Skip to main content

Invoice processing agent

A complete invoice can still be the wrong invoice.

An invoice processing agent prepares supplier invoices for finance review by extracting source-linked fields, checking arithmetic and duplicates, and comparing purchasing and receipt records. It helps expose missing or conflicting evidence before posting. Werkon would validate the path through approval, ledger receipts and correction; qualified owners retain tax, accounting and payment decisions.

Invoice-processing job boundary

Capture the claim. Prove the payable separately.

An invoice is a supplier claim expressed through a document or message. Processing must preserve that claim while testing identity, commercial evidence, accounting context and authority outside it.

01

Original invoice evidence

Register the approved channel, sender and transmission; preserve every original document, structured payload, attachment, signature where supplied, timestamp and digest; detect duplicates and revisions; quarantine hostile content; and never let extracted text replace the artifact.

Required evidence: Channel and message identifiers, sender and transport evidence, receipt time, files and media types, structured payload and syntax, immutable digests, page and attachment inventory, signature or network evidence where applicable, malware and active-content result, duplicate family, revision chain and provenance.

02

Supplier and commercial context

Resolve the legal supplier, buying entity, remit-to and bank-detail records through authoritative master data; retrieve purchase orders, contracts, price and tolerance rules, goods receipts, service acceptance, budget and approver assignments; and surface changed or conflicting identity and payment instructions.

Required evidence: Supplier and entity identifiers, registration and tax identifiers under qualified policy, master-data version, authorized contacts, remit-to and bank-change record, purchase order and contract versions, line and price terms, receipt and acceptance events, budget and cost owner, approval matrix and prior exceptions.

03

Reviewable invoice record

Extract exact field candidates with source spans; validate required structure, identifiers, dates, code lists, decimals, currency, line arithmetic, allowances, charges, tax and totals; match commercial records at member level; show tolerance, alternatives, missing evidence and uncertainty; and abstain where the source cannot support a field.

Required evidence: Schema and profile where relevant, field and line candidates, source coordinates, confidence and validation, supplier and customer references, issue and due dates, invoice and tax currency, purchase and delivery references, item, quantity, unit and price, net, allowance, charge, tax and payable totals, match graph, versions and exceptions.

04

Qualified disposition

Route exceptions by materiality, type and qualified owner; record commercial acceptance, tax and accounting treatment, approval or rejection and reason as separate decisions; revalidate the final payable; post through scoped and idempotent tools only; retain receipts; and keep payment authorization and reconciliation outside invoice approval.

Required evidence: Exception owner and due time, investigation and supplier communication, receipt or service confirmation, reviewer and qualifications, accounting and tax decision, cost allocation, approval and segregation evidence, final payable digest, posting request and receipt, payment handoff, ledger and payment reconciliation, reversal and correction.

Receipt-to-disposition path

Preserve, validate, match, then ask for authority.

The path narrows uncertainty in stages. Structural standards can make an invoice interoperable, but only the organization’s own evidence and qualified owners can make it payable.

  1. 01

    Receive and preserve

    Accept only approved channels and profiles, register transport and sender evidence, retain original messages and files with digests, detect duplicate and revision families, inventory pages and attachments, sanitize hostile content and hold incomplete or corrupted packages.

    Owner
    Supplier-operations, security, and records owners
    Evidence
    Channel policy, transmission receipt, sender evidence, original artifacts and payloads, digests, media and page inventory, malware and active-content result, structured syntax, duplicate and revision checks, quarantine and ingestion receipt.
  2. 02

    Resolve identity and validate facts

    Bind supplier and buying entity to authoritative records, validate invoice identifiers and dates, run exact code-list and arithmetic checks, compare structured and rendered representations, expose bank-detail changes and reject silent normalization or unsupported field completion.

