Three-Way Match Checklist: PO, Receipt and Invoice Controls
Use this three-way match checklist to compare purchase orders, receipts and invoices, route exceptions, preserve evidence and control payment approvals.
On this page +
- Define the matching policy and scope
- Copy this three-way match checklist
- Validate the purchase order
- Verify receipt or service acceptance
- Validate supplier and invoice details
- Compare at the correct level
- Route exceptions without bypass
- Preserve segregation and payment authority
- Perform quality and fraud checks
- Use assisted capture responsibly
- Monitor exceptions and improve controls
- FAQ
- What is a three-way match?
- What fields should be matched?
- What happens when a three-way match fails?
- Can services use a three-way match?
- Who should approve match exceptions?
- Can AI automate three-way matching?
A three way match checklist connects three different assertions: what the organization authorized, what it received and what the supplier billed. A successful match can support invoice approval only when source documents are valid, fields are compared consistently and exceptions cannot bypass authority.
Matching is not proof that a purchase was necessary, a supplier is legitimate, goods are safe or payment is legally due. Qualified procurement, finance, tax, legal, security, operational and technical owners must apply applicable law, policy, contract terms, manufacturer instructions, site-specific controls and professional judgment. A checklist is not payment authorization or proof of compliance.
Define the matching policy and scope
Identify entities, purchasing channels, invoice types, systems, currencies and categories in scope. Define when three-way, two-way, milestone or other matching is authorized. Blanket orders, utilities, expenses, subcontract work and recurring services may need different evidence.
Document tolerance rules, approval limits, duplicate checks, tax handling and escalation. Tolerances should have an owner, rationale, effective date and review cadence. They must not be invented by invoice processors to clear a queue.
Map responsibilities using the purchase order approval workflow. Request, approval, receipt, invoice processing, exception approval and payment release should follow the organization’s segregation design.
Copy this three-way match checklist
THREE-WAY MATCH REVIEW
Entity / business unit / review date:
Supplier ID and legal name / risk flags:
PO / receipt / invoice references and versions:
Reviewer / exception approver / payment status:
PURCHASE ORDER
Authorized before commitment / approver / date:
Item or service / quantity / unit price / currency:
Terms / tax basis / delivery location / change history:
RECEIPT OR ACCEPTANCE
Quantity and condition received / date / location:
Receiver / evidence / rejected or returned quantity:
Service milestone / acceptance criterion / approver:
INVOICE
Invoice number / date / amount / currency:
Line details / tax / freight / terms / bank-change flag:
Duplicate and supplier-master checks:
MATCH AND EXCEPTION
Field / PO value / receipt value / invoice value:
Variance / tolerance source / reason:
Action / owner / due date / evidence:
Approval authority / decision / date / release reference:
Use stable document IDs and preserve source versions. Restrict bank, pricing and personal data to authorized users and avoid copying more information than the review requires.
Validate the purchase order
Confirm that the PO existed before commitment where policy requires it, names the correct supplier and entity, and was approved within authority. Check item or service description, quantity, price, currency, terms, tax basis, delivery location and budget or project coding.
Review changes and cancellations. A revised PO should preserve who changed what, why and when. Do not backdate or inflate a PO merely to make an invoice match. Material scope or price changes require the authorized procurement route.
The procurement intake form template helps capture need, ownership, risk and required reviews before ordering. Intake does not replace a valid PO or contract.
Verify receipt or service acceptance
For goods, verify receiver, date, location, quantity, condition, partial deliveries, returns and rejected items. Use reliable receipt records rather than a verbal assumption that delivery probably occurred. Apply inspection and manufacturer requirements where relevant.
For services, define acceptance evidence such as an approved milestone, timesheet, deliverable or service-period confirmation. The requester should not confirm vague completion merely to unblock payment. Qualified operational owners decide whether deliverables meet contract and technical criteria.
Separate receipt creation from PO approval and invoice processing where the control design requires it. Investigate receipts entered unusually late, in round quantities or by a person without direct knowledge.
Validate supplier and invoice details
Confirm supplier identity through the approved master record and onboarding process. Check invoice number, legal entity, date, purchase reference, line details, quantity, price, currency, tax, freight, terms and total. Recalculate extensions and totals where required.
Run duplicate checks across invoice number variants, amount, date, supplier and supporting images. A system warning should be investigated, not automatically overridden. The supplier onboarding checklist supports ownership of identity, tax, banking and risk evidence.
Treat bank-detail changes as a separate high-risk process using independently verified contact routes and required approvals. A matching invoice does not validate changed payment instructions.
Compare at the correct level
Match line by line where policy requires it. Header totals can conceal quantity and price offsets. Compare units of measure, currency, tax basis, delivery or service period and contractual additions such as freight or discounts.
Handle partial receipts and invoices without marking the whole order complete. Track cumulative ordered, received, invoiced and returned quantities to prevent overbilling across several documents. Close remaining commitments only through authorized procedures.
