Where margin drift shows up before an external audit

Pre-audit checklist for margin drift: five contract-to-invoice checks finance teams should run before an external audit surfaces the gap. Read the full guide.

Twitter LinkedIn WhatsApp
Ask AI: ChatGPT Claude Gemini Grok
Where margin drift shows up before an external audit

Margin drift is the gap between what a vendor contract says and what the invoice actually charges. It rarely gets caught by a normal AP cycle, because AP is built to confirm a PO and a receipt matched an invoice, not to test a rate card, a rebate clause, or a surcharge that outlived its trigger condition.

An external audit does not go looking for margin drift on purpose. But it asks questions that expose it anyway, and a finance team that has not tested for it first ends up explaining a gap live, in the room, instead of ahead of time.

Executive Summary

The problem an external audit surfaces is rarely the audit's actual objective. It asks for a fluctuation explanation, a vendor confirmation, or a sample of invoice support, and margin drift shows up as the residual nobody assigned an owner to. That residual gets asked about at the worst possible time: in front of a partner, with no prepared answer.

The mechanism is structural, not a lapse by any one person. Three-way matching checks the invoice against the purchase order and the receipt. It does not check whether the rate on the invoice matches the rate in the contract, whether a volume tier applies, or whether a rebate the contract promises was ever claimed.

Those checks live nowhere in the standard AP control set, so the gap accumulates quietly across a fiscal year and only becomes visible when someone is asked to explain it.

What changes it is running the contract-to-invoice checks before the auditor asks, not after. This page names the specific places to look: rate card currency, surcharge expiration, rebate accrual, NTE caps, and vendor master duplication. Each one is a bounded, testable question with a clear owner and a clear artifact to produce, so the answer exists before the question is asked.

1. What should you check before an external audit?

Check five things: whether invoiced rates still match the signed rate card, whether surcharges still meet their contractual trigger condition, whether earned rebates were claimed, whether not-to-exceed caps were tested against actual billing, and whether the vendor master contains duplicate or near-duplicate entries. Each is a bounded question with a yes-or-no answer, and each produces a specific artifact an auditor or a controller can review without follow-up questions.

An auditor's fluctuation analysis compares this period's spend to last period's or to budget. A variance in a service vendor category triggers a question: what changed. If nobody has already tested the contract against the invoice, the honest answer is "we don't know yet," and that answer invites more sampling, not less.

Running the five checks above before the request lands turns that exchange around. Instead of investigating on demand, the finance team hands over a short memo: which vendors were tested, what was found, what was corrected. An auditor reviewing a documented control response closes the item faster than one opening a new inquiry.

The checks do not require new software or a new team. They require pulling the current rate card, the current contract, and prior invoices for the vendors that carry the largest indirect spend, and comparing line by line. It is slow work done manually and fast work done with a defined method.

  1. Rate card currency: Confirm the rate on the last several invoices matches the most recently signed rate card, not an earlier version still sitting in the AP system.
  2. Surcharge trigger condition: Confirm a fuel or accessorial surcharge still meets the condition that justified it, rather than continuing to bill after the condition lapsed.
  3. Rebate claim status: Confirm a volume or spend rebate the contract promises has actually been invoiced back or credited, not left unclaimed.
  4. NTE cap testing: Confirm billing on a not-to-exceed contract has not quietly crossed the cap across several invoices that were each approved individually.
  5. Vendor master duplication: Confirm the same vendor is not entered twice under a slightly different name, which both invites duplicate payment and confuses spend reporting.

2. Why does three-way matching miss this?

Three-way matching checks that the invoice quantity and price match the purchase order and that the goods or services were received. It does not read the underlying contract, so it cannot test whether the price on the PO itself is the correct contracted rate, whether a volume tier changed the rate mid-year, or whether a rebate clause applies. It confirms internal consistency, not contract compliance.

The control was designed to catch a different failure: someone billing for goods never received, or at a price never agreed by whoever created the PO. It answers "does this invoice match what we told the vendor to charge," not "is what we told the vendor to charge still correct."

A stale rate card passes three-way matching cleanly, because the PO was built from the same stale rate. The invoice matches the PO. The PO matches the receipt. Every control in the chain reports green, and the gap between the signed contract and the billed rate never touches a system that would flag it.

