
|---|---|---|---|
| R1 | Steered award paid through a perfect match: a rigged or sole-sourced purchase whose invoices match a genuine order and receipt | Procurement tests the file; AP tests the match; neither joins the award analytics to the payments | Flagged awards from the win-rate, bid-spread and sole-source analytics that were paid in full with no exception anywhere downstream |
| R2 | Displaced circumvention: fixing one threshold moves the splitting to the next one | The prior audit tested the cliff it found; nobody re-histograms the whole ladder | Clustering just under the tender or committee threshold after the plant-limit clustering disappeared |
| R3 | Contract-price leakage: invoices priced above the contract, uplifted each renewal, or billed against expired terms | The match tests the invoice to the order, and the order was raised at the invoiced price | Invoice unit prices against contract price lists for the largest vendors; increases without an indexation clause |
| R4 | Phantom or captured vendor: a record created by an insider, fed by invoices the same insider approves | Vendor master tests the record; AP tests the approval; the creator-approver join is nobody’s test | Vendors created and approved for payment by the same user or the same cost center; employee-vendor matches; sequential invoice numbers |
| R5 | Receiving fiction: goods or services received in the system before or without delivery | The warehouse system sits outside the ERP; AP sees a receipt and matches | Receipts posted before the delivery date on the carrier record; service receipts signed off by the requester; receipts posted days after the invoice, in batches |
| R6 | Payment redirection: a genuine liability paid to the wrong account | The change was verified in the vendor master audit’s sample, not for the change that preceded this payment | Payments within ten days of a bank-detail change; changes made outside the portal; changes reversed after payment |
| R7 | Period and ledger drift: liabilities recorded late, manual payments outside the run, suspense used as a parking lot | Payment tests stop at the bank; close tests start at the ledger | Invoices dated before period end received after it and not accrued; manual payment share rising; suspense items older than sixty days |
| R8 | Remediation decay: last year’s fixes reverting under volume pressure | Each stage audit validates its own findings once; nobody re-tests the chain a year later | The prior year’s analytics re-run showing the same shapes returning in the last quarter |
The starter RCM for the chain: twelve controls
An integrated matrix is not the four stage matrices stapled together; it would run to eighty rows and test nothing new. It is the shorter list of controls that hold the chain together, the ones that operate at a handoff or across several stages, with the stage-level controls referenced rather than repeated. Twelve rows carry most organizations. Build them in the RCM template, mark which exist, and treat a missing row as a design finding before any transaction is tested.
| Control | Stage or handoff | Risk | How to test it |
|---|---|---|---|
| One delegation of authority covering requisition, award, receipt sign-off, invoice approval and payment release, enforced in the system at each step | Whole chain | R2, R4 | Export the system’s approval configuration at each step and reconcile it to the policy; test the exceptions the export reveals rather than sampling approvals |
| Requisition approved against a budget line by someone other than the requester before the purchase order is raised | Handoff 1 | R1, R2 | Full-population test of PO date against requisition approval date; sample the approvals for evidence of need |
| Competition or a justified exception above every threshold, with the memo standard the procurement guide sets | Procurement | R1 | Population of awards above threshold tested for competition or memo; the market check re-performed on a sample |
| Purchase order raised before goods or services are ordered; after-the-fact orders permitted only under a documented emergency rule | Handoff 1 and 2 | R5 | PO date against invoice date and delivery date; every after-the-fact order tested for the rule |
| Receipt recorded by someone other than the requester, at line level, with the receiving system reconciled to the ERP monthly | Handoff 2 | R5 | Receiver identity against requester for the year; the twelve interface reconciliations inspected |
