A Practical Guide to Auditing and Improving Your P2P Process
An efficient Procure-to-Pay (P2P) process is critical for controlling spend, maintaining compliance and protecting financial integrity. From raising a purchase request to paying a supplier, every step in the P2P cycle needs to be accurate, controlled and transparent. A P2P audit examines the controls that govern how your organisation requests, approves, purchases, receives and pays for goods and services, so that you can identify improvements in your process.
This P2P audit checklist is designed to help finance teams, internal auditors and procurement leaders assess how well their P2P process is working. It highlights common risks, control gaps and inefficiencies, while providing a structured way to review procurement policies, supplier management, invoice processing, and payment controls.
Regular P2P audits are essential for reducing fraud risk, improving data accuracy, strengthening internal controls, and identifying opportunities to streamline operations. Whether you are preparing for an internal audit, external audit, or looking to improve performance, this guide gives you a clear place to start.
What Is a P2P Audit?
A Procure-to-Pay audit, also known as a P2P audit or purchase-to-pay audit, is a structured review of the processes, systems and internal controls used to purchase goods and services and pay suppliers. The purpose of a P2P audit is to evaluate:
- How efficiently procurement activities carried out
- Whether transactions follow internal policies and approval rules
- If financial data is accurate, complete and properly authorised
- Where risks such as fraud, errors, or non-compliance may exist
For internal audit teams, the objective is not simply to identify individual errors. It’s to understand why errors or control failures can occur, whether existing controls prevent or detect them and whether those controls operate consistently in practice. A strong P2P process internal audit ensures that purchasing decisions are controlled, supplier payments are valid and financial reporting can be trusted.
P2P Audit Checklist: Key Controls to Review
Use this checklist to sense-check the main controls across your Procure-to-Pay process:
- Supplier onboarding and bank detail changes
- Purchase requisitions and approval limits
- Purchase order compliance
- Goods and services receipt
- Invoice validation and matching
- Duplicate invoice and payment controls
- Segregation of duties
- Payment approvals
- User access and permissions
- Exceptions, overrides and audit trails
What Are the Objectives of a P2P Internal Audit?
Before testing begins, define what the audit is intended to establish.
A structured Procure-to-Pay audit typically follows these key stages.
1. Audit Planning and Scope Definition
Start by clearly defining what the audit will cover and why.
- Set audit objectives and success criteria
- Define the scope of the P2P process being reviewed
- Assign audit roles and responsibilities
- Review procurement policies, approval limits, and regulatory requirements
- Build an audit plan with timelines and milestones
Clear planning ensures the audit stays focused on the areas that matter most.
2. P2P Risk Assessment
Risk assessment helps prioritise effort and identify high-impact areas.
- Identify risks such as duplicate payments, unauthorised spend, or weak supplier controls
- Assess transaction volumes, values, and complexity
- Consider regulatory exposure and compliance requirements
- Focus on areas with manual intervention or limited visibility
This step ensures audit resources are used where risk is highest.
3. Data Collection and Evidence Gathering
Accurate data is essential for a meaningful P2P audit.
- Collect purchase orders, contracts, invoices, goods receipts, and payment records
- Extract transaction data from ERP and procurement systems
- Review supplier master data and onboarding documentation
- Interview procurement, finance, and AP teams to understand workflows
Good data access allows auditors to test controls effectively.
4. Transaction Testing and Analysis
Testing confirms whether controls work in practice.
- Check that purchases are approved according to policy
- Verify three-way matching between PO, invoice, and receipt
- Review invoice accuracy, tax treatment, and coding
- Analyse transactions for anomalies, trends, and duplicate payments
This step often reveals inefficiencies or control gaps that are not visible on paper.
A key part of any Procure-to-Pay audit is reviewing internal controls.
5. Internal Control Evaluation
- Assess segregation of duties across procurement and payments
- Review approval hierarchies and system permissions
- Check documentation standards and audit trail completeness
- Evaluate management oversight and control ownership
Weak controls increase the risk of error, fraud, and audit findings.
6. Audit Findings and Recommendations
Clear findings turn audit work into action.
- Document control weaknesses, compliance failures, and inefficiencies
- Assess financial, operational, and reputational impact
- Prioritise issues based on risk and materiality
- Provide practical, achievable recommendations
Strong recommendations focus on long-term improvement, not short-term fixes.
7. Audit Reporting and Communication
Effective reporting ensures findings are understood and acted upon.
