{
  "question_id": "CG-P1B-FULL-083",
  "slug": "what-is-involved-in-outsourcing-accounts-payable-automation",
  "display_title": "What is involved in outsourcing accounts-payable automation to an external provider?",
  "format": "article-v2",
  "applies_to": {
    "countries": [
      "US"
    ],
    "frameworks": [],
    "tax_year": null,
    "platforms": []
  },
  "general_concept": true,
  "summary": "Outsourcing payables automation means an outside provider runs the processing work (intake, coding, matching, exceptions, approval-flow upkeep, payment preparation and vendor-master upkeep) on its own platform or inside your system. You keep invoice approval, payment release, approval of vendor bank-detail changes and responsibility for your records. The work lies in writing down your rules, proving the provider's results in a parallel run, scoping its access, monitoring its output, and settling record access, retention and hand-back before signing.",
  "body": "## Which delivery model is the provider proposing?\n\nThree models are worth telling apart. Record custody, access administration and what you can recover at exit follow from the one a candidate proposes, so ask.\n\n| Model | Software and data | People | What it puts on you |\n|---|---|---|---|\n| Provider's own platform | The provider's system holds your invoices, vendor records and payment files, and returns results or posts them to your ledger | Provider staff | Your records sit with a third party, so access, retention and hand-back must be contract terms |\n| Your system, operated by the provider | Your accounting or payables system, on your subscription | Provider staff under logins you grant | You administer their access, and the records stay with you |\n| Hybrid | Payables software you license, configured and staffed by the provider | Provider staff | You hold the data, but the configured rules stay with the provider unless documented and handed over |\n\n## Which steps transfer, and which authorities stay with you?\n\nPayables is a chain, and a step the engagement does not name is a step neither party performs. The 2023 Interagency Guidance on Third-Party Relationships from the Federal Reserve, FDIC and OCC is directed at banks, but its contract advice fits here: clearly identify the rights and responsibilities of each party.\n\n| Step | The provider can perform | Stays with you |\n|---|---|---|\n| Intake and capture | Receiving invoices and extracting their data | Where vendors send invoices |\n| Coding | Applying your written coding rules | The rules, and any new account |\n| Matching | Matching invoices to orders and receipts | The tolerances, and accepting variances beyond them |\n| Exceptions | Researching and routing them | Vendor disputes and write-offs |\n| Approval-flow administration | Maintaining routing as you direct, each change only after your written approval | Who approves what, and each approval |\n| Payment preparation | Proposing runs from approved invoices | Authorizing and releasing payment |\n| Vendor master upkeep | Keying vendor data other than bank and contact details, and flagging duplicates | Approving new vendors, and verifying and entering every bank or contact-detail change |\n| Reporting | Aging, exception and turnaround reports | Reviewing and acting on them |\n\nFour authorities stay inside the business in every model: invoice approval, payment release, verifying and entering vendor bank and contact changes, and signing off any change to approval routing or to the conditions that trigger approval. Your recordkeeping obligations do not move either, as the records section explains. OpenStax's *Principles of Accounting* gives the reason: separating duties ensures a check and balance, and the person who writes a check should not also sign it. A proposal moves one of these authorities if it gives the provider administrator rights, bank credentials that can release payments, authority to approve invoices, authority to approve vendor bank or contact changes or to make them where step 5 below is impossible, or control of approval routing without your sign-off. Strike those terms.\n\n## How do you keep payments going to the right account?\n\nWith one outside party preparing payments, the vendor master is the obvious target. The FBI's Internet Crime Complaint Center (IC3), in its 2017 business e-mail compromise alert, advises verifying changes in vendor payment location with a secondary sign-off by company personnel, phoning previously known numbers rather than those in the request, and arranging this verification early in the relationship. Build it in this order:\n\n1. At cutover, record each active vendor's bank details and phone number, confirmed by callback, somewhere provider staff cannot edit. The record changes only through steps 2 to 4.\n2. The provider forwards every new-vendor request and every bank or contact-detail change to you, with what it received, and acts on none.