Vendor invoice checks before an external audit

Checklist guide for AP and controller teams to prep vendor invoices before an external audit begins, covering matching, credits, surcharges, and documentation.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Vendor invoice checks before an external audit

Margin drift is the gap between what a vendor contract says and what the invoice actually charges. An external audit, whether financial statement, sponsor-driven, or tied to a refinancing, will surface that gap if you have not already found it yourself.

Running your own checks first changes the audit from a discovery exercise into a confirmation exercise. It also gives you time to fix what you find, book the credit, or explain the variance before an outside party asks the question in a room you do not control.

Executive Summary

An external audit tests whether the numbers on your financial statements match what actually happened between you and your vendors. Most companies walk in having reconciled the general ledger but not the underlying invoices against the contracts that were supposed to govern them. That gap, a rate card nobody re-checked, a rebate nobody claimed, a surcharge that outlived the condition that justified it, is exactly what an experienced auditor's sample testing tends to find.

The mechanism is simple: contracts sit in PDFs outside the ERP, invoices get paid against the PO and the received quantity, and nobody tests the invoice against the contract clause itself. Three-way matching confirms an invoice matches a purchase order and a receipt. It does not confirm the rate on that invoice matches the rate card the vendor agreed to eighteen months ago.

What changes the outcome is running the same checks the auditor will run, before they run them: matching invoices to contract terms, testing surcharges against their stated trigger conditions, and confirming credit memos were applied rather than just issued. Each finding you close before the audit starts is a finding you explain on your own terms instead of theirs.

1. What should you check before an external audit?

Check four things: whether invoiced rates match the current contract or rate card, whether every surcharge still meets the condition that justified it, whether issued credit memos were actually applied against a payable, and whether any vendor was paid twice for the same service period. These are the checks that turn up in sample testing, and they are the ones you can close before an auditor selects them for you.

Start with the vendor list ranked by annual spend, not by invoice count. A high-volume, low-dollar vendor wastes review time; a mid-frequency vendor with a complex rate card is where the exposure sits.

Pull the current signed contract or rate card for each vendor above your review threshold, not the version in the ERP master file, which is often stale. Compare it line by line against a sample of recent invoices.

Separately, pull every credit memo issued in the audit period and trace it to an applied credit on a payable, not just a line in the vendor's records. An issued credit that was never applied is cash sitting with the vendor, not a resolved item.

Finally, run a duplicate-payment scan across vendor, invoice amount, and service date, not just invoice number, since a resubmitted invoice with a new number will not match on number alone.

2. How do you test whether an invoiced rate still matches the contract?

Pull the rate card's effective clauses, tiered volume breakpoints, and any escalation formula, then recompute a sample of invoices from the source terms rather than trusting the vendor's stated rate. A rate that was correct on day one of the contract can drift silently if a volume tier was never re-triggered or an escalation clause was applied without the condition that permits it.

Rate cards rarely fail all at once. They fail one line at a time: a new SKU billed at list instead of the negotiated rate, a volume tier that should have stepped the price down once you crossed a threshold, or an annual escalation applied on the wrong anniversary date.

Build the check as a recomputation, not a comparison. Take the contract's stated formula and the invoice's own quantity and date fields, and calculate what the line should have cost. Then compare that number to what was actually billed.

This matters because a straight side-by-side of "rate on invoice" versus "rate in contract" only catches an error where someone typed the wrong number. It misses a correctly-typed rate that no longer applies because a volume threshold or contract amendment changed it.

3. Which surcharges deserve a second look before the auditor arrives?

Any surcharge tied to a condition, a fuel index, a minimum weight, a peak-season window, deserves review, because the condition that justified it can lapse while the line item on the invoice keeps running unchanged. Pull the vendor's own published tariff or the contract clause for each surcharge type, confirm the trigger condition still holds for the billing period, and flag any surcharge charged on a shipment or service that never met the stated minimum.