This is a design limitation, not an implementation failure at any one company. The fix is a separate check that reads the contract document itself, usually a PDF outside the ERP, and compares its terms against the billed rate directly. That check has to be added; it does not come free with standard AP controls.

3. Which contract terms are easiest to miss?

Terms that depend on a condition changing over time are the easiest to miss, because the invoice looks identical before and after the condition changes. A volume tier, a rebate threshold, a surcharge expiration date, and an escalation clause tied to an index all require someone to notice a date or a quantity crossed a line. Fixed unit prices rarely drift; conditional terms drift constantly because nothing forces a re-check.

A fixed price per unit is easy to audit because it never changes. If the invoice matches the contract on day one, it should match on day 400, and any deviation is visible on sight. Conditional terms are different: they are correct on day one and quietly wrong on day 400, with no visual signal on the invoice itself.

A volume tier is a common example. A contract might price a service lower once annual spend crosses a threshold. Nobody automatically recalculates that threshold as spend accrues, so the lower rate can go unapplied well after it should have started.

A surcharge tied to a market condition, like a fuel index, behaves the same way in reverse: it starts correctly and should fall or expire when the index moves, but nothing in the AP workflow re-tests it once it is set up. It carries forward at the original rate because it was originally correct.

4. How do you document findings for an auditor?

Document each finding as a three-part record: the contract term as written, the rate or condition actually billed, and the dollar effect of the difference over the period tested. Keep the underlying contract page and the invoice line side by side as support. This format answers an auditor's question before it is asked and gives the controller a paper trail for the correction or credit memo that follows.

A finding without its source contract page is an assertion, and an auditor working from assertions will re-derive the number independently, which takes longer for everyone. Attaching the actual contract language, highlighted, removes that step.

The dollar effect should be stated for the period actually tested, not annualized without saying so. If several months of invoices were reviewed and the gap was found in a subset of them, state that subset rather than extrapolating silently. An auditor who catches an unstated extrapolation treats every other number on the page with more suspicion, not less.

Where a finding is still open, a memo, rather than silence, is important. State that the vendor has been notified and a credit is pending. An open item with a documented plan reads as a control working; an open item nobody mentioned reads as a control that failed.

5. Should you fix the drift before or after the audit?

Fix what you can verify before the audit begins, and disclose what is still in progress rather than waiting to present a finished picture. An auditor who finds an issue the company already identified and is actively correcting treats it as a control operating correctly. An auditor who finds the same issue independently, with no prior documentation, treats it as a control gap and tests more broadly as a result.

The instinct to wait until everything is resolved is understandable but works against the company. Audits run on a timeline, and correction work on vendor contracts, credits, and rebate claims can take longer than the audit window allows.

A partial correction, documented honestly, is a stronger position than a delayed, complete one. "We identified this gap during our own review, corrected these vendors, and are pursuing credit on the remainder" is a sentence an auditor can work with. It shows the control exists and is being operated, which is closer to what the audit is actually testing than the dollar figure itself.

This also protects the following year. A documented, self-identified finding this year is evidence of a functioning process next year. An auditor-identified finding with no prior trail invites a deeper look at the whole category going forward.

6. What should change in your process after this audit?

Move the five checks from a one-time pre-audit scramble into a recurring quarterly review, owned by a named person, with a standing list of the vendor contracts that carry the largest indirect spend. A check performed under year-end deadline pressure has less time to follow up on what it finds than the same check run quarterly, and a quarterly rhythm removes the pre-audit scramble entirely.

The work described in this page does not need to repeat as a fire drill. Once the method exists, running it quarterly against the same vendor list costs less each time, because the contract library and the comparison method are already built.

Ownership matters more than tooling here. A check with no named owner gets skipped when the quarter gets busy, regardless of what system holds the data. Assigning it to a controller or a dedicated AP lead, with a standing calendar reminder, is what actually makes it recur.

For a company that has recently added vendors through acquisition, or that is scaling AP volume faster than its controls team, this is also the point to reconsider whether the check should sit inside the existing team or move to a structure built to run it continuously.