- Summarise audit scope, approach, and key results
- Present findings clearly to finance leaders and stakeholders
- Capture management responses and agreed actions
- Align recommendations with business objectives
Clear communication improves buy-in and accountability.
8. Follow-Up and Continuous Monitoring
A P2P audit does not end with the report.
- Track corrective actions and implementation progress
- Review whether controls are operating as intended
- Perform follow-up testing where required
- Use insights to improve future audits
This approach supports continuous improvement rather than one-off compliance.
How to Perform a P2P Audit
1. Define the Audit Scope
Begin by establishing exactly what will be reviewed.
Consider:
- Business entities and locations
- P2P systems and ERP platforms
- Transaction period
- Purchasing categories
- Supplier populations
- Payment methods
- Relevant policies
- Previous audit findings
- Areas of known concern
A narrowly defined scope with clear objectives is usually more effective than trying to test every aspect of the process equally.
2. Perform a P2P Risk Assessment
Identify where control failure could have the greatest impact.
Areas deserving additional attention can include:
- Manual processes
- High-value transactions
- High-volume suppliers
- New suppliers
- Supplier bank detail changes
- Non-PO expenditure
- Manual payments
- Frequent matching exceptions
- Transactions just below approval limits
- Users with privileged access
- Processes that rely heavily on spreadsheets, email or manual intervention.
Use the risk assessment to determine the size and nature of your testing.
3. Understand the Process and Controls
Walk through the complete P2P process with the teams responsible for it.
Document:
- What should happen
- Who performs each activity
- Which system is used
- Where approval occurs
- Where data is transferred between systems
- Which controls are automated
- Which controls are manual
- What happens when the normal process fails.
Process walkthroughs can reveal gaps between formal procedure and day-to-day practice before detailed testing even begins.
4. Test Control Design
First ask whether each control is capable of managing the relevant risk.
For example, if invoices over a particular value require additional approval, verify that:
- The threshold is appropriate
- The right approvers are included
- Users cannot bypass the rule
- Exceptions are appropriately controlled
This is the design effectiveness of the control.
5. Test Operating Effectiveness
Next establish whether the control has actually operated as designed during the audit period.
Select appropriate samples and inspect the underlying evidence.
A correctly designed approval workflow provides little assurance if users routinely bypass it or exceptions are manually overridden without review.
6. Analyse Transactions and Exceptions
Transaction-level analysis can identify patterns that individual samples may miss.
Look for indicators such as:
- Duplicate invoice numbers or values
- Unusual payment values
- Sequential invoices
- Transactions just below approval thresholds
- Purchases made without POs
- Retrospective POs
- Unusual supplier changes
- Repeated matching exceptions
- Excessive manual intervention
- Activity involving dormant or rarely used suppliers.
Where an anomaly is identified, investigate the reason rather than assuming it represents an error or control failure.
7. Record and Prioritise Findings
Each audit finding should clearly explain:
Condition: What did you find?
Risk: What could happen as a result?
Cause: Why did the issue occur?
Control gap: Which preventative or detective measure failed or was missing?
Recommendation: What practical action would reduce the risk?
Owner and target date: Who is responsible for improvement and by when?
Prioritise findings according to their likelihood and potential impact rather than treating every exception equally.
8. Follow Up
A P2P audit does not finish when the report is issued.
Track agreed actions and confirm whether:
- Remediation has been implemented
- The original risk has been addressed
- Revised controls are operating effectively
- Corrective action has created any unintended risks elsewhere in the process.
Where appropriate, perform follow-up testing rather than relying solely on confirmation from the process owner.
From P2P Audit to Continuous Control Improvement
A P2P audit should not be viewed purely as a periodic compliance exercise.vThe most useful audits show an organisation where control weaknesses originate and how the underlying process can be improved.
For example, repeated invoice exceptions may indicate a problem much earlier in the process: incorrect PO data, unclear purchasing policy, poor supplier information or an approval workflow that no longer reflects the organisation’s needs.
Looking at the P2P process from end to end enables finance teams to fix the cause rather than repeatedly correcting the symptom.
Strengthen Your P2P Controls with Documation
For more than 30 years, Documation has helped organisations improve and automate finance processes.
Our P2P solutions are designed around the way an organisation needs to operate, helping finance and AP teams introduce greater control and visibility across processes including invoice capture, matching, approvals, exceptions and audit trails.
If your P2P audit has uncovered manual bottlenecks, control weaknesses or limited process visibility, we can help you explore where automation could strengthen your existing process.
