How do you audit IT and professional services invoices

A practical framework for auditing IT and professional services invoices: matching SOWs to timesheets, rates, milestones, and scope before paying.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
How do you audit IT and professional services invoices

IT and professional services invoices are hard to audit because the deliverable is labor, not units, and labor is easy to mislabel.

Auditing them means checking the invoice against the SOW, the rate card, and the actual work performed, not just the math on the page.

Executive Summary

Auditing IT and professional services invoices means verifying four things on every invoice: that the resource billed is the resource contracted, that the rate matches the master agreement, that the hours or milestones map to approved scope, and that nothing has drifted from the original statement of work. Because these engagements are billed on time and deliverables rather than physical units, the usual three-way match against a purchase order and receipt doesn't catch most of the problems. A consultant can be logged correctly and still be the wrong person at the wrong rate doing work nobody approved.

The practical approach starts with the contract documents, not the invoice: pull the SOW, the rate card, and any change orders before looking at a single line item. From there, an auditor checks resource identity against approved staffing plans, rates against the card, hours against milestones or timesheets, and scope against the original SOW language.

Each of these failure modes has a distinct signature, and catching them requires different evidence. An approved timesheet says nothing about whether the rate applied to it was correct, and a correct rate says nothing about whether the person billing it was ever approved to work the engagement.

1. 1. What documents do you need before starting the audit?

Before touching an invoice, collect the signed SOW, the current rate card, the staffing plan or resource approvals, and any change orders. Without these documents, an invoice looks like a set of numbers instead of a set of claims you can verify against a contract. Each document tests a different part of the invoice: the SOW tests scope, the rate card tests price, the staffing plan tests who is allowed to bill, and change orders test whether expanded work was.

Most invoice review starts and ends with the invoice itself, checking math and totals. That catches almost nothing in professional services, where the risk isn't arithmetic, it's whether the billed work was ever authorized at that rate, by that person, for that scope.

Pull the baseline documents first: the SOW defining deliverables and milestones, the rate card by role and level, the approved staffing roster, and every amendment since signing. Treat the invoice as a claim to be tested against these, not a document to be read alone.

2. 2. How do you verify the resource billed is the resource approved?

Match every named consultant or contractor on the invoice against the approved staffing plan or statement of work roster. Vendors substitute personnel to manage utilization, and substitutions often carry a different, unapproved rate. This check happens at the person level, not the role level, so confirming a title matches is not enough; the specific individual has to be named in the SOW or a signed amendment before their hours are payable.

Vendors reassign staff for their own scheduling reasons far more often than clients realize. A senior architect approved for a project can be swapped for a junior resource billed at the senior rate, or the reverse can occur where scope requires seniority nobody is providing.

Confirm names against the roster, and flag any resource appearing on an invoice who was never named in the SOW or its amendments. This overlaps with, but is distinct from, off-contract billing generally, see off-contract resources for the broader pattern.

3. 3. How do you check that billed rates match the contract?

Compare every line-item rate against the current, contractually approved rate card by role, level, and geography. Rate errors persist quietly because approved timesheets create false confidence that the rate itself was correct, when a timesheet only confirms hours worked, not the price attached to them. The audit step is a direct lookup: role and level on the invoice against the current rate card row, not against a prior number or a remembered figure.

A timesheet approval confirms hours worked, not the price attached to them. Managers signing off on time rarely re-verify the rate against the master agreement, so a stale or incorrect rate can ride through approval indefinitely.

For the mechanics of why approved timesheets still slip through, see rate card enforcement.

4. 4. How do you confirm hours and milestones match approved scope?

Reconcile billed hours or milestone payments against the SOW's defined deliverables and timeline. Time-and-materials engagements are especially exposed because hours can accumulate without a deliverable ever being checked, unlike fixed-fee milestones where payment ties to a defined output. Compare hours logged per phase against the SOW's estimated effort, and investigate variances before payment rather than after it has already gone out.

