All notes

Six checks before you pay a supplier invoice, and when to automate

18 min readUpdated September 13, 2026

Fifty supplier invoices arrive in a month. Somebody opens each one, looks at the total, decides it seems about right, and pays it. The supplier has been sending invoices for years and nothing has ever gone wrong.

That glance is the whole control. It catches a $4,000 invoice where you expected $400. It will not catch a second copy of last month's bill, a rate that crept up without anyone mentioning it, or a line for materials that were never delivered.

What follows is the order worth working through when you check supplier invoices before paying them: what each check actually catches, what it costs you in time, and the point where doing it by hand stops being the sensible option.

What actually goes wrong on a supplier invoice?

Six things, and they are not equally expensive. Four of them are ordinary mistakes that any supplier makes eventually, and they are boring to catch. Two of them are somebody trying it on. The checks that find the mistakes are quick; the checks that find the deliberate ones work differently, and they are the ones owners skip, because a well-made fake looks entirely normal.

  • A duplicate: the same invoice paid twice, usually with one detail changed.
  • A price above the one you agreed.
  • A quantity that does not match what turned up.
  • Tax that is wrong, missing, or applied at a rate that does not exist.
  • An invoice for something nobody in your business ordered.
  • An invoice from somebody impersonating a supplier you really use.

Something failing to pass cleanly is normal rather than exceptional. Even in organisations with a payables team and matching software, a noticeable share of invoices trips over something. In a business where invoices arrive by email, by post and by WhatsApp, expect more of them to, not fewer.

How much money is in this?

Nobody can tell you the share of your payments that went out twice or went out wrong, because nobody has looked. The way to size it is your own bank statement: take one month of supplier payments and, for each one, ask whether you could show that it was paid once, at the agreed amount, for something somebody ordered. Most owners who do this find at least one payment they cannot account for, and a business paying $40,000 a month to suppliers does not need many of those in a year to be losing thousands. Money paid twice is rarely recovered in full, and money paid for an inflated invoice is never recovered at all.

Then there is the deliberate kind, which is far rarer per invoice and far larger per event: invoices for goods that were never supplied, invoices inflated above what was agreed, personal purchases put through as business ones. Small businesses are more exposed to it than large ones, for the reason this whole article is about: fewer people between the invoice and the payment, and rarely anyone whose job is to check.

If you would rather have that arithmetic done on your own invoice volume, that is part of what the process audit produces, in writing.

What does a one-minute check actually look like?

Six questions, asked in this order, because each one is cheaper to answer than the one after it and rules out more invoices. Most invoices die on the first two. The whole sequence takes about a minute once the papers are in front of you, and the slow part is never the thinking, it is finding the order the invoice refers to.

  1. Have you seen this invoice before? Supplier, invoice number, amount, date. Anything familiar goes in a pile for a second look.
  2. Did you order this? A purchase you cannot account for is the one check that catches both fraud and the supplier's filing error.
  3. Did it arrive? Quantity on the invoice against what was actually delivered or done.
  4. Is the price the one you agreed? Unit price and any discount, against whatever record you have of the arrangement.
  5. Does the arithmetic work? Line totals, tax, and the sum. Wrong tax is the most common quiet error, and the one that comes back at you at year end.
  6. Is this the supplier's real bank account? Compare against the details you paid last time, and not against the ones printed on this invoice.

Nobody runs six checks on a $30 invoice for coffee, and nobody should. Full matching is expensive for low-value purchases, where the labour of matching can cost more than the bill being paid. Exclude small-value and recurring invoices from the matching requirement altogether.

So set a threshold and write it down. Below it, questions 1 and 5 only. Above it, all six. As for how much difference should be allowed before you query something, a professional finance team usually treats a few per cent per line as normal drift before an invoice is held. A small business version reads: accept up to 5% or $50, whichever is smaller, and ask about anything above that.

Why are duplicates the hardest to catch?

Because the second copy rarely looks like the first. Most software tests for a duplicate on the exact match of four things: invoice number, invoice date, invoice amount and supplier. Any one of those four drifting is enough to let a duplicate through, and all four drift routinely.

The kinds of drift are worth memorising, because your bookkeeper will produce the same ones: INV1400-0612 typed once as INV14000612, 5724625A shortened to 5724625, a hyphen dropped, a suffix added, a date typed as the day it was entered rather than the day on the document. The other classic is the supplier set up twice under two slightly different names, and a second copy filed under the second record is not a duplicate as far as any software is concerned.

The biggest single cause is not typing at all. It is the same invoice arriving twice by two routes: the person who received the goods forwards their copy, and the supplier also sends one directly.

Three habits close most of this, and none of them costs anything.

One channel for invoices. Decide on one way, post or a single email address, that you receive invoices, and tell every supplier it is the only one. An invoice that arrives by WhatsApp gets forwarded to the one address before anybody looks at it.

One payment method per supplier. A supplier paid by card may also send an invoice, and the invoice gets paid too.