For the wider pattern this sits inside, start with the margin drift guide.

For the wider pattern this sits inside, start with the margin drift guide. See also the six categories drift hides in and margin drift vs. legitimate price increases: how to tell them apart.

7. Frequently Asked Questions (People Also Ask)

What is the difference between margin drift and a duplicate payment?

A duplicate payment is a single transaction error: the same invoice paid twice. Margin drift is a rate or condition problem: the invoice is paid once, correctly matched to a PO, but at a rate or under a condition that no longer reflects the signed contract. Both are recoverable, but they are found with different checks.

Can an internal audit team run these checks instead of waiting for an external one?

Yes. Nothing about the five checks requires an external auditor to be present. An internal audit or controller function can run the same rate card, surcharge, rebate, NTE, and vendor master comparisons on its own schedule, which is what turns this from a pre-audit scramble into a standing control.

How far back should we test invoices when running these checks for the first time?

Start with the current fiscal year and the vendors carrying the largest indirect spend. If time allows, extend to the prior year for the same vendors, since a stale rate card or an unclaimed rebate often predates the period an auditor is actively reviewing.

Who should own the pre-audit contract checks: AP, procurement, or the controller?

Ownership should sit with whoever can read both the contract and the invoice, which is usually the controller or a dedicated AP lead. Procurement typically owns the contract relationship but not the invoice detail, and AP typically owns the invoice but not the contract terms, so the check needs a role that spans both.

What do we do if we find drift but the vendor disputes it?

Document the contract language and the billed rate side by side, and raise it with the vendor as a specific, dated discrepancy rather than a general concern. If the vendor disputes the finding, that dispute itself becomes part of the audit trail: it shows the issue was identified and pursued, which is what an auditor is testing for.

Does finding drift before an audit reduce audit fees?

That depends on the audit firm's scoping approach, which this page has no basis to predict. What a documented pre-audit review reliably does is reduce the number of follow-up questions and additional sampling requests during fieldwork, since open items already have an owner and a status.

Should we tell the auditor about drift we found and already corrected?

Yes. Disclosing a self-identified, corrected item is stronger than staying silent and hoping it does not come up. An auditor who learns about it independently, with no prior documentation, is more likely to expand testing across the whole vendor category.

What counts as a not-to-exceed cap, and why does it need separate testing?

A not-to-exceed, or NTE, cap is a contractual ceiling on total billing for a scope of work. It needs separate testing because individual invoices under the cap can each look reasonable on their own while the running total across several invoices quietly crosses the ceiling, and no single approval catches a cumulative breach.

Is this checklist specific to one ERP system?

No. The checks compare the contract document to the invoice and are independent of which ERP processes the transaction. The one ERP-specific factor is how easily prior rate cards and contract versions can be pulled for comparison, which varies by system configuration rather than by ERP brand.

Executive Summary

The problem an external audit surfaces is rarely the audit's actual objective. It asks for a fluctuation explanation, a vendor confirmation, or a sample of invoice support, and margin drift shows up as the residual nobody assigned an owner to. That residual gets asked about at the worst possible time: in front of a partner, with no prepared answer. The mechanism is structural, not a lapse by any one person. Three-way matching checks the invoice against the purchase order and the receipt. It does not check whether the rate on the invoice matches the rate in the contract, whether a volume tier applies, or whether a rebate the contract promises was ever claimed. Those checks live nowhere in the standard AP control set, so the gap accumulates quietly across a fiscal year and only becomes visible when someone is asked to explain it. What changes it is running the contract-to-invoice checks before the auditor asks, not after. This page names the specific places to look: rate card currency, surcharge expiration, rebate accrual, NTE caps, and vendor master duplication. Each one is a bounded, testable question with a clear owner and a clear artifact to produce, so the answer exists before the question is asked.

