Procurement·Sep 12, 2026·1 min read

Three Way Match Explained for Accurate AP Control

Three way match is the control that keeps a wrong bill from slipping through. It compares an invoice, a PO, and a delivery note before payment goes out.

Procurement

You're standing in AP with three things in front of you, an invoice, a PO, and a delivery note, and one question hanging over all of it, did we get what we're about to pay for? That's the everyday pressure point behind three way match. It's not a fancy accounting phrase, it's the control that keeps a wrong bill from slipping through just because it arrived first or looked familiar.

When the process is weak, the damage usually feels small at first. A shipment shows up short, a price changes, someone keys in the wrong quantity, and payment still goes out because the invoice looks routine. Later, finance has to unwind the mistake, procurement has to answer questions, and audit wants to know why the records didn't line up. If you've ever had to chase a mismatch after the money left the building, you already know why this control matters.

This guide is for AP, procurement, and finance people who deal with volume and don't have time for vague theory. By the end, you should be able to explain three way match in plain language, set sensible tolerances, route exceptions without freezing the queue, and recognize when automation helps and when the problem started earlier in the process. For a broader view of where invoice control breaks down, the procure-to-pay flow breakdown and AI fixes overview is a useful companion.

Table of Contents

Introduction Why Paying the Wrong Invoice Hurts

The easiest way to understand AP pain is to look at a normal day that goes slightly wrong. A buyer places an order, the supplier ships part of it, and the invoice arrives for the full amount. Or the goods arrive, but the invoice uses a different unit price than the PO. If someone approves payment before those differences are checked, the company can overpay, create a dispute, or book a cost that doesn't match reality.

That's why finance teams care about the match itself, not just the payment date. Three way match exists to stop money from moving until the records tell the same story. Microsoft Dynamics 365 describes the control as a policy where invoice quantities must match received quantities on the product receipt, and the receipt and PO are compared line by line for items that require matching, which makes the process a core anti-error and anti-fraud control. The basic documents are always the same, purchase order, goods receipt, and invoice. Microsoft Dynamics 365 three-way matching policies

That sounds simple until volume rises. Larger teams can't afford to manually inspect every line forever, and even small mismatch rates add up when invoice counts are high. That's why three way match becomes less about policing and more about preventing small leaks from turning into a steady drain.

Practical rule: if the invoice can't be tied to what was ordered and what was received, it shouldn't move to payment yet.

For a new finance hire, the key shift is this, AP isn't just paying bills, it's checking whether the bill belongs to a real, approved transaction. Once that clicks, the rest of the process becomes much easier to follow.

What Three Way Match Really Means

Think of a restaurant order. You tell the server what you want, the kitchen prepares it, and the bill arrives at the end. If the bill charges you for a dish you never ordered, or for two portions when you only got one, you'd expect the staff to fix it before you pay. Three way match works the same way in AP, only the three parts are a purchase order, a receipt, and an invoice.

The PO is the promise of what the company agreed to buy. The goods receipt is the proof that something arrived. The invoice is the supplier asking to be paid. Three way match checks whether those three records align, and it only releases payment when they do, within whatever tolerance the business has set. That line-by-line comparison is what turns a paperwork habit into a real control.

A diagram illustrating the three way match process comparing a restaurant order to purchase order, delivery, and invoice.

From two-way to three-way

A lot of new hires first hear about two-way matching, then assume three-way match is just “one more document.” That's true, but incomplete. The extra document matters because it gives AP an independent check that the order was received, not just billed.

A simple way to explain it to a colleague is this, the PO says what should happen, the receipt says what did happen, and the invoice says what the supplier wants paid. If one of those stories doesn't line up, the payment should pause. That's why the control is so useful in larger organizations with heavy invoice volume, because it gives AP a consistent rule instead of relying on memory or guesswork.

Payment should follow evidence, not assumption.

The reason this feels intuitive once you see it is that the control is built on a question every buyer already asks in daily life, “Did we get what we paid for?” Three way match just turns that common-sense question into a repeatable process.

The Three Documents and What Must Align

The PO, receipt, and invoice each have a different job, and mixing them up is where people get confused. The purchase order is authorization. The goods receipt is proof that delivery happened. The invoice is the request for payment. Three way match works only when each document supports the others instead of contradicting them.