Reconcile the monthly statement. If your records show more invoices than the supplier's statement does, you have found either a duplicate or an overpayment. It takes an hour a month, needs nothing you do not already have, and most guides on this subject skip it.

What do you match against if you never raise a purchase order?

Most advice on invoice checking assumes a three-way match: purchase order, delivery record, invoice, all three agreeing on quantity and price. That is the standard, and where purchase orders exist it should not be dropped to save time.

It also assumes purchase orders exist. In a business of five people, orders happen by phone, by email and by standing arrangement, and there is no document to match against.

The fix is smaller than a procurement system. What you need is a written trace of the agreement, in one place, for anything above your threshold:

  • The email where the supplier quoted the price counts as a purchase order. Put it in a folder named for the supplier.
  • A rate card or price list, dated, for suppliers you buy from repeatedly. When the invoice disagrees with the card, one of them is out of date, and finding out which takes one message.
  • A note of what turned up, written by whoever took delivery. Two lines on the delivery note is enough.

That gives you a two-way match, which is the same comparison with the delivery record left out: invoice against agreed price, on the things that matter, and nothing on the things that do not. The EU VAT Directive, which cares a great deal about audit trails, allows exactly this reasoning. Authenticity and integrity can be assured "by any business controls which create a reliable audit trail between an invoice and a supply of goods or services". A folder of emails is a business control.

Does the tax line matter if the total is right?

It does, because the tax line is what makes the invoice usable, and an invoice you cannot use is a price increase you agreed to without noticing. In most of the world a business reclaims the sales tax it was charged by its suppliers, and it can only do that if the paperwork holds up. Where the invoice is wrong, the tax stays with you, and the discount you negotiated last spring quietly disappears.

In the EU, the right to reclaim is tied to holding a proper invoice: Article 178 of the VAT Directive makes deduction conditional on an invoice drawn up according to Article 226, which lists what has to be on it. The Australian Taxation Office states the same idea in one sentence: "An invoice containing incorrect or incomplete information is not a valid tax invoice." HMRC's VAT guide sets out what a UK VAT invoice must show, and expects you to go back to the supplier for a corrected one before anything else.

What changes by country is mostly the threshold below which nobody minds.

Where Full invoice needed above Notes
EU EUR 100 At EUR 100 or less, a simplified invoice with a shorter list of details is allowed (Articles 220a and 226b)
UK GBP 250 A simplified VAT invoice is allowed at GBP 250 or less (VAT Notice 700, section 16.6.1)
Australia AUD 82.50 incl. GST A tax invoice is needed to claim a GST credit above this; AUD 1,000 and above must also identify the buyer
US No VAT equivalent IRS Publication 583 asks for documents showing the amount and that it was a business expense

The practical check is short. Is there a tax number on the invoice, is the rate one that exists, and does the tax figure match that rate applied to the net? HMRC also warns that a document marked "pro forma" cannot be used to reclaim input tax, which catches more small businesses than it should.

One more, for readers in the United States: where a supplier does not charge sales tax on something taxable, the tax can land on the buyer instead. Pennsylvania's Department of Revenue says so directly for its own state, and the rules differ from state to state. None of this is tax advice, and your accountant will have local detail this does not cover. It is a reason to look at the tax line before paying rather than in March.

How do you know the invoice is from a real supplier?

You check that the purchase exists in your own records, which is the only test a convincing fake cannot pass. Appearance tells you nothing now. Logos are copied, layouts are cloned, and the spelling mistakes everyone was taught to watch for have been edited out.

The US Federal Trade Commission has been telling small businesses the same thing for years, in blunter words: "before you pay any invoice, check it out to be sure you actually placed that order." The reason the scam works at all is a split: the person who processes the invoices is often not the person who received the shipment, and does not know the goods were never ordered.

That split between the person who receives and the person who pays is the whole attack. Directory listings, domain renewals, advertising nobody booked and office supplies nobody unpacked all arrive as an invoice that looks like the tail end of a decision somebody else made.

Two rules cover it:

  • Anything you cannot trace to an order in your own records gets queried before it gets paid, however ordinary it looks.
  • Contact details come from your own file and never from the document in front of you. The FTC and Australia's Scamwatch both give this advice.

The version aimed at money you genuinely owe is the redirected payment: a real invoice from a real supplier, with the bank details swapped. That one has its own controls, which the note on supplier bank detail changes sets out.

Who approves payment when there is only one of you?

Every guide says the same thing: the person who orders should not be the person who approves, who should not be the person who pays. In a business of one to five people that advice is unusable, and most guides stop there anyway.

The useful principle does not stop there. Where separating duties is not practical because there are not enough people, the obligation is to substitute something else for the separation, not to shrug. For a one-person accounting function the substitute is at least one other pair of eyes, and an outside accountant counts. Where the same person enters invoices and releases payments, the substitute is an independent review of bank activity, tracing what left the account back to the documents behind it.

