top of page

5 Questions to Assess Audit Readiness in Your NGO Procurement Team

  • Aug 6
  • 9 min read

An audit rarely fails because one document is missing. It fails when a procurement team cannot show a clear, consistent story: why a purchase was needed, how a supplier was selected, who approved it, what was received, and how payment was justified.


For NGOs, that story matters even more. Procurement files often face review from donors, internal auditors, external auditors, finance teams, and sometimes regulators. A clean file protects program delivery, donor confidence, and the people making procurement decisions under pressure.


This quick quiz helps identify whether an NGO procurement team is ready for an audit, or whether weak spots need attention before someone asks for a sample file.


Use it for a single project, one country office, or the full procurement function. The goal is not to catch people out. The goal is to find gaps early, while they are still easy to fix.


Wide-angle view of labeled relief supply boxes in a clean storeroom.
Audit readiness starts with procurement records that match real-world goods and services.

How to use this audit readiness quiz


For each question, choose the answer that best describes how procurement files usually look across the team. Do not score based on the best file in the folder. Score based on the files an auditor is most likely to find in a random sample.


Use this scoring:


Score

What it means

0

No clear evidence, or the process is mostly informal

1

Some evidence exists, but it is inconsistent or incomplete

2

Evidence is usually present, with a few gaps

3

Evidence is complete, clear, and easy to follow


At the end, total the score out of 15.


A strong result does not mean every file is perfect. It means the team can show control, consistency, and sound judgment across the procurement cycle.


1. Can each purchase be traced back to an approved need?


Audit-ready procurement starts before quotations, bids, or purchase orders. The first question is simple: can the team prove the purchase was needed and approved before the procurement process began?


Look for evidence such as:


  • Approved procurement plan

  • Purchase requisition

  • Budget holder approval

  • Donor-approved work plan or activity plan

  • Clear description of the goods, works, or services needed

  • Estimated value and funding source


A common audit weakness is a file that starts halfway through the process. It may contain supplier quotes and an invoice, but no proof that anyone approved the need in advance. That creates risk. The auditor may ask whether the purchase was planned, whether funds were available, and whether the requester had authority.


Score this question:


Score

Answer

0

Purchases often begin through verbal requests, messages, or informal instructions

1

Some files include requisitions or budget approval, but many are missing key details

2

Most files include an approved need, funding source, and basic specifications

3

Every file clearly links the purchase to an approved plan, budget, request, and authority level


A procurement file should answer one basic question without explanation from staff: why did this purchase happen?


If someone has to call the program team to reconstruct the reason, the file is not audit-ready yet.


2. Are procurement thresholds and approval rules followed consistently?


Most NGOs have procurement thresholds. Small purchases may require one quote. Higher-value purchases may require three quotes, a bid committee, sealed bids, or a formal tender. Donors may also set rules that are stricter than the NGO’s internal policy.


The audit question is not just whether a policy exists. The real question is whether the team applies the right method for the purchase value, donor, location, and risk level.


Check whether files show:


  • Estimated purchase value before sourcing

  • Correct procurement method based on thresholds

  • Required approvals at each stage

  • Bid waiver or sole-source justification, when used

  • Donor approval, where required

  • Clear separation between requester, buyer, evaluator, approver, and receiver


Procurement teams often get into trouble when thresholds are treated casually. For example, a purchase just below a competitive bidding threshold may raise questions if similar purchases were split into smaller transactions. Even when there is no bad intent, poor documentation can make the decision look weak.


Score this question:


Score

Answer

0

Staff are unsure which thresholds apply, or rules change from file to file

1

Thresholds are known, but exceptions are not always justified or approved

2

Most files follow the right method, with some missing explanations

3

Files clearly show the threshold, method, approvals, and any justified exception


Good audit readiness means a reviewer can see that the team followed the rule that applied at the time.


Close-up view of color-coded procurement folders in a field storage cabinet.
A well-organized file trail helps explain each procurement decision.

3. Is supplier selection documented well enough to defend the decision?


Supplier selection is often the most scrutinized part of NGO procurement. Auditors want to know whether the process was fair, transparent, and based on clear criteria.


A file should show more than the name of the winning supplier. It should show how the team reached the decision.


