Skip to main content

Three-Way Matching: PO, Receipt, and Invoice

Three-way matching checks a supplier invoice against the purchase order and receiving report before payment. What it catches, its limits, and how to set tolerances.

Written by Eco
Three-Way Matching: PO, Receipt, and Invoice

Three-way matching is the control that compares a supplier invoice against the purchase order that approved it and the receiving report that confirms delivery, before the invoice is approved for payment. All three must agree on quantity, price, and identity, or the invoice does not get paid.

It exists because each document answers a question the others cannot. The purchase order establishes what was agreed, the receiving report establishes what actually arrived, and the invoice states what is being charged. Paying on the invoice alone means paying on the seller's word about all three.

What Is Three-Way Matching?

It is a pre-payment verification comparing three documents: the purchase order, the receiving report or goods receipt, and the supplier invoice. Where all three agree within tolerance, the invoice is approved. Where they do not, the invoice is held as an exception until the difference is resolved or the invoice is adjusted.

The control is long-established in public sector guidance. GAO describes examination focused on comparing information on three critical documents: the obligation or ordering document, the receiving and inspection document, and the invoice, with the invoice adjusted where necessary to reflect items actually received and accepted.

Commercial descriptions match. NetSuite describes it as verifying a supplier invoice by checking it against its corresponding purchase order and order receipt before the invoice is deemed ready for payment.

What Does Three-Way Matching Catch?

It catches four things: invoices for goods never delivered, quantities billed above what arrived, prices above what was agreed, and invoices with no authorizing order at all. Each of these is a payment that would otherwise leave the business with nothing in return for the money.

The fourth is the most important and the most often overlooked. An invoice with no purchase order has no evidence anyone with authority agreed to the spend, which makes it the natural route for both error and fraud. A matching process that only compares invoices to orders that exist cannot see it.

What it does not catch is quality. A receiving report confirms that the stated quantity arrived, not that it was fit for purpose, which is why inspection is treated as part of the receiving step rather than a separate afterthought in the GAO framing, where the document is described as the receiving and inspection report.

Three-Way Matching Documents Compared

The table sets out what each document proves, who creates it, and what fails when it is missing. The third column is the useful one, because it explains why two-way matching is a materially weaker control rather than a slightly faster version of the same thing.

Document

Created by

Proves

What fails without it

Reference

Purchase order

Buyer

What was agreed, at what price, by whose authority

No evidence the spend was authorized or the price agreed

Receiving report

Receiver, independent of buyer

What actually arrived and was accepted

Payment possible for goods never delivered

Supplier invoice

Supplier

What is being claimed and on what terms

No claim to examine; payment lacks a documented basis

All three together

Three separate parties

Agreed, delivered, and billed consistently

Control depends on one party's assertion

The independence in column two is what gives the control its strength. Three documents produced by one party prove very little; three produced by a buyer, a receiver, and a supplier are difficult to falsify simultaneously, which is precisely the segregation principle at work.

When Is Two-Way Matching Enough?

Two-way matching compares only the purchase order and the invoice, and is defensible where there is no physical delivery to confirm. Services, subscriptions, utilities, and rent have no receiving report to produce, so requiring one would create an exception on every invoice.

The substitute control for those categories is approval by the person who consumed the service, which serves the same function as a receiving report by having someone independent of the supplier confirm that the thing was actually provided.

Where physical goods are involved, two-way matching is a genuine weakening. It removes the only independent evidence that delivery occurred and leaves the invoice as the sole assertion that anything arrived. GAO permits payment without an invoice only where compensating controls confirm receipt and acceptance, noting that payment should be authorized only after matching the types and quantities received with those on the purchase order or contract.

How Should Tolerances Be Set?

Tolerances should absorb immaterial noise and nothing else. Rounding, minor freight variances, and small unit-of-measure conversions are worth clearing automatically. A tolerance wide enough to pass a genuine price increase or a quantity shortfall has converted a control into a formality.

Set them in absolute terms as well as percentages. A percentage tolerance alone becomes dangerous on high-value invoices, where a small percentage represents a large amount, so a dual test with a cap on absolute value is the safer construction.

Track the effect rather than assuming it. Every tolerance widening improves the match rate by construction, so the honest measure is what the tolerance let through, monitored as post-payment corrections and recoveries rather than as an unqualified efficiency gain. A control that clears everything is not efficient, it is absent, which is the distinction AS 2201 tests when it asks whether a control actually detects misstatement.

What Happens to Exceptions?

Each exception should carry a cause, an owner, and a deadline. Quantity variances belong with receiving, price variances with whoever owns the contract, and missing purchase orders with the requester who bought without one. Routing everything to accounts payable produces a queue nobody can actually resolve.

