Supply Chain Management Risks and Controls
In CIA Part 2, Engagement Planning requires internal auditors to understand the engagement subject, identify relevant risks, and evaluate controls before setting objectives and scope. Supply chain management (SCM) is a common engagement area because it covers procurement, supplier selection, produc… In CIA Part 2, Engagement Planning requires internal auditors to understand the engagement subject, identify relevant risks, and evaluate controls before setting objectives and scope. Supply chain management (SCM) is a common engagement area because it covers procurement, supplier selection, production, inventory, logistics, and distribution. These activities often involve third parties, so they carry significant financial, operational, and reputational exposure. Key SCM risks include: (1) Supplier risk, such as vendor failure, financial instability, poor quality, or overdependence on a single source; (2) Fraud risk, including kickbacks, fictitious vendors, bid rigging, and conflicts of interest; (3) Operational disruption from natural disasters, geopolitical events, pandemics, or transportation failures; (4) Inventory risk, such as stockouts, obsolescence, shrinkage, or excess carrying costs; (5) Compliance risk involving customs, trade sanctions, labor practices, environmental rules, and contract terms; (6) Information and cybersecurity risk, since suppliers often connect to ERP and EDI systems; and (7) Reputational risk from unethical supplier behavior. Typical controls auditors evaluate include: a formal vendor selection and due diligence process; an approved vendor master file with restricted access and periodic review; segregation of duties among requisitioning, purchasing, receiving, and payment; three-way matching of purchase orders, receiving reports, and invoices; competitive bidding and authorization limits; written contracts with right-to-audit clauses and service level agreements; supplier performance monitoring and scorecards; dual or multiple sourcing and business continuity plans; physical inventory counts and perpetual inventory reconciliation; and third-party risk management, including review of SOC reports. During planning, the auditor should gather background information, review prior audit results, interview process owners, perform a preliminary risk assessment, and possibly use process maps or walkthroughs. This helps prioritize high-risk areas, define objectives such as assessing supplier risk management effectiveness, determine scope across locations and vendors, allocate skilled resources, and develop a work program that tests both control design and operating effectiveness, consistent with the IIA Global Internal Audit Standards.
Supply Chain Management Risks and Controls (CIA Part 2: Engagement Planning)
Supply Chain Management Risks and Controls: A Complete Guide for CIA Part 2
This guide covers why supply chain risk matters, what supply chain management is, how its risks and controls work in practice, and how to answer exam questions on the topic.
1. Why Supply Chain Management Risks and Controls Are Important
Most modern organizations depend on networks of suppliers, manufacturers, logistics providers, distributors and service vendors. A failure anywhere in that chain can stop production, damage reputation, cause regulatory breaches or produce large financial losses. Recent examples include pandemic shortages, semiconductor shortages, port congestion, geopolitical sanctions and cyberattacks launched through vendors.
For internal auditors, supply chain management (SCM) matters because:
• It drives operating costs. Procurement often makes up 50 to 70 percent of a manufacturer's costs, so weak controls lead directly to waste, fraud and margin erosion.
• It extends the organization's risk boundary. The organization stays accountable for outsourced activities. Third-party risk is still the organization's risk.
• It is a common fraud area. Kickbacks, bid rigging, fictitious vendors, duplicate payments and collusion often occur in purchasing and payables.
• It affects strategy and resilience. Single sourcing, just-in-time inventory and global sourcing improve efficiency but increase exposure to disruption.
• It carries compliance and ESG exposure. Examples include conflict minerals, forced labor and modern slavery laws, anti-bribery rules (FCPA, UK Bribery Act), customs and export controls, data privacy, and sustainability reporting.
In CIA Part 2 (Practice of Internal Auditing), SCM appears within engagement planning. Auditors must understand the business area under review, identify its key risks and controls, set engagement objectives and scope, and allocate resources. The Global Internal Audit Standards require auditors to understand the activity's objectives, risks and controls before designing the work program.
2. What Supply Chain Management Is
Supply chain management is the coordinated planning, sourcing, production, delivery and return of goods and services, from raw material suppliers to the final customer. It integrates the flow of:
• Materials and goods (physical flow)
• Information (forecasts, orders, inventory status)
• Funds (payments, credit terms, financing)
A widely used model is the SCOR model (Supply Chain Operations Reference), with core processes of Plan, Source, Make, Deliver, Return and Enable.
