What audit findings often reveal about accounts payable processes
Senior Manager Content Marketing at Medius
- Introduction
- Accounts payable is where auditors look first
- What do AP audits look for?
- The most common AP audit findings and what they signal
- Why do AP audits uncover process problems rather than paperwork problems?
- How weak visibility hides findings until an auditor surfaces them
- How do finance teams strengthen AP controls?
- Where AI changes what controls can catch
- Start with the exceptions your team already works around
Hear what's covered in this article:
An audit finding rarely uncovers something nobody knew about. More often it names something the accounts payable team has been quietly managing for years. The supplier that exists twice in the master file. The invoice that always needs a coding correction before it posts. The approval that arrives as a forwarded email because the workflow never accounted for that scenario.
From inside the function, none of that reads as a control failure. It reads as the job. That distance between how an AP team experiences its own process and how an auditor reads the same process is where most findings come from.
Accounts payable is where auditors look first
Accounts payable is the highest-volume disbursement function in most organizations. Every purchase, every supplier invoice, and every reimbursement eventually moves through it, which makes it the shortest path to understanding whether financial controls actually hold. Auditors concentrate their sampling where the dollars and the risk sit together, and in most companies that describes AP better than anything else on the balance sheet.
There is a second reason, and it has less to do with volume than with how AP problems behave. An accounts payable audit tends to catch weaknesses late because those weaknesses do not fail loudly. A duplicate payment does not stop the close. A missing purchase order does not halt production. The numbers keep looking reasonable while the underlying gap widens, which means the issue tends to surface on an auditor’s schedule rather than the finance team’s.
The metrics most finance leaders watch are efficiency metrics: cost per invoice, cycle time, days payable outstanding. Those numbers can improve while control integrity stays flat or degrades. A team processing invoices 30% faster than last year has said nothing about whether each of those invoices was authorized at the right level. Speed and control are different measurements, and the gap between them is where fraudulent invoices tend to survive.
What do AP audits look for?
Nearly every question an auditor asks about payables reduces to five assertions. Knowing which one a finding maps to is what turns a list of exceptions into a diagnosis.
Completeness
Are all liabilities on the books? External auditors weigh this most heavily, because the risk in payables is understatement rather than overstatement. Testing usually means reviewing disbursements made just after period end to find invoices that should have been accrued.
Accuracy
Does the recorded amount match what was actually owed? Pricing variances against contract terms, quantity mismatches, and duplicate payments all surface here.
Authorization
Was the payment approved by someone with the authority to approve it, at the correct dollar threshold, before it went out? Auditors sample across dollar tiers and check each invoice against a documented approval matrix.
Cutoff
Did the expense land in the period it belongs to? Invoices received within roughly 10 days of period end get the closest scrutiny.
Segregation of duties
Can one person move a payment from supplier setup through release without a second set of eyes? This is typically tested by pulling a user access report and looking for a single name across conflicting roles.
The most common AP audit findings and what they signal
The specific findings vary by company, but the patterns repeat. What matters is less the finding itself than the process condition behind it.
- Duplicate and near duplicate payments. The same invoice paid twice, often under a slightly altered invoice number or a supplier name entered two different ways. Each instance looks like an isolated data entry mistake. Together they indicate invoices entering through more than one uncontrolled channel with no systematic check across them.
- Approval bypass through invoice splitting. A single purchase broken into smaller invoices, each landing just under an approval ceiling. This one is rarely accidental. It signals that the approval matrix exists as policy but is not enforced at submission, so people route around it when it slows work down.
- Purchase orders created after the invoice arrives. Raising a PO to match an invoice already in hand reverses the authorization sequence. Approval is being reconstructed rather than granted, which means three-way matching validates a document trail instead of an actual commitment.
- Supplier master contamination. Outdated addresses, inactive suppliers still eligible for payment, duplicate records for one supplier, and bank detail changes made without independent verification. This sits upstream of nearly every payment finding, and it is where ghost supplier schemes begin. Catching it depends on anomaly detection that flags a bank change or a new address as it happens, rather than a review that finds it a quarter later.
- Segregation of duties violations. One person able to onboard a supplier, enter the invoice, and release payment. In lean teams this is often not a policy failure but a headcount reality that nobody built a compensating control around.
- Unrecorded liabilities and cutoff errors. Invoices received before period end but logged after, which understates liabilities and overstates results for the period. Usually traces back to invoices that never entered the AP system at all before the books closed.
- Incomplete audit trails. Approvals sitting in email threads, supporting documents in a shared drive, evidence reassembled from memory when someone asks about a transaction from eight months ago. This is the finding that tends to expose all the others, because a trail that cannot be produced cannot be relied on.
Stop chasing invoice updates and start leading with data.
When you're flipping between systems and flying blind on liabilities, you can't focus on what matters. This reporting guide written for finance leaders defines a clear path to smarter, faster AI-driven AP reporting.
Why do AP audits uncover process problems rather than paperwork problems?
