Guides
Continuous Enforcement vs. Periodic Audit: Cadence
How to choose between continuous contract-to-invoice enforcement and periodic margin drift audits, and where the two cadences fit together on the calendar.
Margin drift is the gap between what a vendor contract says and what the invoice actually charges. Once a manufacturer decides to close that gap, the next question is rarely whether to check contracts against invoices. It is how often.
Two cadences answer that question differently. One reviews a defined spend population on a set schedule. The other checks every invoice against contract terms as it arrives. Neither is universally right, and the choice depends on what kind of drift a company is trying to catch and what it can staff to catch it.
Executive Summary
The real choice is not continuous versus periodic. It is which drift types each cadence is built to catch, and whether a company has the control infrastructure a continuous check requires before it can rely on one.
A periodic audit, run quarterly or annually, is a deliberate, resourced look back across a defined population of invoices. It finds drift that has already accumulated: rate cards that expired unnoticed, surcharges that never sunset, rebates never applied. A continuous check tests each invoice at the point it enters AP, against the contract terms live at that moment. It stops new drift from accumulating but does not, by itself, recover what already happened.
Manufacturers above $100M generally need both, on a schedule matched to the maturity of their contract data. Start with a periodic audit to establish a baseline and quantify the leakage. Use what it finds to decide which categories are stable enough to check on every invoice and which still need a scheduled human review.
1. How often should a manufacturer check vendor invoices against contract terms?
The right frequency depends on the drift type, not a fixed calendar rule. Category and drift type each carry different decay characteristics, and treating every vendor category on the same clock is itself a control gap. A single fixed schedule, whether monthly or annual, misses drift that accumulates quickly in one category and wastes review effort on a category that barely moves.
A rate card negotiated once a year and never re-uploaded creates drift that compounds every month it sits unchecked, which argues for catching it as invoices arrive rather than waiting for a review cycle. A surcharge that should have expired on a contract anniversary behaves the same way: every invoice after the sunset date repeats the same error.
Other drift types do not behave that way. A volume tier misapplication only becomes visible once a quarter's purchase volume is known, so checking it invoice by invoice adds no value; it has to wait for the period to close. A vendor master duplicate is a structural problem in the AP system itself, not a per-invoice event, and gets caught by a review of the vendor file, not the invoice stream.
The practical answer is to map each category and drift type to the cadence that actually fits its mechanics, rather than picking one calendar and applying it everywhere. That mapping is itself the output of the first periodic audit a company runs.
2. What does continuous enforcement actually catch that a periodic audit misses?
Continuous enforcement catches drift at the moment it enters the AP system, before payment, which means the error never compounds across a review period. A periodic audit finds the same error only after months of invoices have already been paid at the wrong rate. The value of continuous checking is prevention timed to the invoice, not detection after the fact.
The mechanism is simple: every invoice is matched against the contract terms live at the moment it is received, not against terms that were current when a reviewer last looked. This closes the specific window where a price file goes stale between uploads, or a surcharge outlives the clause that authorized it.
What it does not do is look backward. It has no way to recover a payment already made under a rate that expired eight months ago; that recovery still requires someone to pull the historical invoices and compare them to the contract archive, which is periodic-audit work by definition.
3. What does a periodic audit catch that continuous enforcement misses?
A periodic audit recovers drift that already happened across 12 to 18 months of historical spend, across ValueXPA diagnostics, work a point-in-time invoice check cannot do because the invoices are already paid. It also reads unstructured contract terms sitting in PDFs outside the ERP, a task that depends on judgment, not just automated matching against a rule already loaded into a system.
Rebate clauses, minimum volume commitments and NTE caps are frequently written in prose, in a signed PDF, not encoded anywhere a system can check automatically. A periodic audit puts a person against that document, extracts the actual trigger conditions, and builds the reference table a continuous check would need before it can enforce anything.
That means periodic review is not a lesser version of continuous enforcement waiting to be automated. It is the step that produces the structured rules continuous enforcement depends on. A company that tries to run continuous checks without ever doing this reading work is checking invoices against whatever rules happened to get typed into the system, not against what the contract actually says.
4. What does each cadence cost to run?
A periodic audit is a bounded, staffed engagement with a defined start and end date, so its cost is visible and finite. Continuous checking requires ongoing infrastructure: a maintained price file, a maintained vendor master, and a process for keeping contract terms current as they are renegotiated. Its cost is smaller per invoice but never ends.
The comparison matters most at the point a company decides to build continuous checking in-house rather than run periodic reviews indefinitely. Continuous enforcement only produces accurate results if the underlying reference data stays current, and keeping a price file, a rate card, and a surcharge sunset date current is itself an ongoing task, not a one-time setup.
