Skip to main content

Run an AP Self-Audit Your Investors and Auditors Can Verify

By Gruv Editorial Team
Contributor
Updated on
•
18 min read
Diagram showing Define the audit-ready outcome and scope.

Quick Answer

Reconcile period-specific AP and GL balances, then trace both booked items and independent source records to test completeness, accuracy, validity and cutoff. Paid samples need settlement evidence; unpaid obligations need receipt or service support and liability entries. Document findings, potential exposure, owners and remediation, then retest affected controls before sharing the packet.

What Auditors and Investors Need to See in an AP Self-Audit#

Before you start#

Step 1. Set the bar higher than a clean dashboard. The goal is not to make AP look organized. It is to run a self-audit that leaves you with an evidence set you can hand to investor due diligence and an external auditor without scrambling to backfill support. Financial due diligence helps investors judge financial integrity, and auditors can only conclude on what they can support with sufficient appropriate audit evidence. If your review ends with "the numbers seem right," you are not done.

Accounts Payable (AP) is a short-term liability, often due within 30 to 90 days, but timing pressure is only part of the risk. Risk grows when payment activity scales faster than the evidence around it. A report can show settled payouts and balanced totals while still hiding missing source support, late reconciliations, or period cutoff errors that matter the moment someone asks for proof.

Step 2. Test the places that fail quietly. Trace the source obligation, approval, journal and reported balance for every selected item. Paid items also need payment and settlement references; unpaid items need support for the liability without a settlement artifact. Investigate missing links to distinguish accounting errors, incomplete records and failed controls.

Reconcile often enough to identify errors before close; a monthly control may suit lower-volume activity, while daily payment exceptions can need faster review. For cutoff, use the service or goods receipt evidence and terms of the obligation rather than relying on the posting or payment date alone.

Step 3. Keep the scope on platform AP controls that move money and numbers. This guide is for operators managing AP controls tied to ledgers, settlements, payout execution, and reporting at scale. It is not a full company audit manual. The focus is the chain that starts with an obligation to pay and ends in posted balances and financial reporting, especially where asynchronous events, status changes, or manual adjustments can break continuity.

By the end, you should have three things: a repeatable cycle for self-testing, explicit checkpoints for pass or escalation, and a closeout checklist you can drop into period end. The working rule is straightforward. If any handoff in that chain cannot be proven end to end, do not call the area audit-ready. Rebuild the evidence pack first, then test again.

You might also find this useful: Internal Controls for Accounts Payable on Platforms: How to Prevent Fraud and Ensure Accurate Disbursements.

Define the audit-ready outcome and scope#

Before you start sampling, define what "ready" means in a way another reviewer can verify from the file alone.

Control objectiveWhat it asks
CompletenessWhether all liabilities that should be recorded are recorded
AccuracyWhether amounts, dates, and account coding are right
ValidityWhether the obligation is real and properly approved
Cut-offWhether transactions are recorded in the correct period
DisclosureWhether reporting is supportable for investors and other capital providers

Step 1. Define review readiness in evidence terms. For the period, prepare an AP subledger-to-GL bridge, trace selected transactions and test for obligations missing from both records. Resolve or explain differences with owners and evidence. A tie-out proves two records agree; it does not establish that either contains every liability or replace an external auditor's conclusions.

Keep one period-specific tie-out file that shows the General Ledger balance, the AP subledger balance, every reconciling item, and the linked source support for each item. If you cannot hand that file to Finance leadership or an external auditor without extra explanation, the area is not audit-ready yet.

Step 2. Draw the system boundary before you test. Decide early which records are authoritative across the AP subledger, payment operations, settlement data, and reporting outputs. In practice, different systems may serve as the authoritative record for the underlying obligation, the payment activity, and the posted accounting result. Write that down before sampling, or you will end up comparing records that were never meant to agree line for line.

A common failure mode is boundary drift. Teams pull screenshots from different tools, but no single evidence chain proves the transaction end to end. For each handoff, name the source of truth and where the retained evidence lives.

Step 3. Set control objectives inside the Internal Control System. Use table-stakes criteria: completeness, accuracy, validity, cut-off, and disclosure. Completeness asks whether all liabilities that should be recorded are recorded. Accuracy asks whether amounts, dates, and account coding are right. Validity asks whether the obligation is real and properly approved. Cut-off asks whether transactions are recorded in the correct period. Disclosure asks whether reporting is supportable for investors and other capital providers. Do not stop at transaction checks alone. Weak approvals, master data, or journal logic can still break the result.