Key concepts examiners may reference:
• Upstream vs. downstream: Upstream covers suppliers and inputs. Downstream covers distributors, retailers and customers.
• Just-in-time (JIT): Minimal inventory with deliveries timed to production. This lowers carrying costs but raises disruption risk.
• Vendor-managed inventory (VMI): The supplier monitors and replenishes the customer's stock.
• Bullwhip effect: Small changes in customer demand grow into large swings further upstream because of poor information sharing.
• Single, sole, dual and multiple sourcing: Single sourcing is a choice to use one supplier when others exist. Sole sourcing means only one supplier exists.
• Strategic sourcing: Analyzing spending and supplier markets to improve value over the long term.
• Outsourcing and offshoring: Moving activities to third parties and/or other countries.
• Electronic data interchange (EDI) and supplier portals: Electronic exchange of purchase orders, invoices and shipping notices.
• Total cost of ownership (TCO): Price plus acquisition, quality, maintenance, logistics and disposal costs.
3. How It Works: The Procure-to-Pay Cycle and Supply Chain Flow
The typical process flow that internal auditors examine:
1. Demand planning and forecasting: estimating requirements.
2. Requisition: a user department requests goods or services.
3. Supplier selection and onboarding: due diligence, bidding or RFP, vendor master file setup.
4. Contracting: terms, pricing, service level agreements (SLAs), right-to-audit clauses.
5. Purchase order (PO): authorized commitment to buy.
6. Receiving and inspection: confirming quantity and quality, then creating a receiving report.
7. Inventory management and warehousing: storage, safeguarding, counts.
8. Production / make: conversion of inputs.
9. Logistics and distribution: transport, freight, customs.
10. Invoice processing and three-way match: PO, receiving report and vendor invoice agree before payment.
11. Payment: authorized disbursement.
12. Returns and reverse logistics.
13. Supplier performance monitoring: KPIs, scorecards, audits.
4. Key Supply Chain Risks
A. Strategic and operational risks
• Supply disruption from natural disasters, pandemics, political instability, strikes or supplier bankruptcy.
• Overreliance on a single or sole source supplier (concentration risk).
• Poor demand forecasting, leading to stockouts or excess and obsolete inventory.
• Quality failures (defective or counterfeit parts), leading to recalls and liability.
• Logistics delays, capacity shortages and transportation cost volatility.
• Lack of visibility beyond tier-1 suppliers into tier-2 and tier-3.
B. Financial risks
• Price volatility and commodity risk.
• Currency fluctuations in global sourcing.
• Supplier financial instability.
• Overpayment, duplicate payments and unfavorable contract terms.
• Inventory shrinkage, theft and obsolescence.
C. Fraud risks
• Fictitious (ghost) vendors created in the vendor master file.
• Kickbacks and bribery between buyers and suppliers.
• Bid rigging, bid splitting and purchase splitting to avoid approval thresholds.
• Conflicts of interest, such as an employee owning a supplier.
• Billing schemes: inflated invoices, or invoices for goods never received.
• Collusion between receiving staff and vendors.
D. Compliance and legal risks
• Violations of anti-corruption, trade sanctions, customs and export control laws.
• Labor, human rights and modern slavery violations by suppliers.
• Environmental noncompliance and ESG reporting misstatements.
• Product safety regulations.
• Contract breaches.
E. Technology and information risks
• Cyberattacks through vendor connections (third-party or supply chain cyber risk).
• Data leakage of confidential designs or customer data held by vendors.
• Failure of EDI, ERP or warehouse management systems.
• Poor master data quality.
F. Reputational and ESG risks
• Association with unethical suppliers.
• Carbon footprint and sustainability expectations from stakeholders.
5. Key Controls Over Supply Chain Management
Governance and strategic controls
• A board-approved procurement policy and delegation of authority matrix.
• A supply chain risk management framework integrated with ERM (for example, COSO ERM).
• Supplier segmentation by criticality and spend.
• Business continuity and contingency plans, dual or multiple sourcing, and safety stock for critical items.
• Supply chain mapping beyond tier 1.
