{
  "question_id": "CG-P1B-009",
  "slug": "how-a-small-business-can-manage-and-automate-its-accounts-payable-workflow",
  "display_title": "How should a small business manage and automate its accounts-payable vendor-invoice and document workflow?",
  "format": "article-v2",
  "applies_to": {
    "countries": [
      "US"
    ],
    "frameworks": [],
    "tax_year": null,
    "platforms": []
  },
  "general_concept": true,
  "summary": "Map how invoices reach you today, then route every invoice through one logged channel. Specify each stage from intake to a document attached to the bill, with an owner, a check and a record at each. Settle coding rules once, record every approval, and keep payment release apart from invoice processing. Automate stable, rule-based stages first, keep the duplicate, document and payment-detail checks, and measure backlog, exceptions and duplicates caught rather than bills paid.",
  "body": "## How do invoices reach your business today?\n\nStart with the workflow as it actually runs. For the last month or two of vendor invoices, note the channel each came through (email, paper, a vendor portal or an employee), who received it, where the document sits now, and when it arrived, was entered and was approved.\n\nThen mark where invoices stall or disappear: a personal inbox only one person reads, a portal nobody opens until a reminder arrives, a paper tray, invoices held until month-end. A vendor statement listing an invoice you never recorded, a reminder for a bill you have not seen, or a late fee is evidence of a leak; trace each one to its channel.\n\n## How do you consolidate intake into one channel?\n\nWhen invoices arrive through several channels and people, consolidation is the first design decision: later checks can catch a wrong invoice, but not one that never entered the process. Set up the channel in three parts:\n\n- **One role mailbox.** Create one invoice address that belongs to the function, not a person, and give at least two people access.\n- **One paper route.** Paper invoices go to one tray and are scanned into the mailbox the day they arrive.\n- **Portals on a schedule.** One named person moves new invoices from each vendor portal into the mailbox on a fixed day, unless the vendor agrees to email them.\n\nWrite to each active vendor asking them to send invoices only to the new address, one invoice per PDF, quoting their invoice number, your purchase order number where you issued one, and who ordered. Verify any reply asking to change where payments go, as described below.\n\nInvoices will still arrive elsewhere. Make one rule: whoever receives an invoice outside the channel forwards it to the mailbox the same day and does nothing else with it, so nobody approves, pays or files an invoice from a personal inbox.\n\nThe change narrows these failure modes:\n\n| Failure | Fragmented intake | Consolidated intake |\n|---|---|---|\n| Invoice never recorded | Sits in a personal inbox or portal until a reminder or late fee | Every invoice received or forwarded under the rule lands in one logged queue; late notices expose any leak |\n| Invoice paid twice | Arrives by email and by post and is entered twice | The log shows the second copy on arrival |\n\n## What stages does the target workflow need?\n\nThis specification is for an invented business with about 150 invoices a month, an office manager, the owner and an outside bookkeeper:\n\n| Stage | Owner | Check | Record |\n|---|---|---|---|\n| 1. Intake | Office manager | An invoice for this business, not a statement or a copy already logged | Intake log line with the date received |\n| 2. Capture | Office manager | Vendor, invoice number, date, amount and due date read correctly; that vendor and number not already logged | Log line completed; PDF saved under vendor and invoice number |\n| 3. Match, purchase-order spend only | Office manager | Invoice agrees to the purchase order and the receiving record | Match noted, or exception logged |\n| 4. Coding | Bookkeeper | Vendor default applied; any override has a reason | Account and job or class on the approval packet |\n| 5. Approval | Owner, or office manager within limits | Goods or services received and price as agreed, judged from the packet | Approver's name and date on the packet |\n| 6. Entry | Bookkeeper | Entered once, document attached, vendor's invoice number as reference | Approved bill in payables |\n| 7. Handoff to release | Owner | Only approved bills; payee bank details match the verified-details register below | Payment batch listing the bills it pays |\n| 8. Filing | Bookkeeper | Document opens from the paid bill | Paid bill with document and payment reference |\n| Vendor setup and changes | Owner | New vendor's details confirmed from a source other than its invoice; changes verified by calling the number already in the register, never one in the request | Register line: details, number called, date, verifier |\n\nTest every handoff: the next owner should see the invoice in a queue without being told. Handoffs that rely on a forwarded email or a mention lose invoices.