About

How AI Changes the Procure-to-Pay Value Stream

How accounts payable moves from typing every invoice by hand to posting the standard ones automatically, plus what has to stay under human control once a process ends in a payment.
Sebastian Bitter
Sebastian Bitter
21.8.2026
Procure-to-Pay carries a need from the first request through to a paid supplier. Unlike the streams covered earlier in this series it ends in money leaving the company, which is why several of its controls are set by law rather than by preference. Two cases carry the levels. Veolia sits at assistive, where AI reads the invoice and staff check every document the extraction was unsure about. Heineken sits at agentic, with about 210,000 of 230,000 electronic invoices posted with nobody looking at them. What makes that safe is a stopping rule with four named triggers. The release of the money stays attributable to a named person, because COSO, SOX, ISA and the IDW standards all require segregation of duties and an authorisation an auditor can trace. Almost every published example in this field comes from a software supplier writing about its own customer, which the post states at each case. The post also names where the evidence stops. Almost everything documented in this stream sits from the invoice onwards, and the single case in the front half is a supplier negotiation at Walmart.

The stream today and where AI takes it

Procure-to-Pay carries a need from the moment someone in the business raises it to the moment the supplier is paid and the posting is documented well enough to survive an audit. Every company runs this stream. It is highly rule-based and the volume is high, so automation reaches it earlier than most processes.
In its classical form the work runs as six steps, each carried out by a person and each producing a hand-off to the next. Someone raises a purchase requisition. Someone approves it against budget. A buyer selects a supplier and places the order. The goods receipt is recorded. The invoice is checked and matched against order and receipt by hand. Finally the payment is released under a four-eyes rule and posted.
The pain sits in the paper and in the exceptions, in roughly equal measure, which is why faster software on its own does not fix it. The invoice arrives as a PDF and somebody types it in. A price that does not match sets off a chain of emails. Early-payment discounts lapse while the approval sits in an inbox. As in the other streams, the delay lives in the hand-offs rather than in the work.
What separates this stream from the two before it is what happens at the end of it. Idea-to-Market ends in a release that can be rolled back. Issue-to-Resolution ends in a customer who is either satisfied or not. Procure-to-Pay ends in money leaving the company, so a mistake here is a loss rather than a quality problem, often discovered weeks later. That is why the controls here are not a matter of taste. A company that removes them fails an audit.
AI enters this stream where the paper enters it, roughly halfway through, because the front half was served long ago. The requisition, the approval and the order were automated long before this wave, by catalogues, approval limits and order forms, where the data is structured because somebody designed it that way. The first thing to arrive unstructured and from outside is the supplier's invoice. So reading the document and pre-filling the fields go first, then the matching, because that is where the same work repeats and the benefit shows up soonest. The human moves from processing every invoice to deciding the ones the system stopped. What does not move is the release of the money. Working out why is the most interesting part of this stream.
AI-WS Bp3 Fig1 Procure-to-Pay EN
Figure 1: Procure-to-Pay across the four levels. Across the four levels the work moves forward while the human moves backward, from doing every step to deciding only the ones that stopped. Read each row as the same stream at a different level, left to right from request to payment. The bottom row has no company example behind it, for the reason the section on the autonomous level explains.

Level by level, shown by real cases

All three cases below therefore start where the invoice arrives and what the front half has of its own comes after the walk. Each level comes with an example, its headline number and the point where that number stops holding. The classical level is the starting point described above, with no AI in the flow, so the walk begins at assistive.