What each record proves

The PO says the company approved the spend in advance. The goods receipt says someone on the receiving side confirmed what arrived. The invoice says the vendor is asking for money based on that transaction. When AP compares all three, it's looking for agreement on the basic fields that matter most, item identity, quantity, unit price, and total amount. If those don't align, the invoice needs review before payment moves forward.

The receipt deserves special attention because it's the independent assertion in the chain. NetSuite describes three way match as strongest when the receiving record is captured at delivery, because it proves what was received and reduces the risk of paying for unordered, undelivered, or inflated line items. That's the point where the business gets evidence from its own operation, not just from the supplier. NetSuite three-way matching overview

The receipt is the independent proof point. If receiving is weak, the whole control gets weaker.

For teams building cleaner procurement records, it helps to keep the PO disciplined upstream. A practical purchase order audit can show where the order data starts drifting before AP ever sees the invoice. And if your team still treats POs as paperwork instead of control records, a purchase order management guide can help reset that habit.

Why line-by-line matching matters

AP doesn't just compare totals and hope for the best. A total can look right even when one line is wrong, especially on multi-line orders. Matching at the line level makes sure the right item, the right quantity, and the right price all agree.

That line-by-line view is also why the receiving step matters so much. A supplier can bill a line item that was never delivered or overstate the quantity on one line while the overall invoice still looks believable. Three way match catches those problems before payment leaves the company.

Tolerances and Exception Handling That Keep Payments Moving

The control gets practical only when you decide what counts as close enough. If every tiny difference stops payment, AP ends up buried in reviews. If the rules are too loose, the match stops protecting cash. The best setup uses explicit variance tolerances so small, acceptable differences can flow through while real issues get held.

How a hold, approve, or escalate decision works

A clean way to think about it is a simple filter. First, the invoice is checked against the PO and receipt. If the difference sits inside tolerance, it can be auto-approved. If it crosses the threshold, it gets flagged for review. If the issue points to a bigger policy or supplier problem, it gets escalated.

KioLo describes this as a threshold-based process where line-item quantity or price differences beyond the configured limit hold the invoice for review rather than pay it automatically, which turns three way match into a risk filter instead of a simple document check. That same approach helps prevent duplicate payments, unauthorized spend, and mismatch leakage while still letting low-risk invoices move quickly. Three-way match checklist and tolerance routing

Decision

Typical signal

AP action

Approve

Match is within tolerance

Release payment

Hold

Quantity or price variance is outside tolerance

Route for review

Escalate

Repeated issue, policy breach, or unclear ownership

Send to buyer, receiving, or manager

Common exception causes

Most exceptions aren't dramatic. A supplier changes a price after the PO was issued. A warehouse receives a short shipment. Someone uses a different unit of measure on the invoice than the one on the PO. None of those situations means the invoice is fake, but they all need human review before payment.

The key is to route each exception to the right owner. Price issues usually belong with procurement. Quantity issues often belong with receiving. Missing or unclear references belong with the requester or vendor. If everything lands in one AP inbox, the queue becomes a bottleneck instead of a control.

Practical rule: exceptions should move to the person who can fix the cause, not just the person who sees the error first.

A good exception process keeps payments moving because it separates real risk from harmless variation. That's the heart of making three way match usable at scale.

When There Is No Box to Receive Services and Milestones

Goods are easy to picture, crates arrive, someone signs, AP matches the paperwork. Services are messier because there's no box on a dock and no obvious receiving event. That's where many standard explanations of three way match fall short. The control still works, but the “receipt” has to be adapted to proof of service, milestone sign-off, or contractor billing references.

A professional construction engineer in safety gear reviewing a milestone report on a clipboard at a site.

Services need an acceptance event

A consulting invoice for 80 hours shouldn't be treated like a pallet of parts. The control needs an intake record, an approval of the hours or deliverable, and a bill tied to that evidence. PeopleOps Solutions notes that services, milestones, and contractor billing need proof-of-service delivery, milestone sign-off, and clear billing references because there isn't a physical receiving event to anchor the match. Three-way match for contractors and services

That means the business has to define what counts as received. It could be a signed service entry sheet, a project manager's acceptance note, or a milestone form that shows the deliverable was completed. Without that record, AP has no solid basis for saying the invoice belongs in the payment queue.

