Document Management for Accounts Payable: Eliminating Invoice Processing Bottlenecks

Take Control of Your Records

Get a free consultation to simplify storage, scanning, retrieval, and secure destruction.

Get Started

Accounts payable document management is the practice of capturing, indexing, storing and retrieving the documents behind every payment: the invoice, the purchase order, the receiving record, the contract and the remittance. The IRS does not care how fast the approval workflow runs. It cares whether you can produce a legible, indexed record that ties back to the general ledger.

Most accounts payable improvement projects start with the approval chain. Someone maps how long an invoice sits with each approver, adds reminders, and reports a shorter cycle time. Six months later the close is still late, the auditors still send the same request list, and nobody can find the receiving document for a disputed shipment from two years ago.

The approval chain was never the slow part. The document was. An invoice that arrives as a scanned attachment in a shared mailbox, gets renamed by whoever opened it, and ends up in a folder tree that made sense to one person in 2021 is a retrieval problem, and retrieval is what audits, disputes, and fraud investigations run on.

This article covers what the rules actually require of accounts payable documents, what an imaged invoice has to look like before you are allowed to shred the paper, and how to design the document side of AP so that the audit and the dispute both get easier instead of only the approval queue.

What Actually Creates the Bottleneck

The bottleneck is almost never approval latency. It is the time spent finding the supporting document, reconciling it against a mismatched purchase order, and proving that what arrived matches what was billed. Every one of those steps is a document retrieval problem, and every one of them repeats at close, at audit, and at dispute.

Walk an exception backwards and the pattern is consistent. An invoice fails a three way match. Someone has to pull the purchase order, the receiving record and the contract to work out which of the three is wrong. If those three documents live in three systems, owned by three departments, with three different naming conventions, the exception is not resolved in the time it takes to read them. It is resolved in the time it takes to collect them.

The same collection cost shows up again months later, when the auditor asks for a sample of invoices over a threshold and the supporting documentation for each. And again years later, when a vendor disputes a payment, or a tax authority questions a deduction, and the person who built the folder structure has left.

Approval automation reduces one of those costs, once. Document control reduces all of them, every time.

How Long You Have to Keep Invoices

There is no single number. Federal tax rules tie retention to the period of limitations for the return the document supports, which is generally three years but extends to six when income is substantially understated and has no limit at all for a fraudulent or unfiled return. Public companies carry a separate seven year rule for audit records. State and contractual obligations sit on top.

The governing rule for tax purposes is 26 CFR 1.6001-1, and its retention standard is written as a condition rather than a period. Records must be kept “so long as the contents thereof may become material in the administration of any internal revenue law.” The IRS translates that into practice in Publication 583, which ties the retention of supporting records to the period of limitations for the return in question: generally three years, six years where income that should have been reported is more than twenty five percent of the gross income shown, and no limit where a return was fraudulent or was never filed.

That is why a flat “keep everything seven years” policy is both wrong and expensive. It is wrong because the six year and unlimited cases are the ones where you actually need the document, and a seven year default will not protect you in the unlimited case. It is expensive because it applies the longest common period to the entire population rather than to the records that earn it.

Two other clocks run alongside. Issuers and their auditors are covered by 17 CFR 210.2-06, which requires audit and review records to be retained for seven years after the accountant concludes the audit or review. And 18 U.S.C. 1519, added by Sarbanes-Oxley, makes knowingly destroying or altering a record with intent to impede a federal investigation punishable by up to twenty years. That statute is the reason a records program needs a working legal hold, not just a retention schedule. A schedule that disposes on time is a control. A schedule that disposes on time through an active investigation is a felony exposure.

The practical output of all this is a retention schedule that assigns periods by record class and by the obligation that drives them, not a single number applied to a folder. Our business records retention guide works through the industry by industry version of that exercise, and the records retention guidelines reference covers the federal and state layers.

What the IRS Requires of a Scanned Invoice

The IRS will accept an imaged invoice in place of the paper original, and will allow you to destroy the paper, but only if the storage system meets specific conditions: controls that protect integrity, a high degree of legibility on screen and in hardcopy, an indexing and retrieval system, and an audit trail that cross references the general ledger to the source document.

This is the part most AP scanning projects get wrong, because the requirement is not “scan it” but “operate a system.” The conditions are set out in Revenue Procedure 97-22, which remains the operative guidance for imaged records and is still cited as such on the IRS page on automated records. Four requirements do the work.

