Three-way matching is an accounts payable control that checks a supplier invoice against two other documents before it is paid: the purchase order that authorised the spend and the goods receipt note that confirms delivery happened. The invoice clears when supplier, quantity and price agree across all three within a set tolerance. Anything outside tolerance is held for a human to look at.
The reason to bother is narrow but important. Two-way matching compares the invoice to the purchase order, which catches an unauthorised supplier, a price above the agreed rate or a quantity above what was ordered. What it cannot catch is an invoice for goods that were ordered, billed correctly and never delivered. The invoice and the PO agree perfectly. Only a delivery record breaks that one.
Here is the part most guides on this topic skip. If you run Xero or MYOB, neither platform produces a goods receipt note, so the third document does not exist in your system at all. It is not a setting you enable. It is a receiving process you build by hand first. For a lot of Australian businesses it is overhead that buys no extra control.
The three documents in a three-way match
Each document answers a different question. Each is created by a different person. That separation is the control, not the paperwork.
| Document | Question it answers | Who creates it |
|---|---|---|
| Purchase order | What did we agree to buy, at what price? | Whoever raises the order, usually operations or procurement |
| Goods receipt note | What physically arrived, and in what condition? | Whoever accepts the delivery: storeperson, site supervisor, foreman |
| Supplier invoice | What are we being asked to pay? | The supplier |
Three different people, three independent records. That is segregation of duties applied to purchasing. A match across all three is harder to fake than a match across two. One person who raises POs, receives deliveries and processes invoices can defeat the control on their own, no matter how the software is configured.
For services the equivalent of a goods receipt is a completion sign-off: a signed confirmation that the work described was performed. Construction businesses use progress milestone sign-offs. Professional services use project completion confirmations. The principle holds, the artefact just changes.
How the three-way matching process works
The process runs in a fixed order. That order matters more than the software. The purchase order comes first, the goods receipt second, the invoice last. A PO created after the invoice arrives will always match it, which is why retrospective POs are the most common way this control quietly stops working.
Once all three documents exist, the comparison happens at line level rather than on the header total. An invoice for 500 units at $10 matches a PO for 500 units at $10. Change it to 400 units at $12.50 and the total is still $5,000, so a header check passes and a line check does not. Header-level matching is where most manual processes lose the errors they were set up to find.
Tolerances decide what counts as a mismatch. Set them at zero and you will drown in exceptions from rounding and unit conversions. Set them too loose and real variances clear without review. Most teams land between 0.5 and 2 percent on value, with a small fixed dollar floor so a 2 percent tolerance on a $40 invoice does not become meaningless.
If you want to see how your current process handles this, the PO and invoice matching checker walks through the same comparison on a single invoice.
What three-way matching catches that two-way matching does not
One scenario, and it is worth naming precisely: payment for goods that were ordered and invoiced but never arrived. Both documents agree, both are genuine, and the money goes out. A delivery record is the only thing that surfaces it.
That scenario has a fraud version and an error version. The error version is far more common. A supplier ships 18 of 20 items and invoices for 20. A part-delivery gets invoiced in full because the supplier’s system bills on despatch rather than receipt. Nobody is stealing anything. You are still paying for goods sitting in someone else’s warehouse.
The fraud version is smaller in volume and much larger per incident. Payment redirection scams, where an attacker impersonates a supplier to divert payment, cost Australians $166.8 million in 2025, up 9.3 percent on the year before, according to the National Anti-Scam Centre’s Targeting Scams Report released in March 2026. Only investment scams cost more. A matching process will not catch a changed bank account on its own, since the invoice details can be perfectly legitimate, but requiring a purchase order and a delivery record for every payment removes the easiest version of the attack: an invoice for something nobody ordered.
Three-way matching in Xero and MYOB
Neither platform supports it. Xero lets you raise purchase orders and copy them to bills, but there is no automated line-level comparison, no tolerance configuration and no exception queue. MYOB AccountRight converts purchase orders to bills with the same manual, visual process. More to the point, neither system generates a goods receipt note, so there is no third document for anything to match against.
This is the gap that matters for Australian SMBs researching this topic. The US vendor pages that dominate search results assume an ERP with a warehouse management module behind it, where goods receipts are created automatically when stock is put away. On Xero or MYOB you have to create that record yourself, usually as a form, a photographed delivery docket or an entry in a separate inventory or job management system.
