# Preparing AP and contract data for a recovery audit

> What AP and contract files a recovery audit needs, in what format, and why gaps in vendor master data delay findings. Part of the ValueXPA margin drift library.

Source: https://valuexpa.com/insights/how-to-prepare-ap-and-contract-data-for-a-recovery-audit
Publisher: ValueXPA (https://valuexpa.com)
Updated: 2026-09-05

---

Margin drift is the gap between what a vendor contract says and what the invoice actually charges. Finding it depends less on audit skill than on whether the underlying data is assembled correctly before anyone opens an invoice.

Most of the delay in a recovery audit happens before analysis starts: chasing a missing rate card, reconciling two vendor IDs for the same supplier, or waiting on a contract amendment nobody filed. This guide sets out what to pull, in what shape, and why each piece matters.

## Executive Summary

A recovery audit tests every invoice against its contract. That test only works if both sides are complete: the full invoice history at line-item detail, and the full set of governing terms, including amendments, rate cards, and rebate schedules. Gaps on either side do not just slow the work; they hide findings, because an invoice cannot be flagged against a rule the auditor never received.

The mechanism that causes most delay is not missing data so much as fragmented data: a vendor billed under three different vendor IDs, a rate card that exists only as a PDF attached to an email from two years ago, a rebate clause referenced in the master agreement but detailed in a separate side letter. None of this is unusual. It is simply unassembled.

What changes it is treating data preparation as its own step, with its own checklist, rather than something to sort out mid-audit. A company that pulls AP history, contract files, and a clean vendor master before the audit starts gets a shorter engagement and a more complete result. One that does not will spend audit time on document requests instead of findings.

## 1. What data does a recovery audit actually need?

**A recovery audit needs two data sets: complete invoice history at line-item detail for the vendors in scope, and every document that governs pricing for those vendors, including the master agreement, amendments, rate cards, rebate schedules, and surcharge tables. Summary-level AP exports and a single master contract are not enough; line detail and every amendment are what let an invoice be tested against the rule that actually applies to it.**

Invoice history needs to go back far enough to catch drift that accumulated slowly. Twelve to eighteen months is standard, because a rate error that started small compounds across renewal cycles and stops looking like an anomaly.

The invoice extract should include line-item detail, not just invoice totals: unit price, quantity, surcharge lines, and any credit memos applied. A summary export hides exactly the detail an audit tests.

On the contract side, the master agreement alone is rarely the whole picture. Rate cards are often attached separately and updated on their own schedule. Rebate clauses sometimes live in a side letter rather than the main document. Surcharge schedules may reference an index or a carrier tariff that sits outside the contract entirely.

All of this needs to be current. A rate card without its effective date and expiration date cannot be matched to the invoice period it actually governs, and an amendment that was signed but never filed with the rest of the contract file will not surface unless someone asks for it by name.

## 2. How far back should invoice history go?

**Twelve to eighteen months of invoice history is the standard window for a recovery audit, long enough to cross at least one contract renewal and catch drift that started small and compounded. A shorter window can miss the point where a rate change or a rebate clause first went unenforced, which is often the detail that explains the rest of the pattern.**

A three-month or six-month extract is common as a first pass, but it usually understates the problem. Drift rarely starts big. A surcharge that should have expired at the end of a promotional period keeps appearing on invoices for months before anyone notices, and a window that starts after the surcharge began will never catch its origin.

Crossing a contract renewal in the window matters for a different reason: it shows whether a term that changed at renewal, a new rate card or a revised rebate tier, was actually applied from the renewal date forward, or whether the old rate kept running past its expiration.

For vendors with long-cycle work, maintenance contracts and master service agreements among them, eighteen months is often closer to right than twelve, because work orders and scope changes on those contracts move slower than a monthly invoice cycle.

## 3. What contract documents are commonly missing?

**The documents most often missing from a contract file are rate card updates issued after signing, rebate side letters, amendment redlines that were never merged into a clean copy, and the surcharge or accessorial tables a carrier or vendor references but does not attach. Each of these sits outside the master agreement, so a request for the contract alone will not surface them.**

None of these gaps are unusual on their own. What makes them costly is that they are each invisible until an invoice is tested against them, at which point the invoice looks correct against the wrong reference and the actual reference is somewhere nobody thought to look.

Building a single contract file per vendor, with every amendment and side letter merged into one current copy and a clear effective date on each clause, removes this failure mode before analysis starts rather than during it.

- **Rate card updates:** Vendors often issue a revised rate card by email rather than as a formal amendment, so it lives in someone's inbox rather than the contract file.

