Audit readiness: a self-assessment for CFOs

A self-assessment CFOs can run before a margin drift diagnostic: what AP records, contract files and invoice data need to be in place first.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Audit readiness: a self-assessment for CFOs

Margin drift is the gap between what a vendor contract says and what the invoice actually charges. Before a CFO commissions a diagnostic to find it, there is a narrower question worth answering first: is the finance function actually positioned to act on what a diagnostic finds.

Readiness is not a maturity score or a software checklist. It is whether contracts can be located, whether AP data can be pulled at the line-item level, and whether someone owns the fix once a finding is confirmed. This self-assessment walks through each of those in turn.

Executive Summary

Most diagnostics stall for the same reason: not because the audit work is hard, but because the underlying records are scattered. Contracts live in a shared drive nobody indexed. AP data exports at the invoice level, not the line level.

Nobody can say who owns a vendor relationship once the original signer has left. None of that is a criticism of the finance team; it is what happens when contract management and invoice processing grow up as separate functions with separate owners.

The mechanism behind this is straightforward. Contract compliance requires comparing a specific invoice line to a specific contract clause, and that comparison only works if both sides are retrievable in a comparable form. When they are not, an audit spends its early weeks reconstructing records instead of testing them, and a CFO evaluating fixed-scope timelines should know which is which before scoping starts.

What changes it is not a new system. It is naming, before the audit begins, where contracts live, how invoice data exports, and who signs off on a finding once it is confirmed. That is what this self-assessment is for: not to grade the finance function, but to surface the three or four gaps that would otherwise cost time mid-engagement.

1. How do you know if your finance team is ready for an audit?

Readiness comes down to three things: contracts that can be located and read, invoice data that exports at the line-item level rather than just the invoice total, and a named owner for each vendor relationship. If any of the three is missing, the audit's early weeks go to reconstruction instead of testing, which is time a fixed-scope engagement does not have to spare.

A team can be excellent at closing the books and still be unready for a contract compliance audit, because the two disciplines pull on different records. Month-end close reconciles totals. A drift audit needs the clause that set the rate, the invoice line that charged it, and a way to line the two up.

The test is practical, not aspirational. Can someone in your AP team pull every invoice from a single vendor for the last 12 to 18 months, broken into line items, in under a day? Can someone in procurement or legal produce the current signed contract for that same vendor, not a draft, not the prior version? If either answer is no, that is the actual readiness gap, not a lack of audit expertise.

This matters because the diagnostic itself runs on a fixed 2-to-4-week timeline. Time spent locating a contract or re-exporting AP data at a finer grain is time not spent testing invoices against terms.

2. What documentation should be on hand before an audit starts?

A ready finance function can produce four things without a scramble: the current signed contract for each major vendor, 12 to 18 months of invoice-level AP data, the vendor's rate card or price file if one exists separately from the contract, and any amendment or side letter that changed terms after signing. Missing any one of these narrows what an audit can test.

The contract itself is the obvious item, but it is rarely the whole file. Rate cards, surcharge schedules and volume-tier tables are frequently maintained as separate documents, sometimes as spreadsheets a vendor emails once a year and nobody re-files against the master agreement. An audit that only sees the signed MSA and not the current rate card will miss the exact place most drift accumulates, which is where the price file and the contract diverge over time.

A. Contract and amendment file

The signed base agreement plus every amendment, renewal and side letter that changed a rate, cap or rebate term after execution. A contract read in its original form, with a later rate change ignored, produces false findings in both directions.

B. Invoice-level AP export

Not a vendor summary. A line-item export showing quantity, rate, surcharge and total for each invoice over the audit period, in a format that can be matched to contract terms rather than just reconciled to a check total.

3. How well does your AP team match invoices against contracts today?

Three-way matching checks the invoice against the purchase order and the receipt of goods or services. It does not test whether a surcharge has expired, whether a volume tier has been crossed, or whether a labor rate matches the master agreement. Knowing which of those your current process actually covers, and which it does not, is a readiness question in itself.

Most AP systems run some form of matching before an invoice is approved, and that control genuinely catches a category of error: a quantity that does not match the receiving report, a price that was never authorized in the first place. It is a real control, and it is worth stating plainly what it was built to do.

What it was not built to do is read a contract clause. A fuel surcharge with a stated expiration date, a labor rate that steps down after a volume threshold, a rebate that accrues but is never invoiced back: none of these fail a three-way match, because the invoice matches the PO and the PO was cut at whatever rate the vendor billed. The match confirms internal consistency, not contract compliance.