\n3. You call the vendor on the number in your record, or for a new vendor on one from the contract or your own contact, never one from the request. Contact-detail changes get the same callback, because a fraudster who first changes the contact details can then confirm the bank change himself.\n4. Someone in the business enters the verified details, and a second person in the business signs them off against the callback before any payment goes to them.\n5. Before releasing each run, the releaser compares every payee's bank details with your record and releases nothing that differs.\n\nProvider logins should not be able to change vendor bank or contact details. Where your platform cannot prevent that, accept it only with step 5 on every run; otherwise, keep all vendor editing in-house. Where one person is the whole business, nobody can give the step 4 sign-off and nothing replaces it; that person makes every callback personally and never skips step 5.\n\nIf the provider prepares runs and you release them, also check each run against approved invoices. A proposal for the provider to release payments, even within limits, moves release outside the business and puts preparation and release with one party, so keep release in-house. If you accept it anyway, none of these restores the separation, but they are the least you need: limits enforced at your bank, no provider ability to add payees or change bank details in the payables system or at the bank, and review of every released payment against approved invoices before the next run, which catches a bad payment only after it has left.\n\nRequire the provider to report a suspected misdirected payment at once. The IC3's 2017 alert says to act quickly: contact your financial institution immediately, ask it to contact the institution the transfer was sent to, contact your local FBI office if the wire is recent, and file a complaint, regardless of dollar loss, at www.ic3.gov or, for business e-mail compromise, bec.ic3.gov.\n\n## What has to happen before cutover?\n\nA provider cannot discover rules you never wrote down. It will make its own coding and tolerance decisions, and you will find them only when results are wrong.\n\n### What must exist before cutover?\n\nHave these in writing before the provider touches a live invoice:\n\n- A process map from receipt to payment, showing who approves what at which amounts\n- Coding rules with account descriptions and default coding by vendor\n- Matching tolerances, and the route for items outside them\n- A cleaned vendor master, with duplicates merged, inactive vendors closed and your callback-confirmed record of bank and contact details\n- An approval matrix naming who approves invoices, releases payments and signs off vendor changes\n- A payables listing at the cutover date, reconciled to the general ledger\n\n### What does the provider build?\n\nThe provider returns its build as documents you keep: the capture set-up, coding and routing rules configured from your written rules, exception queues and escalation routes, turnaround reports, and named user accounts in roles you approve.\n\n### What must the parallel run prove?\n\nKeep the parallel run out of your live books. Only one process posts to the live ledger and only one process's runs are released; the other's coding, exceptions and proposals are compared outside it, for example in a test file if your platform offers one. Include a month-end and every kind of item you want tested. Stop the old process only when the run shows:\n\n- The same coding on the same invoices, with every difference explained\n- The same exceptions caught, including seeded test items such as a duplicate invoice\n- Payment proposals containing only approved invoices\n- Vendor balances that reconcile to your ledger\n\nAt cutover, assign every open invoice on the reconciled listing to one process, so none is posted or paid twice.\n\nIf you are replacing an in-house clerk, capture what that person knows, including vendor quirks and approvals done by habit. If a bookkeeper stays on, write down who posts, who reconciles payables and who reviews the provider, so nothing is done twice or not at all. The bookkeeper can be the reviewer if they neither work for the provider nor release payments.\n\n## How should the provider's staff get into your system?\n\nWhen the provider works inside your system, access administration, audit attribution and record custody are yours. Set access up this way:\n\n- **Named logins.** Each provider person gets their own login. The FTC's *Start with Security* guide says a company that shared credentials with contractors, and did not end them when one left, could have required distinct access keys and multifactor authentication. Check your platform's documentation for whether it records who made each change and lets you see that record.\n- **Least privilege.