A fuel surcharge or peak-season fee is usually tied to an external index or a calendar window stated in the carrier's tariff or your contract. The number on the invoice is only correct if that index or window still applies to that specific line.

The common failure is not fraud, it is a surcharge that was correctly added once and never removed once the triggering condition ended. A peak-season accessorial charged in a month outside the stated peak window is a clean, checkable example.

Document the trigger condition and the source, the carrier tariff, the fuel index, the contract clause, for each surcharge type you review, and date the figure you checked it against. An auditor asking where a surcharge came from wants that same trail.

4. How do you confirm a credit memo actually reduced what you paid?

Trace every credit memo from issuance to application: find the memo, find the payable or future invoice it was applied against, and confirm the dollar amount matches. A credit memo that exists only as a document, with no corresponding reduction in cash paid or a payable balance, has not actually recovered anything, whatever the AP ledger note says.

Vendors issue credit memos for returns, pricing corrections, and volume rebates. The memo itself is not the recovery. The recovery happens when that credit offsets a payment or reduces a future invoice.

Build the trace both directions. From the memo forward: find where it landed. From the cash side backward: for any large credit balance sitting on a vendor account, confirm whether it has an issued memo behind it or is simply unreconciled.

Rebate clauses are a particular risk here because they are often self-reported by the vendor on an annual or quarterly cycle. If your contract entitles you to a volume rebate, the burden is on you to calculate what you are owed and request it. An auditor testing rebate income will ask for that calculation, not just the vendor's check.

5. What documentation does the audit actually expect you to produce?

Expect to produce the signed contract or rate card for each material vendor, the calculation behind any rebate or credit claimed, and a written basis for any surcharge charged outside its stated schedule. Verbal confirmation from a vendor relationship manager is not documentation. The auditor is testing whether your controls would catch an error, so the paper trail matters as much as the number it supports.

Organize documentation by vendor, not by transaction. For each material vendor, assemble the current contract, the rate card or tariff referenced in it, and any amendment or side letter that changed a term during the period under review.

For any finding you closed before the audit, keep the evidence of the fix: the recalculation, the credit memo obtained, the corrected invoice. A finding you already resolved is a stronger position than a clean invoice file with no evidence you ever tested it.

Wherever the review touches a contractual or regulatory obligation, this guide is general information, not legal advice. Confirm any contract interpretation with counsel before treating it as final.

6. Should you run these checks in-house or bring in outside help?

Run them in-house when your AP team already has time, ERP access, and the contract files organized. Bring in outside help when the volume of vendors and contracts exceeds what your team can test before the audit date, or when you need the review done by someone with no stake in the answer. Both approaches produce the same checklist; the difference is speed and independence.

An in-house team knows the vendor relationships and can move fast on a small vendor list. The constraint is usually time: the same team doing month-end close and AP processing rarely has weeks free to recompute rate cards against a full invoice history.

An outside review adds independence, which matters most when the audit is sponsor-driven or tied to a transaction, because a reviewer with no relationship to the vendor asks harder questions about a rate that looks right on the surface.

Either way, the work is the same four checks: rate card, surcharge, credit memo, duplicate payment, run against 12 to 18 months of invoice history, per the same window an external audit typically samples from.

7. What should you do once the checks are done?

Close what you can before the audit starts: apply outstanding credits, correct rates going forward, and document what you found and fixed. Anything you cannot fully resolve in time, disclose it yourself, with the calculation behind it, rather than leaving it for the auditor to surface. A self-reported finding with a fix in progress reads very differently than the same finding discovered independently.

Prioritize by dollar impact first. A rate error on a high-volume vendor is worth closing before a smaller one, even if the smaller one is easier to fix.

For anything you cannot resolve before the audit date, write it down: what you found, the dollar exposure as best you can calculate it, and what you are doing about it. That memo becomes your talking point instead of the auditor's finding.