The invoice should be adjusted rather than the records bent to fit it. GAO's framing is explicit that where necessary the invoice is adjusted to reflect the items actually received and accepted, which places the receiving report above the invoice in authority.

Aging matters as much as classification. An exception queue with a growing oldest bucket signals that easy items are clearing while genuine disputes accumulate, and those are exactly the ones that later get approved under time pressure at period end.

Can Three-Way Matching Be Automated?

The comparison automates well; the judgment does not. Matching quantity, price, and references across three documents is deterministic work suited to software, while deciding whether an unexpected freight charge is legitimate requires someone with the vendor relationship and the authority to accept it.

Automation's real contribution is coverage rather than speed. A manual process inevitably samples, checking high-value invoices closely and low-value ones lightly, whereas an automated match applies the same test to every invoice, which is where the fraud and error in a long tail actually sits.

GAO's account of a fast pay process illustrates what weak review costs: an inspector general found that 10 percent of the invoices paid had incorrect or missing support over a five-month period, attributed to poor controls in invoice review and processing.

Who Should Create the Receiving Report?

Someone other than the person who issued the purchase order, and someone other than the person who approves payment. The control's strength comes from three parties independently confirming three facts, and collapsing two of those roles into one person removes most of what makes it work.

This is a standards requirement rather than best practice. GAO's internal control standards hold that key duties and responsibilities need to be divided or segregated among different people to reduce the risk of error or fraud, and purchasing, receiving, and paying are the classic three to separate.

Small teams face a genuine constraint here, since there may not be three people available. The workable compromise is compensating detective controls: review of a sample of matched invoices by someone outside the process, and reconciliation that would surface a pattern the preventive control could not.

What should never be conceded is the supplier's role. A receiving report generated from the supplier's own delivery note without independent confirmation is the supplier asserting its own delivery, which returns the control to a single party's word.

How Does Three-Way Matching Fit the Purchase-to-Pay Process?

It sits at the last checkpoint before money leaves. Requisition establishes the need, approval authorizes it, the purchase order commits it, receiving confirms delivery, and matching verifies the invoice against those earlier steps. Every one of them is evidence the match relies on.

That dependency explains why matching problems usually originate upstream. An invoice that cannot be matched is often the consequence of a purchase made without an order or a delivery received without a report, and accounts payable is where the failure becomes visible rather than where it happened.

GAO frames the full sequence around the same logic, describing payment authorized only after confirming that goods and services ordered have been delivered and accepted, evidenced by a receiving and inspection report, and that a claim has been made as evidenced by receipt of an invoice.

The practical consequence for improvement work is that the highest-yield fixes are rarely in the matching step itself. Raising purchase order coverage and tightening receiving discipline reduce exceptions at source, whereas tuning the matching engine only changes how the resulting exceptions are presented.

What Should You Do About Recurring Exceptions?

Treat a repeating exception as a defect to be removed rather than work to be processed. If the same supplier produces a price variance every month, the price on the purchase order and the price in the contract disagree, and correcting that record eliminates every future instance at once.

Recurring quantity variances usually point at a unit-of-measure mismatch: the order in cases, the delivery in units, the invoice in either. These are configuration problems in the item master rather than genuine disputes, and they resolve permanently once the conversion is defined.

Freight and tax variances form a third recurring family. Where a supplier consistently adds charges the purchase order does not anticipate, the fix is agreeing how those charges are represented at order time rather than deciding case by case whether each one is acceptable.

A standing exception review is what makes this happen. Without a periodic look at exceptions grouped by cause and supplier, each instance is resolved individually and the pattern is never seen, which is how a queue stays constant in size while everyone works hard on it. The review needs an owner with authority to change master data and contract terms, since those are where the corrections actually land.

The same reasoning applies to reconciliation more broadly. A 2006 Journal of Accountancy analysis recommended a continuous improvement approach to reconciliation rather than treating each period as a fresh backlog, and exception patterns are exactly what such a process should be consuming.

What Are the Most Common Three-Way Matching Failures?

Four recur: invoices arriving with no purchase order and being paid anyway, receiving reports created in bulk after the fact to clear a backlog, tolerances widened until nothing fails, and exceptions approved at period end under time pressure without the underlying difference being resolved.

Retrospective receiving is the most damaging because it looks like compliance. A receiving report created from the invoice rather than from an actual delivery makes every invoice match perfectly while proving nothing, since two of the three documents now derive from the same source.

No-purchase-order invoices are the largest volume problem in most organizations. The fix is upstream in the buying process rather than in accounts payable, because by the time an unauthorized invoice arrives, the commitment has already been made and refusing to pay creates a supplier dispute rather than a control.

