10.5 Supply Management Audits, Compliance Measurement & Purchase Fraud Investigation

Key Takeaways

  • Compliance measurement turns policy into metrics: maverick-spend rate, PO compliance, approval-threshold exceptions, and segregation-of-duties monitoring.
  • Audit findings demand a structured response: root cause, corrective action plan with owners and dates, evidence, and verified closure — not rebuttal.
  • Procurement fraud follows recognizable patterns: split purchases below approval limits, ghost vendors, duplicate invoices, bid rigging, and conflicts of interest.
  • Fraud investigation is a disciplined, evidence-preserving process run with internal audit and legal — never a solo confrontation by the buyer.
Last updated: August 2026

10.5 Supply Management Audits, Compliance Measurement & Purchase Fraud Investigation

Risk and Compliance testing does not stop at external threats — it reaches inside the procurement function itself. Tasks 3-E-6, 3-E-7, and 3-E-9 form a control loop: measure compliance, resolve what audits find, and investigate fraud and non-compliant buying without destroying evidence or careers on suspicion alone.


1. Measuring & Improving Policy Compliance (Task 3-E-6)

What gets measured gets complied with. Standard compliance instrumentation:

MetricWhat It Reveals
Maverick / off-contract spend %Purchases outside negotiated agreements (Section 12.2) — value leakage and control weakness
PO-before-invoice complianceInvoices with no PO indicate bypassed process
Approval-threshold exceptionsTransactions just under approval limits (e.g., $9,900 vs. a $10,000 limit) — split-purchase signal
Segregation-of-duties (SoD) conflictsSame person creating vendors, approving POs, and posting receipts — the classic fraud enabler
Catalog vs. non-catalog shareProcess adoption of the P2P channel (Section 12.1)
Sole-source justification rateHow often competition is waived, and why

Preventive Control Structure

  • Delegation of authority: dollar-tiered approval matrix; no self-approval at any level.
  • Segregation of duties: vendor master maintenance, requisitioning, receiving, and payment separated across roles.
  • System-enforced workflow: the P2P system blocks non-compliant paths rather than relying on policy memos (three-way match, Section 12.1).
  • Training and publication: policies only bind people who know them (Section 13.6 on dissemination).

2. Responding to Audit Reports (Task 3-E-7)

Internal audit, external auditors, and customer/regulatory audits periodically examine procurement. Common findings and the structured response:

+-----------------------------------------------------------------------------+
|                  AUDIT FINDING RESPONSE LIFECYCLE                           |
|                                                                             |
|   [1. UNDERSTAND]    Read the finding precisely: what control failed,       |
|          │           over what population, with what evidence?              |
|          v                                                                  |
|   [2. ROOT CAUSE]    5-Whys to the process/cause — not 'the buyer erred'    |
|          v                                                                  |
|   [3. CORRECTIVE     CAP with owner, due date, and measurable fix:          |
|        ACTION PLAN]  process change, system control, training, or           |
|          │           role redesign (not just 'reminder email')              |
|          v                                                                  |
|   [4. EVIDENCE &     Implement; produce objective evidence; audit verifies  |
|        CLOSURE]      effectiveness before closure                           |
+-----------------------------------------------------------------------------+
  • Typical procurement findings: missing competitive bids above thresholds, undocumented sole-source awards, expired contracts still in use, vendor-master anomalies, conflicts of interest not disclosed, receipts not recorded (Section 5.5), and maverick spend concentration.
  • Wrong responses: debating the sample size, blaming individuals without fixing process, or closing findings with policy re-circulation and no control change.

3. Investigating Fraudulent & Non-Compliant Purchases (Task 3-E-9)

The Red Flags

  • Split purchases: repeated requisitions just below an approval threshold to the same supplier.
  • Ghost vendors: vendor-master entries sharing an employee's address, bank account, or phone number; vendors with only P.O. boxes and no tax ID.
  • Duplicate / round-dollar invoices: same amount, same date, sequential invoice numbers from the same vendor.
  • Bid rigging patterns: rotating winners, identical pricing errors across bidders, losing bids that make the winner look competitive (links to antitrust exposure, Section 11.1).
  • Lifestyle and relationship signals: unexplained wealth, undisclosed supplier relationships, gifts during sourcing events (Section 11.1).

The Investigation Protocol

  1. Preserve evidence quietly: secure records, system logs, and documents before the subject can alter them; place a legal hold (Section 10.4).
  2. Engage the right owners: internal audit, legal counsel, HR, and — where external crime is suspected — outside counsel/law enforcement. The buyer does not investigate alone.
  3. Analyze with data: vendor-master/employee master matching, threshold-cluster analysis, duplicate-invoice detection (analytics tools, Section 12.3).
  4. Interview last: confront only after documentary evidence is assembled.
  5. Remediate and fix controls: recovery, discipline per policy, disclosure where legally required, and closure of the control gap that allowed it.

CPSM Exam Focus

The exam rewards process discipline: metrics that reveal non-compliance, audit responses that fix root causes with verifiable corrective actions, and fraud response that preserves evidence and involves internal audit/legal before any confrontation. Vigilante options — accuse first, investigate publicly, fire on suspicion — are always wrong.

4. The Fraud Triangle in Procurement

Occupational fraud research (the CFE fraud triangle) explains why otherwise trusted employees cross the line — and why controls target opportunity:

  • Pressure/incentive: personal financial stress, lifestyle demands, addiction.
  • Opportunity: weak segregation of duties, sole control of vendor master and approvals, no receipt verification, infrequent audits. This is the leg management controls.
  • Rationalization: 'the company underpays me,' 'just borrowing,' 'everyone does it.'

A buyer controlling vendor creation, PO approval, and receipt confirmation has the full opportunity chain — which is why SoD conflicts (Section 10.5 table) are treated as critical audit findings even when no fraud has occurred.

5. Analytics That Surface Purchase Fraud

Modern detection runs on data, not hunches (tools in Section 12.3):

  • Vendor/employee master matching: addresses, bank accounts, phone numbers, tax IDs.
  • Threshold clustering: spend histograms bunching just below approval limits.
  • Duplicate detection: same invoice number, amount, or date patterns across periods.
  • Benford-style digit analysis: unnatural leading-digit distributions in fabricated invoices.
  • Speed anomalies: PO created, goods 'received,' and invoice paid within hours, repeatedly.
  • Round-dollar and weekend patterns: non-operational timestamps and suspiciously round amounts.

None of these proves fraud — each earns a quiet, evidence-preserving review under the investigation protocol before any accusation is made.

Test Your Knowledge

A compliance dashboard shows 23 requisitions this quarter from one department, each between $9,200 and $9,800 — just under the $10,000 competitive-bid threshold — all to the same two suppliers. What is the correct interpretation and next step?

A
B
C
D
Test Your Knowledge

An internal audit report finds that 31% of sampled POs above $25,000 had no documented competitive bid, and 12% had no sole-source justification. The category director's draft response reads: 'Auditors sampled unlucky months; buyers are reminded to try harder.' Why is this inadequate, and what should the response contain?

A
B
C
D
Test Your Knowledge

Data analytics reveals a vendor whose remit-to bank account matches a procurement clerk's personal account, with $240,000 paid over 14 months for 'consulting' never documented. What is the correct immediate action?

A
B
C
D