| Three-way match with tolerances set by policy, and override rights restricted to a supervisor with a monitored log | Handoff 3 | R1, R3, R5 | Configuration inspected; override log analyzed in full for concentration by user and vendor |
| Contract price lists loaded to the system for contracted vendors, with invoices matched to contract price rather than to the order price | Handoff 3 | R3 | Invoice unit prices for the largest vendors against the contract schedule; increases traced to an indexation clause |
| Vendor creation by master data after the verification ladder, never by the requester, with bank changes dual-approved and verified through an independent channel | Vendor master, handoff 4 | R4, R6 | Creator against requester for every new record; the verification record for every change followed by payment within ten days |
| Payment run released under dual control, reconciled to the approved register, with manual payments requiring the same approvals plus a reason code | Handoff 4 and 5 | R6, R7 | Three runs re-performed; the manual payment population tested in full for approvals and reason codes |
| Cut-off and accrual procedures at period end that capture goods received not invoiced and invoices received after the period for goods received before | Handoff 5 | R7 | Search for unrecorded liabilities on the first six weeks after year end; GRNI aging reviewed |
| Chain analytics run monthly by finance or by continuous audit, with hits triaged and dispositioned | Whole chain | R1 to R8 | Twelve months of the monitoring output and dispositions inspected; a metric that moved traced to an action |
| Prior findings tracked to closure with the fix re-tested after volume pressure, not just at the closure date | Whole chain | R8 | The prior year’s findings re-tested on the last quarter’s data |
Sizing and sequencing the engagement
An integrated P2P audit is larger than any single stage audit and smaller than the four of them combined, because the analytics do most of the population work once and the file work is aimed by the hits. The ranges below assume a mid-sized organization with a single ERP, receiving in a separate warehouse system, a few thousand vendors and an analytics-capable auditor or co-source specialist. Two things stretch it: multiple ERPs, where every join has to be built twice, and a first-time engagement with no prior stage audits to build on, where the walkthrough alone can take a week. Record the sizing decisions in the sampling memo and write the program to the five-element standard in the work program guide.
| Phase | What happens | Hours |
|---|---|---|
| Planning and the boundary | Prior stage audits and their open findings read; the chain RCM drafted; the delegation of authority and every threshold listed as at each date in the period | 40 |
| Walkthrough of the chain | One purchase of each type (stock, service, capital, emergency) walked from requisition to ledger at head office and at one plant or site | 30 to 40 |
| Data acquisition and joins | Requisitions, purchase orders, receipts, invoices, payments, vendor master with change history, employee master, contracts and tenders extracted with completeness proofs and joined on reconciled keys | 50 to 70 |
| Chain analytics | The cross-stage catalog run on the full year; hits scored and triaged | 60 to 80 |
| Handoff and control tests | The 14-test program, with the file work aimed by the analytics | 120 to 160 |
| Remediation re-test | Every prior-year finding across the four stages re-tested on the last quarter’s data | 30 to 40 |
| Reporting | Findings written to the chain, not to the function; base rates on every number; referrals under the protocol | 50 |
| Total | 380 to 480 |
Sequence matters in three places. The walkthrough goes before the analytics, because the thresholds and tolerances you test have to be the ones in force at the plants, not the ones in the policy document. The analytics go before the file work, because the joins choose the files. And the remediation re-test goes last, on the final quarter’s data, because a fix that held in the quarter after the audit and reverted in the fourth is the R8 finding, and it is only visible at the end.
The 14-test program
The program below reaches across every stage. Tests that belong wholly inside one stage are referenced to that stage’s guide and run there in the depth that guide describes; the integrated program samples them only far enough to confirm the stage controls still operate. The tests that matter here are the handoff tests and the joins, and those run at full population wherever the data allows.
