Corpay

AP Audit Trail: Why It Matters for Compliance

Category:AP Automation, Risk management
Updated:2026-07-24
Author:David Luther

An accounts payable audit trail is the continuous, timestamped, user-attributed record of every action taken on an invoice from capture through payment and reconciliation. It's the evidence that lets you prove who approved what, and when.

Most finance teams believe they have one. What they usually have is fragments. The approval sits in an email thread, a coding change sits in a spreadsheet on a shared drive, the supplier's updated bank details arrived as a PDF attachment from someone's phone, and the ERP shows only the journal entry that came out the other end. Those fragments amount to a pile of artifacts you can assemble into a story if you have three days and a cooperative memory, which is a different thing from a trail.

The distinction worth holding onto is between the audit and the trail. An AP audit is an event with a kickoff date and a request list. The trail is the always-on record the audit draws from. Teams that treat the trail as something they'll reconstruct later end up doing archaeology every quarter.

Key Takeaways

  • An AP audit trail is a continuous record of who did what and when across the invoice-to-pay lifecycle, not a report you generate once the auditor shows up.

  • A complete trail runs from capture through reconciliation, including supplier bank-detail changes and payment delivery. Most trails stop at approval.

  • Occupational fraud runs a median of 12 months before anyone detects it, and internal audit catches only a small fraction of cases, according to the ACFE.

  • Public companies must produce defensible evidence of internal control over financial reporting under Sarbanes-Oxley Section 404, and that evidence has to attach to specific people and specific moments.

  • ERPs hold the ledger. The gaps they leave open around capture, approvals, and payment delivery are exactly where a trail breaks, which makes recordkeeping largely an integration problem.

What is an accounts payable audit trail?

An accounts payable audit trail is the chronological, tamper-evident log of every action and every actor across the invoice-to-pay lifecycle. It answers three questions for any transaction. Who touched this, what did they change, and when did they do it?

The word "trail" does real work in that definition. A ledger tells you the end state of a transaction. A trail tells you the path it took to get there, including the version of the invoice before someone corrected the amount and the approver who was skipped when the request routed around a vacation. Auditors, fraud examiners, and your own controller all care more about the path than the end state, because the end state is where a problem hides rather than where it shows.

Accounting software has recorded some version of this for decades. What's changed is the surface area. A modern accounts payable process crosses an OCR tool, an approval workflow, and a payment rail before anything reaches the bank file, and each handoff is a place the record can go quiet.

What does a complete AP audit trail capture?

A complete AP audit trail captures every state change on an invoice and every change to the master data that governs how it gets paid. In practice that means seven categories of event:

  • Capture. When the invoice arrived, through which channel, and what the system read off it before a human touched anything.

  • Coding. GL account, cost center, and entity, plus any subsequent edits with the prior values preserved.

  • Approval. Who approved, at what threshold, in what sequence, and whether any step was delegated or overridden.

  • Supplier master changes. New vendors, banking updates, and remit-to changes, plus the identity of whoever requested and confirmed each one.

  • Payment authorization. The release decision, the approver, and the funding account.

  • Delivery. The rail used, the transmission timestamp, and the confirmation or return code, including any retries.

  • Reconciliation. How the payment cleared and how it matched back to the invoice and the bank statement.

Miss the fourth and sixth items and you have an approval log, not an audit trail. Supplier banking changes are where payment fraud actually enters the process, and delivery is where a payment quietly fails or gets redirected. A record that ends at "approved" leaves both blind spots wide open.

How is an audit trail different from an AP audit?

The trail is the evidence; the audit is the examination of it. An accounts payable audit is a scheduled review with a scope, a sample, and a set of control objectives an auditor tests against. The trail is what your team hands over when the sample list arrives.

That relationship is why the two get confused. If the trail is complete, the audit is mostly a query exercise, and your team spends its time answering follow-ups rather than assembling a binder. If the trail is fragmented, the audit becomes an internal project measured in weeks, and the answer to "why was this invoice paid at a different amount than approved?" turns into a search through someone's sent folder.

Why does an audit trail matter for compliance and fraud control?

It matters because controls you can't evidence don't count. An approval policy that exists in a document but leaves no per-transaction record is an intention, not a control, and every framework that examines internal controls treats it that way.

The financial stakes are not abstract. The typical organization loses an estimated 5% of revenue to fraud each year, with a median loss of $145,000 per case, according to the Association of Certified Fraud Examiners' 2024 report, Occupational Fraud 2024: A Report to the Nations. AP is a natural concentration point for that risk because it's where authority to move money meets high transaction volume and repetitive review.

How does a weak audit trail let fraud go undetected?

A weak trail lets fraud go undetected by removing the signal that would expose it early. The ACFE's Report to the Nations is blunt on timing, finding that occupational fraud runs a median of 12 months before it's caught, with 43% of cases surfacing through a tip, 14% through internal audit, and 13% through management review.