A useful readiness exercise is naming, for your own AP process, exactly where the matching control stops and where a manual or periodic check would need to begin. That boundary is where a

4. Can your team name its highest-complexity vendor categories?

This is not about which category leaks the most, a question no dataset here can answer. It is whether your team can name, without guessing, which vendor categories carry the most contract complexity: tiered pricing, accessorial schedules, NTE caps, or rebate clauses. That list is what an audit should scope to first.

Complexity and dollar volume are not the same thing. A single large vendor on a flat-rate contract with no tiers, no surcharges and no rebate clause is low complexity even if it is your biggest AP line. A mid-sized staffing vendor with tiered labor rates, an NTE cap per statement of work, and a volume rebate that has to be reconciled quarterly is high complexity even if the spend is smaller.

  • Freight and 3PL: Accessorial and surcharge tables that sit outside the base rate and change independently of it.
  • Contract labor and staffing: Rate cards tied to role and tenure, plus volume rebates that accrue but are rarely reconciled against actual spend.
  • Maintenance and MSA work: Work orders that can drift from the original scope, and warranty work that gets billed as new.
  • IT and professional services: Statements of work with their own scope boundaries, separate from the master agreement that governs rate.

5. Who owns contract compliance once the audit ends?

A diagnostic produces a roadmap, not a standing control. Someone inside the company has to own re-checking rates, catching a surcharge that outlives its sunset date, and reconciling rebate accruals against what was actually invoiced. If no one is named for that role before the audit starts, the findings will repeat within a year.

This is the question self-assessments skip most often, because it is organizational rather than technical. A finding gets fixed once: the overbilled invoice is credited, the missed rebate is claimed. But the contract clause that produced the error is still sitting in the vendor file, and without an owner checking new invoices against it, the same clause produces the same drift again the next time the vendor changes its price file.

The owner does not need to be a new hire. In many finance teams it is the controller, or a category-specific owner in procurement, checking a defined set of vendors on a set schedule. What matters is that the role is named and the cadence is decided before the diagnostic delivers its roadmap, not after.

6. What does a self-assessment score actually tell you?

It tells you where an audit will spend its early time: reconstructing records or testing them. It does not predict what the audit will find, because no benchmark exists to size a finding before the invoices are actually checked line by line. Treat the assessment as a scoping tool, not a forecast.

It is tempting to turn this kind of checklist into a score out of ten and compare it to a benchmark. Resist that. There is no dataset here, or anywhere published, that maps a readiness score to an expected recovery, and a number presented as if there were would be invented rather than found.

What the assessment legitimately does is change the shape of the engagement. A team that can produce contracts, line-level AP data and a named vendor owner list on day one moves straight into invoice testing. A team missing two of those three spends the first stretch of the engagement assembling records, which is still useful work but is not the work the diagnostic was scoped to do.

The honest use of a self-assessment is to have that conversation with whoever scopes the diagnostic, before it starts, rather than discover the gap in week one.

For the wider pattern this sits inside, start with the margin drift guide. See also margin drift vs. legitimate price increases: how to tell them apart and accessorial charge audit: the surcharges nobody validates.

7. Frequently Asked Questions (People Also Ask)

How long does a readiness self-assessment take to complete?

It is a document-gathering exercise, not a formal audit, so most finance teams can complete it internally in a few days: pulling contract files, checking whether AP data exports at the line-item level, and confirming who currently owns each major vendor relationship.

Do we need special software to run this self-assessment?

No. It is a review of what records already exist and where, using whatever contract repository and AP system the company already runs. The point is to find gaps in access and ownership, not to install a new tool before the audit even starts.

What if we cannot locate the current signed contract for a vendor?

That itself is a finding worth recording. An audit can still test the invoice against the vendor's own rate card or prior contract version where available, but any gap in the contract file should be flagged and closed before or during the diagnostic rather than assumed away.

Does a low readiness score mean we should not run a diagnostic yet?

Not necessarily. A gap in documentation is common and can often be closed in the same window the diagnostic is being scoped. What matters is naming the gap up front so the engagement timeline accounts for it, rather than discovering it after the diagnostic has already started.

Is this self-assessment the same as an internal controls audit?

No. An internal controls audit tests whether financial reporting controls are operating as designed. This self-assessment is narrower: it checks whether the specific records a margin drift diagnostic needs, contracts, line-level invoices and vendor ownership, are accessible and current.

Who inside the company should complete this self-assessment?

Typically the controller or AP lead, working with whoever holds the contract repository, often procurement or legal. It is a cross-functional exercise because contracts and invoices are usually owned by different teams even though a diagnostic needs both together.

Can we use this checklist before switching AP automation systems?

Yes, and it is a reasonable time to run it. AP automation improves how new invoices are processed but does not on its own retrieve historical contract terms or line-item detail from prior periods, so the same readiness questions apply before a system change as before a diagnostic.

