Internal audit in procurement is often misunderstood.
Some buyers see audit as a control function that arrives after something has gone wrong. Some stakeholders see it as bureaucracy. Some procurement managers see it as a necessary reporting requirement.
But internal audit can be much more valuable than that.
In a well-managed procurement function, internal audit helps procurement answer a very practical question:
Are we buying in a way that is compliant, transparent, efficient, ethical, and aligned with the company’s business objectives?
This matters because procurement controls a large part of external spend. Poor procurement routines can create unauthorized purchases, weak supplier selection, contract leakage, fraud risk, legal exposure, ethical problems, and lost business value.
This article explains how internal audit supports procurement departments as both a control function and a business development function.
LHTS learning framework
Role: Management
Supporting roles: Tactical buyer, operative buyer
Process: Procurement governance, compliance, Procure-to-Pay, Source-to-Contract, supplier management, contract management
Level: Basic
Related course: Procurement management introduction
Quick answer: what is internal audit in procurement?
Internal audit in procurement is a structured review of how procurement activities follow company policies, legal requirements, ethical standards, approval rules, contract requirements, and internal controls.
It helps procurement identify weaknesses before they become serious problems.
A good internal audit does not only look for mistakes. It also helps procurement improve processes, strengthen accountability, reduce risk, and build trust with management and stakeholders.
The procurement problem: compliance is easy to describe but hard to maintain
Most companies have a purchasing policy. Many companies also have approval limits, contract templates, supplier onboarding rules, code of conduct requirements, sourcing procedures, and delegated authority rules.
The problem is not always the absence of rules.
The problem is that rules are not always followed in daily business.
Typical procurement problems include:
- Purchase orders are created after the supplier has already started work.
- Stakeholders buy outside agreed contracts.
- Suppliers are selected without proper competition or documentation.
- Approval limits are bypassed.
- Contract terms are not stored or followed up.
- Supplier onboarding is incomplete.
- Conflicts of interest are not declared.
- Emergency purchases become normal practice.
- Procurement data is incomplete or unreliable.
- Corrective actions are agreed but not implemented.
This is where internal audit becomes valuable.
Internal audit helps procurement move from assumption to evidence. It checks whether the procurement process works in practice, not only whether it exists on paper.
Internal audit as a support function in procurement
Internal audit supports procurement in three important ways.
First, it gives an independent view of whether procurement controls are working.
Second, it identifies gaps, risks, and process weaknesses that procurement management may not see from inside the daily operation.
Third, it creates recommendations that can help procurement improve the way it works.
This means internal audit should not be seen only as a control function. It is also a structured improvement function.
The value of internal audit is not the audit report itself. The value comes when procurement uses the findings to improve policy, process, system control, documentation, training, supplier management, and stakeholder behavior.
What internal audit normally reviews in procurement
Internal audit can review many parts of procurement. The scope depends on the company, industry, risk profile, legal environment, and maturity of the procurement function.
Common audit areas include:
1. Purchasing policy compliance
The audit checks whether employees follow the company’s purchasing policy.
This may include whether purchases are made through approved channels, whether buyers use correct approval levels, whether contracts are used when available, and whether exceptions are documented.
2. Approval and authorization controls
The audit checks whether purchase requisitions, purchase orders, contracts, and invoices are approved by the right people.
This is important because weak approval control can lead to unauthorized spending, fraud risk, budget leakage, and unclear accountability.
3. Supplier selection and sourcing documentation
The audit checks whether supplier selection is documented and fair.
This may include RFQs, bid evaluations, single-source justifications, supplier qualification records, negotiation documentation, and award decisions.
4. Contract compliance
The audit checks whether the organization follows agreed supplier contracts.
This may include pricing, payment terms, delivery terms, service levels, volume commitments, contract expiry dates, and agreed ordering channels.
5. Supplier onboarding and supplier master data
The audit checks whether suppliers are created and maintained correctly in the system.
This can include bank account verification, tax information, legal entity checks, insurance certificates, sanctions screening if applicable, code of conduct confirmation, and segregation of duties.
6. Ethical conduct and conflict of interest
The audit checks whether procurement decisions are made fairly and objectively.
This may include gifts and hospitality, personal relationships, side agreements, supplier favoritism, conflict of interest declarations, and transparency in supplier communication.
7. Procure-to-Pay process control
The audit checks whether the end-to-end purchasing flow is controlled.
This includes purchase requisition, approval, purchase order, goods receipt, invoice matching, payment, and documentation.
8. Corrective action follow-up
The audit checks whether previous audit findings have actually been resolved.
This is critical. An audit finding that is accepted but never implemented does not reduce risk.
How internal audit connects to the procurement management role
Internal audit is mainly connected to the procurement management role.
A procurement manager or CPO is responsible for creating a procurement function that is structured, reliable, compliant, and aligned with business needs.