1. What should you check before an external audit?

Check five things: whether invoiced rates still match the signed rate card, whether surcharges still meet their contractual trigger condition, whether earned rebates were claimed, whether not-to-exceed caps were tested against actual billing, and whether the vendor master contains duplicate or near-duplicate entries. Each is a bounded question with a yes-or-no answer, and each produces a specific artifact an auditor or a controller can review without follow-up questions. An auditor's fluctuation analysis compares this period's spend to last period's or to budget. A variance in a service vendor category triggers a question: what changed. If nobody has already tested the contract against the invoice, the honest answer is "we don't know yet," and that answer invites more sampling, not less. Running the five checks above before the request lands turns that exchange around. Instead of investigating on demand, the finance team hands over a short memo: which vendors were tested, what was found, what was corrected. An auditor reviewing a documented control response closes the item faster than one opening a new inquiry. The checks do not require new software or a new team. They require pulling the current rate card, the current contract, and prior invoices for the vendors that carry the largest indirect spend, and comparing line by line. It is slow work done manually and fast work done with a defined method. 1. Rate card currency: Confirm the rate on the last several invoices matches the most recently signed rate card, not an earlier version still sitting in the AP system. 2. Surcharge trigger condition: Confirm a fuel or accessorial surcharge still meets the condition that justified it, rather than continuing to bill after the condition lapsed. 3. Rebate claim status: Confirm a volume or spend rebate the contract promises has actually been invoiced back or credited, not left unclaimed. 4. NTE cap testing: Confirm billing on a not-to-exceed contract has not quietly crossed the cap across several invoices that were each approved individually. 5. Vendor master duplication: Confirm the same vendor is not entered twice under a slightly different name, which both invites duplicate payment and confuses spend reporting.

2. Why does three-way matching miss this?

Three-way matching checks that the invoice quantity and price match the purchase order and that the goods or services were received. It does not read the underlying contract, so it cannot test whether the price on the PO itself is the correct contracted rate, whether a volume tier changed the rate mid-year, or whether a rebate clause applies. It confirms internal consistency, not contract compliance. The control was designed to catch a different failure: someone billing for goods never received, or at a price never agreed by whoever created the PO. It answers "does this invoice match what we told the vendor to charge," not "is what we told the vendor to charge still correct." A stale rate card passes three-way matching cleanly, because the PO was built from the same stale rate. The invoice matches the PO. The PO matches the receipt. Every control in the chain reports green, and the gap between the signed contract and the billed rate never touches a system that would flag it. This is a design limitation, not an implementation failure at any one company. The fix is a separate check that reads the contract document itself, usually a PDF outside the ERP, and compares its terms against the billed rate directly. That check has to be added; it does not come free with standard AP controls.

3. Which contract terms are easiest to miss?

Terms that depend on a condition changing over time are the easiest to miss, because the invoice looks identical before and after the condition changes. A volume tier, a rebate threshold, a surcharge expiration date, and an escalation clause tied to an index all require someone to notice a date or a quantity crossed a line. Fixed unit prices rarely drift; conditional terms drift constantly because nothing forces a re-check. A fixed price per unit is easy to audit because it never changes. If the invoice matches the contract on day one, it should match on day 400, and any deviation is visible on sight. Conditional terms are different: they are correct on day one and quietly wrong on day 400, with no visual signal on the invoice itself. A volume tier is a common example. A contract might price a service lower once annual spend crosses a threshold. Nobody automatically recalculates that threshold as spend accrues, so the lower rate can go unapplied well after it should have started. A surcharge tied to a market condition, like a fuel index, behaves the same way in reverse: it starts correctly and should fall or expire when the index moves, but nothing in the AP workflow re-tests it once it is set up. It carries forward at the original rate because it was originally correct.

4. How do you document findings for an auditor?

Document each finding as a three-part record: the contract term as written, the rate or condition actually billed, and the dollar effect of the difference over the period tested. Keep the underlying contract page and the invoice line side by side as support. This format answers an auditor's question before it is asked and gives the controller a paper trail for the correction or credit memo that follows. A finding without its source contract page is an assertion, and an auditor working from assertions will re-derive the number independently, which takes longer for everyone. Attaching the actual contract language, highlighted, removes that step. The dollar effect should be stated for the period actually tested, not annualized without saying so. If several months of invoices were reviewed and the gap was found in a subset of them, state that subset rather than extrapolating silently. An auditor who catches an unstated extrapolation treats every other number on the page with more suspicion, not less. Where a finding is still open, a memo, rather than silence, is important. State that the vendor has been notified and a credit is pending. An open item with a documented plan reads as a control working; an open item nobody mentioned reads as a control that failed.