What happens if AP data only exports at the invoice total level?

A diagnostic can still start, but testing has to work backward from summary totals, which is slower and less precise than testing individual lines. Getting a line-item export configured, even for a handful of priority vendors, is one of the highest-value fixes a readiness assessment can surface.

Should the readiness assessment cover every vendor or just the largest ones?

Start with vendor categories that carry contract complexity, tiered pricing, surcharge schedules, NTE caps, or rebate clauses, rather than simply the largest dollar totals. A low-complexity flat-rate vendor needs little readiness work regardless of its spend size.

Does readiness assessment work apply to Finance Processes Managed Services engagements too?

The same underlying records, contracts, line-level invoice data, named vendor ownership, matter for ongoing AP and controller-function work as well, since a managed services engagement runs on the same source documents a diagnostic would need.

Executive Summary

Most diagnostics stall for the same reason: not because the audit work is hard, but because the underlying records are scattered. Contracts live in a shared drive nobody indexed. AP data exports at the invoice level, not the line level. Nobody can say who owns a vendor relationship once the original signer has left. None of that is a criticism of the finance team; it is what happens when contract management and invoice processing grow up as separate functions with separate owners. The mechanism behind this is straightforward. Contract compliance requires comparing a specific invoice line to a specific contract clause, and that comparison only works if both sides are retrievable in a comparable form. When they are not, an audit spends its early weeks reconstructing records instead of testing them, and a CFO evaluating [fixed-scope timelines](/guides/fixed-scope-vs-contingency-fee-recovery-audits-the-real-cost) should know which is which before scoping starts. What changes it is not a new system. It is naming, before the audit begins, where contracts live, how invoice data exports, and who signs off on a finding once it is confirmed. That is what this self-assessment is for: not to grade the finance function, but to surface the three or four gaps that would otherwise cost time mid-engagement.

1. How do you know if your finance team is ready for an audit?

Readiness comes down to three things: contracts that can be located and read, invoice data that exports at the line-item level rather than just the invoice total, and a named owner for each vendor relationship. If any of the three is missing, the audit's early weeks go to reconstruction instead of testing, which is time a fixed-scope engagement does not have to spare. A team can be excellent at closing the books and still be unready for a contract compliance audit, because the two disciplines pull on different records. Month-end close reconciles totals. A drift audit needs the clause that set the rate, the invoice line that charged it, and a way to line the two up. The test is practical, not aspirational. Can someone in your AP team pull every invoice from a single vendor for the last 12 to 18 months, broken into line items, in under a day? Can someone in procurement or legal produce the current signed contract for that same vendor, not a draft, not the prior version? If either answer is no, that is the actual readiness gap, not a lack of audit expertise. This matters because the diagnostic itself runs on a fixed 2-to-4-week timeline. Time spent locating a contract or re-exporting AP data at a finer grain is time not spent testing invoices against terms.

2. What documentation should be on hand before an audit starts?

A ready finance function can produce four things without a scramble: the current signed contract for each major vendor, 12 to 18 months of invoice-level AP data, the vendor's rate card or price file if one exists separately from the contract, and any amendment or side letter that changed terms after signing. Missing any one of these narrows what an audit can test. The contract itself is the obvious item, but it is rarely the whole file. Rate cards, surcharge schedules and volume-tier tables are frequently maintained as separate documents, sometimes as spreadsheets a vendor emails once a year and nobody re-files against the master agreement. An audit that only sees the signed MSA and not the current rate card will miss the exact place most drift accumulates, which is where the price file and the contract diverge over time. ### A. Contract and amendment file The signed base agreement plus every amendment, renewal and side letter that changed a rate, cap or rebate term after execution. A contract read in its original form, with a later rate change ignored, produces false findings in both directions. ### B. Invoice-level AP export Not a vendor summary. A line-item export showing quantity, rate, surcharge and total for each invoice over the audit period, in a format that can be matched to contract terms rather than just reconciled to a check total.