- **Rebate side letters:** Volume rebate terms are sometimes negotiated separately from the master agreement and never attached to it.

- **Unmerged amendments:** A signed amendment that changes one clause but was never incorporated into a clean, current copy of the contract.

- **Referenced tariff or index tables:** [Surcharge clauses](/guides/surcharge-sunset-dating-as-a-control) that point to a carrier's published tariff or a public index rather than stating a fixed rate.

- **Expired term records:** The prior rate card or rebate tier, needed to confirm exactly when a change took effect and whether billing caught up.

## 4. How do you handle a vendor with multiple names or IDs in AP?

**Map every vendor ID variant, including divisions, DBA names, and old entity names from acquisitions, to a single vendor before analysis starts. Without that mapping, the same supplier's invoices split across two or three IDs, and a rebate tier or volume threshold that depends on total annual spend with that vendor will understate the real total and hide the leakage.**

Duplicate vendor records accumulate for ordinary reasons: an acquired company keeps its old entity name in AP for a year after the deal closes, a regional division bills under its own name, or someone re-entered a vendor rather than searching for the existing record.

The practical effect on an audit is specific. Volume [rebate clauses](/guides/unapplied-volume-rebates-in-staffing-agreements) and tiered rate cards are usually keyed to total annual spend with a vendor. If that spend is split across two IDs, neither one crosses the threshold on its own, and a rebate the contract actually earned goes unclaimed because no single record shows the qualifying volume.

A [vendor master hygiene](/guides/vendor-master-hygiene-and-the-duplicate-vendor-problem) pass before the audit, matching by tax ID, remit-to address, and parent company rather than by name alone, closes this gap. It is mechanical work, but it is a precondition for the rebate and volume-tier checks to run correctly at all.

## 5. Should you prepare data by category or all at once?

**Preparing data by category, freight, maintenance, contract labor, and so on, rather than as one undifferentiated AP export, matches the way contract terms actually differ by category and lets each category's file get the specific documents it needs. An all-at-once pull is faster to produce but usually still needs to be split back into these groups before matching can start.**

Splitting by category also matches how findings get reviewed internally. A controller checking freight findings wants the carrier tariff and the fuel index on hand, not a maintenance work order mixed into the same file.

For a first engagement, an all-at-once AP export is a reasonable starting point, since the categories can be split during preparation rather than before it. What matters is that the split happens before matching starts, not after, since a rate card mismatched to the wrong category produces a finding against the wrong rule.

What each category's file needs beyond invoice and master contract.

| Category
| Documents needed beyond the invoice
| Common gap

| Freight and 3PL
| Fuel surcharge index reference, accessorial tariff
| Surcharge index not dated

| Contract labor and staffing
| Approved rate card by role, timesheet approvals
| Rate card not tied to labor category

| Maintenance and MSA work
| Work order scope, warranty terms
| Work order missing scope detail

| IT and professional services
| SOW deliverables and rate schedule
| SOW change orders not filed centrally

| MRO and Class C
| Approved price file, substitution rules
| Price file update not dated

## 6. What format should the data be in?

**Invoice data should export as a flat file, line-item level, from the AP or ERP system, in a delimited or spreadsheet format rather than as scanned PDFs. Contract documents can stay as PDFs but need consistent naming by vendor and effective date. A scanned invoice image with no extractable line data cannot be matched against a rate card programmatically and has to be read by hand.**

Most ERP and AP systems can export invoice history as a delimited file with one row per line item: vendor ID, invoice number, invoice date, item or service description, quantity, unit price, and total. That structure is what makes automated matching against a rate card possible.

A scanned PDF of the invoice, with no underlying data export, still has value as a backup reference, but it cannot be matched line by line without manual entry first. Where invoices only exist as images, expect that category to take longer to audit, not because the vendor is worse, but because the data has to be rebuilt before it can be tested.

Contracts do not need the same structure. A clean, named PDF per vendor, current as of the audit period and covering every amendment, is sufficient, since contract matching is a smaller volume of documents read for specific terms rather than thousands of line items processed at once.

## 7. What happens if some of this data cannot be found?

**Missing data narrows the audit's scope rather than stopping it. A vendor with invoice history but no locatable current contract gets tested against whatever terms can be confirmed, with the gap stated explicitly rather than assumed away. An audit that fills a missing contract with an assumed rate produces a false finding, which is worse than no finding at all.**

The honest response to a missing document is to say so on the record, not to substitute a plausible term for it. If a rate card cannot be located for a given period, that period is excluded from rate testing for that vendor rather than tested against a rate carried forward from a different period.