| # | Test | Population and method | Risk |
|---|---|---|---|
| 1 | Walk the chain and reconcile the process as performed to the delegation of authority at every step; redraw the RCM to the process that exists | One purchase per type, at head office and one site | All |
| 2 | Requisition-to-order integrity: PO date against requisition approval; approver against requester; evidence of need for a stratified sample | Full population for dates and identities; sample 25 for need | R1, R2 |
| 3 | Threshold ladder: histogram requisition, PO and award amounts against every cliff, not just the one the last audit found | Full population | R2 |
| 4 | Award-to-payment join: every award flagged by the procurement analytics traced through receipt, match and payment for any downstream exception | All flagged awards | R1 |
| 5 | Receiving integrity: receiver against requester; receipt date against carrier or delivery evidence for a sample; the receiving-system interface reconciliation for twelve months | Full population for identities; sample 25 for dates; twelve reconciliations | R5 |
| 6 | Match configuration and overrides: tolerances inspected against policy; override log analyzed in full by user, vendor and timing | Configuration; full override log | R1, R3, R5 |
| 7 | Contract-price compliance: invoice unit prices for the twenty largest contracted vendors against the contract schedule; increases traced to indexation clauses | Twenty vendors, full year of invoice lines | R3 |
| 8 | Creator-approver join: vendors created, invoices approved and payments released by the same user or cost center; employee-vendor match re-performed | Full population | R4 |
| 9 | Bank-change-to-payment: every bank-detail change followed by a payment within ten days, with the verification record inspected | Full population of changes | R6 |
| 10 | Payment run and manual payments: three runs re-performed to the bank and ledger; every manual payment tested for approvals and reason code | Three runs; full manual population | R6, R7 |
| 11 | Duplicate payments across the chain: the AP analytics ladder re-run, with hits traced to root cause in the stage that produced them | Full population | R3, R4 |
| 12 | Cut-off and unrecorded liabilities: invoices received in the six weeks after period end for goods or services received before it; GRNI aging; suspense and clearing accounts aged | Full six-week population; ledger accounts | R7 |
| 13 | Monitoring: twelve months of chain analytics or management reporting, with dispositions; a metric that moved traced to an action | Twelve months | R1 to R8 |
| 14 | Remediation re-test: every open or closed prior-year finding across the four stage audits re-tested on the last quarter’s data | All prior findings | R8 |
Tests 4, 7, 8, 9 and 14 are the ones a stage audit cannot run, and they are the reason to run the integrated engagement at all. Test 4 in particular changes the character of the audit: an award that the procurement analytics flagged and the file review could not resolve becomes a different finding when the join shows it was paid in full, on time, at a price above the losing bids, with no downstream control noticing. Nothing in that sentence is a fraud conclusion, and everything in it belongs in a report.
Analytics across the chain
The single-table tests live in the AP analytics catalog and the payroll catalog‘s sister logic; the cross-stage joins live in the P2P fraud analytics catalog, which is the engine of this engagement. The eight below are the ones the integrated program depends on, stated plainly enough to build in SQL or in a spreadsheet, with the handoff each one tests.
| Analytic | Tables joined | Logic | A hit usually means |
|---|---|---|---|
| Award-to-payment trace | Tenders, purchase orders, invoices, payments | For every award flagged upstream, sum the payments and compare to the award value, the losing bids and the contract | A steered or grown award paid without friction; the R1 signature |
| Ladder histogram | Requisitions, purchase orders, awards | Density just under each cliff against density just above, for every cliff in force | Circumvention at the cliff with the spike, including a cliff that was never tested before |
| PO-after-invoice and PO-after-receipt | Purchase orders, invoices, receipts | Orders raised after the invoice date or after the receipt date, by cost center and requester | After-the-fact ordering; the control operates as a formality |
| Receiver-requester overlap | Receipts, requisitions, HR master | Receipts posted by the requester or by a user in the requester’s cost center | Receiving fiction risk; a segregation break |
| Contract price variance | Invoice lines, contract price lists | Unit price on the invoice against the contracted price on the date, by vendor and item | Leakage; renewals without re-bid; expired contracts still billed |
| Creator-approver-releaser | Vendor master change log, invoice approvals, payment file, user list | Any user appearing in two or more of the three roles for the same vendor | The insider chain; the phantom vendor’s construction material |