Read that distribution carefully. The single largest detection method is somebody deciding to speak up, which is not a control. Active detection, the kind that comes from monitoring and reviewing records rather than waiting for a report, correlates with both shorter fraud duration and smaller losses. A trail is what makes active detection possible, because a monitoring rule needs something to monitor.

The AP-specific patterns are well documented in the fraud literature and in every controller's war stories. A vendor's banking details change without a callback verification. A duplicate invoice clears because two people processed the same PDF a week apart. An employee with both vendor-setup rights and payment-release rights creates a supplier only they can see. Each of those is trivially visible in a complete record and nearly invisible without one, which is the core argument for treating accounts payable fraud as a recordkeeping problem as much as a policy problem.

The volume backdrop makes the exposure concrete. 79% of organizations were victims of attempted or actual payments fraud in 2024, according to the Association for Financial Professionals' 2025 Payments Fraud and Control Survey Report, and 58% of organizations reported check fraud activity, which outpaced both ACH and wire fraud. Checks remain the most attacked instrument in AP, and they're also the instrument with the thinnest native trail, which is a large part of why teams moving off paper checks tend to see their evidence quality improve alongside their fraud numbers.

Protect cash flow with modern AP

Modernize AP to cut costs, speed approvals, and mitigate payment risk — gaining the real-time visibility to protect cash flow and scale with confidence.

Download the whitepaper
protect-cashflow-with-ap.jpg

What do auditors and internal controls actually require?

Auditors require evidence that a control operated, on a specific transaction, at a specific time, by a specific person. The standard isn't "we have an approval matrix." It's "show me the approval for this invoice, and show me that the approver had authority at that threshold on that date." For any transaction they sample, the record needs to establish four things:

  • The identity of every person who acted on it, not the department or the system

  • The exact time of each action, in a sequence nobody can rearrange after the fact

  • The prior value of anything that changed, so a correction is visible as a correction

  • Whether the person who approved it was authorized at that amount on that date

For public companies, Section 404 of the Sarbanes-Oxley Act requires management to assess and report annually on the effectiveness of internal control over financial reporting, with an external auditor attesting to that assessment. Private companies inherit similar expectations from lenders, insurers, private equity sponsors, and their own boards, usually without the statutory deadline but with the same demand for attributable evidence.

Third-party exposure raises the bar further. 15% of breaches involved a third party in the most recent Verizon Data Breach Investigations Report, a 68% year-over-year increase, and AP sits at the center of your third-party surface by definition, which is why verifying an AP platform's SOC 2 report belongs in the same file as your own control evidence. When an auditor asks how you'd detect an unauthorized change to a supplier's banking record, the honest answer depends entirely on whether that change was logged with an actor attached.

How does AP automation build the audit trail for you?

Automation builds the trail as a byproduct of doing the work. Every action passes through a system that timestamps it and attaches an identity, so the record accumulates without anyone maintaining it. Nobody screenshots an approval because the approval already exists as a record.

That distinction is the practical case for automating AP ahead of the fraud math or the cost math. Manual processes don't fail to produce records because people are careless; they fail because email and spreadsheets were never built to be evidence. The ERP isn't built for it either, at least not for the part of the lifecycle that happens before the journal entry. Closing that gap is a large share of what teams mean when they talk about using technology to get real control over finance operations.

How does automation record approvals and supplier changes?

Automation records approvals and supplier changes by making them system events rather than correspondence. An approval in an invoice approval workflow carries the approver's identity alongside the threshold rule that routed it there and the timestamp. The same object records delegations and escalations instead of losing them to an out-of-office reply.

Supplier master changes work the same way and matter more. A vendor-master record with change history shows the prior bank account and the new one, along with who submitted the change and who approved it. It also shows whether a verification step ran before payments resumed. Detection speed is the whole point here, because slow detection is expensive on its own terms. The average data breach took 258 days to identify and contain in 2024, per IBM's Cost of a Data Breach Report 2024 — a useful benchmark for how long a compromise can sit inside a process nobody is actively watching.

Automation also enforces the separation the trail is supposed to prove. If the system won't let the person who created a vendor also release its first payment, you don't need to reconstruct whether segregation of duties held. The record shows two identities because the workflow required two.

How does it make month-end close and audits faster?

It makes close and audit faster by turning reconstruction into retrieval. When the trail is queryable, an auditor's sample request becomes a filter rather than a scavenger hunt, and the AP team answers in an afternoon instead of scheduling a week.

Close benefits for the same structural reason. Payment reconciliation is the step where a broken trail hurts most visibly, because matching a bank line back to an invoice requires knowing what was sent, on what rail, and when. At scale that's a lot of matching. The ACH Network alone processed 33.6 billion payments worth $86.2 trillion in 2024, including 7.3 billion B2B payments, up 11.6% year over year, according to Nacha's 2024 network statistics. Electronic volume growing at that rate is good news for evidence quality, since every one of those payments carries structured data a check never did.

Here's the test I'd apply before believing any vendor's claims about this. Ask them to export the full history of a single paid invoice from a production environment, not a demo tenant, and time it. If the answer involves opening a support ticket, the trail exists somewhere in their database but it isn't yours in any useful sense.