Supplier selection and onboarding controls
• Competitive bidding or RFPs above set thresholds.
• Due diligence covering financial health, ownership, sanctions screening, ethics and compliance history, ESG and cybersecurity posture.
• An approved vendor list.
• A supplier code of conduct and conflict-of-interest declarations from buyers.
• Vendor master file changes restricted and independently approved.
Contract controls
• Legal review of contracts.
• Clear SLAs, KPIs, penalties and incentives.
• Right-to-audit clauses, confidentiality and data protection clauses, and termination clauses.
• Contract management systems that track renewals and price compliance.
Transaction-level (procure-to-pay) controls
• Segregation of duties: separate requisitioning, purchasing approval, receiving, recording and payment. This is the most frequently tested control.
• Pre-numbered purchase orders and documents.
• Authorization limits enforced by the ERP system.
• Three-way match (PO, receiving report, invoice) before payment.
• Blind receiving, where the receiving clerk does not see the ordered quantity, so goods must actually be counted.
• Duplicate invoice detection.
• Positive pay and payment approval controls.
Inventory and logistics controls
• Physical safeguards and restricted warehouse access.
• Perpetual inventory systems with periodic and cycle counts.
• Reconciliation of physical counts to records.
• Obsolescence reviews and reorder points / economic order quantity (EOQ) models.
• Shipment tracking and carrier performance monitoring.
Monitoring controls
• Supplier scorecards (on-time delivery, quality, cost, responsiveness).
• Periodic supplier audits and site visits.
• Spend analytics and continuous monitoring, for example flagging vendors who share addresses or bank accounts with employees, or invoices just under approval limits.
• Independent assurance reports from service providers, such as SOC 1 / SOC 2 reports.
• Key risk indicators (KRIs) for supplier concentration and geopolitical exposure.
6. How Internal Auditors Plan an SCM Engagement
1. Understand the business: Review strategy, organization charts, policies, process flows, ERP configuration, prior audit reports, KPIs and the top suppliers by spend.
2. Perform a risk assessment: Identify inherent risks, evaluate the design of controls and consider residual risk. Use interviews, walkthroughs, process mapping and data analytics.
3. Set engagement objectives: For example, "Evaluate whether controls over supplier selection provide reasonable assurance that vendors are legitimate, qualified and selected competitively."
4. Define scope: Which locations, suppliers, time periods and processes (including third parties)? Is access to supplier records available under right-to-audit clauses?
5. Allocate resources: Determine needed skills such as data analytics, IT, logistics, legal or ESG expertise. Consider guest auditors or external specialists.
6. Develop the work program: Tests of controls and substantive procedures. Examples include vendor master file analytics, testing three-way match exceptions, observing inventory counts, reviewing bid files and confirming with suppliers.
Useful audit procedures (frequently tested):
• Compare the vendor master file to the employee master file (addresses, bank accounts, tax IDs) to detect fictitious vendors or conflicts of interest.
• Search for duplicate invoices: same amount, same vendor, similar invoice numbers.
• Analyze purchases just below approval thresholds to detect split purchases.
• Review sole-source justifications.
• Trace a sample of payments back to POs and receiving reports (validity), and trace receiving reports forward to recorded liabilities (completeness).
• Benchmark prices against market or contract rates.
• Review supplier SOC reports and complementary user entity controls.
7. Exam Tips: Answering Questions on Supply Chain Management Risks and Controls
Tip 1: Identify the risk before choosing the control. Many questions describe a scenario and ask for the best control or the greatest risk. First name the risk (fictitious vendor, overpayment, disruption or quality failure). Then pick the control that directly addresses it.
Tip 2: Know segregation of duties cold. If one person can create a vendor, approve a PO, receive goods and authorize payment, that is the key weakness. The correct answer usually separates authorization, custody, recording and reconciliation.
Tip 3: Match fraud schemes to detective analytics.
• Fictitious vendors: match vendor and employee data, look for vendors with P.O. box addresses only, review new vendors with no history.
• Duplicate payments: run duplicate invoice tests.
• Split purchases: stratify transactions just below thresholds.
• Kickbacks: look for price increases without justification, a buyer's favoritism toward one vendor, or high volumes with a single vendor.
