A procurement audit is an independent review of how an organization buys: whether sourcing followed policy, whether negotiated contracts were used where they existed, whether purchase order controls worked, and whether the terms procurement negotiated actually reached the people placing orders and the suppliers billing against them. Where a contract compliance audit tests whether a single agreement was billed correctly, a procurement audit tests the process that decides which agreements get used in the first place.
The two questions are closely linked. World Commerce & Contracting research puts value erosion in procurement contracts at 11 percent, and attributes much of it to a fragmented operating model in which sourcing, legal, operations, and finance each see only part of the picture. The same research found that only 15 percent of organizations share contracting technology between legal and procurement. A procurement audit is the review designed to see the whole picture at once.
What a procurement audit tests
A procurement audit tests whether the buying process delivered the value it was designed to capture. The scope varies by organization, but most audits cover the same core areas.
- Sourcing and policy adherence. Were competitive processes run where policy required them, and were exceptions documented and approved?
- Contract utilization. When a negotiated agreement existed, was it used, or did spend go to off-contract suppliers at list prices?
- Purchase order controls. Were POs raised before commitments were made, and were PO overrides and after-the-fact POs approved appropriately?
- Pricing realization. Did the rates, discounts, and rebates procurement negotiated appear on the invoices that followed?
- Supplier setup and master data. Were suppliers onboarded with the correct terms, and do system records match the executed agreements?
- Segregation of duties. Are the people who select suppliers, approve purchases, and approve payments appropriately separated?
How a procurement audit differs from other reviews
Procurement audits, contract compliance audits, and payment recovery audits overlap, and organizations often run them together. They are distinguished by the question each one answers.
- Procurement audit. Answers whether the organization bought the right way, from the right source, under the right terms. It examines sourcing, contract use, PO controls, and policy.
- Contract compliance audit. Answers whether the supplier billed what the contract allows. It tests invoices line by line against contract clauses.
- Payment recovery audit. Answers whether each payment was accurate, authorized, and made once. It examines payment records, duplicates, credits, and statements.
The findings of one frequently point to the others. A contract compliance audit that finds rebates were never claimed often traces back to a procurement gap: nobody was assigned to reconcile spend against the rebate schedule. A procurement audit that finds heavy off-contract spend often explains why a contract’s volume commitments were never met.
How a procurement audit runs
Most procurement audits follow a consistent sequence, scaled to the organization’s spend and systems.
- Scoping. The audit focuses on the categories, business units, and suppliers where spend is largest or controls are weakest, rather than sampling evenly across the whole organization.
- Data collection. The team gathers the spend data, purchase orders, contracts and amendments, supplier master records, and invoice and payment history for the review period.
- Testing. Transactions are tested against policy and against the governing contracts: sourcing records, PO timing and approvals, contract coverage, and pricing on the invoice versus pricing in the agreement.
- Validation. Exceptions are reviewed by experienced auditors to confirm genuine findings and rule out false positives before anything is reported.
- Reporting and root cause. Findings are documented with their dollar impact and the specific control or process gap that allowed them, so the fix addresses the cause rather than the symptom.
The most common procurement audit findings
The same handful of findings appear across industries, because they come from the same structural gaps between the people who negotiate terms and the people who use them.
- Off-contract spend. Purchases made from a supplier outside the negotiated agreement, or from a non-contracted supplier when a contracted one existed, typically at list price rather than the negotiated rate.
- Missed volume tiers and rebates. Spend that crossed a tier threshold or earned a rebate under the contract, where the lower rate or the rebate was never applied because nobody reconciled actual volume against the schedule.
- After-the-fact purchase orders. POs raised after the goods or services were ordered, or after the invoice arrived, which removes the point at which pricing and scope should have been checked.
- Price-list drift. Catalog or system prices that were correct when the contract was signed and were never updated for negotiated decreases, amendments, or expired promotional terms.
- Duplicate or incomplete supplier records. The same supplier set up more than once, or set up without the contract terms attached, so orders default to standard pricing.
Each of these has a recoverable component and a control component. The recoverable dollars are documented and resolved with the supplier; the control gap is closed so the same finding does not return in the next review.
What findings look like
Procurement audit findings typically fall into two groups: recoverable dollars, where a supplier billed outside negotiated terms, and process findings, where a control gap explains why it happened. The best audits deliver both, because recovery without root cause simply resets the clock.
A Revenew MRO procurement audit for a mining company illustrates the pattern. The review identified AUD $362,836 and recovered AUD $259,020, resolved long-running billing disputes with suppliers, and produced contractual improvements that carried forward into future purchasing. Findings like these should be read as engagement outcomes rather than predictions; results depend on spend volume, category mix, and how recently the process was last reviewed.
Where procurement audit connects to the rest of the cluster
A procurement audit is most useful when it feeds the disciplines around it. Pricing realization findings point directly to vendor contract management, the practice of keeping negotiated terms enforced after signature. Contract-level findings are best followed up with line-item testing, which our contract audit checklist walks through in detail.
Getting started
The most practical starting point is the category where spend is largest and contract coverage is least certain. Revenew’s Category Strategy and Sourcing and Contract Compliance Reviews bring more than 25 years of experience to reviewing how organizations buy and whether their negotiated terms hold.
Request a No-Risk Review to see how your procurement terms are performing in practice.