Accounts Payable Internal Controls: A Checklist
Jun 17, 2026
Try it now: upload an invoice and get a clean Excel or CSV file in seconds.
PDF, JPG, PNG, BMP, HEIC, TIFF
Upload your invoices
Drop files here or click to upload
Up to 50 files
Uploading...
Accounts payable internal controls are the rules and checks that make sure every dollar your company pays out is for a real, approved, correctly priced purchase. Done well, they stop duplicate payments, catch fake or inflated invoices, and keep your books audit-ready. Most of the friction in running these controls is not the controls themselves, it is the manual data entry that feeds them: someone has to get the numbers off the invoice before anyone can match, verify, or flag them. If that retyping is your bottleneck, drop your PDF or image invoices into the converter at the top of this page to get clean Excel or CSV rows in seconds, then run your checks against structured data. This guide covers what AP internal controls are, why they matter, the core controls (including segregation of duties and duplicate-payment prevention), a practical checklist, the main fraud risks, and how automation strengthens the whole system.
What are internal controls for accounts payable?
Accounts payable internal controls are the policies, approvals, and verification steps that govern how invoices are received, validated, approved, and paid. Their purpose is to make sure payments go only to legitimate vendors for goods or services actually received, at the agreed price, once. They protect cash, prevent fraud and error, and keep financial records accurate and auditable.
In practice the controls span the full payable lifecycle. A purchase is authorized, goods or services are received and confirmed, the vendor invoice is captured and checked against the purchase order and receiving record, an authorized approver signs off, and only then is a payment released and reconciled. Each handoff is a control point. Weak controls at any one of them are where money leaks, through a duplicate bill that gets paid twice, a price that quietly drifts above the quote, or an invoice from a vendor nobody set up.
Why are accounts payable internal controls important?
AP internal controls matter because accounts payable is where most outbound cash and most payment fraud risk sit. Strong controls prevent duplicate and erroneous payments, block fictitious-vendor and inflated-invoice schemes, keep the general ledger accurate for reporting and audits, and give finance leaders confidence that the numbers on the balance sheet reflect real obligations.
The cost of weak controls is concrete. Duplicate payments alone typically run between a tenth of a percent and a full percent of total AP spend, and recovering an overpayment after the fact is slow and sometimes impossible. Beyond the direct loss, sloppy AP records mean a harder year-end audit, more adjusting entries, and a real opening for both external fraudsters and internal misuse. Controls turn accounts payable from a soft target into a checkpoint.
What is segregation of duties in accounts payable?
Segregation of duties means no single person can complete a payment alone. The tasks of setting up a vendor, entering an invoice, approving it, and releasing the payment are split across different people, so committing fraud or hiding an error would require collusion. It is the single most important AP control because it removes the lone path most schemes rely on.
A common split is one person who maintains the vendor master file, a second who enters and approves invoices, and a third who runs and signs the payments, with reconciliation handled by someone outside that chain. In a small team where one person wears several hats, you compensate with other controls: a manager who reviews and approves the payment run, role-based system access so the invoice clerk cannot edit bank details, and a monthly review by the owner or an outside bookkeeper. The goal is the same at any size, which is that initiating, approving, and paying never live in one set of hands.
What are preventive and detective controls in AP?
Preventive controls stop a bad transaction before money moves: approval limits, three-way matching, vendor-master validation, and required purchase orders. Detective controls catch problems after the fact: monthly reconciliations, duplicate-payment audits, exception reports, and statement reviews. A healthy AP function uses both, because no preventive control is perfect and the detective layer is your safety net.
Think of it as two lines of defense. Preventive controls do the heavy lifting day to day, refusing to route an invoice for payment until it matches a PO and a receiving record and carries the right approval. Detective controls then sweep the period for anything that slipped through, such as two invoices with the same number and amount, a payment to a vendor added the same week it was paid, or a balance that does not tie to the vendor statement. When a detective control keeps finding the same issue, that is a signal to add or tighten a preventive one upstream.
How do you prevent duplicate payments?