Related: Finance Automation and Accounts Payable Growth: How Platforms Scale AP Without Scaling Headcount.

Prepare prerequisites and ownership before testing starts#

Before you test a single transaction, assign owners and freeze the evidence boundary. If nobody clearly owns a control, an Exception Queue, or the documents behind your Financial Statements, the review will be harder to defend in a self-review, investor diligence, or an external auditor request.

PrerequisiteDetails
Owner matrixList the control, primary owner, backup owner, related Exception Queue, and escalation path
Artifact packGather chart of accounts mapping, AP policy documents, prior remediation logs, settlement report exports for the period under review, and representative payout batch files
Period and change windowAnchor scope to the most recent fiscal year-end or exact period under review and use separate evidence sets if changes are active
Evidence hygieneRequire versioned files, timestamped exports, restricted access, and one retained final copy for each item

Step 1. Build a named owner matrix with authority#

Build a named owner matrix with authority, not just awareness. Management is responsible for establishing and maintaining internal control over financial reporting, so your matrix should show who executes each control, who reviews it, and who can approve fixes when something breaks. Cover Finance, Ops, and Product explicitly, because gaps often show up at the handoff between teams rather than inside one function.

At minimum, list the control, the primary owner, backup owner, related Exception Queue, and escalation path. Use a real exception type to test the matrix, such as a failed payout posting. If the matrix does not tell you who investigates it, who can correct the logic or data, and who signs off that it is closed, ownership is still fuzzy.

Step 2. Assemble the prerequisite artifact pack before sampling#

Assemble the prerequisite artifact pack before sampling. You are trying to support balances, activity, and disclosures presented in the Financial Statements, so gather the records that explain how amounts move and how prior issues were handled. A practical starter pack might include chart of accounts mapping, AP policy documents, prior remediation logs, settlement report exports for the period under review, and representative payout batch files.

Do not wait until testing to discover that one export is generated differently each week or that a policy changed mid-period without version history. The failure mode here is evidence drift. You pull records later, the fields no longer match, and you cannot prove what existed at the time of posting. Keep a dated index of every artifact you plan to use, with file owner and storage location.

Step 3. Lock the accounting period and define the change window#

Lock the accounting period and define the change window. If you are testing year-end readiness, anchor the scope to the most recent fiscal year-end or the exact period covered by the balances under review. Then decide whether core posting logic, reconciliation rules, or payout configuration changes are happening during that same window.

If posting logic or vendor records changed during the period, mark cutover dates and split pre-change and post-change populations. Retain the configuration versions and approval records. Freeze nonessential changes during evidence capture where practical, while using controlled approvals for necessary operations.

Step 4. Set evidence hygiene rules.

Set evidence hygiene rules before the first export leaves the source system. Require versioned files, timestamped exports, and restricted access for any artifact that ties directly to Financial Statements. Name one retained final copy for each item, and keep earlier drafts only when they explain a revision.

Close the evidence pack on a defined internal completion date and retain revision history. PCAOB AS 1215 governs documentation for PCAOB auditor engagements, with phased effective dates for amendments; it is not a universal company self-review deadline. Borrow its discipline of documenting procedures, findings, preparer and reviewer, without presenting an internal packet as an audit opinion.

If you want a deeper dive, read SOC 2 Type II Certification for Payment Platforms: What Auditors Look For.

Map control points from transaction to ledger posting#

Map recognition of the obligation and settlement separately. Select a recorded invoice and an independently identified source item, then follow each through the accounting records. Investigate a missing link to determine whether the control failed, documentation is incomplete or a different identifier links the same transaction.

Step 1. Trace the real order of operations, including delayed status changes#

Trace liability recognition before payment settlement. Record when goods or services create the obligation, when an invoice or accrual enters AP, and how it posts to the GL. Separately map approval, payment release, provider status, bank settlement and clearing of the liability. Receipt of a provider callback must not be the only trigger for recognizing an expense already incurred.

Do not map only the happy path. Payment and settlement updates can happen asynchronously, outside the immediate payment flow, so your diagram needs separate lines for the initial action and the later event that changes status. That matters because stale status data can be processed after the business event has already moved on, and settlement timing can drift by country and payment method. A two business day interval may be normal in one case and a red flag in another.

Use one paid invoice as a trace test and write down every identifier that should survive each handoff. At minimum, you want a request identifier, the provider reference, the journal entry identifier, and the reconciliation output or match result. If any one of those disappears between teams or tools, your audit trail is broken even if the ending balance looks right.