5. Should you fix the drift before or after the audit?

Fix what you can verify before the audit begins, and disclose what is still in progress rather than waiting to present a finished picture. An auditor who finds an issue the company already identified and is actively correcting treats it as a control operating correctly. An auditor who finds the same issue independently, with no prior documentation, treats it as a control gap and tests more broadly as a result. The instinct to wait until everything is resolved is understandable but works against the company. Audits run on a timeline, and correction work on vendor contracts, credits, and rebate claims can take longer than the audit window allows. A partial correction, documented honestly, is a stronger position than a delayed, complete one. "We identified this gap during our own review, corrected these vendors, and are pursuing credit on the remainder" is a sentence an auditor can work with. It shows the control exists and is being operated, which is closer to what the audit is actually testing than the dollar figure itself. This also protects the following year. A documented, self-identified finding this year is evidence of a functioning process next year. An auditor-identified finding with no prior trail invites a deeper look at the whole category going forward.

6. What should change in your process after this audit?

Move the five checks from a one-time pre-audit scramble into a recurring quarterly review, owned by a named person, with a standing list of the vendor contracts that carry the largest indirect spend. A check performed under year-end deadline pressure has less time to follow up on what it finds than the same check run quarterly, and a quarterly rhythm removes the pre-audit scramble entirely. The work described in this page does not need to repeat as a fire drill. Once the method exists, running it quarterly against the same vendor list costs less each time, because the contract library and the comparison method are already built. Ownership matters more than tooling here. A check with no named owner gets skipped when the quarter gets busy, regardless of what system holds the data. Assigning it to a controller or a dedicated AP lead, with a standing calendar reminder, is what actually makes it recur. For a company that has [recently added vendors through acquisition](/guides/post-acquisition-vendor-contract-consolidation), or that is scaling AP volume faster than its controls team, this is also the point to reconsider whether the check should sit inside the existing team or move to a [structure built to run it continuously](/guides/finance-managed-services-vs-in-house-ap-the-real-cost-model). For the wider pattern this sits inside, start with the [margin drift](/guides/cfo-agenda-mid-market-manufacturing) guide. For the wider pattern this sits inside, start with the [margin drift](/guides/cfo-agenda-mid-market-manufacturing) guide. See also [the six categories drift hides in](/guides/indirect-spend-audit-categories) and [margin drift vs. legitimate price increases: how to tell them apart](/guides/margin-drift-vs-legitimate-price-increases-how-to-tell-them).

Questions & Answers

What is the difference between margin drift and a duplicate payment?

A duplicate payment is a single transaction error: the same invoice paid twice. Margin drift is a rate or condition problem: the invoice is paid once, correctly matched to a PO, but at a rate or under a condition that no longer reflects the signed contract. Both are recoverable, but they are found with different checks.

Can an internal audit team run these checks instead of waiting for an external one?

Yes. Nothing about the five checks requires an external auditor to be present. An internal audit or controller function can run the same rate card, surcharge, rebate, NTE, and vendor master comparisons on its own schedule, which is what turns this from a pre-audit scramble into a standing control.

How far back should we test invoices when running these checks for the first time?

Start with the current fiscal year and the vendors carrying the largest indirect spend. If time allows, extend to the prior year for the same vendors, since a stale rate card or an unclaimed rebate often predates the period an auditor is actively reviewing.

Who should own the pre-audit contract checks: AP, procurement, or the controller?

Ownership should sit with whoever can read both the contract and the invoice, which is usually the controller or a dedicated AP lead. Procurement typically owns the contract relationship but not the invoice detail, and AP typically owns the invoice but not the contract terms, so the check needs a role that spans both.

What do we do if we find drift but the vendor disputes it?

Document the contract language and the billed rate side by side, and raise it with the vendor as a specific, dated discrepancy rather than a general concern. If the vendor disputes the finding, that dispute itself becomes part of the audit trail: it shows the issue was identified and pursued, which is what an auditor is testing for.

Margin Drift Resources