Earlier this year, SSON Research & Analytics published a financial-leakage report with an unexpected title: How AI has made the recovery audit redundant (SSON R&A/Xelix, 2026).
The recovery audit has been finance's backstop for decades. A specialist firm reviews paid transactions on a contingency fee and returns a share of what it finds. When the research arm of the shared-services industry declares that model redundant, it is worth reading closely. The diagnosis is right, the data is useful, and the conclusion stops one step before the larger opportunity.
The part the report gets right
Three findings carry the argument. Companies lose about 0.35% of total spend to duplicate payments, invoice errors, missing credit notes, and fraud. That is $53 billion a year across the eligible market, with losses reaching 2% of spend where controls are weakest (SSON/Xelix analysis of 481 million invoices, 2026). The classic recovery audit reclaims a portion of that at contingency fees of 15–25%, covers roughly the top 20% of transactions, and delivers findings months after the money moved (SSON R&A/Xelix, 2026).
The queues feeding those losses are structural. The median AP team sees 11–14% of invoices become manual exceptions (SSON R&A, 2026), which is where duplicate detection weakens and discrepancies get approved under deadline pressure. The 2026 AP exception-rate benchmarks show how quickly that workload compounds.
The critique underneath those numbers is one we share: sampling was never a methodology. It was a capacity constraint. Human auditors cannot read everything, so they focus on the largest vendors and invoices. Once software can investigate the full population, the annual sampled cleanup loses its reason to exist.
The question prevention still has to answer
The report's replacement for the recovery audit is prevention: AI screening transactions before payment. Prevention is the better outcome. The important question is what the screening reads, and much of the category still begins and ends with the ledger.
The ledger is a summary. A near-duplicate with one transposed digit, the same invoice paid by two group entities, or a credit note netted on a supplier statement that nobody opens may not announce itself in a ledger row. Manual reconciliation reaches only the top 10–15% of suppliers, leaving 85–90% unchecked (SSON/Xelix, 2026). The evidence sits in the documents: the invoice against the delivery note, the deduction against the promotion agreement, and the statement against the full ledger.
AI-generated fraud makes that distinction urgent. A convincing fake invoice can produce a clean ledger entry because the document was designed to pass the expected checks. The fraud is that the document was never real. Detecting it requires reading the document and cross-checking its claims against deliveries, purchase orders, vendor history, and payment behavior. The guide to AI-generated invoice fraud sets out those signals and the controls around them.
The larger exposure sits beyond AP
Accounts payable is the smallest, best-lit corner of leakage. Compare the report's 0.35% of spend with the rest of the stack: 1–3% of revenue written off through customer deductions (Serrala, 2026), with 20–30% of deductions never disputed (ProcIndex, 2026); 5–7% of freight spend lost to overcharges (Capgemini); and a 3–5% gross-sales execution gap in gross-to-net processes (DSG/Cavallo, 2026).
If AI can now audit the full population, the answer should not inherit the old model's narrowest scope. The same approach belongs in deduction claims, freight bills, rebate settlements, and other processes where the documents are messy and per-line amounts are too small for manual review. See the 2026 financial leakage benchmarks by industry for an AP starting point, then the cash leakage guide for the broader process map.
What should replace the annual recovery audit?
A lookback audit should become the beginning of a continuous control, not an annual purchase. Agents can work read-only from 12–24 months of exports, check the scoped population against source documents, and return findings while claims are still recoverable. Claims filed within 30 days win 40–60% of the time, while claims after 60 days win fewer than 20% (CRF Research).
When the lookback ends, the useful checks can move in front of the payment run and the write-off decision. The finance team keeps approval over critical actions, while agents investigate each case and assemble the evidence. Recovery and prevention become two stages of the same control instead of separate purchases.
The practical test is your own transaction history. A lookback audit is read-only, uses exports rather than a production integration, and returns evidence with every finding. The recovery-audit guide explains the process, and the comparison page covers when a traditional firm remains the right choice.
Put it into practice
Automate the workflow behind this article.
Bring your files and business rules. Cloudsquid turns them into an auditable AI workflow in weeks, not quarters.
Book a demo