# Documents you need to audit IT/pro services

> A checklist of the contracts, SOWs, rate schedules and time records an IT and professional services invoice audit actually requires, and why each matters.

Source: https://valuexpa.com/insights/what-documents-do-you-need-to-audit-it-and-professional
Publisher: ValueXPA (https://valuexpa.com)
Updated: 2026-09-04

---

Margin drift is the gap between what a vendor contract says and what the invoice actually charges. An IT and professional services audit lives or dies on whether you can put the actual governing document in front of an actual invoice line, not on how carefully anyone reads the invoice alone.

Most of the documents below already exist somewhere in your organization. The work is collecting them into one place before you start, because an audit that begins with "we'll find the SOW later" stalls on line one.

## Executive Summary

An IT and professional services audit needs five document types before a single invoice gets reviewed: the master service agreement, every statement of work under it, the rate card or labor category schedule, time and resource tracking records, and the change order log. Without all five, a reviewer can flag that a line looks wrong but cannot prove it, and an unproven finding does not recover money.

The mechanism that causes drift here is not fraud. It is that contracts, SOWs and invoices get drafted and paid by different people at different times, and nobody is assigned to reconcile the three against each other. A rate negotiated in the master agreement gets superseded informally inside a SOW. A SOW's fixed scope gets extended by email instead of a change order. The invoice reflects whichever version the vendor's billing system last saw, and it is rarely the version you signed.

What changes it is treating the document set as a prerequisite of the audit rather than a byproduct of it. Assemble the master agreement, the SOWs, the rate schedule, the time records and the change log first, index them against each other by vendor and engagement, and only then start pulling invoices against that index.

## 1. What does the master service agreement establish for the audit?

**The master service agreement sets the terms that apply across every engagement with a vendor: payment terms, base labor categories and rates, expense reimbursement rules, and any volume or tenure discounts. It is the document a reviewer checks first, because a rate or term that conflicts with a SOW is only a conflict once you know what the MSA actually says.**

Many IT vendors operate under an MSA signed years earlier, sometimes by a different buyer than the one now approving invoices. The rates and terms in it do not expire just because nobody has looked at them recently.

Pull the current, fully executed MSA, not a draft or a renewal email referencing it. Confirm the effective dates and any amendments, because an MSA amended in year two changes what every SOW signed after that point should reflect.

Without the MSA in hand, a reviewer has no baseline for labor rates and no basis to challenge a rate that has crept upward invoice over invoice. See how labor rate deviations against master service agreements typically surface once the baseline is established.

## 2. Why does every SOW matter, not just the current one?

**Each statement of work defines the specific scope, deliverables, staffing plan and price for one engagement, and it can modify MSA terms for that engagement alone. An audit needs every SOW active during the invoice period under review, including ones that have technically expired but are still being invoiced against, because that mismatch is itself a finding.**

A vendor relationship with an IT provider often runs several SOWs at once: one for a platform migration, another for ongoing support, a third for a discrete project. Invoices frequently reference a SOW number without specifying which deliverable or phase the hours apply to.

Collect the full set, not a sample. An audit that reviews only the largest SOW will miss drift sitting in a smaller, easily overlooked one.

Check each SOW's term dates against the invoice dates being billed. Work invoiced after a SOW's stated end date, with no renewal or extension on file, is [scope creep in professional services SOWs](/guides/scope-creep-in-professional-services-sows) until proven otherwise.

## 3. What rate documentation do you need beyond the MSA?

**A rate card or labor category schedule lists the approved billing rate for each role: architect, project manager, developer, analyst. It may live inside the MSA, as a SOW exhibit, or as a standalone document updated periodically. The audit needs whichever version was in force on the date of service, not the current one.**

Rate cards change. A vendor renegotiates rates periodically, or a specific SOW carves out a project-specific rate that differs from the standing schedule. If the reviewer applies today's rate card to an older invoice, every comparison is wrong regardless of how carefully it was done.

Request a dated history of rate cards, not just the current file. Match each invoice period to the rate schedule that was actually in effect.

Where a resource is billed at a title or level not listed on any approved schedule, that line has no contractual basis at all, which is a distinct finding from a simple rate mismatch.

### A. Standing rate cards

A standing rate card applies across all SOWs under an MSA unless a specific SOW overrides it. It typically lists a rate range or a fixed rate per labor category, sometimes with a location or seniority modifier.

### B. SOW-specific rates

Some SOWs negotiate a rate exhibit unique to that engagement, often lower than the standing card in exchange for volume or commitment. When both exist, the SOW-specific rate governs for that engagement only.