Fixed-fee milestones are easier to audit because payment ties to a defined output, but time-and-materials work has no such anchor unless the auditor builds one. Compare hours logged per phase against the SOW's estimated effort, and investigate large variances before, not after, payment.

Watch for scope creep hiding inside hours: additional tasks folded into an existing SOW without a change order. See scope creep in professional services SOWs for how this presents.

5. 5. What counts as scope drift versus a legitimate change order?

Scope drift is work performed and billed without a signed amendment; a legitimate change order is the same expanded work with client sign-off and an updated price. The line is the signature, not the size of the change, so a small unapproved addition is still drift and a large approved addition is still legitimate. Audit this by checking every deliverable against the SOW's original language, not against what the delivery team says was needed.

Vendors and delivery teams often expand scope informally to keep a project moving, then bill for it under the original SOW because renegotiating takes time. The work may be reasonable and even necessary, the problem is that it was never priced or approved.

Audit this by checking every deliverable against the SOW's original language, not against what the project team says was needed. Any billed work absent from that language should trace to a signed change order or be flagged as unapproved.

6. 6. How do you turn these checks into a repeatable process?

A repeatable IT and professional services audit runs the same four checks, resource, rate, hours-to-scope, and scope drift, on every invoice, on a fixed cadence, rather than as a one-time cleanup project. A single deep audit finds existing errors but doesn't stop new ones from accumulating the following month, so the checks need to run continuously, ideally before payment, so errors are caught while they are still cheap to dispute.

A single deep audit finds existing errors but doesn't stop new ones from accumulating next month. The four checks above need to run on a cadence, ideally before payment, so errors are caught while they're still cheap to dispute.

The cadence choice itself matters: continuous enforcement catches issues invoice by invoice, while periodic audit trades speed for lower overhead. See continuous enforcement vs. periodic audit for how to choose between them, and n-way invoice matching explained for how the matching mechanics generalize beyond professional services.

For the wider pattern this sits inside, start with the margin drift guide.

For the wider pattern this sits inside, start with the margin drift guide. See also accessorial charge audit: the surcharges nobody validates and rate card enforcement: why approved timesheets still produce wrong invoices.

7. Frequently Asked Questions (People Also Ask)

Who should own this audit, procurement or finance?

Either can own it, but whoever does needs access to the signed SOW, rate card, and staffing approvals, not just the invoice and PO. Procurement usually holds the contract documents while finance holds payment timing, so the process works best when both sides share visibility into the same source documents before an invoice is approved.

Does a three-way match catch these errors?

No. A three-way match compares invoice, purchase order, and receipt, which works for physical goods but not for labor. A consultant's hours can match the PO amount exactly while the person billing, the rate applied, or the scope covered is still wrong, so professional services need the document-level checks described above instead.

What triggers a deeper review of a specific invoice?

A new name appearing on the roster without a matching SOW amendment, a rate that doesn't match the current card, hours that spike relative to the milestone schedule, or deliverables described in the invoice that don't appear in the SOW language are all signals worth a closer look before payment.

Can this audit be automated?

The lookups themselves, matching names to a roster, rates to a card, and hours to a schedule, can be automated once the underlying documents are digitized and kept current. The judgment calls, like whether a scope change was reasonable, still need a person, but the automation removes the manual line-by-line comparison work.

How far back should an audit look?

At minimum, cover the current SOW term and any active amendments. If rate card errors are found, it's worth checking prior invoices under the same rate card version, since a stale rate applied once is often applied repeatedly until someone catches it.

What's the difference between auditing T&M and fixed-fee engagements?

Fixed-fee engagements are audited against milestone deliverables, so the question is whether the output was actually produced. Time-and-materials engagements are audited against hours and rates directly, since there's no deliverable checkpoint forcing a pause, which is why T&M work needs closer, more frequent review.

Who typically has authority to approve a change order?

That's set by the master agreement, but it's usually a named signatory on the client side, not the project manager running day-to-day delivery. If the person who approved a scope expansion isn't the person named in the contract as having that authority, the change order itself may not be valid.

