A purchasing or procurement card (P-Card) is a credit or debit-like card that allows employees of an organization to purchase goods and services on behalf of the organization without having to go through the traditional procurement or purchase request and subsequent approval process.
P-Card programs enable employees to complete business transactions more efficiently and allow charges to be reviewed within moments of purchase. While P-Cards can be a great way to support effective and efficient purchases for your organization, P-Cards are at greater risk for misuse and fraud. Additionally, when P-Cards are used for online purchases, there is an increased risk that P-Card data is stolen and used to execute fraudulent transactions. Organizations should monitor and manage P-Card spending and reduce misuse and fraudulent behavior by implementing internal control activities, including the performance of P-Card audits.
The purpose of a P-Card audit is to identify whether controls are working as intended or whether other controls are needed to prevent misuse or fraud and detect instances in which misuse or fraud have occurred. Auditing P-Cards can benefit an organization by identifying opportunities for further process efficiencies and cost-saving benefits and help to reinforce a strong internal control environment around purchasing. Below are some key objectives for an effective P-Card audit.
P-Card audit objectives
Objectives of a P-Card audit may include, but are not limited to, the following:
- Determining whether the control environment is sufficient to prevent and/or detect possible fraudulent activities or misuse of organization funds
- Assessing whether fraud or misuse has occurred within the P-Card program
- Identifying procurement-related efficiencies the organization may implement to optimize financial resources
P-Card audit approach
A P-Card audit may have many different approaches depending on the audit objectives. An audit approach may include, but is not limited to, the following:
- Review available documentation such as organizational policies and procedures to identify controls designed to prevent or detect possible instances of misuse or fraud
- Examine available documentation to identify organization-specific compliance attributes to inform analytics and testing procedures. Testing procedures may include, but are not limited to:
- Transactions are below organization established P-Card thresholds
- Verification of business purpose
- Verification sales tax was not applied (if organization is a tax-exempt entity)
- Transactions include appropriate supporting documentation (e.g., receipts, invoices, etc.) - Assess training and workflow materials to identify and confirm organization-specific training requirements are met and workflows are optimized to meet the purchasing demands of the organization
- Conduct interviews with key personnel, process owners and procurement stakeholders at the organization to understand:
- Setup, usage and approval practices within the organization
- Organization requirements for P-Card holders, including any necessary training
- Monitoring and oversight to review spend - Perform data analytics to identify:
- Vendor trends (e.g., top vendors by volume and/or spend, most frequently used vendors, unusual vendors). Gaining an understanding of vendors with which the organization does a lot of business may lead the organization to explore opportunities to leverage economies of scale
- Employee spending trends (e.g., top employees by volume and/or spend, inactivity, determining whether P-Card is appropriate method to procure certain goods or services). Employee spending trends can serve as a reasonableness check to confirm whether the top spenders make sense given their role at the organization
- Transactions that may not comply with the organization’s policies and procedures (e.g., missing business purpose, splitting transactions to avoid P-Card spending limit thresholds or receipt thresholds, purchase of restricted items). This analytic test, as well as the identification of vendor and employee spending trends, may also be used to inform a sample selection for more detailed testing at the transaction level
- Review purchase amounts to consider whether current P-Card spending limits are appropriate and in line with the organization’s needs as well as leading industry practices
Key risks and how to approach them during audit fieldwork
Through analytics and purchasing trend reviews, auditors can identify possible unauthorized use or fraudulent activity within an organization. For example, if transactions are split, there is a risk of individuals bypassing the required approvals in effort to expedite the procurement process. For further information on risks associated with P-Cards and how to prevent them, read our insight, Optimizing P-Card use with internal audit.
Baker Tilly can help
Our specialized higher education risk advisory team can help your organization. How we help: