Skip to content
Playbooks10 min read

An Accounts Payable Audit Checklist That Finds Real Money

Most AP audit checklists test whether your controls exist. This one tests whether they worked, which is a different question with a much more useful answer.

There are two kinds of accounts payable audit. A controls audit asks whether the right approval steps are documented and followed. A recovery audit asks a blunter question: how much money left the building that should not have, and can we get it back? This checklist is the second kind.

Work through it in order. The early sections clean up the data that the later sections depend on, and running them out of sequence produces false positives that waste a day.

1. Vendor master hygiene

Every duplicate-detection technique compares transactions within a vendor. If one supplier exists as three records, none of those techniques work. Fix this first.

  • Export the full vendor list and sort alphabetically. Scan for near-identical names, punctuation variants, and trailing entity suffixes.
  • Check for shared tax IDs across differently named records. This catches the cases the name scan misses.
  • Check for shared bank details or remittance addresses across records. Same purpose, different key.
  • Flag vendors with no transactions in 18 months. Dormant records are both a leakage risk and a fraud surface.
  • Flag vendor records whose bank details changed in the period, and confirm each change against something other than the email that requested it.

2. Duplicate and near-duplicate payments

  • Exact matches: same vendor, same amount, same reference.
  • Reference variants: same vendor, same amount, references differing by a prefix, suffix, or leading zeros.
  • Fuzzy amounts: same vendor, amounts within one percent, within a 45 day window.
  • Cross-method: the same invoice settled once by ACH and once by card.
  • Statement-driven: a payment matching the total of several invoices already settled individually.

3. Contract and rate compliance

This section usually finds more money than the duplicate section, and almost nobody runs it, because it requires reading the contract.

  • Pull the rate card for your ten largest vendors by spend and check invoiced unit rates against contracted rates.
  • Check that volume-tier discounts actually applied once you crossed the tier threshold.
  • Check for price escalations applied earlier than the contract permits, or above the contracted cap.
  • Check that services billed were services provisioned. Cancelled and downgraded lines are the classic finding here.
  • Check freight, surcharges, and tax against contract terms. Exempt items billed with tax are common and easy to recover.

4. Three-way match failures

  • Payments with no matching purchase order.
  • Payments exceeding the authorised PO value, including small tolerances applied repeatedly.
  • Goods receipts with no corresponding invoice, which is money you owe and have not been billed for. Worth knowing before the vendor remembers.
  • Invoices received with no goods receipt, which is the reverse and worth pausing.

5. Credits and unapplied balances

  • Credit memos issued but never applied against an outstanding invoice.
  • Vendor deposits and prepayments never drawn down.
  • Unapplied cash sitting on vendor accounts.
  • Credits with expiry terms approaching. These convert to zero if ignored.

6. Anomaly review

Everything above is rule-based. This section is where you look for the things no rule anticipated.

  • Payments that are statistical outliers against that vendor's own history.
  • Round-number payments just below an approval threshold. A cluster of 9,900 dollar invoices where the threshold is 10,000 is worth a conversation.
  • Payments on weekends or holidays, or outside your normal payment run cadence.
  • New vendors receiving unusually large payments within their first 60 days.
  • Sequential invoice numbers from a vendor who serves many customers. It suggests the invoices were generated only for you.

7. Close the loop

An audit that finds 80,000 dollars and changes nothing will find a similar amount next year. For each category above, write down the process change that would have prevented it, and who owns that change. The categories that recur are telling you which control does not exist.

Leaki automates sections two, four, five, and six against your live ledger, and flags section three where contract terms have been supplied. It runs continuously rather than annually, which is the difference between catching a recurring overcharge on its first occurrence and catching it on its twelfth.

Run this against your own books.

Leaki connects read-only to QuickBooks, Xero, and Zoho Books, audits your full payment history, and charges nothing unless it recovers money for you.