Assistive: the AI reads the invoice, the human posts it

At the assistive level the six steps stay exactly where they are while AI works inside each one, which makes this the stage most companies reach first and the one that changes least about how the department is organised. The system suggests a catalogue item and an account assignment, summarises what is being approved, flags anything unusual, then reads the incoming invoice and proposes the match. The human checks each proposal and posts.
The example is Veolia Group Shared Services and its case starts at the point where the invoice arrives. Everything before that point, the requisition, the approval and the order, stays as the classical lane described it. Veolia runs accounts payable for 30 group entities from a single centre using software from Rossum, a supplier of intelligent document processing. That term describes the reading step. The system takes an invoice as a PDF or a scan and works out which number is the total, which is the tax and which supplier it belongs to, then proposes the posting. Staff the company calls AI associates check every document the extraction was unsure about, so nothing reaches the ERP system unchecked. The reported effect is eight times faster processing per document plus about 90 percent less manual data entry.
Those two figures come from the software supplier's own case study about its own customer. No independent confirmation exists, so they are best read as a claim rather than a measurement.
Putting a money value on that gain means choosing a baseline, which is where the published figures stop being comparable with each other. The firmest anchor is an official one. The German finance ministry, costing its own e-invoicing mandate, attributes about 1.36 billion euros of annual bureaucracy relief for German business to compulsory business-to-business e-invoicing alone, out of 1.44 billion for the whole law. That is an aggregate for one economy rather than a price per invoice, which is also what makes it worth quoting, because nobody selling software produced it. Per-invoice figures are looser. APQC, a non-profit benchmarking organisation, reports a median of about 5.80 dollars with best performers under 2.00, measured as a fully loaded cost for the accounts payable process itself, element 5.2 of its process framework. Higher figures circulate widely. Where their method is described they cover the whole journey from requisition to payment, which pulls in delays in purchasing and approval that sit outside the accounting department. The difference is scope rather than sampling, which has to be settled before two savings claims can be compared at all. The wider the baseline, the more impressive the same project looks.
More interesting than the speed is the question of where the work went, because it did not disappear, it only changed shape. Keying becomes exception clearing, which costs more per case than typing a clean invoice ever did, because someone has to work out what is actually wrong. How much lands in each pile is set by the confidence threshold on the extraction. Lower it and more invoices post automatically. Raise it and the queue of manual checks grows. Accuracy is also uneven. Clean structured invoices read well, while poor scans, foreign-language invoices and unstructured line-item tables read noticeably worse. Those were the slow ones to begin with.
Headcount does still come down, just far less than the touchless rate suggests at first glance. Heineken reports about 40 percent less headcount in accounts payable at over 90 percent automatic matching and not 90 percent less. The rest of the saving drains into exception clearing, which takes more time and more experience per case than keying ever did.
AI-WS Bp3 Fig2 Veolia EN
Figure 2: the Veolia case. At this level the AI never touches the ERP system, it only prepares work for someone else to approve. Read the four boxes left to right as one invoice moving through the centre. The note above summarises the case, the two below mark what the human decides and what the reported figures do not cover.

Agentic: standard invoices post untouched, four triggers call the human

At the agentic level the stream is rebuilt around the automation and the steps merge, while the change that matters sits elsewhere. The point where a human intervenes stops being an accident of workload and becomes an explicit design decision.
The example is Heineken Nederland, whose shared service centre processes about 430,000 incoming invoices a year for 25 business units across five SAP systems, using software from Basware. Electronic invoices with an order behind them are matched automatically against order and goods receipt. Inside the tolerances they post without anyone looking. About 210,000 of the 230,000 invoices in that electronic channel go through untouched, roughly 91 percent. The company also reports over 90 percent automatic matching overall plus about 40 percent less headcount in accounts payable.
The part worth studying is the stopping rule, meaning the definition of when the automatic run breaks off and the human takes over. Four things halt the automatic flow. Those are price or quantity outside tolerance, an invoice with no purchase order behind it, any change to supplier master data including bank details and a document that is defective or incomplete. Those four are not a technical detail. They define what the system may decide alone, so every other design choice in the case follows from them.
Three qualifications belong next to the numbers, because together they decide how much of the 91 percent would transfer to another company. They come from the supplier's case study, which the trade press repeats rather than checks. The 91 percent covers the electronic channel alone, so for the roughly 200,000 paper invoices no touchless rate is published. And a large part of this automation is deterministic rule processing rather than an AI agent. The AI reads the document. The three-way match with tolerance limits is classic ERP logic and has been for twenty years. That is no objection to the case, but it changes the answer to how far AI already carries this stream. It changes nothing about the need for the gate.
What is not publicly available is the error rate behind the automation, meaning the share of invoices posted without a check that later turn out to be wrong. Duplicate payments, a wrong cost centre, a price inside tolerance that should not have been there. Suppliers do quote figures, though for different quantities and from their own case studies, at 80 to 95 percent touchless and 85 to 97 percent extraction accuracy. The first measures how much passes without a human look, the second how well the system reads. The rate in question, postings later found wrong, stays open. No independent survey exists, because auditors see the corrections but publish only aggregate findings. A touchless rate therefore says how much work moved rather than how well it went.
AI-WS Bp3 Fig3 Heineken EN
Figure 3: the Heineken case. The gate carries this case rather than the intelligence of the system. The four boxes show one electronic invoice matching automatically against order and goods receipt. The notes below name the four triggers that halt the run, plus the limits of the reported rate.