In practice, missing contract documents are themselves a finding. A vendor whose current rate card cannot be produced by either the client or the vendor is a control gap independent of anything found on the invoices, and it belongs in the [recovery and prevention roadmap](/guides/diagnostic-or-software-what-to-buy-first) alongside the dollar findings.

The preparation work described here reduces how often this happens, but it does not eliminate it. Some documents are genuinely gone. What matters is that the audit states the gap plainly rather than papering over it with an assumption.

For the wider pattern this sits inside, start with the [margin drift](/margin-drift-diagnostic) guide.

## 8. Frequently Asked Questions (People Also Ask)

### How much AP history do I need to provide for a recovery audit?

Twelve to eighteen months of line-item invoice detail is standard. That window is long enough to cross at least one contract renewal, which shows whether new terms were actually applied on the renewal date or whether the old rate kept running past it.

### Do I need to provide the whole contract or just the rate card?

Both, plus every amendment and any side letter covering rebates or rate updates. A rate card alone cannot confirm the rebate terms or NTE caps that sit elsewhere in the agreement, and the master agreement alone often does not contain the current rate card.

### What if our AP system only exports invoice totals, not line items?

Line-item detail is what makes matching against a rate card possible, so a totals-only export will need to be supplemented, either with a re-export at line level from the ERP or with source invoice documents for the vendors in scope.

### How do we handle a vendor that has been through an acquisition?

Map every legacy entity name and vendor ID the acquired company used to the current vendor record before the audit starts. Volume-based rebate and rate tiers are usually calculated on total spend, and a split vendor record can hide a rebate the combined spend actually earned.

### Can scanned PDF invoices be used instead of a data export?

They can be used, but line items in a scanned image cannot be matched against a rate card without manual entry first, so that vendor's invoices will take longer to process. A structured export is faster and more complete wherever the AP system supports one.

### What if we can't find the current contract for a vendor?

That vendor's invoices are tested against whatever terms can be confirmed, and the missing document is recorded as a gap rather than filled with an assumed rate. A missing current contract is itself a finding worth including in the recovery and prevention roadmap.

### Should data be organized by vendor or by spend category?

Both groupings matter, but organizing by spend category, freight, maintenance, contract labor, and so on, generally works best for preparation, since each category needs different supporting documents beyond the invoice and contract, such as a fuel index for freight or a role-based rate card for staffing.

### Does data preparation change the length of the audit itself?

It affects how much of the engagement is spent on document requests versus analysis. A prepared data set lets the diagnostic run in its 2 to 4 week window; a data set with major gaps extends the time spent locating documents before analysis can proceed.

### Who inside the company should own pulling this data together?

AP typically owns the invoice extract, and procurement or the contract owner typically owns the contract file, since neither team alone holds both sides. Assigning both explicitly before the audit starts avoids a mid-audit search for whoever has the missing document.

### Is there a general legal consideration in gathering contract documents?

Contract interpretation can carry legal implications, particularly around rebate clauses and termination terms. This is general information, not legal advice, and any disputed contract term should be reviewed with counsel before a claim is made against a vendor.

### Is contract complexity quietly draining your operating margin?

A small systematic drift between your negotiated contracts and your actual vendor billing compounds quietly across a year of invoices. Stop guessing at your exposure and run a targeted audit.

**[Take the Free Screener → https://valuexpa.com/margin-drift-screener](https://valuexpa.com/margin-drift-screener)**

## Executive Summary

A recovery audit tests every invoice against its contract. That test only works if both sides are complete: the full invoice history at line-item detail, and the full set of governing terms, including amendments, rate cards, and rebate schedules. Gaps on either side do not just slow the work; they hide findings, because an invoice cannot be flagged against a rule the auditor never received. The mechanism that causes most delay is not missing data so much as fragmented data: a vendor billed under three different vendor IDs, a rate card that exists only as a PDF attached to an email from two years ago, a rebate clause referenced in the master agreement but detailed in a separate side letter. None of this is unusual. It is simply unassembled. What changes it is treating data preparation as its own step, with its own checklist, rather than something to sort out mid-audit. A company that pulls AP history, contract files, and a clean vendor master before the audit starts gets a shorter engagement and a more complete result. One that does not will spend audit time on document requests instead of findings.