For an owner-run business that comes down to three things:

  1. Your bookkeeper or accountant reviews the payment list monthly against the invoices, after the fact. Late detection beats none.
  2. Payments above a value you choose need your eyes before release, even when you are also the person who ordered.
  3. Any change to a supplier's bank details is verified by voice, on a number you already held.

When does checking by hand stop paying for itself?

Later than the software vendors suggest, and earlier than most owners assume. The honest answer is that the arithmetic is yours to do, because the published benchmarks describe organisations nothing like yours: dedicated payables teams, tens of thousands of invoices, and a cost per invoice that includes overheads you do not carry. What transfers is the method, not the number.

So run your own numbers: invoices per month, minutes each including the chasing, your hourly cost. Then set that against what a tool would cost and what it would leave you doing anyway.

Three rough bands, based on where the effort actually lands:

Invoices a month What usually makes sense
Under 20 Checks by hand, a written threshold, monthly statement reconciliation
20 to 80 Capture and entry handed to a tool; checking and approval stay yours
Over 80 Worth designing the whole flow, including where exceptions go and who clears them

The middle band is where owners get this wrong. A tool takes the typing off you and leaves the deciding, so a payback sum that counts both as saved time is measuring the wrong task. The same split runs through what automation costs a small business, where the build cost and the running cost separate along the same line.

What your accounting software already does for free

You are probably paying for part of this already. Capture, the step that turns a PDF into a line in your ledger, is now bundled with most accounting subscriptions rather than sold separately. Xero includes document capture on every paid plan, under the Smart Document Capture name and previously as Hubdoc, and QuickBooks Online includes receipt capture on its paid plans. The step the vendors advertise hardest may be the one you already own.

Duplicate warnings are where the products genuinely differ, and the differences are not advertised. Taken from the vendors' own help documentation on 11 August 2026: Zoho Books refuses a second bill with the same number for the same supplier within a financial year, and Sage 50 warns when reference, date, net amount and account all match, with the warning switchable off. Xero does not block at entry, showing links to bills with a matching reference and contact, and separately flagging likely duplicates on the purchases screen in an alert you can dismiss. FreeAgent and Wave document nothing of the kind, and QuickBooks Online has no published answer either way, which is its own reason to test it.

So test yours rather than reading its help page. Enter last month's invoice number a second time against the same supplier and watch what happens. Whatever it does is what stands between you and the 0.8% to 2%.

The trap is on the other side of the same subscription. Xero's entry plans cap the number of bills you can enter: five a month on the US Early plan, ten on the UK Ignite plan, as listed on Xero's own pricing pages on 11 August 2026. A business handling 20 to 80 supplier invoices cannot live there, and the real floor is the middle plan at $55 or GBP 37 a month. Xero has announced price changes for September and October 2026, so read the current page rather than this one.

Standalone capture, if you need it, is priced per document and costs less than people expect: AutoEntry at roughly GBP 0.19 to GBP 0.28 per document, which it bills as credits, and Sage at GBP 0.20 per capture above its allowance, both taken from their pricing pages on 11 August 2026. Dext works the other way round, bundling 250 documents into a plan at $25.21 a month on annual billing, with per-document add-ons from $0.32. At 80 invoices a month that is a bill in the tens, which is the figure your payback sum should be run against. Getting the data out of the document reliably is a separate problem with its own answer, covered in getting invoice data out of PDFs.

What is worth automating first

Take these in order and stop at whichever one stops paying for itself. The sequence matters more than the tools: each step here makes the next one possible, and skipping to the interesting part is how businesses end up with extraction software pointed at four different inboxes. Nothing below needs a platform, and the first item needs nothing but a decision.

  1. One inbox for invoices. Everything else depends on it, and a system that never sees an invoice cannot check it.
  2. Capture and entry, using whatever your accounting package already includes before you buy a second product.
  3. A duplicate flag on supplier, amount and date together, rather than on the invoice number alone. This is usually the one that pays for itself first.
  4. A threshold rule that routes anything above a value to you and lets the rest through.
  5. A monthly statement reconciliation, which stays a human job for longer than the rest of it.

We would rather tell you that steps four and five are not worth building than sell you a system that automates a check you were never going to trust. If you want the order worked out against your actual invoice volume before you spend anything, that is what the process audit is for: $299, three business days, and a written map of what each step would save and what it would cost to build.

What to do this week

None of these needs a budget, and between them they close most of what a supplier invoice can do to you. The first four take an afternoon in total. The last one is the only item on the list that looks backwards, which is why it is the one worth starting with.

  • Pick one channel for invoices and tell your suppliers. One inbox, one address.
  • Write your threshold down. Above it, all six checks; below it, duplicates and arithmetic only.
  • Test your accounting package for a duplicate warning, with a real invoice number.
  • Check that the bank details on file for each regular supplier match what you actually paid last time.
  • Ask your two largest suppliers for a statement and reconcile it against what you have paid.

That last one is where duplicates going back months usually turn up. It costs an hour, and it is the only check on this page that can bring back money you have already sent.

Sources