5.1 Asset, Supply Chain, Inventory, Payables, Procurement, and Compliance Processes

Key Takeaways

  • CIA Part 2 A.3.f is a planning skill: recognize key risks and typical controls for named business processes so objectives and scope hit what threatens the activity; it is not yet a test of operating effectiveness
  • Asset-management key risks at planning are existence and safeguarding; typical controls include tagging, assigned custody, physical verification against the register, and dual authorization for disposal
  • Match the KEY risk to the named activity: supply-chain disruption and three-way match; inventory valuation, obsolescence, and count; AP duplicate pay and cutoff; procurement vendor-master segregation; compliance with laws and policies
  • The three-way match (purchase order, receiving report, vendor invoice) bridges procurement, receiving, and accounts payable; the same person maintaining the vendor master and influencing payment is the classic procurement fraud enabler
Last updated: August 2026

5.1 Asset, Supply Chain, Inventory, Payables, Procurement, and Compliance Processes

Quick Answer: CIA Part 2 A.3.f is a planning skill. When you plan an engagement, recognize the key risks and typical controls for common business processes—asset management, supply chain management, inventory management, accounts payable, procurement, and compliance—so objectives, scope, and the work program address what actually threatens the activity. You are not yet testing operating effectiveness (Chapter 9). The exam names an activity; you pick the KEY risk for that activity, not every risk that could exist.

CIA Part 2 Section A is Engagement Planning (50%). Objective A.3 asks you to identify relevant information to plan the engagement. Bullet f lists named operational and financial processes and, in later sections of this chapter, named systems. This section covers the six process names. The skill sits in the Global Internal Audit Standards under Principle 13, Plan Engagements Effectively, especially Standard 13.2, Engagement Risk Assessment: you cannot write a useful objective until you know how the activity under review creates risk.

Do not turn this section into Chapter 4.3 (finance and accounting concepts such as current versus fixed assets, capital, and investments) or into Chapter 9 (procedures to evaluate design and test operating effectiveness). The question here is narrower: for this named process, what is the key risk, and what control would a competent planner expect to see?

How to use a process-risk map while planning

Walk the activity, name the process, and write one key risk plus two or three typical controls into the planning file. If the activity is a warehouse, inventory valuation, shrinkage, and count accuracy dominate. If the activity is vendor onboarding, procurement segregation and the vendor master dominate. A planning memo that lists twenty generic control-environment risks and no process-specific key risk will not support a focused objective.

The key risk is the one that, if it materializes, most threatens the engagement objective for that activity. Theft of a stapler is not the key asset-management risk for a fleet of diagnostic machines. Duplicate payment of a construction invoice is a key accounts-payable risk. Exam items are built on that distinction.

Asset management: existence and safeguarding

Asset management is the process that records, locates, protects, and retires assets the organization uses to operate—equipment, vehicles, IT hardware, tools, and sometimes licenses or spares that live on an asset register rather than in inventory.

Key risks. Existence: the register lists items that are missing, never received, or already sold. Safeguarding: unauthorized removal, damage, or use. Related planning risks include incomplete tagging, no assigned custodian, unauthorized disposal or scrap, and a register that does not reconcile to the general ledger. Existence and safeguarding are the exam’s first stop. Detailed valuation and depreciation methods belong more to Chapter 4.3 unless the stem is clearly about the asset process (for example, capitalizing supplies to hide purchases).

Typical controls. Unique asset tags tied to a register; assigned custodians; restricted storage for high-value movable items; physical verification (full count or cycle count) compared to the register; dual authorization for disposal, transfer, or scrap; and reconciliation of the asset register to the general-ledger control account.

Planning cue. If the stem involves tools, laptops, medical devices, or rolling stock, ask: could this item walk away, and would anyone notice? That is existence and safeguarding, not accounts-payable cutoff.

Supply chain management: disruption and the three-way match

Supply chain management is the flow of goods, information, and funds from supplier to the organization (and often onward to the customer). Planning-level key risks are disruption—sole-source failure, logistics shock, quality escape, weather or geopolitical interruption—and integrity of receiving and matching: goods that never arrived but were recorded, or arrived damaged and were still accepted.

Typical controls. Dual sourcing or qualified alternates for critical parts; supplier scorecards and incoming inspection; safety stock for long-lead items; logistics service-level agreements; and the three-way match—purchase order, receiving report, and vendor invoice—before the payable is recognized. A four-way match adds an inspection or quality ticket. Concentration of spend with one supplier is a supply-chain issue and a third-party issue (Section 5.2).

Planning cue. A plant that stops if one vendor misses a shipment has disruption as the key risk. A receiving dock that posts receipts without a packing slip has match integrity as the key risk.

Inventory management: valuation, obsolescence, and count

Inventory management covers quantities and values of raw materials, work-in-process, finished goods, and merchandise.

Key risks. Valuation (wrong unit cost, ignored net realizable value); obsolescence and slow-moving stock still carried at full cost; count error and shrinkage; cutoff (goods counted in inventory and also in transit, or omitted from both); consignment or customer-owned stock mixed with owned stock.

