{
  "question_id": "CG-P1B-FULL-040",
  "slug": "what-outsourcing-accounts-payable-invoice-matching-involves",
  "display_title": "Who provides outsourced invoice-matching services, and what does having a provider perform AP invoice matching involve?",
  "format": "article-v2",
  "applies_to": {
    "countries": [
      "US"
    ],
    "frameworks": [],
    "tax_year": null,
    "platforms": []
  },
  "general_concept": true,
  "summary": "Three models exist: an accounting firm matching in your system under a login you grant; a processing service matching on its own platform, returning results your staff post; or a software vendor's staff matching in licensed software that posts to your ledger by integration. Each receives invoices, purchase orders and receiving records, compares them within tolerances you set, and returns matched items and exceptions. Approving invoices, releasing payments, changing vendor records and answering for the books stay with you.",
  "body": "## Who performs invoice matching as an outside service?\n\nThree kinds of provider take on this work, and the difference that matters for control is where the matching runs:\n\n| Provider | How it delivers matching | What it needs from you |\n|---|---|---|\n| Accounting or bookkeeping firm | Its staff match inside your accounting system | A named login with a restricted role |\n| Managed processing service | It receives your documents, matches on its own platform and returns results | Document routing and data exports, and a login only if it posts results |\n| Software vendor's staffed service | Its staff run the matching in software you license and connect to your ledger | An integration with your ledger, and document routing |\n\nA firm that already keeps your books may hold broad access. Intuit's help page on inviting accountant users to QuickBooks Online says those users have tools to review your books and make corrections, which is far more than matching needs. The page does not say what those tools exclude, so run matching through a named login whose role passes the test below, not the accountant access. Keep vendor changes and payment release with your own staff, and review the firm's users in the audit log every cycle.\n\nSettle the delivery model first. A provider working in your system needs a role you restrict. A provider working on its own platform holds copies of your records, so you must reconcile its results into your ledger and be able to recover everything at exit.\n\n## What work moves to the provider, and what comes back?\n\nHow to run the matching comparison is a separate topic; the engagement concerns what crosses the boundary. Write each flow into the contract:\n\n- **Inputs.** The provider receives supplier invoices from the channel you route to it, open purchase orders, receiving records, the vendor list without bank details, and your written tolerances and coding rules.\n- **Work.** It captures invoice data, pairs each invoice with its order and receipt, compares them within tolerance, applies your coding rules, and flags duplicates and any invoice announcing new payment details.\n- **Outputs.** It returns a matched set ready for approval, a held list, an exception list giving each item's reason, documents and owner, and a cycle summary reconciling documents received with documents returned.\n\n## Which decisions stay with the business?\n\nHanding over the work does not hand over responsibility for the records. IRS Rev. Proc. 98-25 says that using a third party, such as a service bureau, for custodial or management services over your machine-sensible records does not relieve you of your recordkeeping obligations and responsibilities.\n\nDecide first who releases a matched invoice for payment:\n\n- **The provider prepares and you approve.** The provider marks matches ready, and your approver approves each invoice before payment. This is the stronger control and needs the least provider access.\n- **The provider clears within tolerance.** The provider clears in-tolerance matches and escalates the rest. Your written tolerances then act as your approval, so set them yourself and review a sample of cleared items every cycle.