Internal audit helps procurement management understand whether that structure works in reality.
For procurement management, internal audit supports questions such as:
- Are procurement policies followed?
- Are approval limits respected?
- Are sourcing decisions documented?
- Are contracts used correctly?
- Are suppliers onboarded properly?
- Are stakeholders using procurement in the right way?
- Are process risks increasing or decreasing?
- Are corrective actions implemented on time?
- Do we have evidence that the procurement function is under control?
This makes internal audit a valuable management tool.
It helps the procurement manager build credibility with senior management, finance, legal, operations, and external stakeholders.
How internal audit connects to the procurement process
Internal audit can support both operative and tactical procurement processes.
In Procure-to-Pay
Internal audit may review whether purchase orders are approved before commitment, whether invoices match purchase orders and goods receipts, whether emergency purchases are justified, and whether users follow the buying channels.
This is important for operative control.
In Source-to-Contract
Internal audit may review whether RFQs are documented, whether evaluation criteria are used fairly, whether supplier selection is approved, and whether contracts are properly stored and signed.
This is important for sourcing integrity.
In supplier management
Internal audit may review whether suppliers are qualified, whether supplier performance is followed up, whether supplier audits are completed, and whether corrective actions are closed.
This is important for supplier risk control.
In contract management
Internal audit may review whether contract terms are used in practice, whether contract expiry dates are monitored, whether price updates are controlled, and whether stakeholders buy from contracted suppliers.
This is important for reducing contract leakage.
Practical example: audit finds weak purchase order approval
Imagine that internal audit reviews the Procure-to-Pay process in a procurement department.
The audit finds that several purchase orders have been created without the required approval. In some cases, the purchase order was created after the supplier had already delivered the goods or started the service.
This creates several risks:
- Unauthorized spending
- Weak budget control
- Poor audit trail
- Increased fraud risk
- Disputes with suppliers
- Incorrect invoice matching
- Lack of management visibility
The audit finding is not only “someone made a mistake.”
The deeper question is:
Why did the process allow the mistake to happen?
Possible root causes may include:
- Approval rules are unclear.
- The system allows users to bypass controls.
- Stakeholders do not understand the policy.
- Procurement is involved too late.
- Emergency purchases are not governed.
- Managers approve after the fact without review.
- There is no monthly follow-up of non-compliant orders.
A good audit recommendation should therefore not only say: “Follow the approval process.”
A stronger recommendation would be:
- Update the approval workflow in the purchasing system.
- Block purchase order release without required approval.
- Define a specific emergency purchase process.
- Train buyers and key stakeholders.
- Report monthly exceptions to procurement management.
- Review repeat deviations with line managers.
- Follow up implementation after three or six months.
This turns audit from a control activity into a business improvement activity.
Internal audit as a business development function
Internal audit creates business value when it helps procurement improve how work is done.
Examples of business development value include:
Better process design
Audit findings can show where the procurement process is unclear, too manual, too dependent on individuals, or too easy to bypass.
Better system control
Audit can identify where ERP, P2P, contract management, or supplier onboarding systems need stronger controls, clearer workflows, or better master data.
Better stakeholder behavior
Audit can show where stakeholders need training, clearer buying channels, or stronger accountability.
Better supplier risk management
Audit can identify missing supplier qualification, weak supplier documentation, poor contract follow-up, or lack of supplier performance evidence.
Better procurement credibility
When procurement can show strong controls and clear improvement actions, it becomes easier to gain trust from management, finance, legal, operations, and external auditors.
Internal audit as a control function
Internal audit must also remain a control function.
That is important.
If audit becomes too close to procurement operations, it may lose independence. Internal audit can advise, challenge, and recommend improvements, but procurement management must still own the process and implement the corrective actions.
Internal audit should not become the owner of procurement policy, sourcing decisions, supplier selection, or daily purchasing execution.
A healthy relationship looks like this:
Procurement owns the process.
Internal audit reviews the process.
Procurement implements improvements.
Internal audit follows up whether actions were completed.
This balance keeps internal audit useful without weakening its independence.
Internal audit: support or threat?
Whether internal audit is seen as support or threat depends on the culture of the procurement organization.
If audit is used only to expose mistakes, people may become defensive.
If audit is used to improve the process, people are more likely to cooperate.
Procurement managers should communicate internal audit as a normal part of professional procurement maturity.
A useful message is:
Internal audit helps us identify where our procurement process is strong, where it is weak, and where we need to improve.
This does not remove accountability. It makes accountability more constructive.
Common mistakes in procurement internal audits
Mistake 1: Treating audit as punishment
Audit should not be presented as a punishment. It should be presented as a structured way to improve compliance, control, and performance.
Mistake 2: Focusing only on individual errors
Many audit findings are symptoms of process weaknesses. Procurement should ask why the error could happen, not only who made the error.