\n\nBills enter payables once approved. AccountingTools' article on accounts payable controls says recording invoices after approval forces staff to verify the approval of every invoice before entering it. At month-end the bookkeeper gets the intake log's list of invoices received but not yet entered. Until approved, those invoices are outside payables, so the month's payables and expenses omit them; their month-end treatment belongs to the question on entering bills and paying from the bill.\n\nWith an outside bookkeeper who does not receive documents first, the handoff between the organizations becomes the failure point. Record which side owns each stage, give the bookkeeper read access to the intake log and saved documents, and agree one channel for coding questions. Approval, vendor changes and payment release stay with the business.\n\n## How do you make coding repeatable?\n\nCoding decided invoice by invoice consumes time and produces inconsistent categories. Decide these once and write them down:\n\n- **Vendor defaults.** Each vendor record carries its usual expense account.\n- **Job, class or location.** A written rule says which vendors' invoices always carry one, and who supplies it when it is missing.\n- **Split invoices.** One rule covers an invoice that spans two accounts or jobs.\n- **Overrides.** One named person may change a default, and the reason goes on the bill.\n- **Invoice numbers.** One format governs how the vendor's invoice number is keyed, including leading zeros and dashes.\n\nAccountingTools' guide to setting up an accounts payable system lists default general ledger expense accounts among the supplier details entered in the vendor master file. AccountingTools' article on accounts payable controls explains the numbering rule: an invoice recorded as 0000078234 one time and 78234 the next will not be flagged as a duplicate. When a vendor's bills keep needing overrides, change the default.\n\n## Who approves, and how is approval recorded?\n\nWrite the approval matrix before configuring any software. COSO's executive summary of its Internal Control — Integrated Framework places the assignment of authority and responsibility in the control environment and lists authorizations and approvals among control activities. In the example, the office manager approves invoices up to $1,000 from established vendors for recurring services, and the owner approves everything else, including each new vendor's first invoice and anything the office manager ordered. Write your limits down, and let no employee approve their own purchase.\n\nAccountingTools' article on accounts payable controls calls approval a relatively weak control if the approver only sees the supplier invoice, since there is no way to tell whether the goods or services were received or the price is what was agreed. The controls article recommends a packet of the invoice, the authorizing purchase order and the receiving documentation, with the invoice stamped with a signature block that includes the account number to be charged. Without a purchase order, the packet is the invoice, its coding and a note from whoever ordered confirming receipt and price.\n\nEvery approval record, whether a signed stamp, a saved email reply or a software approval, shows who approved and when. On QuickBooks Bill Pay Elite or QuickBooks Online Advanced, which Intuit says are needed to use workflows, Intuit's help page on bill approval and payment release workflows describes approval workflows triggered by conditions for the amount, vendor or location, and says a bill not reviewed after 30 days is automatically denied. Auto-denial means nobody reviewed the bill, not that nothing is owed: work the queue inside 30 days and send auto-denied bills to the exception queue.