Compensating Control

A compensating control catches errors after the fact, when the control designed to prevent them at source is missing or fails. Written for finance and AP teams.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Compensating Control

A compensating control is a check that catches an error after it happens because the process step that should have prevented it does not exist or does not work. Margin drift is the gap between what a vendor contract says and what the invoice actually charges, and a compensating control exists because AP systems often cannot enforce contract terms directly at the point of invoice entry.

1. How does a compensating control differ from a preventive control?

A preventive control sits inside the transaction path and stops a bad invoice before it pays: a hard match rule that blocks approval when price exceeds the PO. A compensating control sits outside that path and finds the error after payment, by comparing the invoice against the contract terms separately. It exists specifically for terms the preventive control cannot see or enforce.

Purchase order matching is preventive for price and quantity. It is not preventive for a rate card tier, an index escalation clause, or a rebate threshold, because none of those terms are loaded into the PO. A compensating control fills exactly that space.

Executive Summary

A preventive control stops an error before it posts. A compensating control catches it afterward, on a schedule the business chooses: monthly, quarterly, at diagnostic time. Most AP systems run three-way matching against a purchase order and a receipt.

That step confirms quantity and unit price against the PO. It does not test a rate card's tier break, a rebate clause's trigger, or a not-to-exceed cap, because those terms live in a contract PDF the ERP never reads.

A compensating control closes that gap by comparing the invoice to the contract directly, independent of whatever the ERP approved. It does not require rebuilding AP. It requires someone, or some process, to reconcile the two documents on a cadence and act on the difference.

The tradeoff is timing: a compensating control finds drift after cash has already moved, so the recovery mechanism becomes a credit memo, a chargeback, or a rebate claim rather than a blocked payment.

2. Why do contract terms need a separate control at all?

Contract terms such as a volume tier, an accessorial cap, or a minimum commitment live in a PDF signed once and rarely revisited. The ERP enforces what was configured into it at setup, not what the contract says today. When a vendor's rate changes or a tier resets, the ERP keeps applying the old rule until someone updates it, and nothing in the transaction path flags the mismatch on its own.

That gap is structural, not a process failure at one company. A rate card and a purchase order are two different documents maintained on two different schedules.

3. What does a compensating control actually check?

A compensating control checks the terms a purchase order cannot: rate card tiers, not-to-exceed caps, minimum commitments, and whether promised credits or rebates were actually applied. Each of these is written into the contract, not the ERP, so nothing prevents an invoice from ignoring the term unless someone compares the two documents directly, line by line.

The list below is not exhaustive. Any clause the ERP does not encode needs the same treatment: a manual or scheduled comparison against the source document.

  • Rate and tier terms: Confirms the invoiced unit price matches the contracted rate card at the volume tier the period's actual spend earned.
  • Caps and commitments: Tests billed amounts against a not-to-exceed cap or a minimum commitment clause the PO never encoded.
  • Credits and rebates: Checks whether a promised credit memo or rebate was actually applied, since the ERP has no trigger to flag a missing one.

4. Where should a compensating control sit in the AP process?

A compensating control runs outside the invoice approval path, on a recurring cycle, comparing a batch of paid or pending invoices against the relevant contract clauses. It can run monthly as an internal review or as a defined-scope diagnostic covering a longer look-back period. Either way it is a detection step, not a gate, so it never blocks a payment on its own.

Placing it outside the approval path is deliberate. A gate that halts every invoice for manual contract review would stall AP entirely.

For the wider pattern this sits inside, start with the margin drift guide.

5. Frequently Asked Questions (People Also Ask)

Is a compensating control the same as an internal control weakness?

No. A compensating control is a designed response to a gap, not evidence that AP is broken. It is common practice wherever a system cannot enforce a rule directly, and it is a normal part of a contract compliance program.

Does three-way matching count as a compensating control?

Three-way matching is preventive for quantity and PO price. It becomes a compensating control only when someone also uses it, after the fact, to check terms the PO never captured, such as a rate card tier or an accessorial cap.

How often should a compensating control run?

That depends on invoice volume and the terms being checked. Some companies run a monthly reconciliation; others rely on a periodic diagnostic covering a longer window. The choice is about cadence, not whether the control is needed.

Can a compensating control recover money already paid?

Yes, that is its main output. Because it runs after payment, the recovery mechanism is a credit memo, a chargeback, or a rebate claim rather than a blocked invoice.

What is the downside of relying only on compensating controls?

Cash has already moved by the time the error is found, so recovery takes negotiation with the vendor instead of a simple hold. A preventive control, where feasible, avoids that step entirely.

Does a compensating control require new software?

No. It requires comparing two documents, the invoice and the contract, on a defined schedule. That can be a manual review, a spreadsheet process, or a structured diagnostic engagement.