Read individually, each of those findings looks like a discipline issue. Someone was careless, someone skipped a step, someone should have checked. That reading is exactly why the same findings return in the next cycle. The remediation plan says the team will be more careful, the team genuinely tries, and 12 months later the exception report looks the same.
The more accurate reading is that each finding describes a process that permits the exception. Duplicate payments are not a carelessness problem, they are a consequence of invoices arriving through email, portals, postal mail, and individual inboxes with no single point of capture. Backdated purchase orders are not a discipline problem, they are what happens when the workflow allows an invoice to be received before a commitment is recorded. Documentation gaps are not a filing problem, they are what happens when evidence gets assembled after the fact instead of captured at each step as the transaction moves.
That distinction carries real cost. A finding attributed to human error gets a training memo. A finding attributed to a process gap gets a workflow change, and only the second one stops the finding from recurring. Repeat findings also invite closer scrutiny the following year, since a control environment that produced the same exception twice gives an auditor reason to sample more heavily. Improving audit readiness is largely a matter of removing the conditions that generate exceptions rather than getting better at explaining them.
How weak visibility hides findings until an auditor surfaces them
An exception nobody can count is an exception nobody can fix. Most AP teams know their pain points anecdotally. What they usually cannot produce on demand is how many invoices required a manual coding correction last quarter, which suppliers generate the most match exceptions, how long exceptions sit before someone resolves them, or what share of invoices completed without a human touch.
That gap is why findings feel like surprises. The auditor is not seeing something the team could not see. The auditor is aggregating something the team never had in aggregate. One coding correction is invisible. 400 of them against the same nine suppliers is a control finding.
Building reporting and analytics into the AP process closes that gap by making exception patterns visible while they are still small. Straight-through processing rate shows how much volume moves without manual intervention. Exception aging shows whether issues get resolved or accumulate. Match exception volume by supplier indicates whether the problem is the process itself or one upstream relationship. None of those measures is an audit requirement. All of them let a finance team find its own findings first.
How do finance teams strengthen AP controls?
Stronger internal controls usually mean fewer steps rather than more sign-offs. Each of the following closes a specific gap behind the findings above.
One point of invoice intake
Duplicates and unrecorded liabilities both depend on invoices entering through channels nobody monitors. A single capture point removes the condition rather than catching the result.
Duplicate detection at submission
Screening on supplier, amount, invoice number, and a defined date window catches the repeat invoice before payment, not months later in a recovery review.
Authorization recorded before the invoice
When the commitment gets captured at the point of purchase, three-way matching validates something real. This is the control that eliminates backdated purchase orders.
An enforced approval matrix with split detection
Thresholds that apply automatically, plus flags on same-supplier clusters that suggest a split, turn approval policy into approval behavior.
Dual control on bank detail changes
Redirected payments almost always begin with a quiet edit to a supplier’s account number, so that field warrants a second approver and a reviewable change log.
Separation of duties enforced by the system
Rules that run independently of who holds which role let a small team pass a segregation test it could not pass on headcount alone.
Sequence matters here, and it is worth being direct about it. Automating a broken process makes the broken process run faster. If invoice intake is fragmented and the supplier master is unreliable, automation moves the same errors through more quickly and with more apparent authority. Standardizing the workflow and cleaning up supplier data comes first. Medius AP Automation then holds those controls inside the process rather than depending on people to remember them, with every invoice, match decision, approval, and payment time stamped and attributed as it moves.
Where AI changes what controls can catch
Rule-based controls catch what someone thought to configure. That covers known findings well and unfamiliar ones poorly, because a rule written for last year’s fraud pattern does not recognize this year’s.
Models trained on transaction behavior work differently. They surface what deviates from an established pattern, including combinations nobody wrote a rule for: a supplier whose invoice volume changes shape, a payment request arriving outside a normal cadence, coding that does not fit how that expense has always been treated. Medius applies AI across the invoice lifecycle rather than at a single checkpoint. SmartFlow auto-fills coding, tax, and approver values for non-PO invoices with 95% precision after only two invoices, and Fraud and Risk Detection surfaces anomalies for review before money leaves.
There is a control benefit in that accuracy that is easy to overlook. Every manual touch is a place where an exception can be introduced, worked around, or documented inconsistently. Raising the share of invoices that process without intervention shrinks the surface area where findings originate in the first place.
CFOs are expected to do more than ever. Your AP system should carry some of that weight.
AI-powered AP automation eliminates manual work, strengthens financial controls, and gives finance leaders the real-time visibility they need to make smarter, faster decisions. Less about liabilities, more about opportunities.
Start with the exceptions your team already works around
The shortest route to fewer findings is not a new policy. It is an honest look at the corrections the AP team makes every month without escalating them. Recurring coding fixes, duplicate supplier records, POs raised after the fact, and approvals that arrive outside the workflow are the same items an auditor will pull, surfaced months before anyone external asks about them.
Medius gives finance teams standardized approvals, an audit trail that builds itself as invoices move, and visibility into the exception patterns that become findings. Book a demo to see how it maps to your current process.