Post-Audit

Post-audit definition: reviewing paid invoices against vendor contracts to recover overcharges. What it covers, its timing, and its limits. Read the full guide.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Post-Audit

A post-audit is a review of invoices already paid, checked line by line against the vendor contract that governed them, to find charges the contract did not permit. Margin drift is the gap between what a vendor contract says and what the invoice actually charges. A post-audit is one way to find where that gap already happened.

Because it looks backward, a post-audit produces two things: a recovery claim for money already spent incorrectly, and a record of which contract terms the payment process failed to enforce.

1. What does a post-audit actually check?

A post-audit compares paid invoices against the contract that should have governed them: the rate card, volume tiers, rebate clauses, and scope of work. It tests whether the amount billed matches the amount the contract allows, and whether credits owed to the buyer were actually issued. The result is a list of specific invoices where the two disagree.

The comparison runs invoice by invoice rather than by sampling a few and extrapolating. Each line item gets matched to a contract clause: a rate, a tier threshold, a surcharge schedule, or a scope boundary.

Where no match exists, or the invoice amount exceeds what the clause permits, the line becomes a finding. Findings get grouped by vendor and by the type of drift they represent.

2. How is a post-audit different from a forward control?

A post-audit tests invoices that have already been paid. A forward control, like three-way matching in an AP system, tests an invoice before payment against a purchase order and receipt. The two check different documents at different points in time, so a forward control missing a contract term will not catch drift that a post-audit is built to find.

Three-way matching confirms an invoice matches a purchase order and a receipt. It does not test whether the price on that PO reflects the current rate card, or whether a surcharge expired and kept billing anyway.

A post-audit is not a substitute for that control. It runs after payment, on records the forward control already approved, which is exactly why it can find what the forward control was never built to check.

3. When does a company run a post-audit?

A post-audit is run when a company suspects contract drift has accumulated in vendor spend, usually service categories like freight, contract labor, or maintenance, and wants a documented recovery claim before renegotiating or renewing those contracts. It can be a one-time engagement or a recurring review scheduled around contract renewal dates.

Common triggers include a new CFO or controller wanting a spend baseline, a vendor contract coming up for renewal, or a finance team noticing invoice totals that do not track with volume.

A post-audit can also run alongside a forward control implementation. Reviewing what already happened gives the team the specific contract terms to encode into the new control, rather than starting from a blank rule set.

4. What are the limits of a post-audit?

A post-audit only finds drift in the period and vendors it covers, and it cannot prevent the next invoice from repeating the same error. Its recovery value depends on the credit or repayment terms in the contract and on how far back records exist. Without a forward control installed afterward, the same drift types tend to recur on future invoices.

A post-audit is a retrospective exercise. It does not touch invoices issued after the review period closes, so drift that starts the week the audit ends goes uncaught until the next review.

Recovering a finding also depends on what the contract allows: some contracts specify a credit memo process, others require negotiation. A post-audit documents the claim; collecting it is a separate step.

For the wider pattern this sits inside, start with the margin drift guide. See also margin drift vs. legitimate price increases: how to tell them apart and off-contract resources: people billed outside the agreement.

5. Frequently Asked Questions (People Also Ask)

What is a post-audit in accounts payable?

A post-audit is a review of invoices and payments already made, checked against the vendor contract that governed them, to find overcharges, missed credits, and other contract violations. It happens after payment, so its output is a recovery claim and a record of what the payment process missed.

How is a post-audit different from a duplicate payment review?

A duplicate payment review checks one specific error type. A post-audit is broader: it also tests rate accuracy, volume tier placement, rebate clauses, and contract scope, so a duplicate payment check is one component of a full post-audit, not the whole of it.

Does a post-audit replace AP automation?

No. AP automation reviews an invoice before payment against a purchase order and receipt. A post-audit reviews invoices already paid against the underlying contract. They test different documents at different points and work as complements, not substitutes.

How far back can a post-audit go?

The lookback period depends on the engagement scope and on how far back contracts and payment records are available, not on a fixed rule. It can cover a single fiscal year or several years of paid invoices.

Who requests a post-audit?

CFOs, controllers, and procurement leads typically request a post-audit when they suspect margin drift in service vendor spend but lack the internal capacity to test every invoice against every contract clause manually.

What happens after a post-audit finds an error?

Findings are documented by vendor and line item, then pursued through whatever recovery mechanism the contract specifies, such as a credit memo request or direct negotiation with the vendor. The audit documents the claim; collecting it is a separate step.

