What Does a Healthy Accounts Payable Function Actually Look Like?
Accounts Payable can look healthy from a distance.
Invoices are being processed. Vendors are being paid. Month-end closes somehow get completed. The ERP is running. Nothing appears to be on fire.
But activity is not the same as health.
A healthy AP function is one where evidence, ownership, control and visibility remain intact across the process.
Can the organisation explain why an invoice was valid? What it was checked against? Who approved it? Who owned the exception? Why the payment was released? And, if somebody came back months later, could the decision still be reconstructed?
Those questions tell us far more about AP health than invoice volume alone.
There is also no single operating model that guarantees the answer.
A manufacturing organisation may rely heavily on purchase orders, goods receipts and three-way matching. A services organisation may operate a two-way match. Another business may have no PO process at all and instead validate invoices against contracts, statements of work, order forms or other commercial agreements.
All of those models can work.
All of them can also fail.
The better question is whether the operating model is appropriate, controlled, traceable and consistently owned.
The questions I find most useful when looking at an AP function tend to fall into eight areas.
1. Invoice intake: do you know what has actually entered the process?
A healthy AP process begins before somebody starts entering an invoice into an ERP.
It begins with receipt.
Depending on the organisation, invoices may arrive physically with goods, through dedicated AP mailboxes, portals, EDI connections, individual employees, or directly from vendors.
The channel itself is not the health indicator.
The control around that channel is.
Earlier in my career, in a manufacturing environment, invoices could arrive alongside transported material and supporting documentation. The documents would eventually become part of a digital processing queue and be allocated across invoice processors.
In other environments, the process has been almost entirely email-driven.
The important question across both models is the same: once an invoice enters the organisation, is there a reliable way to know that it exists and what should happen to it next?
An invoice sitting unnoticed in somebody’s inbox has technically been received.
Operationally, it has not entered a controlled process.
Healthy intake therefore creates enough visibility and ownership that invoices do not depend on memory, individual inboxes or informal hand-offs.
2. Invoice validation: does the invoice reflect what the organisation actually agreed to buy?
This is where AP operating models start to differ significantly.
In a manufacturing environment, invoice processing may rely on a three-way relationship:
- what was ordered;
- what was received; and
- what the vendor invoiced.
If the goods receipt is missing, the PO is incorrect, or the invoice pricing does not match the underlying purchasing information, the invoice cannot simply flow through.
In another environment, the process may rely on a two-way match between the PO and invoice.
Different exceptions appear there.
The wrong PO number.
An invoice raised in a different currency.
An exhausted PO balance.
A PO that has already been closed even though further billing is expected.
These are often called AP exceptions.
But many of them did not originate in AP.
AP is simply where an upstream procurement or receiving problem becomes visible.
And then there are environments where no PO exists at all.
In my current work, an invoice may instead need to be checked directly against a contract, statement of work, order form or other commercial agreement.
That places much more weight on human interpretation.
The processor may need to establish the billing period, price, currency, frequency, contractual term, amendments and other commercial conditions before deciding whether the invoice is correct.
That has taught me to separate two ideas.
Invoice checking asks whether the invoice looks complete and internally consistent.
Invoice validation asks whether the invoice actually represents what the organisation authorised and agreed to purchase.
An invoice can pass the first test and fail the second.
A vendor can invoice twelve months when the executed agreement covers thirteen.
The arithmetic may be perfect.
The invoice may still be commercially wrong.
And where validation depends on contracts rather than structured PO data, another question becomes important: is the commercial evidence itself current, easy to locate and sufficiently clear for somebody to make a consistent decision?
The control objective therefore is not simply:
Do you use three-way matching?
It is:
Can every invoice be reliably validated against appropriate authorised commercial evidence before payment?

3. Approval governance: is the approval actually doing anything?
An approval is only useful if it represents a real control.
Most AP environments have some form of approval.
The more interesting question is what that approval actually means.
Is the approver validating the amount and underlying commercial basis?
Or are they simply clicking because AP has followed up repeatedly and the due date is approaching?
I have seen the difference matter in practice.
In one case involving usage-based technology costs, the supporting usage summary was attached to the invoice. But the existence of the report effectively became the control. The detailed usage itself was not fully reconciled against the contracted limit before approval.
In another case, an invoice for a contractor was approved even though the contractor had already left the organisation roughly a week earlier. The discrepancy surfaced only later when the exit date was reviewed, leading to a request for a refund or credit note.
And in another example, a significant spike in legal costs passed the initial approval stage. A second approver challenged the increase and requested the underlying timesheet and justification. That additional review ultimately revealed that the billing was higher than it should have been.
These examples reinforce an important distinction:
The presence of an approval does not prove that validation occurred.
A second approval is also not necessarily administrative duplication. It can add real control value when the second reviewer provides a different level of challenge.
Segregation of duties belongs in this discussion as well. The AICPA describes segregation of duties as a basic building block of sustainable risk management and internal controls.
But good control design also has to recognise reality.
A small finance team may simply not have enough people to split every activity across separate roles. That does not automatically make the environment unhealthy.