Mistake 3: Writing recommendations that are too general
A recommendation such as “improve compliance” is too weak. A strong recommendation should include owner, action, deadline, expected control effect, and follow-up method.
Mistake 4: Ignoring stakeholder behavior
Procurement compliance is not only a buyer issue. Stakeholders also influence supplier selection, purchase requests, contract usage, and emergency purchases.
Mistake 5: Closing findings too early
A finding should not be closed just because an action plan exists. It should be closed when the action has been implemented and the control is working.
Mistake 6: Allowing audit to become process owner
Internal audit can recommend improvements, but procurement management must own the procurement process. Otherwise, independence and accountability become unclear.
Useful KPI: audit finding closure rate
One useful KPI is the audit finding closure rate.
This measures the percentage of audit findings that have been resolved within the agreed time frame.
A simple formula is:
Audit finding closure rate = closed audit findings / total audit findings × 100
Example:
If procurement has 25 audit findings and 20 are closed within the agreed deadline:
20 / 25 × 100 = 80%
This KPI helps procurement management follow whether agreed improvements are actually implemented.
However, the KPI should not be used alone. Procurement should also review the quality of the closure.
The real question is not only:
Was the action closed?
The better question is:
Did the action reduce the risk and improve the process?
What a procurement manager should do before an internal audit
A procurement manager should not wait passively for audit.
Before an internal audit, procurement management should review:
- Current purchasing policy
- Approval rules
- Delegation of authority
- Procurement process descriptions
- RFQ and sourcing documentation
- Contract storage and contract ownership
- Supplier onboarding rules
- Supplier master data controls
- Purchase order compliance
- Invoice matching routines
- Exception reports
- Previous audit findings
- Corrective action status
- Training records
- Stakeholder compliance issues
This preparation is not about hiding problems. It is about understanding the current situation and being ready for a constructive audit dialogue.
How buyers should work with internal audit findings
Buyers may be asked to provide information during an audit.
This can include purchase orders, supplier communication, RFQ documentation, contract references, approval records, delivery records, or explanations of process exceptions.
A buyer should treat audit questions professionally.
Good buyer behavior includes:
- Answer factually.
- Provide documentation.
- Explain the process honestly.
- Do not hide deviations.
- Clarify whether the deviation was approved.
- Suggest practical improvements.
- Learn from the finding.
For a buyer in training, internal audit can be an excellent learning opportunity. It shows how procurement work connects to risk, compliance, policy, finance, legal requirements, and management control.
Related Learn How to Source course
If you want to go deeper into how procurement should be managed as a function, the related Learn How to Source course is the Procurement management introduction.
This course connects well with internal audit because audit findings often relate to procurement organization, governance, KPIs, policy, category management, supplier responsibility, digitalization, and management control.
Internal audit shows whether procurement is working as intended.
Procurement management decides how the function should work.
That is why these two topics belong together.
FAQ
What is internal audit in procurement?
Internal audit in procurement is a structured review of procurement activities, controls, documentation, compliance, and risk. It checks whether procurement follows company policy, approval rules, legal requirements, ethical standards, and agreed processes.
Is internal audit part of procurement?
Usually, internal audit is not part of procurement. It should be independent from the function it reviews. However, it works closely with procurement when reviewing procurement processes and following up corrective actions.
Why is internal audit important in procurement?
Internal audit is important because procurement manages external spend, supplier selection, contracts, approvals, and business-critical purchasing decisions. Weak controls can create financial, legal, ethical, and operational risk.
Is internal audit only a control function?
No. Internal audit is a control function, but it can also support business improvement. Good audit findings help procurement improve processes, system controls, documentation, training, supplier management, and stakeholder compliance.
What procurement areas are commonly audited?
Common areas include purchasing policy compliance, approval workflows, purchase orders, supplier selection, contract compliance, supplier onboarding, supplier master data, invoice matching, conflict of interest, and corrective action follow-up.
Who owns audit findings in procurement?
Procurement management owns the corrective actions related to procurement findings. Internal audit identifies and follows up findings, but procurement must implement the improvements.
What is a good KPI for procurement audit follow-up?
A useful KPI is audit finding closure rate. It measures how many audit findings are resolved within the agreed deadline. However, procurement should also check whether the corrective action actually reduced the risk.
Conclusion
Internal audit in procurement should not be seen only as a threat or a control exercise.
When used well, internal audit helps procurement build a stronger, more reliable, and more business-oriented function. It identifies weaknesses in policy compliance, approval control, supplier selection, contract usage, documentation, ethics, and process execution.
The most important point is this:
Internal audit does not replace procurement management. It supports procurement management.
Procurement owns the process. Internal audit gives independent assurance, challenge, and improvement insight.
A mature procurement function uses internal audit findings as input for better governance, better stakeholder behavior, better system control, and better business results.
