Three-Way Match in Accounts Payable: Tolerances, Fraud, and Automation

The three-way match in accounts payable is a control that compares three documents before a vendor invoice gets paid: the purchase order the company issued, the receiving report confirming what actually arrived, and the invoice the vendor sent. If all three agree on quantities and prices, the invoice clears for payment. If they disagree, the invoice sits on hold until someone reconciles the difference. That single checkpoint is what stops overbilling, duplicate payments, and fabricated invoices from turning into money out the door.

The Three Documents Being Compared

Each of the three records comes from a different point in the transaction, and that separation is what gives the match its teeth.

The purchase order is issued by the buyer to the seller. It specifies the items or services requested, quantities, agreed prices, and delivery terms, and once the seller confirms or begins fulfilling it, the PO functions as a binding agreement.1University System of New Hampshire. PO vs. Contract – Section: Purchase Order (PO)

The receiving report is generated by the buyer’s warehouse or receiving team when goods physically arrive. It records what was delivered, in what quantity, and whether anything showed up damaged. This document lives entirely inside the buyer’s organization, independent of whatever the vendor claims was shipped.

The vendor invoice is the seller’s formal request for payment. It lists items, quantities, unit prices, taxes, and payment terms such as Net 30 or Net 60, meaning the buyer has that many days from receiving the invoice to pay.2U.S. Chamber of Commerce. What Are Net Payment Terms – Section: What are net terms?

The purchase order reflects what was authorized. The receiving report reflects what was delivered. The invoice reflects what the vendor wants paid. Matching them forces agreement across all three independent sources before a check gets cut.

How the Match Actually Runs

The first comparison lines up the purchase order against the receiving report. Accounts payable checks whether the quantity received matches the quantity ordered. Fewer units than the PO specified means a partial shipment. More units than ordered means something went wrong upstream. Either way, the discrepancy has to be resolved before the invoice moves forward, because nobody wants to pay for inventory that never reached the building.

The second comparison brings in the vendor invoice. Unit prices on the invoice are checked against the rates locked into the purchase order. Quantities billed are checked against what the receiving report says arrived. If all three documents line up on both quantities and prices, the system marks the invoice approved and records it as a liability scheduled for payment.

When the numbers don’t line up, the invoice gets flagged for manual review. Someone has to figure out whether the vendor billed the wrong price, shipped the wrong quantity, or whether the receiving team miscounted. The flag prevents payment while the discrepancy is open, and that hold is the entire point of the control.

Tolerance Thresholds for Small Discrepancies

Perfect matches happen less often than you might expect. Rounding, shipping cost changes, and small price adjustments between when a PO was issued and when the invoice arrived can produce differences of a few cents or a few dollars. Flagging every one for manual review would bury the AP team in trivial exceptions.

Most organizations set tolerance thresholds, small bands of acceptable variance that let invoices clear automatically.3Microsoft Learn. Accounts Payable Invoice Matching Overview These can be defined as a percentage, a flat dollar amount, or both. A company might allow a 1–2% price variance or a $50 absolute difference, whichever is smaller. Invoices inside the threshold pass; invoices outside it go on hold.4Oracle Documentation. Invoice Tolerances

Setting the threshold is a judgment call. Too tight and the AP team spends its day chasing pennies. Too loose and real pricing errors slip through. Tolerances can also be configured differently by vendor, item category, or dollar value. A 2% variance on a $200 order is $4, but on a $200,000 order it is $4,000, which might warrant human review regardless of the percentage.3Microsoft Learn. Accounts Payable Invoice Matching Overview

When a discrepancy exceeds the threshold, AP contacts the purchasing team or the vendor. Resolution usually means the vendor issues a credit memo adjusting the balance, or the buyer’s receiving team recounts and updates the receiving report. The invoice stays on hold until then.

Handling Partial Shipments

Vendors don’t always ship everything at once, and the match has to accommodate that. When a purchase order covers 500 units but only 300 arrive in the first delivery, the system tracks cumulative receipts against the total PO rather than treating each shipment as a standalone.

For partial shipments, AP approves payment only for the quantity confirmed by the receiving report. The purchase order stays open for the remaining balance. Later deliveries generate their own receiving reports, and each batch goes through the same match against the original PO terms. The order closes only when the full quantity has been received and paid, or the company formally cancels the remaining balance.

Quality disputes add a wrinkle. If 300 units arrive but 20 are damaged, the damaged portion typically routes to a separate dispute workflow while payment proceeds for the 280 acceptable units. Holding up the full payment over a small defective portion strains vendor relationships without adding protection.

When Two-Way or Four-Way Matching Is Used Instead

Three-way is the standard for physical goods, but it is not the only option, and knowing where it doesn’t apply matters as much as knowing how it works.