Can a post-audit prevent the same error from happening again?

Not by itself. A post-audit is retrospective and does not touch invoices issued after its review period closes. Preventing recurrence requires installing a forward control, informed by what the post-audit found, on future invoices.

Is a post-audit only for large companies?

Post-audits are commonly used by companies above $100M in revenue with enough vendor contract volume and complexity that manual invoice review misses drift. Below that scale, the same contract-matching work is often smaller in scope but still follows the same method.

1. What does a post-audit actually check?

A post-audit compares paid invoices against the contract that should have governed them: the rate card, volume tiers, rebate clauses, and scope of work. It tests whether the amount billed matches the amount the contract allows, and whether credits owed to the buyer were actually issued. The result is a list of specific invoices where the two disagree. The comparison runs invoice by invoice rather than by sampling a few and extrapolating. Each line item gets matched to a contract clause: a rate, a tier threshold, a surcharge schedule, or a scope boundary. Where no match exists, or the invoice amount exceeds what the clause permits, the line becomes a finding. Findings get grouped by vendor and by the type of drift they represent.

2. How is a post-audit different from a forward control?

A post-audit tests invoices that have already been paid. A forward control, like three-way matching in an AP system, tests an invoice before payment against a purchase order and receipt. The two check different documents at different points in time, so a forward control missing a contract term will not catch drift that a post-audit is built to find. Three-way matching confirms an invoice matches a purchase order and a receipt. It does not test whether the price on that PO reflects the current [rate card](/glossary/rate-card), or whether a surcharge expired and kept billing anyway. A post-audit is not a substitute for that control. It runs after payment, on records the forward control already approved, which is exactly why it can find what the forward control was never built to check.

3. When does a company run a post-audit?

A post-audit is run when a company suspects contract drift has accumulated in vendor spend, usually service categories like freight, contract labor, or maintenance, and wants a documented recovery claim before renegotiating or renewing those contracts. It can be a one-time engagement or a recurring review scheduled around contract renewal dates. Common triggers include a new CFO or controller wanting a spend baseline, a vendor contract coming up for renewal, or a finance team noticing invoice totals that do not track with volume. A post-audit can also run alongside a forward control implementation. Reviewing what already happened gives the team the specific contract terms to encode into the new control, rather than starting from a blank rule set.

4. What are the limits of a post-audit?

A post-audit only finds drift in the period and vendors it covers, and it cannot prevent the next invoice from repeating the same error. Its recovery value depends on the credit or repayment terms in the contract and on how far back records exist. Without a forward control installed afterward, the same drift types tend to recur on future invoices. A post-audit is a retrospective exercise. It does not touch invoices issued after the review period closes, so drift that starts the week the audit ends goes uncaught until the next review. Recovering a finding also depends on what the contract allows: some contracts specify a credit memo process, others require negotiation. A post-audit documents the claim; collecting it is a separate step. For the wider pattern this sits inside, start with the [margin drift](/insights/margin-drift-spend-leakage-guide) guide. See also [margin drift vs. legitimate price increases: how to tell them apart](/guides/margin-drift-vs-legitimate-price-increases-how-to-tell-them) and [off-contract resources: people billed outside the agreement](/guides/off-contract-resources-people-billed-outside-the-agreement).

Questions & Answers

What is a post-audit in accounts payable?

A post-audit is a review of invoices and payments already made, checked against the vendor contract that governed them, to find overcharges, missed credits, and other contract violations. It happens after payment, so its output is a recovery claim and a record of what the payment process missed.

How is a post-audit different from a duplicate payment review?

A duplicate payment review checks one specific error type. A post-audit is broader: it also tests rate accuracy, volume tier placement, rebate clauses, and contract scope, so a duplicate payment check is one component of a full post-audit, not the whole of it.

Does a post-audit replace AP automation?

No. AP automation reviews an invoice before payment against a purchase order and receipt. A post-audit reviews invoices already paid against the underlying contract. They test different documents at different points and work as complements, not substitutes.

How far back can a post-audit go?

The lookback period depends on the engagement scope and on how far back contracts and payment records are available, not on a fixed rule. It can cover a single fiscal year or several years of paid invoices.

Who requests a post-audit?

CFOs, controllers, and procurement leads typically request a post-audit when they suspect margin drift in service vendor spend but lack the internal capacity to test every invoice against every contract clause manually.

Margin Drift Resources