Internal audit explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Purchases and stock are where most small and mid-sized businesses lose money quietly: an inflated rate, a duplicate payment, goods received short, stock that exists only in the system. An internal audit of this cycle follows the purchase from need to payment and then to the stock room. This guide gives an illustrative programme, built on the ICAI Standards on Internal Audit, that finance heads can use to prepare or to commission such an audit.
There is no standard on internal audit specific to procurement. The approach rests on SIA 120 (evaluating internal controls), SIA 130 (risk-based audit), SIA 310 (planning the assignment) and SIA 320 (evidence), from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). The control lists and tests below are TaxClue's own and are illustrative; nothing in them is mandatory unless a cited standard or a linked law post says so. Under paragraph 5.1 of the Preface the ICAI Council decided to make the SIAs mandatory in a phased manner (see our article on the Standards on Internal Audit). Check the current SIA versions on internalaudit.icai.org.
Plan from a risk assessment, document the cycle, test the design and operating effectiveness of key controls, and gather enough reliable evidence for each finding. In procurement the usual control points are vendor master, authorisation, three-way matching, payment and stock custody. The report states each finding with its risk, evidence and agreed action.
How the SIAs shape the audit
- Risk first. SIA 130, paragraph 5.1, asks for risk-based audits so effort goes where it matters; SIA 310, paragraph 3.4, asks for an independent risk assessment of the unit before testing.
- Controls are tested for design and operation. SIA 120, paragraph 5.2, requires procedures sufficient to check design, implementation and operating effectiveness, and paragraph 5.3 directs work mainly to high and medium risk controls, linked to risks in a document such as a risk control matrix.
- Programme and evidence. SIA 310, paragraph 3.5, requires an Internal Audit Programme; SIA 320, paragraph 3.1, requires sufficient and appropriate evidence from reliable sources. See our guide to SIA 310, 320, 330 and 350.
Our guide to SIA 120 explains the control terms used here. Stock held by the business is also examined in a stock audit; see our stock audit service for physical verification and valuation checks.
Purchase-to-pay: an illustrative control and test map
| Stage | Illustrative risk | Illustrative key control | Illustrative test |
|---|---|---|---|
| Vendor creation | Fictitious or conflicted vendor | Approval and background check before creation; change log | Match vendor bank, address and PAN data to employee master; review changes in the period |
| Requisition and order | Purchase without approval; splitting to stay under limits | Approval matrix; purchase order before commitment | Compare orders to the matrix; group orders by vendor and day |
| Rate selection | Inflated rates | Quotations or rate contract for purchases above a set value | Compare rates paid with contract and other vendors |
| Goods receipt | Short receipt, wrong quality | Goods receipt note against order, quality check | Compare GRN quantities to invoice and order |
| Invoice processing | Duplicate or unmatched invoice | Three-way match of order, GRN and invoice; duplicate check | Re-run duplicate test on vendor, invoice number, date and amount |
| Payment | Payment before due date, to wrong account, or without approval | Payment approval separate from preparer; bank detail change controls | Compare payment dates to terms; review bank-detail changes |
| Accounting | Liabilities missing at period end | Cut-off review of GRNs not invoiced | Trace goods received before year end to recorded liability |
Payment timing for micro and small enterprise suppliers is governed by law, which this guide does not restate; read our post on the MSME payment rule for buyers and test whether the system flags such vendors and due dates.
Inventory: an illustrative control and test map
| Area | Illustrative risk | Illustrative control | Illustrative test |
|---|---|---|---|
| Receipts into store | Goods received but not recorded | GRN numbering in sequence; store sign-off | Check GRN sequence for gaps; compare to gate entries |
| Issues | Issue without authority | Requisition slip approved by department head | Match issues to approved slips |
| Custody | Theft, damage | Access restrictions, store layout, periodic counts | Observe the store; check keys and access logs |
| Counting | Book and physical stock differ | Cycle counts and year-end count with reconciliation | Attend a count; re-count a selection; trace differences |
| Valuation | Slow-moving or obsolete stock carried at full value | Ageing review and provisioning policy | Review ageing; test price lists and cost build-up |
| Stock with third parties | Goods held elsewhere not confirmed | Periodic confirmation from the holder | Obtain confirmations; inspect agreements |
For the statutory audit view of count attendance and valuation, see our article on audit of inventories.
Red flags in the cycle
Illustrative signals that deserve a closer look: a vendor with no phone or address on file or sharing details with an employee; vendors paid in round sums just under an approval limit; invoices numbered consecutively over several months; rates that rise without a contract change; payment of an invoice before the goods receipt; repeated manual overrides of the three-way match; store adjustments posted by the storekeeper alone; and stock counts that agree to the book to the last unit. Red flags are starting points, not conclusions; where they point to possible fraud, see our article on fraud risk and red flags.
Reporting the findings
Each finding should state the observation, the criteria (policy or control that applies), the evidence and its extent, the risk, a recommendation, management's response with owner and date, and a rating. SIA 370, paragraph 3.1, asks for scope, a summary of key observations and agreed corrective actions, and paragraph 3.3 requires a draft to go to the auditee before the report is final; our article on SIA 360, 370 and 390 covers this.
Illustrative example
Illustrative: Anand Fasteners Pvt Ltd buys raw material worth about 6 crore a year. The internal auditor selects 60 purchase invoices from 900 above a set value and tests three-way matching. Four invoices were paid with no goods receipt note; all four are from one vendor whose bank account was changed twice in the year with no documented approval. The auditor extends testing to every invoice from that vendor, finds rates 8 per cent above the contract, and reports the vendor-master and bank-change controls as design gaps and the matching failures as operating exceptions. A store count finds two items 5 and 7 per cent short against the book; the cause traced is issues without slips. All findings are recorded with evidence, and management agrees owners and dates.
Common lapses
- Testing paid invoices only and not goods received but not invoiced.
- Sampling only the largest vendors and missing many small, split orders.
- Treating the stock count as a once-a-year event with no reconciliation of differences.
- Reporting "weak controls" without naming the control, the evidence and the risk.
Need help reviewing stock and purchase controls?
If you want a physical stock check or a review of purchase and stock controls before the year-end count, our team can assist with a stock audit and a written findings report.
Key takeaways
- Start from a risk assessment and an Internal Audit Programme (SIA 310, paragraphs 3.4 and 3.5).
- Test design and operation of key controls, concentrating on high and medium risk (SIA 120, paragraphs 5.2 and 5.3).
- Typical control points are vendor master, approval, three-way match, payment and stock custody; the lists here are illustrative.
- Red flags are prompts for enquiry, not proof.
- Share a draft with the auditee and report each finding with evidence and an agreed action.
Read next
- Internal audit of sales and receivables
- SIA 120: internal controls and internal financial controls
- SIA 310, 320, 330 and 350: planning, evidence, documentation and review
- Audit of inventories
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