| Change-then-payment | Vendor master change log, payments | Payments within N days of a bank-detail change, weighted by amount | Redirection risk; the verification record is pulled for every large hit |
| Quarter-over-quarter remediation drift | All of the above, by quarter | Each prior-year finding’s analytic re-run per quarter; the trend read for reversion | A fix that held, then did not; the R8 finding |
Worked example: Brightwater Foods’ integrated P2P audit, year two
Brightwater Foods, the 180-million-dollar food manufacturer with three plants and about 600 staff used across this site, had spent a year auditing procure-to-pay in pieces. The co-sourced function’s analytics run over eighteen months of data found two referrals and five control findings on the payment and vendor side; the rebuilt function’s procurement audit found nine findings on the front end, three of them High, including a refrigeration contract that grew from 640,000 to 912,000 dollars through eleven unapproved change orders and a sole-source program that had quietly reached 16 percent of award value. The next year’s plan replaced the stage audits with one integrated engagement, partly to re-test the remediation across the chain and partly because the chief audit executive wanted to know whether the fixes had moved the problems rather than solved them. The window was the twelve months after the procurement audit: 15,600 invoices, 6,300 purchase orders, 1,710 active vendors after the cleanse, 28 tenders and 610 employees. The engagement took 420 hours, 80 of them the co-source specialist re-running and extending the analytics.
| Test | What it found | Disposition |
|---|---|---|
| 1. Chain walkthrough | Two plants had adopted the central requisition path; the third plant’s buyer still used a legacy requisition form for maintenance parts under the 10,000-dollar limit, outside the system’s approval routing. | Finding, Medium: the local purchase path at one plant |
| 2. Requisition to order | 190 purchase orders raised after the invoice date in the year, 22 without an emergency justification, down from 38 in the prior eighteen months; requisition approvals by someone other than the requester in every case tested. | Finding, Low; improving |
| 3. Threshold ladder | No clustering under the 10,000-dollar plant limit after the prior year’s fix. Seven contracts between 90,000 and 99,900 dollars, just under the 100,000-dollar tender threshold, four of them with the same vendor for scope that read as one project. | Finding, Medium: displaced circumvention |
| 4. Award-to-payment join | The prior year’s flagged maintenance contractor, six of seven tenders won with single-evaluator scoring, was paid 610,000 dollars in the year against awards of 585,000 dollars; the difference was two change orders, both re-approved. The four contracts under the tender threshold in test 3 were paid in full at contract price. | Reported inside finding 3; the contractor pair flagged again for the next run |
| 5. Receiving integrity | Receiving still lived in the warehouse system; the monthly interface reconciliation existed for ten of twelve months. Eleven service receipts in the sample were signed off by the requester. | Finding, Low: interface reconciliation and service receipt sign-off |
| 6. Match and overrides | Tolerance 2 percent or 150 dollars as the policy states; 130 overrides in the year, spread across four supervisors, none concentrated by vendor; override authority restricted as the prior year’s finding required. | Remediation verified; no finding |
| 7. Contract-price compliance | Three of the twenty largest contracted vendors billed above the contracted price for part of the year, 41,000 dollars in total, one of them after an unindexed increase the buyer had accepted by email; 38,500 dollars recovered during fieldwork. | Finding, Medium: contract price matching |
| 8. Creator-approver-releaser | No user in two of the three roles for any vendor; employee-vendor match re-performed with no new hits after the screening control at creation. | Remediation verified |
| 9. Bank change to payment | 44 bank-detail changes, 43 with a complete verification record; one made by an AP user through the portal with the call-back recorded to a number taken from the request, followed by a payment of 9,200 dollars that proved genuine. | Finding, Low: the channel-independence line |
| 10. Payment run and manual payments | Three runs reconciled to the bank and ledger under dual control; 96 manual payments in the year, nine without a second approver, all to genuine vendors under plant deadline pressure. | Finding, Medium: manual payment approvals |
| 11. Duplicates | Fourteen confirmed duplicate payments, 23,800 dollars, eleven of them re-keyed invoices from the plant that still used the legacy requisition path; 21,000 dollars recovered. | Reported inside finding 1, with the recovery |
| 12. Cut-off and accruals | 41 invoices received in the six weeks after year end for goods received before it, 310,000 dollars; nine were not accrued, 52,000 dollars, below the audit’s materiality but inside the pattern the external auditor had raised. | Finding, Low |