Keep the rules specific to the service type

A time-and-materials contract needs different checks from a fixed-deliverable project. For hours-based work, the question is whether the hours were approved and within scope. For milestone billing, the question is whether the milestone was accepted by the right owner. For contractors, the invoice should reference the engagement, the period, and the approval trail.

The main mistake is trying to force goods logic onto services. That creates false exceptions and delays payment for work that was already accepted. A better approach is to define the intake process before the invoice arrives, then set tolerance rules around the way that service is delivered.

When those rules are clear, service matching stops feeling like an exception and starts feeling like a deliberate control adapted to a different kind of spend.

Automation Audit Readiness and Upstream Data Quality

Automation helps most when the source data is already decent. That's the part many teams miss. A matching engine can compare records quickly, but it can't fix a bad PO description, missing receiving data, or a scope that was never captured properly in the first place. Recent procurement guidance argues that many three way match exceptions start before the PO exists, when request data, rates, scope, and terms are first entered, so the control stack begins upstream. Three-way match exceptions and upstream intake quality

What automation improves and what it can't

Automation is valuable because it raises the ceiling on throughput and consistency. Peakflo reports that automated three way matching can prevent 90% to 95% of invoice overpayments, can reach 95%+ match rates, and can cut AP processing costs by 40% to 60%. The same source says manual matching error rates sit around 1% to 3%, while automated performance can reduce errors to under 0.1%. Peakflo three-way matching benchmarks

Measured Impact of Automated Three Way Matching

Manual Process

Automated Matching

Overpayment prevention

Lower, error-prone

90% to 95% prevention

Match rate

Lower and inconsistent

95%+ match rates

AP processing cost

Higher

40% to 60% lower

Error rate

1% to 3%

Under 0.1%

Those numbers explain the business case, but they don't tell the whole story. A clean automation stack still needs traceable PO, receipt, and invoice links, tolerance logs, and exception history so finance can defend the payment decision later. That's where audit readiness starts, not in the software itself, but in the quality of the record it preserves.

If your team is tightening controls, a compliance audit guide can help frame the evidence trail auditors usually expect to see.

Choose technology after the process is clear

Tools help most when they support a process that already makes sense. Procright is one option that can compare an invoice against the original purchase order and goods receipt, then flag mismatches for review as part of its procurement workflow. That matters because AP automation should reduce manual checking, not hide weak intake discipline under a faster interface. For teams evaluating which procurement tasks are ready for AI, the automation readiness guide is a useful reference point.

The lesson is simple. Automation improves speed, but upstream data quality decides how much of that speed turns into clean approvals instead of faster exceptions.

Putting Three Way Match Into Practice

A good three way match policy feels boring in the best way. POs are clean, receipts are logged when delivery happens, invoices carry the right references, and only real problems reach AP. That's the goal, not perfect paperwork, but a payment process that tells the truth about what was ordered, received, and billed.

A practical rollout usually starts with six habits:

  • Lock PO discipline. Don't let spend bypass the order process just because a vendor is familiar.

  • Capture the receipt at delivery. If the receiving step is late, the match loses its strongest proof point.

  • Set tolerances by risk. Tight controls for sensitive categories, more flexibility where small variances are normal.

  • Define service acceptance clearly. For non-goods spend, the “receipt” needs to be a real approval event.

  • Route exceptions by cause. Price, quantity, missing references, and scope issues shouldn't all sit in one queue.

  • Keep evidence together. Store the PO, receipt, invoice, tolerance decision, and exception history in a way audit can follow.

Supercenter's practical roadmap for invoice teams is helpful if you want a broader view of invoice workflow design, but the basic judgment still stays the same, if there's no valid basis for payment, don't push the invoice through just to clear the inbox.

Use two-way match when the spend is service-based or when a receiving record doesn't add value. Use three way match when physical goods are involved and delivery confirmation matters. Keep the policy category-based so AP isn't forced to make the same decision by hand on every invoice.

If you want a clearer AP control setup, Procright can help you build the procurement side of the record before invoices even reach finance, with evidence-backed sourcing and traceable decision support. Visit Procright to see how it fits into a cleaner, more defensible control process for three way match and the procurement work that feeds it.

Try it on a real buy

Bring one category. Watch where the flags land.

Book 20 minutes
Book 20 minutes