** The FTC guide says administrative access should be limited to the employees tasked with that job. Provider staff never get administrator roles.\n- **People changes.** Remove a provider person's login the day you learn they left or changed role, and check the user list monthly against the provider's team.\n\nFor QuickBooks Online, Intuit's help page on bill approval and payment release workflows (updated August 26, 2026) ties these workflows and bill-payment roles to QuickBooks Bill Pay Elite or QuickBooks Online Advanced; on another plan, confirm what a provider login can do before granting one. On those plans, it says the following; check your own platform's documentation the same way:\n\n- Only admins can be approvers for payment release, so an admin login would let provider staff approve releases.\n- The bill clerk role can add bills, mark bills as paid, and add and edit vendors, so give it to provider staff only with step 5 on every run, and match bills marked paid to your bank activity, investigating any marked paid outside a run you released.\n- The bill payer role can pay bills and edit vendor details, so never give it to provider staff.\n- The amount and vendor conditions you set are what trigger release approval, so set them to catch every payment a provider login can create.\n- Downgrading from Bill Pay Elite to a plan without Online Advanced removes roles and permissions settings and bill approval workflows, so bills needing approval can be paid without it, and automatically rejects all bill payments pending approval. Make plan changes an owner decision; before any downgrade, resolve pending payments and, as Intuit recommends, remove users in the bill clerk, bill payer and bill approver roles.\n\nWhen the provider works on its own platform, ask instead how it segregates duties among its staff, which the interagency guidance treats as part of assessing a provider's risk management, and how you reach your own data.\n\n## What does a provider's assurance report cover, and what do you still monitor?\n\nThe AICPA describes a SOC 1 report as an examination of controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting, intended for those customers and their auditors. AS 2601 is the PCAOB's auditing standard for the customer's auditor, and its terms can differ from the AICPA's (it says \"user organization\" where the AICPA says \"user entity\"); the AICPA's SOC 1 page lists its reporting guide. Find three things in any report:\n\n- **Tests over a stated period.** AS 2601 separates a report on controls placed in operation at a date, not intended to provide any evidence of their operating effectiveness, from one that adds tests over a stated period; ask for the second. Its opinion covers only the controls tested, during that period, with reasonable, but not absolute, assurance, and the report warns of the risk of projecting its conclusions forward, so check that the period is recent.\n- **Which controls were tested.** Compare them with the steps the provider performs for you.\n- **Controls the report assumes you apply.** Under AS 2601 they should be listed in the description of controls if the service auditor is aware of the need for them and, where they are needed to achieve the control objectives, the opinion assumes you applied them. Ask the provider in writing for any it assumes that the report does not list, and give each a named owner and run it.\n\nAS 2601 also has the service auditor state that it performed no procedures on controls at individual customers, so the report tests nothing you do. If the provider has no report, the interagency guidance, written for banks, gives options such as getting other information to assess the provider, adding controls on or monitoring of it, or using a different provider. Whatever the report says, keep this monitoring:\n\n- Each run checked against approved invoices and your bank-detail record before release\n- Monthly vendor-master changes checked against callback records\n- Monthly routing and workflow-condition changes checked against your written approvals\n- The monthly user-list check\n- Aged payables, exception and turnaround reports reviewed against the commitments\n- A quarterly sample traced from receipt to payment, checking coding, matching and approvals\n- The payables ledger reconciled to the general ledger and vendor statements\n\nWith no in-house finance staff, the owner or a named manager who does not work for the provider holds release, vendor-change approval and these reviews. An outside accountant independent of the provider can do the sampling and reconciliations, but not release or vendor-change approval. If nobody inside can hold them, do not outsource the function.\n\n## What should the engagement terms say?\n\nWrite these terms into the agreement:\n\n- **Scope.** Every step in your table is assigned to the provider or to you.\n- **Service levels.