Which accounts-payable automation software or solution should a business choose, and what are the leading options and alternatives?
Applies to: United States · Updated 2026-09-27
List your payables facts first. Then shortlist your accounting platform's own bill features, dedicated products documenting a sync with your ledger, and a provider-run service; treat any "leader" label as unproven without independent evidence. Trial finalists on your invoices away from your live books. Remove any that cannot post correctly, separate payment release from bill entry and vendor changes, or return your records. Buy a dedicated product only if it beats your existing option by a preset margin.
What should you write down before you look at any product?
Write these facts down first; each becomes a requirement or a gate:
| Your fact | What it becomes |
|---|---|
| Bills per month and their mix: emailed PDFs, paper, portal downloads, credit memos | The volume and document types the trial must include; low, simple volume points first to native features or a manual routine |
| Purchase orders and receipts | If you use them, matching is a gate; if not, it carries no weight |
| Approval rules | Rules the workflow must run, on top of the second-person gate |
| Entities and ledgers | A working path to every ledger, with vendors and permissions kept per entity |
| Where payments leave from | If the product must pay, it holds vendor bank details, so payment execution is weighted and the assurance gate applies; if your bank pays, the second-person check must hold at the bank |
| Who runs it day to day | Roles keeping entry, vendor editing, approval and release apart; for an outside firm, logins without approval or administrator rights and cross-client administration; if work is split, who does each step; how each user is licensed |
| Your accounting platform and plan | The integration that must work, and the payables features you already hold |
What kinds of option are on the list?
These six groups are a working division for eliminating options, not a published market classification:
- Your platform's own payables features. Some accounting platforms include bills, approvals and sometimes payment, depending on your plan; check yours.
- Dedicated payables platforms. A separate product captures, codes, routes, pays and syncs to your ledger.
- Capture-and-coding tools. These read and code bills, leaving approval and payment elsewhere.
- Spend-management suites. Cards, reimbursements and bill payment share one product.
- A provider-operated service. An outside firm runs payables while you keep approval; engaging one is a separate question.
- A manual or template-based routine. You enter bills in the ledger and pay them from your bank.
Strike a candidate, not a group: if its current pages show it cannot pay, it cannot serve a business that must pay from the product; if they show it cannot match bills to orders, it cannot serve one that raises purchase orders.
When is buying nothing new the right answer?
If your platform already includes bill approval and payment, score those features against the same criteria and gates as any outside candidate. Check the entitlement: Intuit's help page on bill approval and payment release workflows says you need either QuickBooks Bill Pay Elite or QuickBooks Online Advanced to use workflows. The same page says that if you downgrade from QuickBooks Bill Pay Elite to another plan and are not subscribed to QuickBooks Online Advanced, you lose your roles and permissions settings and bill approval workflows, and bills needing approval can be paid without it, so the native gates hold only while you keep a plan that includes them; re-check them before any plan change.
A manual routine can stay right at low volume without purchase orders, provided payments still get the second person and callback described below. A provider suits a business where nobody in-house should run payables; you keep approval, and its system faces the same gates. Before scoring, set the margin by which a dedicated product must beat the best of these to justify a second system; buy none if one of these passes every gate and no dedicated candidate beats it by that margin.
Which products are the leading options?
No product is named the leader for your segment: that standing needs independent evidence, and neither a vendor's own "leader" badge nor a ranking the ranked vendors pay to join supplies it. Build the shortlist from your platform's own payables features and from products whose current pages document a sync with the ledger you run, keeping two or three per remaining group. Take every capability claim from the candidate's current help pages, note each page's date, or the day you read it if it shows none, and confirm each claim in your trial before signing. QuickBooks and BILL appear below only as examples of what such pages settle and leave open.
Which criteria matter, and what evidence meets each?
