# What causes not-to-exceed overrun?

> Not-to-exceed caps fail when contract language, invoice review, and change orders don't share one number. Here's where the overrun actually starts.

Source: https://valuexpa.com/insights/what-causes-not-to-exceed-overrun
Publisher: ValueXPA (https://valuexpa.com)
Updated: 2026-09-07

---

Margin drift is the gap between what a vendor contract says and what the invoice actually charges. A not-to-exceed clause is one of the plainest forms of that gap to spot on paper and one of the easiest to miss in practice, because the invoice that beats its own cap rarely says so.

An NTE cap is a ceiling, not a target. It exists so a time-and-materials job cannot run past an agreed dollar limit without a new conversation. When it fails, the failure has a specific, traceable mechanism, not a vague one, and this page walks through what that mechanism actually is.

## Executive Summary

A [not-to-exceed overrun](/glossary/not-to-exceed-overrun) happens when a vendor bills past a contracted ceiling and nobody in the payment chain checks the invoice against that ceiling before paying it. The cap is a term written into a contract PDF. It is not a field in most AP systems, and three-way matching checks the invoice against the purchase order and the receipt, not against a dollar cap stated somewhere else. That structural gap, a real number with no system home, is the mechanism.

The overrun compounds through scope creep, change orders that reset the cap informally, and multi-invoice jobs where no single invoice looks wrong on its own. Each partial bill can sit under the line while the running total sits over it, and nothing in a standard AP workflow adds those partials up against the original ceiling.

What changes it is putting the cap somewhere it gets checked: a running total tied to the PO, a rule that flags the invoice that crosses the line, and a change-order process that updates the number in writing before work continues instead of after the invoice arrives. None of this requires new software function claims, only a matching discipline the underlying contract already specifies.

## 1. What is a not-to-exceed cap supposed to control?

**A not-to-exceed cap is a dollar ceiling written into a time-and-materials or scope-of-work contract, meant to stop a vendor from billing past an agreed limit without a new approval. It applies to the cumulative total across every invoice tied to that job or purchase order, not to any single invoice in isolation. The cap protects the buyer from open-ended labor and materials billing when the final cost of a job cannot be fixed in advance.**

The clause exists because some work cannot be priced as a fixed fee up front. A repair job, an IT project, or a maintenance call may start with a rough estimate and run on time and materials until the job is done. The NTE cap is the compromise: the vendor gets flexibility to bill actual hours and parts, and the buyer gets a ceiling that limits the downside.

The cap is a cumulative figure. It has to be tracked across every invoice issued against that PO or job number, not evaluated invoice by invoice. That distinction is where most of the mechanism described later in this page actually starts.

The contract language stating the cap usually lives in the statement of work or a PO comment field, not in the ERP's rate tables. A vendor whose ERP does not read the buyer's contract PDF has no automatic reason to stop billing at that number.

## 2. Why does three-way matching not catch the overrun?

**Three-way matching checks that an invoice agrees with its purchase order and its receipt of goods or services. It confirms quantity and unit price line up across those three documents. It does not test whether the cumulative dollar total billed against a job has crossed a not-to-exceed ceiling, because that ceiling is a separate contract term the match was never built to reference.**

The match logic answers a narrow question: did the vendor bill for what was ordered and received. An invoice can pass that test cleanly, correct hours, correct rate, correct parts, and still push the job's running total past its cap.

The NTE figure sits outside the fields the match compares. It is a project-level ceiling, not a line-item price, so the control built to catch price and quantity errors has no field to check it against.

This is a description of what the control does, not a claim about how often it fails. The gap is structural: a cap stored in a contract document is invisible to a match process that only reads the PO and the receipt.

## 3. How does scope creep push billing past the cap?

**Scope creep pushes a job past its cap when work expands beyond the original statement without a matching change order. Each added task adds billable hours or materials, and if the cap was set against the original scope, added work has nowhere to go but over the line. The invoice for the added work looks legitimate on its own; it is the scope that grew, not the invoice that lied.**

A repair job scoped for one system component becomes two once the technician is on site and finds a related failure. The additional work is real and often necessary, but the original NTE figure was set against the narrower scope.

Without a written change order that states a new cap, the vendor has no formal instruction to stop at the old number, and the buyer has no updated figure to check the invoice against. Both sides can be acting in good faith and still produce an overrun.

The fix is procedural: a change order that states the new ceiling in writing before the additional work is billed, not after the final invoice arrives asking for more than the original PO.

## 4. Can a series of small invoices cause an overrun no single invoice shows?

**Yes. A job billed across multiple partial invoices can exceed its not-to-exceed cap even when every individual invoice looks reasonable, because the cap applies to the cumulative total and nothing in a standard AP workflow automatically sums invoices against a job's original ceiling. Each invoice clears review on its own merits while the running total quietly crosses the line.**

Multi-month maintenance contracts and phased IT projects commonly bill in installments. Invoice one covers the first phase, invoice two the second, and so on. Reviewed individually, each invoice matches its own PO line and receipt.