** Time to entry, exception turnaround and run cutoffs are set. The interagency guidance warns against measures encouraging processing volume or speed without regard for accuracy, so pair each with an accuracy measure.\n- **Quality and errors.** Sample errors, duplicate or misdirected payments and overdue exceptions are tracked, with who corrects a mis-posted item, by when, and who bears the cost of a payment the provider misdirected.\n- **Audit and remediation.** You have a right to audit with remediation, as the interagency guidance describes, and a named assurance report.\n- **Security and incidents.** The FTC advises insisting that appropriate security standards are part of your contracts, and the interagency guidance adds a term on when and how the provider discloses security breaches or unauthorized intrusions in a timely manner.\n- **People.** The provider gives same-day notice when anyone with access to your system leaves or changes role, and notice of key personnel changes or use of subcontractors, which the interagency guidance lists among changes to notify.\n\n## What happens to your records, at exit and if the provider fails?\n\nRev. Proc. 98-25 sets the IRS's basic requirements for records kept within an Automatic Data Processing system (ADP). It applies to a taxpayer with assets of $10 million or more at the end of its taxable year, a controlled group of corporations counting as one corporation with all members' assets aggregated. A smaller taxpayer is covered if any one of these holds: all or part of the information section 6001 requires is not in its hardcopy books and records but is available in machine-sensible records; machine-sensible records were used for computations that cannot be reasonably verified or recomputed without a computer; or the District Director notifies it that machine-sensible records must be retained. Either way, the procedure also requires meeting Rev. Rul. 71-20's record retention requirements; have your tax adviser check your retention terms against it. The IRS's FAQ on electronic accounting software records adds that these exemptions excuse no taxpayer from producing electronic books and records that otherwise exist.\n\nMachine-sensible records are data in an electronic format intended for use by a computer. Paper records converted to an electronic storage medium are excluded, and for electronic storage systems the procedure points to Rev. Proc. 97-22, so check that procedure too if the provider scans paper invoices. Using a third party such as a service bureau does not relieve the taxpayer of its recordkeeping obligations. Whether or not the procedure applies, the IRS's FAQ says you must present your records when requested in an examination, so settle these terms before signing; items marked Rev. Proc. 98-25 apply only where it does:\n\n- **Ownership and access.** Your records and any data the provider generates are yours to view and export at any time.\n- **Retention.** The procedure requires keeping records so long as their contents may become material, at a minimum until the period of limitation for assessment, including extensions, expires for each tax year, and says some, such as records pertaining to fixed assets, should be kept longer. The provider keeps them that long and returns them before deleting anything.\n- **Examination access (Rev. Proc. 98-25).** The procedure requires records to be available on request and capable of being processed, with the resources the District Director determines are needed at an examination; no agreement, such as a contract or license, may limit IRS access to and use of the system, wherever it is maintained. Your agreement must not restrict that access, and the provider supplies what you need.\n- **Record events (Rev. Proc. 98-25).** Except as its section 9.02 on partial loss of data provides, the procedure requires prompt notice to the District Director if records are lost, stolen, destroyed, damaged or otherwise no longer capable of being processed, or are found incomplete or materially inaccurate. The notice identifies the records and plans how, and in what timeframe, they will be replaced or restored. The provider tells you of any such event at once; ask the IRS or your tax adviser which office receives the notice now.\n- **Hand-back.** On exit you receive invoice images with their data, the vendor master, approval evidence, payment history, the audit trail and the configured rules, in formats your next system can read.\n- **Documentation (Rev. Proc. 98-25).** Each file comes with the documentation the procedure requires: record layouts, field definitions (including the meaning of all codes), file descriptions, evidence that it reconciles to your books, and evidence of periodic checks if you want to rely on section 9.02; you keep the reconciliation to your tax return. The provider also returns the system documentation the procedure requires: how data flows through the system, internal controls for accurate processing and against unauthorized changes to records, the chart of accounts with account descriptions, and a dated record of changes to all of these.