\n\nA queue nobody works must hold invoices, never pass them by default: an approval no person gave looks like evidence and is worse than none. AccountingTools' guide to setting up an accounts payable system offers negative approvals, where managers only notify the payables staff if they do not approve a payment. It leaves no record that anyone looked, so use it only if the approver signs and dates the list of invoices it covers; an unsigned list is not an approval.\n\n## Why keep payment release apart from invoice processing?\n\nApproval establishes that money is owed; release is when it leaves. COSO's executive summary says segregation of duties is typically built into the selection and development of control activities. In this workflow that means four rules:\n\n- The person who releases payment did not enter or code the bill.\n- The release step takes only approved bills, listed in a batch that names each one.\n- Nobody who enters bills or prepares payments can add vendors or change a vendor's contact or payment details.\n- The verified-details register and vendor-change rights sit with the person who releases payment, or with someone who neither approves, codes nor enters bills.\n\nCheck this in your software's permissions. Intuit's help page on bill approval and payment release workflows gives its bill clerk role the right to add bills and to add and edit vendors, and its bill payer role the right to pay bills and edit vendor details. Intuit's workflows page also says QuickBooks Online Advanced users can customize roles. The same page says Bill Pay Elite's role permissions are set, so without QuickBooks Online Advanced the bill clerk and bill payer can both change vendor details and the third rule cannot be enforced through those roles; the release-time comparison of payee bank details with the register is the check that catches an unverified change. How payments are then scheduled, sent or automated is a separate question.\n\n## Which checks must survive automation?\n\nManual processing performs checks nobody names, and automation removes them quietly. Name them before automating anything:\n\n| Check | What it prevents | How automation tends to remove it |\n|---|---|---|\n| Duplicate detection | Paying one invoice twice | The number is read or keyed differently, or the vendor exists twice |\n| Agreement to the document | Paying an amount, vendor or due date the invoice does not show | Extracted fields post without anyone comparing them with the PDF |\n| Agreement to purchase order and receipt | Paying for goods not ordered or not received | Invoices route to approval without the match |\n| Verification of changed vendor details | Paying an impostor | Details are updated straight from an email, a form or the invoice itself |\n| A real approval | Paying for something nobody authorized | The queue approves by default |\n\nAccountingTools' article on accounts payable controls says a computerized payables system conducts an automatic search for duplicate invoice numbers, and warns that in a manual system invoice volume can make the search so difficult that staff abandon it. Keep the manual check at capture against the intake log, and move it into software as volume grows.\n\nWhere purchase orders cover only part of the spend, route two populations: invoices quoting a purchase order are matched before approval, others go straight to coding and approval, and an invoice that should have had a purchase order goes to the exception queue. The matching itself belongs to the question on two- and three-way matching.\n\nTreat any request to change a vendor's payment details, email address, phone number or remittance address as a control point, not an update: a false request that first changes the contact details on file turns a later callback into a call to the fraudster. The FBI's Internet Crime Complaint Center advises using secondary channels and/or two-factor authentication to verify requests for changes in account information. The FTC's cybersecurity guidance for small businesses says to use a number you know to be correct, not the number in the email or text.\n\nSo keep a verified-details register: each vendor's payment details, the phone number used to verify them, the date and who verified, editable only by whoever holds vendor-change rights. Verify every change through the register, never through contact details in the request or changed since the last verification. Pay only registered details, never bank details printed on an invoice, and pay nothing to changed details until the change is verified and registered. Confirm a new vendor's first details the same way, from a source other than its invoice. The step-by-step verification belongs to the question on verifying a vendor's new bank account.