## 4. What time and resource records are needed to check hours billed?

**Time tracking records, whether timesheets, a vendor portal export, or resource utilization reports, show who worked, on what task, for how long. The audit compares these against invoiced hours by resource and by week, because an approved timesheet only proves hours were logged, not that the invoice matches them line for line. Both records need to sit side by side before a single dollar is confirmed correct.**

Timesheet approval and invoice generation frequently happen in different systems that do not talk to each other. A project manager approves hours in a vendor portal; accounts payable pays whatever total appears on a separate PDF invoice.

Request the underlying time detail, not just the approved summary total. A summary total can mask hours shifted between resources or between billing periods.

Where the invoice groups hours differently than the time records do, by role instead of by named resource for example, ask for the mapping. Rate card enforcement: why approved timesheets still produce wrong invoices covers the specific failure mode this comparison exposes.

## 5. Why do you need a change order log separate from the SOW?

**A change order log tracks every formal modification to a SOW's scope, price or timeline after signing. The audit needs this log to distinguish billed work that was properly authorized from billed work that expanded past the original agreement without a documented approval, which is the gap between contract and invoice this document closes.**

IT and professional services engagements change scope often, and legitimately. The failure is not that scope changes; it is that the change gets approved verbally or by email and never converted into a signed change order, while the invoice bills for it anyway.

Ask for a complete change order log per SOW, cross-referenced by date and dollar value. Compare it against the original SOW's price and scope to see the delta.

Any invoiced amount above the original SOW value with no corresponding change order is an off-contract charge until someone produces the authorization. Off-contract resources: people billed outside the agreement describes the parallel pattern on staffing, and the same document gap drives both.

## 6. How do you organize these documents before reviewing invoices?

**Build an index that maps every vendor to its MSA, active SOWs, applicable rate schedule and change order log, each with effective dates. Only after that index exists should invoices be pulled and matched line by line, because reviewing invoices against an incomplete document set produces findings that cannot survive a vendor's first objection.**

The index does not need to be elaborate. A spreadsheet with one row per SOW, columns for MSA reference, term dates, rate schedule version and change order status is enough to start.

Gaps in the index are themselves useful. A SOW with no rate exhibit on file, or a vendor with no MSA at all despite years of invoices, tells you where to look first.

For the full walk-through of what happens once the document set is assembled, see how do you audit IT and professional services invoices, and for context on why this category resists the invoice-only review that works elsewhere, see why are IT and professional services invoices so hard to check.

For the wider pattern this sits inside, start with the margin drift guide. See also accessorial charge audit: the surcharges nobody validates and rate card enforcement: why approved timesheets still produce wrong invoices.

For the wider pattern this sits inside, start with the [margin drift](/guides/indirect-spend-audit-categories) guide. See also [accessorial charge audit: the surcharges nobody validates](/guides/accessorial-charge-audit-the-surcharges-nobody-validates) and [rate card enforcement: why approved timesheets still produce wrong invoices](/guides/rate-card-enforcement-why-approved-timesheets-still-produce).

## 7. Frequently Asked Questions (People Also Ask)

### Do we need the MSA if all our work is under one SOW?

Yes. The MSA sets baseline terms, payment terms, and often the labor rate schedule the SOW references rather than restates. Without it, a reviewer cannot confirm whether a SOW rate is a negotiated exception or simply what the vendor decided to bill.

### What if a SOW was never signed, only agreed by email?

Treat the email thread as the governing document and flag the gap. An unsigned SOW is still a weaker basis for a finding than a signed one, so note it separately and prioritize getting it formalized before disputing charges under it.

### Can we audit without vendor portal access to time records?

You can start with invoice-level detail, but resource-level findings need the underlying time data. Request timesheet exports or portal access directly from the vendor as part of the audit scope, not after a discrepancy is already suspected.

### How far back should we pull SOWs and change orders?

Pull every SOW and change order active during the invoice period under review, plus anything referenced by an invoice still being paid, even if the SOW itself has expired.

### What counts as proof a change order was approved?

A signed change order document, or at minimum written approval from someone with contractual authority, referencing the specific scope, price and timeline change. A verbal go-ahead or an email confirming receipt of work is not the same as an approval record.

### Who inside the company usually holds these documents?

Procurement or legal typically holds the MSA and signed SOWs. Project managers usually hold time records and informal scope changes. Accounts payable holds invoices. None of these groups routinely shares with the others, which is why the documents need to be assembled centrally before review starts.