A two-way match compares only the purchase order against the vendor invoice. It works for services, subscriptions, or other low-risk purchases where there is nothing physical to receive and inspect. A receiving report would be meaningless, so the control drops back to authorization plus billing.

A four-way match layers an inspection report on top of the other three. Beyond confirming that items arrived, someone verifies they meet quality standards, recording how many units were accepted and how many rejected. Industries with strict quality tolerances, such as manufacturing and pharmaceuticals, use this level.

The matching level is typically set at the purchase order level when the order is created, so high-value or high-risk purchases can carry tighter controls without slowing routine procurement.

Fraud Schemes the Match Catches

The three-way match exists because the most common accounts payable fraud schemes all exploit gaps in document verification.

  • Fictitious invoices. A fraudster submits an invoice for goods or services that were never ordered and never delivered. There is no PO and no receiving report to validate the claim, so the match blocks it.
  • Shell company billing. An employee sets up a fake vendor and submits invoices through it. Without a legitimate PO tied to an approved vendor and a receiving report confirming delivery, the invoice can’t clear the match.
  • Inflated invoices. A real vendor, sometimes colluding with an employee, bills higher prices or larger quantities than were agreed and delivered. The PO catches the price inflation and the receiving report catches the quantity inflation.
  • Duplicate billing. The same invoice is submitted twice, either deliberately or by mistake. Matching against the PO’s remaining open balance shows the goods were already paid for.

What makes any of this work is separation of duties. The person who authorizes the purchase, the person who receives the goods, and the person who processes payment should be three different people. When one individual controls multiple steps, the match loses much of its protective value because that person can fabricate consistent documents across all three stages.5GSA Office of Inspector General. Procurement Fraud Handbook

Automating the Match

Manual matching, pulling paper documents and comparing line items by hand, still happens at smaller organizations, but it is slow and error-prone. Most mid-size and large companies use AP automation software that ingests purchase orders, receiving reports, and invoices electronically, runs the comparisons, and routes exceptions to the right people.

Automated systems handle tolerances, partial shipment tracking, and cumulative PO balances without human intervention on clean matches. The AP team only gets involved when something doesn’t line up. Companies processing thousands of invoices monthly see the biggest gains: fewer late payments, fewer duplicate payments, and lower per-invoice processing cost. The shift also produces a digital audit trail that is far easier to review than a filing cabinet of paper.

Automation only works as well as the data going in. Vague purchase orders, item descriptions that don’t match between systems, or receiving staff who don’t enter receipts promptly will cause the system to flag everything as an exception, and the team ends up doing manual work anyway. Clean master data and disciplined receiving are prerequisites, not extras.

Records Retention and Regulatory Stakes

A completed match generates a paper trail that has to be preserved long after payment. The IRS requires businesses to keep records supporting any item of income, deduction, or credit on a tax return until the applicable statute of limitations expires.6Internal Revenue Service. How Long Should I Keep Records For most business expense deductions, that means holding purchase orders, invoices, and receiving reports for at least three years after filing the return that claimed the deduction.7Office of the Law Revision Counsel. United States Code Title 26 – 6501 Limitations on Assessment and Collection The window stretches to six years if unreported income exceeds 25% of gross income shown on the return, and there is no time limit at all if a return was fraudulent or never filed.

To substantiate a business expense, records must show the payee, the amount paid, proof of payment, the date, and a description of what was purchased.8Internal Revenue Service. What Kind of Records Should I Keep A completed three-way match naturally produces all of these elements. The purchase order identifies the payee and items, the receiving report confirms delivery, and the invoice plus payment record establish the amount and date. Companies that skip the match often find themselves reconstructing these details under audit pressure.

Publicly traded companies carry an additional layer. Section 404 of the Sarbanes-Oxley Act requires management to assess and report annually on internal controls over financial reporting, and an independent auditor must attest to that assessment.9U.S. Securities and Exchange Commission. Study of the Sarbanes-Oxley Act of 2002 Section 404 Internal Control Over Financial Reporting Requirements A functioning three-way match is one of the AP controls auditors look for. A material weakness in AP controls can trigger a negative audit opinion, which is public.

Federal contractors have their own reason to care about how quickly the match runs on the agency side. The Prompt Payment Act requires federal agencies to pay valid vendor invoices on time, with interest penalties that accrue automatically when they don’t, at a rate recalculated every six months.10Bureau of the Fiscal Service. Prompt Payment11Office of the Law Revision Counsel. United States Code Title 31 – 3903 Regulations Document mismatches that hold up the agency’s match can push payment past the deadline. Clean invoice documentation that flows through verification without exceptions is the fastest way to get paid.