What each cadence requires to run, independent of any specific tool.
| Requirement | Periodic audit | Continuous check | | --- | --- | --- | | Staffing pattern | Scoped engagement, defined end date | Ongoing, never fully off | | Data dependency | Historical invoice and contract archive | Live, current price file and contract terms | | Output | A recovery finding and a roadmap | A stopped error, before payment | | Best suited to | Drift already accumulated | Drift that recurs invoice by invoice |
5. How do continuous enforcement and periodic audit work together instead of competing?
The two are sequential, not competing. A periodic audit first quantifies leakage and builds the structured rule set from contract language. Continuous checking then holds the line on that rule set going forward, on the categories where per-invoice checking is mechanically useful. Without the first step, the second has nothing accurate to enforce against.
This is also where the roadmap from an AP recovery audit becomes actionable rather than a one-time report. The findings identify which categories drifted and why: a stale price file, an unsunset surcharge, a duplicate vendor record. Each of those has a specific fix, and some of those fixes are process changes, not new checking infrastructure.
A company does not need continuous checking on every category to get the benefit of this sequence. It needs it on the categories where the audit found the same error repeating month after month, and a periodic review on the categories where drift only becomes visible once a period closes.
6. Which cadence fits a company's current stage of control maturity?
A company with no prior contract compliance review should start with a periodic audit, because it has no baseline and no structured rule set yet to check continuously against. A company that has already run one or more audits and fixed the structural gaps they found is in a better position to add continuous checks on specific categories.
The sequence below reflects that dependency rather than a fixed timeline, since the pace depends on what the first audit finds and how quickly the fixes it recommends get implemented.
- Run a first periodic audit: Establish the baseline: what has drifted, in which categories, and why. This produces the recovery finding and the rule set.
- Fix the structural gaps it finds: Vendor master duplicates, stale price files, and missing surcharge sunset dates get corrected before any per-invoice check is built on top of them.
- Add per-invoice checks on stable categories: Categories with a clear, structured contract rule and a recurring error pattern are the ones worth checking continuously first.
- Keep a periodic review on the rest: Categories that depend on period-close data, like volume tiers, stay on a scheduled review rather than a per-invoice check.
- Repeat the periodic audit on a cycle: Even with continuous checks in place, a scheduled review catches new contract terms and categories the continuous check does not yet cover.
For the wider pattern this sits inside, start with the margin drift guide.
Common questions
Is continuous enforcement a replacement for a periodic contract compliance audit?
No. Continuous enforcement stops new errors on invoices going forward. It does not recover money already paid under stale rates, and it cannot read unstructured contract terms in a PDF on its own. A periodic audit does both of those, and its findings are what a continuous check needs to enforce accurately.
How often should a periodic margin drift review happen once continuous checks are in place?
On a recurring cycle, commonly quarterly, even after continuous checks cover the stable categories. New contracts, renegotiated rates, and categories not yet under continuous coverage still need a scheduled human review, which is the pattern a quarterly margin drift review is built around.
Which drift types are better suited to continuous checking than periodic review?
Drift types tied to a single invoice event, such as a surcharge that should have sunset or a price file that went stale, are checkable at the point the invoice arrives. Drift types that depend on a period closing, such as volume tier calculations, cannot be resolved until that period's data exists.
Do we need clean contract data before we can run continuous checks?
Yes. Continuous checking is only as accurate as the reference rules loaded into it. Vendor master hygiene, a current price file, and correctly dated surcharge clauses all need to be in place first, or the continuous check enforces the wrong terms with the same confidence as the right ones.
What does a periodic audit cost compared to running continuous checks?
A periodic audit is a scoped, fixed-scope engagement with a defined start and end date. Continuous checking is not a one-time cost; it depends on maintaining current contract and price data indefinitely, which is a standing process commitment, not a project.
Can a smaller AP team run both cadences at once?
Most teams start with one periodic audit, use its findings to fix the structural gaps in vendor and price data, and only then add continuous checks on the categories where the audit found a recurring, well-structured error. Running both from day one without that sequence tends to enforce inaccurate rules.
Does continuous enforcement catch rebate leakage the same way it catches surcharge errors?
Not in the same way. A surcharge sunset date is a single, checkable condition on an invoice. A rebate clause usually depends on cumulative volume across a period and requires the underlying calculation to be tracked separately, which makes it closer to periodic-review work even when checked frequently.
What should the first periodic audit focus on if a company has never run one?
The categories where invoice-to-contract matching is most likely to be broken: freight and 3PL, contract labor, and maintenance and repair are common starting points, since each carries rate cards, tiers, or NTE caps that are easy to misapply without producing an obviously wrong invoice.
ValueXPA runs a fixed-scope Margin Drift Diagnostic that validates every service vendor invoice against contract terms. Two to four weeks, and you keep 100% of what is recovered.
Arrange a scoping call