Score each criterion only on behavior seen in your trial or in current, dated documentation:
| Criterion | Evidence that meets it |
|---|---|
| Ledger integration | Trial bills, payments, vendors and credits posted in a test company at the accounts, dimensions and detail you use |
| Capture and coding accuracy | Share of your own bills with every field right and uncorrected, not the vendor's stated rate |
| Matching | Purchase-order bills matched to orders and receipts, and a planted mismatch stopped |
| Approval workflow | Your real routing rules running, including thresholds and cover for an absent approver |
| Payment execution | The methods you need, documented and demonstrated by the candidate |
| Controls and audit trail | A product-kept log, unalterable by vendor editors, of who entered, changed, approved and released each item, with old and new values |
| Roles and permissions | Test logins proving entry, vendor editing, approval and release can sit with different people, each refused sign-in without its second factor |
| Exception handling | Duplicates caught, credit memos applied, partial and disputed payments handled |
| Reporting | Payables aging and approval-status reports that agree with the test company |
| Data export and exit | A full export run in the trial, opened and checked |
| Security and assurance | A current independent report, or written answers to the questions below |
| Support model | Answers and response times during the trial, and who does onboarding |
| Effort per bill | Minutes per bill, corrections included, against your current baseline |
| Cost | Expected annual cost at your volumes; pricing structures are a separate question |
How do you check the integration with your ledger?
Connect each finalist only to a test company on your accounting platform, set up with your chart of accounts and dimensions, never to your live books, where your test documents are already posted: syncing them again would double that month's payables and expenses and put paid bills back in line for payment. Ask your platform whether you can create a test company, and on what plan, and ask each candidate whether it can host one on your platform with your chart of accounts. If neither can, have the candidate show postings on your ledger product, record that the posting test did not run on your chart, and never connect to your live books instead. A test company for your platform's own bill features needs the plan they require; for QuickBooks, Intuit's workflows page names Bill Pay Elite or Online Advanced. Then check these points:
- Direction. Find what flows in from the ledger and what flows back. A vendor change synced in from the ledger must be logged and shown at approval like one made in the product.
- Detail. Compare how a bill posts, as one line or line by line and to which accounts, with the same bill entered by hand.
- Timing. See when an approved bill or a payment reaches the ledger, and whether that suits your close.
- Conflicts. Edit and delete a synced bill in the test company, and watch for duplicate vendors or bills.
A sync claim shows none of this. For example, BILL's integrations page, read on 25 September 2026, says BILL Accounts Payable and BILL Accounts Receivable offer automatic two-way sync with QuickBooks Online, QuickBooks Pro/Premier, QuickBooks Enterprise, Xero, Oracle NetSuite, Sage Intacct and Microsoft Dynamics, and offers CSV export and import for other accounting software. Asked whether you can control when sync occurs, it says automatic sync runs every 24 hours and that you can also choose to sync on demand. The page does not say which BILL plans include each sync; get the sync for the plan you would buy confirmed in writing before the trial.
Which controls over vendor details and payment release must a candidate support?
An FBI Internet Crime Complaint Center announcement on business e-mail compromise advises verifying changes in vendor payment location with added two-factor authentication such as a secondary sign-off by company personnel and, for phone checks, using previously known numbers, not those in the e-mail request. OpenStax's accounting text adds that typically, the person who writes a check should not also sign it. Where the product pays, require five behaviors; where your bank pays, the staffing table's bank row below says which the product still needs:
- Restricted editing. Only named users can add a vendor or change its bank, remittance or contact details.
- A log editors cannot alter. The product records who added or changed each vendor field, when, with old and new values, beyond the reach of anyone who edits vendors.
- A second person on every payment. Every payment, of any amount to any payee, needs approval from a second user, and roles stop anyone who enters bills or edits vendors from giving it. Treat this as your own safety rule; it keeps preparing and releasing a payment separate. If a set-up lets some payments through without that approval, for example those under a set amount, a user who can both edit vendors and make payments could change a vendor's bank details and pay that vendor below that amount alone.
- Changes shown at approval. The approver sees on the payment that the payee's bank details are new or changed since the last payment, and who changed them.
- Second-factor sign-in. Every login that can add or change vendors, approve or release payments, or manage users must sign in with a second factor, such as a dynamic PIN or code, that you can make mandatory.
The second-person gate protects only while nobody else can sign in as the approver. The FBI announcement suggests considering two-factor authentication for corporate e-mail accounts against compromised passwords; the fifth behavior asks the same of payables logins.