    Owner
    Supplier-master, finance-data, and deterministic validation owners
    Evidence
    Master-data and entity versions, supplier and tax identifiers, remit-to and bank state, schema and profile, field-source spans, decimals and currency, line and total calculations, cross-representation conflicts, missing fields and validation results.
  3. 03

    Match commercial evidence

    Compare each invoice line and total with current purchase order, contract, receipt and service-acceptance records; apply exact tolerances and prior-use controls; use bounded ranking only where references are ambiguous; and retain unmatched, partial, over-tolerance and non-PO cases.

    Owner
    Deterministic matching service with bounded extraction assistance
    Evidence
    Order, contract, receipt and acceptance members and versions, line mappings, quantity and price arithmetic, currency and unit treatment, tolerance rules, consumed-quantity checks, candidate alternatives, model and retrieval versions, uncertainty and exception receipt.
  4. 04

    Review and approve by authority

    Present original evidence, structured record, commercial match and every exception in one accessible packet; route to qualified commercial, tax, accounting and budget owners; enforce threshold and segregation; capture edits, decisions and reasons; and revalidate the final payable.

    Owner
    Qualified procurement, business, accounting, tax, and approval owners
    Evidence
    Review packet and digest, reviewer identity, role and delegation, receipt or service decision, price and contract exception, accounting and tax treatment, coding and allocation, approval or rejection, reason, escalation and final validation.
  5. 05

    Post, hand off, and reconcile

    Create the approved payable through a scoped, idempotent request, verify the target receipt and ledger state, preserve payment as a separate authorized workflow, link later payment and bank evidence, reconcile, handle credits and reversals and correct both source relationships and accounting records visibly.

    Owner
    Accounts payable, controller, payment, and reconciliation owners
    Evidence
    Final payable and approval digest, target request and idempotency key, posting response and external receipt, ledger entry, payment proposal and separate authorization, payment and bank receipt, reconciliation, credit or reversal, close state, correction and retained package.

Authority model

Let software read and compare. Keep acceptance and money governed.

Invoice work contains deterministic document checks, uncertain extraction and consequential commercial, accounting and payment decisions. Those layers should never collapse into one score.

01

Deterministic document and finance controls

Code should own channel, artifact, digest, duplicate, entity, identifier, schema, code-list, date, decimal, currency, line, allowance, charge, tax, total, tolerance, prior-use, role, approval, idempotency, receipt and reconciliation checks.

  • Message and file inventory, immutable digest, duplicate and revision family, media and page validation, structured syntax and profile, malware and active-content handling
  • Supplier and buying-entity identifiers, exact dates and references, code lists, currency and decimals, quantity-times-price, line extension, allowance, charge, tax subtotal, rounding and payable total arithmetic
  • Purchase-order, contract, receipt and acceptance member mapping, quantity and amount tolerances, prior invoicing and consumed-quantity checks, approval threshold, delegation and segregation
  • Final record digest, period lock, posting idempotency, target receipt, payment separation, ledger and bank reconciliation, access expiry, export completeness and correction checks
02

Bounded extraction and matching

A model may locate fields, normalize candidate text and rank permitted commercial records. It cannot establish supplier identity, invent a missing field, confirm delivery, choose tax or accounting treatment, approve a payable or authorize payment.

  • Header, line, tax, payment and reference candidates with exact page or payload location, document digest, field confidence, deterministic validation, alternative and abstention
  • Supplier, order, contract, receipt and item candidate ranking inside an authorized population with all member identifiers, changed conditions, counterevidence and uncertainty
  • Line grouping and exception summaries whose quantities, prices and totals are calculated deterministically and whose underlying artifacts and commercial records remain directly inspectable
  • Evidence requests and review questions that cannot change supplier or bank master data, mark receipt or service acceptance, decide duplicate or fraud status, post a payable, release money or learn silently from overrides
03

Qualified commercial and financial authority

Named owners confirm supplier and buying relationships, delivery and service acceptance, contractual treatment, accounting and tax decisions, approval, posting, payment, reconciliation, correction and external response.