Once this cycle is done, the harder question is how to stop the same drift from reaccumulating before the next audit. That is a control question, not an audit-prep question, and it points toward margin drift as an ongoing discipline rather than a once-a-year scramble.

For the wider pattern this sits inside, start with the margin drift guide. See also the six categories drift hides in and margin drift vs. legitimate price increases: how to tell them apart.

8. Frequently Asked Questions (People Also Ask)

How far back should we check invoices before an external audit?

Align the review window to what the audit itself will sample, typically 12 to 18 months of invoice history. Checking further back rarely changes the audit outcome and spreads review time thin across periods the auditor is not testing.

What is the difference between three-way matching and a contract compliance check?

Three-way matching checks that an invoice agrees with a purchase order and a receipt. It does not test whether the rate, surcharge, or rebate clause on that invoice matches the underlying contract, which is a separate check against a document outside the ERP.

Do we need to review every vendor or just the largest ones?

Rank vendors by annual spend and review down to the point where remaining vendors are individually immaterial. A high-invoice-count, low-dollar vendor is a poor use of review time compared to a mid-frequency vendor with a complex rate card.

What counts as evidence that a finding was resolved before the audit?

The recalculation showing the error, the corrected invoice or credit memo obtained from the vendor, and a note of when it was applied. A verbal confirmation from a vendor contact is not sufficient documentation on its own.

Can an unapplied credit memo cause a problem in an external audit?

Yes. An issued but unapplied credit memo means the vendor still holds cash that belongs to you, and an auditor testing accounts payable balances may flag the unreconciled credit even if the memo itself is not in question.

Should we tell the auditor about issues we find before they ask?

Disclosing a finding you identified and are actively resolving is generally viewed differently than the same issue being discovered independently. This is general information, not legal advice; confirm disclosure obligations with counsel where a regulatory filing is involved.

Is a surcharge review really worth the time before an audit?

Surcharges tied to a fuel index, a peak season window, or a minimum weight are checkable against a stated source in minutes per vendor, and a surcharge charged outside its trigger condition is one of the more visible findings a sample test can surface.

What is the fastest way to prioritize which vendors to check first?

Sort by annual spend, then flag vendors with tiered pricing, rebate clauses, or recurring surcharges, since those contract structures create more opportunities for the invoice to drift from the agreed terms than a flat-rate vendor does.

Does this replace the work an external auditor does?

No. It closes the gap between what your invoices say and what your contracts say before the auditor tests that same gap, which changes how findings surface but does not replace the audit's own procedures.

What should we do if we find a duplicate payment right before the audit?

Document the duplicate, the invoice numbers and dates involved, and pursue the credit or refund from the vendor immediately. A duplicate payment identified and in recovery reads as a working control; one discovered by the auditor reads as a gap in one.

Executive Summary

An external audit tests whether the numbers on your financial statements match what actually happened between you and your vendors. Most companies walk in having reconciled the general ledger but not the underlying invoices against the contracts that were supposed to govern them. That gap, a rate card nobody re-checked, a rebate nobody claimed, a surcharge that outlived the condition that justified it, is exactly what an experienced auditor's sample testing tends to find. The mechanism is simple: contracts sit in PDFs outside the ERP, invoices get paid against the PO and the received quantity, and nobody tests the invoice against the contract clause itself. Three-way matching confirms an invoice matches a purchase order and a receipt. It does not confirm the rate on that invoice matches the rate card the vendor agreed to eighteen months ago. What changes the outcome is running the same checks the auditor will run, before they run them: matching invoices to contract terms, testing surcharges against their stated trigger conditions, and confirming credit memos were applied rather than just issued. Each finding you close before the audit starts is a finding you explain on your own terms instead of theirs.

