Procurement processes are highly vulnerable to internal and external fraud due to the significant volume of financial capital passing through corporate purchasing lines. Internal auditors focus on identifying collusive agreements, shell vendor creations, and bidding manipulations.
[Bidding Preparation Phase] ──► [Submission Selection Phase] ──► [Contract Execution Phase]
• Bid Rigging Schemes • Phantom Shell Vendors • Duplicate Invoice Entry
• Leaking Spec Criteria • Tailored Requirements • Product Substitution
Procurement fraud schemes generally map across three operational phases:
- The Bidding Preparation Phase: Involves schemes like Bid Rigging, where a corrupted procurement employee colludes with external contractors to leak competitor pricing data or intentionally tailor tender specification criteria to favor a specific vendor, restricting open market competition.
- The Submission Selection Phase: Involves the creation of Phantom Shell Vendors. Employees with database write privileges set up fake supplier profiles inside the vendor master directory and route authorized corporate approvals to bank accounts they control.
- The Contract Execution Phase: Involves Product Substitution (billing the organization for premium materials while delivering sub-standard parts) or duplicate invoicing, where multiple identical invoices are routed through separate departments to collect double payments for a single service.
Internal audit teams mitigate these risks by executing automated cross-matching scripts that compare employee HR records (such as home addresses, phone numbers, and bank routing details) directly against the vendor master database to flag matching profiles.