Finance Operations

2 Way vs 3 Way Matching: When Each Is Right (And When to Drop Tolerances)

The decision AP managers actually face isn't which control is better, it's which control fits which invoice

July 19, 2026
12 min read
By Rhocash Team
2-way vs 3-way matching — definition

2-way matching compares a vendor invoice against its purchase order only. 3-way matching adds a goods receipt note, confirming the ordered items were actually received before payment. Choosing between them is a risk decision, not a maturity level.

Key takeaways
  • 2-way matching works when there's no physical delivery to verify: services, subscriptions, low-dollar trusted-vendor spend
  • 3-way matching earns its exception overhead on capital purchases, new vendors, and anything with a physical receiving step
  • Tolerances aren't a single dial. Price tolerance and quantity tolerance interact differently with each matching level, and copying one blanket percentage across every category is how exception queues or fraud exposure happen

The Decision AP Managers Actually Face

Your matching controls policy probably says "3-way matching required." In practice, your AP team applies 2-way matching to half your invoice volume anyway, they just don't call it that. The SaaS renewal gets rubber-stamped against the PO. The consulting retainer clears without anyone checking for a goods receipt that will never exist. The office supplies order under $500 clears because chasing a GRN for staplers isn't worth anyone's time.

That's not a control failure. That's your team correctly sensing that not every invoice carries the same risk, even if the policy document doesn't say so explicitly.

The real question isn't "should we use 3-way matching." The 3-way matching pillar post already covers what 3-way matching is and why exception queues grow once you adopt it. This post answers the question that comes next: which invoices actually need the goods receipt check, which don't, and how tight should your tolerances be at each level before you're either drowning in exceptions or leaving the door open to errors and fraud.

What 2-Way Matching Is, and Where It's Sufficient

2-way matching compares two documents: the purchase order and the vendor invoice. No goods receipt note enters the equation. If the invoice's price, quantity, and vendor match what the PO authorized, the invoice clears.

The logic holds up cleanly in a specific set of categories:

Services with no physical delivery. Consulting, professional services, legal retainers, marketing agencies. There's no box to open, no warehouse dock to check. A goods receipt step for a services invoice usually means someone in the business manually confirming "yes, the work happened," which is a judgment call, not a physical verification. Building a 3-way workflow around a step that's really just a second approval adds process without adding control.

SaaS and subscription spend. Software licenses renew on a schedule, the PO (or contract) sets the price and term, and the invoice either matches the agreed rate or it doesn't. There's nothing to receive.

Low-dollar, trusted-vendor spend. Office supplies, recurring small purchases from vendors with a long clean history. The cost of building and maintaining a 3-way matching path (and staffing the exception queue it generates) can exceed the risk the extra check is protecting against, especially under a reasonable dollar threshold.

High-trust, long-tenure vendors within a defined category. A vendor you've transacted with for years, with a track record of accurate invoicing and no history of quantity or pricing disputes, presents a different risk profile than a vendor you onboarded last quarter. Matching policy that treats every vendor identically ignores information you already have.

The pattern: 2-way matching is appropriate when the invoice risk is primarily a pricing or authorization risk, not a delivery risk. If there's nothing to physically receive, a goods receipt requirement doesn't add control, it adds a manual step that becomes its own bottleneck.

What 3-Way Matching Adds, and Where It's Necessary

3-way matching adds the goods receipt note (GRN) to the comparison: PO, GRN, invoice. All three have to align before payment. That third document exists to answer one question the PO and invoice can't answer on their own: did the goods actually arrive, in the quantity billed.

That verification earns its overhead in specific situations:

Physical goods and inventory. Raw materials, manufacturing inputs, anything that sits in a warehouse before it becomes a line item on a balance sheet. Without a receipt check, you're paying for goods based entirely on a vendor's word that they shipped what they billed.

Capital purchases and high-value POs. Equipment, large one-time purchases, anything where a pricing or quantity error carries real financial weight. The exception overhead of 3-way matching is worth absorbing when a single mismatch could represent a five- or six-figure error.

New vendors, regardless of category. A vendor without transaction history hasn't earned the lighter-touch treatment yet. Requiring a goods receipt check for the first several months of a new vendor relationship, even for categories that would otherwise qualify for 2-way matching, is a reasonable default until the vendor has a track record.

Anything with partial shipment or quality risk. If deliveries commonly arrive in multiple shipments, or if quality issues occasionally mean received goods don't match what was ordered, the GRN is doing real verification work, not just adding a checkbox.