| 13. Monitoring | Finance ran four of the chain analytics quarterly since the remediation, with dispositions; the ladder histogram was not among them, which is why test 3’s clustering was new to management. | Ladder added to the quarterly pack |
| 14. Remediation re-test | All nine prior findings re-tested on the final quarter: seven held; the sole-source rate had fallen from 16 to 11 percent with the memo template in use on 17 of 19 awards and the sanitation chemicals supply competed at a 9 percent saving; the refrigeration contract had closed and six later contracts with change orders above 10 percent were all re-approved at the right level; the two that had not fully held were the plant requisition path (test 1) and the conflict declarations, current for 91 of 91 people with influence at the start of the year but not refreshed for fourteen new evaluators since. | Two findings reopened, both Medium or below |
The report carried eight findings, four Medium and four Low, no High, no referrals, and an overall rating of Satisfactory, which the audit committee questioned and then accepted on the reasoning the report gave: every prior High had been remediated and re-tested on the year’s final quarter, the new findings were leakage and drift rather than absent controls, and the amounts had denominators, 41,000 dollars of contract-price leakage on 38 million dollars of contracted spend, 23,800 dollars of duplicates on 15,600 invoices. Three things about the engagement generalize. The displaced clustering under the tender threshold is the most useful lesson in the file: fixing the 10,000-dollar cliff had moved the behavior to the 100,000-dollar one, and a stage audit that re-tested only its own finding would have called the remediation a success. The contract-price finding was new because no stage audit tests it: procurement stops at the award, AP matches to the order, and the order is raised at whatever price the vendor invoiced last time. And the join in test 4 turned the prior year’s unresolved win-rate pattern into a sentence the committee could act on, six of seven tenders, 610,000 dollars paid, all at contract, no downstream exception, which is not an allegation and is exactly the kind of fact that a procurement lead now has to explain at the next tender.
The findings that recur, and wording that lands
Integrated findings are written to the chain, not to the function, which changes their shape: the condition names the handoff, the cause usually sits in a different function from the one that showed the symptom, and the recommendation is a control at the boundary rather than more diligence on one side of it. The two below are the ones that recur most, in the five-Cs form the findings masterclass sets out.
Contract-price leakage. Condition: invoices from three of the twenty largest contracted vendors were paid at unit prices above the contracted price for between two and nine months of the year, 41,000 dollars in total; in each case the purchase order had been raised at the invoiced price and the three-way match therefore passed. Criteria: the procurement policy requires contracted prices to be applied for the contract term, and increases to be supported by an indexation clause or a re-bid. Cause: the ERP matches invoices to purchase orders, not to contract price lists, and no control compares order prices to contracted prices when the order is raised. Consequence: leakage of 41,000 dollars in the year, of which 38,500 dollars has been recovered, and no assurance that the remaining contracted spend of 38 million dollars is billed at contract. Corrective action: management will load contract price lists for all contracted vendors by the second quarter and configure the match to test invoice price against contract price, with exceptions routed to procurement; internal audit will re-run the contract price variance analytic quarterly until the control has operated for two quarters.
Displaced threshold circumvention. Condition: seven contracts were awarded at values between 90,000 and 99,900 dollars in the year, four of them to one vendor for scope that management confirmed was a single project, in a period when no clustering remained under the 10,000-dollar plant limit that the prior year’s audit had reported. Criteria: purchases above 100,000 dollars require a formal tender; splitting a requirement to avoid a threshold is prohibited by policy. Cause: the prior remediation changed the approval logic at the plant limit and left the tender threshold’s monitoring to a quarterly report that did not include amount clustering. Consequence: 380,000 dollars of related scope was awarded without competition, and the pricing obtained cannot be shown to be market-based. Corrective action: management will add the full threshold ladder to the quarterly monitoring pack, require an aggregate-scope check before any award within 10 percent of a threshold, and compete the remaining scope of the project at its next phase.
