Your external auditors signed off. Internal audit found no material weaknesses. The AP control environment scored well on the SOX review. And yet hundreds of thousands—sometimes millions—in recoverable AP dollars sit unclaimed.
This isn’t an audit failure. It’s a design mismatch. Traditional AP audits aren’t built to find money. They’re built to assess controls.
What AP Audits Are Designed to Do
A standard AP audit evaluates whether your payment processes follow policy and regulation. Auditors test approval workflows, segregation of duties, and compliance with internal controls. They sample transactions to confirm that invoices have proper authorization, that three-way matches functioned as designed, and that payments comply with tax and reporting requirements.
This is necessary work. It protects the business from fraud, ensures regulatory compliance, and provides assurance to the board and stakeholders. A clean audit report means your control framework is sound.
It does not mean every dollar paid was owed, paid once, or paid at the correct rate.
What Audits Don’t Look For
Audit samples are just that—samples. Auditors select a subset of transactions, typically based on risk factors or materiality thresholds. They don’t reconcile every invoice against every contract term, purchase order line item, or prior payment. They’re not matching vendor remittances to ledger credits. They’re not tracking down pricing variances that fall within tolerance but shouldn’t have occurred in the first place.
Consider common recovery scenarios that pass a standard audit without comment:
- Two invoices with the same amount but different invoice numbers, paid weeks apart—looks like two legitimate transactions in a sample review
- A vendor increases unit pricing by three percent when the contract allows up to five percent annual adjustment—within tolerance, not flagged
- A credit memo issued after a return sits unapplied in the vendor’s system for eighteen months—no control failure, just incomplete follow-through
- Freight charges billed separately when the contract specifies freight included—compliant with AP policy if the invoice was approved, but incorrect per contract terms
None of these represent control breakdowns. All of them represent recoverable dollars.
Why ERP Systems Don’t Close the Gap
Modern ERP platforms include duplicate invoice detection, three-way matching, and tolerance monitoring. These controls catch obvious errors—identical invoice numbers from the same vendor, quantities that exceed PO limits, prices that violate hard thresholds.
They don’t catch nuance. A duplicate payment with a slightly different invoice number. A price increase that’s contractually unjustified but within system tolerance. A credit that requires manual application across entity codes. These issues live in the details, and the details aren’t the focus of an audit or an ERP alert queue.
The Recovery Model Is Different

AP recovery work starts with a different question: not whether the process worked, but whether the outcome was correct. This requires transaction-level review—matching payments to contracts, comparing invoices to POs and prior invoices, reconciling vendor statements to internal ledgers, and following up on every credit and adjustment.
It’s a volume exercise. In a business with seventy-five million in annual AP spend, you might have two hundred thousand transactions across eight hundred vendors over a three-year lookback. An audit samples dozens or hundreds of those. A recovery review examines all of them.
That’s why recovery engagements are nearly always structured on contingency. The work only makes economic sense if findings are substantial, and substantial findings only emerge when you look at every transaction.
What This Means for the CFO
If your most recent audit came back clean, that’s good news for governance. It doesn’t mean you’ve recovered everything you’re owed. Audit and recovery serve different purposes, and one doesn’t substitute for the other.
A well-controlled AP function can still pay duplicate invoices when invoice numbering isn’t standardized across vendors. Strong procurement policies don’t prevent gradual price drift when no one is matching every payment to contract pricing schedules. A compliant three-way match process won’t catch a vendor credit that was issued but never applied because it requires a manual journal entry across subsidiaries.
The question isn’t whether your auditors missed something. The question is whether anyone has looked at your AP transactions with recovery as the explicit objective. If the answer is no—or not recently—then the economics of a contingency-based review are hard to argue against.
Fintralis works exclusively with finance leaders at companies running SAP, Oracle, or JD Edwards, with annual AP spend over fifty million. We recover money that audits aren’t designed to find, and we’re only compensated when we do. If your AP function has been audited but never reviewed for recovery, let’s talk.
Frequently asked questions
Why don’t AP audits find duplicate payments and vendor errors?
Most AP audits focus on control frameworks and compliance documentation, not transactional matching against vendor contracts and invoices. They verify that approval processes exist, not whether the approved amounts were correct or paid only once.
What’s the difference between an AP audit and an AP recovery review?
An AP audit examines internal controls and regulatory compliance. An AP recovery review matches every payment against contract terms, purchase orders, and prior invoices to identify duplicate payments, pricing errors, and unapplied credits.
Can a clean AP audit report still mean money is sitting unclaimed with vendors?
Yes. A strong control environment doesn’t prevent duplicate invoice numbers across vendors, pricing variances within contract tolerances, or credits issued but never applied. Audits confirm controls work; they don’t reconcile every vendor transaction.
How much AP spend typically goes unrecovered after a standard audit?
Recovery specialists working on contingency typically identify findings worth one half to one percent of three-year AP spend in companies over fifty million in annual payables. Traditional audits aren’t structured to find these transactional discrepancies.
Do ERP systems flag the issues that AP recovery specialists find?
ERP systems flag control breaks like missing approvals or PO mismatches. They don’t typically flag same-amount invoices paid weeks apart, unit price creep within tolerance bands, or vendor credits sitting unapplied for months across multiple entity codes.
Should a CFO request a recovery review if the last audit was clean?
A clean audit confirms process integrity. A recovery review confirms transactional accuracy. They measure different things. If your AP spend exceeds fifty million annually and you haven’t done a detailed vendor-by-vendor reconciliation in three years, the answer is yes.