\n\nIn both, your own people release every payment. This checklist places each task of the cycle on one side:\n\n| Task | Who does it |\n|---|---|\n| Receive and capture invoices from the agreed channel | Provider |\n| Pull purchase orders and receiving records | Provider, read-only |\n| Compare documents within the written tolerances | Provider |\n| Apply coding rules and flag items outside them | Provider |\n| Flag duplicates and any new payment instructions | Provider |\n| Set and change tolerances and coding rules | Business |\n| Decide exceptions that need a business judgment | Business, named owner |\n| Re-run and close resolved exceptions | Provider |\n| Approve invoices, or the tolerance rule that clears them | Business |\n| Release payments | Business |\n| Add or change any vendor record, after an independent callback | Business |\n| Grant, review and remove access | Business |\n| Produce the cycle summary and exception log | Provider |\n| Reperform a sample and reconcile the output | Business |\n| Keep the records and produce them on request | Business, with the provider returning copies on request and at exit |\n\n## What must be ready before the first cycle?\n\nA provider executes a process; it cannot invent one. If these are not written down first, the provider will return exceptions nobody can interpret:\n\n- **Tolerances.** Set price and quantity limits, by vendor or category where they differ, and say what happens just outside them.\n- **Coding rules.** Assign the account and class for each recurring purchase type, and name who decides items the rules do not cover.\n- **Vendor master.** Keep one record per vendor. AccountingTools' guide to cleaning the vendor master file says to look for duplicate names that indicate duplicate records and to check key fields, such as taxpayer identification numbers, for missing information.\n- **Document routing.** Fix one inbox or portal for invoices, how orders and receipts reach the provider, and a cut-off for each cycle.\n- **Spend without orders.** Write a rule for invoices with no purchase order or receipt, as described below.\n\n## How should exceptions come back and be resolved?\n\nMatching produces exceptions by design, so the scope must define the loop in order:\n\n1. The provider returns each exception within an agreed time, with its reason, the documents and the owner it is routed to.\n2. The named owner decides: the buyer on price, the receiver on quantity, the payables lead on coding.\n3. The owner records the decision where the provider can see it, and the provider re-runs the match and closes or escalates the item.\n4. Anything open past an agreed age goes to a named manager, and nothing held is paid.\n\nPlan for items nobody touches. Check the exception list's aging every cycle.\n\n## How do you keep the provider away from payments and vendor bank details?\n\nAccess granted for matching could also create or pay a payable, so keep it narrow. The FTC's small-business cybersecurity guidance on vendor security says to limit access \"to a need-to-know basis, and only for the time the vendor needs to do the job.\"\n\nIntuit's help for QuickBooks Online shows how far preset roles reach and where you can narrow them:\n\n- Intuit's user roles page describes the Accounts Payable Manager role as able to \"see and do everything with expenses, vendors, and accounts payable (A/P) reports\".\n- Intuit's page on roles for paying bills says the QuickBooks Bill Pay role Bill clerk \"can add bills, mark bills as paid, and add and edit vendors\", so it fails the test below.\n- Intuit's custom roles page, which covers QuickBooks Online Advanced and Intuit Enterprise Suite, lets you set each area's permissions to levels such as view only, create, edit, delete and approve.\n\nWhatever the platform, the role you assign must allow no adding or editing of vendors, no bill payment, no marking bills paid, no banking and no user management. If your plan offers no role that passes that test, keep the provider out of your ledger: let it work on its own platform from documents and exports, and have your staff post the results. Give each person at the provider a separate login so the audit trail shows who did what.\n\nIntuit's audit log page says a connected third-party app's data and changes appear as System Administration events, so a provider's integration leaves no named person in the log. Before connecting one, get in writing what it can create or change. Accept none that can add or edit vendors or pay bills, review its System Administration events every cycle, and disconnect it the day the engagement ends.\n\nVendor bank details need their own guard:\n\n- **The provider routes and never acts.