  • Supplier onboarding and master-data change, entity and account ownership, purchase order and contract interpretation, price, quantity, acceptance, credit, dispute, duplicate and commercial exception
  • Accounting framework and entity policy, recognition, period, accrual, allocation, account and dimension, tax type and jurisdiction, recoverability, withholding, foreign currency, materiality and professional advice
  • Budget and commitment ownership, approval and rejection, segregation exception, payable posting, payment proposal and authorization, bank instruction verification, reconciliation, close, reversal and correction
  • Fraud and security investigation, supplier communication, audit and tax response, retention and legal hold where applicable, access and provider approval, expansion, rollback and retirement

Invoice-processing components

Build a payable trail that starts before extraction.

A trustworthy invoice record joins source artifacts, supplier identity, commercial evidence, accounting decisions and system receipts without letting one overwrite another.

01

Invoice source registry

Preserve channel, sender and transmission, original documents and structured payloads, digests, pages and attachments, syntax and profile, duplicate and revision family, security results, normalized views, corrections and provenance.

Operating contract: Received is not trusted, readable is not verified, rendered is not structured, valid syntax is not a valid invoice, normalized is not original, same filename is not duplicate, and a revised artifact never erases its predecessor.

02

Supplier and commercial registry

Resolve legal supplier, buying entity, contacts, remit-to and bank details, purchase orders, contracts, catalogs, receipts, service acceptance, budget and approvers with effective versions, authority, prior use and change history.

Operating contract: Name is not identity, email is not authority, bank detail on an invoice is not mastered instruction, order is not delivery, receipt is not necessarily acceptance, historical price is not current contract, and budget is not approval.

03

Validation and match engine

Extract source-linked candidates, validate schemas and exact arithmetic, apply entity and period rules, compare line-level commercial members, calculate tolerances, prevent duplicate consumption, retain versions and alternatives and route exceptions.

Operating contract: Extracted is not verified, schema-valid is not legally valid, total agreement can hide wrong lines, three-way matched is not correct tax or accounting, highest rank is not a decision, and an exception cannot disappear without disposition.

04

Review, posting, and outcome ledger

Assign qualified owners, capture separate commercial, tax, accounting and approval decisions, revalidate the final record, post through scoped tools, retain receipts, hand off payment separately, reconcile and preserve credits, reversals, disputes and corrections.

Operating contract: Viewed is not accepted, accepted is not approved, approved is not posted, posted is not paid, paid is not reconciled, successful request is not target state, and close never removes correction or retention duties.

Delivery path

Prove one supplier stream before opening the payable ledger.

Extraction can look accurate on clean templates while failing on the invoices most likely to create loss or delay. Start with a bounded supplier, entity and document population and follow every item to disposition.

  1. 01

    Observe the invoice stream

    Follow receipt, security checks, duplicate handling, master-data lookup, extraction, validation, commercial matching, questions, approval, posting, payment handoff, reconciliation, correction, staff effort, provider cost, incidents and known harm.

  2. 02

    Define invoice contracts

    Name artifact, payload, supplier, entity, invoice, line, tax, order, contract, receipt, acceptance, tolerance, candidate, exception, reviewer, approval, payable, posting receipt, payment handoff, reconciliation and correction fields and authorities.

  3. 03

    Run a shadow population

    Replay representative structured, PDF, scan, multi-page, duplicate, revised, partial-receipt, split-order, credit, prepayment, recurring, foreign-currency, tax, changed-bank, non-PO, closed-period, hostile and corrupted cases without posting, then compare with qualified outcomes.

  4. 04

    Release a controlled queue

    Limit channels, suppliers, entities, document profiles, amounts, purchase categories and tools; require review for extracted and exceptional fields; verify segregation, idempotency, target receipts, payment separation, manual bypass, outage recovery and stop authority.

  5. 05

    Review after reconciliation

    Compare population completeness, field precision and coverage, validation and match quality by segment, duplicate and exception burden, approval edits, posting failures, payment and ledger reconciliation, staff impact, security, cost and harm before expansion or retirement.