The cap was never a per-invoice number. It was a total across all of them. An AP process built around invoice-by-invoice approval has no natural point where someone adds up every invoice against a single job and compares that sum to the original ceiling.

Catching this requires tracking spend against the PO cumulatively, not per transaction, which is a workflow design choice rather than a pricing dispute with the vendor.

## 5. Which vendor categories carry this exposure?

**Not-to-exceed exposure concentrates in categories billed on time and materials rather than a fixed price: contract labor and staffing, maintenance and repair, and IT and professional services. Each involves work whose final scope is uncertain at the start of the job, which is exactly the condition that makes an NTE clause necessary and exactly the condition that makes tracking the cumulative total against it harder to do by hand.**

These categories share one trait: the job starts before the full scope is known, which is why they carry a cap in the first place rather than a fixed price. Tracking the running total against that cap matters most where billing arrives in installments.

- **Contract labor and staffing:** Hourly billing against a project cap, where overtime or added headcount can push the total past the ceiling without a single line item looking wrong.

- **Maintenance and repair:** Emergency and diagnostic work that expands once a technician is on site, often without a revised cap in writing.

- **[IT and professional services](/glossary/it-and-professional-services-audit):** Phased statements of work billed in installments, where the cumulative total is the only number that matters and the one least often tracked.

- **Calibration and safety compliance:** Recurring service contracts where added units or added visits can accumulate against an annual cap over many small invoices.

## 6. How does an unclear change order process cause the overrun?

**A change order process causes overrun when it exists informally, over email or a phone call, instead of as a written revision to the PO and its stated cap. Verbal approval to proceed with added work is not the same document as an updated not-to-exceed figure, and AP has nothing but the original number to check the final invoice against when the change was never captured in writing.**

A site manager telling a vendor to go ahead with extra work is a common and reasonable operational decision. It is not, by itself, a contract amendment. If that approval never becomes a written change order with a new dollar figure, the PO in the ERP still shows the old cap.

AP then faces an invoice that exceeds the only number in the system, with no paper trail explaining why. The choice becomes pay it anyway, on the assumption the field approval was legitimate, or hold it and chase down an explanation after the fact.

A change order process that requires the new cap in writing before work continues removes that ambiguity. It gives AP a current number to match against instead of a stale one.

## 7. What closes the gap between the contract cap and the paid invoice?

**Closing the gap means giving the not-to-exceed figure a place to live where it gets checked automatically: a running cumulative total tied to the PO, a rule that flags any invoice pushing that total past the stated cap, and a change order requirement that updates the figure in writing before additional work is billed. None of this changes what three-way matching does. It adds a second check the match was never designed to perform.**

The contract already states the number. The work is making that number visible at the point an invoice is reviewed, as a running total rather than a one-time reference buried in a statement of work.

A cumulative tracking rule flags the invoice that crosses the line before payment, which is the point where the overrun is still recoverable as a hold rather than a completed payment to chase back.

A written change order requirement closes the scope creep path by giving both sides an updated ceiling before the next invoice is billed against it, rather than after.

For the wider pattern this sits inside, start with the [margin drift](/insights/margin-drift-spend-leakage-guide) guide.

## 8. Frequently Asked Questions (People Also Ask)

### What is a not-to-exceed overrun?

It is billing on a job that exceeds the dollar ceiling stated in that job's contract or purchase order. It happens when the cumulative total across all invoices tied to the job passes the agreed cap, whether or not any single invoice looks incorrect on its own.

### Does three-way matching catch a not-to-exceed overrun?

No. Three-way matching checks an invoice against its purchase order and receipt for quantity and price. It does not compare the cumulative billed total on a job against a separate not-to-exceed figure stated in the contract, because that figure is not a field the match reads.

### Can a vendor legitimately bill past the NTE cap?

Only with a written change order that revises the cap. Without that document, an invoice pushing the cumulative total past the original figure has no contractual basis for the amount above the line, regardless of whether the added work was actually performed.

### Why do multiple small invoices cause this more than one large invoice?

Because the cap is a cumulative figure, not a per-invoice limit. A series of partial invoices can each clear review individually while their running sum crosses the ceiling, and a workflow built around single-invoice approval has no natural point to catch that.

### Is scope creep the same thing as a not-to-exceed overrun?

Scope creep is a common cause of it. Added work beyond the original statement of work increases billable hours or materials, and if the cap was never revised in writing to match the new scope, the added billing has nowhere to go but past the original ceiling.

### Which contract types are most exposed to NTE overrun?

Time-and-materials and phased statements of work carry this exposure, because the final billed amount is not fixed in advance. Fixed-price contracts do not carry the same risk, since the total is set before work begins.