The 3-way matching pillar post covers what happens after this control catches something: partial shipments, freight add-ons, and missing GRNs that generate exceptions that aren't actually errors. That's the tradeoff you're accepting when you apply 3-way matching. It's usually worth it for the categories above. It's usually not worth it everywhere else.

How Tolerances Interact With Each Matching Level

This is where most matching policies fall apart, because tolerances aren't a single dial you set once. Price tolerance and quantity tolerance behave differently depending on whether you're running 2-way or 3-way matching, and getting the interaction wrong produces one of two failure modes: exception overload or a control gap wide enough for errors and fraud to pass through unnoticed.

Price tolerance under 2-way matching. Since there's no receipt check acting as a second verification layer, price tolerance is effectively your only defense against overbilling. A tolerance set too loose (say, 10%+ variance auto-approved) on 2-way matched categories means a vendor can drift pricing upward gradually and nothing flags it. A tolerance set too tight (under 1%) on categories with routine small variances, like usage-based SaaS billing, generates exceptions for differences that were never actually errors.

Quantity tolerance under 2-way matching. Quantity tolerance matters less here since there's no physical count to verify against, but it still applies to anything billed by unit or usage, like consulting hours or per-seat software charges. A quantity variance on a 2-way matched invoice should route to a human, since there's no GRN to resolve the discrepancy automatically.

Price tolerance under 3-way matching. The GRN is already absorbing some of the risk that price tolerance covers in 2-way matching, since a fraudulent or erroneous quantity gets caught at the receipt step regardless of price tolerance settings. This means price tolerance under 3-way matching can typically be somewhat tighter without a corresponding spike in exceptions, because the receipt check is doing part of the verification work that would otherwise fall entirely on the price tolerance threshold.

Quantity tolerance under 3-way matching. This is the tolerance that does the real work here. A quantity tolerance set too loose defeats the purpose of running 3-way matching at all, since you've added the GRN step but then permitted enough variance that it rarely blocks anything. A tolerance set too tight generates exceptions for the operational reality covered in the pillar post: partial shipments, backorders, and freight-related quantity adjustments that aren't fraud, they're just how physical delivery works.

A single blanket tolerance percentage across every category is a common source of both exception overload and control gaps

Loose tolerances applied to high-risk categories (new vendors, capital purchases) create room for errors and fraud to clear unnoticed. Tight tolerances applied to low-risk, high-variance categories (freight-inclusive shipments, usage-based billing) generate exceptions for normal business activity, and AP teams predictably start rubber-stamping exceptions to keep up, which quietly defeats the control.

Ask on the demo

Does our matching tool support different tolerance thresholds by vendor, category, and matching level, or only one global setting?

Good sign

Tolerances configurable per category and vendor, with tighter defaults for new vendors that loosen automatically as a track record builds

Red flag

One tolerance percentage applied uniformly regardless of vendor history, category, or matching type

The core tradeoff: tighter tolerances reduce fraud and error exposure but increase exception volume. Looser tolerances reduce exception volume but increase exposure. The fix usually isn't picking one setting for the whole business, it's matching the tolerance to the risk of the category, the same way you match the matching level itself.

A Practical Decision Framework

Use this as a starting point, not a rigid rule. Dollar thresholds and tolerance percentages below are directional, not universal, adjust them to your risk appetite and industry.

ScenarioRecommended MatchTypical Price Tolerance
SaaS / subscriptions, trusted vendor2-way2-4%
Professional services / consulting2-way2-3%
Low-dollar office / supply purchases2-way, under defined threshold5-10%
Raw materials / inventory3-way1-3%
Capital equipment / high-value POs3-way1-2%
Any category, new vendor (first 90-180 days)3-way, regardless of category default1-2%

Ask this before assigning a matching level: what's the actual failure mode if this invoice is wrong?

If the failure mode is 'we overpaid a few percent on a services invoice,' the cost of a tighter control likely exceeds the risk. If the failure mode is 'we paid for inventory that never arrived,' the receipt check is worth the exception overhead every time.

Ask on the demo

Can we set matching level and tolerance rules by category and vendor tenure, and have new vendors automatically default to tighter controls?