\n\n## How do you store the document so it can be found later?\n\nStore the document against the bill it supports, not in a folder the bill does not point to: attach it at entry if your software allows, and enter the vendor's invoice number as the bill's reference number. Intuit's help page on searching for transactions in QuickBooks Online says a search can combine transaction type, reference number, contact, date or amount, and that transactions more than 2 years old are found through Advanced transactions search with the date filter adjusted. Without attachments, file documents by vendor and year, name each file with vendor, invoice number and date, and put the file name in the bill's memo.\n\nAfter payment the bill carries the payment reference and keeps its document, so the chain runs from bank line to bill to document. Test it monthly by opening the documents from three paid bills and finding the bills for three documents by invoice number. Fix any failure now, not when an accountant or lender asks.\n\n## Where should the workflow live?\n\nThree homes work, depending mostly on volume and headcount:\n\n| If | Then |\n|---|---|\n| Volume is low and one or two people handle invoices | Run a manual routine: shared mailbox, folder structure, spreadsheet intake log, and bills entered in the accounting software |\n| Your accounting software's payables features cover capture, attachment, approval and permissions on your plan | Run the workflow inside it, with the shared mailbox as the front door |\n| Volume, approvers or locations outgrow those features | Use a dedicated payables application that feeds the accounting software, and decide which system holds the approval record |\n\nA plan change can remove a control. Intuit's help page on bill approval and payment release workflows says Bill Pay Elite customers can add a bill approval workflow, and warns that after a downgrade from QuickBooks Bill Pay Elite, where the business is not subscribed to QuickBooks Online Advanced, the business loses its roles and permissions settings and bill approval workflows, bills that need to be approved can be paid without approval, and all bill payments pending approval are automatically rejected. Before changing plan, remove users from the bill clerk, bill payer and bill approver roles as Intuit recommends, set up a manual approval record and release check, and list payments pending approval so none goes unpaid. Choosing a product is a separate question.\n\n## Which stage should you automate first?\n\nAutomate nothing until intake runs through one channel and coding decisions are written down; automation applied earlier runs an undefined process faster and less visibly than the manual version. Then sort each stage:\n\n| If the stage is | Then |\n|---|---|\n| Stable, exception-light and expressible as a rule | Automate it and sample its output |\n| Still varying case by case | Standardize it first, then test again |\n| Carrying a control judgment | Keep a person in it and automate only the routing |\n\nA stage is ready when its inputs are consistent and its exceptions known: vendors code the same way, the exception queue is small and understood, and the stage has run unchanged through a few month-ends. Among ready stages, start where the mapping showed the most handling time or longest waits.\n\nIn the invented example, approvals wait a median of nine days and keying takes about four minutes an invoice, or 10 hours a month at 150 invoices. That gives this order:\n\n1. **Approval routing and reminders.** The written matrix is already a rule, and routing cuts the longest wait while approving stays human.\n2. **Coding defaults.** Apply vendor defaults automatically once overrides are rare.\n3. **Capture.** Keying takes the most time, but automatic reading is ready only once vendors send one invoice per PDF to the one address. Then a person compares each bill with its PDF until the reading is reliable, and samples after that.\n\n## What should stay manual?\n\nThe stages that carry a control judgment stay manual: setting up vendors and changing their details, approving invoices, resolving exceptions such as a missing purchase order, a disagreeing price or quantity, a disputed charge, a credit note or a suspected duplicate, and urgent payments outside the normal run, which still pass approval and the release check. Keep one exception queue with a named owner and a target time for clearing it, so an exception waits where it is visible, not in someone's inbox.