Invoice matching compares what you agreed to buy against what arrived and what you were billed. Two-way matching tests the invoice against the purchase order, three-way adds the goods receipt, and four-way adds inspection. You decide what clears without review when you set a tolerance, which makes your tolerance table a precise statement of what you do not check.
Key takeaways
- A tolerance is two decisions on one number, namely what variance is legitimate for this category and how much money you're willing to pay without a second look.
- Pair every percentage with an absolute cap and apply the tighter of the two. Two percent of $2.4 million is $48,000.
- A header-level tolerance is far more permissive than a line-level one. In the worked example below, a 5% header test clears a $526 problem untouched.
- Variance clustered just under your threshold, always positive, repeating on one vendor, is priced error rather than random error. Random error is symmetric.
Your matching tolerance is a number somebody set once, usually to clear a backlog. It is also the most precise instruction your suppliers will ever get about what you do not check.
Where invoice matching quietly becomes a rubber stamp
The purchase order (PO) is the agreement and the receiving record is the proof of delivery. The invoice is the claim. When any of those disagree, it is up to accounts payable (AP) to work it out.
Ardent Partners published its State of ePayables benchmarks in January 2026. The average invoice exception rate was 18.4%, and the average cost to process one invoice was $9.84. Close to one invoice in five stops for a human decision, and every stop is a person reading two documents side by side.
Tolerances keep that queue survivable. A variance under the threshold does not deserve a human. Freight came in $12 above the quote, or a supplier rounded unit price to four decimals where you carry two.
So the threshold gets set, then widened, then forgotten. A number introduced to absorb rounding ends up absorbing price increases nobody agreed to. It is a field on an enterprise resource planning (ERP) screen, reviewed at no fixed interval.
The pressure is all in one direction. Ardent Partners put average cycle time at 8.2 days in the same research, and every team working on that number asks matching to stop fewer invoices.
How to think about a tolerance
A tolerance is two decisions wearing one number. The first is what variance is legitimate for this category of spend. The second is how much money you will pay without a second look. Most teams make the first decision carefully and inherit the second by accident.
Legitimate variance is a property of the commodity and the contract. Hedged commodity prices move. Fixed-price contract manufacturing does not, so a price variance there is a contract breach rather than market noise. Acceptable exposure is a property of your balance sheet.
Then decide where the test applies. A header-level tolerance tests whether the invoice total is close enough to the PO total. A line-level tolerance tests that on every line. The header test is far more permissive.
Materiality is the last trap. Your external auditor's threshold describes the financial statements, not whether a control works. A recurring variance well below materiality can still be an unmanaged loss that never appears in an audit finding.
Set the threshold from the spend profile, report on what clears inside it, then adjust on a fixed cycle. A tolerance with no report behind it is an unmonitored control that passes every audit anyway.
How the invoice matching models compare
Two-way matching
Two-way matching compares the invoice against the PO. Price, quantity billed, item, and payment terms are tested against what was ordered. No delivery record is part of the comparison, so it cannot tell you whether anything arrived. It fits subscriptions and low-value indirect goods.
Three-way matching
Three-way matching adds the goods receipt, so quantity billed is tested against quantity received rather than quantity ordered. A short shipment invoiced in full now fails. It fits inventory, direct materials, and capital equipment. It remains blind to quality, and to whether the purchase was needed.
Four-way matching
Four-way matching adds an inspection record, so the invoice pays only against material that passed inspection. The cost is a fourth document somebody must create on time, and inspection records lag receiving. It fits regulated manufacturing. It is still blind to whether the PO itself was legitimate.
A worked example
PO 4471 orders 1,200 machined parts at $12.50 with a $250 freight allowance, so $15,250. Receiving logs 1,180 units, and the 20 short-shipped units never come back as a credit. The invoice bills 1,200 units at $12.68 plus $310 freight, or $15,526.
Run the line tests. Quantity billed exceeds quantity received by 1.69 percent, and unit price exceeds the PO price by 1.44 percent. Freight exceeds the allowance by $60, a 24% variance. Under a 2% line tolerance, only freight stops the invoice, a $60 exception on a $526 problem.
Now run the header test. You owe $15,000 for the units received plus the freight allowance, and the invoice bills $15,526, a gap of 3.5 percent, so under a 5% header tolerance nothing stops the invoice. You pay for units that never arrived, and the audit trail shows a clean match.
Setting a tolerance you can defend
Percentage against absolute value
A percentage tolerance scales with the invoice, which is the problem. Two percent is a rounding allowance on a small invoice and an open line of credit on a large one. Exposure at a flat 2% works out as follows.
- On a $2,000 invoice, 2% is $40.
- On a $50,000 invoice, 2% is $1,000.
- On a $2.4 million invoice, 2% is $48,000.
Run both tests and apply whichever is tighter. The percentage fits the small end, where a flat threshold stops everything or nothing. The absolute cap fits the large end. A workable shape is 2% or $500, whichever is lower.
