A three way match, purchase order, goods receipt, supplier invoice, is only as reliable as the approval workflow feeding it. Most procurement systems are built for the smooth, uninterrupted case, and quietly break down around the everyday disruptions: someone on leave, small recurring costs, or a Board Chair who doesn't have a login at all. A properly designed system builds those situations in from the start, rather than leaving staff to invent workarounds.
A three way match is one of the more reliable controls in any finance function, checking that the purchase order, what was actually received, and the supplier invoice all agree before anything gets paid. Most organisations get that basic structure right. Where it tends to fall apart is the approval workflow feeding into it, which is usually built for a tidy, uninterrupted operation and starts breaking down the moment real life gets in the way.
Where the workarounds actually start
When the approval process creates too much friction, people find their own way around it, and every workaround chips away at a control that was otherwise doing its job. Staff start raising a purchase order after the supplier invoice has already arrived, which quietly removes any real commitment accounting or budget visibility. A requisition sits untouched because the named approver is on leave, delaying a payment nobody meant to delay. Or people just default to a verbal sign off, an email thread, or a shared login, none of which holds up well under audit.
Umbrella POs for the small, regular stuff
Not every purchase needs its own PO and a full sign off chain. Forcing that process onto a utility bill, a regular consumable order, or a routine software subscription creates exactly the kind of friction that pushes people to skip the system entirely for anything that feels too small to bother with.
A properly scoped blanket or umbrella purchase order solves this cleanly: an approved limit set for a specific supplier and category over a defined period, with incoming invoices matched against it within a set tolerance. The budget commitment stays visible in the ledger the whole time, without a fresh approval cycle for every small, regular transaction.
Building delegation in, rather than working around it
A workflow that assumes the named approver is always available is going to fail regularly, because people take leave. The fix is to build coverage into the system itself: requisitions automatically reroute to a secondary approver based on the organisation's Schedule of Delegated Authority, and anything left unactioned for too long escalates automatically to someone with the authority to clear it. For the genuine edge cases that fall outside even that, a documented release valve, usually a Financial Controller or CFO with the authority to clear a trapped requisition, with the override properly logged, stops the whole process grinding to a halt over one absence.
When the Board Chair doesn't have a login
Above a certain value, a Schedule of Delegated Authority will usually require Board or Chair approval, not just an executive sign off. In the NFP and education sectors specifically, a volunteer Chair very rarely has an active login to the finance system, and there's rarely a good reason to build one just for occasional high value approvals.
Letting an executive approve that spend under their own system credentials, on the basis that the Chair approved it offline, is exactly the kind of thing an audit picks up and a board doesn't want to explain. The better approach documents the governance path properly: the Chair provides written authorisation, by email or digital signature, the CFO then completes the system approval step and attaches that authorisation directly to the record, and the ledger carries a clear, permanent trail showing exactly who approved what, and how.
Design for how things actually work, not just the ideal case
Good financial governance isn't about building a rigid process that only survives when everything goes to plan. It's building the realistic disruptions in from the start, delegation for leave, a properly scoped umbrella PO for the small stuff, a genuine release valve for the edge cases, and a clear, audit ready path for the approvals that have to happen outside the system entirely.
If your procurement process only works when everyone's in the office and available, that's worth redesigning before it causes a real problem.
Contact us