Back to blog

We’re a Heavy PO Company, So Duplicates Can’t Happen. Right?

Every time I’m in a sales conversation, some version of this comes up: “We’re a heavy PO company. We require a purchase order for everything, so duplicate payments really can’t happen to us.”

I understand why people believe it. Purchase orders do add a layer of control. But here’s the uncomfortable truth from 25 years of analyzing AP data and performing audits: in the duplicate payments we’ve validated, more than 52% had a PO involved.

More than half. So how can that be? Here are the ways it happens.

POs add control, but they don’t add immunity

A purchase order is a good control. It creates a matching trail, sets expectations with the vendor, and gives AP something to check an invoice against. But a control only works if it’s actually doing its job at the moment of payment. Too often the PO is treated as a force field, as in “we have one, so we’re covered,” when in reality it may not be controlling anything at all.

1. The blanket PO: the easy button

Many organizations require a PO for everything. That sounds great until you remember that purchasing teams have been squeezed for resources for years: the same “do more with less” pressure AP has lived under. It’s easy for AP to say the PO is Supply Chain’s job, and easy for Supply Chain, working with an ongoing supplier, to just set up a blanket PO and move on.

I’m actually fine with blanket POs in principle. The problem is the follow-up question nobody asks: how long does it last? Weekly? Monthly? Annually? Forever?

I’ve seen data where the same PO line item was used for more than 10,000 invoices. Is that a control? Not even close. At that point the PO isn’t matching anything meaningful: it’s just an open door every invoice walks through. It’s the easy button. And when AP relies on it as their duplicate-payment control, they don’t actually have one.

2. The “one-touch” PO that never stays one-touch

I believe in a one-touch PO: create it once, correctly, and never touch it again. The reality is that most POs get touched by buyers two to five times over their life: pricing changes, quantity changes, revisions.

Here’s where duplicates creep in. Say a PO is set up with the wrong price. The invoice comes in, doesn’t match, and lands in the exception queue. To fix it, the PO gets corrected, and sometimes the invoice has to be re-created or re-entered to match the new terms. I can’t tell you how many times both invoices end up entered, often for slightly different amounts. Two records, one real obligation, and a payment that goes out twice.

3. Duplicate vendor records that hide the PO

Now combine POs with a messy vendor master file. A PO gets created under one vendor record. Later, an invoice arrives without referencing the PO. AP goes looking, but they’re looking under the other duplicate vendor record, where there is no PO. So the invoice drops into the exception queue.

It can sit there for weeks while purchasing reviews it, and sometimes the resolution is simply to create another PO under the second record. Weeks or months later, the vendor sends another invoice, and this time AP finds the original PO and applies it to that one. Now you have two POs, two invoices, and a very real path to paying the same thing twice.

4. After-the-fact POs (the compliance mirage)

When a company brags that they’re nearly 100% PO compliant, I get interested, because that’s often where we find the best results. Here’s why.

Compare the dates in the data: invoice date, received date, entered date, and PO creation date. Time and again, you’ll find POs that were created after the invoice arrived. Someone got an invoice with no PO, so they created one just so it would match. On paper, compliance looks great. In reality, the PO didn’t control anything: it was written to fit an invoice that was already in hand.

That’s not a two- or three-way match; it’s a rubber stamp. And it leaves organizations with a false sense of security, believing a control is protecting them when the sequence of events shows it never did.

5. And a few more ways it slips through

Even a real, well-scoped PO has limits:

  • Weak matching. A two-way match (PO to invoice) with no receipt confirmation, or loose price and quantity tolerances, lets near-duplicates through.
  • Overrides. When a match fails, someone can usually override it, and under volume pressure, they do.
  • PO and non-PO overlap. The same charge gets paid once against a PO and again as a non-PO invoice, or through a different system. Each path looks clean on its own.

A PO is only a control if it’s controlling something

Here’s what I want heavy-PO organizations to sit with: a purchase order on the invoice is not the same as a control on the payment. A blanket PO left open forever, a PO revised five times, a PO hiding under a duplicate vendor, a PO created after the fact: in every case the PO is present and the duplicate still gets paid. That’s how you end up with 52% of validated duplicates carrying a PO.

None of this means POs are bad. It means “we’re a heavy PO company” is not the same as “we don’t have duplicates.” The only way to know the difference is to look at the data.

Think your POs have you covered? Start a no-cost Proof of Value and we’ll show you what’s actually getting through. We only get paid a percentage of what we recover.

Karl Andersson
CEO, AP Impact

Karl has spent 25+ years in AP auditing and analytics, helping finance teams recover lost value and understand their payables. He writes about what he’s actually seen in the field. Read his story →

Keep reading

Never Fear the Hard Stop
Most duplicate payments start at the keyboard. How your ERP is configured, hard stop or soft stop, matters more than you think.
We Asked AI to Find Our Duplicate Payments. Here's What Actually Happened.
Point AI at your ERP and ask it to find duplicate payments. Here’s what really happens, and how we do it differently.