5.1 Asset, Supply Chain, Inventory, Payables, Procurement, and Compliance Processes
Key Takeaways
- CIA Part 2 A.3.f is a planning skill: recognize key risks and typical controls for named business processes so objectives and scope hit what threatens the activity; it is not yet a test of operating effectiveness
- Asset-management key risks at planning are existence and safeguarding; typical controls include tagging, assigned custody, physical verification against the register, and dual authorization for disposal
- Match the KEY risk to the named activity: supply-chain disruption and three-way match; inventory valuation, obsolescence, and count; AP duplicate pay and cutoff; procurement vendor-master segregation; compliance with laws and policies
- The three-way match (purchase order, receiving report, vendor invoice) bridges procurement, receiving, and accounts payable; the same person maintaining the vendor master and influencing payment is the classic procurement fraud enabler
5.1 Asset, Supply Chain, Inventory, Payables, Procurement, and Compliance Processes
Quick Answer: CIA Part 2 A.3.f is a planning skill. When you plan an engagement, recognize the key risks and typical controls for common business processes—asset management, supply chain management, inventory management, accounts payable, procurement, and compliance—so objectives, scope, and the work program address what actually threatens the activity. You are not yet testing operating effectiveness (Chapter 9). The exam names an activity; you pick the KEY risk for that activity, not every risk that could exist.
CIA Part 2 Section A is Engagement Planning (50%). Objective A.3 asks you to identify relevant information to plan the engagement. Bullet f lists named operational and financial processes and, in later sections of this chapter, named systems. This section covers the six process names. The skill sits in the Global Internal Audit Standards under Principle 13, Plan Engagements Effectively, especially Standard 13.2, Engagement Risk Assessment: you cannot write a useful objective until you know how the activity under review creates risk.
Do not turn this section into Chapter 4.3 (finance and accounting concepts such as current versus fixed assets, capital, and investments) or into Chapter 9 (procedures to evaluate design and test operating effectiveness). The question here is narrower: for this named process, what is the key risk, and what control would a competent planner expect to see?
How to use a process-risk map while planning
Walk the activity, name the process, and write one key risk plus two or three typical controls into the planning file. If the activity is a warehouse, inventory valuation, shrinkage, and count accuracy dominate. If the activity is vendor onboarding, procurement segregation and the vendor master dominate. A planning memo that lists twenty generic control-environment risks and no process-specific key risk will not support a focused objective.
The key risk is the one that, if it materializes, most threatens the engagement objective for that activity. Theft of a stapler is not the key asset-management risk for a fleet of diagnostic machines. Duplicate payment of a construction invoice is a key accounts-payable risk. Exam items are built on that distinction.
Asset management: existence and safeguarding
Asset management is the process that records, locates, protects, and retires assets the organization uses to operate—equipment, vehicles, IT hardware, tools, and sometimes licenses or spares that live on an asset register rather than in inventory.
Key risks. Existence: the register lists items that are missing, never received, or already sold. Safeguarding: unauthorized removal, damage, or use. Related planning risks include incomplete tagging, no assigned custodian, unauthorized disposal or scrap, and a register that does not reconcile to the general ledger. Existence and safeguarding are the exam’s first stop. Detailed valuation and depreciation methods belong more to Chapter 4.3 unless the stem is clearly about the asset process (for example, capitalizing supplies to hide purchases).
Typical controls. Unique asset tags tied to a register; assigned custodians; restricted storage for high-value movable items; physical verification (full count or cycle count) compared to the register; dual authorization for disposal, transfer, or scrap; and reconciliation of the asset register to the general-ledger control account.
Planning cue. If the stem involves tools, laptops, medical devices, or rolling stock, ask: could this item walk away, and would anyone notice? That is existence and safeguarding, not accounts-payable cutoff.
Supply chain management: disruption and the three-way match
Supply chain management is the flow of goods, information, and funds from supplier to the organization (and often onward to the customer). Planning-level key risks are disruption—sole-source failure, logistics shock, quality escape, weather or geopolitical interruption—and integrity of receiving and matching: goods that never arrived but were recorded, or arrived damaged and were still accepted.
Typical controls. Dual sourcing or qualified alternates for critical parts; supplier scorecards and incoming inspection; safety stock for long-lead items; logistics service-level agreements; and the three-way match—purchase order, receiving report, and vendor invoice—before the payable is recognized. A four-way match adds an inspection or quality ticket. Concentration of spend with one supplier is a supply-chain issue and a third-party issue (Section 5.2).
Planning cue. A plant that stops if one vendor misses a shipment has disruption as the key risk. A receiving dock that posts receipts without a packing slip has match integrity as the key risk.
Inventory management: valuation, obsolescence, and count
Inventory management covers quantities and values of raw materials, work-in-process, finished goods, and merchandise.
Key risks. Valuation (wrong unit cost, ignored net realizable value); obsolescence and slow-moving stock still carried at full cost; count error and shrinkage; cutoff (goods counted in inventory and also in transit, or omitted from both); consignment or customer-owned stock mixed with owned stock.
