Internal Control Issues in Accounts Payable: Step by Step

Notice: No webinar is currently available in this series.

This webinar is not currently available, new dates coming soon.

Frequently Asked Questions

Accounts payable is one of the highest-risk functions for financial loss, and internal control weaknesses cluster around predictable failure points. Insufficient segregation of duties is the foundational vulnerability: when the same person can enter a vendor, create a purchase order, approve an invoice, and initiate a payment, the conditions for fraud are complete. Inadequate vendor master file controls allow fictitious vendors to be established and paid. Missing three-way matching—failing to compare purchase orders, receiving documents, and vendor invoices before payment—allows duplicate and erroneous invoices through. Weak invoice approval processes with vague thresholds or no electronic audit trail create opportunities for inappropriate payments. Failure to periodically review the vendor master file allows inactive vendors, duplicate entries, and potentially fraudulent profiles to accumulate undetected. Check signing controls that allow blank check access or manual checks without dual authorization are serious vulnerabilities. Each represents an identifiable, addressable control gap that a step-by-step AP internal control assessment can surface before auditors or fraudsters discover them first.
Segregation of duties (SOD) in accounts payable distributes key process steps among multiple individuals so no single person can initiate, approve, and complete a transaction without independent verification. Proper AP segregation requires at minimum: one person to maintain the vendor master file; a separate person to process and enter invoices; a separate person to approve invoices for payment; and a separate person or automated control to release payments. When these functions collapse into one or two individuals—common in small AP departments—the organization loses its primary fraud prevention mechanism. A single employee with access to all four functions can create a fictitious vendor, create and approve an invoice, and release payment with no independent check. For small organizations where full SOD isn't feasible due to staffing, compensating controls are essential: management review of exception reports, independent vendor master audits, bank reconciliations by someone outside AP, and positive pay services. SOD is not optional—it is the cornerstone of any functional AP internal control environment regardless of organization size.
Three-way matching is the process of comparing three documents before releasing payment: the purchase order (what was ordered, at what price, and with what terms), the receiving document or delivery confirmation (what was actually received in what quantity), and the vendor invoice (what the vendor claims is owed). Payment is only authorized when all three documents agree within acceptable tolerance. Three-way matching prevents paying for goods or services never received, paying the wrong price due to discrepancies between PO terms and invoice pricing, paying incorrect quantities, and processing duplicate invoices. Automated matching in ERP and AP automation systems flags exceptions for human review while automatically processing clean matches, dramatically reducing manual handling burden while strengthening controls. For organizations processing high volumes of invoices, automated three-way matching is one of the highest-ROI AP control investments available. For smaller organizations relying on manual matching, a documented step-by-step matching checklist ensures the process is consistently applied rather than selectively performed under time pressure or during staff absences.
The vendor master file is one of the most critical and most frequently under-controlled elements of the AP function. Fictitious vendor fraud—where an employee adds a fraudulent vendor and routes payments to a personal account—is one of the most common and costly AP fraud schemes, and inadequate vendor master controls are its primary enabler. Strong controls begin with access restriction: only designated administrators should have authority to add, modify, or deactivate vendors, expressly segregated from invoice processing and payment release functions. Every new vendor should require documentation verifying legitimacy: W-9 form, business verification, banking information confirmation, and authorization by a business owner outside AP. Periodic vendor master reviews—quarterly or semi-annually—should identify duplicate vendors, inactive vendors, vendors with missing TIN information, and vendors whose banking details have been recently changed (a common indicator of payment redirection fraud). Automated duplicate detection logic should flag records with matching names, addresses, tax ID numbers, or banking details. A well-controlled vendor master file is the foundation on which all other AP controls depend.
A step-by-step AP internal control review examines the complete procure-to-pay process to identify vulnerabilities before they result in financial loss or audit findings. Begin with an access rights review: pull all users with AP system access and verify segregation of duties is enforced in the current access profile. Next, review the vendor master file for completeness, accuracy, and audit trails documenting who made changes and when. Examine invoice processing workflows for evidence of consistent three-way matching, proper approval routing, and exception handling procedures. Review a sample of payments for appropriate supporting documentation and authorization. Test for duplicate payments by analyzing payment records for matching invoice numbers, amounts, or vendor combinations. Review check and ACH payment controls: who can release electronic payments, is dual authorization enforced, and are positive pay services in place? Examine period-end reconciliations and verify that AP subledger balances reconcile to the general ledger. Document all control gaps with risk ratings and specific remediation recommendations. This systematic approach produces a prioritized roadmap for strengthening AP controls proactively.