Prevent duplicate payments by enforcing a unique vendor invoice number, recording each invoice in the system only after proper approval, and running automated duplicate checks that flag matching vendor, amount, invoice number, and date before a payment is released. A clean, deduplicated vendor master file removes the second-most-common cause, which is the same supplier set up twice under slightly different names.
Duplicates creep in through ordinary chaos: an invoice arrives by email and by mail, a copy gets entered while the original sits unposted, or a statement balance gets paid on top of the individual bills. The fix is structure. When invoice data lives in clean rows rather than scattered PDFs, a simple check on invoice number plus amount surfaces repeats instantly, and a COUNTIF in a spreadsheet does the same job for a smaller shop. Our guide to duplicate invoice detection walks through the spreadsheet and software methods in detail.
What should be on an accounts payable internal controls checklist?
An accounts payable internal controls checklist should confirm that duties are segregated, vendors are verified before setup, every invoice is matched to a PO and receiving record, approvals follow a documented authority matrix, duplicate and exception checks run before payment, bank-detail changes are independently verified, and accounts are reconciled monthly with an audit trail retained for every transaction.
A working checklist usually includes these items:
- Segregation of duties: vendor setup, invoice entry, approval, and payment are handled by different people.
- Vendor validation: new vendors are verified (tax ID, address, bank details) and the master file is reviewed for duplicates and dormant records.
- Three-way matching: invoices are matched to the purchase order and the receiving report before approval. See our three-way matching guide.
- Approval authority matrix: dollar thresholds determine who can approve, with larger amounts requiring senior sign-off.
- Duplicate and exception checks: automated flags for repeated invoice numbers, price variances, and out-of-tolerance amounts.
- Bank-change verification: any change to a vendor's payment details is confirmed through a known contact, not the email that requested it.
- Reconciliation and audit trail: the AP ledger is reconciled to the general ledger and to vendor statements monthly, with documentation kept for every step.
What are the main accounts payable fraud risks?
The main AP fraud risks are fictitious or shell vendors set up to receive payments, duplicate and inflated invoices, billing-scheme collusion between an employee and a supplier, and business email compromise where a fraudster poses as a vendor and requests a change of bank account. Most of these succeed only when controls are weak or one person controls too much of the process.
Business email compromise deserves special attention because it bypasses the invoice entirely. A convincing email asks AP to update a vendor's banking details, the next legitimate payment routes to the fraudster, and the loss is often large and hard to recover. The control is simple and non-negotiable: verify every banking change through a phone number you already have on file, never the contact information in the request. Pair that with vendor-master discipline and segregation of duties, and the common schemes lose their footing.
How does automation strengthen accounts payable controls?
Automation strengthens AP controls by enforcing them consistently instead of relying on memory. Software can require a matching PO before routing an invoice, apply approval thresholds automatically, flag duplicates and price variances in real time, lock down access by role, and timestamp every action into an audit trail. It also removes the manual data entry that introduces errors in the first place.
The capture step is where automation pays off first. When invoices are still PDFs and images, someone retypes the vendor, invoice number, dates, line items, and totals, and every keystroke is a chance for the error a control later has to catch. Turning those documents into clean structured data with AI invoice data extraction and line-item extraction gives every downstream control accurate inputs, which is why teams looking to reduce invoice processing costs and automate accounts payable data entry usually start here. Once approval routing, payment execution, and policy enforcement become the priority, a full accounts payable automation platform handles the workflow end to end. For the capture and verification groundwork, you can extract invoice data to Excel and feed clean rows into whatever controls you run today.
Who is responsible for accounts payable internal controls?
Responsibility is shared. The AP team and its manager run the day-to-day controls, the controller or finance director designs the control framework and approves policy, department managers approve their own purchases within set limits, and internal or external auditors test that the controls actually work. Ownership sits with finance leadership, but the controls only hold if everyone in the chain follows them.
For a small business, much of this collapses onto one or two people, which is exactly when written procedures and software-enforced rules matter most. Document who approves what, set role-based access so the system itself prevents the wrong person from acting, and bring in an outside reviewer for a monthly look. Controls that depend on one trusted person remembering to do the right thing are not controls. The work that builds them is the same boring discipline every month, and it is what stands between your cash and an avoidable loss.