Good sign

Rules-based defaults by category and vendor age, with an easy path to loosen tolerances once a vendor earns trust through clean transaction history

Red flag

Matching level is a company-wide setting with no per-category or per-vendor override

When 3-Way Matching Is Still the Right Call, Even at Low Volume

It's tempting to read a decision framework like this and default toward 2-way matching wherever possible, since it generates fewer exceptions and moves faster. That instinct is wrong in a few specific situations.

Regulated or audited environments. If your business operates under SOX requirements, government contracts, or industry-specific audit standards, the goods receipt step may not be optional regardless of dollar value or vendor trust. Check with your controller or auditor before loosening matching requirements on any category that touches a compliance boundary.

Any category with a history of disputes. If a vendor relationship has produced quantity or quality disputes in the past, even infrequently, that history overrides whatever the category default would otherwise suggest. Trust is earned per vendor, not assumed per category.

Businesses without a reliable exception resolution process. Dropping to 2-way matching removes a check. If your team doesn't have a solid process for catching pricing drift through other means (regular vendor spend reviews, contract audits), removing the GRN check removes one of the few mechanisms actually watching for it. Loosening controls without something else picking up the slack is a net risk increase, not a net efficiency gain.

Low volume doesn't automatically mean low risk. A company processing 50 invoices a month might assume the exception overhead of 3-way matching isn't worth it at that scale. But if those 50 invoices include capital purchases or new vendor relationships, volume isn't the relevant variable, risk concentration is. A handful of high-value invoices can carry more exposure than a few hundred low-value ones.

Dropping to 2-way matching is a decision to trade a layer of verification for speed. That's a reasonable trade in low-risk categories. It's not a reasonable trade just because exception queues are inconvenient, that's a signal to fix the coordination work behind exception resolution, not to remove the control that's generating the exceptions.

Walk through your matching and tolerance rules with us

Matching level and tolerance rules shouldn't be a single company-wide setting you set once and forget.

Rhocash lets AP teams configure matching controls the way risk actually works:

  • Category and vendor-based matching rules, so SaaS and services default to 2-way while inventory and capital purchases default to 3-way, automatically
  • Tenure-aware tolerances that start tight for new vendors and loosen as a clean transaction history builds
  • Exception context assembled automatically, so when a 3-way match does flag a variance, the reviewer isn't starting from zero
  • Pattern learning that recognizes recurring, legitimate variances (like freight add-ons from a specific vendor) instead of flagging the same exception every month

Teams using Rhocash typically tighten controls where risk is concentrated and loosen them where it isn't, without manually rebuilding matching rules for every category change.

Frequently Asked Questions

Should every invoice under a certain dollar amount use 2-way matching?

Dollar thresholds are a reasonable starting filter, but they shouldn't be the only variable. A low-dollar invoice from a brand-new vendor or in a category with a history of disputes still carries more risk than the dollar amount alone suggests. Use dollar thresholds alongside vendor tenure and category risk, not as a standalone rule.

Can I use 3-way matching for services if there's no physical goods receipt?

Some teams build a "confirmation of work" step that functions like a GRN for services, typically a manager attesting the deliverable was received. It adds a verification layer but it's a judgment-based approval, not a physical count, so it doesn't carry the same fraud protection a genuine goods receipt does. Whether it's worth the process overhead depends on how high-value or high-risk the services category is.

How often should tolerance thresholds be reviewed?

Many mid-market AP teams review tolerance settings annually, or whenever exception volume for a category shifts noticeably in either direction. A sudden spike in exceptions for a previously clean category often means the tolerance is now too tight for a legitimate change in vendor billing practice. A sudden drop can mean the opposite, that too much variance is quietly clearing.

Does tightening tolerances always reduce fraud risk?

Generally, yes for the specific transactions it catches, but tightening tolerances without addressing exception resolution capacity often backfires. If exception queues grow faster than your team can review them, the practical effect is that reviewers start approving exceptions faster and with less scrutiny just to keep up, which can quietly erode the control benefit the tighter tolerance was meant to provide.

What's a reasonable default for a new vendor before I have transaction history?

Many AP teams default new vendors to 3-way matching with tight tolerances (often under 2%) regardless of category, for a defined trial period, typically 90 to 180 days or the first several transactions. Once the vendor has a track record of clean invoices, the category default can take over.

Do 2-way and 3-way matching need to be all-or-nothing across the company?

No, and treating it as all-or-nothing is one of the more common mistakes in matching policy. Most AP teams that run this well apply matching level per category and per vendor, not as a single company-wide rule. The framework in this post is meant to be applied that way.