** Any invoice, letter or email announcing new bank details, a new remit-to address or new contact details comes to you unmatched.\n- **Verify on a number you already held.** The FBI's Internet Crime Complaint Center advises using \"secondary channels and/or two-factor authentication to verify requests for changes in account information\", and the FTC's guidance says to call \"a number you know to be correct, not the number in the email or text\". Take that number from a record that predates the request, and if the vendor's phone or email changed recently, verify that change the same way first, or your callback may reach the fraudster.\n- **Call back on every change request.** If one person both changes vendor details and releases payments, never skip the callback: the provider's flag catches only requests that reach the provider, so every change request, however it arrives, gets the callback before anything is changed.\n\nEach cycle, check under Manage users that every provider login still has the role you assigned. Have an admin filter the audit log by each provider user for vendor edits, bill payments or settings changes, and resolve anything found before the next payment run. Remove access the day the engagement ends and whenever the provider's staff change, and close any document forwarding or shared folders it used. Intuit's Add and manage users page says that after you delete a user, \"you can still view their history in the audit log\".\n\n## What evidence shows the control operated?\n\nThe provider now runs part of your control, so you must be able to show it ran. Keep these for every cycle:\n\n- **Cycle summary.** It shows documents received, matched, held and excepted, reconciled to what you sent.\n- **Exception log.** It records each item's reason, owner, decision and closing date.\n- **Approvals and releases.** Your own people record them in your own system.\n- **Change history.** Intuit's audit log page says the log records edits to vendors and the user who made each change, and that \"Events recorded in the audit log are available for two years\", so export what you must keep longer.\n- **Your own testing.** AS 2601, the PCAOB auditing standard on how a company's auditor considers its use of a service organization, treats a user organization's independent reperformance of selected items and its reconciliation of output reports with source documents as controls an auditor can test. Reperform a sample of cleared matches and tie the provider's output to your invoices each cycle.\n\nFor independent assurance, ask whether the provider has a SOC 1 report, which the AICPA describes as an examination of controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting. AS 2601 distinguishes a report on whether controls had been placed in operation as of a specific date from one that also tests whether they operated effectively during a specified period. Whatever the provider's SOC 1 report calls itself, ask for one that tests operating effectiveness, and check that its period covers the months the provider matched for you. AS 2601 also says the service auditor's report should be modified where controls at user organizations are needed to achieve the stated control objectives, and that those controls should be listed in the description of controls; run each one it assigns to you. If the provider has no such report, ask for an agreed-upon procedures report describing relevant tests of controls, which AS 2601 also names as evidence; failing both, rely on your own reperformance.\n\n## Who holds the records during the engagement and after it ends?\n\nIRS Rev. Proc. 98-25 sets rules for machine-sensible records: data in electronic format intended for use by a computer, kept in an accounting or financial system. It excludes paper records converted to an electronic storage medium, such as scanned invoices, which it refers to Rev. Proc. 97-22. It applies to a business with assets of $10 million or more at the end of its tax year, and to a smaller one if any of several listed conditions exists, the first being that all or part of the information section 6001 requires is not in its hardcopy books and records but is available in machine-sensible records. Under it, records must be kept so long as their contents may become material to administering the tax laws: at least until the period of limitation for assessment, including extensions, expires for each tax year; some, such as fixed-asset records, should be kept longer. Records must also be made available to the IRS on request and capable of being processed, and the system must not be subject to any agreement, such as a contract or license, that would limit or restrict the IRS's access to it, wherever it is maintained.