Accounts Payable Recovery Audit: Process, Contingency Fees, Lookback

An accounts payable recovery audit is a forensic review of a company’s historical payment records that identifies and reclaims money lost to duplicate payments, missed credits, pricing errors, and billing mistakes. The auditor pulls two to three years of transactional data, runs it through specialized analysis, validates the errors with source documents, and then works with vendors to return the funds. Most engagements run on a contingency fee, so the client pays only out of what is actually recovered.

What the Audit Looks For

The audit is not a review of your AP team’s current work. It is a look backward at money already spent, searching for payments that should not have gone out or credits that were never taken. A handful of error types account for most of what turns up.

Duplicate Payments

The same invoice paid twice is the most common finding. It happens when two departments both process the invoice, when a system fails to flag a previously paid invoice number, or when a small formatting variation lets the duplicate slip past exact-match controls. Auditors detect these by comparing vendor name, invoice number, amount, and date across the full disbursement file, including near-matches within short time windows.

Pricing and Discount Errors

Contract rates and volume discounts negotiated by purchasing do not always land cleanly in the AP system. A vendor bills at list price instead of the contract rate, or a tiered discount kicks in at a threshold no one tracks. On high-volume, repetitive purchases the gap compounds quickly.

Missed Credits and Rebates

Returned goods, canceled services, and volume rebates all generate credit memos. If those credits are never applied against future invoices, the company effectively pays twice. Open credits age off the radar in a busy AP shop because tracking them requires active follow-up that rarely gets prioritized.

Sales and Use Tax Overpayments

Companies sometimes pay sales tax on items that are exempt, such as manufacturing equipment or certain professional services. The cause is usually an incorrect tax code applied at the point of purchase or blanket tax treatment that ignores jurisdictional exemptions.

Freight, Utility, and Logistics Billing Errors

Complex service contracts with tiered rates, fuel surcharges, and accessorial charges produce small per-invoice mistakes that add up. Catching them requires comparing each line item against the underlying contract, which almost never happens during routine processing.

How the Audit Actually Runs

Data Extraction and Cleansing

The auditor pulls historical financial records: the general ledger detail, the AP disbursement file, the vendor master file, and, where relevant, purchase orders and receiving documentation. Before analysis, the data is normalized. Vendor names are a frequent problem. “Acme Corp,” “Acme Corporation,” and “ACME CORP.” need to be recognized as the same supplier so every payment lands in one bucket.

Algorithmic Analysis

Proprietary software runs hundreds of tests against the transaction history at once. Fuzzy-logic matching flags potential duplicates that a simple exact-match filter would miss, such as an invoice number that differs by a single transposed digit while every other field matches. Another set of tests compares payment amounts against digitized contract terms and flags anything outside tolerance.

Human Validation and Client Approval

Software identifies anomalies; a human auditor confirms them. Every flagged item is checked against the original invoice, purchase order, and receiving report before it becomes a claim, because not every anomaly is an error. Confirmed errors are packaged into formal claims organized by vendor, and no claim goes out until the client reviews and signs off.

Vendor Outreach and Repayment

Once the client approves, the auditor contacts the vendor’s accounts receivable department with a claim package documenting each overpayment. Recovery generally takes one of three forms:

  • A credit memo applied against future invoices, which is the most common outcome because it lets the vendor keep its cash flow while correcting the error.
  • A direct refund by check or wire, usually when the client no longer does business with the vendor or the amount is large.
  • A balance offset against an outstanding invoice the client already owes.

Because the auditor works from extracted historical files, day-to-day AP operations are largely unaffected during the engagement.

The Contingency Fee Model

Most external recovery auditors work on contingency, earning a negotiated percentage of funds actually recovered. The percentage varies with engagement scope, transaction volume, and the complexity of the payment environment. If nothing is found, nothing is owed, which makes the service effectively self-funding.

The trade-off is that the fee comes out of money the company already lost, so net benefit is always smaller than gross recovery. When comparing proposals, weigh the fee percentage against the projected recovery range and ask for references from companies of similar size and complexity.

How Far Back the Audit Can Reach

The legal ceiling is set by the statute of limitations for contract claims. Under the Uniform Commercial Code, an action for breach of a sales contract must be commenced within four years after the cause of action accrues, with accrual occurring when the breach happens whether or not the aggrieved party knew about it.1Legal Information Institute. UCC 2-725 Statute of Limitations in Contracts for Sale Parties can shorten that window by agreement to as little as one year, but they cannot extend it beyond four.