What matters is whether that concentration of responsibility is understood and supported by credible compensating controls – for example, independent review or secondary approval at an appropriate point in the process.
Where full segregation is not practical, compensating controls should be deliberately designed around the specific risk. Some may prevent a transaction from proceeding without independent review, while others detect issues through subsequent monitoring. What matters is that the control genuinely addresses the exposure created by concentrated responsibility.
The health question is therefore not whether every organisation achieves textbook segregation.
It is whether important concentrations of responsibility exist without somebody recognising and addressing the risk.
4. Vendor master governance: is the organisation controlling who becomes payable?
Vendor governance does not always begin inside AP.
In larger or more procurement-led environments, supplier onboarding can take place well before AP ever sees an invoice.
A procurement platform may require a prospective supplier to move through sourcing, commercial review, policy requirements, security checks or other onboarding steps before the supplier becomes available for use.
In leaner environments, AP may become involved much earlier.
In my current environment, when a new vendor first appears, part of the work is establishing whether that vendor is actually connected to a legitimate purchase before creating or enabling the profile.
That can mean checking procurement records, reviewing the underlying contract, confirming the internal business owner, or treating an unverified request as suspicious until the commercial relationship can be established.
But the principle is broader than AP ownership.
AP may not own vendor onboarding, but AP depends heavily on its quality.
Vendor governance is therefore better viewed as a lifecycle:
onboard -> approve -> create -> amend -> verify -> monitor -> deactivate
There is also an important difference between two risks.
The first is creating a fraudulent or illegitimate vendor.
The second is altering the payment information of a perfectly legitimate vendor.
The second can be harder to spot because the commercial relationship itself is real.
The vendor exists.
The invoice may be genuine.
The only thing that changes is where the money is being sent.
Vendor master governance is therefore much more than maintaining addresses and tax information.
It helps determine who the organisation believes its suppliers are and where its cash ultimately goes.

5. Duplicate payments: sometimes the invoice is not duplicated at all
Duplicate-payment risk is often discussed as though the same invoice simply arrives twice.
That certainly happens.
But in practice, duplicate exposure can arise even when there is only one invoice.
Earlier in my career, I handled certain international payments outside the ERP payment batch process.
Invoices selected for payment were pulled from ageing, transferred into the bank’s CSV template and uploaded separately to the banking portal.
After the payment was released, the invoice still had to be manually cleared in SAP.
That created an important dependency.
If the payment happened but the clearing did not, SAP could continue to show the invoice as outstanding.
On the next payment cycle, the invoice could appear eligible again.
The payment happened, but the accounting system did not know that it happened.
I see a modern version of the same risk with auto-debit vendors.
The vendor collects payment directly from the bank account. AP then needs to recognise that transaction and update the invoice status in the relevant system.
If that update is delayed or missed, the invoice can remain open.
A payment processor who does not recognise the vendor as auto-debit may then see what appears to be a perfectly legitimate unpaid invoice.
The underlying problem is not necessarily duplicate invoicing.
It is a failure to keep bank activity, payment execution and system liability status synchronised.
That is why duplicate-payment health checks should go beyond asking whether the ERP has a duplicate invoice warning.
A healthy process should also ask what happens when payment occurs outside the standard AP workflow, how quickly those payments are reflected in the system, and whether open liabilities accurately represent what is genuinely unpaid.
Sometimes AP risk lives in the gap between two otherwise legitimate steps.
6. Payment execution: when a believable request is still the wrong request
One of the more difficult payment-control lessons comes from situations where nothing initially looks suspicious.
I have seen a fraud incident in which the request appeared to come from an existing vendor.
There was already an ongoing genuine email conversation with that supplier.
The fraudulent communication appeared in a separate thread but carried forward enough context from the real discussion to make the request look completely credible.
The request involved changing the vendor’s banking information.
Because the conversation appeared consistent with what was already happening, the banking details were changed.
They belonged to the fraudster.
That experience changed the way I think about vendor-payment verification.
The dangerous request is not always the badly written email from an unknown person.
Sometimes the dangerous request is the one that fits perfectly into an existing business conversation.
Familiarity is not authentication.
A recognised vendor name is not authentication.
A realistic invoice is not authentication.
And a message containing genuine historical context is still not authentication.
Payment-detail changes need independent verification through a channel that is not controlled by the same communication requesting the change.
The broader risk is visible in industry research as well. The AFP’s 2025 Payments Fraud and Control Survey found that 79% of organisations experienced attempted or actual payment fraud in 2024. Vendor impersonation was cited by 45% of respondents, an increase of 11 percentage points from the previous survey.
The ACFE’s 2024 occupational-fraud study found that more than half of cases were linked to either a lack of internal controls (32% of cases) or management override of existing controls (19%).
The lesson is not that every vendor request should be treated as fraudulent.
It is that payment controls need to remain effective precisely when a request looks normal enough to avoid scrutiny.
Urgency creates a similar challenge.
A vendor threatens service suspension.
A senior stakeholder says the payment has to go today.
The team begins to treat the control as the obstacle rather than the safeguard.
Controls often fail gradually – when exceptions become familiar enough to stop feeling exceptional.
