AP recovery audit
Accounts Payable Recovery Audit Services: Duplicate Payment Recovery and Overpayment Prevention
Try it now, capture a real invoice
Your file is processed for the demo only and never stored.
An accounts payable recovery audit is a backward looking review of two to four years of paid invoices that finds money you already sent out the door: duplicate payments, missed credits, unclaimed discounts, and pricing that did not match the contract. Firms work on contingency, commonly 20% to 30% of what they recover, so there is no upfront fee. A first time audit typically recovers 0.05% to 0.5% of audited spend, or roughly $1M for every $1B in supplier spend. Hiring a firm recovers history. It does not stop next quarter's duplicates, which is a separate job for controls at the point of entry.
0.05% to 0.5%
Of audited spend a first time AP recovery audit typically recovers
20% to 30%
Common contingency fee on recovered dollars, paid only on recovery
2 to 4 years
Payment history a recovery audit firm usually reviews
~20%
Share of recovery audit findings that duplicate detection alone covers
Syncs to your accounting system
What actually causes the overpayments a recovery audit finds
Every recovery finding traces back to a control that was missing when the invoice was approved. These are the ones software can close.
Duplicate invoices that clear two different checks
The same invoice arrives by email and again on paper, or a supplier re-sends it with the invoice number formatted differently. A duplicate check that only compares exact invoice number plus vendor ID misses it. Fuzzy matching on amount, date, and vendor across the whole payment history catches the version a human eye would not.
Credit memos that were never applied
A supplier issues a credit for a short shipment, the credit sits unapplied in the vendor account, and you keep paying full invoices around it. Recovery audits pull a large share of their findings from exactly this. Capturing credit memos in the same queue as invoices means the credit is visible against the vendor before the next payment run.
Prices that did not match the purchase order
The PO said $48 a unit, the invoice said $52, and nobody matched at the line level because the header total looked reasonable. Line item matching against the PO and receipt is the control that stops a price variance from becoming a recovery finding two years later.
Early payment discounts you were entitled to and lost
A 2/10 net 30 term is only worth something if the invoice is approved inside ten days. Invoices that sit in an approval queue for three weeks forfeit the discount quietly, and it never appears as an error on any report. Cycle time is the metric that predicts this one.
Duplicate vendor records in the master file
The same supplier set up twice under slightly different names is how a duplicate payment gets past a same-vendor check: the two invoices are not attached to the same vendor ID at all. A clean vendor master is unglamorous and it prevents a category of overpayment outright.
Statement balances nobody reconciled
Supplier statement reconciliation is where the largest share of recovery findings comes from, and it is the routine most AP teams drop first when they are short staffed. Reconciling statements monthly surfaces the missing credits and the double-paid invoices while they are still easy to claim.
How an accounts payable recovery audit works
The engagement is more predictable than most finance projects, because the firm does nearly all of the work on extracted data.
You extract the payment history
The firm asks for two to four years from your ERP: vendor master, invoice header, invoice line, payment records, and the matching general ledger postings. This is the part that lands on your team, and it is usually a few days of work from whoever owns ERP reporting.
The firm normalizes and screens it
Data from multiple entities and ERPs gets standardized, then run through the firm's own analytics to flag potential overpayments. Large firms describe screening for hundreds of separate error patterns, not just duplicates.
Auditors validate every candidate claim
Flagged items are reviewed by hand before anything is submitted, because a claim that turns out to be wrong costs you supplier goodwill. This validation step is why the process takes months rather than days.
Claims go to suppliers and cash comes back
Recoveries arrive as credits against future invoices or as refunds. You pay the agreed percentage of what actually lands, and the firm hands over a findings report describing where the leaks were.
You close the controls that caused them
The findings report is the valuable part that most teams underuse. Each finding names a control gap at the point of entry, and closing those is what keeps the next audit from recovering the same categories again.
Recovering history vs stopping the next one
A recovery audit and prevention software solve opposite halves of the same problem. Most finance teams that have run an audit end up doing both.
Recovery audit alone
- Finds overpayments two to four years after the cash left
- Costs 20% to 30% of every dollar recovered, every cycle
- Runs every one to two years, so leaks accumulate in between
- Recovered credits depend on the supplier still trading with you
- Findings report describes control gaps but does not close them
Recovery audit plus prevention
- Flags the duplicate before the payment run releases it
- Fixed monthly cost that does not scale with the size of the leak
- Runs on every invoice as it arrives
- Nothing to claim back because it was never overpaid
- Matching, approval limits, and duplicate checks enforced in the workflow
Who gets the most out of a recovery audit
Recovery yield is not evenly distributed. These are the profiles where firms report the highest findings.
Companies that recently completed an acquisition
Two AP teams, two vendor masters, and an overlap period where the same supplier invoices both entities is the single most reliable source of duplicate payments. If you closed a deal in the last three years and never audited the overlap, that is where the money is.
Finance teams running more than one ERP
Duplicate checks only look inside the system they run in. An invoice paid from one instance and again from another is invisible to both, which is why firms consolidate everything before screening. Multi-ERP environments consistently show higher recovery rates.