Step 2. Build a control matrix with owner, evidence, and re-test method#

Build a control matrix that names the owner, evidence, and re-test method. Keep it in a documented procedure or policy set, not just a shared sheet living outside controlled documentation. The point is to show what each control is meant to prevent or detect, who owns it, what evidence proves it ran, what failure looks like, and how you will confirm the fix.

Control objectiveSystem ownerEvidence artifactCommon failure modeRe-test method
Approved invoices only move to payment releaseFinance OpsInvoice approval log, payment release reportUnapproved invoice released after manual overrideSelect a sample of released payments and confirm matched approval evidence
Each provider event is processed onceProduct or EngineeringEvent log with processed event IDs, request ID recordDuplicate event delivery causes duplicate posting or duplicate status changeRe-send or inspect a known duplicate event and confirm no second posting occurred
Liability recognition and settlement clearing use the correct dates and accountsFinance SystemsReceipt/service evidence, AP/accrual and clearing journals, bank recordsExpense recognized only when payment settlesTrace obligation date and later settlement entries separately
Exceptions are investigated and closed before close signoffFinance OpsException Queue export, owner notes, closure proofAged unresolved item remains open with no dispositionRe-open the sample queue, verify resolution evidence, and confirm related posting outcome

A good matrix is specific enough that another operator could re-run the test without asking what file to pull.

Step 3. Verify traceability at every handoff and flag breakpoints#

Verify end-to-end traceability at every handoff, then flag breakpoints fast. In platform environments, common breakpoints include duplicate webhook-like events, stale statuses from snapshot data, settlement timing drift, and Exception Queue items that never reach a real conclusion. You are not trying to prove that every event arrives in neat order. You are proving that your controls can still prevent or detect misstatements on a timely basis when timing is messy.

For a paid sample, link invoice, approval, payment request, provider reference, bank movement, journal entries and reconciliation. For an unpaid invoice or accrual, retain the obligation and posting support; no settlement report should exist yet. Identify the missing link and its cause rather than forcing every sample into a paid-transaction template.

An unresolved item attached to a posted balance needs an owner, exposure estimate, disposition and due date. Determine whether it indicates an error, missing evidence or a control-design or operating deficiency. AS 2201 provides a useful distinction for PCAOB integrated audits: severity depends on potential misstatement and the likelihood of failure, not simply the existence of an open queue item.

For a step-by-step walkthrough, see Accounts Payable Outsourcing for Platforms When and How to Hand Off Your Payables to a Third Party.

Execute core AP self-audit tests in a fixed sequence#

Once the posting path is mapped, keep the test order fixed so a failure tells you where to look next. Use completeness, accuracy, validity, then cutoff testing. That order is a practical operating choice, not a universal rule from one standard, but it keeps re-test work clean.

TestFocusMain evidence
CompletenessAll transactions and accounts that should appear in the financial statements are includedTrace independent receiving, supplier, late-invoice and subsequent-payment records into AP/accruals and GL
AccuracyAmounts, dates, account coding, and period assignment are correctCompare selected journals to the source invoice, settlement report, and chart of accounts mapping
ValidityThe obligation is real, amounts are not duplicated or fabricated, and approval exceptions are separately investigatedInspect approval evidence, manual override logs, duplicate event handling, and exception closures
CutoffLiabilities are recorded in the correct accounting periodReview subsequent cash disbursements and invoices received after period end

Step 1. Test completeness of AP liabilities and disbursements#

Start with completeness, because missing activity makes later checks look cleaner than they are. Under AS 1105, the completeness assertion is whether all transactions and accounts that should appear in the financial statements are included. In AP, that means proving your ledger contains the liabilities and disbursements that should be there, not just that the items already posted look reasonable.

Build the completeness population outside the posted AP ledger as well as inside it. Trace receiving records, supplier statements, unmatched purchase receipts, invoices arriving after close and subsequent payments into the period's liabilities. Separately inspect high-value, unusual and aged accruals for support, later invoicing, clearing and reversal. Starting only with booked invoices can miss an obligation absent from both AP and the GL.

For each source item, determine when the goods or services were received, the amount owed and whether AP or an accrual records it in the right period. Inspect unsupported booked accruals too, but distinguish overstatement or valuation questions from the search for unrecorded liabilities.

Step 2. Move to accuracy and validity testing#

Move to accuracy and validity while keeping completeness work open where source populations or exceptions remain unresolved. Amount, currency, account coding and period assignment must be supported. Authorization is a control check; an unapproved but genuine obligation may still need recognition while the approval breach is investigated.