7. Reconciliation and month-end readiness: do you know what has not been recorded?
A healthy AP function should be able to explain its balances.
Month-end is often where the quality of the underlying process becomes visible.
The mechanics, however, can differ considerably between organisations.
In some PO-based environments I have worked in, AP followed a form of soft close. Routine PO invoice processing stopped around the 25th of the month, while selected non-PO or ad-hoc invoices could still be processed.
The remaining days gave finance teams time to work through areas such as accruals, prepaids, PO analysis, fixed assets and other close activities before the period was hard-closed.
A non-PO environment can work differently.
In my current process, invoices continue to be processed through month-end. On the first day of the new month, the focus is on ensuring invoices belonging to the period have been recorded, AP is reconciled, and the AP period is hard-closed.
After that point, costs that belong to the closed period but whose invoices had not reached AP are identified for accrual.
The mechanics are different.
The objective is the same:
establish a controlled cut-off and understand what has not yet been recorded.
That leads to another distinction I think is important.
A good close is not necessarily one in which every invoice has arrived.
That is rarely fully within AP’s control.
A good close is one where the organisation has enough visibility to identify what has not arrived, evaluate whether an accrual is required, reconcile what has been recorded, and explain what remains unresolved.
Healthy AP therefore does not mean zero exceptions at month-end.
It means the exceptions are visible, understood and owned.
Reconciliation is more than an accounting formality.
It is one of the ways AP proves that all the operational activity during the month has resulted in a financial position somebody can actually explain.
8. Technology and visibility: is automation improving the process or hiding it?
Automation can make AP faster.
It does not automatically make AP healthier.
A badly controlled process can be automated.
So can a badly designed workflow.
And automation can create a subtler problem: fewer people may touch the process while exceptions sit quietly inside integrations, interfaces or automated queues that nobody is actively watching.
In a multi-system finance environment, an integration failure can be particularly deceptive.
A process does not always fail with a dramatic error message.
Sometimes data simply stops flowing from one system to another.
The absence of noise can create the appearance that nothing is wrong.
That is why the important technology questions are not simply:
How automated are we?
How many invoices are touchless?
How many people have we removed from the process?
The better questions are:
Can management see what is ageing?
Can AP identify invoices waiting for approval?
Can it see recurring matching problems?
Can it distinguish normal processing from exceptions?
Can it identify which vendors or business units generate the most rework?
And when an integration or automated workflow stops behaving as expected, does somebody know?
Technology should create visibility and discipline, not merely speed.
A healthy AP function does not need every process automated.
It needs to understand where manual judgement remains, where system dependencies exist, and whether both are adequately controlled.
AP risk often sits between the steps
Looking across these areas, a pattern emerges.
Many AP failures do not begin with an obviously broken process.
They begin in the space between two processes that are individually legitimate.
An invoice arrives, but the goods receipt does not.
The payment is released, but the invoice is not cleared.
The vendor is legitimate, but the bank-detail change is not.
The contract exists, but somebody interprets the billing terms incorrectly.
The approval exists, but nobody meaningfully challenges it.
The automation works – until an integration quietly stops moving information.
That is why the same four ideas keep returning throughout the AP process: evidence, ownership, control and visibility.
If one of those disappears between two steps, the process may continue to look functional while risk quietly accumulates underneath it.

The Finance Practitioner AP Health Check
The eight areas above form the basis of The Finance Practitioner AP Health Check:
- Invoice Intake & Capture
- Invoice Validation & Matching
- Approval Governance & Segregation of Duties
- Vendor Master Governance
- Duplicate & Erroneous Payment Prevention
- Payment Execution & Controls
- Reconciliation & Month-End Readiness
- Technology, Visibility & Exception Management
The intention is not to provide an audit opinion, compliance certification or formal assessment of control adequacy.
The objective is simpler.
The self-assessment will invite finance practitioners to examine their AP environment systematically and identify where the process appears strong, where it depends heavily on individuals, and where risk may be sitting quietly between otherwise normal steps.
Not:
Do you use the right ERP?
Not:
Do you process enough invoices per person?
But questions such as:
Is the underlying commercial evidence reliable?
Are exceptions clearly owned?
Are vendor changes independently verified?
Do payment and ERP records remain aligned?
Can somebody explain what remains unresolved?
Because a busy AP function is not necessarily a healthy one.
An automated AP function is not necessarily a healthy one.
And perhaps the most useful question is not:
How many invoices did we process this month?
It is:
How confidently can we explain why those invoices should have been paid?
References
Association of Certified Fraud Examiners (ACFE). Occupational Fraud 2024: A Report to the Nations.
Association for Financial Professionals (AFP). 2025 Payments Fraud and Control Survey.
AICPA/CIMA. Segregation of duties resources and guidance, including the principle that segregation of duties is a basic building block of sustainable risk management and internal controls.
Committee of Sponsoring Organizations of the Treadway Commission (COSO). Internal Control – Integrated Framework: Guidance for Smaller Public Companies, referenced specifically for its discussion of segregation-of-duties constraints and compensating controls in smaller organisations.