Tolerance by category and by vendor
One threshold across all spend is a threshold set for the messiest thing you buy. Price-volatile commodities need room, and a fixed-price contract needs almost none. Freight and duty are better tolerated as their own line types. New suppliers deserve a tighter band, because you have no baseline for normal yet.
Your tolerance is a published attack surface
A tolerance is a rule about what you will not examine. Rules like that are worth money to anyone who learns them.
A supplier's billing clerk needs no system access to find your threshold. They submit invoices and watch which come back. Price a line 1.5% over the agreed rate and nothing happens. Within a quarter they have mapped the boundary.
In the ledger this looks like health. You see no exceptions, no queue, and no case file, because the control performed as designed. Look at shape rather than transaction and you see something else. The variance is always positive, clustered under the threshold, and repeating on the same vendor and line. Random error is symmetric, and priced error is not.
Now scale that pattern up. Forty invoices a year averaging $80,000, at 1.5%, is $48,000 that never triggers a match failure.
Duration is the argument for detecting patterns rather than transactions. In the ACFE Report to the Nations 2026, the median occupational fraud scheme lasted 12 months before detection. Schemes caught inside six months produced a median loss of $40,000, against a median loss of $1.1 million for schemes that lasted more than five years.
An insider works the same way. A requisitioner who knows the threshold waves through a friendly supplier's inflated pricing, and matching confirms it was fine.
The tolerance trade-off
Tightening a tolerance moves invoices out of straight-through processing (STP) and into a human queue. The average exception rate was already 18.4% in 2025, at $9.84 an invoice. Halving a threshold across all spend is a staffing decision.
So target the tightening. Narrow the band where exposure concentrates, on high-value lines, fixed-price contracts, and new suppliers. Leave it wide where variance is noise, and monitor what clears inside it.
What invoice matching does not catch
Matching validates a claim against a record. It has no opinion on the record.
It cannot tell you whether the goods were needed. Four hundred laptops nobody had a use for, ordered on a valid PO and received in full, produce a flawless match.
It cannot tell you whether the PO was legitimate. Matching treats the PO as truth, so a PO raised for a paper-only supplier still produces a clean match.
It evaluates one transaction at a time, so an invoice sent by email and again through a portal under a different number matches twice.
It is also not where most fraud surfaces. ACFE found tips the most common detection method in 2026, at 43% of cases.
Where current approaches fall short
Tolerance configuration in most ERP systems is a static table. It evaluates one invoice against one PO, returns pass or fail, and remembers nothing. It holds no memory of the previous 41 invoices from that supplier that cleared at 1.6% over. It cannot compare one vendor's variance distribution against the rest of the category.
Exception queues compound that blindness. Most are worked oldest first, because aging is what the reporting measures. A $200 freight variance and a first invoice from a supplier added last week are in one queue, and the analyst works the older one first.
Exception routing rarely helps. Most systems record the reason code and the resolver, and almost none record what the tolerance absorbed on invoices that never stopped. The result is a control precise about single transactions and blind to patterns, which is the inverse of the risk you carry.
How we approach invoice matching
We built our AI to read the invoice, the PO, and the receipt at line level, with multi-line PO matching and routing. The comparison uses actual lines rather than a header total, which is the difference between catching the example above and paying it.
The part that reduces tolerance exposure is history. Our platform evaluates an invoice against what that supplier billed before, so a variance that is always just under the threshold becomes a visible pattern. That is the same engine behind our fraud and risk detection work, where duplicates, ghost vendors, and repeat-variance behavior are population-level questions.
TruGreen reached 60% autonomous processing with us and identified $870,000 in duplicate payments, which is what population-level review finds. Every decision our Agents make record the evidence, so a cleared variance retains a reason a reviewer can inspect months later. The tolerance becomes something you report on.
The bottom line
Pull every invoice from the last 12 months that cleared inside tolerance, group by vendor, and plot the variance distribution. Variance clustered under your threshold is something your matching engine was configured not to see. Our team can walk your tolerance table with you.
Frequently asked questions
What is the difference between two-way and three-way matching?
Two-way matching compares the invoice against the purchase order, testing price and quantity against what was ordered. Three-way matching adds the goods receipt, so quantity billed is tested against quantity received. Only three-way matching detects billing for goods that never arrived.
What is a reasonable matching tolerance?
No single number is right, and any source quoting one has skipped the question. Use near zero on fixed-price lines, wider bands on volatile commodities, and a tight band for a supplier's first invoices. Always pair a percentage with an absolute cap.
Should a tolerance be a percentage or a fixed amount?
Use both, with the tighter of the two winning. A percentage alone leaves a large absolute exposure, because 2% of $2.4 million is $48,000. A fixed amount alone stops trivial variances or lets proportionally large ones through.
Can invoice matching detect invoice fraud?
It detects only the kind that breaks a rule. It misses a scheme priced inside your tolerance, or a fraudulent PO the invoice matches perfectly. Catching those means reading vendor patterns over time, alongside the mechanics in our guides to three-way PO matching automation and invoice approval workflow design.