Every organisation’s biggest cash outflow is also one of its biggest fraud risks. Fictitious vendors collecting payments for goods never delivered. Invoices split just below the approval threshold so nobody notices. Kickbacks hiding in plain sight as preferred vendor relationships. Duplicate payments processed twice and never recovered. The Accounts Payable and Procurement Audit Program gives internal auditors, forensic investigators, and finance teams a comprehensive, data-driven framework to test every layer of the procure-to-pay cycle. With 90 audit procedures across 10 specialist sections, it covers everything from proving your AP control totals to detecting conflict of interest through employee-vendor cross-matching, testing three-way match failures, identifying threshold avoidance patterns, and assessing VAT and withholding tax compliance. Every procedure includes detailed audit steps and the exact data file required — so you can move from planning to fieldwork without starting from scratch. Whether you are auditing a large corporate, a public sector entity, or a growing business, this program brings structure, rigour, and forensic depth to one of the highest-risk areas in any organisation.
Section 1 — AP Proof and Reconciliation (8 procedures)
The foundation before any analysis begins. Reproduces the purchase analysis and proves posting totals, reconciles the AP subledger to the general ledger, proves cash and electronic payment totals against the bank statement, verifies accruals completeness, reconciles vendor statements for the top 20 vendors by spend, and confirms that payment run control totals match the bank output file exactly — with no amendments made after authorisation.
Section 2 — Payment Analysis and Trend Testing (9 procedures)
Statistical analysis of the entire payments portfolio. Groups payments by value band to identify unusual distribution shifts, detects invoice splitting below authorisation thresholds, summarises by payment type (EFT, cheque, cash, petty cash), analyses seasonal and periodic trends, tests payment term compliance for early and late payments, reviews one-off and ad hoc payments, analyses round-amount payments, and extracts all payments processed on weekends and public holidays.
Section 3 — Invoice Exception Tests (10 procedures)
Identifies high-risk invoices across ten dimensions — large value outliers, invoices without a valid purchase order, VAT number validation, invalid VAT reclaim, price increases exceeding acceptable thresholds, invoices covering multiple PO authorisations, the classic threshold avoidance pattern of multiple invoices just below the approval cut-off, invoices with no goods received note, backdated invoices, and invoices with unusually short payment terms used to rush payments through.
Section 4 — Duplicates and Gaps (9 procedures)
Comprehensive duplicate and sequence testing across five dimensions — exact duplicate invoices by internal and external reference number, duplicate invoices by vendor and amount, duplicate invoices by PO number, duplicate payments against the same invoice, duplicate purchase orders, missing PO sequence numbers, missing or duplicate cheque numbers, and duplicate vendor bank accounts across the master file.
Section 5 — Vendor Master File Integrity (9 procedures)
Tests the legitimacy and completeness of every vendor on the master file — invoices against the approved supplier list, mandatory field completeness, fictitious vendor address analysis, vendors sharing a physical address, bank account changes with verification of authorisation, new vendors with immediate high-value payments, registration number validation, vendors added by AP staff (self-dealing test), and dormant vendors with no transactions in 12 months.
Section 6 — Three-Way Match Testing (9 procedures)
The core prevention control tested rigorously. Matches purchase orders to invoices, GRNs to purchase orders, invoice quantities to GRN quantities, and invoice prices to PO prices. Groups price and quantity variances by vendor to detect systematic non-compliance. Identifies invoices raised before goods were received, GRNs created after payment, and shipments received with no purchase order.
Section 7 — Conflict of Interest and Kickback Tests (9 procedures)
Relationship analysis designed to surface what transaction testing cannot see. Cross-matches vendors against employees by name, address, and bank account. Identifies buyers approving payments to their own vendors, sole-source procurements without competitive tender, vendor contacts who are also employees, consecutive tender awards to the same vendor, and management overrides of the vendor approval process.
Section 8 — Procurement Process and Internal Controls (10 procedures)
End-to-end control assessment of the procure-to-pay cycle — segregation of duties matrix, authorisation level compliance, competitive tender compliance, contract existence and expiry testing, PO amendment controls, invoice approval workflow compliance, goods returned and credit note tracking, petty cash fund testing, and terminated user access revocation.
Section 9 — Vendor Performance and Concentration Analysis (9 procedures)
Supply chain risk assessment through performance data. Analyses vendor spend concentration, identifies categories dominated by a single vendor, measures on-time delivery and quality return rates by vendor, benchmarks prices across vendors for the same items, analyses new vendor spend trajectories, compares actual spend to contracted values, identifies single-bid tender outcomes, and reviews the vendor dispute and complaint register.
Section 10 — Tax and Regulatory Compliance (9 procedures)
VAT input tax reclaim validation, VAT on non-eligible expenditure, withholding tax compliance for non-resident and consultant payments, import duty and customs compliance, transfer pricing on related party transactions, statutory supplier payment timeframe compliance, expense report tax compliance for taxable benefits, contractor versus employee classification risk, and statutory reporting completeness.






Reviews
There are no reviews yet.