Invoice safeguards

Six controls before an invoice becomes a payable.

The strongest controls prevent forged or duplicate evidence, wrong-entity records, arithmetic drift, false receipt matches, unauthorized bank changes and approval that silently becomes payment.

Original artifact, channel, and duplicate family
Allow approved receipt paths; retain messages, payloads, files, digests, pages and attachments; detect duplicate and revision families across channels; quarantine hostile content; preserve sender and transmission evidence; and never replace originals with OCR or generated text.
Entity, supplier, bank, period, and provenance
Use stable mastered identifiers; bind supplier and buying entity before processing; treat remit-to and bank-detail changes as separate high-risk workflows; preserve every field source and transformation; enforce currency and period rules; and expose missing or conflicting identity.
Schema, code, decimal, and total validation
Version applicable syntax, semantic profile, code lists, units, currency and tax rules; use exact decimals; validate lines, allowances, charges, tax subtotals, rounding and payable totals; compare rendered and structured views; and show every failure without auto-repair.
Commercial match and prior-use control
Match orders, contracts, receipts and acceptance at member level; calculate quantity and price tolerances deterministically; prevent reused receipt quantities or duplicate invoices; retain partial and alternative matches; and require qualified ownership for non-PO, over-tolerance and disputed items.
Permission, segregation, and financial commit
Separate receive, extract, validate, master-data change, accept, code, approve, post, pay, reconcile, reverse and administer capabilities; scope credentials to entity and tool; enforce thresholds and conflicts; use idempotency and target receipts; and keep payment authorization distinct.
Exceptions, security, retention, and recovery
Own unreadable, duplicate, changed-bank, missing-order, partial-receipt, tax, approval, posting and payment exceptions; set age and escalation rules; isolate tenants, protect secrets, test restore and replay, reconcile after outages, retain and export by policy and correct visibly.

Outcome proof

Measure approved evidence, not fields extracted.

An agent can populate every field while increasing duplicate risk, reviewer effort or incorrect payables. Proof follows each original invoice through validation, commercial evidence, decisions, posting, payment handoff, reconciliation and correction.

Baseline

  • Invoices by channel, supplier, entity, document and profile, currency, line count, source quality, order and receipt state, tax and accounting complexity, duplicate family, extraction, validation, match, exception, reviewer, approval, posting, payment, reconciliation, correction and known outcome
  • Current evidence by message and artifact digest, structured payload, supplier and master version, field spans, schema and code-list version, arithmetic result, order, contract, receipt and acceptance members, decision, approval, target receipt, payment and reconciliation
  • Manual receipt, malware review, duplicate search, supplier lookup, extraction, validation, matching, evidence request, commercial and accounting review, approval, posting, payment handoff, reconciliation, correction and audit-support effort, queue age, interruption, provider fees and operating cost
  • Wrong supplier, entity, bank detail, period, currency, field, line, tax, total, duplicate, order, receipt, match, approval, account, payment, access, correction, exposed data, failed recovery, control override and harm

Outcome evidence

  • More eligible invoices reach qualified review with intact originals, validated structured records, exact arithmetic, current supplier and commercial context, inspectable matches, visible uncertainty and owned exceptions
  • Fewer duplicate, wrong-entity, unsupported, over-tolerance, changed-bank, stale-policy or silently repaired records become payables, and posting and payment each retain separate authority, idempotent requests, target receipts and reconciliation
  • Qualified reviewers spend less avoidable time re-entering and gathering evidence while retaining clear correct, reject, hold, accept, code, approve, post, pay, reconcile, reverse and escalate authority, measured by document and exception segment
  • Comparable periods expose population completeness, field and match precision and coverage, abstention, reviewer edits, duplicate and exception age, posting and payment failures, reconciliation, staff effort, security incidents, cost and harm without assuming a financial result