Period-end approvals are worth monitoring specifically. A spike in exception approvals in the last days of a period usually means the deadline, not the evidence, resolved the exception, and that pattern is visible in the data if anyone looks for it. GAO's response to weak review in a fast pay process was to require regular examination of statistical samples of paid invoices, adequate training, and regular review of control implementation.

How Do You Measure Three-Way Matching Performance?

Track first-pass match rate, exception volume by cause, exception age, the proportion of spend arriving without a purchase order, and post-payment corrections. The last two matter most, because they measure what the control never saw and what it wrongly let through.

First-pass match rate alone is a poor metric in isolation, since it rises when tolerances widen and when receiving reports are created retrospectively. Read alongside corrections and no-purchase-order spend, it becomes meaningful; read alone, it can improve while the control degrades.

Exception cause analysis is where the operational value sits. Variances concentrated on one supplier usually indicate a pricing disagreement that should be settled contractually rather than re-litigated on every invoice, which removes the cause instead of processing the symptom.

Coverage is the final measure. NetSuite frames three-way matching as ensuring invoices are paid only when properly validated against two other documents, and the proportion of spend actually subject to that validation is the number that determines whether the control governs the payables population or a subset of it.

How Does Three-Way Matching Relate to Reconciliation?

Three-way matching is preventive and happens before payment; reconciliation is detective and happens after. One stops bad payments, the other finds what the preventive control missed, including payments that bypassed matching entirely. They are complementary and neither substitutes for the other.

The common error is treating a high match rate as evidence that reconciliation is unnecessary. That assumes every payment went through the matching process, and payments made by exception, on manual request, or outside the purchase order system are precisely where errors concentrate.

Reconciliation is also the control auditors test for detection. Under PCAOB AS 2201, a material misstatement the company's own control did not detect is a strong indicator of a material weakness, and prevention alone does not demonstrate detection.

What Records Must Be Retained?

All three documents, kept together and retrievable as a set for as long as the retention policy requires. The purpose of retention is reconstruction: showing on demand what was ordered, what arrived, what was billed, what was paid, and who approved each step, without depending on anyone's recollection.

Paper form is not required. GAO has long recognized that agency records need not be maintained in original paper-based form, provided controls ensure the digital images accurately represent the corresponding paper document, that changes are detectable, that access is limited to authorized personnel, and that images remain accessible until retention expires.

Storing the three documents in separate systems that cannot be joined defeats the purpose. Retention is only useful if the set can be reassembled, which is a data design question rather than a storage capacity one.

Retention periods should be set from the longest applicable requirement rather than the most convenient one. Tax authorities, contractual audit rights, and regulatory obligations each impose their own horizon, and the binding one is whichever extends furthest.

Does Faster Settlement Change Three-Way Matching?

No, and that is the point worth stating plainly. Three-way matching is a control over whether a payment should be made at all. Settlement speed concerns how quickly an approved payment moves, which is a different question entirely and does not touch authorization, delivery evidence, or price agreement.

Faster settlement does raise the stakes. When payments are irreversible and immediate, a control failure cannot be caught in a payment run and cancelled, so the pre-payment check carries more weight rather than less. The float that once absorbed mistakes was never a control, but it did function as an informal safety net, and removing it exposes how much a process was relying on it.

That shift is already underway on conventional rails. Nacha reported Same Day ACH volume growing 16.7 percent in 2025 to 1.45 billion payments worth $3.92 trillion, shortening the window in which a mistaken payment might be stopped.

Eco's Role

Eco operates the routing and execution layer that stablecoin payments move through. It affects how a payment settles once approved, not whether it should have been approved, so three-way matching sits entirely upstream of anything Eco does and remains the buyer's control to run.

The relevant consequence is the one above: settlement that is fast and final makes pre-payment controls more important, because there is no float period in which an error can be intercepted. Teams moving to faster rails should tighten matching rather than relax it.

For the settlement record those controls eventually reconcile against, Eco's comparison of stablecoin settlement APIs with audit trails covers what that record should expose.

Methodology. The three critical documents, the invoice adjustment principle, the fast pay error finding, and the digital records criteria are from GAO's Streamlining the Payment Process While Maintaining Effective Internal Control (GAO/AIMD-21.3.2), retrieved September 9, 2026. Segregation of duties is per GAO internal control reporting. The commercial description is from NetSuite. Audit consequences are per PCAOB AS 2201. ACH figures are Nacha's ACH Network statistics for full year 2025. No vendor performance or pricing claims appear in this article.

Related Reading

Did this answer your question?