Revenew International logo

A contract compliance audit is only as reliable as the checklist behind it. Skip a document, miss a clause type, or fail to verify a finding before raising it with a supplier, and the audit either misses real leakage or damages a relationship over a false positive. This is the checklist Revenew auditors work from, organized the way an engagement actually runs: intake, testing, verification, and resolution.

1. Document intake

Before any testing begins, gather:

  • The fully executed master agreement, plus every amendment, side letter, and renewal.
  • The current pricing schedule and any historical versions in effect during the review period.
  • Purchase orders and receiving records tied to the contract.
  • The complete population of invoices and payment records for the review period.
  • Credit memos, statement balances, and any documented rebate or incentive agreements.
  • Correspondence documenting any informal scope changes or price concessions.

Gaps here are the single biggest limiter on what an audit can find. Missing amendments in particular are a common source of false disputes with suppliers, since a rate that looks wrong against the master agreement may be correct against a side letter no one filed.

2. Pricing and rate verification

  • Does the invoiced rate match the contract's current pricing tier for this date?
  • Was every rate escalation applied at the correct time, percentage, and base?
  • Are quantity-based pricing tiers (volume breaks, minimums) applied correctly?
  • Do multi-year contracts show any rates that were never updated after a renegotiation?

3. Rebates, discounts, and incentives

  • Were all contractually earned volume rebates actually claimed?
  • Were early-payment discounts applied when payment terms qualified?
  • Are performance-based incentives calculated against the correct baseline?
  • Is there a reconciliation process, or did rebates depend on someone remembering to check?

4. Scope and billing accuracy

  • Does every billed line item fall within the contract's defined scope?
  • Were any change orders issued for out-of-scope work, and billed at the negotiated change-order rate rather than the base contract rate?
  • Are there duplicate charges across invoice numbers, payment methods, or business units?
  • Do subcontractor or third-party pass-through charges match the markup terms in the contract?

5. Labor and equipment terms

  • Are personnel billed at the classification and rate the contract specifies?
  • Is equipment billed at the negotiated contract rate, or at list price?
  • Do per diem, overtime, and mobilization charges match contract terms?

6. Performance and service-level terms

  • Where the contract ties payment to service levels, were those levels documented as met before payment was released?
  • Are penalty or credit clauses for missed service levels being enforced?

7. Verification, before anything reaches the supplier

Every flagged discrepancy goes through a verification step before it becomes a finding:

  • Confirm the error against the correct, current version of the contract (accounting for amendments).
  • Rule out a legitimate explanation, such as an approved but undocumented change.
  • Quantify the dollar impact across the full review period, not just the sample transaction.
  • Document the finding to a standard the supplier can independently verify.

This step is what separates a credible audit from a billing dispute. Revenew runs 140 audit tests against every contract, and every flagged item is verified by an experienced auditor before it is ever raised externally.

8. Root-cause and prevention

  • What specific process or control gap allowed this error to occur?
  • Is the same gap likely to affect other contracts with this or other suppliers?
  • What contract language, rate table correction, or control change would prevent recurrence?

A checklist that stops at "was money recovered" leaves the underlying cause in place. The strongest audits close with a specific, actionable fix for every recurring finding.

This checklist tests a single contract. A procurement audit tests the buying process around it, and a supplier audit applies these tests across every agreement with one supplier.

Getting started

This checklist reflects the same process Revenew's audit teams run on every contract compliance engagement. If you'd rather have an independent team run it for you, our Contract Compliance Reviews apply this exact framework, backed by full-population analytics rather than sampling.

Request a No-Risk Review to see what this checklist would find in your contracts.

Frequently Asked Questions

What documents are needed for a contract compliance audit? At minimum: the fully executed master agreement and all amendments, the current and historical pricing schedules, purchase orders, the full population of invoices and payments for the review period, credit memos, and any rebate or incentive agreements.
What is the most commonly missed item in a contract audit? Amendments and side letters. When they aren't incorporated into a single source of truth, rates that are actually correct under an amendment can look like errors against the outdated master agreement, and vice versa.
Why does every finding need to be verified before it's presented to a supplier? Unverified findings risk becoming disputes rather than resolved recoveries. Verification confirms the error against the correct contract version, rules out legitimate explanations, and quantifies the true dollar impact, which is what makes a finding credible and low-friction to resolve.
Does a contract audit checklist replace an independent audit? It's a useful internal tool for a first-pass review, but full-population testing, verification by experienced auditors, and supplier-facing documentation are difficult to replicate without dedicated resources, which is why many organizations use the checklist internally and bring in a specialist for the full audit.