Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026in 2 days 11 OCTGSTR-1 · Outward supplies · Sep 2026in 6 days 15 OCTPF & ESI · Contributions · Sep 2026in 10 days 20 OCTGSTR-3B · Summary return · Sep 2026in 15 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 25 days 31 OCTITR filing · Audit cases · AY 2026-27in 26 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 55 days 15 DECAdvance Tax · 3rd (75%) instalment · FY 2026-27in 71 days
All due dates

Internal audit of procurement and inventory: the purchase-to-pay cycle, key controls, tests an internal auditor runs, red flags and how findings are reported

Plan from a risk assessment, document the cycle, test the design and operating effectiveness of key controls, and gather enough reliable evidence for each finding. In procurement...

Published
Updated
Reading time
7 min
Views
2
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 5, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Purchases and stock are where most small and mid-sized businesses lose money quietly: an inflated rate, a duplicate payment, goods received short, stock that exists only in the system. An internal audit of this cycle follows the purchase from need to payment and then to the stock room. This guide gives an illustrative programme, built on the ICAI Standards on Internal Audit, that finance heads can use to prepare or to commission such an audit.

There is no standard on internal audit specific to procurement. The approach rests on SIA 120 (evaluating internal controls), SIA 130 (risk-based audit), SIA 310 (planning the assignment) and SIA 320 (evidence), from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). The control lists and tests below are TaxClue's own and are illustrative; nothing in them is mandatory unless a cited standard or a linked law post says so. Under paragraph 5.1 of the Preface the ICAI Council decided to make the SIAs mandatory in a phased manner (see our article on the Standards on Internal Audit). Check the current SIA versions on internalaudit.icai.org.

How the SIAs shape the audit

  • Risk first. SIA 130, paragraph 5.1, asks for risk-based audits so effort goes where it matters; SIA 310, paragraph 3.4, asks for an independent risk assessment of the unit before testing.
  • Controls are tested for design and operation. SIA 120, paragraph 5.2, requires procedures sufficient to check design, implementation and operating effectiveness, and paragraph 5.3 directs work mainly to high and medium risk controls, linked to risks in a document such as a risk control matrix.
  • Programme and evidence. SIA 310, paragraph 3.5, requires an Internal Audit Programme; SIA 320, paragraph 3.1, requires sufficient and appropriate evidence from reliable sources. See our guide to SIA 310, 320, 330 and 350.

Our guide to SIA 120 explains the control terms used here. Stock held by the business is also examined in a stock audit; see our stock audit service for physical verification and valuation checks.

Purchase-to-pay: an illustrative control and test map

StageIllustrative riskIllustrative key controlIllustrative test
Vendor creationFictitious or conflicted vendorApproval and background check before creation; change logMatch vendor bank, address and PAN data to employee master; review changes in the period
Requisition and orderPurchase without approval; splitting to stay under limitsApproval matrix; purchase order before commitmentCompare orders to the matrix; group orders by vendor and day
Rate selectionInflated ratesQuotations or rate contract for purchases above a set valueCompare rates paid with contract and other vendors
Goods receiptShort receipt, wrong qualityGoods receipt note against order, quality checkCompare GRN quantities to invoice and order
Invoice processingDuplicate or unmatched invoiceThree-way match of order, GRN and invoice; duplicate checkRe-run duplicate test on vendor, invoice number, date and amount
PaymentPayment before due date, to wrong account, or without approvalPayment approval separate from preparer; bank detail change controlsCompare payment dates to terms; review bank-detail changes
AccountingLiabilities missing at period endCut-off review of GRNs not invoicedTrace goods received before year end to recorded liability

Payment timing for micro and small enterprise suppliers is governed by law, which this guide does not restate; read our post on the MSME payment rule for buyers and test whether the system flags such vendors and due dates.

