Procurement Audit Controls for Procurement Managers Training Course

5 days Auditing Certificate on completion
Course codeSD-A-060
Duration5 days
LevelIntermediate to Advanced
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Procurement managers are accountable for decisions that can withstand audit scrutiny: supplier selection, contract awards, purchase-order approvals, changes to scope, emergency purchases, and payment authorisations. Yet many control failures arise in ordinary operational activity rather than deliberate misconduct—split orders below approval thresholds, incomplete bid evaluations, undocumented single-source justifications, weak segregation of duties, and supplier master-data changes without review. This course enables managers to identify where their procurement process is exposed, test whether controls are operating, and correct weaknesses before they become audit findings, financial losses, or supplier disputes.

Participants learn to build a procurement audit universe, map procure-to-pay risks, distinguish preventive from detective controls, and design control tests around key evidence. The programme covers approval matrices, competitive tender controls, conflict-of-interest declarations, supplier onboarding, contract compliance, three-way matching, change-order governance, spend analytics, and remediation tracking. Managers practise using risk-control matrices, audit test scripts, sampling plans, exception logs, and root-cause analysis to assess both manual and system-enabled controls.

Delivery combines instructor-led audit methods with procurement case files, spreadsheet-based testing, and peer challenge sessions. Participants review realistic tender, contract, purchase-order, invoice, and supplier-master-data records to identify control gaps and substantiate findings. Each participant leaves with a tailored Procurement Audit Control Pack containing a risk-control matrix, testing plan, evidence checklist, issue-rating model, and 90-day remediation roadmap for application in their own procurement environment.

The course is designed for experienced procurement professionals who manage sourcing, purchasing, contracts, supplier relationships, or procure-to-pay operations and need a stronger command of internal-control and audit practice.

Course objectives

By the end of this course, participants will be able to:

  • Map procure-to-pay risks into a procurement audit universe covering sourcing, contracting, purchasing, receiving, and payment
  • Construct a risk-control matrix linking procurement risks, control objectives, owners, evidence, and test procedures
  • Test approval authority, delegation-of-authority, and segregation-of-duties controls using transaction evidence
  • Evaluate competitive bidding, sole-source, conflict-of-interest, and tender-evaluation controls against documented policy requirements
  • Design audit sampling plans and test scripts for purchase orders, supplier records, invoices, contract changes, and emergency purchases
  • Analyse procurement exceptions using Excel pivot tables, duplicate-payment checks, threshold-splitting tests, and spend-pattern indicators
  • Rate audit findings by financial, compliance, operational, and fraud risk and document root causes with corrective actions
  • Produce a 90-day procurement control remediation roadmap with accountable owners, milestones, and follow-up testing measures

Benefits of attending

For you

  • Build the confidence to challenge weak procurement practices with evidence rather than opinion
  • Develop reusable audit test scripts for sourcing, contracting, purchasing, and supplier-master-data reviews
  • Strengthen credibility with finance, internal audit, legal, and senior management during control discussions
  • Learn to translate transaction exceptions into clearly rated findings and practical corrective actions
  • Create a portfolio-ready Procurement Audit Control Pack that demonstrates governance capability for senior procurement roles

For your organisation

  • Reduce exposure to unauthorised spend, order splitting, duplicate payments, and unsupported supplier awards
  • Improve audit readiness through consistent evidence requirements, control ownership, and documented testing procedures
  • Identify segregation-of-duties and approval-matrix weaknesses before they lead to fraud or policy breaches
  • Increase contract and purchase-order compliance by applying targeted exception testing to high-risk transactions
  • Accelerate remediation of procurement audit findings through accountable action plans and follow-up controls testing

Target competencies

Procurement risk assessmentControl design testingAudit evidence evaluationSpend exception analysisFinding root-cause analysisRemediation roadmap planning

Who should attend

  • Procurement Managers — who own purchasing controls and must defend procurement decisions to internal audit and finance
  • Strategic Sourcing Managers — who oversee tender, evaluation, and award processes requiring transparent evidence trails
  • Procure-to-Pay Managers — who manage requisition, purchase-order, receipt, invoice, and approval workflows
  • Category Managers — who need to identify control risks within supplier agreements, spend categories, and sourcing events
  • Contract and Commercial Managers — who govern contract changes, supplier performance records, and commercial approvals
  • Procurement Compliance Leads — who monitor policy adherence and coordinate responses to procurement audit findings

Requirements and prerequisites

Participants should have practical experience with purchasing, sourcing, contract administration, supplier management, or procure-to-pay operations. They should understand basic procurement documents and terms such as requisition, purchase order, request for quotation, tender evaluation, contract variation, goods receipt, invoice, approval limit, and three-way match. Familiarity with their organisation’s procurement policy, delegation-of-authority matrix, and ERP or e-procurement workflow is useful. Participants should also be comfortable reviewing data in Microsoft Excel. Formal internal-audit certification, accounting qualifications, statistical expertise, or prior use of specialist audit software are not required.

Training methodology

The five-day programme uses short instructor-led sessions to establish audit concepts, followed by hands-on work with procurement documents and transaction datasets. Participants build risk-control matrices, inspect tender and contract files, test approval and three-way-match evidence, and analyse spend exceptions in Excel. Group case reviews simulate discussions between procurement, finance, and internal audit, requiring participants to defend their findings and recommendations. The final day converts course work into an individual 90-day control improvement plan for a live procurement process in each participant’s organisation.

