Accounts payable audit: process, checklist and controls

What an AP audit is, how internal, external and recovery audits differ, the audit process step by step, and a checklist you can run between audits.

An accounts payable audit is a review of the invoices, approvals, vendor records and payments that make up your payables, to confirm that each payment was owed, approved, recorded in the right period and paid once to the right vendor. It can be run by your own team, by external auditors, or by a recovery audit firm.

The word “audit” covers several different jobs, and they answer different questions. This guide explains the three common types, walks through the process, and ends with a checklist and a set of controls you can keep running between formal audits.

What is an AP audit?

An AP audit tests whether your payables process does what it is supposed to do. In practice that means pulling a sample (or the full population) of invoices and payments and tracing each one back to its evidence: a purchase order or contract, proof that goods or services were received, an approval by someone with authority, and a vendor record that is legitimate and current.

Auditors look at two things at once. The first is the balances: is the accounts payable figure on the balance sheet complete and accurate at period end? The second is the process: are the controls around vendor setup, invoice approval and payment release designed well, and do people follow them?

For a small or mid-sized company, the most useful output is usually a short list of specific problems (a duplicate payment here, an inactive vendor with a changed bank account there) plus a few control fixes that stop the same issue from coming back.

Internal audit, external audit and recovery audit: what is the difference?

All three look at payables, but they start from different goals.

Internal AP audit

An internal audit is run by your own finance or internal audit team, or by an outside firm you hire to act as one. The goal is to find process weaknesses and errors before they turn into losses or findings in the year-end audit. You set the scope, so you can go deep on a single vendor category, a new approval workflow, or a period where staff turned over.

External audit

An external audit is performed by an independent CPA firm as part of the annual financial statement audit. For payables, the auditor’s main concern is whether liabilities are complete and properly stated at year end, so expect cutoff testing and a search for unrecorded liabilities. Public companies in the US also get an audit of internal control over financial reporting under PCAOB AS 2201, which is integrated with the financial statement audit. Private companies are not subject to that standard, but their auditors still assess controls when planning their work.

External auditors are looking for material misstatement. A handful of small duplicate payments may never come up in their findings, which is one reason companies run their own checks as well.

Recovery audit

A recovery audit (also called an AP recovery audit or profit recovery audit) looks back over already paid transactions, often covering several prior years, to find money that can be recovered from vendors. Typical findings are duplicate payments, missed credit memos, unapplied vendor credits, pricing that does not match the contract, overlooked discounts or rebates, and tax charged in error.

Recovery audit firms usually work on a contingency basis: they are paid a share of what is actually recovered, so the engagement costs nothing up front. The trade-off is that the fee comes out of money that was yours in the first place, and the recovered amounts can be months or years old by the time they are found. For many companies it is still worth doing periodically, especially after a system migration, a merger, or a period of high staff turnover.

What is the AP audit process?

Most AP audits, internal or external, follow the same broad sequence.

  1. Set the scope and period. Decide which entities, vendors and dates you are covering and what you are testing for: completeness of liabilities, duplicate payments, control compliance, or all of these.
  2. Pull the data. Export the vendor master file, the AP subledger or open items report, the paid invoice history, the payment register, and purchase orders and receiving records if you use them. Reconcile the AP subledger to the general ledger before you start, so you know the data is complete.
  3. Understand the process. Walk through how an invoice arrives, who codes it, who approves it, who can create or edit vendors, and who releases payments. Note where one person can do more than one of those steps.
  4. Review the vendor master file. Look for duplicate vendors, missing tax IDs, vendors that share a bank account or address with an employee, and recent changes to bank details.
  5. Test invoices and payments. Trace a sample of payments back to invoices, approvals and receiving evidence. Run analytics over the full population for duplicates, round amounts, invoices just under approval limits, and price changes against contract terms.
  6. Test cutoff and unrecorded liabilities. Review invoices received and payments made after period end to find expenses that belong in the period being audited but were never recorded.
  7. Reconcile supplier statements. Request statements from key vendors and compare them with your own records to find missing invoices, unapplied credits and payments the vendor has not matched.
  8. Report and follow up. Document each finding with the evidence, the amount and the control gap behind it. Assign an owner and a date for each fix, and recover any overpayments from vendors.

Accounts payable audit checklist

Use this as a working checklist for an internal review. Each line is something you can check with data you already have.

Area What to check Why it matters
Vendor master file Duplicate vendor records, missing or invalid tax IDs, inactive vendors still set up for payment, bank detail changes and who approved them, vendor addresses or bank accounts that match employee records Duplicate vendor records make duplicate payments easier, and a loosely controlled vendor file is where fake vendors get added
Duplicate payments Same vendor with the same or similar invoice number, same amount on nearby dates, the same invoice paid under two vendor records A duplicate paid once tends to be paid again the next time the same invoice arrives twice
Invoice approval Every invoice has an approval from someone with authority for that amount; no approvals by the person who entered the invoice Confirms the approval control works as designed
Segregation of duties No single person can create a vendor, enter an invoice and release a payment This combination is where both errors and fraud go unnoticed
Price checks Unit prices and fees on invoices match contracts, price lists or purchase orders; price increases were agreed Small increases on recurring invoices add up and rarely get noticed
Purchase order and receipt Invoices are matched to purchase orders and receiving records where your policy requires them Confirms you pay only for what was ordered and delivered
Cutoff and unrecorded liabilities Invoices dated before period end but entered after, goods received without an invoice, accruals for known services Keeps period-end liabilities complete
Supplier statement reconciliation Statements from top vendors agree to your AP subledger; differences explained Finds missing invoices, unapplied credits and duplicate charges
Credits and refunds Open credit memos are applied or refunded; vendor refunds are recorded Unapplied credits are money you are owed
1099 and W-9 (US) A current W-9 on file for each vendor that needs one, TIN and name checked, vendors correctly flagged for 1099 reporting Missing or wrong TINs cause filing problems and possible backup withholding
Payment release Payments match approved invoices; manual and urgent payments have extra review Manual payments bypass the normal checks most often

A few notes on the areas that cause the most questions.