  • Controls. The system needs reasonable controls to ensure the integrity, accuracy and reliability of stored records, and separate controls to prevent and detect unauthorized creation, addition, alteration, deletion or deterioration.
  • Legibility. Records must exhibit a high degree of legibility and readability both on a display and when reproduced in hardcopy. A compressed scan that loses a handwritten approval initial fails this test.
  • Indexing and retrieval. The system must include a retrieval system with an indexing system, and the ability to produce legible hardcopies. Filenames in a folder tree are not an indexing system.
  • Audit trail. Stored records and the taxpayer’s books must be cross referenced so that there is an audit trail between the general ledger and the source documents. This is the requirement that turns scanning into records management.

Only once those conditions are met and tested does the revenue procedure permit destruction of the paper. Its own language is conditional: the taxpayer must have completed testing that establishes the system reproduces records in compliance with the procedure, and must have instituted procedures that ensure continued compliance. Destroying the originals first and documenting the system later inverts the order the rule requires.

One distinction worth keeping straight, because it causes real confusion in AP projects. Revenue Procedure 98-25 governs machine sensible records, meaning computer generated accounting data. The IRS states plainly that machine sensible records “do not include paper records or paper records that have been converted to an electronic storage medium.” A scanned vendor invoice is an imaged record under 97-22. The ERP transaction that pays it is machine sensible data under 98-25. They are different obligations on different objects, and a project that satisfies one has not satisfied the other.

In practice this is why the document scanning step and the records management step are one project rather than two. Capture without indexing produces a searchable pile.

The Audit Trail Is the Deliverable

The document an auditor asks for is rarely the invoice on its own. It is the invoice plus the purchase order, the receiving evidence, the approval, and the payment record, linked to a general ledger entry. A system that stores the invoice but not the link between them has stored the least useful half.

Read the audit trail requirement in the revenue procedure literally and it describes a data model, not a filing cabinet. There has to be a path from a line in the general ledger to the source document that supports it, and back. That means an index built on the identifiers the business already uses: vendor, purchase order number, invoice number, GL account, period, entity, and the payment reference.

Building the index on those identifiers rather than on where the file happened to land has a second effect that matters more day to day. It makes the exception queue self serving. A three way match failure can pull all four related documents on the purchase order number without anyone opening a folder, and the reconciliation becomes reading rather than collecting.

It also makes disposition possible. You cannot apply a retention schedule to records you cannot classify, and you cannot classify records that are only identified by filename. Every organization that has tried to clean up an AP archive has hit this wall: the retention rule is clear, and the population it applies to is unknowable without opening every file. Indexing at capture is what avoids paying that bill later.

Where AP Documents Meet Fraud Control

Accounts payable is where an organization sends money out on the strength of a document. Payments fraud is now close to universal in reported experience, tips remain the leading detection channel, and both facts point at the same control: someone other than the person processing the payment must be able to pull the supporting documents quickly.

The exposure is well measured. The 2026 AFP Payments Fraud and Control Survey, released in April 2026, reports that seventy six percent of organizations in the United States experienced attempted or actual payments fraud in 2025, that seventy four percent were affected by business email compromise, and that fifty eight percent report checks are subject to fraud. The FBI’s 2025 Internet Crime Report puts reported business email compromise losses at 3,046,598,558 dollars across 24,768 complaints.

Business email compromise in an AP context is a document attack. The mechanism is a plausible invoice or a plausible change of banking details, delivered through a channel the AP team already trusts. The control that catches it is comparison against the record of what the vendor previously submitted, which only works if that record is retrievable in the moment rather than at the end of a search.

Detection data points the same way. The Association of Certified Fraud Examiners’ Occupational Fraud 2026: A Report to the Nations, published in May 2026, reports a median loss per case of 104,000 dollars, an estimate from certified fraud examiners that a typical organization loses five percent of revenue to fraud each year, and that forty three percent of frauds were detected after a tip, with more than half of those tips coming from employees.

A tip is only actionable if it can be checked. When someone raises a concern about a vendor, the investigation begins with pulling every document associated with that vendor across several years. In an indexed archive that is a query. In a folder tree it is a project, and projects get deprioritized.

What About E-Invoicing Mandates

There is no United States federal mandate requiring electronic invoicing between private businesses. In the European Union, the VAT in the Digital Age package entered into force on 14 April 2025 and allows member states to impose national e-invoicing mandates, but the EU wide digital reporting requirement for cross border business to business transactions does not apply until 1 July 2030.

This matters for two reasons. The first is that a US company with no European operations is under no legal deadline to move off paper or PDF invoices, and should not be sold one. The second is that a US company with European subsidiaries may already be inside a national mandate today, because the ViDA package made those national mandates easier to adopt from the day it entered into force, while the harmonized cross border obligation waits until 2030 and full alignment of existing national systems is set for 1 January 2035.