1. What should you check before an external audit?

Check four things: whether invoiced rates match the current contract or rate card, whether every surcharge still meets the condition that justified it, whether issued credit memos were actually applied against a payable, and whether any vendor was paid twice for the same service period. These are the checks that turn up in sample testing, and they are the ones you can close before an auditor selects them for you. Start with the vendor list ranked by annual spend, not by invoice count. A high-volume, low-dollar vendor wastes review time; a mid-frequency vendor with a complex rate card is where the exposure sits. Pull the current signed contract or rate card for each vendor above your review threshold, not the version in the ERP master file, which is often stale. Compare it line by line against a sample of recent invoices. Separately, pull every credit memo issued in the audit period and trace it to an applied credit on a payable, not just a line in the vendor's records. An issued credit that was never applied is cash sitting with the vendor, not a resolved item. Finally, run a duplicate-payment scan across vendor, invoice amount, and service date, not just invoice number, since a resubmitted invoice with a new number will not match on number alone.

2. How do you test whether an invoiced rate still matches the contract?

Pull the rate card's effective clauses, tiered volume breakpoints, and any escalation formula, then recompute a sample of invoices from the source terms rather than trusting the vendor's stated rate. A rate that was correct on day one of the contract can drift silently if a volume tier was never re-triggered or an escalation clause was applied without the condition that permits it. Rate cards rarely fail all at once. They fail one line at a time: a new SKU billed at list instead of the negotiated rate, a volume tier that should have stepped the price down once you crossed a threshold, or an annual escalation applied on the wrong anniversary date. Build the check as a recomputation, not a comparison. Take the contract's stated formula and the invoice's own quantity and date fields, and calculate what the line should have cost. Then compare that number to what was actually billed. This matters because a straight side-by-side of "rate on invoice" versus "rate in contract" only catches an error where someone typed the wrong number. It misses a correctly-typed rate that no longer applies because a volume threshold or contract amendment changed it.

3. Which surcharges deserve a second look before the auditor arrives?

Any surcharge tied to a condition, a fuel index, a minimum weight, a peak-season window, deserves review, because the condition that justified it can lapse while the line item on the invoice keeps running unchanged. Pull the vendor's own published tariff or the contract clause for each surcharge type, confirm the trigger condition still holds for the billing period, and flag any surcharge charged on a shipment or service that never met the stated minimum. A fuel surcharge or peak-season fee is usually tied to an external index or a calendar window stated in the carrier's tariff or your contract. The number on the invoice is only correct if that index or window still applies to that specific line. The common failure is not fraud, it is a surcharge that was correctly added once and never removed once the triggering condition ended. A peak-season accessorial charged in a month outside the stated peak window is a clean, checkable example. Document the trigger condition and the source, the carrier tariff, the fuel index, the contract clause, for each surcharge type you review, and date the figure you checked it against. An auditor asking where a surcharge came from wants that same trail.

4. How do you confirm a credit memo actually reduced what you paid?

Trace every credit memo from issuance to application: find the memo, find the payable or future invoice it was applied against, and confirm the dollar amount matches. A credit memo that exists only as a document, with no corresponding reduction in cash paid or a payable balance, has not actually recovered anything, whatever the AP ledger note says. Vendors issue credit memos for returns, pricing corrections, and volume rebates. The memo itself is not the recovery. The recovery happens when that credit offsets a payment or reduces a future invoice. Build the trace both directions. From the memo forward: find where it landed. From the cash side backward: for any large credit balance sitting on a vendor account, confirm whether it has an issued memo behind it or is simply unreconciled. Rebate clauses are a particular risk here because they are often self-reported by the vendor on an annual or quarterly cycle. If your contract entitles you to a volume rebate, the burden is on you to calculate what you are owed and request it. An auditor testing rebate income will ask for that calculation, not just the vendor's check.