Compare journal amounts and account mapping to the invoice or accrual support. For paid items, inspect approval, manual overrides and settlement clearing; test duplicate-event handling too. An unauthorized release is a control breach, while the underlying genuine obligation may remain valid. A duplicate journal can misstate the liability even when the vendor invoice is real.

This is also where targeted testing should get less predictable. PCAOB AS 2301 says the auditor should incorporate an element of unpredictability in procedure selection from year to year, and that is a good self-audit discipline too. If you always pull the same vendor types or the same payment lane, fraud-sensitive control gaps can sit untouched.

Step 3. Run the cutoff test using subsequent disbursements#

Use subsequent payments and late invoices to search for unrecorded liabilities and test cutoff. A payment after month-end may settle a properly recorded prior-period payable, reveal a missing accrual or relate to a later period. Its timing alone does not decide which outcome applies.

Anchor the review to post-period cash activity and the supporting invoices or receiving documents behind it. For each selected disbursement, determine whether the underlying obligation related to the period under audit and whether the liability was recorded in the correct accounting period. Where the posting date and the supporting documents disagree, follow the support rather than assuming the ledger timestamp is enough.

If the support shows the liability belonged in a different period, treat it as a cutoff exception and assess it before close. Cutoff is not a cosmetic clean-up step. It is part of proving that liabilities were recognized in the period they relate to.

Build the investor-ready AP closeout packet#

Before diligence or fieldwork, package the exact close period, population definitions, tests and exceptions. Show what was resolved, what remains open and the balance management approved. A completed packet supports review; it does not certify audit assurance.

Weekly evidence checklist#

Use a practical starter pack, then align it with the actual investor or auditor request.

  • A dated AP subledger-to-GL tie-out for the exact close period.
  • An aged payables report by vendor, currency, and due-date bucket such as current, 30 days, 60 days, and 90+ days.
  • An open Exception Queue export with owner, created date, aging, and planned resolution.
  • A vendor master change log covering bank-detail edits, tax-form updates, and approval history.
  • A subsequent-disbursement sample pack linking invoice, approval, payment, and posting evidence.

Escalation thresholds for unresolved AP items#

Set monetary and timing triggers for your population, reporting currency and risk. These are operating thresholds, not materiality rules. For illustration, a team might investigate unmatched items above $10,000 or duplicate-payment indicators still open after two business days; fraud indicators or bypassed bank-detail controls may need immediate review regardless of amount.

  • Apply approved unmatched-item amount and aging triggers by currency; keep the threshold and rationale in the review file.
  • Investigate duplicate-payment indicators promptly, including lower-value repeated items.
  • Review manual AP journal overrides under the approved authority and independent-review policy.
  • Escalate vendor bank-detail changes that bypass verification and maker-checker review.
  • Assess cutoff exceptions for individual and aggregate financial statement impact.

What the investor or auditor file should show#

The review file should answer who approved, what changed, when it changed, and how the final balance was cleared.

  • One summary memo naming the tested population, the risk areas, and any unresolved items.
  • A reconciliation schedule tying the AP subledger, cash disbursement log, and general ledger.
  • Evidence that stale exceptions were cleared, waived, or escalated with approver names.
  • A bridge for foreign-currency vendors showing source amount, booked amount, and FX treatment.
  • A final sign-off page dated before the board pack, lender update, or 2026 fieldwork window.

Questions to ask before external fieldwork starts#

Use a short challenge list before you claim the file is audit-ready.

  • Can a reviewer reconstruct a transaction using the packet and its stated identifiers?
  • Can finance explain every reconciling item without reopening production systems?
  • Are all vendor bank changes supported by approvals and callback controls?
  • Do subsequent-disbursement samples prove the right period was charged?
  • Is every open exception assigned to one owner and one target date?

AP self-audit FAQ#

These questions help controllers answer the follow-up points investors and auditors usually raise.

How many transactions should we trace before calling the AP file review-ready?#

Set the extent of testing from population size, risk, control frequency and the quality of evidence. Include normal activity, unusual vendors, manual overrides and source items outside the ledger. A few end-to-end traces help map a process, but five or ten traces do not establish coverage or prove operating effectiveness for the full period.

What is the fastest way to prove the AP subledger matches the general ledger?#

Use a dated bridge showing the AP balance, GL balance, reconciling items, owners and supporting entries. Reproduce the exports and explain differences for the same date, entity and currency. Meeting a one-day preparation target does not establish correctness or completeness.

