Purchase to Pay
The process and the controls in it.
12 min
The cycle
- Requirement identified and a requisition raised.
- Authorised within delegated limits by someone other than the requester.
- Purchase order raised against an approved supplier, with agreed price and terms.
- Goods or services received, recorded against the order with a receipt note or a confirmation of work done.
- Invoice received and matched.
- Approved and posted to the correct account and cost centre.
- Paid in a controlled payment run on the due date.
- Reconciled against the supplier statement.
Supplier onboarding
Setting up a supplier is a control point, not an administrative task:
- Verify the entity exists and is trading — registration details, address, and the correct legal name.
- Verify bank details independently. Telephone a number obtained from a source other than the document supplying the details, and speak to a known contact.
- Check tax registration and any required certification, licences or insurance.
- Screen against sanctions lists where your jurisdiction requires it, and consider the relevant anti-bribery and modern slavery checks.
- Record agreed payment terms, currency and contract reference.
- Segregate duties: the person who creates or amends a supplier record must not be able to approve payments to it. This single control prevents the most common internal payment fraud.
- Review the supplier master file periodically for duplicates, dormant records and suppliers sharing a bank account or address with an employee.
Invoice processing
- Three-way match — purchase order, goods received note and invoice. Confirms that what was ordered was received and is what is being charged. Set tolerances for minor differences and investigate anything outside them.
- Two-way match where no physical receipt exists, such as services, matching invoice to order with confirmation from the requisitioner.
- Non-order invoices are the highest-risk category and should be minimised. Where unavoidable, require approval by someone with budget authority and independent evidence of receipt.
- Duplicate detection — check supplier, invoice number, amount and date. Duplicate payment is the most common avoidable loss in payables, and it is almost always recoverable only if noticed.
- Coding — correct account, cost centre, period and tax treatment. Miscoding distorts management reporting and tax recovery.
- Accruals — goods received but not invoiced at period end must be accrued, or costs are understated.
Payments
- Pay to terms in scheduled runs; ad hoc urgent payments outside the normal process are where control breaks down and where fraud is most often successful.
- Require dual authorisation above defined thresholds, with authorisers independent of the person preparing the run.
- Review the payment listing before release — unfamiliar payees, round amounts, new suppliers and amounts just below an approval threshold all deserve a second look.
- Never change bank details on the instruction of an email alone, however convincing. Verify by calling a known number.
- Keep an audit trail of who approved what and when.