3. How well does your AP team match invoices against contracts today?

Three-way matching checks the invoice against the purchase order and the receipt of goods or services. It does not test whether a surcharge has expired, whether a volume tier has been crossed, or whether a labor rate matches the master agreement. Knowing which of those your current process actually covers, and which it does not, is a readiness question in itself. Most AP systems run some form of matching before an invoice is approved, and that control genuinely catches a category of error: a quantity that does not match the receiving report, a price that was never authorized in the first place. It is a real control, and it is worth stating plainly what it was built to do. What it was not built to do is read a contract clause. A fuel surcharge with a stated expiration date, a labor rate that steps down after a volume threshold, a rebate that accrues but is never invoiced back: none of these fail a three-way match, because the invoice matches the PO and the PO was cut at whatever rate the vendor billed. The match confirms internal consistency, not contract compliance. A useful readiness exercise is naming, for your own AP process, exactly where the matching control stops and where a manual or periodic check would need to begin. That boundary is where a

4. Can your team name its highest-complexity vendor categories?

This is not about which category leaks the most, a question no dataset here can answer. It is whether your team can name, without guessing, which vendor categories carry the most contract complexity: tiered pricing, accessorial schedules, NTE caps, or rebate clauses. That list is what an audit should scope to first. Complexity and dollar volume are not the same thing. A single large vendor on a flat-rate contract with no tiers, no surcharges and no rebate clause is low complexity even if it is your biggest AP line. A mid-sized staffing vendor with tiered labor rates, an NTE cap per statement of work, and a volume rebate that has to be reconciled quarterly is high complexity even if the spend is smaller. - Freight and 3PL: Accessorial and surcharge tables that sit outside the base rate and change independently of it. - Contract labor and staffing: Rate cards tied to role and tenure, plus volume rebates that accrue but are rarely reconciled against actual spend. - Maintenance and MSA work: Work orders that can drift from the original scope, and warranty work that gets billed as new. - IT and professional services: Statements of work with their own scope boundaries, separate from the master agreement that governs rate.

5. Who owns contract compliance once the audit ends?

A diagnostic produces a roadmap, not a standing control. Someone inside the company has to own re-checking rates, catching a surcharge that outlives its sunset date, and reconciling rebate accruals against what was actually invoiced. If no one is named for that role before the audit starts, the findings will repeat within a year. This is the question self-assessments skip most often, because it is organizational rather than technical. A finding gets fixed once: the overbilled invoice is credited, the missed rebate is claimed. But the contract clause that produced the error is still sitting in the vendor file, and without an owner checking new invoices against it, the same clause produces the same drift again the next time the vendor changes its price file. The owner does not need to be a new hire. In many finance teams it is the controller, or a category-specific owner in procurement, checking a defined set of vendors on a set schedule. What matters is that the role is named and the cadence is decided before the diagnostic delivers its roadmap, not after.

6. What does a self-assessment score actually tell you?

It tells you where an audit will spend its early time: reconstructing records or testing them. It does not predict what the audit will find, because no benchmark exists to size a finding before the invoices are actually checked line by line. Treat the assessment as a scoping tool, not a forecast. It is tempting to turn this kind of checklist into a score out of ten and compare it to a benchmark. Resist that. There is no dataset here, or anywhere published, that maps a readiness score to an expected recovery, and a number presented as if there were would be invented rather than found. What the assessment legitimately does is change the shape of the engagement. A team that can produce contracts, line-level AP data and a named vendor owner list on day one moves straight into invoice testing. A team missing two of those three spends the first stretch of the engagement assembling records, which is still useful work but is not the work the diagnostic was scoped to do. The honest use of a self-assessment is to have that conversation with whoever scopes the diagnostic, before it starts, rather than discover the gap in week one. For the wider pattern this sits inside, start with the [margin drift](/margin-drift-diagnostic) guide. See also [margin drift vs. legitimate price increases: how to tell them apart](/guides/margin-drift-vs-legitimate-price-increases-how-to-tell-them) and [accessorial charge audit: the surcharges nobody validates](/guides/accessorial-charge-audit-the-surcharges-nobody-validates).

Questions & Answers

How long does a readiness self-assessment take to complete?

It is a document-gathering exercise, not a formal audit, so most finance teams can complete it internally in a few days: pulling contract files, checking whether AP data exports at the line-item level, and confirming who currently owns each major vendor relationship.

Do we need special software to run this self-assessment?

No. It is a review of what records already exist and where, using whatever contract repository and AP system the company already runs. The point is to find gaps in access and ownership, not to install a new tool before the audit even starts.

What if we cannot locate the current signed contract for a vendor?

That itself is a finding worth recording. An audit can still test the invoice against the vendor's own rate card or prior contract version where available, but any gap in the contract file should be flagged and closed before or during the diagnostic rather than assumed away.

Does a low readiness score mean we should not run a diagnostic yet?

Not necessarily. A gap in documentation is common and can often be closed in the same window the diagnostic is being scoped. What matters is naming the gap up front so the engagement timeline accounts for it, rather than discovering it after the diagnostic has already started.

Is this self-assessment the same as an internal controls audit?

No. An internal controls audit tests whether financial reporting controls are operating as designed. This self-assessment is narrower: it checks whether the specific records a margin drift diagnostic needs, contracts, line-level invoices and vendor ownership, are accessible and current.

Margin Drift Resources