Start with three fields most apps already expose: category, requester department, and cycle time from requisition to PO. Plot density, not drama. A category that represents 4% of spend but 22% of after-the-fact approvals deserves ink before any random draw.
Score without false precision
Use a 1–3 scale for policy sensitivity, vendor concentration, and historical exception rate. Multiply only if your controller accepts the fiction of a composite; many Korea desks prefer a simple heat table so debates stay transparent.
Hand the map to sampling
Once scored, decide which strata get judgmental oversampling. Document that choice in the same log you will later attach to the workpaper set. In Procurement Audit Workbench we treat this map as Module 02’s primary deliverable — unfinished maps mean sampling week starts late on purpose.