Strong accounts payable controls make the correct invoice easy to process and the unusual invoice difficult to pay by mistake. They protect supplier records, approval authority, accounting data and payment release while leaving a clear record of every important decision.

More control does not mean adding another approval to every invoice. The strongest design puts attention where the risk changes: a new supplier, altered bank details, a likely duplicate, missing purchase evidence, an unusual amount or a manual payment. Routine invoices should follow a short controlled route, while exceptions stop with a reason and an owner.

1. Start with the loss or failure you need to prevent

Begin with realistic AP risks rather than copying a generic checklist. An invoice could be paid twice, posted to the wrong supplier, approved outside authority, paid to changed bank details, recorded in the wrong period or omitted completely. A valid invoice could also be delayed because the control is too difficult to follow.

For each material risk, name the control, its owner, when it operates and the evidence it leaves. Duplicate searching is a control only when the team knows which fields are checked, what happens to a warning and who can release it. “Finance reviews invoices” is too vague to test.

A useful control statement: before a new supplier can receive payment, an authorised employee independently verifies its identity and bank details using trusted contact information, then records the evidence and approval.

Prioritise controls that prevent or detect a meaningful error before payment. Low-risk formatting checks should not consume the same attention as supplier identity, approval authority or payment destination.

2. Separate duties that become dangerous in one pair of hands

No employee should control the complete route from supplier creation to payment. Separate supplier maintenance, invoice preparation, commercial approval, payment release and reconciliation where practical. The person who changes bank details should not be the only person able to approve the next payment to that supplier.

Small teams may not have five different employees. Separate the highest-risk actions first and add compensating review. One employee might capture and code invoices, a budget owner approves the purchase, and a director releases the bank payment. A manager can independently review supplier changes and unusual payments.

  1. Supplier records. Restrict who can create suppliers or change payment details.
  2. Invoice preparation. Allow AP to validate and code without approving its own purchase.
  3. Approval. Route the decision to someone with budget knowledge and sufficient authority.
  4. Payment release. Keep banking authority separate from routine invoice handling.
  5. Reconciliation. Give an independent reviewer visibility of what was recorded and paid.

3. Protect supplier identity and bank details

Supplier-master controls deserve special attention because a correctly approved invoice can still be paid to the wrong account. Limit supplier creation and amendment to authorised roles. Require enough information to distinguish the legal supplier, tax identity, trading address, payment terms and bank destination.

Verify new or changed bank details independently. Use contact information already held by the business or obtained from a trusted source, not the telephone number or email contained in the change request. Record who requested the amendment, who checked it, the method used and who approved it.

Flag the first payment after a bank change and changes made close to a payment run. Review duplicate bank accounts across unrelated suppliers, dormant suppliers becoming active and several amendments made by the same user. These signals do not prove fraud, but they justify a closer look before money leaves.

Email alone is not independent verification. A convincing message may come from a compromised supplier or employee account. Confirm high-risk changes through a separate trusted channel.

4. Make invoice checks specific and repeatable

Preserve the original invoice and receipt time, then validate the supplier, invoice number, dates, currency, arithmetic, tax and required business details. Search for possible duplicates across supplier, invoice number, date, amount, currency and previous payments. A formatting difference should not allow the same liability through twice.

Connect the invoice to evidence of the purchase. Where purchase orders are used, compare the supplier, items, quantities, prices and receipt. Set tolerances deliberately and require an owner for differences. A tolerance is an approved boundary for investigation, not permission to ignore every mismatch below it.

Keep exception reasons visible. An unknown supplier, missing order, changed bank account or possible duplicate should remain blocked until an authorised person records why it is valid. For the complete operational sequence, see How to process an invoice from receipt to payment.

5. Control approval and payment as separate decisions

Approval should confirm a defined fact: the goods or service were received, the price is acceptable, the cost belongs to the budget and the purchase is authorised. The approver needs the invoice, purchase evidence, coding, exceptions and earlier decisions in one place.

Use delegated authority by amount, entity, department or category. Prevent self-approval and make temporary delegation dated and visible. Adding more approvers is not automatically stronger; an unnecessary reviewer can delay payment without improving the decision.