\n\nThose rules, and your need to produce the scanned documents behind each match, become engagement terms:\n\n- The matched sets, images, exception logs and audit trails are your records, including the provider's copies.\n- You can export all of them in a usable format at any time, not only at exit.\n- No clause limits access by you or by the IRS, and the provider produces records on request.\n- On exit, the provider returns everything within an agreed period and confirms in writing what it deleted and what it kept.\n- Your retention period, at least that long, governs, not the provider's.\n\n## How do you write the scope and measure performance?\n\nA scope statement a provider can be held to covers these parts:\n\n- **Inputs.** It lists document types, channels, cut-off times and expected volume per cycle.\n- **Rules.** It attaches your tolerances, coding rules and treatment of spend without orders as documents you own.\n- **Outputs.** It defines the matched set, held list, exception list and cycle summary, with format and delivery time.\n- **Exception routing.** It names owners by exception type, response times on both sides and the escalation age.\n- **Measures.** It sets turnaround from invoice receipt to result, exception rate by reason, the error rate in your reperformed sample and the backlog at cycle end, reported every cycle.\n- **Access and records.** It states the role granted, what the role excludes, and the ownership, export and exit terms.\n\nTie remedies to the measures, and treat a rising error rate in your sample as a reason to narrow what the provider may clear.\n\n## What changes if some spend has no purchase order, or a bookkeeper already keeps your payables?\n\nA provider can only match documents that exist. AccountingTools' three-way matching article notes that a business \"might elect to only conduct a two-way match\" against the purchase order, but warns that this does not compare receiving documentation, so there is a risk of paying \"an invoice for an incorrectly-billed quantity\". It also notes that matching can be made more efficient \"by excluding small-dollar and recurring invoices from the matching requirement\". So the scope must say what the provider does with spend that has no purchase order or no receiving record, such as checking it against a contract price, routing it for approval or only coding it, and which person in your business decides each item. Route any invoice with no receiving record to a named person in your business to confirm what was received before approval.\n\nIf an outside bookkeeper already keeps your payables, a second provider in the same ledger splits the control evidence and blurs who fixes what. Either add matching to the bookkeeper's engagement under its own written scope, through a login whose role passes the test above, not the firm's accountant access, or write both scopes so they do not overlap: one party matches, one named party resolves exceptions, one keeps the exception log, and neither holds rights it does not need.\n\n## When is delegating the matching worth it?\n\nDelegation is worth pursuing when all of these hold:\n\n- Invoice volume is steady and more than your staff can match on time.\n- Most spend carries purchase orders and receiving records, so matches are mechanical.\n- Tolerances, coding rules and document routing are already written.\n- Someone in the business has time to resolve exceptions, approve, release payments and test samples.\n\nThese conditions argue against it:\n\n- Most spend has no order or receipt, so there is little to match.\n- The process is undocumented, so the provider would be standardizing a process nobody specified.\n- Nobody in the business can own exceptions.\n- Your platform cannot keep the provider away from vendor edits and payments, and the provider cannot work from its own platform.\n\nMoving the whole payables function to a provider, rather than only matching, is a larger decision with its own terms.",
  "sources": [
    {
      "id": "REF::1",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/account-management/managing-accountant-users-quickbooks-online/L2AcdYvHw_US_en_US",