## 1. What data does a recovery audit actually need?

A recovery audit needs two data sets: complete invoice history at line-item detail for the vendors in scope, and every document that governs pricing for those vendors, including the master agreement, amendments, rate cards, rebate schedules, and surcharge tables. Summary-level AP exports and a single master contract are not enough; line detail and every amendment are what let an invoice be tested against the rule that actually applies to it. Invoice history needs to go back far enough to catch drift that accumulated slowly. Twelve to eighteen months is standard, because a rate error that started small compounds across renewal cycles and stops looking like an anomaly. The invoice extract should include line-item detail, not just invoice totals: unit price, quantity, surcharge lines, and any credit memos applied. A summary export hides exactly the detail an audit tests. On the contract side, the master agreement alone is rarely the whole picture. Rate cards are often attached separately and updated on their own schedule. Rebate clauses sometimes live in a side letter rather than the main document. Surcharge schedules may reference an index or a carrier tariff that sits outside the contract entirely. All of this needs to be current. A rate card without its effective date and expiration date cannot be matched to the invoice period it actually governs, and an amendment that was signed but never filed with the rest of the contract file will not surface unless someone asks for it by name.

## 2. How far back should invoice history go?

Twelve to eighteen months of invoice history is the standard window for a recovery audit, long enough to cross at least one contract renewal and catch drift that started small and compounded. A shorter window can miss the point where a rate change or a rebate clause first went unenforced, which is often the detail that explains the rest of the pattern. A three-month or six-month extract is common as a first pass, but it usually understates the problem. Drift rarely starts big. A surcharge that should have expired at the end of a promotional period keeps appearing on invoices for months before anyone notices, and a window that starts after the surcharge began will never catch its origin. Crossing a contract renewal in the window matters for a different reason: it shows whether a term that changed at renewal, a new rate card or a revised rebate tier, was actually applied from the renewal date forward, or whether the old rate kept running past its expiration. For vendors with long-cycle work, maintenance contracts and master service agreements among them, eighteen months is often closer to right than twelve, because work orders and scope changes on those contracts move slower than a monthly invoice cycle.

## 3. What contract documents are commonly missing?

The documents most often missing from a contract file are rate card updates issued after signing, rebate side letters, amendment redlines that were never merged into a clean copy, and the surcharge or accessorial tables a carrier or vendor references but does not attach. Each of these sits outside the master agreement, so a request for the contract alone will not surface them. None of these gaps are unusual on their own. What makes them costly is that they are each invisible until an invoice is tested against them, at which point the invoice looks correct against the wrong reference and the actual reference is somewhere nobody thought to look. Building a single contract file per vendor, with every amendment and side letter merged into one current copy and a clear effective date on each clause, removes this failure mode before analysis starts rather than during it. - Rate card updates: Vendors often issue a revised rate card by email rather than as a formal amendment, so it lives in someone's inbox rather than the contract file. - Rebate side letters: Volume rebate terms are sometimes negotiated separately from the master agreement and never attached to it. - Unmerged amendments: A signed amendment that changes one clause but was never incorporated into a clean, current copy of the contract. - Referenced tariff or index tables: [Surcharge clauses](/guides/surcharge-sunset-dating-as-a-control) that point to a carrier's published tariff or a public index rather than stating a fixed rate. - Expired term records: The prior rate card or rebate tier, needed to confirm exactly when a change took effect and whether billing caught up.

## 4. How do you handle a vendor with multiple names or IDs in AP?

Map every vendor ID variant, including divisions, DBA names, and old entity names from acquisitions, to a single vendor before analysis starts. Without that mapping, the same supplier's invoices split across two or three IDs, and a rebate tier or volume threshold that depends on total annual spend with that vendor will understate the real total and hide the leakage. Duplicate vendor records accumulate for ordinary reasons: an acquired company keeps its old entity name in AP for a year after the deal closes, a regional division bills under its own name, or someone re-entered a vendor rather than searching for the existing record. The practical effect on an audit is specific. Volume [rebate clauses](/guides/unapplied-volume-rebates-in-staffing-agreements) and tiered rate cards are usually keyed to total annual spend with a vendor. If that spend is split across two IDs, neither one crosses the threshold on its own, and a rebate the contract actually earned goes unclaimed because no single record shows the qualifying volume. A [vendor master hygiene](/guides/vendor-master-hygiene-and-the-duplicate-vendor-problem) pass before the audit, matching by tax ID, remit-to address, and parent company rather than by name alone, closes this gap. It is mechanical work, but it is a precondition for the rebate and volume-tier checks to run correctly at all.