Tip 4: Prefer preventive over detective controls when asked for the "best" control, unless the question asks how the auditor would detect or test. For example, restricting vendor master file access is preventive. Reviewing vendor change reports is detective.
Tip 5: Watch the direction of testing.
• To test existence/validity (were payments for real goods?), sample from paid invoices and vouch back to POs and receiving reports.
• To test completeness (are all liabilities recorded?), sample from receiving reports and trace forward to recorded payables.
Tip 6: Remember that third-party risk remains the organization's responsibility. Answers stating that outsourcing "transfers" accountability are wrong. Look for right-to-audit clauses, SLAs, SOC reports and ongoing monitoring.
Tip 7: Weigh efficiency trade-offs. JIT and single sourcing reduce cost but increase disruption risk. The best mitigation answer often involves dual or multiple sourcing, safety stock, supplier risk assessment or business continuity planning, not abandoning the strategy entirely.
Tip 8: Engagement planning questions focus on what comes first. Expect questions about the first or most important step. The usual order is: understand the activity's objectives, then identify risks, then assess controls, then define objectives and scope, then allocate resources, then build the work program. A preliminary risk assessment comes before detailed testing.
Tip 9: Know the documents and their purpose.
• Purchase requisition: internal request (authorizes need).
• Purchase order: external commitment (authorizes purchase).
• Receiving report: evidence that goods arrived (supports existence and quantity).
• Vendor invoice: claim for payment.
• Bill of lading: shipping document from the carrier.
A blind copy of the PO given to receiving forces an independent count.
Tip 10: Look for the root cause. If inventory shortages recur, a better counting schedule treats the symptom. Weak forecasting, poor access controls or lack of reconciliation may be the root cause. CIA answers favor addressing root causes.
Tip 11: Watch for ESG and compliance angles. Newer questions may involve supplier codes of conduct, modern slavery, conflict minerals, sanctions screening and sustainability data. The best controls are due diligence, contractual requirements, certifications and supplier audits.
Tip 12: Read for keywords. Words such as most, best, primary, first and least likely change the answer. Eliminate options that are true but do not address the specific risk, or that are too costly or impractical.
Tip 13: Data analytics answers are often correct. The IIA emphasizes full-population testing. When choosing between manual sampling and analytics over the whole population for fraud indicators, analytics is usually better.
Tip 14: Consider the cost-benefit of controls. Controls should be proportionate to risk. Critical, high-spend suppliers deserve deeper due diligence than low-risk, low-spend vendors (a risk-based supplier segmentation approach).
8. Sample Exam-Style Questions and Reasoning
Q1: An internal auditor finds that the purchasing manager can add new vendors to the master file and approve purchase orders. Which risk is greatest?
Answer reasoning: The greatest risk is payments to fictitious vendors, which this incompatible combination of duties allows. The fix is to separate vendor master maintenance from purchasing and payment.
Q2: Which control best prevents payment for goods not received?
Answer reasoning: A three-way match of the PO, receiving report and invoice before payment approval.
Q3: A company relies on one overseas supplier for a critical component. What should the auditor recommend first?
Answer reasoning: Assess the supplier's criticality and disruption risk. Then recommend mitigation, such as qualifying alternate suppliers, holding safety stock and preparing contingency plans.
Q4: During planning for a procurement audit, what should the auditor do first?
Answer reasoning: Gain an understanding of the procurement function's objectives, processes and risks, for example through walkthroughs and a preliminary survey, before writing the work program.
Q5: Which analytic would best detect purchases split to avoid approval limits?
Answer reasoning: Identify multiple purchases from the same vendor on the same or adjacent dates whose individual amounts fall just below the approval threshold.
9. Summary
Supply chain management covers the end-to-end flow of goods, information and funds from suppliers to customers. Its main risks are disruption, fraud, financial loss, compliance breaches, cyber exposure and reputational harm. Key controls include governance, supplier due diligence, contract terms (especially right-to-audit clauses), segregation of duties, three-way matching, inventory safeguards and ongoing supplier monitoring. In the exam, identify the specific risk, choose the control that most directly mitigates it, favor preventive and root-cause solutions, remember that accountability cannot be outsourced, and follow the logical sequence of engagement planning.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!