Autonomous: blocked by audit rules, not by technology

At the autonomous level the limit sits in audit law rather than in the state of the technology, which makes it worth stating precisely what is blocked, because it is narrower than it first sounds. Rule-based, deterministic straight-through processing below defined value limits is audit-compliant and common practice, provided the application controls and the IT general controls are in place and tested. That is exactly what Heineken does. What is not permissible is handing the release itself to a stochastic AI system without fixed rule barriers, without a complete audit trail and without segregation of duties. The line is drawn at whether the rule that authorised a given payment can be written down and shown to an auditor afterwards. How much of the flow runs automatically does not settle the question.
Three sets of standards put that line where it is, independently of each other, so it cannot be avoided by appointing a different auditor. COSO Principle 10 requires strict separation between authorising a transaction, recording it and holding the assets, so an agent that both orders and pays collapses all three roles into one. SOX 404 with PCAOB AS 2201 requires evidence of effective controls against payments made without proper authorisation, while ISA 315 (revised) requires automated approval logic to be auditable and protected by effective IT general controls. In Germany, IDW PS 261 n.F. and IDW PS 330 ask the same, plus the GoBD requirement that every release stays attributable to an authorised entity. Missing segregation of duties in the payment process regularly produces a material weakness finding, the most serious verdict an auditor can reach short of refusing an opinion.
The obvious counter is to build that separation technically and let two agents work apart, one for the order and one for the payment. Segregation of duties asks for organisational independence plus attribution to an accountable party. Two agents from the same supplier under the same administration remain one instance for that purpose.
So this level has no company example behind it, only one fraud case, in which no AI system was doing the company's work. It is here because it shows why the last step in this stream deserves protection.
The case predates current AI entirely and that is precisely why it belongs here, since it shows the attack surface of the process rather than a failure of the technology. Between 2013 and 2015 a Lithuanian man named Evaldas Rimasauskas registered a company in Latvia under the same name as Quanta Computer, a Taiwanese manufacturer that genuinely supplied both Google and Facebook. He then invoiced those companies for goods they really had ordered, from a supplier they really used, with bank details that were his own. Over two years they paid him more than 120 million dollars. He was extradited to the United States, pleaded guilty and was sentenced in 2019.
Nothing technological failed in that case, because the real supplier relationship made the invoices plausible and forged confirmation letters plus forged executive correspondence covered the rest. Two claims circulate about the case that are not in the court record. The first is that the three-way match approved the fakes automatically. The second is the widely quoted split of the loss between the two companies. What the case does establish is the attack surface. A payment process is only as strong as its control over supplier bank details, at every level in this post, with or without AI. For straight-through processing that is the real lesson. The case predates current AI, yet it shows what a plausible invoice does when it runs through without a human check, which is exactly the state a high touchless rate creates.
AI-WS Bp3 Fig4 Gain and price EN
Figure 4: gain and price across the four maturity levels. Every level buys something and charges something for it. The price is the part that usually goes unmentioned. Read each row as one level, gain on the left, cost on the right. Agentic is where the documented cases sit, autonomous is blocked by audit requirements rather than by technology. A concept drawn from the cases in this post rather than aggregated metrics.

One case before the invoice

The three cases above all begin where the invoice arrives and that leaves a fair question open, that is whether the front half has a case of its own and why it might not.
It has one documented case, at the single step where the form explanation runs out. Walmart negotiates with the small suppliers it could never afford to negotiate with by hand, using software from Pactum, whose agents run the conversation themselves. Four authors reported in Harvard Business Review in November 2022 that 68 percent of the suppliers approached end up signing. Two of the four work for Walmart International, so the figure is the operator's own.
Why the step was never automated before stands in the same article and is the more useful part. Walmart has more than 100,000 suppliers. Around a fifth of them work on standard terms nobody negotiated. Hiring enough buyers to change that would cost more than it would bring in. A negotiation is an exchange of messages with a counterparty and no form fits it. Everything in the front half that fits a form was automated decades ago. The one part that stayed a conversation stayed manual until an agent could hold it.
The savings figures in that article sit behind a paywall, were not consulted for this post and therefore do not appear here.
The requisition, the approval and contract review remain without a single published case to this day. Two rounds of research have now come back empty on those three steps, which makes it a finding of its own rather than a gap in the search.

What is realistic

Put the levels together and the picture is unusually clear for this series, in both directions.
Everything up to and including the automatic match is available today, from document capture and field extraction to tolerance-based matching and exception routing. The gain is real on structured, high-volume, order-backed invoices. It is much smaller on paper, on foreign-language documents and on invoices with no order behind them, which is where the effort was concentrated in the first place.
Getting there depends, as in the other streams, on things that have nothing to do with AI itself. It takes clean supplier master data, tolerances someone has thought about, a catalogue and framework contracts worth buying from, plus a rule for which invoices may post on their own. The cleaner those are, the more the system can take. Heineken is mostly a story about that groundwork rather than about intelligence.
The release of money is where this stops being an automation question and becomes a governance one. Deterministic straight-through processing under defined limits is audited routinely and troubles nobody. Handing the release to a system that can produce a different answer on a different day is another matter. The obstacle is not one of opinion. It is COSO, SOX, ISA and IDW, appearing in the audit report as a material weakness.
Two effects deserve watching once the automation runs, one visible in the cases and one not. The first can be read off the Heineken case, the second none of the cases show directly, because it appears only after the rollout and is rarely traced back to it. The saving is smaller than the vendor arithmetic suggests, because exception work grows as keying shrinks, so cost per invoice across all invoices is the number to follow rather than the touchless rate on the best channel. Fraud exposure shifts rather than falls. Across 1,921 cases in 138 countries the ACFE puts the median loss per occupational fraud case at 145,000 dollars, with asset misappropriation present in 89 percent of them and billing schemes, the category that lives in this stream, in 22 percent. On the everyday scale below fraud, PRGX reports from its own client work that a recovery audit typically returns one million dollars per billion of supplier spend, so about 0.1 percent. That figure serves the firm selling the audit. Automating the routine path while leaving supplier bank-detail changes to one person's judgement moves the risk to where nobody is watching, which is what the Rimasauskas case looks like from outside.