Manufacturing, retail, and distribution
High invoice volume, complex supplier pricing, rebates, and freight billing put these industries at the top end of the published recovery range. The pricing and rebate findings usually outweigh the straight duplicates.
Decentralized organizations with local purchasing
When branches or plants can raise their own POs and approve their own invoices, the same spend gets committed twice more often than anyone expects. Central AP never sees enough of the picture to catch it.
Teams that have never had an outside review
First time audits recover more than repeat ones, because the backlog has been building. If nobody has looked at your paid invoice history, assume the standard benchmark applies to your spend and size the opportunity from there.
Smaller teams for whom a firm is not worth it
Below roughly $50M in annual spend, a contingency engagement is often not worth either side's time, and the honest answer is to run the checks yourself. Duplicate detection, statement reconciliation, and line level matching cover most of what you would find.
What is an accounts payable recovery audit?
An accounts payable recovery audit is a review of already paid invoices, usually covering two to four years, that identifies and reclaims money paid in error. The categories are consistent across every firm: duplicate payments, credit memos that were issued but never applied, contract pricing that was not honored, missed early payment discounts, unclaimed rebates, and sales tax paid where an exemption applied. The firm finds the money, files the claim with the supplier, and takes a share of what comes back.
It is worth being precise about what the word audit means here, because it is not a financial statement audit and it is not an internal controls review. Nobody is issuing an opinion. A recovery audit is a data exercise aimed at cash, and the deliverable is recovered dollars plus a report describing where the leaks were.
How much does an accounts payable recovery audit cost?
Almost all recovery audits are priced on contingency, which means there is no upfront fee and you pay only a percentage of what is actually recovered. Published ranges vary by provider and by the complexity of the engagement, but most land between 20% and 30% of recovered dollars, with some quotes running as high as 40% for smaller or unusually messy scopes. If the firm recovers nothing, you pay nothing.
Some engagements use a hybrid structure instead: a modest fixed fee combined with a lower contingency percentage. That shifts a small amount of risk onto you in exchange for keeping more of each recovered dollar. It tends to make sense when you already have a good idea of the size of the opportunity, and much less sense for a first audit where nobody knows what is there.
The cost that does not appear on the invoice is your own team's time. Extracting several years of clean payment data across every entity and ERP is not trivial, and someone in finance will spend days on it. Budget for that alongside the fee.
How much does an accounts payable recovery audit typically recover?
Industry benchmarks put first time recoveries at roughly 0.05% to 0.5% of audited spend. The most commonly quoted midpoint is about 0.1% of total spend, which works out to around $1M recovered for every $1B in supplier spend. The spread is wide because recovery yield depends much more on how your organization is structured than on how carefully your AP clerks work.
Yields sit at the high end when purchasing is decentralized, when more than one ERP is in play, or when a merger or acquisition happened in the audit window. Manufacturing, retail, and distribution tend to recover more than average because of rebate programs, freight billing, and complex supplier pricing. A single entity company on one ERP with centralized purchasing will usually land near the floor of the range, and may not clear the threshold where a firm is interested at all.
Repeat audits recover less than first audits. That is the point: the backlog gets cleared once, and after that you are only catching what accumulated since the last cycle.
What data does a recovery audit firm need?
Firms work from ERP extracts rather than from your live system. The standard request covers the vendor master file, invoice headers, invoice lines, payment records, and the corresponding general ledger postings, for every entity in scope across the full audit period. Contracts, pricing agreements, and rebate terms usually come next, because a large share of findings depends on comparing what was invoiced against what was agreed.
Two practical points. First, if you cannot produce clean line level invoice data, the audit will skew heavily toward duplicates and miss most of the pricing findings, which is where a lot of the value sits. Second, this extract is the same dataset that tells you whether you need an audit at all. Running your own duplicate and credit balance checks over it first costs nothing and tells you how large the opportunity is before you sign a contingency agreement.
Recovery audit vs duplicate payment software: which do you need?
These are usually presented as alternatives and they are not. One recovers history and the other prevents the future, and the honest position is that a company with real recovery exposure needs both.
| Question | Recovery audit firm | Prevention software |
|---|---|---|
| What it addresses | Overpayments already made, two to four years back | Invoices arriving now, before payment |
| Pricing model | 20% to 30% of recovered dollars, contingency | Fixed subscription, independent of findings |
| Time to result | Several months per cycle | Immediate, on each invoice |
| Frequency | Every one to two years | Continuous |
| Coverage | Duplicates, credits, pricing, rebates, tax, discounts | Duplicates, matching, coding, approval limits |
| What you get back | Cash, plus a findings report | No leak to recover in the first place |
| Best for | Large or complex spend with an unaudited backlog | Any team that wants the leak to stop recurring |
What a recovery audit finds that duplicate detection misses
This is the part vendors in our category tend to skip, so here it is plainly. Duplicate payment software addresses only about 20% of what a recovery audit surfaces. The larger share, roughly 80% of recoveries, comes out of supplier statement audits and account reconciliation work: credits sitting unapplied, balances that never got cleared, deposits and prepayments that were forgotten.