\n- **Exit and failure.** The interagency guidance lists termination terms with reasonable time frames for an orderly transition, timely return or destruction of your data, and assignment of all costs of transition and termination. It also raises transferring your accounts, data or activities to another third party without penalty on the provider's bankruptcy, business failure or business interruption.\n\nRemove every provider login and integration the day the engagement ends, and get written confirmation of what was destroyed. If a third party reformats or processes records during migration, Rev. Proc. 98-25 says the taxpayer must be able to demonstrate quality controls were in place. Holding release and bank access lets you keep paying if the provider stops, but only what you can see is owed, so export the vendor master, open items and approval status after every payment run, and keep invoices arriving at an address you control.\n\n## When does outsourcing payables fit, and when does it not?\n\nIt fits when these hold:\n\n- Your process can be written down and does not change month to month\n- Invoice volume is steady enough to repay the transition work\n- Someone inside can hold release, vendor-change approval and the monthly reviews\n- Your platform lets you scope the provider's access, or the provider's platform gives you access and exports\n\nIf any of these fails, or the provider insists on release rights, administrator access or authority over vendor changes, do not outsource the function.\n\nIf the same provider already runs other functions for you, the interagency guidance lists dependency on a single provider for multiple activities as an operational-resilience consideration. Weigh it, and strengthen the exit and continuity terms.",
  "sources": [
    {
      "id": "REF::1",
      "url": "https://www.irs.gov/pub/irs-drop/rp-98-25.pdf",
      "title": "Rev. Proc. 98-25",
      "publisher": "Internal Revenue Service",
      "published": "effective for machine-sensible records relating to taxable years beginning after December 31, 1997",
      "retrieved_at": "2026-09-25T18:02:34+00:00",
      "sha256": "db28dec2d05880f4df3ce407243589170bee286fb03cfbe84bed2b425c9434a8",
      "supports": [
        "C5",
        "C42",
        "C43",
        "C44",
        "C45",
        "C46",
        "C47",
        "C48",
        "C52",
        "C53",
        "C54",
        "C55",
        "C56",
        "C57",
        "C58",
        "C59",
        "C60",
        "C61",
        "C63",
        "C64",
        "C66",
        "C67",
        "C68",
        "C69",
        "C70",
        "C71",
        "C72",
        "C73",
        "C74",
        "C75",
        "C76",
        "C77",
        "C78",
        "C84",
        "C96",
        "C97",
        "C98",
        "C99",
        "C100",
        "C101",
        "C102"
      ]
    },
    {
      "id": "REF::2",
      "url": "https://www.irs.gov/businesses/small-businesses-self-employed/use-of-electronic-accounting-software-records-frequently-asked-questions-and-answers",
      "title": "Use of electronic accounting software records: Frequently asked questions and answers",
      "publisher": "Internal Revenue Service",
      "published": "page last reviewed or updated 03-Jul-2026",
      "retrieved_at": "2026-09-25T18:02:35+00:00",
      "sha256": "310e2356274e263bcd15ebd39e25d4332eeb23863418642c6e3d8ea25c427073",
      "supports": [
        "C51",
        "C95"
      ]
    },
    {
      "id": "REF::3",
      "url": "https://www.federalreserve.gov/supervisionreg/srletters/SR2304a1.pdf",
      "title": "Interagency Guidance on Third-Party Relationships: Risk Management",
      "publisher": "Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation and Office of the Comptroller of the Currency",
      "published": "June 7, 2023",
      "retrieved_at": "2026-09-25T18:02:36+00:00",
      "sha256": "71c4773040a51928eea587fa74442ab37d313d184684ab690bb4b4b445cb7c54",
      "supports": [
        "C1",
        "C2",
        "C26",
        "C36",
        "C37",
        "C38",
        "C40",
        "C41",
        "C79",
        "C80",
        "C81",
        "C82",
        "C83",
        "C85"
      ]
    },
    {
      "id": "REF::4",
      "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS2601",
      "title": "AS 2601: Consideration of an Entity's Use of a Service Organization",
      "publisher": "Public Company Accounting Oversight Board",
      "published": "effective for service auditors' reports dated after March 31, 1993",
      "retrieved_at": "2026-09-25T18:02:36+00:00",
      "sha256": "9116f7986c2809df0aeecb57e84076a374c85c48c687122335a4620914248ac1",
      "supports": [
        "C29",
        "C30",
        "C31",
        "C33",
        "C34",
        "C35",
        "C92",
        "C93",
        "C94"
      ]
    },
    {
      "id": "REF::5",