Before payment release, confirm that bills remain approved, due, unblocked and linked to verified supplier details. Review new suppliers, bank changes, manual additions, unusual values and changes made after approval. A separate authorised person should release the payment through the controlled banking process.

For guidance on designing the complete ownership route, read How to build an accounts payable workflow.

6. Treat overrides as controlled exceptions

Real businesses sometimes need urgent payments, non-PO invoices or temporary overrides. Prohibiting every exception can push work into email or spreadsheets where it becomes harder to see. Define who may approve an override, the evidence required, its expiry and the review that follows.

Do not allow one person to create, approve and release an urgent supplier payment. Record the business reason and identify the control being bypassed. If the same exception repeats, fix the purchasing rule or workflow instead of renewing the workaround.

Weak exception

“Urgent, please pay”

No accountable owner, independent check, expiry or evidence explains why the normal control was bypassed.

Controlled exception

Reason, authority and review

The system records what changed, who authorised it, which checks still operated and when the exception will be reviewed.

7. Keep evidence and test whether controls work

Retain the source invoice, validation results, match evidence, coding changes, comments, approval, supplier amendments, payment release and bank outcome as one traceable record. Restrict access by role and entity, remove leavers promptly and review powerful permissions regularly.

Reconcile supplier statements, the AP ledger, the general-ledger control account and the bank. Review duplicate warnings, overridden matches, bank-detail changes, manual payments, approvals outside target time and changes made after approval. These reports show whether controls operate in practice rather than only on paper.

Test a sample from receipt to payment and another sample from bank payment back to the source invoice. The first shows whether authorised invoices completed the route. The second can reveal payments or supplier changes that bypassed it. Record failures, assign corrective action and confirm the fix.

Perform a structured review at least annually and sooner after fraud, a material error, acquisition, system change or change in payment method. A control that no longer matches the process creates false confidence.

Using ArrowBill to apply AP controls consistently

ArrowBill keeps the invoice and its control evidence together from receipt to accounting export. Invoices can be dragged and dropped, scanned from a printer or forwarded to a custom email address. Automatic checks surface possible duplicates and unknown suppliers before unusual items continue.

On Team, role-based access, approval rules and entity permissions help separate preparation from approval. Staff see only the dashboards and entities their authority permits, while head office retains oversight and can allocate invoice volume and user seats across the organisation. Dated delegation keeps approvals moving when an authorised employee is away.

The audit history preserves actions and decisions, and approved bills are sent to Xero or QuickBooks Online while payment release remains in the organisation's banking process. Team starts at £70 with approval and procurement controls; Solo starts at £45 per month for 100 invoices for invoice OCR and accounting export. Compare the plans on ArrowBill's pricing page.

Map your accounting controls

Use the free flowchart builder to document control owners, supplier and nominal-code data, decisions, exceptions and handoffs across accounting and finance. It is a process-design canvas: it does not select or apply a compliance framework, test controls or certify the resulting design. No sign-in is required.

Frequently asked questions

What are the most important accounts payable controls?

The core controls are independent supplier and bank-detail verification, duplicate detection, invoice validation and matching, approval by an authorised budget owner, separation of invoice preparation from payment release, controlled access and regular reconciliation.

How can a small finance team separate AP duties?

Separate the highest-risk actions first. One person may prepare invoices, while another approves payment and a manager reviews supplier or bank-detail changes. Where full separation is impossible, use documented compensating reviews and retain the evidence.

How should supplier bank-detail changes be verified?

Verify the change independently using trusted contact information already held by the business, not the details in the change request. Record who requested, checked and approved the amendment, then highlight payments made soon after the change.

How often should AP controls be reviewed?

Monitor important exceptions throughout each payment cycle and perform a structured review at least annually. Review sooner after fraud, a material error, an acquisition, a system change, a new payment method or a significant change in roles or invoice volume.

Can AP automation replace manual controls?

Automation can apply rules consistently, restrict access, detect likely duplicates, route approval and preserve evidence. It cannot decide an unclear policy or remove the need for judgement, independent verification, payment authority and management review.

Authored by Tayyib Ali

Tayyib writes practical guides for finance teams building clearer invoice, approval and payment processes. His focus is making accounts payable controls easier to understand, operate and test.