Typical controls. Perpetual records plus cycle counts or a controlled annual physical; quarantine of damaged goods; aging and obsolescence reviews with write-down authority; bill-of-materials accuracy; receiving and shipping cutoff procedures; and flags that identify consignment stock. Costing method (FIFO, weighted average) must be applied consistently—here as a process control, not as a financial-reporting essay.
Planning cue. Year-end warehouse, pharmaceutical expiry, or fashion seasonality points to obsolescence and count. Do not default to AP duplicate-pay.
Accounts payable: duplicate pay and cutoff
Accounts payable (AP) records amounts owed to vendors and pays them.
Key risks. Duplicate payment (same invoice paid twice, or paid on both an invoice and a statement); payment to a fictitious or substituted vendor; cutoff / unrecorded liabilities (goods received, invoice not booked); wrong amount or payment that ignores terms.
Typical controls. Three-way match before the voucher is approved; automated duplicate-invoice edits (vendor + invoice number + amount); vendor-statement reconciliations; a period-end search for unmatched receipts (goods received not invoiced); dual authorization of the payment run; and extra review before a one-time vendor is paid.
Planning cue. “Paid twice,” “invoice and copy,” or “received before year-end but not recorded” is AP duplicate pay or cutoff, not inventory obsolescence.
Procurement: vendor master and segregation
Procurement is sourcing, contracting, and raising purchase orders. It sits upstream of AP.
Key risks. Inappropriate or related-party vendor; bid-rigging or noncompetitive awards; maverick spend (buying outside a purchase order); vendor-master fraud (an employee creates a vendor and directs payment to a controlled account). The classic control failure is missing segregation of duties: the same person maintains the vendor master, issues purchase orders, and can influence payment.
Typical controls. Competitive bid or documented sole-source justification; an approval matrix for purchase orders by amount; segregation among vendor-master maintenance, requisitioning, receiving, and payment; conflict-of-interest attestations; and monitoring of non-PO spend.
Planning cue. The same employee “sets up vendors and pays them” is procurement segregation / vendor master, not an inventory count problem.
Compliance processes: laws and policies
Compliance in A.3.f is the process that identifies applicable laws, regulations, licenses, and internal policies, then monitors adherence and exceptions. It is not a full regulatory specialty exam.
Key risks. Operating without a required license; violating a statute or internal policy; unreported exceptions; a stale policy library so people follow yesterday’s rule.
Typical controls. A current inventory of obligations with assigned owners; training; monitoring or quality checks; exception logs with escalation; and a regulatory calendar for filings and renewals.
Planning cue. The stem names a license, privacy rule, or mandatory policy → compliance-process risk. Do not recast it as AP cutoff unless the issue is specifically an unrecorded legal obligation.
Comparison table: key risk versus typical control
Use this table when the stem names an activity and asks which risk is KEY.
| Process | Key risks at planning | Typical controls | Stem cue for the KEY risk |
|---|---|---|---|
| Asset management | Existence; safeguarding; unauthorized disposal; incomplete register | Tagging; custody; physical verification; dual-authorized disposal; register-to-GL reconciliation | Tools, laptops, equipment “missing” or untagged |
| Supply chain management | Disruption; sole-source concentration; inbound quality; receiving without a match | Dual sourcing; scorecards; incoming inspection; safety stock; three-way match | Plant stoppage; one critical vendor; dock receipts |
| Inventory management | Valuation error; obsolescence; shrinkage; count error; cutoff; consignment mix | Cycle counts; NRV/aging reviews; cutoff procedures; consignment flags | Warehouse; expiry; slow-moving; physical inventory |
| Accounts payable | Duplicate pay; fictitious vendor; unrecorded liabilities / cutoff; wrong amount | Three-way match; duplicate edits; vendor statements; GRNI search; payment dual authorization | Paid twice; goods received not invoiced |
| Procurement | Vendor-master fraud; weak segregation; bid-rigging; maverick spend | SOD on vendor master versus payment; bid/justification; PO approval; conflict attestations | Same person adds vendor and pays |
| Compliance | Breach of law or policy; expired license; hidden exceptions | Obligation inventory; training; monitoring; exception escalation; filing calendar | License, statute, mandatory policy |
When two processes touch the same document, pick the risk that matches the activity named in the objective. An engagement on vendor setup is procurement. An engagement on the payment run is AP. An engagement on dock receiving is supply chain or inventory, with three-way match as the bridging control. Do not let a generic “fraud risk” answer replace the named-process key risk the syllabus is testing.
An assurance engagement is being planned over a hospital’s portable ultrasound units, which move among wards and are listed on an asset register. Which risk is KEY for this activity?
A manufacturer will idle an assembly line if a sole-source chip vendor misses a shipment. The engagement objective is operational continuity of that line. Which risk is KEY?
Planning interviews show that the same accounts clerk can add a vendor to the vendor master and can initiate a payment in the weekly run. Which risk is KEY?