ValueXPA

Guides

What an AP Recovery Audit Finds and Misses

A CFO's guide to what an AP recovery audit finds, what it misses, and why contract compliance and indirect spend audits close the gap. Read the full guide.

Margin drift is the gap between what a vendor contract says and what the invoice actually charges. An AP recovery audit is the tool most finance teams reach for first when they suspect they are leaving money on the table, and it does real work: it catches duplicate payments, vendor overbilling, missed credit memos, and rebates that were never applied.

But an AP recovery audit is retrospective by design. It looks backward at payments already made, across 12 to 18 months of historical spend. It was never built to test whether a surcharge schedule still matches the contract today, or whether next quarter's invoices will repeat the same error. Understanding where that boundary sits is what lets a CFO or AP lead choose the right engagement instead of assuming one audit covers everything.

What does an AP recovery audit actually find?

An AP recovery audit finds money already lost inside historical payment data: duplicate payments to the same vendor, invoices billed above the agreed rate, credit memos issued but never applied against a balance, and rebates a vendor owed but never paid. It works by reconciling payment history line by line against remittance records and contract terms, then flagging discrepancies for recovery.

The mechanism is reconciliation, not prediction. An auditor pulls a window of paid invoices, typically 12 to 18 months, and cross-references each payment against the purchase order, the remittance advice, and the vendor's own credit history. Where two payments match the same invoice number, amount, and vendor, that is a duplicate. Where a credit memo exists in the vendor's system but no matching credit appears in the client's ledger, that is unapplied.

This is real recovery. A duplicate payment found and clawed back is cash back in the bank, not a projection. The same is true of an unapplied rebate: the vendor already owes it, the audit just surfaces the claim.

What it does not do is tell you why the error happened, or whether the same vendor will bill the same way next month. It closes a specific, dated transaction. It does not change the process that produced it. That distinction is the entire reason a recovery audit and a contract compliance audit are different disciplines, even when the same invoices pass through both.

What does an AP recovery audit miss?

An AP recovery audit misses anything that requires reading the contract itself rather than the payment record: a surcharge that was correctly disclosed but never actually authorized by a rate card, a volume tier that should have triggered a lower rate months ago, or a not-to-exceed cap the vendor has been quietly billing past. These are compliance failures, not payment errors, and a payment reconciliation will not surface them.

A recovery audit works from what was paid. A rate card violation, by contrast, only shows up when someone reads the contract's rate table and compares it to the invoice line by line. Nothing about the payment itself looks wrong. The invoice was approved, matched to a purchase order, and paid on time. The error lives in the gap between the contract's terms and the number the vendor chose to bill.

The same is true of a volume tier that should have stepped the rate down, or an NTE cap the vendor drifted past a few dollars at a time. None of these produce a duplicate or a missing credit. They produce a rate that is technically invoiced and technically paid, and technically wrong.

A contract is often a PDF sitting outside the ERP entirely, with rebate clauses, surcharge schedules, and tier triggers that no payment system reads. Finding these requires matching the invoice against the contract's actual language, which is a different exercise than reconciling payment history.

Why can't AP automation software catch what a recovery audit misses either?

AP automation platforms prevent forward-looking errors at the point of invoice receipt, mainly duplicate entry and mismatches against the purchase order. They cannot interpret unstructured contract terms living in a PDF outside the ERP, such as a rebate clause, an NTE cap, or a volume tier trigger, because that logic was never built into the matching rule in the first place.

Three-way matching checks the invoice against the purchase order and the goods receipt. It does not test a surcharge's expiration condition, because no one entered that condition as a system rule. It does not know a volume tier exists, because the contract that defines the tier was never parsed into structured data.

This is not a flaw in the automation software. It is doing exactly what it was configured to do: catch quantity and price mismatches against a PO. The rate card, the rebate clause, and the tier trigger sit in a contract document the system was never given.

Building that rule requires someone to read the contract, extract the trigger condition, and translate it into logic the automation tool can enforce going forward. That translation work is what a contract compliance audit produces, and it is also the exact input an automation platform needs to close its own blind spot. The two are complementary, not competing.

How does a contract compliance audit close the gap a recovery audit leaves open?

A contract compliance audit matches every invoice line against the contract's actual rate card, volume tiers, rebate clauses, surcharge schedules, and not-to-exceed caps, rather than against payment history. It finds vendor overbilling that a recovery audit cannot see because the invoice was paid correctly against the PO but still violates a term the contract specifies.

The starting document is different. A recovery audit starts from the payment ledger. A contract compliance audit starts from the contract itself: the rate card, the tier schedule, the rebate terms, the surcharge conditions, the cap. Every invoice line is tested against that document, not against what was previously paid.

This catches drift a payment reconciliation structurally cannot see. A surcharge that was contractually tied to a fuel index and never adjusted when the index moved. A volume tier that should have dropped the unit rate after a threshold was crossed months ago. An NTE cap the vendor has been billing past in small increments that never individually look alarming.

This is general information about how contract terms are commonly structured in service vendor agreements, not legal advice about your specific contracts. Where a compliance question turns on contract law or enforceability, involve counsel.

Where does indirect spend audit work fit alongside recovery and compliance audits?