5. What documentation does the audit actually expect you to produce?

Expect to produce the signed contract or rate card for each material vendor, the calculation behind any rebate or credit claimed, and a written basis for any surcharge charged outside its stated schedule. Verbal confirmation from a vendor relationship manager is not documentation. The auditor is testing whether your controls would catch an error, so the paper trail matters as much as the number it supports. Organize documentation by vendor, not by transaction. For each material vendor, assemble the current contract, the rate card or tariff referenced in it, and any amendment or side letter that changed a term during the period under review. For any finding you closed before the audit, keep the evidence of the fix: the recalculation, the credit memo obtained, the corrected invoice. A finding you already resolved is a stronger position than a clean invoice file with no evidence you ever tested it. Wherever the review touches a contractual or regulatory obligation, this guide is general information, not legal advice. Confirm any contract interpretation with counsel before treating it as final.

6. Should you run these checks in-house or bring in outside help?

Run them in-house when your AP team already has time, ERP access, and the contract files organized. Bring in outside help when the volume of vendors and contracts exceeds what your team can test before the audit date, or when you need the review done by someone with no stake in the answer. Both approaches produce the same checklist; the difference is speed and independence. An in-house team knows the vendor relationships and can move fast on a small vendor list. The constraint is usually time: the same team doing month-end close and AP processing rarely has weeks free to recompute rate cards against a full invoice history. An outside review adds independence, which matters most when the audit is sponsor-driven or tied to a transaction, because a reviewer with no relationship to the vendor asks harder questions about a rate that looks right on the surface. Either way, the work is the same four checks: rate card, surcharge, credit memo, duplicate payment, run against 12 to 18 months of invoice history, per the same window an external audit typically samples from.

7. What should you do once the checks are done?

Close what you can before the audit starts: apply outstanding credits, correct rates going forward, and document what you found and fixed. Anything you cannot fully resolve in time, disclose it yourself, with the calculation behind it, rather than leaving it for the auditor to surface. A self-reported finding with a fix in progress reads very differently than the same finding discovered independently. Prioritize by dollar impact first. A rate error on a high-volume vendor is worth closing before a smaller one, even if the smaller one is easier to fix. For anything you cannot resolve before the audit date, write it down: what you found, the dollar exposure as best you can calculate it, and what you are doing about it. That memo becomes your talking point instead of the auditor's finding. Once this cycle is done, the harder question is how to stop the same drift from reaccumulating before the next audit. That is a control question, not an audit-prep question, and it points toward [margin drift as an ongoing discipline](/guides/margin-drift-in-industrial-distribution) rather than a once-a-year scramble. For the wider pattern this sits inside, start with the [margin drift](/guides/cfo-agenda-mid-market-manufacturing) guide. See also [the six categories drift hides in](/guides/indirect-spend-audit-categories) and [margin drift vs. legitimate price increases: how to tell them apart](/guides/margin-drift-vs-legitimate-price-increases-how-to-tell-them).

Questions & Answers

How far back should we check invoices before an external audit?

Align the review window to what the audit itself will sample, typically 12 to 18 months of invoice history. Checking further back rarely changes the audit outcome and spreads review time thin across periods the auditor is not testing.

What is the difference between three-way matching and a contract compliance check?

Three-way matching checks that an invoice agrees with a purchase order and a receipt. It does not test whether the rate, surcharge, or rebate clause on that invoice matches the underlying contract, which is a separate check against a document outside the ERP.

Do we need to review every vendor or just the largest ones?

Rank vendors by annual spend and review down to the point where remaining vendors are individually immaterial. A high-invoice-count, low-dollar vendor is a poor use of review time compared to a mid-frequency vendor with a complex rate card.

What counts as evidence that a finding was resolved before the audit?

The recalculation showing the error, the corrected invoice or credit memo obtained from the vendor, and a note of when it was applied. A verbal confirmation from a vendor contact is not sufficient documentation on its own.

Can an unapplied credit memo cause a problem in an external audit?

Yes. An issued but unapplied credit memo means the vendor still holds cash that belongs to you, and an auditor testing accounts payable balances may flag the unreconciled credit even if the memo itself is not in question.

Margin Drift Resources