In practice, most audits use a two- to three-year look-back. Reaching further increases the odds that supporting documentation has been purged, vendor contacts have moved on, or the vendor will resist the claim based on the passage of time. If the company has never done a recovery audit, the first engagement typically covers the maximum practical period; subsequent audits, run annually or every two years, cover only the period since the last review.

Booking the Recovered Funds

Under GAAP, gain contingencies are not recognized until the gain is realized or realizable, meaning cash or a confirmed claim to cash has been received without expectation of repayment. In practical terms, you do not book the recovery when the claim is submitted to the vendor. You book it when the vendor confirms the credit or sends the refund.

The entry itself depends on timing. A recovery tied to the current fiscal year is generally booked as a reduction to the original expense account, correcting the prior charge. A recovery tied to a closed prior period may need to be handled as a prior-period adjustment, depending on materiality and the company’s accounting policies. The auditor’s contingency fee is calculated against the net amount actually returned.

Tax Treatment of Recovered Overpayments

A vendor refund or credit for an overpayment is not new income. It is the return of money you already spent, and in most cases already deducted. For that reason, recovered overpayments do not trigger a 1099-MISC or 1099-NEC reporting obligation, since those forms cover payments made in the course of business rather than reversals of prior payments.2Internal Revenue Service. Instructions for Forms 1099-MISC and 1099-NEC

The taxability of the recovery itself turns on the tax benefit rule. If the original overpayment was fully deducted as a business expense in a prior year, the recovery may need to be included in gross income for the year received. If the original deduction produced no tax benefit, because the company had a net operating loss that year for example, the recovery is not taxable. The accounting entry and the tax treatment are not always the same, and the year of recovery matters.

Dormant Credits and Escheatment Risk

Recovery audits also touch a legal obligation most AP departments overlook. Every state requires businesses to report and remit certain unclaimed property, including aged AP credit balances, after a dormancy period. For most AP-related credits the dormancy period is around three years, though it varies by state. Reporting priority generally follows the owner’s last known address; if no address is available, the obligation defaults to the company’s state of incorporation.

If a vendor issued a credit that was never applied and it sits on your books past dormancy, your company may have to escheat those funds to the state rather than write them off. Identifying dormant credits before the deadline lets the company apply them against active vendor accounts or request a refund, and it heads off compliance exposure. States actively audit for unclaimed property, and penalties can be substantial.

What Public Companies Should Know

Section 404 of the Sarbanes-Oxley Act requires management to assess and report on the effectiveness of internal controls over financial reporting.3Securities and Exchange Commission. Study of the Sarbanes-Oxley Act of 2002 Section 404 Internal Control Over Financial Reporting A recovery audit that surfaces a pattern of systemic overpayments, such as a pricing matrix that has been wrong for two years, could indicate a material weakness that triggers disclosure obligations.

The recovered cash is good news. The findings can be less comfortable, and may prompt conversations with external auditors and the audit committee. Public companies should treat recovery audit results as diagnostic information about the control environment, and start remediation planning as soon as a gap is identified rather than waiting for the annual financial statement audit to flag it.

Data Security Before You Engage an Auditor

Handing years of financial data to an outside firm raises legitimate concerns. The disbursement file alone contains vendor bank details, payment amounts, and internal account structures. Before signing an engagement, confirm how the auditor handles data in transit and at rest.

The industry standard for third-party data handling is a SOC 2 Type 2 report, which covers both the design and operating effectiveness of security controls over a sustained period. The framework evaluates five trust services criteria set by the American Institute of Certified Public Accountants: security, availability, processing integrity, confidentiality, and privacy. Ask for a current SOC 2 Type 2 report and review the auditor’s data retention and destruction policies. If your company operates under HIPAA or handles payment card data, confirm the auditor’s environment meets those additional requirements.

When to Schedule One

Industry practice favors annual audits for companies with significant vendor payment volume. Errors compound over time, and recovery gets harder as documentation ages and vendors push back. High invoice volumes across multiple locations or ERP systems raise the error rate further.

Certain events should prompt an audit even outside the regular cycle:

  • An ERP or AP platform migration, which almost always produces data translation errors that create duplicate payments or missed credits.
  • A merger or acquisition, where combining vendor master files multiplies the risk of duplicate vendor records and redundant payments.
  • Turnover in experienced AP staff, since institutional knowledge about vendor contracts and pricing walks out with them.
  • Rapid growth in transaction volume, which can overwhelm existing controls before anyone notices the error rate climbing.

A company that has never run a recovery audit and processes more than a few thousand vendor payments a year almost certainly has material recoveries sitting in its historical data. Because the fee is contingent on results, the cost of finding out is limited to the time it takes to hand over the file.