What happens if a resource mismatch is found after payment?

The invoice can still be disputed, though recovery gets harder the longer the gap. Document the mismatch against the SOW roster, notify the vendor in writing, and request either a credit or a corrected future invoice, depending on what the contract's dispute terms allow.

Executive Summary

Auditing IT and professional services invoices means verifying four things on every invoice: that the resource billed is the resource contracted, that the rate matches the master agreement, that the hours or milestones map to approved scope, and that nothing has drifted from the original statement of work. Because these engagements are billed on time and deliverables rather than physical units, the usual three-way match against a purchase order and receipt doesn't catch most of the problems. A consultant can be logged correctly and still be the wrong person at the wrong rate doing work nobody approved. The practical approach starts with the contract documents, not the invoice: pull the SOW, the rate card, and any change orders before looking at a single line item. From there, an auditor checks resource identity against approved staffing plans, rates against the card, hours against milestones or timesheets, and scope against the original SOW language. Each of these failure modes has a distinct signature, and catching them requires different evidence. An approved timesheet says nothing about whether the rate applied to it was correct, and a correct rate says nothing about whether the person billing it was ever approved to work the engagement.

1. 1. What documents do you need before starting the audit?

Before touching an invoice, collect the signed SOW, the current rate card, the staffing plan or resource approvals, and any change orders. Without these documents, an invoice looks like a set of numbers instead of a set of claims you can verify against a contract. Each document tests a different part of the invoice: the SOW tests scope, the rate card tests price, the staffing plan tests who is allowed to bill, and change orders test whether expanded work was. Most invoice review starts and ends with the invoice itself, checking math and totals. That catches almost nothing in professional services, where the risk isn't arithmetic, it's whether the billed work was ever authorized at that rate, by that person, for that scope. Pull the baseline documents first: the SOW defining deliverables and milestones, the rate card by role and level, the approved staffing roster, and every amendment since signing. Treat the invoice as a claim to be tested against these, not a document to be read alone.

2. 2. How do you verify the resource billed is the resource approved?

Match every named consultant or contractor on the invoice against the approved staffing plan or statement of work roster. Vendors substitute personnel to manage utilization, and substitutions often carry a different, unapproved rate. This check happens at the person level, not the role level, so confirming a title matches is not enough; the specific individual has to be named in the SOW or a signed amendment before their hours are payable. Vendors reassign staff for their own scheduling reasons far more often than clients realize. A senior architect approved for a project can be swapped for a junior resource billed at the senior rate, or the reverse can occur where scope requires seniority nobody is providing. Confirm names against the roster, and flag any resource appearing on an invoice who was never named in the SOW or its amendments. This overlaps with, but is distinct from, off-contract billing generally, see [off-contract resources](/guides/off-contract-resources-people-billed-outside-the-agreement) for the broader pattern.

3. 3. How do you check that billed rates match the contract?

Compare every line-item rate against the current, contractually approved rate card by role, level, and geography. Rate errors persist quietly because approved timesheets create false confidence that the rate itself was correct, when a timesheet only confirms hours worked, not the price attached to them. The audit step is a direct lookup: role and level on the invoice against the current rate card row, not against a prior number or a remembered figure. A timesheet approval confirms hours worked, not the price attached to them. Managers signing off on time rarely re-verify the rate against the master agreement, so a stale or incorrect rate can ride through approval indefinitely. For the mechanics of why approved timesheets still slip through, see [rate card enforcement](/guides/rate-card-enforcement-why-approved-timesheets-still-produce).

4. 4. How do you confirm hours and milestones match approved scope?