Indirect spend audit work applies the same invoice-to-contract discipline to categories that rarely get reviewed line by line: freight and 3PL, contract labor and staffing, maintenance and repair, IT and professional services, MRO and safety supply, and calibration. These categories carry recurring, easy-to-miss drift because they generate high invoice volume and low per-line dollar amounts, so no single line looks worth investigating alone.

Direct materials spend gets scrutiny because it flows through standard cost and shows up in gross margin immediately. Indirect service spend does not get the same attention by default, because freight accessorials, staffing markups, and maintenance labor rates arrive in smaller, more frequent invoices that individually look unremarkable.

That is precisely the condition margin drift needs to persist. A freight accessorial applied incorrectly on one invoice is a rounding error. Applied across a year of shipments, it becomes material. A staffing markup drifted above the contract rate reads the same way on any single invoice and compounds the same way over a contract term.

Covering these categories requires the same contract-first method as the compliance work described above: read the rate schedule, match it to the invoice, flag the difference. The categories differ in what documents govern them, freight tariffs versus staffing rate cards versus maintenance service agreements, but the audit discipline is identical across all of them.

Should a company run a recovery audit, a compliance audit, or both?

For a manufacturer above $100M in revenue with meaningful service vendor spend, running both in a single engagement finds more than either alone, because they look at different failure modes. Recovery audit work catches errors already paid. Compliance audit work catches errors that will keep recurring until the underlying rate logic is fixed. Combining them avoids paying twice for the same data-gathering step.

A company with a small service vendor footprint or a short history with its current vendors may get most of its value from a recovery audit alone. There is less historical spend to review and fewer long-running rate agreements to have drifted.

For a $100M-plus manufacturer with multiple service vendor categories under multi-year contracts, that calculation changes. The volume of invoices is large enough that reconciliation-only work leaves real spend unexamined, and contracts old enough to have accumulated tier changes, surcharge additions, and rate escalations no one re-verified against the original terms.

The case against running both together is cost and time: a combined scope takes longer to complete than a recovery-only engagement, and a smaller company may not have enough spend at risk to justify it.

Margin drift found across a full diagnostic typically runs 1% to 3% of service vendor spend, across ValueXPA diagnostics. A fixed-scope engagement covering both, with the client retaining 100% of what is found, is worth weighing against a narrower recovery-only engagement priced on contingency.

For the wider pattern this sits inside, start with the margin drift guide. See also shift and overtime premium misuse and freight and 3pl audit.

Common questions

Is an AP recovery audit the same thing as a contract compliance audit?

No. A recovery audit reconciles payment history to find errors already made, such as duplicate payments and unapplied credits. A contract compliance audit reads the contract itself, rate card, tiers, rebate clauses, surcharge schedules, and tests each invoice line against those terms. They use the same invoice data but start from different documents and catch different problems.

How far back does an AP recovery audit typically look?

A recovery audit reviews a window of historical payments, commonly 12 to 18 months, across ValueXPA diagnostics. That window is long enough to catch duplicate payments and unapplied credits within active vendor relationships, but it only examines transactions that already occurred.

Can our AP automation software find contract compliance errors on its own?

Not on its own. Three-way matching checks the invoice against the purchase order and the goods receipt. It does not read a rate card, a rebate clause, or an NTE cap sitting in a contract PDF outside the ERP, because that logic was never entered as a system rule. A contract compliance audit produces the rule the automation tool would need to enforce it going forward.

Will an AP recovery audit find rate card violations?

No. A rate card violation happens when an invoice is paid correctly against the purchase order but still bills above the rate the contract specifies. Nothing about the payment looks wrong, so a payment-history reconciliation will not flag it. Finding it requires comparing the invoice line to the contract's rate table directly.

What counts as indirect spend for this kind of audit?

Freight and 3PL, contract labor and staffing, maintenance and repair, IT and professional services, MRO and safety supply, and calibration. These are service vendor categories rather than direct materials, and they are audited using the same invoice-to-contract method as the compliance work described above.

Do we need a lawyer to run a contract compliance audit?

The audit itself is an invoice-to-contract matching exercise, not a legal review. This page is general information about how contract terms are commonly structured in service vendor agreements, not legal advice about your specific contracts. Where a finding turns on contract law or enforceability, involve counsel.

How is a fixed-scope diagnostic different from a contingency-fee recovery audit?

A contingency-fee recovery audit firm takes a share of whatever it recovers, commonly 25% to 50%, across the industry. A fixed-scope diagnostic charges a set fee and the client retains 100% of what is found. The fixed-scope model also covers compliance work a contingency firm has less incentive to do, since compliance findings prevent future overbilling rather than recovering past payments.

How long does a combined recovery and compliance engagement take?

A fixed-scope diagnostic covering both recovery and compliance work delivers a prioritized recovery and prevention roadmap in 2 to 4 weeks, across ValueXPA diagnostics.

Is a recovery-only audit enough for a smaller company?

It can be. A company with a small service vendor footprint or a short history with its current vendors has less historical spend to review and fewer long-running rate agreements that could have drifted, so a recovery audit alone may capture most of the available value without the added scope of a compliance review.

ValueXPA runs a fixed-scope Margin Drift Diagnostic that validates every service vendor invoice against contract terms. Two to four weeks, and you keep 100% of what is recovered.

Arrange a scoping call
Ask an assistant about this page: ChatGPTClaudePerplexityGemini