\n\n## What if one person does everything?\n\nIf one person receives, codes, approves and pays, make that a decision backed by compensating checks, not drift. COSO's executive summary says where segregation of duties is not practical, management selects and develops alternative control activities. The executive summary names no specific alternatives but lists verifications, reconciliations and business performance reviews among control activities; the checks below are of those kinds, chosen to close the ways money goes astray. With one employee processing and the owner as the second person, use these checks:\n\n- **Vendor changes stay with the owner.** Only the owner adds vendors or changes their contact or payment details, verifying each change when it arrives, and only the owner can edit the register. Remove the employee's right to edit vendors wherever the software allows.\n- **The owner releases payment.** The owner releases each payment batch after checking every payee's bank details on file against the register. Any difference stops that payment until the change is verified, which also catches an edit the software could not prevent.\n- **The owner reads the bank statement.** Each month the owner reads the statement straight from the bank and traces a few payments to approved bills with documents attached.\n- **The owner reviews exceptions.** Each month the owner reviews the exception queue and any overridden duplicate warnings, and initials and dates what was reviewed.\n\nIf the owner cannot release payments, the owner compares every payment in the month with the register instead, which finds a redirected payment only after the money has gone. If the owner is the one person, keep the verification rule and the register anyway, since the danger is deception rather than self-dealing, and have the outside bookkeeper or accountant, with read-only access, compare each month's payments with the register and the bills. Without an outside reviewer, make that comparison yourself each month, using the statement straight from the bank. That comparison finds a redirected payment only after the money has gone and cannot find a change you were deceived into registering, since the payment will match the register; of these checks, only the call to the number already in the register, made before anything changes, stops the loss.\n\nPlan for absence too: the mailbox, the software and the approval role each need a second person, with access limited to their stages.\n\n## How do you know the workflow is working?\n\nPaid or unpaid is the wrong test: a workflow can pay every bill on time while unentered invoices pile up and duplicates slip through. Read these monthly from the intake log and software:\n\n- **Cycle time.** Days from receipt to approval and to entry show where invoices wait.\n- **Unentered backlog.** Log lines with no bill yet, and the age of the oldest, show whether processing keeps up.\n- **Exception volume.** Open exceptions and the age of the oldest show whether exceptions are resolved or parked.\n- **Duplicates intercepted.** Copies caught before entry show the duplicate check working; any invoice paid twice shows it failing.\n- **Late notices.** Reminders or late fees for invoices never logged show a channel leaking.\n\nA rising backlog or an ageing exception queue shows the workflow degrading before a payment goes wrong.",
  "sources": [
    {
      "id": "REF::1",
      "url": "https://www.coso.org/_files/ugd/3059fc_1df7d5dd38074006bce8fdf621a942cf.pdf",
      "title": "Internal Control — Integrated Framework: Executive Summary",
      "publisher": "Committee of Sponsoring Organizations of the Treadway Commission (COSO)",
      "published": "May 2013",
      "retrieved_at": "2026-09-25T15:56:45+00:00",
      "sha256": "488d8ddec9ed24b61aea05374e255824fe7d181ea861b9cbedc63c5e2675fd59",
      "supports": [
        "C4",
        "C5",
        "C13",
        "C28",
        "C29"
      ]
    },
    {
      "id": "REF::2",
      "url": "https://www.accountingtools.com/articles/accounts-payable-controls",
      "title": "Accounts payable controls",
      "publisher": "AccountingTools (Steven Bragg)",
      "published": "May 02, 2026",
      "retrieved_at": "2026-09-25T15:56:46+00:00",
      "sha256": "80d00f0c8def80c4f3896e1752ddbd079d3a58f99de389e348eaa49d24733b6a",
      "supports": [
        "C1",
        "C3",
        "C6",
        "C7",
        "C8",
        "C9",
        "C17",
        "C18"
      ]
    },
    {
      "id": "REF::3",