Scoping variants: plants, shared services, migrations, small organizations
Plants and sites are where the chain as performed diverges from the chain as documented, and the integrated audit should walk at least one purchase at a site for every purchase it walks at head office. Local buyers under a plant limit, receiving in a system the ERP does not see, and maintenance emergencies that bypass the requisition are the three patterns to expect, and all three were present at Brightwater in some form for two consecutive years. Shared service centers move the AP and master-data links to one place and leave the requisition, award and receipt links distributed, which puts the risk at handoffs 1 and 2: test whether the center can refuse a bad input, and whether the sites have kept local rights for speed. ERP migrations and acquisitions manufacture the R4 and R7 risks at scale, because migrated vendor records inherit trust they never earned and migrated open orders and receipts land in the new system without their history; audit the migrated population as unverified, and run the duplicate ladder across both systems for the year after cut-over. Outsourced payables, whether a business process provider or a managed service, keep the risk and move the keying; the provider’s SOC 1 report lists the complementary user entity controls it assumes the client operates, and the SOC 1 review method shows how to test them, with the independent call-back on bank changes almost always among them. Small organizations cannot separate seven links across seven functions; the compensating control is an owner outside purchasing and payables, usually the controller, who approves every award above a low threshold and every bank change with the evidence in front of them, and the integrated audit for a small organization is largely a test of whether that person is actually looking.
One boundary decision applies everywhere. The integrated audit is not a substitute for the stage audits’ depth; it is the engagement that tests what they cannot. A function with the hours for one engagement a year on this cycle should run the integrated audit and use its analytics to choose which stage gets the deep engagement the following year, which is the rotation Brightwater settled on: the chain every year, one stage in depth on top of it, chosen by the hits.
Where to go next
Run the stage audits for depth and the integrated audit for the handoffs. Build the chain matrix from the twelve controls above, sequence the walkthrough before the analytics and the analytics before the files, re-test last year’s fixes on this year’s last quarter, and write the findings to the chain so that the cause lands in the function that owns it rather than the one that showed the symptom. When a hit clusters around a person or a vendor, the first 48 hours protocol takes over from the program, and the procurement fraud schemes guide explains what the cluster is likely to be. The order-to-cash side of the business gets the same treatment in the receivables guide, and the two cycles meet at the bank in cash management and bank reconciliations.
Related guides
- How to audit procurement — the front end, with Brightwater’s year-one engagement
- How to audit the vendor master file — the record every payment trusts, with MidState’s engagement
- How to audit accounts payable — the back end, with a 14-test program and MidState’s worked engagement
- How to audit payment operations and wire transfers — the bank interface and the hours after a bad payment
- The P2P fraud analytics catalog — the cross-stage joins this engagement runs on
- The accounts payable analytics catalog — the single-table tests the joins are built from
- Procurement fraud schemes — bid rigging, kickbacks and phantom vendors, and how each uses the chain
- The ACFE fraud tree explained — corruption and billing schemes in context
- When internal audit finds fraud: the first 48 hours — what to do with a cluster
- The risk and control matrix template — where the chain matrix lives
- Writing the audit work program — the five-element procedure standard the 14 tests follow
- The sampling memo template — recording the sizing and stratification decisions
- Segregation of duties beyond the ERP — the creator-approver-releaser logic as a segregation framework
- How to review a SOC 1 report — testing an outsourced payables provider’s assumed controls
- The 5 C’s of audit findings — the form the two findings above are written in
- The finding and issue log template — tracking remediation across four functions
- How to audit accounts receivable — the mirror-image cycle
- Fieldwork and testing guides and internal controls guides — the full collections
Leave a Reply