Recovery Audit

Recovery audit definition: a retrospective review of paid vendor invoices to find and recover overpayments, duplicate payments, and missed credits.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Recovery Audit

A recovery audit is a retrospective review of paid vendor invoices to find money already lost: duplicate payments, overbilling against contract terms, missed credit memos, and unapplied rebates. It looks backward at spend already recorded, checking what was actually invoiced and paid against what a contract or purchase order allowed.

Recovery audit is one of the components inside a broader margin drift review. Margin drift is the gap between what a vendor contract says and what the invoice actually charges, and a recovery audit is the part of the work aimed specifically at money that already left the bank.

1. What does a recovery audit actually check?

A recovery audit checks paid invoices against the records that should have controlled them: purchase orders, receiving documents, contract rate cards, and prior credit memos. It looks for a paid amount that has no matching authorization, a payment made twice, a rebate that was earned under a contract but never issued, or a credit that was promised and never applied to the account.

The check runs on records already closed in the ERP. That is what separates it from a control that stops an invoice before payment.

An auditor works from the paid invoice file, the vendor master, and the underlying contracts, matching each line against its source document rather than trusting the coded general ledger entry.

2. How does a recovery audit differ from a forward control?

A recovery audit is retrospective: it tests invoices already paid, months or years after the fact. A forward control, such as three-way matching at invoice entry, tests the next invoice before it is paid. The two answer different questions: one recovers money already lost, the other prevents the next dollar from leaking the same way.

Neither replaces the other. A forward control checks the invoice against the purchase order and the receipt; it does not test whether a surcharge clause has expired or a rebate tier has been crossed, because those facts often live in a contract PDF outside the ERP.

A recovery audit can surface exactly that kind of gap, then hand it to the AP team as a rule to build into future matching.

3. What documents does a recovery audit require?

A recovery audit needs the paid invoice detail, the purchase order and receiving record for each line, the governing contract or rate card, and the vendor's rebate or credit memo history. Without the contract, an auditor can only find duplicate payments and clerical errors. With the contract, an auditor can also test whether the price charged matches the price agreed.

Invoice and payment data. The paid invoice file with vendor, amount, date, and general ledger coding, plus the corresponding payment record, gives the auditor the population to test and the ability to spot duplicates across vendor names or invoice number formats.

Contract and rate documentation. A rate card, a volume tier schedule, or a master service agreement is what turns a duplicate-payment scan into a contract compliance check. Without it, overbilling against an agreed rate is invisible to the audit.

4. What findings come out of a recovery audit?

Findings from a recovery audit fall into a small set of named categories: duplicate payment, missed credit memo, rebate gap, volume tier misapplication, not-to-exceed overrun, and accessorial charge creep, among others. Each is a distinct mechanism, not a severity ranking, and a single engagement can surface several categories in the same vendor file.

Each finding is documented with the source invoice, the contract clause or duplicate record that supports it, and the dollar amount at stake, so the client can validate the claim independently.

Some findings recover cash directly, such as a duplicate payment refund. Others, like a volume tier misapplication, change the rate going forward as well as the recovered amount.

For the wider pattern this sits inside, start with the margin drift guide.

5. Frequently Asked Questions (People Also Ask)

What is a recovery audit?

A recovery audit is a retrospective review of paid vendor invoices to find money already lost: duplicate payments, overbilling against contract terms, missed credit memos, and unapplied rebates. It looks backward at spend already recorded, not forward at the next invoice.

How far back does a recovery audit look?

Scope is set per engagement based on how far records go back and how long the relevant contracts have been in force. There is no fixed lookback window; it depends on what documentation the AP team and vendors can produce.

Is a recovery audit the same as an accounts payable audit?

They overlap. An AP audit can mean a controls review of the payment process itself. A recovery audit specifically targets dollar recovery: finding paid amounts that should not have been paid and building the case to get them back.

Does a recovery audit include contract compliance checking?

It can, when the engagement matches invoices against contract terms such as a rate card or a volume tier, not just against duplicate invoice numbers. That combination catches overbilling a duplicate-payment scan alone would miss.

What does a recovery audit find that automated AP software misses?

Automated AP software checks the invoice against the purchase order and receipt at the point of entry. It does not interpret contract terms sitting in a PDF outside the ERP, such as a rebate clause or a not-to-exceed cap, and it does not look back at invoices already paid.

Who pays for a recovery audit?