Vendor master file review

The vendor master file is the list of every supplier you can pay, with names, addresses, tax IDs, payment terms and bank details. Clean it at least once a year: merge duplicate records, deactivate vendors with no activity for a year or more, and confirm that every bank detail change was requested through a verified channel and approved by someone other than the person who made the edit. Duplicate vendor records are a common source of duplicate payments, because the same invoice can be entered under each record without a system warning.

Supplier statement reconciliation

Supplier statement reconciliation means comparing the statement a vendor sends you with the balance in your own AP ledger for that vendor. Differences usually fall into a few buckets: invoices the vendor has billed that you have not entered, payments you made that the vendor has not applied, credit notes that never reached AP, and the occasional invoice billed twice. For the last case, see our guide to double billing. You do not need to reconcile every vendor every month. Start with your highest-spend vendors and any vendor with a history of disputes.

W-9 and 1099 checks for US companies

Collect a Form W-9 from each new vendor as part of setup, ahead of the first payment. The IRS describes the form as the way a payee gives their taxpayer identification number to anyone required to file an information return about them (IRS, About Form W-9). Payers who file Forms 1099 can use the IRS TIN Matching program to check name and TIN combinations before filing. Reporting thresholds have changed in recent tax years, so check the current Form 1099 instructions rather than relying on last year’s setup.

Price checks against contracts

Compare what vendors bill with what you agreed to pay. This is where contract rates, volume discounts and fixed fees drift over time. An invoice price variance is the gap between the price on the purchase order or contract and the price on the invoice, and it is worth reviewing every time it goes above a set tolerance. Other invoice discrepancies, such as quantity or tax differences, belong in the same review.

What are the key AP internal controls?

Internal controls are the rules and checks built into the process so that errors surface during normal work, while they are still easy to fix. The COSO Internal Control Integrated Framework describes itself as the most widely used internal control framework in the US, and it is a common way to organize them. For accounts payable, the controls that matter most are:

  • Separate duties so that creating vendors, entering invoices, approving invoices and releasing payments are split across people. In a small team where that is not possible, add a review by someone outside AP, such as the controller reviewing the payment run.
  • Restrict who can add or edit vendors, and require a second person to approve bank detail changes. Confirm any change by calling the vendor on a number you already have, not one from the request.
  • Set approval limits by amount and make the system enforce them.
  • Match invoices to purchase orders and receiving records for goods, and to contracts for services, before approval.
  • Check each new invoice against paid history for possible duplicates on vendor, invoice number, amount and date.
  • Review payment runs before release, with extra review for manual, urgent or first-time payments.
  • Reconcile the AP subledger to the general ledger every month, and reconcile statements for key vendors on a regular schedule.
  • Keep an audit trail of who entered, changed and approved each invoice and vendor record.

If you are looking at controls because of a suspected scheme, our list of invoice fraud warning signs covers the red flags to look for.

What are the golden rules of accounts payable?

There is no official list, but most AP teams work from the same short set of principles:

  • Pay only invoices that match something you ordered and received, at the price you agreed.
  • Pay each invoice once, to a vendor you have verified, at bank details you have confirmed.
  • Keep the person who approves a payment separate from the person who sets up the vendor or releases the money.
  • Record every liability in the period it belongs to.
  • Pay on the agreed terms, not earlier than needed and not late.
  • Keep the evidence for every payment where an auditor can find it.

How often should you audit accounts payable?

A full external audit happens once a year for companies that need one. Internal reviews work better on a shorter cycle, and different checks suit different frequencies:

Frequency Checks
Every invoice Duplicate check against paid history, approval within limits, match to purchase order or contract
Every payment run Review of the payment list, manual and urgent payments, first payments to new vendors, recent bank detail changes
Monthly AP subledger to general ledger reconciliation, supplier statements for top vendors, review of vendor master changes
Quarterly Duplicate payment analysis across the full quarter, price review for recurring vendors, access review for vendor and payment permissions
Yearly Vendor master cleanup, W-9 refresh and 1099 preparation (US), full internal AP audit ahead of the external audit

A recovery audit every few years can also make sense, particularly after a change of ERP or accounting system, when duplicates and lost credits tend to pile up.

If you do not have tooling yet, a spreadsheet is a reasonable start for the quarterly duplicate analysis. Our guide on how to find duplicate invoices in Excel walks through the formulas.

Where OverpayAlert fits between audits

An audit looks backward. The longer the gap between reviews, the more a duplicate invoice or a quiet price increase has time to repeat before anyone looks at it.

OverpayAlert is not an audit service and does not replace your auditors or your controls. It covers two of the checks in the list above on an ongoing basis. You forward invoices by email or upload them, and each one is compared with the invoices you have already sent. Potential duplicate invoices and unusual vendor price increases are flagged for a person on your team to review and decide on. On the Growth and Scale plans, results can be exported as CSV, and the Scale plan adds an API for teams that want the data in their own systems. The how it works page shows each step, and pricing lists what each plan includes.

If you want those two checks running between audits, start a 7-day free trial.