
A warehouse clerk receives a delivery, signs the paperwork, and moves on to the next truck. Two weeks later an invoice from the same supplier arrives in accounting, for a slightly different quantity and a price that does not quite match the original order. Nobody catches the gap because nobody is comparing the three documents — the purchase order, the goods receipt, and the invoice — side by side. The invoice gets paid on trust, and the discrepancy, whether an honest error or something else, disappears into the books.
This is the exact control gap a parent company's internal audit team looks for first when reviewing a Turkish subsidiary, and it is also one of the most common sources of duplicate payment and invoice fraud in growing operations. The fix is not more paperwork — it is a structured chain that connects what was ordered, what arrived, and what was billed.
What three-way matching actually checks
Three-way matching compares three documents before an invoice is approved for payment:
| Document | What it confirms |
|---|---|
| Purchase order | What was ordered, at what price, in what quantity |
| Goods receipt note | What actually arrived, and when |
| Supplier invoice | What the supplier is billing for |
Payment is released only when the three agree within a defined tolerance. If the invoice shows a higher quantity than the goods receipt, or a price that doesn't match the purchase order, the invoice is held rather than paid automatically. This single check catches the majority of pricing errors, short shipments billed as full, and duplicate invoices — long before they reach the bank account.
Why tolerance thresholds matter more than perfect matching
Requiring an exact match on every field sounds rigorous but breaks down fast in practice. A shipment arrives with 998 units instead of 1,000 because of normal handling loss, or a supplier's invoice rounds a unit price to two decimals instead of four. A system that blocks every invoice with any variance quickly trains the finance team to override the control rather than use it.
A workable setup defines tolerance bands instead:
- Within tolerance (for example, a small percentage or absolute variance on price or quantity): invoice clears automatically.
- Outside tolerance, below a materiality threshold: routed to a single approver for a quick review.
- Outside tolerance, above the threshold: routed to a full exception review, with the purchasing and receiving records attached.
This keeps routine purchasing moving while forcing a human decision exactly where the risk actually concentrates.
Where the approval chain starts — before the order, not after
Three-way matching only works if the first document, the purchase order, was itself properly authorized. If anyone can create a purchase order for any amount, matching the invoice against it later just confirms that an unauthorized order was fulfilled correctly.
The approval chain typically has three tiers, defined by spend amount:
- Low-value, routine purchases clear with a single approval, often the requester's direct manager.
- Mid-value purchases require a second approval, usually from a budget owner or department head.
- High-value or capital purchases route through a multi-level chain, sometimes including a parent-company sign-off for subsidiaries operating under group spending policy.
The chain should be defined by rule, not by who happens to be at their desk that day. A purchase order created outside the defined tiers — split into smaller amounts to stay under an approval limit, for instance — is itself a red flag that a well-configured system can surface automatically.
Segregation of duties: the control auditors test first
A recurring finding in subsidiary audits is that the same person who creates a purchase order can also approve the matching invoice, or the same person who receives goods in the warehouse can also enter the goods receipt without a second check. Segregation of duties means these functions sit with different people:
- The person requesting a purchase is not the person approving it.
- The person receiving goods is not the person approving the invoice.
- The person creating a vendor record is not the person approving payments to that vendor.
None of this requires a large finance team. Even a lean subsidiary can maintain segregation by splitting roles across two or three people rather than concentrating the full purchase-to-pay cycle in one set of hands.
What happens when the match fails
An exception is not a dead end — it is a queue. When a purchase order, goods receipt, and invoice don't align, the invoice should move into a visible exception list rather than sit unpaid and unexplained in someone's inbox. A clear exception typically resolves one of three ways:
- Receiving correction — the goods receipt was recorded incorrectly and needs to be fixed.
- Supplier correction — the supplier issues a credit note or corrected invoice.
- Approved variance — the difference is legitimate (a small price adjustment, a partial shipment) and a manager approves it explicitly, with the reason recorded.
What should not happen is a fourth path, where someone simply pays the invoice as billed to make the exception disappear. Every exception needs a resolution that leaves a trace.
How Birasyo structures this in practice
In Birasyo ERP, the purchase-to-pay cycle is a single connected chain rather than three separate records that happen to reference each other:
- Purchase orders route through a configurable approval matrix based on amount, with each tier assigned to a named approver role.
- Goods receipts are recorded against the original purchase order, so quantity and price variances are visible the moment goods arrive — not weeks later at invoice time.
- Supplier invoices are matched automatically against the purchase order and goods receipt; matches within tolerance clear without manual intervention, and exceptions route to the Purchasing module's exception queue with the full document trail attached.
- Role-based access keeps purchase requesting, approval, and payment authorization separated by design, which is typically the first item a group internal audit checklist tests.
Summary
Three-way matching only works when the purchase order it starts from was properly authorized, and the approval chain only works when receiving and invoice approval sit with different people. Tolerance thresholds keep the control from becoming friction on routine purchases while still catching the variances that matter. Every match failure should land in a visible exception queue with a clear resolution path, not disappear into an inbox. For a subsidiary preparing for its first group internal audit, this is usually the single control that determines whether the review goes smoothly or produces a list of findings.
If you'd like to see how your current purchase-to-pay process would hold up against this checklist, a demo is a good place to start.
Related reading:
Share this on LinkedIn
Headline, summary and hashtags copy to your clipboard and the LinkedIn composer opens — paste (Cmd/Ctrl+V) and post.