      "url": "https://www.accountingtools.com/articles/how-to-set-up-an-accounts-payable-system.html",
      "title": "How to set up an accounts payable system",
      "publisher": "AccountingTools (Steven Bragg)",
      "published": "February 01, 2026",
      "retrieved_at": "2026-09-25T15:56:46+00:00",
      "sha256": "363a2797b39adfe7aca231aa483ddbd0546b140d90af3bc1294ae2e2bc20912b",
      "supports": [
        "C2",
        "C12"
      ]
    },
    {
      "id": "REF::4",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/manage-workflows/set-use-bill-approval-payment-release-workflows/L1IOLL9hv_US_en_US",
      "title": "Set up and use bill approval and payment release workflows",
      "publisher": "Intuit Inc.",
      "published": "updated 8/26/2026",
      "retrieved_at": "2026-09-25T15:58:48+00:00",
      "sha256": "524e16c168ea23aae7cef0f1afd8b3e87751b642548366750e07acb368504edc",
      "supports": [
        "C10",
        "C11",
        "C14",
        "C15",
        "C16",
        "C23",
        "C24",
        "C25",
        "C26",
        "C30",
        "C31",
        "C32",
        "C33",
        "C34"
      ]
    },
    {
      "id": "REF::5",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/bank-transactions/search-transactions-quickbooks-online/L4hBemuUP_US_en_US",
      "title": "Search for transactions and other data in QuickBooks Online",
      "publisher": "Intuit Inc.",
      "published": "updated 8/4/2026",
      "retrieved_at": "2026-09-25T16:01:11+00:00",
      "sha256": "ef57768017b1905ba35b36bf6240e0d3488039a65948bc5f876d2e38aa44c94e",
      "supports": [
        "C21",
        "C22"
      ]
    },
    {
      "id": "REF::6",
      "url": "https://www.ic3.gov/PSA/2024/PSA240911",
      "title": "Business Email Compromise: The $55 Billion Scam",
      "publisher": "Federal Bureau of Investigation, Internet Crime Complaint Center (IC3)",
      "published": "Alert Number I-091124-PSA, September 11, 2024",
      "retrieved_at": "2026-09-25T16:01:32+00:00",
      "sha256": "208db1c6f382d340a5447a674f8364a1e47ea83630d5a27a666f344bf5abd7bb",
      "supports": [
        "C19"
      ]
    },
    {
      "id": "REF::7",
      "url": "https://www.ftc.gov/business-guidance/small-businesses/cybersecurity",
      "title": "Cybersecurity for Small Business",
      "publisher": "Federal Trade Commission",
      "published": "September 2025",
      "retrieved_at": "2026-09-25T16:01:33+00:00",
      "sha256": "4ebe58a7e0b9bc45b719829dcd3bcf6862eaabffe559792a75e96e0b637cf22f",
      "supports": [
        "C20"
      ]
    }
  ],
  "related": [
    {
      "question_id": "CG-MCE-059",
      "slug": "a-vendor-emailed-asking-me-to-send-their-payments-to-a-new-bank-account-how-do-i",
      "display_title": "A vendor emailed asking me to send their payments to a new bank account — how do I verify that before I pay?"
    },
    {
      "question_id": "CG-P1B-001",
      "slug": "what-is-two-way-and-three-way-invoice-matching-in-accounts-payable",
      "display_title": "What is 2-way and 3-way invoice matching in accounts payable, and how do I run it across POs, receiving documents, and vendor invoices?"
    }
  ],
  "review_class": "consequential",
  "review_class_trigger": "claim_level_review_required",
  "provenance": {
    "author_model": "claude-opus-5-5",
    "reviewer_model": "claude-opus-5-5",
    "review_verdict": "ACCEPT",
    "review_source": "closure",
    "review_verdict_on_sha256": "dff799ab3466e0882e66694d319bd9977b59a624131df47db9f889d52f70a8a9",
    "editorial_disposition": "ACCEPT",
    "corrections": 1,
    "approved_by": null,
    "approved_at": null,
    "article_sha256": "dff799ab3466e0882e66694d319bd9977b59a624131df47db9f889d52f70a8a9",
    "source_map_sha256": "23227a24b11a4a929124086e194d21ab0598481164c12f08425bbcb6ec07afad",
    "transform_sha256": "0b964ca6c99b0ae3d44d5404dab8392696d0f899444776a7666f0d7fd3d3372f"
  },
  "offer": "ask",
  "offer_id": null,
  "sample_target_id": null,
  "datePublished": "2026-09-26T01:29:00Z",
  "reviewed_at": "2026-09-26T01:29:00Z",
  "content_sha": "278307deadc15b1db562a57688a364e10bdba0e5390dbe871b9465466607bfa7",
  "release": "2.7.0",
  "slug_provenance": "minted at first publication",
  "question_text": "How should a small business manage and automate its accounts-payable vendor-invoice and document workflow?",
  "jsonld_types": [
    "Article"
  ],
  "related_question_ids": [
    "CG-MCE-059",
    "CG-MCE-150",
    "CG-MCE-153",
    "CG-P1B-001",
    "CG-P1B-FULL-111"
  ],
  "aliases": [],
  "alias_provenance": []
}