For foreign currency, use the contract and accounting policy to determine which values should match and how exchange differences are treated. Finance and tax owners approve the accounting response.
Route exceptions without bypass
Classify failures: quantity, price, missing receipt, duplicate, tax, supplier, coding, unauthorized change, damaged goods or disputed performance. Record source evidence, impact, action owner and due date. Keep the invoice blocked unless an authorized exception route permits release.
The exception approver should have appropriate authority and independence. Document the decision, rationale, limits and evidence. Repeated “one-time” exceptions indicate a process or master-data issue and should trigger root-cause review.
Use the audit findings tracker template for systemic remediation. Do not solve queue pressure by raising tolerances or creating receipts without evidence.
Preserve segregation and payment authority
Design roles so no single person can create a supplier, order, confirm receipt, process the invoice, approve the exception and release payment. Where staffing makes separation difficult, qualified control owners must assess risk and implement evidenced mitigating review.
Emergency and manual payments need explicit criteria, authority, independent verification and retrospective review. Payment release should rely on approved bank and supplier data, not details copied from an email or invoice alone.
Record user, timestamp, decision and document version in the workflow. The audit evidence log template helps maintain provenance where system logs and supporting documents are stored separately.
Perform quality and fraud checks
Review duplicate indicators, split orders, approvals just below limits, weekend changes, new bank details, unusual delivery locations, rapid PO changes and repeated tolerance use. These are prompts for investigation, not proof of wrongdoing.
Reperform matches for a sample covering full, partial, returned, service, foreign-currency and exception-approved transactions. Trace each field to the original controlled document or system record, not a manually retyped summary. Confirm that document versions and timestamps reflect the sequence of authorization, receipt and billing. Test invoices exactly at tolerance boundaries and just outside them. Review canceled POs, reversed receipts and credit notes to ensure later changes do not leave an invoice apparently matched when the underlying authorization or receipt no longer supports it.
Sample matched transactions back to source evidence and confirm the system logic operates as designed. Check completeness of invoice populations and interfaces; testing only successful matches ignores blocked or diverted items.
Record reviewer, population, period, exceptions and conclusion. Route suspected fraud, sanctions, misconduct or legal issues through restricted qualified channels without adding allegations to broadly accessible notes.
Monitor interface failures and unmatched populations as well as successful transactions. Reconcile invoice intake counts to the accounts-payable queue so missing documents cannot escape review. Validate that workflow users and delegates remain current, and inspect emergency overrides for documented reason, authority and retrospective review. Where optical character recognition or extraction is used, track correction rates by field and supplier; an overall accuracy impression can hide repeated errors in tax, quantity or bank-related fields.
Confirm that exception reports include aged blocked invoices, rejected documents and items routed outside the standard workflow. Review whether suppliers receive accurate, authorized status information without exposure of internal control logic or unrelated data. If an operational deadline creates pressure to pay, document the risk and obtain the required exception authority; urgency does not validate missing receipt evidence.
Use assisted capture responsibly
Procurement reviews can expose pricing, bank details, supplier disputes and employee information. Record only with authority, clear notice, consent where applicable, privacy controls, secure handling, restricted access and approved retention.
For an authorized match-exception review, Kuno can assist with capture and draft action notes for human verification. It does not authenticate documents or authorize an invoice or payment. Explore Kuno
Verify AI-extracted fields against originals, especially decimal places, currencies, dates and supplier identity. Do not upload invoices or banking data to an unapproved tool.
Monitor exceptions and improve controls
Track exception volume, age, cause, owner and resolution without treating a lower count as automatic improvement. Missing exceptions can indicate bypass, changed scope or incomplete data. Review tolerance use and manual overrides by supplier, requester and approver.
Discuss recurring issues with process owners through a controlled forum such as the procurement evaluation meeting minutes template, adapting it to internal control review. Assign remediation, evidence and closure reviewers.
Keep authorized exception discussions connected to controlled action. Kuno supports reviewable drafts, while procurement and finance owners validate evidence and retain payment authority. See Kuno
FAQ
What is a three-way match?
It compares an authorized PO, receipt or acceptance evidence, and supplier invoice before payment approval, subject to controlled exceptions.
What fields should be matched?
Match supplier, order, item or service, quantity, price, currency, tax basis, delivery, terms and policy-required attributes.
What happens when a three-way match fails?
Block or route the invoice through the approved exception workflow, assign an owner and require evidence and authorized resolution.
Can services use a three-way match?
Yes, when reliable service-acceptance or milestone evidence is defined, though the control design differs from physical-goods receipt.
Who should approve match exceptions?
An authorized, appropriately independent owner should approve within policy limits without bypassing segregation rules.
Can AI automate three-way matching?
AI can assist extraction, but qualified humans must verify documents, fraud indicators, tolerances, tax, receipt and payment authority.