When does an exception queue item become an investor-level issue?#

Escalate when the potential balance or disclosure effect, fraud risk, aging or repeated control failure exceeds the approved risk policy. Assess issues individually and together; neither one stale exception nor a fixed count of three determines materiality.

Should we freeze vendor master changes during AP self-audit week?#

Freeze nonessential vendor master edits during the critical testing window whenever possible. If business operations require a change, route it through an emergency approval path with maker-checker evidence and same-day review.

What should we show when approvers bypass the normal workflow?#

Show the reason, authority, amount, affected records and independent follow-up. Test whether the payment and liability remain valid, whether the control breach allowed other exceptions and whether the corrective control works. Documentation alone does not make an override acceptable.

How do we evidence cutoff testing when payments settle after month-end?#

Use the date goods or services were received and the contractual obligation, supported by receipts, service acceptance, invoices and later payments. For example, $12,000 of December services invoiced and paid in January can require a December accrual; the later cash entry clears the liability rather than moving the expense into January. Retain the recognition and settlement entries together.

Frequently Asked Questions

How many transactions should we trace before calling the AP file review-ready?

Set the extent of testing from population size, risk, control frequency and the quality of evidence. Include normal activity, unusual vendors, manual overrides and source items outside the ledger. A few end-to-end traces help map a process, but five or ten traces do not establish coverage or prove operating effectiveness for the full period.

What is the fastest way to prove the AP subledger matches the general ledger?

Use a dated bridge showing the AP balance, GL balance, reconciling items, owners and supporting entries. Reproduce the exports and explain differences for the same date, entity and currency. Meeting a one-day preparation target does not establish correctness or completeness.

When does an exception queue item become an investor-level issue?

Escalate when the potential balance or disclosure effect, fraud risk, aging or repeated control failure exceeds the approved risk policy. Assess issues individually and together; neither one stale exception nor a fixed count of three determines materiality.

Should we freeze vendor master changes during AP self-audit week?

Freeze nonessential vendor master edits during the critical testing window whenever possible. If business operations require a change, route it through an emergency approval path with maker-checker evidence and same-day review.

What should we show when approvers bypass the normal workflow?

Show the reason, authority, amount, affected records and independent follow-up. Test whether the payment and liability remain valid, whether the control breach allowed other exceptions and whether the corrective control works. Documentation alone does not make an override acceptable.

How do we evidence cutoff testing when payments settle after month-end?

Use the date goods or services were received and the contractual obligation, supported by receipts, service acceptance, invoices and later payments. For example, $12,000 of December services invoiced and paid in January can require a December accrual; the later cash entry clears the liability rather than moving the expense into January. Retain the recognition and settlement entries together.

Gruv Editorial Team

Researched and edited by the Gruv editorial team. Gruv builds cross-border billing, payouts, and finance-operations software for global businesses.

Sources

Includes 2 external sources outside the trusted-domain allowlist.

  1. sec.gov/interps/account/sab99.htmtrusted
  2. pcaobus.org/oversight/standards/auditing-standards/detai...external
  3. pcaobus.org/oversight/standards/auditing-standards/detai...external

Educational content only. Not legal, tax, or financial advice.

Related Posts

What Payment Platform Auditors Actually Test in SOC 2 Type II
Deep Dives27 min read

What Payment Platform Auditors Actually Test in SOC 2 Type II

If buyers are asking for SOC 2 Type II, the real question is simple: can you show that controls operated over time, with clear scope and clear evidence ownership?

soc 2 type ii2 type ii certificationtype ii certification payment
Read
How Platform Teams Scale AP Volume Without Adding Headcount
Deep Dives35 min read

How Platform Teams Scale AP Volume Without Adding Headcount

Use this as a decision list for operators scaling Accounts Payable, not a generic AP automation explainer. In these case-study examples, invoice volume can grow faster than AP headcount when the platform fit is right, but vendor claims still need hard validation.

accounts payable automationinvoice processingtouchless processing
Read
Internal Controls for AP Platforms to Prevent Fraudulent Disbursements
Deep Dives23 min read

Internal Controls for AP Platforms to Prevent Fraudulent Disbursements

Start here: your AP control design should reduce fraudulent disbursements and payment errors without turning every payout into a bureaucratic exercise. In practice, that means clear escalation points at the moments where money can move incorrectly, not extra approvals added just to look controlled.

internal controlsprevent fraud accurate disbursementscontrols accounts payable
Read