Risks and Controls in Procurement, Payables, and Inventory
5 minutes
5 Questions
Procurement, payables, and inventory represent interconnected business cycles with significant financial and operational risks that internal auditors must evaluate during engagement planning. In PROCUREMENT, key risks include unauthorized purchases, favoritism or kickbacks to vendors, buying goods …Procurement, payables, and inventory represent interconnected business cycles with significant financial and operational risks that internal auditors must evaluate during engagement planning. In PROCUREMENT, key risks include unauthorized purchases, favoritism or kickbacks to vendors, buying goods at inflated prices, purchasing unnecessary items, and duplicate orders. Essential controls include segregation of duties between requisitioning, approving, and ordering; proper authorization limits; competitive bidding requirements; approved vendor lists; and purchase order matching. In ACCOUNTS PAYABLE, risks involve duplicate payments, fictitious vendors, unauthorized disbursements, incorrect payment amounts, and payments for goods not received. Controls include three-way matching (purchase order, receiving report, and invoice), vendor master file maintenance with restricted access, segregation of duties between recording and payment functions, review of supporting documentation before payment, and periodic vendor statement reconciliations. For INVENTORY, risks include theft, obsolescence, misstatement of quantities or valuation, shrinkage, and inadequate physical safeguards. Controls encompass physical security measures (locks, cameras, restricted access), periodic physical counts and cycle counting, reconciliation of physical counts to perpetual records, proper valuation methods (FIFO, LIFO, weighted average), and segregation between custody and record-keeping. During engagement planning, auditors should understand how these cycles integrate, since weaknesses in one area affect others. For example, poor receiving controls impact both payables accuracy and inventory records. Auditors assess inherent risk, evaluate the design and operating effectiveness of controls, and identify where fraud risks concentrate, particularly collusion opportunities. Key audit objectives include verifying completeness, accuracy, validity, and proper cutoff of transactions. Analytical procedures such as trend analysis, ratio analysis (inventory turnover, days payable outstanding), and comparison to budgets help identify anomalies. Understanding the IT systems supporting these processes, including automated controls and access rights, is critical. Effective engagement planning aligns audit scope and resources with the highest-risk areas across these three interrelated cycles.
Risks and Controls in Procurement, Payables, and Inventory
Introduction The procurement-to-payment cycle (often called the purchasing or expenditure cycle) is one of the most risk-intensive processes in any organization. It involves acquiring goods and services, receiving them, recording liabilities, paying vendors, and managing inventory. Because this cycle involves large volumes of transactions and significant cash outflows, it is a frequent target for fraud, error, and waste. For CIA Part 2 (Practice of Internal Auditing), understanding the risks and controls in this area is essential for engagement planning and for designing effective audit procedures.
Why It Is Important This cycle directly affects an organization's financial health, operational efficiency, and reputation. Weak controls can lead to: • Overpayment or duplicate payments to vendors. • Fraudulent disbursements (fictitious vendors, kickbacks, bid rigging). • Inventory theft, obsolescence, or misvaluation. • Inaccurate financial reporting of liabilities and assets. • Supply chain disruptions from poor vendor management. Internal auditors must evaluate whether controls adequately mitigate these risks to ensure accuracy, safeguard assets, and promote compliance.
What It Is The cycle generally includes three interlinked sub-processes:
1. Procurement (Purchasing): Identifying needs, selecting vendors, issuing purchase requisitions and purchase orders (POs), and approving purchases. 2. Payables (Accounts Payable): Matching invoices with supporting documents, recording liabilities, and disbursing payments. 3. Inventory: Receiving, storing, tracking, valuing, and safeguarding goods.
How It Works — Key Risks and Controls
Procurement Risks: • Purchasing unneeded, excessive, or unauthorized goods. • Favoritism, conflicts of interest, or kickbacks in vendor selection. • Purchasing at unfavorable prices or terms. Procurement Controls: • Approved vendor lists and competitive bidding. • Segregation of duties between requisitioning, ordering, and approving. • Authorization limits and pre-numbered purchase orders. • Conflict-of-interest policies and periodic vendor review.
Payables Risks: • Duplicate, fictitious, or inflated invoices. • Payment for goods not received. • Unauthorized changes to vendor master file (bank details). Payables Controls: • Three-way match (PO, receiving report, and vendor invoice) before payment. • Segregation of duties between recording and paying. • Restricted access and change controls over the vendor master file. • Review and approval of disbursements; dual signatures for large amounts. • Automated detection of duplicate invoice numbers.
Inventory Risks: • Theft, shrinkage, and damage. • Obsolescence and overstocking. • Inaccurate quantities or valuation. Inventory Controls: • Physical safeguards (locked storage, restricted access, surveillance). • Periodic physical counts and cycle counts reconciled to records. • Perpetual inventory systems and reorder points. • Proper valuation methods (FIFO, weighted average) and obsolescence reviews. • Segregation between custody of inventory and record-keeping.
Core Control Concepts to Remember • Segregation of Duties (SoD): Separate authorization, custody, and record-keeping across all three processes. • Three-way matching: The cornerstone control linking procurement, receiving, and payables. • Authorization and approval hierarchies. • Reconciliations between physical counts and ledgers. • Access and system controls over master data.
How to Answer Exam Questions CIA exam questions on this topic are typically scenario-based. They may describe a process and ask you to identify the missing control, the risk present, or the best control to mitigate a stated risk. • Read the scenario carefully and identify which sub-process (procurement, payables, or inventory) is involved. • Determine the specific risk being tested (fraud, error, inefficiency, misstatement). • Match the risk to the most appropriate control — select the option that directly addresses the stated risk, not a generally good practice. • Watch for segregation-of-duties conflicts; these are heavily tested. • Distinguish between preventive controls (stop issues before they occur, e.g., authorization) and detective controls (identify issues afterward, e.g., reconciliations).
Exam Tips: Answering Questions on Risks and Controls in Procurement, Payables, and Inventory • Focus on the three-way match — it is one of the most tested controls; know exactly what documents it compares (PO, receiving report, invoice). • Identify SoD violations quickly: if one person both approves purchases and pays invoices, that is a red flag. • Choose the BEST answer, not merely a correct one. Several options may be valid controls, but only one directly addresses the risk in the scenario. • Classify controls as preventive, detective, or corrective when asked. • Vendor master file controls are a common fraud topic — associate changes to bank details with fraud risk. • Physical inventory counts and reconciliations are the key detective controls for inventory shrinkage. • Think like an auditor: ask what could go wrong and what control would detect or prevent it. • Beware of distractors that sound authoritative but do not relate to the specific risk stated.
Conclusion Mastering the risks and controls in procurement, payables, and inventory equips internal auditors to plan effective engagements, assess control adequacy, and recommend improvements. In the exam, success comes from precisely linking each identified risk to the single most appropriate control while recognizing segregation-of-duties issues and the critical role of the three-way match.