What should you look for in an AP audit-trail capability?

Look for a record that is complete, attributable, immutable, and exportable on your terms. Those four properties separate a genuine audit trail from an activity feed, and vendors rarely distinguish between the two in a demo. Six things to verify:

  1. Immutability. Entries can't be edited or deleted, and corrections append rather than overwrite. Ask specifically whether an administrator can remove a log entry.

  2. Full-lifecycle coverage. The trail spans capture through reconciliation, not just the approval steps.

  3. Attribution to individuals. Actions tie to named users, never to a shared service account or a generic "system" actor.

  4. Exportability. You can pull the record yourself, in a format an auditor accepts, without vendor assistance.

  5. Access controls and segregation of duties. Who can view the trail, who can change workflow rules, and whether those are the same people.

  6. Retention. How long entries persist, whether that matches your document retention policy, and what happens to the record if you leave the platform.

The last one gets skipped constantly and deserves more attention than it gets. Your retention obligation doesn't end when a contract does, and "we'll provide an export upon termination" is a promise worth reading in the actual agreement rather than the sales deck. Where card payments are in the mix, the record also has to respect what PCI DSS requires for storing cardholder data.

Does it cover payment delivery and reconciliation, not just approvals?

Most platforms cover approvals well and delivery poorly, so this is the question to press hardest. Buyer reviews across the AP software category repeatedly flag gaps in audit-trail visibility during payment runs, which is exactly the window where a redirected payment or a failed transmission needs to leave a mark.

Ask what the record shows after the approval. A payment that was released, returned by the receiving bank, and retried on a different rail before settling should produce a legible sequence of events, each with a timestamp and a status. If the platform can only tell you that a payment was "sent," you have an approval trail and a payment black box, and the black box is where the money is. Verifying this is one of the more useful questions to bring to a vendor evaluation, alongside the broader set of AP automation practices worth confirming before you sign.

Build a defensible AP audit trail with Corpay

The gap this article keeps circling is the one between your ERP's ledger and everything that happens before an entry lands in it. That's the gap Corpay was built to close. Corpay AP Automation records capture, coding, approval routing, and supplier master changes as attributable events, so the evidence exists whether or not anyone thought to preserve it, and it connects to the four ERPs most of our mid-market and enterprise customers run — NetSuite, Sage Intacct, Microsoft Dynamics 365, and Acumatica.

The delivery half is where our managed model changes the answer. Corpay Payments Automation executes supplier payments across virtual card, ACH, and check, and the record follows the payment through transmission, confirmation, and reconciliation rather than stopping at release. Our team enrolls suppliers and handles the banking-detail verification that manual processes do over email, which means the change history on a vendor record reflects a verification step someone actually performed.

What you get out of it is narrower than a transformation pitch and more useful. Your close stops depending on who remembers what, your auditor's sample request becomes a query, and an unauthorized supplier change has to get past a control that leaves a mark.

Frequently Asked Questions

What is an audit trail?

An audit trail is a chronological, tamper-evident record of who performed an action, what changed, and when. In accounting and finance systems, it links every transaction back to the sequence of events and the individuals that produced it, so a reviewer can verify what happened without relying on recollection.

What is an audit trail in accounting?

In accounting, an audit trail is the documented chain connecting a source document to its final entry in the general ledger. It runs from the original invoice or receipt through coding and adjustment activity, then through the approvals applied and the resulting payment, with every step attributable to a user and a timestamp.

How do you build an audit trail for every expense?

Route every expense through a system that captures the source document, records approvals as events, and attaches receipts to transactions automatically. The mechanism matters more than the policy. If a step happens over email or in a spreadsheet, it won't appear in the record no matter how clearly the policy describes it.

What is a document-signing audit trail?

A document-signing audit trail is the certificate of activity an electronic signature platform produces, showing each signer's identity, the authentication method used, IP address, and the timestamp of every view and signature. In AP, it's most relevant for vendor agreements and payment authorizations that require a signature rather than a workflow approval.

How do you find the audit trail in accounting software?

Most accounting and ERP systems expose it under a reports or administration menu, labeled audit log, activity log, or transaction history, and access is usually restricted to admin or controller roles. What varies is depth. Check whether the log covers master-data changes and payment events or only journal-entry activity, because that difference determines how much of the lifecycle you can actually evidence.

Headshot.JPG

David Luther

Product Marketing Program Manager
David Luther, MBA is a product marketing program manager with years of experience in commercial banking, finance, and technology sectors, with research and writing appearing in financial publications.
AP Automation
Risk management

Smarter payments. Stronger growth. Keep business moving.

Corpay powers payments for 800,000+ businesses worldwide. Let’s build what’s next for yours.

Please select your communication type
Please enter your first name
Please enter your last name
Email address is required
Please enter your company
Please enter your region

By submitting your information through this form, you agree to receive a telephone call or email from a Corpay representative. Your information will be used in accordance with our Privacy Policy.