Accounts Payable Audits

Introduction

Accounts payable sits at a busy intersection. It touches cash flow, vendor relationships, expense reporting, and the accuracy of your financial statements all at once. A small crack in that process rarely stays small.

Duplicate or erroneous payments affect a median of 1.5% of annual disbursements, according to APQC's 2024 benchmarking data. For a company processing $10 million in payments a year, that's $150,000 quietly leaking out.

This guide breaks down what an accounts payable audit actually is, why auditors focus on the objectives they do, what documents get requested, and how startups and SMEs can prepare without scrambling.

An AP audit isn't always a standalone event. Sometimes it's folded into a broader financial statement audit. Other times it's a separate internal review, an operational controls check, or a recovery-focused engagement.

Legal requirements depend heavily on your business structure and reporting obligations, so not every company needs the same type of review.

Key Takeaways

  • AP audits confirm liabilities and payments are complete, accurate, authorized, and booked in the right period.
  • Completeness and cutoff gaps often trip up businesses that receive goods before the invoice arrives.
  • Common findings include duplicate payments, unauthorized vendors, and weak vendor-master controls.
  • A clean audit trail speeds review and helps fix root causes, not just symptoms.

What Is an Accounts Payable Audit and What Are Its Objectives?

An accounts payable audit is a systematic review of your AP transactions, vendor records, supporting documentation, payment activity, and related controls. Its goal is to confirm that your obligations and disbursements are fairly and accurately recorded.

How It Differs From Related Reviews

People often use "AP audit," "financial statement audit," and "recovery audit" interchangeably. They're not the same thing.

  • Financial statement audit provides assurance over the financial statements as a whole. AP is one piece of a much bigger picture.
  • AP audit zooms in specifically on liabilities, payments, processes, and the controls surrounding them.
  • Recovery audit searches historical transactions for recoverable overpayments, typically looking back several years.
  • Internal controls review evaluates whether preventive controls are designed properly and actually working, separate from any opinion on the financial statements themselves.

The Core Objectives

Every AP audit tests a core set of assertions:

  1. Completeness — Have all goods and services received, invoices, accrued expenses, and other obligations been recorded?
  2. Accuracy and valuation — Are invoice amounts, tax calculations, discounts, and ledger postings correct?
  3. Occurrence, validity, and authorization — Do transactions relate to genuine purchases from approved vendors, properly signed off?
  4. Cutoff, classification, and disclosure — Are liabilities recorded in the right period and presented correctly?

Four core objectives of accounts payable audit assertions framework

Completeness usually gets the most attention because unrecorded liabilities are notoriously easy to miss. The CPA Journal describes the search for unrecorded liabilities as a fundamental audit procedure, not an afterthought.

An unrecorded liability doesn't just understate AP. It can also:

  • Overstate income
  • Misstate cost of goods sold
  • Distort taxable income
  • Throw off working capital metrics that lenders and investors track

For US companies, US GAAP is the applicable framework, and PCAOB auditing standards govern how a formal audit is conducted. Not every business needs a statutory external AP audit—requirements depend on entity structure, investor demands, lending covenants, and reporting obligations.

How Does an Accounts Payable Audit Work?

Auditing every transaction isn't practical or efficient. AP audits instead follow a structured, risk-based process across five stages.

Planning and Risk Assessment

The first step defines the boundaries: audit period, objectives, materiality thresholds, systems in scope, business units, and vendor populations. Prior audit findings, when available, help shape where attention goes.

Data Collection

Auditors typically request:

  • AP subledger and aging reports
  • General ledger detail and trial balance
  • Payment registers and bank disbursement records
  • Vendor master data, purchase orders, and receiving records
  • Invoices, credit memos, contracts, and accrued-liability schedules

Reconciling these sources against each other is where duplicates, unmatched payments, and obligations recorded in the wrong period tend to surface.

Fieldwork and Substantive Testing

This is where the real digging happens. Auditors typically:

  • Match invoices to purchase orders and receipts
  • Validate vendors and trace payments
  • Reconcile the general ledger
  • Test selected transactions in detail

Cutoff testing deserves special mention. Auditors review subsequent payments, invoices received after period-end, unmatched purchase orders, and service dates to catch obligations that existed before the reporting date but weren't recorded yet.

Here's a simple example: your company receives a consulting service in December, but the invoice doesn't arrive until January. Without an accrual, December's financials understate expenses and liabilities. An auditor testing cutoff would catch this by reviewing January invoices for services rendered in the prior period.

Exception Validation and Reporting

Not every unusual transaction is an error. Auditors investigate exceptions and decide whether each one is a genuine mistake or a legitimate business difference. They then quantify the impact and document control weaknesses with recommendations.

Remediation and Follow-Up

The process closes with clear ownership and follow-through:

  • Assign owners and deadlines for correcting entries
  • Recover any overpayments
  • Update vendor records
  • Retest the controls that failed

5-stage accounts payable audit process flow from planning to remediation

Accounts Payable Audit Preparation Checklist

Preparation determines how smoothly (and quickly) your audit goes. A hundred invoices scattered across shared folders and email threads slow everything down.