### What if the rate card contradicts the MSA?

Check the effective dates and the document hierarchy stated in the MSA itself. Most MSAs specify which document governs in a conflict; if it does not, treat the more specific and more recent document as controlling and flag the ambiguity as a contract gap.

### Should we request documents from the vendor or find them internally?

Start internally with procurement, legal and the project owner. Request from the vendor only for gaps you cannot fill internally, since a vendor-supplied copy of a document you signed is a weaker record than your own file.

### Is contract complexity quietly draining your operating margin?

A small systematic drift between your negotiated contracts and your actual vendor billing compounds quietly across a year of invoices. Stop guessing at your exposure and run a targeted audit.

**[Take the Free Screener → https://valuexpa.com/margin-drift-screener](https://valuexpa.com/margin-drift-screener)**

## Executive Summary

An IT and professional services audit needs five document types before a single invoice gets reviewed: the master service agreement, every statement of work under it, the rate card or labor category schedule, time and resource tracking records, and the change order log. Without all five, a reviewer can flag that a line looks wrong but cannot prove it, and an unproven finding does not recover money. The mechanism that causes drift here is not fraud. It is that contracts, SOWs and invoices get drafted and paid by different people at different times, and nobody is assigned to reconcile the three against each other. A rate negotiated in the master agreement gets superseded informally inside a SOW. A SOW's fixed scope gets extended by email instead of a change order. The invoice reflects whichever version the vendor's billing system last saw, and it is rarely the version you signed. What changes it is treating the document set as a prerequisite of the audit rather than a byproduct of it. Assemble the master agreement, the SOWs, the rate schedule, the time records and the change log first, index them against each other by vendor and engagement, and only then start pulling invoices against that index.

## 1. What does the master service agreement establish for the audit?

The master service agreement sets the terms that apply across every engagement with a vendor: payment terms, base labor categories and rates, expense reimbursement rules, and any volume or tenure discounts. It is the document a reviewer checks first, because a rate or term that conflicts with a SOW is only a conflict once you know what the MSA actually says. Many IT vendors operate under an MSA signed years earlier, sometimes by a different buyer than the one now approving invoices. The rates and terms in it do not expire just because nobody has looked at them recently. Pull the current, fully executed MSA, not a draft or a renewal email referencing it. Confirm the effective dates and any amendments, because an MSA amended in year two changes what every SOW signed after that point should reflect. Without the MSA in hand, a reviewer has no baseline for labor rates and no basis to challenge a rate that has crept upward invoice over invoice. See how labor rate deviations against master service agreements typically surface once the baseline is established.

## 2. Why does every SOW matter, not just the current one?

Each statement of work defines the specific scope, deliverables, staffing plan and price for one engagement, and it can modify MSA terms for that engagement alone. An audit needs every SOW active during the invoice period under review, including ones that have technically expired but are still being invoiced against, because that mismatch is itself a finding. A vendor relationship with an IT provider often runs several SOWs at once: one for a platform migration, another for ongoing support, a third for a discrete project. Invoices frequently reference a SOW number without specifying which deliverable or phase the hours apply to. Collect the full set, not a sample. An audit that reviews only the largest SOW will miss drift sitting in a smaller, easily overlooked one. Check each SOW's term dates against the invoice dates being billed. Work invoiced after a SOW's stated end date, with no renewal or extension on file, is [scope creep in professional services SOWs](/guides/scope-creep-in-professional-services-sows) until proven otherwise.

## 3. What rate documentation do you need beyond the MSA?

A rate card or labor category schedule lists the approved billing rate for each role: architect, project manager, developer, analyst. It may live inside the MSA, as a SOW exhibit, or as a standalone document updated periodically. The audit needs whichever version was in force on the date of service, not the current one. Rate cards change. A vendor renegotiates rates periodically, or a specific SOW carves out a project-specific rate that differs from the standing schedule. If the reviewer applies today's rate card to an older invoice, every comparison is wrong regardless of how carefully it was done. Request a dated history of rate cards, not just the current file. Match each invoice period to the rate schedule that was actually in effect. Where a resource is billed at a title or level not listed on any approved schedule, that line has no contractual basis at all, which is a distinct finding from a simple rate mismatch. ### A. Standing rate cards A standing rate card applies across all SOWs under an MSA unless a specific SOW overrides it. It typically lists a rate range or a fixed rate per labor category, sometimes with a location or seniority modifier. ### B. SOW-specific rates Some SOWs negotiate a rate exhibit unique to that engagement, often lower than the standing card in exchange for volume or commitment. When both exist, the SOW-specific rate governs for that engagement only.