The practical implication is that buying duplicate detection and declaring the problem solved is a mistake. If you want to close the same gap a recovery firm would, the routine that matters most is reconciling supplier statements against your ledger on a schedule, every month, for your largest vendors at minimum. Software makes that faster by keeping invoices, credits, and payments against each vendor in one place, but the discipline is the control, not the tool.
When should you hire a recovery audit firm?
Hire one when three things are true at once: your annual spend is large enough for a contingency engagement to be worth the firm's time (in practice, generally north of $50M), you have two or more years of payment history nobody has reviewed, and at least one complexity factor applies, meaning multiple ERPs, decentralized purchasing, or a recent acquisition. Under those conditions the benchmark yield usually pays for the effort several times over, and it costs you nothing if it does not.
Do not hire one if your spend is modest, you run a single ERP, and purchasing is centralized. Run the checks yourself instead. Pull the paid invoice history, look for same vendor same amount within a short window, look for near duplicate vendor names in the master file, and reconcile the top twenty supplier statements. Most of what you would find is reachable that way, and you keep all of it.
How to stop refilling the bucket after the audit
The failure mode that repeats everywhere is running an audit, banking the recovery, changing nothing, and running another audit two years later that recovers roughly the same categories. The findings report exists to prevent exactly this, and it is usually read once and filed.
Each finding maps to a specific control at the point of entry. Duplicate payments map to duplicate checking that compares amount, date, and vendor rather than exact invoice numbers, and to a deduplicated vendor master. Unapplied credits map to capturing credit memos in the same queue as invoices so they are visible against the vendor. Price variances map to line level matching against the purchase order and receipt. Lost discounts map to approval cycle time, because a discount you did not approve in time is not recoverable at all. Fraudulent or manipulated invoices map to segregation of duties and approval limits that the system enforces rather than a policy document.
Automating capture and matching does not replace a recovery audit for historical exposure, and we would not claim it does. What it changes is the size of the next one. When invoices are read automatically, checked against prior payments, matched at the line level, and routed through approval limits the system enforces, the categories that generate most recovery findings stop accumulating. The audit trail that accounts payable audit software maintains also means the next external review is an export rather than a fire drill.
Frequently asked questions
An accounts payable recovery audit is a review of two to four years of already paid invoices that identifies and reclaims money paid in error. It targets duplicate payments, unapplied credit memos, contract pricing that was not honored, missed early payment discounts, unclaimed rebates, and sales tax paid where an exemption applied. Firms find the money, file the claim, and take a share of what comes back.
Recovery audits are almost always priced on contingency, so there is no upfront fee and you pay only on recovery. Most published fees fall between 20% and 30% of recovered dollars, with some quotes reaching 40% for smaller or more complex scopes. Hybrid deals pair a small fixed fee with a lower percentage. If nothing is recovered, you pay nothing.
First time audits generally recover 0.05% to 0.5% of audited spend, with about 0.1% quoted most often as a midpoint. That works out to roughly $1M for every $1B in supplier spend. Yields run higher for organizations with decentralized purchasing, multiple ERP systems, or a recent acquisition, and lower for centralized single ERP companies.
Firms work from ERP extracts covering the full audit period: vendor master file, invoice headers, invoice lines, payment records, and the matching general ledger postings, for every entity in scope. Contracts, pricing agreements, and rebate terms follow, since many findings depend on comparing invoiced amounts against agreed terms. Producing this extract takes a few days of internal effort.
Usually not through a firm. Contingency engagements generally need annual spend above roughly $50M to be worth either side's time. Below that, run the checks yourself: search paid history for the same vendor and amount within a short window, look for near duplicate vendor records, and reconcile your largest supplier statements. You keep everything you find.
No. Duplicate detection covers only about 20% of what a recovery audit surfaces. Roughly 80% of recoveries come from supplier statement audits and account reconciliation, meaning unapplied credits, uncleared balances, and forgotten prepayments. Software prevents future duplicates efficiently, but it cannot claim back an overpayment made two years ago.
Expect several months from data handover to recovered cash. Extraction takes days, normalizing multi entity data takes weeks, and manual validation of every candidate claim is the longest phase, because a wrong claim costs supplier goodwill. Claim submission and collection then depend on how quickly each supplier responds and whether recovery comes as credit or refund.
Most organizations that use firms run them on a one to two year cycle. Repeat audits recover less than the first, because the historical backlog has been cleared and only new leakage accumulates. If recoveries drop sharply between cycles, that is evidence the controls you tightened after the first audit are working.
A recovery audit is a data exercise aimed at reclaiming cash from already paid invoices, and it is usually run by an outside firm on contingency. An internal audit tests whether controls operate as designed and reports on risk, not on recoverable dollars. Recovery findings often become internal audit input, since each one names a control gap.
It can if claims are submitted carelessly, which is why reputable firms validate every candidate by hand before it reaches a supplier. Ask any prospective firm how claims are approved, whether you review them before submission, and how disputed claims are withdrawn. Most suppliers accept well evidenced claims routinely, since the error was usually mutual.
Stop the next overpayment before it clears
Upload a real supplier invoice and see the extracted vendor, invoice number, totals, and line items checked against what you have already paid. The free plan covers 20 invoices a month, with no credit card.