Skip to main content
BlogSeptember 10, 202611 min read

How to set up an AP approval workflow that auditors accept

Design an AP approval workflow: thresholds, approvers by amount and department, Slack-native approvals, and a logged record of every decision.

Zuny FesterBy Zuny Fester, Head of Operations and Marketing
Reviewed by Zuny Fester
Published Editorial policy

Part of the accounts payable and invoice processing guide.

How to set up an AP approval workflow that auditors accept

To set up an AP approval workflow that auditors accept, write down an approval matrix by amount and department, enforce it with fixed routing rules, separate who enters, approves, and pays each bill, and log every decision with the approver's name, the time, and the exact version of the bill they approved. Auditors do not test whether your workflow is fast. They test whether every payment in their sample was approved by someone with the authority to approve it, before the money left.

This guide gives you the approval matrix, the rules that make it defensible, how it runs in QuickBooks and NetSuite, and how the same workflow looks on a Loopfour Studio canvas with Slack-native approvals.

Key takeaways

• An AP approval workflow is a documented delegation of authority enforced by routing rules: which invoices need approval, from whom, in what order, and at what amounts.

• Auditors test design and operation. Design means a written approval matrix. Operation means every sampled bill shows an authorized approval before payment.

• Six rules make approvals defensible: no self-approval, separate entry, approval, and payment, re-approval on any edit, backup approvers, split-invoice detection, and a separate approval for vendor bank changes.

• Native tools cover the basics. QuickBooks approval workflows support conditions on amount, vendor, and location with up to five layers; NetSuite SuiteApprovals pairs rule criteria with an approval hierarchy.

• Loopfour, the deterministic finance workflow automation platform, runs the matrix as predefined rules and sends approvals to Slack, with every decision recorded in the execution tree.

What is an AP approval workflow?

An AP approval workflow is the set of rules that routes each supplier invoice to the right person for authorization before it is paid. It turns your delegation of authority, the document that says who can commit company money and up to what amount, into something the system enforces.

A good workflow answers four questions for every bill:

• Does this bill need approval at all? A PO-backed invoice that passed a three-way match within tolerance may not.

• Who approves it? Usually the budget owner for the department or cost center charged.

• How many approvals? More layers as the amount rises.

• What happens if no one responds? Escalation to a backup, not silent expiry.

What auditors look for in an AP approval workflow

Auditors look for a documented control that is designed properly and operated consistently across the whole period. They will read your policy, then pull a sample of paid bills and trace each one back to its approval.

What auditors testWhat they ask forWhat fails the test
DesignThe written approval matrix and delegation of authorityApproval rules that exist only in someone's head
AuthorizationEvidence each sampled bill was approved by an authorized personApprover not on the matrix, or above their limit
TimingApproval timestamp before payment dateApprovals recorded after the payment ran
Segregation of dutiesUser access showing entry, approval, and payment are separatedOne person who can create, approve, and pay
IntegrityProof the approved bill is the one that was paidAmount or vendor edited after approval, with no re-approval
Change controlHistory of changes to approval rules and who made themRules edited mid-year with no record

The integrity row is the easiest one to miss. If someone can change the amount on a bill after it was approved, the approval no longer proves anything about the payment.

The approval matrix by amount and department

The approval matrix is the core artifact: a table that maps each combination of department and amount to the required approvers. Here is an illustrative matrix for a SaaS company. Set your own thresholds from your board-approved delegation of authority.

Amount (per bill)Engineering and productSales and marketingG&A and financePO-backed, matched within tolerance
Under $2,500Engineering managerMarketing managerControllerNo additional approval
$2,500 to $25,000VP EngineeringVP Marketing or VP SalesControllerNo additional approval
$25,000 to $100,000VP Engineering, then CFOVP, then CFOController, then CFOCFO
Over $100,000VP, CFO, then CEOVP, CFO, then CEOController, CFO, then CEOCFO, then CEO

Three overlays apply across every cell:

• New vendor's first bill: add the controller, whatever the amount.

• Non-PO bill over $10,000: add finance review, because nothing upstream checked it.

• Any change to vendor bank details: separate approval by someone outside AP before the next payment.

A fractional CFO firm running 12 clients will want one matrix template per client, with thresholds scaled to each client's size. The structure stays the same; only the numbers change.

Six rules that make approvals defensible

The matrix says who approves. These rules make sure the approval means something.

• No self-approval. The requester, the person who entered the bill, and the approver must be different people. If the only eligible approver is also the requester, route to the next level up.

• Separate entry, approval, and payment. Three roles, three people. QuickBooks' Bill Clerk, Bill Approver, and Bill Payer roles map directly to this separation.

• Re-approve on edit. Any change to amount, vendor, or GL coding after approval sends the bill back for approval. The record should show both versions.

• Backup approvers with escalation. Every approver has a named backup. After a set time, the request escalates instead of sitting. QuickBooks, for example, automatically denies bills not reviewed within 30 days.

• Split-invoice detection. Flag multiple bills from the same vendor, close in date, that together cross a threshold one bill alone would not. Splitting is the most basic way to avoid a higher approval.

• Bank detail changes are their own approval. A new remittance account is a payment-fraud signal. It needs verification outside the invoice itself, by someone who cannot also release the payment.

These rules also close gaps that lead to duplicate vendor payments, because the same controls that stop an unapproved bill also stop a second copy of an approved one.

How to set it up in QuickBooks and NetSuite

Both ledgers can enforce a basic matrix natively; the gaps are in overlays, integrity rules, and where approvers work.