Organize your audit trail:

  • Reconciled AP aging reports, subledger, general ledger detail, and trial balance
  • Payment registers, bank records, and period-end close documentation
  • Invoices, purchase orders, receiving evidence, and contracts retrievable by vendor, date, and amount

Review vendor-master data before fieldwork starts:

  • Flag duplicate vendors, inconsistent names or addresses, and inactive suppliers
  • Check for missing tax documentation and unusual bank-account changes
  • Confirm restricted access and independent review for any vendor-record changes

Reconcile and test transactions:

  • Perform three-way matching: purchase order, receiving evidence, and invoice
  • Scan for duplicate or near-duplicate invoice numbers, amounts, or bank details
  • Investigate unapplied credits, voided payments, and unusual manual checks

Prepare for completeness and cutoff testing:

  • Compile subsequent-disbursement reports and post-period invoices
  • Gather unmatched receiving reports and open purchase orders
  • Document recurring expenses, accrued taxes, and known unrecorded liabilities—not only the invoice register

Document internal controls:

  • Provide AP policies, approval matrices, and segregation-of-duties documentation
  • Identify who handles procurement, receiving, invoice entry, payment approval, and vendor maintenance

Finally, build an audit request tracker: a simple log of each information request, owner, submission date, and resolution status. It keeps the audit from depending on scattered email chains, which is where most delays actually happen.

How Controls, Fraud Prevention, and Technology Support AP Audits

Strong AP controls reduce audit findings by catching errors and fraud risk early. When auditors review your payables process, they typically evaluate:

  • Segregation of duties and defined approval limits
  • Purchase-order requirements and three-way matching
  • Vendor onboarding checks and bank-detail verification
  • Payment-release controls and independent review of exceptions

Fraud and Error Indicators

A few red flags warrant a closer look without assuming guilt automatically:

  • Fictitious or duplicate vendors, duplicate invoices
  • Altered bank instructions, round-dollar amounts
  • Rushed approval requests or payments outside normal terms

Those indicators matter because AP fraud is costly. ACFE's 2024 Report to the Nations analyzed 1,921 occupational fraud cases across 138 countries, totaling more than $3.1 billion in losses. Billing schemes made up 22% of cases with a median loss of $100,000, while check and payment tampering accounted for 11% with a $155,000 median loss.

Each red flag should trigger investigation and documentation under your company's fraud policy—not an automatic assumption of wrongdoing.

Technology as a Control Aid

Modern AP systems create searchable records, approval histories, automated matching, and duplicate detection alerts. This builds an audit trail almost automatically: who approved what, when payment went out, and what got flagged along the way.

Automation still isn't a substitute for judgment. A Deloitte survey found that only 59.7% of finance professionals trusted AI agents to make decisions even within a clearly defined framework. Systems flag anomalies. People still need to investigate and resolve them.

Choosing an AP Audit Approach and Acting on Findings

Not every business needs the same review. The right approach depends on your size, history, and what you're actually trying to accomplish.

Internal review works well for routine reconciliations and monthly control monitoring, provided staff have enough independence and expertise to spot issues objectively. An independent specialist becomes more valuable after rapid growth, an acquisition, an ERP change, a suspected fraud event, or a long stretch without an outside review.

Which type fits your situation depends on the objective:

Objective Best-Fit Approach
Reporting assurance Financial-statement-focused AP audit
Prevention Operational controls review
Recovery of overpayments Recovery audit

When evaluating an external provider, look for:

  • Relevant US accounting expertise and a clearly defined scope
  • Sound data-security practices
  • Transparent pricing without hidden fees
  • Root-cause analysis that fixes the process, not just the individual error

Findings only create value when you act on them. After the review:

  • Rank issues by dollar impact, control weakness, and fraud risk
  • Assign owners and deadlines for each remediation item
  • Recover confirmed overpayments and update vendor master data
  • Retest key controls after fixes land, then fold lessons into monthly AP monitoring

When internal capacity is stretched, KnowVisory Global can strengthen AP workflows, reconciliations, and audit preparation for startups and SMEs. The team includes US CPAs and Indian CAs trained on US GAAP and US chart-of-accounts conventions, so you can get books audit-ready without expanding your in-house accounting bench.

KnowVisory Global accounting team supporting AP audit preparation for SMEs

That support is for AP readiness and process cleanup—not a statutory audit opinion.

Frequently Asked Questions

What is the primary audit objective for accounts payable?

Completeness is the primary focus: auditors need to confirm all liabilities existing at the reporting date have been recorded. Accuracy, validity, cutoff, authorization, and disclosure still matter, but completeness gets the most attention.

What are the golden rules of accounts payable?

Accurate documentation, approved vendors, proper authorization, and segregation of duties form the foundation. Add timely recording, three-way matching where applicable, regular reconciliation, and a complete audit trail.

What does an accounts payable audit typically review?

AP ledgers, aging reports, invoices, purchase orders, and receiving records top the list. Auditors also review vendor-master data, contracts, payment records, accrued liabilities, and internal controls.

Is an accounts payable audit the same as a recovery audit?

No. An AP audit evaluates payment accuracy and controls broadly, while a recovery audit focuses specifically on finding and recovering historical overpayments, often looking back several years.

How often should a business conduct an accounts payable audit?

Frequency depends on transaction volume, risk, system changes, and prior findings. Consider additional reviews after acquisitions, suspected fraud, or major process or ERP changes.

What documents should a company prepare for an accounts payable audit?

Prepare the AP subledger, aging reports, general ledger detail, and payment registers. Add invoices, purchase orders, receiving reports, contracts, vendor records, and reconciliations for a complete package.