      "title": "Invite accountant users",
      "publisher": "Intuit Inc.",
      "published": "updated 8/28/2026",
      "retrieved_at": "2026-09-25T16:11:26+00:00",
      "sha256": "3366078265a6482734450a1e83240fd872f3d29a80a2ee0e0b1c1dcbf8fdbb12",
      "supports": [
        "C1"
      ]
    },
    {
      "id": "REF::2",
      "url": "https://www.accountingtools.com/articles/what-is-three-way-matching.html",
      "title": "Three-way matching definition",
      "publisher": "AccountingTools, Inc.",
      "published": "last updated May 14, 2026",
      "retrieved_at": "2026-09-25T16:11:49+00:00",
      "sha256": "f2704b3f9412907c9e2f7ce741d83da236f795b03abc4fd1933938128a591cc0",
      "supports": [
        "C32",
        "C33",
        "C34"
      ]
    },
    {
      "id": "REF::3",
      "url": "https://www.irs.gov/pub/irs-irbs/irb98-11.pdf",
      "title": "Internal Revenue Bulletin No. 1998-11 (Rev. Proc. 98-25, Books and records; automatic data processing system)",
      "publisher": "Internal Revenue Service",
      "published": "March 16, 1998",
      "retrieved_at": "2026-09-25T16:11:50+00:00",
      "sha256": "c212988fcb3df1bce2b9c5ec53cc2ba51ea55f85a8bd8db07c03f8ae89cd8381",
      "supports": [
        "C4",
        "C26",
        "C27",
        "C28",
        "C29",
        "C30",
        "C31",
        "C45",
        "C46",
        "C47",
        "C48",
        "C49",
        "C50",
        "C51"
      ]
    },
    {
      "id": "REF::4",
      "url": "https://www.accountingtools.com/articles/clean-the-vendor-master-file",
      "title": "How to clean the vendor master file",
      "publisher": "AccountingTools, Inc.",
      "published": "last updated July 18, 2026",
      "retrieved_at": "2026-09-25T16:11:51+00:00",
      "sha256": "b92812316c42ac8fee51e7023d32b697d1b8afa1ae67d6180e6bf698fcd1bba6",
      "supports": [
        "C5",
        "C6"
      ]
    },
    {
      "id": "REF::5",
      "url": "https://www.ftc.gov/business-guidance/small-businesses/cybersecurity",
      "title": "Cybersecurity for Small Business",
      "publisher": "Federal Trade Commission",
      "published": "September 2025",
      "retrieved_at": "2026-09-25T16:14:16+00:00",
      "sha256": "0eaa74d868a6fd9d52dc3c53c66960a8296d7a8dc0520640d808845421a4c99c",
      "supports": [
        "C9",
        "C15"
      ]
    },
    {
      "id": "REF::6",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/user-roles-access-rights-quickbooks-online/L66POfRrI_US_en_US",
      "title": "User roles and access rights",
      "publisher": "Intuit Inc.",
      "published": "updated 9/8/2026",
      "retrieved_at": "2026-09-25T16:16:17+00:00",
      "sha256": "3d0bd1c98504682f21825dca058d85dbcbf05c6c4905c9e0d9edb8dcf98619b5",
      "supports": [
        "C10"
      ]
    },
    {
      "id": "REF::7",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/manage-workflows/set-roles-permissions-paying-bills-quickbooks-bill/L0Z0K2aXV_US_en_US",
      "title": "Set up roles and permissions for paying bills",
      "publisher": "Intuit Inc.",
      "published": "updated 8/3/2026",
      "retrieved_at": "2026-09-25T16:29:21+00:00",
      "sha256": "703fdeacf3eec8177279761fff7c64ca27e848761a627b7e6d0b4a90ca8df60c",
      "supports": [
        "C11",
        "C41"
      ]
    },
    {
      "id": "REF::8",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US",
      "title": "Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite",
      "publisher": "Intuit Inc.",
      "published": "updated 8/3/2026",
      "retrieved_at": "2026-09-25T16:21:41+00:00",
      "sha256": "5f1e506f5706c4dde2a2d9426f240d1ef7da4e5ead550d5b256af0c122856133",
      "supports": [
        "C12",
        "C13"
      ]
    },
    {
      "id": "REF::9",
      "url": "https://www.ic3.gov/PSA/2024/PSA240911",
      "title": "Business Email Compromise: The $55 Billion Scam (Alert I-091124-PSA)",
      "publisher": "Federal Bureau of Investigation, Internet Crime Complaint Center",
      "published": "September 11, 2024",
      "retrieved_at": "2026-09-25T16:22:04+00:00",
      "sha256": "5bc816f351942763c3f80064ba3194c68ee6a96667df18898dee99de246fe37b",
      "supports": [
        "C14"
      ]
    },
    {
      "id": "REF::10",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/manage-users/add-manage-users-quickbooks-online/L1welhiJZ_US_en_US",
      "title": "Add and manage users",
      "publisher": "Intuit Inc.",
