The 5 main stages of the P2P cycle

With this article, we would like to begin a series on the most important controls in the key finance and accounting areas of a modern organisation:

  • Procure to Pay (P2P/PtP for short),
  • Record to Report (R2R/RtR for short),
  • Order to Cash (O2C/OtC for short),
  • and others, such as Payroll and Business Travel.

Often, these processes are handled in part by highly specialised outsourcing companies or by shared service centres carved out within the organisation itself. Delegating these kinds of processes allows any company to focus on its main activity (its so-called core business). When we delegate a process, we also delegate the controls assigned to it.

We begin our series with Procure to Pay, which is frequently the domain of outsourcing. The entire process runs from the moment someone in the company says “I need something” until the moment the supplier is paid.

The 5 main stages of the P2P cycle

  1. Purchase requisition – an employee reports a need to buy goods or a service
  2. Approval and ordering – the order is approved by managers and sent to the supplier
  3. Receipt of goods or services – the company receives the ordered goods or service and checks that it matches the order
  4. Invoice receipt – the supplier issues an invoice, which is verified against the order and the receipt
  5. Payment – the approved invoice is paid by the agreed due date

The 5 most important internal controls in the P2P area

It is hard to point unequivocally to the 5 most important internal controls for the P2P area, but for the purposes of this article, and drawing on my experience, I have selected the following 5 control areas:

1. Access control and segregation of duties (SOD)

As number 1, without a doubt: Access control and segregation of duties (SOD) – even when our P2P is a mess, or a construct we do not yet fully understand, we are exposed to many risks, from fictitious invoices and unauthorised payments to collusion between employees; I recommend ensuring a basic separation of duties.

The key principle is this: no single employee should have access to the entire purchasing and payment process. Responsibility should be divided among different employees and reviewed at least quarterly.

Control of system authorisations (e.g. in SAP or Oracle systems) rests on:

  • assigning roles consistent with the employee’s function;
  • blocking so-called conflicting roles (e.g. the “create supplier” role combined with “execute payment”);
  • access reviews – the periodic verification of who has access to what.

The access triangle in particular – purchasing, invoicing and payment – is a risky combination that should be segregated in every company

For more on SOD, see: New risks, a new SoD matrix – how does S/4HANA change the approach to SoD? | LinkedIn

2. Changes to supplier master data (Vendor Master Data)

Particular attention should be paid to changes in supplier master data (Vendor Master Data), banking details, and the initial verification of a supplier (adding a new supplier to the system).

In a world where we are attacked daily by fraud attempts targeting our bank accounts and by payment scams, special attention and control should be applied to changes to the bank accounts of existing suppliers and to the verification of new suppliers added to the database, in order to avoid fraud involving fictitious and dishonest suppliers.

3. Checking invoices without a purchase order (PO) and purchase authorisation

Checking invoices without a purchase order (PO – Purchase Order) and the authorisation of that type of purchase.

If we have no order, the invoice unfortunately cannot be part of the next control – the three “key” documents check – so such invoices should be examined closely to find the reason for this situation and to obtain approval.

In our control, working from the list of invoices without an order, we should look for the reasons behind such invoices, for example:

  • the supplier issued the invoice before the order was placed;
  • the purchase was below the threshold requiring a purchase order;
  • an emergency purchase.

There are certain warning signs indicating that the absence of an order was a deliberate circumvention of the process.

If there is no order, the invoice should go through an alternative approval path.

4. Verification of the three “key” documents (Three-Way Match)

Verification of the three “key” documents (Three-Way Match) – before we pay for an order, we need to check three things: whether order = goods receipt = invoice (PO – Purchase Order = GR – Goods Receipt = INV – Invoice).

All three elements must match one another (and where there is a discrepancy, it must fall within the agreed tolerance threshold – by value or by percentage, e.g. £10, 0.5%) for the payment to be approved. If discrepancies exceed the set tolerance thresholds, the payment is held until they are clarified and approved.

5. Payment approval

Payment approval – payment approval should be based on a predefined hierarchy. The principle here is clear: the higher the value of the payment or transfer, the higher the level of seniority within the organisation that should be required to approve it.

Automated and continuous controls monitoring (CCM)

In mature organisations, controls are often no longer based solely on manual checks or periodic (e.g. monthly) reviews, but on automated and continuous controls monitoring (Continuous Controls Monitoring – CCM). CCM monitors controls automatically and continuously – for example, it keeps watch over key SOD role conflicts, detects breaches of Three-Way Match tolerance thresholds and of payment approval thresholds, and flags changes to supplier bank details and invoices without an order. These tools are most often based on a dedicated system – see more in the article: Continuous Controls Monitoring (CCM) | LinkedIn

The list above is only the beginning of the internal control list and the foundation of P2P that organisations should address when building their own control list. This process, although often delegated to shared service centres, remains one of the areas most exposed to abuse in an organisation – fictitious suppliers, unauthorised payments, attempts to bypass the purchasing process.

What’s next in the series?

This article is only the beginning of our journey through the key finance and accounting processes. In the coming articles, we will take a closer look at:

  • Record to Report (R2R) – how to control the process of financial recording and reporting;
  • Order to Cash (O2C) – what risks lie in wait on the sales and receivables side;
  • Payroll and business travel – areas equally vulnerable to abuse, though often treated as an afterthought in discussions of internal control;
  • and other processes.

We invite you to follow the next parts of the series – together we will discover which top controls we need in our organisation.