Reconcile billed hours or milestone payments against the SOW's defined deliverables and timeline. Time-and-materials engagements are especially exposed because hours can accumulate without a deliverable ever being checked, unlike fixed-fee milestones where payment ties to a defined output. Compare hours logged per phase against the SOW's estimated effort, and investigate variances before payment rather than after it has already gone out. Fixed-fee milestones are easier to audit because payment ties to a defined output, but time-and-materials work has no such anchor unless the auditor builds one. Compare hours logged per phase against the SOW's estimated effort, and investigate large variances before, not after, payment. Watch for scope creep hiding inside hours: additional tasks folded into an existing SOW without a change order. See [scope creep in professional services SOWs](/guides/scope-creep-in-professional-services-sows) for how this presents.

5. 5. What counts as scope drift versus a legitimate change order?

Scope drift is work performed and billed without a signed amendment; a legitimate change order is the same expanded work with client sign-off and an updated price. The line is the signature, not the size of the change, so a small unapproved addition is still drift and a large approved addition is still legitimate. Audit this by checking every deliverable against the SOW's original language, not against what the delivery team says was needed. Vendors and delivery teams often expand scope informally to keep a project moving, then bill for it under the original SOW because renegotiating takes time. The work may be reasonable and even necessary, the problem is that it was never priced or approved. Audit this by checking every deliverable against the SOW's original language, not against what the project team says was needed. Any billed work absent from that language should trace to a signed change order or be flagged as unapproved.

6. 6. How do you turn these checks into a repeatable process?

A repeatable IT and professional services audit runs the same four checks, resource, rate, hours-to-scope, and scope drift, on every invoice, on a fixed cadence, rather than as a one-time cleanup project. A single deep audit finds existing errors but doesn't stop new ones from accumulating the following month, so the checks need to run continuously, ideally before payment, so errors are caught while they are still cheap to dispute. A single deep audit finds existing errors but doesn't stop new ones from accumulating next month. The four checks above need to run on a cadence, ideally before payment, so errors are caught while they're still cheap to dispute. The cadence choice itself matters: continuous enforcement catches issues invoice by invoice, while periodic audit trades speed for lower overhead. See [continuous enforcement vs. periodic audit](/guides/continuous-enforcement-vs-periodic-audit-choosing-a-cadence) for how to choose between them, and [n-way invoice matching explained](/guides/n-way-invoice-matching-explained) for how the matching mechanics generalize beyond professional services. For the wider pattern this sits inside, start with the [margin drift](/guides/indirect-spend-audit-categories) guide. For the wider pattern this sits inside, start with the [margin drift](/guides/indirect-spend-audit-categories) guide. See also [accessorial charge audit: the surcharges nobody validates](/guides/accessorial-charge-audit-the-surcharges-nobody-validates) and [rate card enforcement: why approved timesheets still produce wrong invoices](/guides/rate-card-enforcement-why-approved-timesheets-still-produce).

Questions & Answers

Who should own this audit, procurement or finance?

Either can own it, but whoever does needs access to the signed SOW, rate card, and staffing approvals, not just the invoice and PO. Procurement usually holds the contract documents while finance holds payment timing, so the process works best when both sides share visibility into the same source documents before an invoice is approved.

Does a three-way match catch these errors?

No. A three-way match compares invoice, purchase order, and receipt, which works for physical goods but not for labor. A consultant's hours can match the PO amount exactly while the person billing, the rate applied, or the scope covered is still wrong, so professional services need the document-level checks described above instead.

What triggers a deeper review of a specific invoice?

A new name appearing on the roster without a matching SOW amendment, a rate that doesn't match the current card, hours that spike relative to the milestone schedule, or deliverables described in the invoice that don't appear in the SOW language are all signals worth a closer look before payment.

Can this audit be automated?

The lookups themselves, matching names to a roster, rates to a card, and hours to a schedule, can be automated once the underlying documents are digitized and kept current. The judgment calls, like whether a scope change was reasonable, still need a person, but the automation removes the manual line-by-line comparison work.

How far back should an audit look?

At minimum, cover the current SOW term and any active amendments. If rate card errors are found, it's worth checking prior invoices under the same rate card version, since a stale rate applied once is often applied repeatedly until someone catches it.

Margin Drift Resources