Course outline

Day 1: Procurement risk, governance and audit planning

  • Procurement audit objectives, assurance roles, and the three lines model
  • Procure-to-pay process mapping from demand request to supplier payment
  • Procurement risk taxonomy for fraud, compliance, financial, and operational exposure
  • Audit universe development for sourcing, contracts, purchasing, suppliers, and payments
  • Control objectives and the distinction between preventive, detective, and corrective controls
  • COSO Internal Control Framework applied to procurement processes
  • Risk assessment scoring using likelihood, impact, control maturity, and residual risk

Workshop: Participants map a procure-to-pay process and produce a prioritised procurement audit universe for a case organisation.

Day 2: Sourcing, supplier and contract control testing

  • Competitive bidding controls for RFQs, RFPs, tender issue, and bid receipt
  • Tender-evaluation governance, scoring integrity, and award-decision evidence
  • Single-source and emergency procurement justification testing
  • Conflict-of-interest declarations, gifts registers, and evaluator independence controls
  • Supplier onboarding controls including due diligence, sanctions screening, and bank-detail validation
  • Contract approval, signature authority, and contract repository controls
  • Contract variation and change-order governance with commercial approval trails

Workshop: Participants audit a tender-to-contract case file and produce an evidence-based control-gap register with issue ratings.

Day 3: Purchase-to-pay controls and transaction evidence

  • Delegation-of-authority matrices and approval workflow testing
  • Segregation-of-duties analysis across requisition, purchase order, receipt, and payment roles
  • Purchase-order compliance and retrospective purchase-order detection
  • Three-way matching controls for purchase orders, goods receipts, and invoices
  • Invoice exception handling, duplicate-payment prevention, and credit-note controls
  • Supplier master-data change controls for bank accounts, addresses, and tax records
  • Audit evidence standards for system logs, approvals, documents, and management attestations

Workshop: Participants test a purchase-to-pay transaction sample and prepare a working-paper file that documents exceptions and supporting evidence.

Day 4: Data-driven procurement auditing and findings

  • Audit sampling methods including judgemental, random, systematic, and risk-based selection
  • Excel pivot tables for spend concentration and supplier-payment analysis
  • Threshold-splitting tests for repeated purchases below approval limits
  • Duplicate supplier, duplicate invoice, and duplicate bank-account detection logic
  • Price variance and contract-rate compliance testing
  • Exception log design, finding severity criteria, and audit issue wording
  • Root-cause analysis using the five whys and cause-and-effect mapping

Workshop: Participants analyse a procurement spend dataset and produce an exception log, risk-rated findings, and root-cause statements.

Day 5: Remediation, reporting and control sustainability

  • Corrective action design for policy, process, people, system, and data failures
  • Management action plans with owners, deadlines, dependencies, and measurable outcomes
  • Follow-up testing procedures to validate remediation effectiveness
  • Procurement control dashboards using key risk indicators and key control indicators
  • Audit report writing for executive, finance, and procurement stakeholders
  • Escalation protocols for suspected fraud, conflicts, and material control breaches
  • Ninety-day procurement control improvement planning and stakeholder engagement

Workshop: Participants present a Procurement Audit Control Pack and produce a 90-day remediation roadmap for one priority process in their organisation.

Tools & standards covered

Microsoft Excel, SAP Ariba, Coupa, COSO Internal Control Framework

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course is built for procurement managers and related professionals who need to assess and improve controls in the processes they manage. It introduces audit planning, testing, and reporting methods in procurement language, without assuming prior audit certification.

Bring a laptop with Microsoft Excel, ideally with pivot table functionality enabled. The exercises use supplied case data and templates, so access to your employer's SAP Ariba, Coupa, or ERP environment is not required during the course.

It suits managers responsible for sourcing, purchasing, contracts, supplier management, procurement compliance, or procure-to-pay operations. It is particularly useful for professionals preparing for an internal audit, responding to repeat findings, or redesigning approval and evidence controls.

General audit courses address audit methodology across many business functions. This programme applies those methods specifically to tendering, supplier onboarding, approval limits, purchase orders, three-way matching, contract changes, and procurement spend data.

You will be able to use the supplied risk-control matrix and test scripts to review a live procurement process, prepare for internal audit, or validate remediation actions. The 90-day roadmap gives you a structured way to assign owners, set milestones, and report progress to leadership.

You leave with a Procurement Audit Control Pack developed during the programme, including a risk-control matrix, audit test plan, evidence checklist, exception log, finding-rating model, and remediation roadmap. These templates can be adapted to your organisation's policy, delegation, and system workflow.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

Microfinance Internal Audit and Control Testing Training Course

Microfinance institutions operate through dispersed branches, high-volume loan transactions, field collections, group lending arrangements, …

5 Days Certificate

Insurance Premium and Claims Auditing Training Course

Premium leakage, inaccurate earned-premium calculations, duplicate claim payments, weak reserving evidence, and inconsistent authority contr…

5 Days Certificate

COBIT 2019 Control Assessment for IT Auditors Training Course

IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and p…

5 Days Certificate

COSO Internal Control Assessment Training Course

Finance, audit, compliance and control professionals are often asked to assess whether internal controls are designed effectively and operat…