Purchase-to-Pay Internal Audit Checklist for Growing SMEs
A purchase starts long before an invoice reaches the accounts team. Someone requests an item, chooses a vendor, approves a price, confirms delivery and releases payment. When these steps are unclear, a growing SME can find it difficult to explain who approved a transaction or whether the goods arrived as expected.
A purchase-to-pay internal audit checklist helps organise a review across the whole process. Use the following questions as a starting point for a discussion with your process owners and internal audit team. The scope and sample size should reflect the business's risks and transaction volumes.
1. Vendor creation and bank-detail changes
Identify who can create or amend a vendor record. Check whether there is evidence supporting the business need and whether the person approving the record is separate from the person preparing it where staffing allows. Review how bank-detail changes are independently confirmed through a trusted contact channel.
Is there a current vendor list with clear ownership?
Are duplicate or inactive vendor records reviewed?
Can the business trace who requested, checked and approved a bank-detail change?
2. Purchase requests and approvals
Select transactions across different buyers and spend categories. Follow each transaction back to the original requirement and approval. Check whether approval limits are documented and whether the person approving the purchase had the right authority at the time.
Look for patterns that deserve explanation, such as repeated urgent purchases or several closely related orders just below an approval limit. A pattern is a reason to investigate, rather than proof of misconduct.
3. Receipt of goods or confirmation of services
Ask how the business records quantities received, damaged goods, partial deliveries and service completion. The person confirming receipt should have enough information to verify what was actually delivered. For services, this may involve a milestone approval or confirmation from the responsible department.
Can a receipt be connected to the relevant purchase order?
Are differences in quantity or quality documented and resolved?
Are pending receipts reviewed before invoices move to payment?
4. Invoice checking and payment release
Where applicable, compare the purchase order, receipt record and invoice. Check how price or quantity differences are approved. Review the process for identifying duplicate invoices and for confirming that credit notes or advance payments have been considered.
Follow a selected payment through preparation, approval and bank release. If a small team cannot separate every responsibility, discuss an appropriate independent review with management and document how that review operates.
5. Access rights and exception reporting
Review who can amend vendor information, enter invoices and release payments. Ask whether access changes when an employee moves roles or leaves. Then look at the exception reports management actually reviews: overdue approvals, unmatched receipts, duplicate invoice warnings and unresolved supplier balances.
Reports should identify an owner and a response date. A long list of exceptions with no follow-up provides less value than a shorter list that is investigated and resolved.
How to record findings so action follows
For each finding, record the expected control, the evidence examined, what happened, the business impact and the agreed corrective action. Assign an owner and a target date. Distinguish a missing procedure from a procedure that exists but is not followed; the corrective action may be different.
For example, if service completion evidence is missing, the action could be to define who confirms completion and where that confirmation is stored. Follow-up should check a later transaction to see whether the revised process is being used.
Do SMEs need the same checklist as large companies?
The basic questions can be similar, but the review should reflect the size and complexity of the organisation. A checklist supports judgement; it does not replace a risk-based audit plan or demonstrate compliance by itself.
Review your purchase controls with Coreinfo
Coreinfo provides internal audit services. Share your transaction volumes, purchasing process and main concerns so the review scope can be discussed.



Comments