Internal Controls Master Plan for Accounts Payable

Access this expert-led webinar instantly, available anytime on-demand.

4.2
Included in All-Access Membership
Live Webinar - no upcoming date
Customer Satisfaction Guarantee Learn with confidence. If you're not happy, we'll make it right. That's our guarantee.

Purchase Options

Select an attendee quantity to add to cart.

Recorded Webinar Only

$219.00
or

All Access Membership

The Aurora All Access Membership is designed to provide you with the training that you want when you want it. You will have 100% access to every live webinar, on demand webinar, professional alert, and podcast that Aurora Training Advantage offers with no additional cost.

Learn More About Our All Access Membership
$599.00
All Access Membership

While most executives are savvy enough to realize they need to be concerned about payment fraud, not everyone realizes they can also experience losses if they don’t have the proper controls around all aspects of their AP function. Duplicate and erroneous payments, audit issues and lost vendor credits all have a lethal impact on the bottom line. Control problems can creep in at almost any point in the process.. Mary Schaeffer, your presenter for this session will show you how to take advantage of instilling controls across the entire accounts payable spectrum.

After this session, you will be able to:

  • Identify controls that no longer work;
  • Ensure your segregation of duties regime doesn’t fail;
  • Create the “building blocks” of a strong internal control master plan
  • Identify best control practices for the entire procure-to-pay process;
  • Evaluate your own processes to identify weak controls that need tightening;
  • Fix the questionable controls so fraud and erroneous payments don’t sneak through; and
  • Introduce practices that are often overlooked but strengthen controls.
  • Mary Schaeffer

ATATX Credit

Aurora Training Advantage is offering continuing education points designed to recognize dedication to training and excellence in accounting.

Customer Satisfaction Guarantee
Invest in your future with confidence! Our Customer Satisfaction Guarantee eliminates all risk, letting you focus purely on mastering new skills and advancing your career. If you're not completely satisfied, we'll ensure you are. Your satisfaction is not just a promise; it's our guarantee.

Webinar Survey Overall Rating

This webinar received a total of 2 survey responses. Attendees have given an average rating of 4.2 stars out of a possible 5, reflecting the quality and value of the content presented.

Average rating

4.2 / 5
Webinar Presentation
How many of the objectives of the event were met?
5.0 Stars
How useful was the information presented at this event?
3.0 Stars
Overall, how satisfied were you with this event?
4.0 Stars
Speaker Performance
Overall, how satisfied were you with this presenter?
4.5 Stars
How closely did the presenter follow the schedule?
4.5 Stars

Reviews From Webinar Survey

Our webinars are crafted to deliver exceptional value and insight to business professionals. Below, you'll find genuine feedback from attendees.

Dawn G.
February 23, 2021
4.2 / 5
Webinar Rating:
4.0 Stars
Speaker Rating:
4.5 Stars
Do you have any other comments, questions or concerns?
no comment

Deborah G.
February 23, 2021
4.2 / 5
Webinar Rating:
4.0 Stars
Speaker Rating:
4.5 Stars
Do you have any other comments, questions or concerns?
I got some good reminders about what we need to do with our procedure updates.

Frequently Asked Questions

An accounts payable internal controls master plan is a comprehensive, strategic framework covering all aspects of the AP function—from vendor onboarding through invoice processing, payment execution, and reconciliation—to prevent fraud, erroneous payments, and compliance failures. Unlike addressing individual control issues reactively, a master plan approach identifies the building blocks of a complete AP control environment and assesses the entire procure-to-pay spectrum systematically. Organizations need a master plan because control problems can creep in at almost any point in the AP process: strong vendor master controls don't protect against weak invoice approval controls, and neither prevents duplicate payment risk if matching controls are absent. The real cost of AP control failures extends beyond direct fraud losses: duplicate payments, erroneous payments, lost vendor credits, audit findings, and operational disruption from discovering and recovering from fraud all have serious bottom-line impact. A master plan provides the holistic architecture that ensures controls work together as a system rather than in isolation—giving AP leaders a framework for systematically evaluating and continuously improving their control environment.
A strong AP internal control environment rests on a layered architecture of complementary controls reinforcing each other across the procure-to-pay process. Preventive controls establish structural barriers that stop problems before they occur: segregation of duties, vendor master file access controls, invoice approval hierarchies based on risk-tiered thresholds, and purchase order requirements for goods and services above designated values. Detective controls identify problems that bypass preventive measures: duplicate payment analysis, vendor master file reviews, AP subledger reconciliation, and regular exception report review. Corrective controls address discovered issues and prevent recurrence: documented procedures for recovering duplicate payments, updating vendor records, and closing identified gaps. Technology controls leverage ERP system configurations to enforce rules automatically: three-way match requirements, payment approval routing, hold flags for vendors with unresolved issues, and positive pay integration. A master plan audit maps each risk to the controls addressing it, identifies gaps where risks have no coverage, and prioritizes control investments based on the materiality of financial exposure across the entire AP function.
Segregation of duties in accounts payable requires ongoing monitoring to ensure the segregation established on paper reflects actual access and authority in practice. Common ways SOD breaks down include system access rights not updated after role changes, shared login credentials between AP staff members, informal work-arounds during staff absences where single individuals temporarily perform multiple functions, and workarounds created during system implementations that were never resolved. To prevent SOD failures, maintain a formal access rights matrix documenting which AP system functions each individual can perform, and review it quarterly or whenever personnel or role changes occur. Configure ERP or AP automation systems to enforce SOD rules through technical access restrictions rather than relying solely on behavioral policy compliance—system controls are far more reliable. Engage internal audit in periodic SOD conflict reviews using automated tools that analyze system access data against a defined SOD ruleset. For small AP teams where some SOD compromise is unavoidable, compensating controls—particularly documented management review—must be explicitly designed and consistently performed to address the residual risk.
Several AP control practices deliver significant fraud and error prevention value but are frequently absent from AP control environments. Positive pay services—where the organization provides its bank with a list of authorized checks before they can be presented for payment, and the bank rejects items not on the list—are remarkably effective at preventing check fraud yet remain underutilized by many organizations. Regular vendor credit statement reviews identify credits owed to the organization that have not been applied, preventing the loss of funds the company is legitimately owed. Using the annual 1099 reporting review as a control tool surfaces fictitious vendors and missing tax documentation before regulatory deadlines. Requiring a callback verification to the vendor's known phone number (not the number on the invoice) before making any payment to a new or recently updated banking account is a highly effective and underutilized control against payment redirection fraud. Periodic benchmarking of AP metrics against industry norms helps identify both process efficiency opportunities and control gaps that may not surface through internal audit activities alone.
AP internal controls require ongoing evaluation and improvement rather than a one-time assessment, because the risk environment, organizational structure, and technology continuously evolve. Establish a regular AP control review cycle—at minimum annually, with quarterly reviews of high-risk areas like vendor master changes and payment exception reports. Use loss events and near-misses as mandatory improvement triggers: every AP fraud or erroneous payment above a materiality threshold should trigger a root cause analysis and control improvement, not just a recovery effort. Benchmark against industry best practices through peer networks, accounts payable professional associations, and published AP internal control frameworks. Engage internal audit as a partnership—AP leaders who proactively request assessments and respond constructively to findings build credibility with executive leadership and reduce the likelihood of significant findings in external audits. Technology investments in AP automation, duplicate payment detection, and exception reporting typically deliver measurable control improvement while reducing manual processing burden. Documenting all control changes, rationale, and expected outcomes creates the institutional memory that prevents controls from silently degrading when personnel changes occur.