### What should AP do when an invoice exceeds the stated NTE cap?

Hold the invoice and request the change order or written approval that authorizes the amount above the original cap. Paying it without that document treats a verbal or informal approval as equivalent to a contract amendment, which it is not.

### Does this apply to fixed-fee contracts?

Not typically. A not-to-exceed cap is a control specific to open-ended, time-and-materials style billing. A fixed-fee contract already states the total price, so there is no separate ceiling to track against a running invoice total.

### Is contract complexity quietly draining your operating margin?

A small systematic drift between your negotiated contracts and your actual vendor billing compounds quietly across a year of invoices. Stop guessing at your exposure and run a targeted audit.

**[Take the Free Screener → https://valuexpa.com/margin-drift-screener](https://valuexpa.com/margin-drift-screener)**

## Executive Summary

A [not-to-exceed overrun](/glossary/not-to-exceed-overrun) happens when a vendor bills past a contracted ceiling and nobody in the payment chain checks the invoice against that ceiling before paying it. The cap is a term written into a contract PDF. It is not a field in most AP systems, and three-way matching checks the invoice against the purchase order and the receipt, not against a dollar cap stated somewhere else. That structural gap, a real number with no system home, is the mechanism. The overrun compounds through scope creep, change orders that reset the cap informally, and multi-invoice jobs where no single invoice looks wrong on its own. Each partial bill can sit under the line while the running total sits over it, and nothing in a standard AP workflow adds those partials up against the original ceiling. What changes it is putting the cap somewhere it gets checked: a running total tied to the PO, a rule that flags the invoice that crosses the line, and a change-order process that updates the number in writing before work continues instead of after the invoice arrives. None of this requires new software function claims, only a matching discipline the underlying contract already specifies.

## 1. What is a not-to-exceed cap supposed to control?

A not-to-exceed cap is a dollar ceiling written into a time-and-materials or scope-of-work contract, meant to stop a vendor from billing past an agreed limit without a new approval. It applies to the cumulative total across every invoice tied to that job or purchase order, not to any single invoice in isolation. The cap protects the buyer from open-ended labor and materials billing when the final cost of a job cannot be fixed in advance. The clause exists because some work cannot be priced as a fixed fee up front. A repair job, an IT project, or a maintenance call may start with a rough estimate and run on time and materials until the job is done. The NTE cap is the compromise: the vendor gets flexibility to bill actual hours and parts, and the buyer gets a ceiling that limits the downside. The cap is a cumulative figure. It has to be tracked across every invoice issued against that PO or job number, not evaluated invoice by invoice. That distinction is where most of the mechanism described later in this page actually starts. The contract language stating the cap usually lives in the statement of work or a PO comment field, not in the ERP's rate tables. A vendor whose ERP does not read the buyer's contract PDF has no automatic reason to stop billing at that number.

## 2. Why does three-way matching not catch the overrun?

Three-way matching checks that an invoice agrees with its purchase order and its receipt of goods or services. It confirms quantity and unit price line up across those three documents. It does not test whether the cumulative dollar total billed against a job has crossed a not-to-exceed ceiling, because that ceiling is a separate contract term the match was never built to reference. The match logic answers a narrow question: did the vendor bill for what was ordered and received. An invoice can pass that test cleanly, correct hours, correct rate, correct parts, and still push the job's running total past its cap. The NTE figure sits outside the fields the match compares. It is a project-level ceiling, not a line-item price, so the control built to catch price and quantity errors has no field to check it against. This is a description of what the control does, not a claim about how often it fails. The gap is structural: a cap stored in a contract document is invisible to a match process that only reads the PO and the receipt.

## 3. How does scope creep push billing past the cap?

Scope creep pushes a job past its cap when work expands beyond the original statement without a matching change order. Each added task adds billable hours or materials, and if the cap was set against the original scope, added work has nowhere to go but over the line. The invoice for the added work looks legitimate on its own; it is the scope that grew, not the invoice that lied. A repair job scoped for one system component becomes two once the technician is on site and finds a related failure. The additional work is real and often necessary, but the original NTE figure was set against the narrower scope. Without a written change order that states a new cap, the vendor has no formal instruction to stop at the old number, and the buyer has no updated figure to check the invoice against. Both sides can be acting in good faith and still produce an overrun. The fix is procedural: a change order that states the new ceiling in writing before the additional work is billed, not after the final invoice arrives asking for more than the original PO.