      "url": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-1",
      "title": "SOC 1® - SOC for Service Organizations: ICFR",
      "publisher": "AICPA & CIMA",
      "published": "undated",
      "retrieved_at": "2026-09-25T18:02:41+00:00",
      "sha256": "002cc0fe260a2fa9c7d707abd31675e3c890c63ebbbd436dcbad368485f755f3",
      "supports": [
        "C27",
        "C28",
        "C91"
      ]
    },
    {
      "id": "REF::6",
      "url": "https://openstax.org/books/principles-financial-accounting/pages/8-3-describe-internal-controls-within-an-organization",
      "title": "Principles of Accounting, Volume 1: Financial Accounting — 8.3 Describe Internal Controls within an Organization",
      "publisher": "OpenStax, Rice University",
      "published": "April 11, 2019",
      "retrieved_at": "2026-09-25T18:02:41+00:00",
      "sha256": "7079e278c524b2b4bb389648aa1e4e65c14d852f740a4220e988fd8082b0d84a",
      "supports": [
        "C3",
        "C4"
      ]
    },
    {
      "id": "REF::7",
      "url": "https://www.ic3.gov/PSA/2017/PSA170504",
      "title": "Business E-mail Compromise E-mail Account Compromise The 5 Billion Dollar Scam (Alert I-050417-PSA)",
      "publisher": "Federal Bureau of Investigation, Internet Crime Complaint Center",
      "published": "May 4, 2017",
      "retrieved_at": "2026-09-25T18:02:42+00:00",
      "sha256": "0addb813ce2c25137fa5c7c8b4a9bf132ec8d04c9e09c88aba497e70c3ab9c52",
      "supports": [
        "C6",
        "C7",
        "C8",
        "C9",
        "C10",
        "C11",
        "C12",
        "C13"
      ]
    },
    {
      "id": "REF::8",
      "url": "https://www.ftc.gov/business-guidance/resources/start-security-guide-business",
      "title": "Start with Security: A Guide for Business",
      "publisher": "Federal Trade Commission",
      "published": "August 2023",
      "retrieved_at": "2026-09-25T18:02:43+00:00",
      "sha256": "b3ef494e42634ba7a11270fd93f0ca59b03ec38767eded2f5afe7399080b7cbd",
      "supports": [
        "C14",
        "C15",
        "C16",
        "C17",
        "C39"
      ]
    },
    {
      "id": "REF::9",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/manage-workflows/set-use-bill-approval-payment-release-workflows/L1IOLL9hv_US_en_US",
      "title": "Set up and use bill approval and payment release workflows",
      "publisher": "Intuit Inc.",
      "published": "updated 8/26/2026",
      "retrieved_at": "2026-09-25T18:04:26+00:00",
      "sha256": "54f8edc5d0165e5691c629754d752a284aefa771945b10f9179de45dbbb0afd7",
      "supports": [
        "C19",
        "C20",
        "C21",
        "C23",
        "C24",
        "C25",
        "C86",
        "C87",
        "C88",
        "C89",
        "C90"
      ]
    }
  ],
  "related": [
    {
      "question_id": "CG-P1B-FULL-040",
      "slug": "what-outsourcing-accounts-payable-invoice-matching-involves",
      "display_title": "Who provides outsourced invoice-matching services, and what does having a provider perform AP invoice matching involve?"
    },
    {
      "question_id": "CG-P1B-FULL-097",
      "slug": "what-is-involved-in-outsourcing-bank-reconciliation-to-a-provider",
      "display_title": "What is involved in having bank reconciliation performed by an outside provider?"
    },
    {
      "question_id": "CG-P1B-009",
      "slug": "how-a-small-business-can-manage-and-automate-its-accounts-payable-workflow",
      "display_title": "How should a small business manage and automate its accounts-payable vendor-invoice and document workflow?"
    }
  ],
  "review_class": "consequential",
  "review_class_trigger": "claim_level_review_required",
  "provenance": {
    "author_model": "claude-opus-5-5",
    "reviewer_model": "claude-opus-5-5",
    "review_verdict": "ACCEPT",
    "review_source": "closure",
    "review_verdict_on_sha256": "e2339686ccb240f600e466351652660512f4fadb01ee8196bed1e40aa0ad45ad",
    "editorial_disposition": "ACCEPT",
    "corrections": 1,
    "approved_by": null,
    "approved_at": null,
    "article_sha256": "e2339686ccb240f600e466351652660512f4fadb01ee8196bed1e40aa0ad45ad",
    "source_map_sha256": "335f741ec822d4123c11d0a423ee66090b214797ae7e3d765a360ce94b216c86",
    "transform_sha256": "284d608b5deb00d10ebc4f4fe62c8f8e12689e1f226d4a79e863d77781515a2f"
  },
  "offer": "ask",
  "offer_id": null,
  "sample_target_id": null,
  "datePublished": "2026-09-26T01:29:00Z",
  "reviewed_at": "2026-09-26T01:29:00Z",
  "content_sha": "7ebd24953d5259e2670066d83b1129c28137caee323e9aefd683cd1328f8aef9",
  "release": "2.7.0",
  "slug_provenance": "minted at first publication",
  "question_text": "What is involved in outsourcing accounts-payable automation to an external provider?",
  "jsonld_types": [
    "Article"
  ],
  "related_question_ids": [
    "CG-P1B-FULL-040",
    "CG-P1B-FULL-097",
    "CG-P1B-009",
    "CG-P1B-FULL-111",
    "CG-MCE-136"
  ],
  "aliases": [],
  "alias_provenance": []
}
