Preventive Control

A preventive control stops an incorrect invoice from being paid before it posts, unlike an audit that finds the error afterward. Read the full guide.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Preventive Control

A preventive control is a check applied before an invoice posts for payment, built to stop an error at the point of entry rather than find it afterward. In accounts payable, that means testing the invoice against the contract, the purchase order, or the rate card before the payment runs, not after.

Most AP controls sit downstream of the mistake. Three-way matching confirms an invoice against a PO and receipt. A preventive control goes further: it tests the price, the rate, and the term the contract actually specifies, before the vendor gets paid.

1. What makes a control preventive rather than detective?

A preventive control acts before payment: it blocks, flags, or holds an invoice that fails a contract test, so the wrong amount never posts. A detective control acts after payment: it identifies an error in invoices already paid, such as during an AP recovery audit, so the finding becomes a recovery claim rather than an avoided charge. The difference is timing relative to the cash leaving the business, not the rule being tested.

Executive Summary

A preventive control changes when an error gets caught. A detective control, like a periodic AP recovery audit, finds an overcharge after the invoice has been paid and the cash is gone; recovering it means a credit memo, a vendor call, or a write-off. A preventive control tests the same invoice line against the contract before payment, so the wrong amount never leaves the account.

The distinction matters because the two are not substitutes. A retrospective audit tells a CFO where the last 12 to 18 months of spend leaked and by how much. A preventive control only stops the next invoice from repeating that pattern, and only for the rules it has actually been configured with.

An organization needs the first to find out what its contracts are worth enforcing, and the second to keep enforcing them.

Both control types can test the identical rule, a rate card, a not-to-exceed cap, a volume tier. What changes is the point in the payment cycle where the test runs and what happens if the invoice fails it.

2. What does a preventive control actually check?

A preventive control compares a specific invoice field to a specific contract term: the unit rate to the rate card, the cumulative spend to a not-to-exceed cap, the volume to a tier threshold, the surcharge to its stated trigger condition. It does not judge whether a price increase is fair; it tests whether the invoiced number matches the number the contract specifies for that condition.

Building the check requires the contract term in a structured, comparable form. A PDF rate schedule the system cannot parse cannot be tested before payment, only after.

3. Where do preventive controls typically fail to catch drift?

A preventive control only catches what it has been configured to test. A term buried in an amendment, a rebate clause never entered as a rule, or a surcharge condition nobody codified will pass through untested, invoice after invoice, because the control has no rule to apply. This is a configuration gap, not a detection failure: the control works exactly as built, against an incomplete rule set.

Closing the gap starts with knowing which terms are actually being violated, which is what a retrospective diagnostic establishes before any rule gets written.

4. How does a preventive control relate to an AP recovery audit?

An AP recovery audit finds drift already paid and quantifies it by vendor and category; a preventive control stops the same drift from recurring once the rule is known. The audit supplies the rule set: which rate cards, tiers, and caps are actually being violated. Without that input, a preventive control is only as good as whichever rules someone guessed at, tested against invoices nobody has yet checked for accuracy.

Treated as sequential work rather than a substitute for each other, the audit finds the leak and the control holds the fix. See margin drift vs. legitimate price increases: how to tell them apart for how a specific invoice line gets classified before either step applies.

For the wider pattern this sits inside, start with the margin drift guide.

5. Frequently Asked Questions (People Also Ask)

Is a preventive control the same as three-way matching?

No. Three-way matching confirms an invoice against a purchase order and a receipt; it does not test whether the unit rate or surcharge matches the contract. A preventive control tests the invoiced amount against the contract term itself, which three-way matching was never built to check.

Can a preventive control replace an AP recovery audit?

No. A preventive control only stops future invoices from repeating a known error. It has no way to identify or recover drift already paid in the last 12 to 18 months, which is what an AP recovery audit is built to find.

What happens when an invoice fails a preventive control?

Depending on how the control is configured, the invoice is held, flagged for review, or blocked from the payment run until someone confirms whether the charge is correct or the contract term has changed.

Does a preventive control need the contract in a specific format?

It needs the relevant term, such as a rate card or a not-to-exceed cap, in a structured form the system can compare against an invoice field. A term that exists only as text in a PDF amendment cannot be tested before payment.

Which categories most need preventive controls?

Any category with a contract term the invoice can violate silently: a rate card, a volume tier, a surcharge trigger, or a not-to-exceed cap. Freight and 3PL audit, contract labor and staffing audit, and maintenance and repair audit are common places these terms live.