## 4. What time and resource records are needed to check hours billed?

Time tracking records, whether timesheets, a vendor portal export, or resource utilization reports, show who worked, on what task, for how long. The audit compares these against invoiced hours by resource and by week, because an approved timesheet only proves hours were logged, not that the invoice matches them line for line. Both records need to sit side by side before a single dollar is confirmed correct. Timesheet approval and invoice generation frequently happen in different systems that do not talk to each other. A project manager approves hours in a vendor portal; accounts payable pays whatever total appears on a separate PDF invoice. Request the underlying time detail, not just the approved summary total. A summary total can mask hours shifted between resources or between billing periods. Where the invoice groups hours differently than the time records do, by role instead of by named resource for example, ask for the mapping. Rate card enforcement: why approved timesheets still produce wrong invoices covers the specific failure mode this comparison exposes.

## 5. Why do you need a change order log separate from the SOW?

A change order log tracks every formal modification to a SOW's scope, price or timeline after signing. The audit needs this log to distinguish billed work that was properly authorized from billed work that expanded past the original agreement without a documented approval, which is the gap between contract and invoice this document closes. IT and professional services engagements change scope often, and legitimately. The failure is not that scope changes; it is that the change gets approved verbally or by email and never converted into a signed change order, while the invoice bills for it anyway. Ask for a complete change order log per SOW, cross-referenced by date and dollar value. Compare it against the original SOW's price and scope to see the delta. Any invoiced amount above the original SOW value with no corresponding change order is an off-contract charge until someone produces the authorization. Off-contract resources: people billed outside the agreement describes the parallel pattern on staffing, and the same document gap drives both.

## 6. How do you organize these documents before reviewing invoices?

Build an index that maps every vendor to its MSA, active SOWs, applicable rate schedule and change order log, each with effective dates. Only after that index exists should invoices be pulled and matched line by line, because reviewing invoices against an incomplete document set produces findings that cannot survive a vendor's first objection. The index does not need to be elaborate. A spreadsheet with one row per SOW, columns for MSA reference, term dates, rate schedule version and change order status is enough to start. Gaps in the index are themselves useful. A SOW with no rate exhibit on file, or a vendor with no MSA at all despite years of invoices, tells you where to look first. For the full walk-through of what happens once the document set is assembled, see how do you audit IT and professional services invoices, and for context on why this category resists the invoice-only review that works elsewhere, see why are IT and professional services invoices so hard to check. For the wider pattern this sits inside, start with the margin drift guide. See also accessorial charge audit: the surcharges nobody validates and rate card enforcement: why approved timesheets still produce wrong invoices. For the wider pattern this sits inside, start with the [margin drift](/guides/indirect-spend-audit-categories) guide. See also [accessorial charge audit: the surcharges nobody validates](/guides/accessorial-charge-audit-the-surcharges-nobody-validates) and [rate card enforcement: why approved timesheets still produce wrong invoices](/guides/rate-card-enforcement-why-approved-timesheets-still-produce).

## Common questions

### Do we need the MSA if all our work is under one SOW?

Yes. The MSA sets baseline terms, payment terms, and often the labor rate schedule the SOW references rather than restates. Without it, a reviewer cannot confirm whether a SOW rate is a negotiated exception or simply what the vendor decided to bill.

### What if a SOW was never signed, only agreed by email?

Treat the email thread as the governing document and flag the gap. An unsigned SOW is still a weaker basis for a finding than a signed one, so note it separately and prioritize getting it formalized before disputing charges under it.

### Can we audit without vendor portal access to time records?

You can start with invoice-level detail, but resource-level findings need the underlying time data. Request timesheet exports or portal access directly from the vendor as part of the audit scope, not after a discrepancy is already suspected.

### How far back should we pull SOWs and change orders?

Pull every SOW and change order active during the invoice period under review, plus anything referenced by an invoice still being paid, even if the SOW itself has expired.

### What counts as proof a change order was approved?

A signed change order document, or at minimum written approval from someone with contractual authority, referencing the specific scope, price and timeline change. A verbal go-ahead or an email confirming receipt of work is not the same as an approval record.

---

ValueXPA runs a fixed-scope Margin Drift Diagnostic that validates every service vendor invoice against contract terms, for $100M+ US industrial manufacturers and distributors. Two to four weeks. The client retains 100% of recoveries. https://valuexpa.com/contact-us
