Where does the money actually leak?
Leakage is the same control gap appearing in several finance processes:
| Process | Typical leakage | What it looks like |
|---|---|---|
| Accounts payable | 0.3–0.7% of AP spend (SSON/Xelix analysis of 481M invoices, 2026) | Duplicate and near-duplicate payments, unapplied credit notes, invoice pricing that differs from contracts |
| Deductions and receivables | 1–3% of revenue written off (Serrala, 2026); 20–30% of deductions never disputed (ProcIndex, 2026) | Invalid short-pays absorbed because the workup costs more than the claim |
| Freight | 5–7% of transportation spend (Capgemini); 10–25% of invoices contain errors (Trax/NSSTC) | Rate-card mismatches, fuel-surcharge errors, and surcharges that were not rolled back |
| Gross-to-net and trade | 3–5% gross-sales execution gap (DSG/Cavallo, 2026); 59% of trade promotions lose money (McKinsey) | Promotion settlements that do not match agreements, rebate double-dips, and pricing drift |
Applied to a $1B enterprise, those sources imply an annual range of $50M–$170M (cross-source synthesis, 2026). Most control programs focus on accounts payable even though it is only one part of the exposure. The relevant operating views are accounts payable controls, deductions and order-to-cash controls, and controlling and close investigations.
Why don't our controls catch it?
Most controls read the ledger, but the ledger is a summary. The investigation usually depends on material outside it: an invoice PDF that does not match the delivery note, a deduction that does not match the promotion agreement, or a freight line that does not match the rate card.
- Exact-match logic. ERP duplicate checks compare fields such as invoice number and vendor. Near-duplicates, vendor-master duplicates, and the same invoice paid by two entities can pass those checks (SSON/Xelix, 2026).
- Sampling. Manual statement reconciliation typically reaches the top 10–15% of suppliers, leaving 85–90% unchecked (SSON/Xelix, 2026).
- Volume. Median AP exception rates run at 11–14% of invoices (SSON R&A, 2026). Teams have to process the queue, which leaves little time for investigation.
How do you find it and prevent it from recurring?
Start with a lookback recovery audit. It works from read-only exports and checks the scoped population from the last 12–24 months against source documents. Every finding should arrive with evidence and a quantified recovery opportunity. The same checks can then run before payment, deduction write-off, or claim approval, with finance retaining approval over critical actions.
The lookback audit FAQ explains the data, timing, controls, and commercial model in more detail.