The planning consequence is a document one. Whatever format invoices arrive in over the next decade, the retention obligation attaches to the record, and organizations will spend those years operating a mixed estate: paper originals from prior years, PDF and image files from the current period, and structured electronic invoices from some jurisdictions. A retrieval system that only understands one of those three is a system that will be replaced.

Designing the Document Side of AP

Five decisions do most of the work: classify the record types, set retention by obligation rather than by folder, index on business identifiers at the point of capture, split the archive into a fast tier and a deep tier, and build the legal hold before you build the disposition.

Classify before you capture. Accounts payable is not one record class. Invoices, purchase orders, receiving documents, vendor contracts, W-9 forms, 1099 filings, remittance advices and banking change requests carry different obligations and different sensitivity. A classification scheme decided at the start costs a design meeting. Decided later, it costs a re-indexing project.

Set retention by obligation. Each class inherits its period from the rule that governs it: the period of limitations for tax supporting documents, the seven year audit record rule where it applies, contractual retention where a customer or a lender imposes one, and any state requirement. Document which obligation drives each period. When the schedule is challenged, that mapping is the defence. Our records retention policy guide covers how to build and document that mapping.

Index at capture. Vendor, purchase order, invoice number, GL account, entity, period, payment reference. Indexing later means opening files, and opening files means the project stalls at the volume where it would have started paying off.

Split fast tier from deep tier. The current period and any open dispute need instant access. Records past their active life need survivability and a defensible chain of custody more than they need speed. Splitting them lets you buy the right thing for each: digital access for the fast tier, secure offsite storage with logged retrieval for the deep tier. Trying to give everything the same service level is how archives get expensive enough that nobody cleans them up.

Build the hold before the disposition. Given 18 U.S.C. 1519, the ability to suspend disposition on a defined population, and to prove you suspended it, is the control that makes automated disposition safe. Turn on disposition without it and the schedule becomes a liability rather than a policy.

Where the AP process itself needs workflow, routing and approval logic on top of the document layer, that sits with the content services platform of GRM’s sister company, VisualVault, described on the content services platform page. The records obligations discussed here attach to the documents regardless of which system routes them.

Frequently Asked Questions

How long should a company keep accounts payable invoices?

Long enough to cover the period of limitations for the tax return the invoice supports, which under IRS guidance is generally three years, extends to six years where reported income was understated by more than twenty five percent, and has no limit for a fraudulent or unfiled return. Public companies and their auditors carry a separate seven year retention requirement for audit and review records under SEC rules. Contracts, grants and state rules can impose longer periods, so the defensible answer is a schedule that assigns a period per record class and records which obligation set it.

Can you throw away paper invoices after scanning them?

Yes, if the electronic storage system meets the IRS conditions first. Revenue Procedure 97-22 permits destruction of the original hardcopy records only after the taxpayer has completed testing showing the system reproduces records in compliance with the procedure, and has put procedures in place to ensure continued compliance. Those conditions include integrity controls, a high degree of legibility on screen and in print, an indexing and retrieval system, and an audit trail linking the general ledger to the source documents. Scanning alone does not satisfy them.

What is the difference between an imaged record and a machine sensible record?

An imaged record is a paper document converted to an electronic form, such as a scanned vendor invoice, and it falls under Revenue Procedure 97-22. A machine sensible record is computer generated accounting data, such as the ERP transaction that records the payment, and it falls under Revenue Procedure 98-25. The IRS states that machine sensible records do not include paper records that have been converted to an electronic storage medium. The two carry different requirements, and satisfying one does not satisfy the other.

Does a three way match require keeping the receiving document?

Yes, in any practical sense. A three way match compares the invoice, the purchase order and the receiving evidence, so the match is only reproducible later if all three are retained and linked. Auditors testing controls over expenditure typically request the supporting set rather than the invoice alone, and a disputed delivery is resolved by producing the receiving record. Keeping the invoice while discarding the receiving evidence retains the claim and discards the proof.

No. There is no United States federal mandate requiring electronic invoicing between private businesses. Organizations with operations in the European Union may be subject to national e-invoicing mandates, which the VAT in the Digital Age package made easier for member states to adopt when it entered into force on 14 April 2025, while the EU wide digital reporting requirement for cross border business to business transactions applies from 1 July 2030. Retention obligations apply to the record whatever format it arrives in.

Getting the Document Layer Right

An accounts payable program that shortens approval time and leaves the archive untouched has moved the visible part of the problem and left the expensive part alone. The audit request, the vendor dispute and the fraud investigation all arrive as retrieval problems, and they arrive years after the workflow project closed. GRM builds that layer: high volume scanning with indexing on your own business identifiers, enterprise records management with retention schedules and legal hold, and secure offsite storage with logged retrieval for what has to survive. Request a quote to work through your AP record classes and retention schedule with us.