Research · Published:
Can an AP reviewer prove which invoice attachment was processed?
Research on attachment provenance, replacement files, version history, and review boundaries in a shared AP inbox.
Research question and method
Can a second reviewer determine exactly which invoice attachment supplied the fields entered into the accounting workflow? This study examines a narrow but common evidence problem: one email thread or portal case can contain an original invoice, a corrected copy, a scan, and a forwarded duplicate. The method follows the record from receipt through extraction, exception handling, approval preparation, and archive. It draws on GAO guidance about quality information and documentation, NIST controls for audit records and access, and National Archives records-management principles. The review uses a declared sample rather than a production benchmark. Include single-attachment messages, corrections, renamed files, image-only scans, portal downloads, forwarded threads, and two documents with the same visible invoice number. The question is whether provenance survives the workflow, not whether the attachment looks professional.
Evidence population
For each item, capture the intake channel, receipt time, message or portal identifier, original filename, file type, page count, stable file hash if the approved system provides one, supplier shown on the document, invoice identifier, and the record created from it. Preserve a link between extracted fields and the exact source version. A filename is weak evidence because users and systems can rename files. A visual match is also limited: two PDFs may display the same first page while containing different later pages or metadata. These are factual comparisons only when the underlying records are retained. Calling one file "correct" requires an authorized disposition or a controlled rule that applies to the case. An outsourced specialist may describe differences and route the question without choosing the commercially valid document.
Case analysis
The study tests version collisions. Suppose an invoice arrives on Monday, a corrected tax field arrives Tuesday, and an employee approves a packet Wednesday. The review should show which version was prepared, which differences were noticed, whether the earlier version remained linked, and which version the approval covered. Overwriting Monday's file with Tuesday's copy destroys chronology even if the new document is accurate. A better evidence chain appends the replacement and records the relationship between versions. The same principle applies when optical character recognition is rerun: the extracted values may change while the source file does not. Retain the extraction event and reviewer correction separately. That makes it possible to locate whether a later discrepancy began in the supplier document, intake handling, automated extraction, or manual preparation.
Reproduction test
A blinded reproduction test provides more useful evidence than a simple completion count. Give a reviewer the system record without the preparer's explanation. Ask the reviewer to open the attachment that supports the recorded amount, entity, currency, invoice date, and purchase-order reference. Then ask for the superseded version and the reason it was not used. Sample at least one thread where the latest attachment is not automatically the valid one, such as a later duplicate or an unrelated statement. Record every place where the reviewer relies on filename, inbox order, or memory because a stable relationship is missing. Those dependencies are findings. They are not proof of an error, but they show that the result may not survive staff turnover or a later dispute.
Operating boundary
Access boundaries shape the workflow. Support can save approved-source attachments, assign stable identifiers, transcribe visible fields, compare versions, note discrepancies, and request missing pages. The company should reserve invoice acceptance, tax and accounting treatment, purchase authorization, exception override, and payment release for authorized employees. Least privilege may also restrict who can download or redistribute documents containing bank or tax data. When access prevents a preparer from viewing a needed source, the truthful status is "source inaccessible," not "verified." The reviewer can then route the gap to an owner with appropriate permission. Auditability depends on showing the access limit instead of encouraging staff to work around it through personal email or unapproved storage.
Interpretation
The evidence can support several classifications: original source linked; replacement linked and prior version retained; duplicate intake linked to an existing record; attachment incomplete; extraction conflict; source inaccessible; or validity undecided. These labels describe the record state. They do not decide whether money is owed. A quality review should sample across classifications and trace individual fields back to pages, rather than checking whether a file merely exists. Page-level references are especially useful for multi-invoice PDFs and credit documents. If a packet combines several invoices, the relationship between each accounting record and its pages must remain explicit. Otherwise, a reviewer may find an attachment while still being unable to prove which document supported the transaction.
Limitations
This study has limits. General control and records-management sources do not prescribe a universal AP file-naming convention, hash technology, retention period, or evidentiary standard for a private company. Hashes can show that bytes differ or remain unchanged; they do not establish authenticity or commercial validity. System timestamps may reflect upload, migration, or processing rather than supplier creation. A bounded sample cannot measure the frequency of attachment substitution outside the sampled population. Privacy, licensing, and contractual limits may affect document retention. Each organization needs counsel and accountable records owners for those decisions. The proposed test only asks whether the organization's chosen record can be reproduced within its declared systems, period, and permissions.
Evidence-led conclusion
The evidence supports a practical conclusion: an AP record is traceable when each material field points to a specific retained attachment version and later replacements extend the history instead of rewriting it. Outsourced support is well suited to preserving intake identifiers, comparing versions, and preparing discrepancy notes because those are repeatable evidence tasks. It should not decide which conflicting document creates an obligation. A reviewer should be able to start with the posted or prepared record, reach the exact source pages, see every superseded file, and identify the employee disposition. If that path breaks, the appropriate result is an exception with a named next owner. A neat folder or a familiar filename cannot substitute for provenance.
Sources
These primary sources support the control principles and evidence boundaries in this report.
FAQs
Are the planning numbers benchmarks?
No. They describe a testable workflow shape and are not promises, market averages, or production targets.
What should an outsourced AP assistant own?
Repeatable preparation, documentation, status tracking, and follow-up within least-privilege access. Named finance owners retain approval and payment decisions.
When should an item be escalated?
When evidence is missing, a request changes payment details, a duplicate or fraud signal appears, or the item falls outside the written rule.