Depending on the procurement method, strong evidence may include:


  • Supplier invitation list

  • Requests for quotation or tender documents

  • Quotes, bids, or proposals received

  • Bid opening record, if required

  • Evaluation criteria

  • Technical assessment

  • Price comparison

  • Evaluation minutes

  • Conflict of interest declarations

  • Award recommendation

  • Approval of the selected supplier


The key is not always choosing the lowest price. In many NGO procurements, the best decision may depend on delivery time, quality, technical compliance, warranty, location, past performance, or donor conditions. The file should explain that reasoning.


Weak files often include a simple comparison table with three prices and no explanation. That may be enough for a low-value purchase, depending on policy. For higher-value or higher-risk purchases, it is rarely enough.


Score this question:


Score

Answer

0

The file does not show how the supplier was chosen

1

Quotes or bids are attached, but the evaluation is thin or unclear

2

Selection is documented, but some criteria, minutes, or approvals are missing

3

The file clearly shows the process, criteria, comparison, recommendation, and approval


A strong file lets a new reviewer understand the decision without asking the procurement officer to explain it.


4. Can the team show that supplier risk was checked before award?


Audit readiness is not only about price and paperwork. NGOs also need to manage supplier risk. That includes fraud risk, conflict of interest, sanctions exposure, poor performance, and reputational harm.


The level of due diligence should match the risk. A one-time low-value purchase from a local supplier may need basic checks. A high-value construction contract, cash-based service provider, logistics provider, or consultant may need deeper review.


Look for records such as:


  • Supplier registration form

  • Tax or legal registration documents, where applicable

  • Bank account verification

  • Reference checks or past performance notes

  • Conflict of interest declarations

  • Sanctions or restricted party screening, where required

  • Beneficial ownership information, when relevant

  • Anti-fraud, child safeguarding, or code of conduct acceptance, where required by policy

  • Vendor master data approval


This area can be uncomfortable because teams may see it as extra administration. Yet supplier due diligence protects the organization and the people signing the award. It also shows donors that procurement decisions are not based only on speed.


Score this question:


Score

Answer

0

Supplier checks are rarely documented

1

Basic supplier forms exist, but checks are incomplete or done after award

2

Most supplier files include required checks, with a few timing or evidence gaps

3

Supplier risk checks are completed, documented, approved, and matched to the level of risk


The strongest teams do not treat due diligence as a separate exercise. They build it into sourcing and award decisions.


Eye-level view of sealed envelopes beside a locked metal tender box.
Fair supplier selection depends on evidence that bids were handled with care.

5. Does the payment file prove that goods or services were received as agreed?


The final question follows the money. Before payment, the file should prove that the NGO received what it ordered, at the agreed quality, quantity, price, and time.


Auditors often test whether the procurement, receiving, and payment records match. If they do not, the file may raise concerns even when the purchase was legitimate.


A complete file may include:


  • Approved purchase order or contract

  • Delivery note

  • Goods received note

  • Inspection or acceptance report

  • Service completion certificate

  • Timesheets or deliverables for consultants

  • Invoice

  • Payment request

  • Proof of payment

  • Three-way match between purchase order, receipt, and invoice

  • Asset registration, where applicable

  • Stock record update, where applicable


The most common issue is missing receiving evidence. An invoice alone proves that a supplier requested payment. It does not prove that the NGO received the goods or services.


For services, the risk can be even higher. A training consultant, transport provider, software vendor, or construction contractor may not leave a simple delivery note. The team needs other proof, such as approved deliverables, attendance sheets, completion reports, or signed acceptance.


Score this question:


Score

Answer

0

Payments are often made without clear receiving or acceptance evidence

1

Some files include delivery or completion proof, but matching is inconsistent

2

Most payments are supported by purchase, receipt, invoice, and approval records

3

Every payment file clearly proves order, receipt, acceptance, invoice review, and payment approval


This is where procurement and finance need to work as one chain. If procurement files stop at supplier selection and finance files hold the payment evidence, the audit trail may still feel fragmented. A reviewer should be able to connect both sides quickly.


What your score says about audit readiness


Add the five scores together.


