Purchase order and spend approval
Uncontrolled spend rarely starts with fraud. It starts with someone ordering something urgently, promising to raise the paperwork later, and that becoming normal. Once retrospective orders are routine, budget holders lose visibility and the invoice-approval control downstream has nothing to match against.
- 1
Requester raises a purchase requisition stating what, why, the estimated cost, and the budget line it comes from.
Requester
The budget line matters. A request with no budget line cannot be approved by anyone accountable for it, so it ends up approved by whoever is nearest.
- 2
Requester confirms whether the goods or services have already been ordered or received.
Requester
Ask this explicitly rather than assuming. Retrospective orders are common and pretending otherwise means they never get counted.
Not yet ordered: go to step 3
Already ordered or received: go to step 10
- 3
Requester checks whether an approved supplier already exists for this category.
Requester
Approved supplier exists: go to step 5
New supplier needed: go to step 4
- 4
Finance Lead completes new-supplier checks before any commitment: legal entity, bank details verified independently, and tax or registration status.
Finance Lead
Verify bank details by phoning a number you already hold, never one supplied in the email or the invoice. This is the single most exploited step in procurement.
Supplier approved: go to step 5
Rejected: go to step 11
- 5
Requester checks the value against the competitive quote threshold.
Requester
Below threshold: go to step 7
At or above threshold: go to step 6
- 6
Requester obtains the required number of quotes, or documents why a single source is justified.
Requester
A written single-source justification is a legitimate outcome. An undocumented one is the finding.
Quotes obtained: go to step 7
Single source justified in writing: go to step 7
- 7
Budget Holder reviews the requisition against remaining budget and approves or rejects it in the system.
Budget Holder
In the system, not by replying to a message. An approval that exists only in a chat thread cannot be evidenced.
Approved: go to step 8
Rejected: go to step 11
- 8
Finance Lead applies the second approval where the value exceeds the escalation threshold, and records it.
Finance Lead
Two approvers above a stated value, and the same person cannot provide both. Set the value in writing.
Approved or not required: go to step 9
- 9
Finance Lead issues the purchase order to the supplier and records the PO number against the requisition.
Finance Lead
The PO number is what makes the three-way match possible when the invoice arrives. Without it, invoice approval has nothing to check against.
PO issued: the procedure ends
- 10
Finance Lead records the retrospective order, notifies the Budget Holder, and raises a PO to cover the committed spend.
Finance Lead
Record it as retrospective rather than backdating it. A backdated PO destroys the only signal that the control is being bypassed, and the pattern is what needs fixing.
Recorded and covered: go to step 7
- 11
Requester is informed of the rejection with the reason, and the requisition is closed.
Requester
Record the reason. A rejected request resubmitted through a different approver is a pattern worth being able to see.
Closed: the procedure ends
Change these before you use it
- Set your competitive quote threshold in step 5 and your second-approval threshold in step 8, both in writing.
- Define how many quotes count as competitive for your business, since "the required number" is not followable.
- Name your actual requisition system. If there is not one, decide the single channel and name it, or requests will arrive by chat.
- Add category-specific rules if some spend needs extra approval, for example anything touching customer data or committing you beyond twelve months.
- Connect step 9 to your invoice approval procedure so the PO number is the key both use.
This is a starting point, not compliance advice. It is written to be adapted, and a procedure that touches access, money, or customer data needs to match how your business actually operates and whatever rules apply to you. Use it as a first draft to edit, not a policy to adopt.
Make it yours in a couple of minutes
Rather than retyping this and editing it, describe your own version of the process out loud or click through it once, and get a first draft with your actual steps, roles, and systems in it. No account needed to see the result.
No account neededNo credit cardSee the whole SOP before you sign up