Keep administrator logins with the owner or an approver who does not maintain vendors, and check what each role can do, not its name. An administrator may be able to both change vendor details and approve, and the control test below does not check administrators; where approvers must be administrators, separation rests on keeping those logins from anyone who maintains vendors. Intuit's help page on bill approval and payment release workflows says its Bill payer role can view and pay bills and edit vendor details, that conditions on amount, vendor or both trigger payment release approval, that a user creating a bill payment meeting those conditions is asked to submit it for approval, and that only admins can be approvers. The same page says further When this happens and Do this blocks can be filled in for when the initial conditions aren't met, but not that this catches every payment. In the trial, set them so every payment, including one below any amount condition, goes to an admin approver other than the Bill payer, and run the control test; if any payment goes through unapproved, the set-up fails the second-person gate, since a Bill payer could change a vendor's details and pay that vendor alone.
Before any payment goes to changed bank details, the approver, not whoever made the change, calls the vendor on a number the business held before the change, from a record the changer cannot edit, such as the signed contract. Never use a number from the request or from a vendor record whose contact details changed since the last verified payment: a false request can change those first and answer the call. Pay nothing to changed details until the call confirms them.
These checks cover changes to an existing vendor. The FBI announcement also advises arranging out-of-band verification early in the relationship and outside the e-mail environment, but how to confirm a new vendor's first bank details belongs to the payables-workflow question.
Three staffing situations change who makes these checks:
| If | Then |
|---|---|
| You are the only person in the business | No product can supply a second person. Judge the second-person gate on whether the product could enforce it once you add someone, and make the callback yourself before paying changed bank details. |
| An outside bookkeeper or firm enters bills or maintains vendors | Give their staff no approval, release or administrator rights; before approving, your approver checks the product's own change log, not a list the bookkeeper supplies, and makes the callback. |
| Your bank executes payments | The product's approvals do not govern a payment keyed at the bank, but the product still needs restricted editing, a log editors cannot alter and second-factor sign-in. Whoever releases at the bank must not enter bills or maintain vendors, and checks the product's change log and makes the callback before each run. If that cannot be arranged in a business of more than one person, ask whether your bank can require a second user's approval on every payment; if not, the set-up fails the gate. |
How do you run the trial?
Run the trial on your own documents and people, in this order:
- Time your current process in minutes per bill as the baseline, and keep it running unchanged in your live books throughout.
- Connect the candidate to a test company, and get its assurance answer before loading real vendor data.
- Set up your real approval rules, with a separate login per role, and run the control test below.
- Build a test set from a recent month with every document type you receive, plus one invoice entered twice, a new vendor's bill and, if you use purchase orders, a quantity mismatch.
- Have the people who will run the process work the set, logging every correction and inspecting every posting. Pay no test bill: your current process already handles each one.
- Run a full export and open it.
- Work a second month's set, timed, so learning does not count against the candidate, and reconcile the test company's payables aging to your documents.
- Finish by confirming no test bill is scheduled for payment, and disconnect the candidate from any bank account you linked.
Measure fields right first time, minutes per bill, duplicates and mismatches caught, postings corrected, approvals routed correctly and the control test. A failed gate removes the candidate; every other result feeds its score.
How do you test the second-person gate safely?
From each non-administrator login that can edit vendors, change a test vendor's bank details to an account the business itself holds, then, where the product pays, try to pay that vendor the smallest amount the product accepts, outside any approval condition, stopping before the final confirmation. If the login gets there without a second person's approval, the gate has failed: cancel and record it. Otherwise record what the approver sees and what the log shows, and have the approver reject the payment. Last, try to sign in to the approver's and a vendor editor's test logins without the second factor; each must be refused.
What should remove a candidate outright?
Treat these findings as gates, passed or failed and never averaged into a score:
- The candidate cannot be shown posting bills, payments, vendors and credits to a company other than your live books on each ledger you run, at the detail you use, or its postings routinely need correction.
- Where the product pays, it lacks any of the five control behaviors above.
- Where your bank pays, the product lacks restricted editing, a log editors cannot alter or second-factor sign-in, or the release at the bank misses the conditions in the staffing table's bank row.
- Processed bills, payments and their attachments cannot be exported in a form you can open.
- You raise purchase orders and the candidate cannot match bills to them.
- The candidate will pay your vendors but offers neither an independent assurance report nor satisfactory written answers on its controls.
- For a bookkeeping firm, the candidate does not keep client records separate.
What can you take with you if you leave?