Total score

Readiness level

What it means

0 to 5

High risk

The team may struggle to defend procurement decisions during an audit

6 to 10

Partly ready

Key controls exist, but gaps could lead to findings

11 to 13

Mostly ready

The team has a solid base, but should clean up weak areas before review

14 to 15

Audit ready

Files are likely clear, complete, and easy to test


The score is only a guide. One critical weakness can matter more than the total. For example, a team might score well overall but still face a serious issue if supplier conflicts of interest are never declared or if high-value awards skip required approvals.


Use the result to start a practical conversation, not to assign blame.


Overhead view of a clipboard checklist beside packaged medical supply cartons.
A short checklist can reveal audit gaps before the formal review begins.

How to act on the result


A quiz only helps if it leads to better files. Once the team has a score, pick the weakest question and fix that area first.


If the lowest score is on approved need, start with requisitions and budget checks. Make sure staff know that procurement should not begin until the request is documented and approved.


If the lowest score is on thresholds, create a one-page threshold guide. Keep it simple. Show the purchase value, method, required documents, and approval level. If donors have stricter rules, flag them clearly.


If the lowest score is on supplier selection, improve evaluation records. A good comparison sheet should show the criteria, the bids received, the reason for the recommendation, and the approval.


If the lowest score is on supplier risk, review vendor registration and due diligence. Build a clear rule for what checks apply to low, medium, and high-risk suppliers.


If the lowest score is on receiving and payment, work with finance and programs. Make sure every invoice can be matched to an order and proof of receipt or service completion.


A useful next step is to test five closed procurement files from the last three to six months. Choose different purchase types, such as supplies, services, logistics, consultancy, and construction or maintenance. Score each one. Patterns will appear quickly.


What an audit-ready procurement file looks like


An audit-ready file does not need to be fancy. It needs to be complete, organized, and easy to follow.


A strong file usually tells the story in this order:


  1. The need was identified and approved.

  2. The budget and donor rules were checked.

  3. The right procurement method was selected.

  4. Suppliers were invited or sourced fairly.

  5. Bids or quotes were received and evaluated.

  6. The supplier was selected for documented reasons.

  7. Required approvals were obtained.

  8. The order or contract was issued.

  9. Goods or services were received and accepted.

10. The invoice was checked and paid.

11. Records were filed so someone else can review them later.


That sequence matters. When documents appear out of order, or approvals come after the fact, the file may raise questions. Even if the purchase was valid, late paperwork weakens the audit trail.


The best procurement teams make audit readiness part of routine work. They do not wait until an audit notice arrives. They use checklists, file naming rules, clear approval routes, and periodic self-reviews.


Common red flags to watch for


Some findings repeat across procurement audits because they point to weak control. Watch for these signs:


  • Purchase orders dated after invoices

  • Missing requisitions

  • Quotes from related suppliers with similar formatting

  • No evidence of bid opening or evaluation

  • Repeated awards to the same supplier without explanation

  • Split purchases just below approval thresholds

  • Sole-source decisions with weak justification

  • Missing conflict of interest declarations

  • Delivery notes not signed or dated

  • Payment made before acceptance

  • Different supplier names across quote, invoice, and bank records


One red flag does not always mean misconduct. It does mean the file needs closer review. The team should resolve the issue before an auditor selects it.


Build readiness into daily procurement work


Audit readiness improves when the process is simple enough for busy teams to follow. A long policy that no one uses will not protect the organization. A clear process, backed by training and routine checks, will.


Practical habits help:


  • Use a standard file checklist for every procurement method.

  • Keep donor rules attached or linked to project files.

  • Record exceptions when they happen, not weeks later.

  • Require conflict of interest declarations for evaluations.

  • Match purchase order, receipt, and invoice before payment.

  • Review a small sample of files each month.

  • Give feedback to requesters, not only procurement staff.


This matters because procurement does not work alone. Program teams define the need. Finance confirms budget and payment. Logistics may receive goods. Management approves awards. Audit readiness depends on the full chain.


The five questions in this quiz give that chain a shared language. If every team can answer them with evidence, the organization is in a stronger position.


A good procurement file should speak for itself. When it does, audits become less stressful, decisions are easier to defend, and donor-funded work can keep moving with confidence.


Comments


bottom of page