Purchase to Pay

The process and the controls in it.

12 min

The cycle

  1. Requirement identified and a requisition raised.
  2. Authorised within delegated limits by someone other than the requester.
  3. Purchase order raised against an approved supplier, with agreed price and terms.
  4. Goods or services received, recorded against the order with a receipt note or a confirmation of work done.
  5. Invoice received and matched.
  6. Approved and posted to the correct account and cost centre.
  7. Paid in a controlled payment run on the due date.
  8. Reconciled against the supplier statement.

Supplier onboarding

Setting up a supplier is a control point, not an administrative task:

  • Verify the entity exists and is trading — registration details, address, and the correct legal name.
  • Verify bank details independently. Telephone a number obtained from a source other than the document supplying the details, and speak to a known contact.
  • Check tax registration and any required certification, licences or insurance.
  • Screen against sanctions lists where your jurisdiction requires it, and consider the relevant anti-bribery and modern slavery checks.
  • Record agreed payment terms, currency and contract reference.
  • Segregate duties: the person who creates or amends a supplier record must not be able to approve payments to it. This single control prevents the most common internal payment fraud.
  • Review the supplier master file periodically for duplicates, dormant records and suppliers sharing a bank account or address with an employee.

Invoice processing

  • Three-way match — purchase order, goods received note and invoice. Confirms that what was ordered was received and is what is being charged. Set tolerances for minor differences and investigate anything outside them.
  • Two-way match where no physical receipt exists, such as services, matching invoice to order with confirmation from the requisitioner.
  • Non-order invoices are the highest-risk category and should be minimised. Where unavoidable, require approval by someone with budget authority and independent evidence of receipt.
  • Duplicate detection — check supplier, invoice number, amount and date. Duplicate payment is the most common avoidable loss in payables, and it is almost always recoverable only if noticed.
  • Coding — correct account, cost centre, period and tax treatment. Miscoding distorts management reporting and tax recovery.
  • Accruals — goods received but not invoiced at period end must be accrued, or costs are understated.

Payments

  • Pay to terms in scheduled runs; ad hoc urgent payments outside the normal process are where control breaks down and where fraud is most often successful.
  • Require dual authorisation above defined thresholds, with authorisers independent of the person preparing the run.
  • Review the payment listing before release — unfamiliar payees, round amounts, new suppliers and amounts just below an approval threshold all deserve a second look.
  • Never change bank details on the instruction of an email alone, however convincing. Verify by calling a known number.
  • Keep an audit trail of who approved what and when.
1 of 9

Checking your enrolment…