## 5. Should you prepare data by category or all at once?

Preparing data by category, freight, maintenance, contract labor, and so on, rather than as one undifferentiated AP export, matches the way contract terms actually differ by category and lets each category's file get the specific documents it needs. An all-at-once pull is faster to produce but usually still needs to be split back into these groups before matching can start. Splitting by category also matches how findings get reviewed internally. A controller checking freight findings wants the carrier tariff and the fuel index on hand, not a maintenance work order mixed into the same file. For a first engagement, an all-at-once AP export is a reasonable starting point, since the categories can be split during preparation rather than before it. What matters is that the split happens before matching starts, not after, since a rate card mismatched to the wrong category produces a finding against the wrong rule. What each category's file needs beyond invoice and master contract. | Category | Documents needed beyond the invoice | Common gap | | --- | --- | --- | | Freight and 3PL | Fuel surcharge index reference, accessorial tariff | Surcharge index not dated | | Contract labor and staffing | Approved rate card by role, timesheet approvals | Rate card not tied to labor category | | Maintenance and MSA work | Work order scope, warranty terms | Work order missing scope detail | | IT and professional services | SOW deliverables and rate schedule | SOW change orders not filed centrally | | MRO and Class C | Approved price file, substitution rules | Price file update not dated |

## 6. What format should the data be in?

Invoice data should export as a flat file, line-item level, from the AP or ERP system, in a delimited or spreadsheet format rather than as scanned PDFs. Contract documents can stay as PDFs but need consistent naming by vendor and effective date. A scanned invoice image with no extractable line data cannot be matched against a rate card programmatically and has to be read by hand. Most ERP and AP systems can export invoice history as a delimited file with one row per line item: vendor ID, invoice number, invoice date, item or service description, quantity, unit price, and total. That structure is what makes automated matching against a rate card possible. A scanned PDF of the invoice, with no underlying data export, still has value as a backup reference, but it cannot be matched line by line without manual entry first. Where invoices only exist as images, expect that category to take longer to audit, not because the vendor is worse, but because the data has to be rebuilt before it can be tested. Contracts do not need the same structure. A clean, named PDF per vendor, current as of the audit period and covering every amendment, is sufficient, since contract matching is a smaller volume of documents read for specific terms rather than thousands of line items processed at once.

## 7. What happens if some of this data cannot be found?

Missing data narrows the audit's scope rather than stopping it. A vendor with invoice history but no locatable current contract gets tested against whatever terms can be confirmed, with the gap stated explicitly rather than assumed away. An audit that fills a missing contract with an assumed rate produces a false finding, which is worse than no finding at all. The honest response to a missing document is to say so on the record, not to substitute a plausible term for it. If a rate card cannot be located for a given period, that period is excluded from rate testing for that vendor rather than tested against a rate carried forward from a different period. In practice, missing contract documents are themselves a finding. A vendor whose current rate card cannot be produced by either the client or the vendor is a control gap independent of anything found on the invoices, and it belongs in the [recovery and prevention roadmap](/guides/diagnostic-or-software-what-to-buy-first) alongside the dollar findings. The preparation work described here reduces how often this happens, but it does not eliminate it. Some documents are genuinely gone. What matters is that the audit states the gap plainly rather than papering over it with an assumption. For the wider pattern this sits inside, start with the [margin drift](/margin-drift-diagnostic) guide.

## Common questions

### How much AP history do I need to provide for a recovery audit?

Twelve to eighteen months of line-item invoice detail is standard. That window is long enough to cross at least one contract renewal, which shows whether new terms were actually applied on the renewal date or whether the old rate kept running past it.

### Do I need to provide the whole contract or just the rate card?

Both, plus every amendment and any side letter covering rebates or rate updates. A rate card alone cannot confirm the rebate terms or NTE caps that sit elsewhere in the agreement, and the master agreement alone often does not contain the current rate card.

### What if our AP system only exports invoice totals, not line items?

Line-item detail is what makes matching against a rate card possible, so a totals-only export will need to be supplemented, either with a re-export at line level from the ERP or with source invoice documents for the vendors in scope.

### How do we handle a vendor that has been through an acquisition?

Map every legacy entity name and vendor ID the acquired company used to the current vendor record before the audit starts. Volume-based rebate and rate tiers are usually calculated on total spend, and a split vendor record can hide a rebate the combined spend actually earned.

### Can scanned PDF invoices be used instead of a data export?

They can be used, but line items in a scanned image cannot be matched against a rate card without manual entry first, so that vendor's invoices will take longer to process. A structured export is faster and more complete wherever the AP system supports one.

---

ValueXPA runs a fixed-scope Margin Drift Diagnostic that validates every service vendor invoice against contract terms, for $100M+ US industrial manufacturers and distributors. Two to four weeks. The client retains 100% of recoveries. https://valuexpa.com/contact-us
