Your AP team moves fast. They process thousands of invoices, clear exceptions, and hit payment deadlines. What they don’t do is look backward through two years of paid invoices to find duplicate charges, pricing errors, and line items that don’t match contracts.
That’s not a criticism. It’s a design feature. AP functions are built for throughput, not forensics.
Performance Metrics Work Against Recovery
AP performance is measured by days payable outstanding, invoice processing cost, and exception rate. Managers track how quickly invoices clear the queue and how few touch the payment run twice. Those metrics reward forward motion.
Recovery work runs in the opposite direction. It requires pulling closed transactions, comparing them to source documents that may sit in different systems, and investigating variances that require supplier contact and internal approvals to resolve. None of this helps an AP manager hit this month’s processing target.
The result: overpayments accumulate in the paid file. Duplicate invoices submitted under different numbers. Freight charges billed twice. Contracted pricing that drifted higher without anyone noticing. Early-payment discounts taken on invoices paid late. Line-item quantities that exceed the purchase order but matched a receiving document no one questioned.
Three-Way Matching Isn’t a Fraud Detector

Three-way matching compares the invoice to the purchase order and the receiving document. If all three align, the invoice pays. This control prevents paying for goods not ordered or not received. It does not detect duplicate submissions, pricing above contract, or receiving errors that cascade into payment errors.
When a supplier submits the same invoice twice with different invoice numbers, three-way matching sees two valid transactions. When a receiving clerk accepts a shipment of 120 units instead of the ordered 100, and the supplier bills for 120, matching confirms the documents agree. The overpayment is now locked into the ERP as a successfully processed transaction.
The Multi-ERP Problem
Companies operating SAP in one region, Oracle in another, and JD Edwards in a third face a structural barrier. Duplicate detection across ERP instances requires either middleware that doesn’t exist or manual export-and-compare work that no one has time to do. A supplier can submit the same invoice to two subsidiaries, get paid twice, and leave no trace inside either system.
Internal Audit Has Other Priorities
Internal audit teams focus on controls, compliance, and risk. They test whether AP controls work as designed. They sample transactions to confirm segregation of duties and approval hierarchies. They do not conduct line-by-line recovery audits across the full paid file.
When audit does find an overpayment, it typically appears in a quarterly report as a control observation. It gets corrected going forward. The past overpayment may or may not be pursued, depending on dollar threshold and relationship sensitivity. Audit’s goal is control improvement, not cash recovery.
Procurement Doesn’t Look Backward
Procurement negotiates contracts and sets pricing terms. Once a contract is in place, the procurement team moves to the next negotiation. They don’t track whether every invoice over the next three years matches the contracted rate, especially when the contract includes volume tiers, geographic variations, or annual escalators.
Pricing drift happens gradually. A supplier’s billing system applies the wrong tier. A rate increase takes effect one month early. A discontinued discount continues to appear on the contract but disappears from invoices. Each variance is small enough to clear three-way matching. Over time, the leakage compounds.
The ROI Problem No One Solves

Running a recovery audit internally requires dedicated staff, forensic software, and months of work. For a company with $200 million in annual AP spend, the decision looks like this: spend $150,000 on a recovery project that might find $400,000, or allocate those people and dollars to close the books faster and improve forecasting accuracy.
The recovery project loses. It delivers one-time cash and uncovers past mistakes no one wants to revisit. Process improvement delivers ongoing value and makes future quarters easier.
Contingency Flips the Equation
A contingency model removes the ROI debate. The service provider funds the audit, conducts the analysis, and pursues recovery. The client pays a percentage of cash recovered. If the audit finds nothing, the cost is zero.
This model works for companies with sufficient AP spend that the absolute dollar opportunity justifies a third-party engagement. It’s not for everyone. But for finance teams operating SAP, Oracle, or JD Edwards environments with $50 million or more in annual spend, it converts an unfunded project into a risk-free cash opportunity.
Your AP team will keep processing invoices. Your internal audit team will keep testing controls. And someone else will look backward through the paid file to find the money that shouldn’t have left the building.
Frequently asked questions
Why do accounts payable teams miss overpayments?
AP teams are structured to process invoices quickly, not audit them retroactively. Performance metrics reward throughput and error prevention, not recovery. Most teams lack dedicated staff, forensic tools, or time to compare paid invoices against contracts and purchase orders across multiple years of historical data.
What types of overpayments do companies typically miss?
Common missed overpayments include duplicate invoices paid under different numbers, pricing that exceeds contracted rates, early-payment discounts taken but not earned, freight charges billed twice, and invoice line items that don’t match purchase order quantities. These errors slip through three-way matching when supporting documents contain the same mistakes.
How much money do companies lose to AP overpayments?
The amount varies by company size, transaction volume, and control environment. Organizations with high invoice volumes, multiple ERP instances, decentralized AP functions, or frequent supplier changes face greater exposure. Recovery audits typically focus on companies with annual AP spend above fifty million dollars where the absolute dollar opportunity justifies the effort.
What is contingency-based AP recovery?
Contingency recovery means the service provider conducts the audit, identifies overpayments, and manages the recovery process at no upfront cost. The provider is paid only a percentage of cash actually recovered and returned to the company. This eliminates budget requests, implementation costs, and internal resource allocation.
Why don’t ERP systems catch overpayments automatically?
ERP systems validate invoices against purchase orders and receipts at the time of payment, but they don’t continuously compare paid invoices against contract terms, check for duplicates across subsidiaries, or flag pricing drift over time. Once an invoice clears three-way matching and is paid, most systems consider the transaction closed. Retrospective analysis requires separate forensic tools and manual investigation.
Who should own AP recovery in a finance organization?
AP recovery sits awkwardly between accounts payable, internal audit, and procurement. AP owns payment accuracy but lacks bandwidth for backward-looking work. Internal audit has the investigative skills but prioritizes compliance and control testing. Procurement owns supplier relationships but rarely audits past transactions. Contingency providers solve this ownership gap by operating independently and reporting results to the CFO.