Typical controls. Perpetual records plus cycle counts or a controlled annual physical; quarantine of damaged goods; aging and obsolescence reviews with write-down authority; bill-of-materials accuracy; receiving and shipping cutoff procedures; and flags that identify consignment stock. Costing method (FIFO, weighted average) must be applied consistently—here as a process control, not as a financial-reporting essay.

Planning cue. Year-end warehouse, pharmaceutical expiry, or fashion seasonality points to obsolescence and count. Do not default to AP duplicate-pay.

Accounts payable: duplicate pay and cutoff

Accounts payable (AP) records amounts owed to vendors and pays them.

Key risks. Duplicate payment (same invoice paid twice, or paid on both an invoice and a statement); payment to a fictitious or substituted vendor; cutoff / unrecorded liabilities (goods received, invoice not booked); wrong amount or payment that ignores terms.

Typical controls. Three-way match before the voucher is approved; automated duplicate-invoice edits (vendor + invoice number + amount); vendor-statement reconciliations; a period-end search for unmatched receipts (goods received not invoiced); dual authorization of the payment run; and extra review before a one-time vendor is paid.

Planning cue. “Paid twice,” “invoice and copy,” or “received before year-end but not recorded” is AP duplicate pay or cutoff, not inventory obsolescence.

Procurement: vendor master and segregation

Procurement is sourcing, contracting, and raising purchase orders. It sits upstream of AP.

Key risks. Inappropriate or related-party vendor; bid-rigging or noncompetitive awards; maverick spend (buying outside a purchase order); vendor-master fraud (an employee creates a vendor and directs payment to a controlled account). The classic control failure is missing segregation of duties: the same person maintains the vendor master, issues purchase orders, and can influence payment.

Typical controls. Competitive bid or documented sole-source justification; an approval matrix for purchase orders by amount; segregation among vendor-master maintenance, requisitioning, receiving, and payment; conflict-of-interest attestations; and monitoring of non-PO spend.

Planning cue. The same employee “sets up vendors and pays them” is procurement segregation / vendor master, not an inventory count problem.

Compliance processes: laws and policies

Compliance in A.3.f is the process that identifies applicable laws, regulations, licenses, and internal policies, then monitors adherence and exceptions. It is not a full regulatory specialty exam.

Key risks. Operating without a required license; violating a statute or internal policy; unreported exceptions; a stale policy library so people follow yesterday’s rule.

Typical controls. A current inventory of obligations with assigned owners; training; monitoring or quality checks; exception logs with escalation; and a regulatory calendar for filings and renewals.

Planning cue. The stem names a license, privacy rule, or mandatory policy → compliance-process risk. Do not recast it as AP cutoff unless the issue is specifically an unrecorded legal obligation.

Comparison table: key risk versus typical control

Use this table when the stem names an activity and asks which risk is KEY.

ProcessKey risks at planningTypical controlsStem cue for the KEY risk
Asset managementExistence; safeguarding; unauthorized disposal; incomplete registerTagging; custody; physical verification; dual-authorized disposal; register-to-GL reconciliationTools, laptops, equipment “missing” or untagged
Supply chain managementDisruption; sole-source concentration; inbound quality; receiving without a matchDual sourcing; scorecards; incoming inspection; safety stock; three-way matchPlant stoppage; one critical vendor; dock receipts
Inventory managementValuation error; obsolescence; shrinkage; count error; cutoff; consignment mixCycle counts; NRV/aging reviews; cutoff procedures; consignment flagsWarehouse; expiry; slow-moving; physical inventory
Accounts payableDuplicate pay; fictitious vendor; unrecorded liabilities / cutoff; wrong amountThree-way match; duplicate edits; vendor statements; GRNI search; payment dual authorizationPaid twice; goods received not invoiced
ProcurementVendor-master fraud; weak segregation; bid-rigging; maverick spendSOD on vendor master versus payment; bid/justification; PO approval; conflict attestationsSame person adds vendor and pays
ComplianceBreach of law or policy; expired license; hidden exceptionsObligation inventory; training; monitoring; exception escalation; filing calendarLicense, statute, mandatory policy

When two processes touch the same document, pick the risk that matches the activity named in the objective. An engagement on vendor setup is procurement. An engagement on the payment run is AP. An engagement on dock receiving is supply chain or inventory, with three-way match as the bridging control. Do not let a generic “fraud risk” answer replace the named-process key risk the syllabus is testing.

Loading diagram...
Procure-to-pay flow and the three-way match
Documents in a vendor-pay match (planning recognition)
Test Your Knowledge

An assurance engagement is being planned over a hospital’s portable ultrasound units, which move among wards and are listed on an asset register. Which risk is KEY for this activity?

A
B
C
D
Test Your Knowledge

A manufacturer will idle an assembly line if a sole-source chip vendor misses a shipment. The engagement objective is operational continuity of that line. Which risk is KEY?

A
B
C
D
Test Your Knowledge

Planning interviews show that the same accounts clerk can add a vendor to the vendor master and can initiate a payment in the weekly run. Which risk is KEY?

A
B
C
D