Adding an AP automation layer changes what happens to the invoice, not whether a goods receipt exists. Automated matching, tolerances and exception routing all become available. The receiving discipline is still yours to run. For how the matching layer fits with the rest of the AP process, see the full guide to purchase order matching.
What the receiving step actually costs
Every delivery needs a record, created by someone who is usually doing something else. That is the real cost. It is a people cost rather than a licence cost.
Australian invoice processing is already expensive. The ATO publishes Deloitte Access Economics costings that put an emailed PDF invoice at AU$27.67 to process, rising to AU$30.87 for a paper one. Those figures were modelled in 2016 and the ATO still cites them, so treat them as an order of magnitude rather than a current quote. Manual handling is also where the errors come from: DocuClipper puts the share of manually processed invoices containing an error at 39 percent. Adding a receiving step that nobody owns pushes that number up without improving control, because an unreliable GRN is worse than no GRN. It generates exceptions the AP team learns to override, which is how a control becomes a formality.
Work out the volume before committing. If you take twelve deliveries a week against purchase orders and one person receives all of them, the process is realistic. If deliveries land at six sites across three states, at unpredictable times, to whoever happens to be standing there, the honest answer is that you will not get consistent goods receipts. Construction teams hit this constantly, which is covered in more depth in receiving and approvals on construction sites.
Where the match breaks in practice
Four failure modes account for most of it. None of them are software problems.
The first is the retrospective purchase order. An invoice arrives with no PO behind it, someone raises one to clear the block, then copies the numbers off the invoice. The documents now agree because they were written from the same source. This is the single most common way the control stops working. It shows up as a suspiciously low exception rate rather than as an error.
The second is the missing goods receipt. Delivery happens, the docket goes in a ute or a drawer. The AP team is left with an invoice and nothing to check it against. At that point there are two bad options: hold a legitimate invoice and age it past terms, or release it and record that the third check was skipped. Teams pick the second one, repeatedly, until skipping is the default.
Third is tolerance drift. Exceptions pile up, someone widens the thresholds to clear the queue. Nobody narrows them again. A 10 percent tolerance on a $50,000 order passes a $5,000 variance without a glance. Review the thresholds on a schedule and treat a widening as a decision with a reason attached, not an admin fix.
Fourth is concentration of duties. If one person raises the order, signs for the delivery and codes the invoice, the three documents stop being independent and the whole structure collapses to a single point of trust. Small teams hit this by default rather than by choice. Where you genuinely cannot separate the roles, a second approver on payment is the compensating control. That belongs in your approval workflow rather than in the matching step.
Exception rates tell you which of these you have. Under 10 percent usually means tolerances are too loose or POs are being written from invoices. Above 40 percent means either the thresholds are unrealistic or purchasing discipline upstream needs work before any matching rule will help. Between roughly 15 and 25 percent is where a working process tends to sit.
When two-way matching is the better choice
Most Australian SMBs should run two-way matching properly rather than run the three-document version badly. The decision comes down to whether a verifiable delivery actually occurs.
| Situation | Better fit | Why |
|---|---|---|
| Physical goods, one receiving point, someone owns it | Three-way | The GRN is a by-product of work already happening |
| Physical goods, multiple sites, no designated receiver | Two-way | Goods receipts will be inconsistent, so exceptions become noise |
| Subcontractor progress claims | Two-way against the contract | Nothing is delivered to a dock, so the claim is matched to the subcontract value and prior claims |
| Professional fees, software, services | Two-way | No goods to receive, so a third document adds paperwork and no control |
| High-value inventory, formal stock control | Three-way | Stock accuracy and margin depend on receipted quantities |
The honest position is that two-way matching with tight tolerances, real exception ownership and consistent PO discipline catches most of what goes wrong in an Australian SMB’s payables. The full three-document check is the right answer when you already have a receiving function, not a reason to create one. The two-way versus three-way comparison works through the trade-off in more detail.
Pulsify does two-way PO matching at line level, with configurable tolerances and exception routing into the approval workflow. Goods receipt matching is deliberately out of scope, for the reason above: most businesses on Xero and MYOB do not generate GRNs, so a three-way feature would match against a document that does not exist. You can see how the comparison and exception handling work on the PO matching page.
Sources: ACCC, Targeting Scams Report 2025 · ATO, Peppol eInvoicing value assessment: cost calculations · DocuClipper, cost to process an invoice
Further reading: Purchase Order Matching in Accounts Payable · Three-Way vs Two-Way Matching in Australia · Receiving, Approvals and 3-Way Matching in Construction AP