Who typically owns a compensating control in AP?

Ownership varies by company: some assign it to AP, some to procurement, some to controllership. What matters is that someone owns the comparison, since no system performs it automatically.

Is a compensating control specific to freight or does it apply broadly?

It applies to any category with contract terms an ERP does not enforce directly, including freight, contract labor, maintenance, and professional services.

1. How does a compensating control differ from a preventive control?

A preventive control sits inside the transaction path and stops a bad invoice before it pays: a hard match rule that blocks approval when price exceeds the PO. A compensating control sits outside that path and finds the error after payment, by comparing the invoice against the contract terms separately. It exists specifically for terms the preventive control cannot see or enforce. Purchase order matching is preventive for price and quantity. It is not preventive for [a rate card](/glossary/rate-card) tier, an index escalation clause, or a rebate threshold, because none of those terms are loaded into the PO. A compensating control fills exactly that space. Executive Summary A preventive control stops an error before it posts. A compensating control catches it afterward, on a schedule the business chooses: monthly, quarterly, at diagnostic time. Most AP systems run three-way matching against a purchase order and a receipt. That step confirms quantity and unit price against the PO. It does not test a rate card's tier break, a rebate clause's trigger, or [a not-to-exceed cap](/glossary/not-to-exceed-overrun), because those terms live in a contract PDF the ERP never reads. A compensating control closes that gap by comparing the invoice to the contract directly, independent of whatever the ERP approved. It does not require rebuilding AP. It requires someone, or some process, to reconcile the two documents on a cadence and act on the difference. The tradeoff is timing: a compensating control finds drift after cash has already moved, so the recovery mechanism becomes a credit memo, a chargeback, or a rebate claim rather than a blocked payment.

2. Why do contract terms need a separate control at all?

Contract terms such as a volume tier, an accessorial cap, or a minimum commitment live in a PDF signed once and rarely revisited. The ERP enforces what was configured into it at setup, not what the contract says today. When a vendor's rate changes or a tier resets, the ERP keeps applying the old rule until someone updates it, and nothing in the transaction path flags the mismatch on its own. That gap is structural, not a process failure at one company. A rate card and a purchase order are two different documents maintained on two different schedules.

3. What does a compensating control actually check?

A compensating control checks the terms a purchase order cannot: rate card tiers, not-to-exceed caps, minimum commitments, and whether promised credits or rebates were actually applied. Each of these is written into the contract, not the ERP, so nothing prevents an invoice from ignoring the term unless someone compares the two documents directly, line by line. The list below is not exhaustive. Any clause the ERP does not encode needs the same treatment: a manual or scheduled comparison against the source document. - Rate and tier terms: Confirms the invoiced unit price matches the contracted rate card at the volume tier the period's actual spend earned. - Caps and commitments: Tests billed amounts against a not-to-exceed cap or [a minimum commitment clause](/glossary/minimum-commitment-shortfall) the PO never encoded. - Credits and rebates: Checks whether [a promised credit memo](/glossary/missed-credit-memo) or rebate was actually applied, since the ERP has no trigger to flag a missing one.

4. Where should a compensating control sit in the AP process?

A compensating control runs outside the invoice approval path, on a recurring cycle, comparing a batch of paid or pending invoices against the relevant contract clauses. It can run monthly as an internal review or as a defined-scope diagnostic covering a longer look-back period. Either way it is a detection step, not a gate, so it never blocks a payment on its own. Placing it outside the approval path is deliberate. A gate that halts every invoice for manual contract review would stall AP entirely. For the wider pattern this sits inside, start with the [margin drift](/insights/margin-drift-spend-leakage-guide) guide.

Questions & Answers

Is a compensating control the same as an internal control weakness?

No. A compensating control is a designed response to a gap, not evidence that AP is broken. It is common practice wherever a system cannot enforce a rule directly, and it is a normal part of a contract compliance program.

Does three-way matching count as a compensating control?

Three-way matching is preventive for quantity and PO price. It becomes a compensating control only when someone also uses it, after the fact, to check terms the PO never captured, such as a rate card tier or an accessorial cap.

How often should a compensating control run?

That depends on invoice volume and the terms being checked. Some companies run a monthly reconciliation; others rely on a periodic diagnostic covering a longer window. The choice is about cadence, not whether the control is needed.

Can a compensating control recover money already paid?

Yes, that is its main output. Because it runs after payment, the recovery mechanism is a credit memo, a chargeback, or a rebate claim rather than a blocked invoice.

What is the downside of relying only on compensating controls?

Cash has already moved by the time the error is found, so recovery takes negotiation with the vendor instead of a simple hold. A preventive control, where feasible, avoids that step entirely.

Margin Drift Resources