      "published": "updated 8/5/2026",
      "retrieved_at": "2026-09-25T16:24:06+00:00",
      "sha256": "53a1058f0064bac6b106fdcc2fb07e7269a46f1a1d28171f07f7c42a9037e95e",
      "supports": [
        "C16",
        "C35"
      ]
    },
    {
      "id": "REF::11",
      "url": "https://quickbooks.intuit.com/learn-support/en-us/help-article/audit-log/use-audit-log-quickbooks-online/L2WoVnW6I_US_en_US",
      "title": "Use the audit log in QuickBooks Online",
      "publisher": "Intuit Inc.",
      "published": "updated 8/4/2026",
      "retrieved_at": "2026-09-25T16:26:29+00:00",
      "sha256": "f8479245de6d30ceb3f689f710d9c80b39dd4efab4b63a38bc3658032c72f03b",
      "supports": [
        "C17",
        "C18",
        "C19",
        "C36",
        "C37",
        "C38",
        "C39",
        "C40"
      ]
    },
    {
      "id": "REF::12",
      "url": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS2601",
      "title": "AS 2601: Consideration of an Entity's Use of a Service Organization",
      "publisher": "Public Company Accounting Oversight Board",
      "published": "current standard as published on the PCAOB website",
      "retrieved_at": "2026-09-25T16:26:51+00:00",
      "sha256": "9116f7986c2809df0aeecb57e84076a374c85c48c687122335a4620914248ac1",
      "supports": [
        "C20",
        "C21",
        "C23",
        "C24",
        "C25",
        "C42",
        "C43",
        "C44"
      ]
    },
    {
      "id": "REF::13",
      "url": "https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-1",
      "title": "SOC 1® - SOC for Service Organizations: ICFR",
      "publisher": "AICPA & CIMA",
      "published": "undated",
      "retrieved_at": "2026-09-25T16:26:51+00:00",
      "sha256": "49313e5dba30e1d1d553143b246ff69afbf91ef50fe7cbb6d277e3ae00f1a261",
      "supports": [
        "C22"
      ]
    }
  ],
  "related": [
    {
      "question_id": "CG-P1B-001",
      "slug": "what-is-two-way-and-three-way-invoice-matching-in-accounts-payable",
      "display_title": "What is 2-way and 3-way invoice matching in accounts payable, and how do I run it across POs, receiving documents, and vendor invoices?"
    },
    {
      "question_id": "CG-P1B-009",
      "slug": "how-a-small-business-can-manage-and-automate-its-accounts-payable-workflow",
      "display_title": "How should a small business manage and automate its accounts-payable vendor-invoice and document workflow?"
    },
    {
      "question_id": "CG-P1B-FULL-083",
      "slug": "what-is-involved-in-outsourcing-accounts-payable-automation",
      "display_title": "What is involved in outsourcing accounts-payable automation to an external provider?"
    },
    {
      "question_id": "CG-P1B-FULL-097",
      "slug": "what-is-involved-in-outsourcing-bank-reconciliation-to-a-provider",
      "display_title": "What is involved in having bank reconciliation performed by an outside provider?"
    }
  ],
  "review_class": "consequential",
  "review_class_trigger": "criterion_4: the answer directs a payment, a filing or a legal or tax obligation (a recorded judgment about what the article tells the reader to do)",
  "provenance": {
    "author_model": "claude-opus-5-5",
    "reviewer_model": "claude-opus-5-5",
    "review_verdict": "ACCEPT",
    "review_source": "closure",
    "review_verdict_on_sha256": "aa23ccf99e0e0b47b4dce8f71e44dcc16fea30223137dcee84b8ee640fa674cf",
    "editorial_disposition": "ACCEPT",
    "corrections": 1,
    "approved_by": null,
    "approved_at": null,
    "article_sha256": "aa23ccf99e0e0b47b4dce8f71e44dcc16fea30223137dcee84b8ee640fa674cf",
    "source_map_sha256": "9dc8191051529240e472298a17fb35a5143f103b234d5c9318795b2964820f75",
    "transform_sha256": "164b34c62c66505576adab520a57a39ec883059819094d03e020d76c5f13d353"
  },
  "offer": "ask",
  "offer_id": null,
  "sample_target_id": null,
  "datePublished": "2026-09-26T01:29:00Z",
  "reviewed_at": "2026-09-26T01:29:00Z",
  "content_sha": "77be47388c09f445b7b2174966b35bda7892d5df0ab8abae99ca7ffd2cb1f0ba",
  "release": "2.7.0",
  "slug_provenance": "minted at first publication",
  "question_text": "Who provides outsourced invoice-matching services, and what does having a provider perform AP invoice matching involve?",
  "jsonld_types": [
    "Article"
  ],
  "related_question_ids": [
    "CG-P1B-001",
    "CG-P1B-009",
    "CG-P1B-FULL-083",
    "CG-P1B-FULL-097",
    "CG-MCE-136"
  ],
  "aliases": [],
  "alias_provenance": []
}