What comes next

Procure-to-Pay follows the same shape as the rest of the series, with a harder edge at the end. Routine work moves to the system, the human moves to the exceptions and the whole thing rests on a gate. The difference is that this gate is not a design preference. The release has to stay attributable to a named person, in a way an auditor can follow afterwards. The question this series puts to every stream is the same one here. What is actually possible at each step today and who has measured it? That answer ages quickly, which is why the figures here carry a date. The next post puts the same lens on Order-to-Cash, the stream from the customer's order to the payment received.
A word on the evidence behind this post, since it is thinner here than in the first two streams. Almost every published example of AI in accounts payable comes from a software supplier describing its own customer, including the two cases used above. No independently audited company case exists for AI-supported invoice processing. Between 2023 and 2026 there is also no documented case of an AI system in procurement or payment causing damage on its own, which is worth stating plainly rather than filling with speculation. The numbers here are claims. The sources below name each one together with what it is worth.
Eight verified cases sit behind this post, of which three carried the argument above, while the other five fill in the levels without being told individually. Veolia, Purple Innovation and Stonewall Kitchen belong to the assistive level, Heineken, McDonald's Deutschland and SUEZ to the agentic one. The Rimasauskas fraud stands at the autonomous end and Walmart sits alone in the front half. Six of the eight rest on vendor marketing. The two that do not are a fraud case from a court record and one account written for a management journal by the operator's own executives.

Sources

Where a number rests on a study that is not freely retrievable, or on a party with an interest in the result, the entry says so.
Walmart, agreements closed with 68 percent of the suppliers approached. Van Hoek, DeWitt, Lacity and Johnson, "How Walmart Automated Supplier Negotiations", Harvard Business Review, digital article of 8 November 2022. Two of the four authors are executives at Walmart International, so this is the operator's own account. Paywalled after the opening, the 68 percent stands in the freely readable part.
Veolia Group Shared Services, eight times faster per document plus about 90 percent less manual data entry. Rossum, customer story. Written by the software supplier about its own customer.
Heineken Nederland, about 210,000 of 230,000 electronic invoices posted untouched, which is the 91 percent quoted above, plus about 40 percent less headcount. Basware, case study, published as a PDF. Reported by Heineken, published by its software supplier.
Cost per invoice, median about 5.80 dollars, top performers under 2.00. APQC, Open Standards Benchmarking, accounts payable, process element 5.2 of the Process Classification Framework. Non-profit benchmarking body, method described on that page. The measure library itself is open to members, so the figure comes from APQC's published extracts.
About 1.36 billion euros of annual bureaucracy relief for German business from compulsory business-to-business e-invoicing, out of 1.44 billion for the whole law. German Federal Ministry of Finance, monthly report April 2024, section on simplification and bureaucracy. Official costing of the ministry's own legislation.
Median loss per occupational fraud case 145,000 dollars, asset misappropriation in 89 percent of cases, billing schemes in 22 percent. ACFE, Occupational Fraud 2024: A Report to the Nations, pages 8 to 15, from 1,921 cases in 138 countries. Professional association, funded by its members.
Overpayments recovered by a recovery audit, about 0.1 percent of supplier spend. PRGX, accounts payable recovery audit guide. The wording there is one million dollars recovered for every billion in supplier spend, drawn from the firm's own client mandates. PRGX sells recovery audits.
Google and Facebook, more than 120 million dollars paid to a supplier that did not exist, 2013 to 2015. United States Attorney's Office for the Southern District of New York, press release of 19 December 2019. Court document.
Segregation of duties and traceable authorisation.COSO Internal Control Integrated Framework, Principles 10 and 11, quoted from the executive summary. SOX 404 with PCAOB AS 2201. ISA 315, IDW PS 261 n.F. and IDW PS 330, all three sold by the bodies that set them.
Supplier approximations, 80 to 95 percent touchless and 85 to 97 percent extraction accuracy. Ranges from case studies by several invoice-automation suppliers, without independent verification and marked as supplier figures in the text.
transentis consulting
Geisbergstraße 9
10777 Berlin
info@transentis.com© 2026 transentis.
Services