## 4. Can a series of small invoices cause an overrun no single invoice shows?

Yes. A job billed across multiple partial invoices can exceed its not-to-exceed cap even when every individual invoice looks reasonable, because the cap applies to the cumulative total and nothing in a standard AP workflow automatically sums invoices against a job's original ceiling. Each invoice clears review on its own merits while the running total quietly crosses the line. Multi-month maintenance contracts and phased IT projects commonly bill in installments. Invoice one covers the first phase, invoice two the second, and so on. Reviewed individually, each invoice matches its own PO line and receipt. The cap was never a per-invoice number. It was a total across all of them. An AP process built around invoice-by-invoice approval has no natural point where someone adds up every invoice against a single job and compares that sum to the original ceiling. Catching this requires tracking spend against the PO cumulatively, not per transaction, which is a workflow design choice rather than a pricing dispute with the vendor.

## 5. Which vendor categories carry this exposure?

Not-to-exceed exposure concentrates in categories billed on time and materials rather than a fixed price: contract labor and staffing, maintenance and repair, and IT and professional services. Each involves work whose final scope is uncertain at the start of the job, which is exactly the condition that makes an NTE clause necessary and exactly the condition that makes tracking the cumulative total against it harder to do by hand. These categories share one trait: the job starts before the full scope is known, which is why they carry a cap in the first place rather than a fixed price. Tracking the running total against that cap matters most where billing arrives in installments. - Contract labor and staffing: Hourly billing against a project cap, where overtime or added headcount can push the total past the ceiling without a single line item looking wrong. - Maintenance and repair: Emergency and diagnostic work that expands once a technician is on site, often without a revised cap in writing. - [IT and professional services](/glossary/it-and-professional-services-audit): Phased statements of work billed in installments, where the cumulative total is the only number that matters and the one least often tracked. - Calibration and safety compliance: Recurring service contracts where added units or added visits can accumulate against an annual cap over many small invoices.

## 6. How does an unclear change order process cause the overrun?

A change order process causes overrun when it exists informally, over email or a phone call, instead of as a written revision to the PO and its stated cap. Verbal approval to proceed with added work is not the same document as an updated not-to-exceed figure, and AP has nothing but the original number to check the final invoice against when the change was never captured in writing. A site manager telling a vendor to go ahead with extra work is a common and reasonable operational decision. It is not, by itself, a contract amendment. If that approval never becomes a written change order with a new dollar figure, the PO in the ERP still shows the old cap. AP then faces an invoice that exceeds the only number in the system, with no paper trail explaining why. The choice becomes pay it anyway, on the assumption the field approval was legitimate, or hold it and chase down an explanation after the fact. A change order process that requires the new cap in writing before work continues removes that ambiguity. It gives AP a current number to match against instead of a stale one.

## 7. What closes the gap between the contract cap and the paid invoice?

Closing the gap means giving the not-to-exceed figure a place to live where it gets checked automatically: a running cumulative total tied to the PO, a rule that flags any invoice pushing that total past the stated cap, and a change order requirement that updates the figure in writing before additional work is billed. None of this changes what three-way matching does. It adds a second check the match was never designed to perform. The contract already states the number. The work is making that number visible at the point an invoice is reviewed, as a running total rather than a one-time reference buried in a statement of work. A cumulative tracking rule flags the invoice that crosses the line before payment, which is the point where the overrun is still recoverable as a hold rather than a completed payment to chase back. A written change order requirement closes the scope creep path by giving both sides an updated ceiling before the next invoice is billed against it, rather than after. For the wider pattern this sits inside, start with the [margin drift](/insights/margin-drift-spend-leakage-guide) guide.

## Common questions

### What is a not-to-exceed overrun?

It is billing on a job that exceeds the dollar ceiling stated in that job's contract or purchase order. It happens when the cumulative total across all invoices tied to the job passes the agreed cap, whether or not any single invoice looks incorrect on its own.

### Does three-way matching catch a not-to-exceed overrun?

No. Three-way matching checks an invoice against its purchase order and receipt for quantity and price. It does not compare the cumulative billed total on a job against a separate not-to-exceed figure stated in the contract, because that figure is not a field the match reads.

### Can a vendor legitimately bill past the NTE cap?

Only with a written change order that revises the cap. Without that document, an invoice pushing the cumulative total past the original figure has no contractual basis for the amount above the line, regardless of whether the added work was actually performed.

### Why do multiple small invoices cause this more than one large invoice?

Because the cap is a cumulative figure, not a per-invoice limit. A series of partial invoices can each clear review individually while their running sum crosses the ceiling, and a workflow built around single-invoice approval has no natural point to catch that.

### Is scope creep the same thing as a not-to-exceed overrun?

Scope creep is a common cause of it. Added work beyond the original statement of work increases billable hours or materials, and if the cap was never revised in writing to match the new scope, the added billing has nowhere to go but past the original ceiling.

---

ValueXPA runs a fixed-scope Margin Drift Diagnostic that validates every service vendor invoice against contract terms, for $100M+ US industrial manufacturers and distributors. Two to four weeks. The client retains 100% of recoveries. https://valuexpa.com/contact-us