Inventory: an illustrative control and test map

AreaIllustrative riskIllustrative controlIllustrative test
Receipts into storeGoods received but not recordedGRN numbering in sequence; store sign-offCheck GRN sequence for gaps; compare to gate entries
IssuesIssue without authorityRequisition slip approved by department headMatch issues to approved slips
CustodyTheft, damageAccess restrictions, store layout, periodic countsObserve the store; check keys and access logs
CountingBook and physical stock differCycle counts and year-end count with reconciliationAttend a count; re-count a selection; trace differences
ValuationSlow-moving or obsolete stock carried at full valueAgeing review and provisioning policyReview ageing; test price lists and cost build-up
Stock with third partiesGoods held elsewhere not confirmedPeriodic confirmation from the holderObtain confirmations; inspect agreements

For the statutory audit view of count attendance and valuation, see our article on audit of inventories.

Red flags in the cycle

Illustrative signals that deserve a closer look: a vendor with no phone or address on file or sharing details with an employee; vendors paid in round sums just under an approval limit; invoices numbered consecutively over several months; rates that rise without a contract change; payment of an invoice before the goods receipt; repeated manual overrides of the three-way match; store adjustments posted by the storekeeper alone; and stock counts that agree to the book to the last unit. Red flags are starting points, not conclusions; where they point to possible fraud, see our article on fraud risk and red flags.

Reporting the findings

Each finding should state the observation, the criteria (policy or control that applies), the evidence and its extent, the risk, a recommendation, management's response with owner and date, and a rating. SIA 370, paragraph 3.1, asks for scope, a summary of key observations and agreed corrective actions, and paragraph 3.3 requires a draft to go to the auditee before the report is final; our article on SIA 360, 370 and 390 covers this.

Illustrative example

Illustrative: Anand Fasteners Pvt Ltd buys raw material worth about 6 crore a year. The internal auditor selects 60 purchase invoices from 900 above a set value and tests three-way matching. Four invoices were paid with no goods receipt note; all four are from one vendor whose bank account was changed twice in the year with no documented approval. The auditor extends testing to every invoice from that vendor, finds rates 8 per cent above the contract, and reports the vendor-master and bank-change controls as design gaps and the matching failures as operating exceptions. A store count finds two items 5 and 7 per cent short against the book; the cause traced is issues without slips. All findings are recorded with evidence, and management agrees owners and dates.

Common lapses

  • Testing paid invoices only and not goods received but not invoiced.
  • Sampling only the largest vendors and missing many small, split orders.
  • Treating the stock count as a once-a-year event with no reconciliation of differences.
  • Reporting "weak controls" without naming the control, the evidence and the risk.

Need help reviewing stock and purchase controls?

If you want a physical stock check or a review of purchase and stock controls before the year-end count, our team can assist with a stock audit and a written findings report.

Key takeaways

  • Start from a risk assessment and an Internal Audit Programme (SIA 310, paragraphs 3.4 and 3.5).
  • Test design and operation of key controls, concentrating on high and medium risk (SIA 120, paragraphs 5.2 and 5.3).
  • Typical control points are vendor master, approval, three-way match, payment and stock custody; the lists here are illustrative.
  • Red flags are prompts for enquiry, not proof.
  • Share a draft with the auditee and report each finding with evidence and an agreed action.

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Internal audit

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Is there an ICAI standard on internal audit of procurement?

No. The approach rests on SIA 120, 130, 310 and 320; the checklist in this article is illustrative.

What is a three-way match?

A check that the purchase order, the goods receipt and the supplier invoice agree on quantity and price before payment. It is a common control, not a requirement of any SIA.

Provisions and estimates should be made honestly; the next year's figures will test them.

— TaxClue Accounts & Audit Desk

Internal audit: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,327 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. The approach rests on SIA 120, 130, 310 and 320; the checklist in this article is illustrative.

A check that the purchase order, the goods receipt and the supplier invoice agree on quantity and price before payment. It is a common control, not a requirement of any SIA.

That is a matter of judgement under the sampling guidance; see our article on SIA 5 and SIA 6.

The auditor may observe or re-count a selection; the full count is management's responsibility.

SIA 11, paragraph 19, asks the internal auditor to bring actual or suspected fraud to the attention of management at once.

No. They are an illustrative programme; the auditor designs the actual tests from the risk assessment.