What Should an Accounts Payable Controls Checklist Include?
An accounts payable controls checklist covering segregation of duties, approval limits, duplicate detection, supplier verification, exception tracking and audit trails.
Article Summary
- 01
Strong AP controls cover approvals, supplier checks, duplicate invoices, and payment reviews.
- 02
Clear roles and approval limits help reduce errors, fraud, and improper payments.
- 03
Automation can flag exceptions and keep audit trails while high-risk issues still need human review.
A thorough accounts payable controls checklist must address the full range of invoice handling: from who has the authority to create, approve and pay them, to the verification of supplier information and the recording of payment activity. It should also have a way of identifying any transaction that’s unusual or a duplicate.
At their core, these controls are about segregation of duties, setting approval limits, validating invoices and bank details, as well as maintaining proper reconciliations and audit trails.
In Australia, such controls aren’t simply an administrative formality. They’re an important part of the broader framework for safeguarding funds, ensuring financial records are sound and minimising the risk of improper payments. Auditing guidance in this country points to authorisations, approvals and logical access as key control activities.
The National Anti-Scam Centre’s data for 2025 shows reported losses of $166.8 million from payment redirection scams alone. When scammers make fraudulent alterations to what appear to be legitimate supplier details, it becomes even more important for AP teams to remain vigilant.
What Should an Accounts Payable Controls Checklist Include?
It’s best to have defined controls at every point in the AP transaction, from onboarding a supplier to final reconciliation, rather than relying on a single review at the end. The business should be clear on who’s responsible for entering invoices, releasing payments and reconciling accounts. Ideally, those roles are separate.
Segregation of Duties
As a rule, the individual who sets up or amends a supplier shouldn’t be the one to approve and settle that supplier’s invoices. An AP officer might enter an invoice, but a budget owner would approve the spend and another employee with the right authorisation would release the payment. This makes it difficult for any one person to create and conceal an unsuitable transaction.
Australian auditing standards describe segregation of duties as a way to reduce opportunities for one person to commit and conceal fraud or error. While they acknowledge that some smaller firms may lack the headcount for total separation and will need other supervisory measures, the principle remains.
The NSW ICAC has seen how weak segregation can lead to false invoicing; in the case of the former City of Botany Bay Council, for instance, an investigation found AP and financial duties were too concentrated in certain individuals, along with poor vendor controls.
Invoice Validation and Duplicate Detection
An invoice should be checked for authenticity and proper documentation before it’s paid. A strong process will examine the supplier name, date, GST, terms and whether the goods or services were actually received. Three-way matching is a good way to do this by comparing the purchase order and proof of delivery with the invoice. If the three don’t match, the matter is put on hold for further review. The NSW ICAC considers this a useful defence against fraud.
For duplicates, an automated system can be set to flag any combination of supplier, date and amount for a human to review rather than simply deleting them. This is an important part of accounts payable process improvement, particularly where transaction volumes make manual checking inefficient.
Approval Limits
There should be no reliance on informal understandings when it comes to approval authority; documented spending thresholds are necessary. A department manager may be able to sign off on routine invoices under a certain figure, but anything larger requires further approval. The exact limits will depend on the organisation’s size and risk profile.
An automated workflow can route to the correct approver based on the value or cost centre. The ICAC advises having these delegation limits clearly specified.
Verifying Supplier and Bank Details
Any change to a supplier’s bank account is a high-risk event for AP since a valid invoice could be diverted to an unauthorised account. The accounts payable controls checklist should call for independent verification of new suppliers and any bank detail changes.
That means using contact details you have on file, not simply responding to the email that asks for the change. There’s a particular danger Scamwatch has highlighted, criminals can infiltrate a supplier’s email, change the bank information on an invoice, and do so without leaving the thread of an ongoing conversation.
The advice is to stop and get in touch with the supplier directly to verify any payment details. Such independent verification is also what the NSW ICAC advocates when new vendors are being set up, a position backed by Australian corruption-prevention data.
The stakes are clear from ICAC investigations into weak vendor controls and false invoices; in one case, two hospitals were found to have made corrupt payments totalling over $650,000 on bogus invoices.
Exception Tracking
The standard workflow isn’t suitable for every invoice. A sound AP system will identify the exceptions: values that exceed what can be approved, missing purchase orders, GST or coding anomalies, failed matches between invoice and payment or any unusual detail in the supplier’s bank details or the amount due.
These should be placed in an exception queue where there’s a record of the owner, the status and how it was resolved.
It’s a key element of accounts payable process improvement as it changes the review model; rather than manually going through each transaction in the same manner, staff can focus on those that don’t conform to the rules.
Reconciliations and Payment Review
Controls don’t end with an approved invoice. Before a batch of payments is released, it should be reviewed and the relevant accounts reconciled against supplier balances.
As Australian auditing guidance states, this is a control activity to find discrepancies in the records. The point is to make sure the right supplier and amount were processed and to look into any outstanding differences, not just to note that a payment has been made.
Regular reviews may also identify unexpected patterns, like repeated payments or activity outside normal spending.
Audit Trails and Access Controls
An automated system needs to keep a dependable record of what has happened. The software should be able to tell you who entered a supplier, who approved an invoice or when a transaction was altered.
Access rights must be appropriate to the job; the person creating a supplier shouldn’t have unrestricted access to approve and release payments. This is in line with Australian auditing guidance on logical access and monitoring internal controls.
An audit trail is invaluable for an investigation, allowing the business to piece together events instead of depending on an email or someone’s memory.
How Can AP Automation Strengthen These Controls?
There’s more to accounts payable automation than simply speeding up invoice processing, as it also helps support the control framework. The software can be configured to maintain an audit trail of all activity, hold any invoice that hasn’t been approved or identify a duplicate.
It doesn’t replace a well-designed process. If the underlying procedure is weak, has incorrect rules or gives users too many permissions, automation will only make those problems happen faster. The system works best when it combines automated checks with the necessary human oversight, letting most work go through the normal process while having high-risk matters reviewed more closely.
A Practical Accounts Payable Controls Checklist
You have to ask if there’s a proper delineation of duties and that approval responsibilities are in order. We need to know whether the documented thresholds for approval are being adhered to.
On the supplier side, have we made an independent check of their bank information and put in place screening for duplicates?
When it comes to reconciling purchase orders with invoices, do we route any irregularities through an exception workflow? The system should be leaving a secure audit trail while user access is restricted by role.
Before a payment batch is released, is it reviewed, and are the financial records kept securely?
But this goes beyond a simple accounting checklist. What we’re after is the convergence of authorisation, validation, security and the evidence to back it up. The point of refining the process isn’t to layer on superfluous approvals; rather, it’s to ensure controls are applied when they ought to be and to allow for the automation of routine checks.
Keep up with what I'm working on
I'll send you occasional emails about new articles, tools and offers that could help with your business.