Commercial models vary by firm. Some charge a percentage of dollars recovered. Others charge a fixed fee regardless of the outcome. The model determines who keeps the recovered money and how the auditor is incentivized to scope the work.

Does a recovery audit cover freight and logistics spend?

It can when freight invoices and carrier contracts are in scope. Freight billing carries its own set of accessorial and surcharge terms that need the carrier's rate schedule to test.

Can a recovery audit be run on contract labor invoices?

Yes, when staffing or contract labor spend is included in scope. Those invoices are tested against agreed bill rates, shift premiums, and overtime terms in the staffing agreement.

1. What does a recovery audit actually check?

A recovery audit checks paid invoices against the records that should have controlled them: purchase orders, receiving documents, contract rate cards, and prior credit memos. It looks for a paid amount that has no matching authorization, a payment made twice, a rebate that was earned under a contract but never issued, or a credit that was promised and never applied to the account. The check runs on records already closed in the ERP. That is what separates it from a control that stops an invoice before payment. An auditor works from the paid invoice file, the vendor master, and the underlying contracts, matching each line against its source document rather than trusting the coded general ledger entry.

2. How does a recovery audit differ from a forward control?

A recovery audit is retrospective: it tests invoices already paid, months or years after the fact. A forward control, such as three-way matching at invoice entry, tests the next invoice before it is paid. The two answer different questions: one recovers money already lost, the other prevents the next dollar from leaking the same way. Neither replaces the other. A forward control checks the invoice against the purchase order and the receipt; it does not test whether a surcharge clause has expired or a rebate tier has been crossed, because those facts often live in a contract PDF outside the ERP. A recovery audit can surface exactly that kind of gap, then hand it to the AP team as a rule to build into future matching.

3. What documents does a recovery audit require?

A recovery audit needs the paid invoice detail, the purchase order and receiving record for each line, the governing contract or rate card, and the vendor's rebate or credit memo history. Without the contract, an auditor can only find duplicate payments and clerical errors. With the contract, an auditor can also test whether the price charged matches the price agreed. Invoice and payment data. The paid invoice file with vendor, amount, date, and general ledger coding, plus the corresponding payment record, gives the auditor the population to test and the ability to spot duplicates across vendor names or invoice number formats. Contract and rate documentation. A rate card, a volume tier schedule, or a master service agreement is what turns a duplicate-payment scan into a contract compliance check. Without it, overbilling against an agreed rate is invisible to the audit.

4. What findings come out of a recovery audit?

Findings from a recovery audit fall into a small set of named categories: duplicate payment, missed credit memo, rebate gap, volume tier misapplication, not-to-exceed overrun, and accessorial charge creep, among others. Each is a distinct mechanism, not a severity ranking, and a single engagement can surface several categories in the same vendor file. Each finding is documented with the source invoice, the contract clause or duplicate record that supports it, and the dollar amount at stake, so the client can validate the claim independently. Some findings recover cash directly, such as a [duplicate payment](/glossary/duplicate-payment) refund. Others, like a [volume tier misapplication](/glossary/volume-tier-misapplication), change the rate going forward as well as the recovered amount. For the wider pattern this sits inside, start with the [margin drift](/insights/margin-drift-spend-leakage-guide) guide.

Questions & Answers

What is a recovery audit?

A recovery audit is a retrospective review of paid vendor invoices to find money already lost: duplicate payments, overbilling against contract terms, missed credit memos, and unapplied rebates. It looks backward at spend already recorded, not forward at the next invoice.

How far back does a recovery audit look?

Scope is set per engagement based on how far records go back and how long the relevant contracts have been in force. There is no fixed lookback window; it depends on what documentation the AP team and vendors can produce.

Is a recovery audit the same as an accounts payable audit?

They overlap. An AP audit can mean a controls review of the payment process itself. A recovery audit specifically targets dollar recovery: finding paid amounts that should not have been paid and building the case to get them back.

Does a recovery audit include contract compliance checking?

It can, when the engagement matches invoices against contract terms such as a rate card or a volume tier, not just against duplicate invoice numbers. That combination catches overbilling a duplicate-payment scan alone would miss.

What does a recovery audit find that automated AP software misses?

Automated AP software checks the invoice against the purchase order and receipt at the point of entry. It does not interpret contract terms sitting in a PDF outside the ERP, such as a rebate clause or a not-to-exceed cap, and it does not look back at invoices already paid.

Margin Drift Resources