• QuickBooks Online. Intuit's documentation says bill approval workflows are available to QuickBooks Bill Pay Elite customers, and payment release workflows to Bill Pay Elite or QuickBooks Online Advanced. Conditions can use amount, vendor, location, or a combination, with up to five approval layers, and each layer can require one, two, or all members of a group. Department-based routing needs locations or a workaround. See how to set up QuickBooks AP automation for the full setup.

• NetSuite. SuiteApprovals lets you define approval rules for vendor bills. Oracle's documentation describes an approval rule as a unique set of criteria plus an approval hierarchy that together define how records get approved. NetSuite also offers the 3 Way Match Vendor Bill Approval workflow for PO-backed bills.

Where native tools usually need help: approvers who don't log in to the ERP, overlays like "new vendor" or "bank change," split-invoice detection, and a single approval log across several entities.

Book a workflow review to see your own approval matrix running as a workflow.

The workflow on the canvas

In Loopfour Studio, the approval workflow is a set of blocks on a visual canvas, each doing one job in a fixed order. Here is the flow for a single bill:

• Trigger: a new bill arrives from the AP inbox, QuickBooks, NetSuite, or Bill.com.

• Extract: the Invoice Agent reads the PDF; any read below the confidence threshold goes to an AP reviewer before routing.

• Validate: fixed rules check vendor status, duplicates, and bank details against the vendor master.

• Look up the matrix: the department and amount select the required approvers; overlays add the controller or finance review.

• Check segregation: the requester and the person who entered the bill are removed from the approver list.

• Split check: recent bills from the same vendor are summed against the threshold.

• Approve in Slack: each approver gets the bill, PDF, coding, and match status in Slack with Approve and Reject buttons; layers run in order.

• Escalate: no response within the set window routes to the backup approver.

• Lock and post: the approved version is recorded; the bill posts or is released for payment; any later edit reopens approval.

• Record: the execution tree stores every input, rule result, approver, timestamp, and the approved version.

The routing is deterministic. The same bill with the same inputs goes to the same approvers every time, which is exactly what an auditor re-performing the control expects. AI is used only in step two, to read the document, and a person reviews every low-confidence read. An AI agent decides what to do at runtime. Loopfour does only what was approved.

Audit questionEmail-based approvalsLoopfour workflow
Who approved this bill?Search inboxes for a replyNamed approver in the execution tree
Were they authorized?Compare manually to the matrixMatrix lookup recorded with the run
Before payment?Compare email date to payment dateApproval timestamp precedes release by design
Is this the version approved?Often unknowableApproved version recorded; edits reopen approval

For more on what a complete record looks like, see audit trails for automated finance.

How to choose an approval approach

Choose based on how many approvers sit outside the ERP and how many entities you run.

• Native ERP approvals fit a single entity where approvers already work in QuickBooks or NetSuite and the matrix is mostly amount-based.

• Horizontal automation platforms can route approvals into Slack or email with a lot of flexibility. Your team owns the rules, the segregation checks, and the proof that each run followed the matrix.

• Deterministic, finance-specific automation encodes the matrix, overlays, and integrity rules once, and runs them identically for every bill and every entity. Loopfour builds, monitors, and maintains the workflow, so rule changes go through one accountable owner instead of ad hoc edits.

Frequently asked questions

How do I set up an AP approval workflow? Write an approval matrix by amount and department from your delegation of authority, add overlays for new vendors, non-PO bills, and bank changes, then enforce it with routing rules in your ERP or a workflow tool. Separate entry, approval, and payment, and log every decision.

What do auditors check in an AP approval workflow? Auditors review the written approval matrix, then sample paid bills to confirm each was approved by an authorized person before payment. They also check segregation of duties, whether bills were edited after approval, and whether approval rules changed during the period.

How many approval levels should an AP workflow have? Most teams use one level for small bills and add a level at each major threshold, typically reaching the CFO or CEO for the largest amounts. QuickBooks supports up to five approval layers in its native workflow.

Can approvals happen in Slack and still satisfy auditors? Yes, if the approval is tied to a specific bill version, the approver is authorized under the matrix, and the decision is logged with a timestamp before payment. Loopfour records each Slack approval in the execution tree with those details.

What is split-invoice detection? Split-invoice detection flags several bills from the same vendor, close in date, that together exceed an approval threshold none of them crosses alone. It prevents approvals from being avoided by breaking one purchase into smaller bills.

Should PO-backed invoices need approval? Many teams skip extra approval when a PO-backed invoice matches its purchase order and receipt within tolerance, because the PO was already approved. Large amounts, new vendors, and anything outside tolerance should still route to an approver.

Conclusion

An AP approval workflow that auditors accept is a written approval matrix, enforced by fixed routing, with separated duties, re-approval on edits, and a complete record of who approved what and when. Build the matrix by amount and department, add the overlays that catch risk, and run it deterministically so the same bill always goes to the same approvers. That is a control your auditors can re-perform and trust.

Tell us the one workflow your team dreads. We will show it running — deterministic, permissioned, and auditable.

Book a demo.

Sources

• Intuit QuickBooks, Set up and use bill approval and payment release workflows

• Intuit QuickBooks, Set up roles and permissions for paying bills

• Oracle NetSuite, Defining approval rules (SuiteApprovals)

• How to set up QuickBooks AP automation

• Audit trails for automated finance: how to keep every run inspectable

• How to do three-way matching for AP invoices

• How to prevent duplicate vendor payments

• AI in finance: the compliance risks finance leaders can't ignore

Sources

  1. Intuit QuickBooks, Set up and use bill approval and payment release workflows (opens in a new tab).
  2. Intuit QuickBooks, Set up roles and permissions for paying bills (opens in a new tab).
  3. Oracle NetSuite, Defining approval rules (SuiteApprovals) (opens in a new tab).