Is a credit memo a preventive control?

No. A credit memo corrects an error after the fact, once a vendor has agreed the invoice was wrong. It is a resolution step for a detective finding, not a check that runs before payment.

Why do preventive controls miss drift a diagnostic later finds?

A preventive control only tests the rules it has been given. A rebate clause, escalation formula, or amended rate that was never entered as a rule will pass through unchecked no matter how well the control is built.

1. What makes a control preventive rather than detective?

A preventive control acts before payment: it blocks, flags, or holds an invoice that fails a contract test, so the wrong amount never posts. A detective control acts after payment: it identifies an error in invoices already paid, such as during an AP recovery audit, so the finding becomes a recovery claim rather than an avoided charge. The difference is timing relative to the cash leaving the business, not the rule being tested. Executive Summary A preventive control changes when an error gets caught. A detective control, like a periodic AP recovery audit, finds an overcharge after the invoice has been paid and the cash is gone; recovering it means a credit memo, a vendor call, or a write-off. A preventive control tests the same invoice line against the contract before payment, so the wrong amount never leaves the account. The distinction matters because the two are not substitutes. A retrospective audit tells a CFO where the last 12 to 18 months of spend leaked and by how much. A preventive control only stops the next invoice from repeating that pattern, and only for the rules it has actually been configured with. An organization needs the first to find out what its contracts are worth enforcing, and the second to keep enforcing them. Both control types can test the identical rule, a rate card, a [not-to-exceed cap](/glossary/not-to-exceed-overrun), a [volume tier](/glossary/volume-tier). What changes is the point in the payment cycle where the test runs and what happens if the invoice fails it.

2. What does a preventive control actually check?

A preventive control compares a specific invoice field to a specific contract term: the unit rate to the rate card, the cumulative spend to a not-to-exceed cap, the volume to a tier threshold, the surcharge to its stated trigger condition. It does not judge whether a price increase is fair; it tests whether the invoiced number matches the number the contract specifies for that condition. Building the check requires the contract term in a structured, comparable form. A PDF rate schedule the system cannot parse cannot be tested before payment, only after.

3. Where do preventive controls typically fail to catch drift?

A preventive control only catches what it has been configured to test. A term buried in an amendment, a rebate clause never entered as a rule, or a surcharge condition nobody codified will pass through untested, invoice after invoice, because the control has no rule to apply. This is a configuration gap, not a detection failure: the control works exactly as built, against an incomplete rule set. Closing the gap starts with knowing which terms are actually being violated, which is what a retrospective diagnostic establishes before any rule gets written.

4. How does a preventive control relate to an AP recovery audit?

An AP recovery audit finds drift already paid and quantifies it by vendor and category; a preventive control stops the same drift from recurring once the rule is known. The audit supplies the rule set: which rate cards, tiers, and caps are actually being violated. Without that input, a preventive control is only as good as whichever rules someone guessed at, tested against invoices nobody has yet checked for accuracy. Treated as sequential work rather than a substitute for each other, the audit finds the leak and the control holds the fix. See margin drift vs. legitimate price increases: how to tell them apart for how a specific invoice line gets classified before either step applies. For the wider pattern this sits inside, start with the [margin drift](/insights/margin-drift-spend-leakage-guide) guide.

Questions & Answers

Is a preventive control the same as three-way matching?

No. Three-way matching confirms an invoice against a purchase order and a receipt; it does not test whether the unit rate or surcharge matches the contract. A preventive control tests the invoiced amount against the contract term itself, which three-way matching was never built to check.

Can a preventive control replace an AP recovery audit?

No. A preventive control only stops future invoices from repeating a known error. It has no way to identify or recover drift already paid in the last 12 to 18 months, which is what an AP recovery audit is built to find.

What happens when an invoice fails a preventive control?

Depending on how the control is configured, the invoice is held, flagged for review, or blocked from the payment run until someone confirms whether the charge is correct or the contract term has changed.

Does a preventive control need the contract in a specific format?

It needs the relevant term, such as a rate card or a not-to-exceed cap, in a structured form the system can compare against an invoice field. A term that exists only as text in a PDF amendment cannot be tested before payment.

Which categories most need preventive controls?

Any category with a contract term the invoice can violate silently: a rate card, a volume tier, a surcharge trigger, or a not-to-exceed cap. Freight and 3PL audit, contract labor and staffing audit, and maintenance and repair audit are common places these terms live.

Margin Drift Resources