Records synced to your ledger stay there; what lives only in the product, such as invoice images, approval history, change logs and vendor bank details, is lost unless exported. For native features, Intuit's page on exporting QuickBooks Online data says reports and lists export as Excel files in one .zip file, and attachments in a zip file; it also gives steps for non-posting transactions. Confirm in the trial whether approval history and change logs can be exported. From each dedicated candidate, get in writing before signing what can be exported, in what format, whether attachments and history are included, and how long the account stays reachable after canceling, then run that export in the trial. BILL's integrations and Security Center pages, as read, do not say what a customer can export on leaving; the integrations page's CSV export is for accounting software BILL does not sync with, not an exit export.
What assurance should you ask for?
The AICPA's publication page for its SOC 2 guide says a SOC 2 examination covers controls at a service organization relevant to security, availability, processing integrity, confidentiality or privacy, and that customers and business partners usually need information about the design, operation and effectiveness of those controls and often request a SOC 2 report. BILL's Security Center page, for example, says BILL undergoes an annual SOC 1 and SOC 2 Type II audit by a national CPA firm; the page as read does not say whether or how customers can obtain the reports.
Ask each finalist for the report itself, not a badge, covering the product you are buying and a recent period, and ask your auditor, if you have one, which report they want. Where none is published, ask for one under a nondisclosure agreement; if none exists, get written answers on how vendor bank-detail changes, payment release and staff access to your data are controlled and how your users' sign-in is protected.
How does the choice change for a bookkeeping firm choosing for many clients?
A firm choosing one product for many client entities adds three criteria: client separation, so staff see only assigned clients and vendor records never cross; multi-entity administration, so staff are added, removed and moved between clients in one place; and onboarding hours per client to connect a ledger, import vendors and set approval rules. Test them after the assurance check with two or more clients on different ledgers, each in its own test company; they can reverse the ranking a single business would reach. The staffing controls above apply to each client.
What does a scoring worksheet look like?
Turn each fact into a gate or a weighted criterion, give the weights 100 points in total, score each finalist from 1 to 5 and multiply; gates override the total, and the margin is set before scoring.
In this example, a business has 180 bills a month, mostly emailed PDFs, no purchase orders and one ledger; an outside bookkeeper enters bills and maintains vendors, and the owner releases payments at the bank. Its gates are a ledger path, restricted vendor editing, a change log the bookkeeper cannot alter and the owner checks before each bank run, second-factor sign-in, the owner as releaser at the bank, and export with attachments. Matching and payment execution do not apply, and roles, the change log, sign-in and export are gates, so none carries weight; assurance is weighted because neither candidate pays vendors, though each finalist's answer still comes before real vendor data is loaded. The margin is 40 points; A is the platform's own features, B a dedicated product:
| Criterion | Weight | A score | A weighted | B score | B weighted |
|---|---|---|---|---|---|
| Ledger integration | 20 | 5 | 100 | 4 | 80 |
| Capture and coding accuracy | 20 | 2 | 40 | 4 | 80 |
| Approval workflow | 10 | 3 | 30 | 4 | 40 |
| Exception handling | 10 | 3 | 30 | 4 | 40 |
| Effort per bill | 10 | 3 | 30 | 4 | 40 |
| Security and assurance | 5 | 4 | 20 | 4 | 20 |
| Reporting | 5 | 4 | 20 | 4 | 20 |
| Support model | 5 | 3 | 15 | 3 | 15 |
| Cost | 15 | 5 | 75 | 3 | 45 |
| Total | 100 | 360 | 380 |
Both pass every gate. B leads by 20 points out of 500, short of the 40-point margin, so the business keeps its platform's features. Had B's export left out attachments, B would have left the list whatever its score.
Keep the worksheet with its evidence, such as trial measurements, role and change-log screenshots, export files, the assurance answer and dated vendor pages, so a renewal or successor can see why you chose and what you rejected.
Sources
- Intuit Inc. — Set up and use bill approval and payment release workflows, updated 8/26/2026
- BILL Operations, LLC — BILL Accounting Software Integrations, undated; retrieved 25 September 2026
- Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) — Business E-mail Compromise E-mail Account Compromise The 5 Billion Dollar Scam, Alert Number I-050417-PSA, May 4, 2017
- OpenStax, Rice University — Principles of Accounting, Volume 1: Financial Accounting — 8.3 Describe Internal Controls within an Organization, publication date April 11, 2019
- Intuit Inc. — Export your QuickBooks Online data, updated 8/3/2026
- AICPA & CIMA — SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy (publication page), publication date 2022
- BILL Operations, LLC — Security Center, undated; retrieved 25 September 2026