Guardrails

  • Channel, artifact, supplier, entity, invoice, line, order, contract, receipt, tax, reviewer, approval, payable, payment or receipt is misbound; original evidence is lost; normalized values overwrite conflicts; or financial and supplier data crosses tenant, role or purpose boundaries
  • Hostile content changes instructions, OCR invents a value, structured and rendered records disagree, exact arithmetic is rounded, duplicate submissions evade detection, receipt quantities are reused, bank changes bypass verification or a high-rank match appears approved
  • The model confirms supplier identity, delivery or service acceptance, decides contract, tax or accounting treatment, approves, posts, pays or learns silently from overrides; reviewers lack current evidence, qualification or segregation; or staff cannot stop and correct the workflow
  • Outage loses artifacts or receipts, replay duplicates payables, restore changes decisions, failed target responses appear successful, exceptions age unseen, close blocks necessary correction, evidence cannot be exported, access survives role change or expansion precedes reconciled proof

Agent fit

Use this pattern when one supplier stream can be followed to reconciliation.

Good reason to begin

  • The organization can bound one entity, supplier or invoice class and name channel, master-data, procurement, receipt, service-acceptance, accounting, tax, approval, posting, payment, reconciliation, security, retention, correction, baseline, cost, harm and stop owners.
  • Original documents and structured payloads retain stable digests and provenance; supplier, order, contract, receipt and acceptance records are authoritative and versioned; exact formulas and tolerances are inspectable; and posting and payment tools support scoped access, idempotency and receipts.
  • Representative structured, PDF, scanned, duplicate, revised, partial, split, credit, prepayment, recurring, currency, tax, changed-bank, non-PO, closed-period, hostile and corrupted cases plus qualified decisions exist for shadow evaluation by segment.
  • The team can abstain, quarantine, hold queues, revoke credentials, preserve manual processing, verify bank changes independently, separate posting and payment, reconcile after outages, correct visibly, export evidence, roll back versions and retire the agent safely.

Resolve before beginning

  • Supplier and buying-entity ownership, receipt channels, master-data change, order and contract authority, delivery or service acceptance, accounting and tax policy, approval, segregation, posting, payment, reconciliation, retention or correction responsibility is unclear or disputed.
  • Original artifacts are not retained, supplier or commercial records lack stable identifiers, quantities and totals cannot be reproduced, receipt evidence is unavailable, bank details can change through invoice fields, tools cannot be scoped, or target systems lack idempotency and receipts.
  • The desired first step permits generated invoice fields without source spans, silent arithmetic repair, free-form supplier creation, automatic receipt acceptance, direct bank-detail change, autonomous tax or accounting treatment, approval, posting or payment and omits qualified review.
  • The business case depends on unverified perfect extraction, fraud prevention, legal or tax compliance, audit readiness, touchless processing, reduced headcount, exact savings, discounts, faster payment, implementation time or financial outcome.

Source basis

Sources behind the control model.

  • 01

    European Commission

    European Standard and Specifications for eInvoicing

    The Commission states that EN 16931-1:2026 was published in May 2026, the 2017 version was formally withdrawn and migration plans are still being developed, with the older version remaining compliant during the migration period. The standard defines core electronic-invoice semantics in its European context. It does not establish supplier identity, delivery, commercial acceptance, accounting or tax treatment, fraud status, approval, posting or payment.

  • 02

    OASIS Open

    Universal Business Language Version 2.4

    The June 2024 OASIS Standard defines interoperable business-document models, including invoices, with schemas, code lists, validation resources and examples. A UBL-valid document is not automatically EN 16931 compliant, legally valid in a jurisdiction, commercially correct, tax-correct, approved, posted or payable, and organizations must select the applicable profile and rules.

  • 03

    NIST AI Resource Center

    Artificial Intelligence Risk Management Framework

    Provides voluntary Govern, Map, Measure and Manage functions for AI risk. NIST states that AI RMF 1.0 is being revised. It does not certify extraction or matching, establish invoice, accounting, tax, procurement or payment policy, authorize financial access, prove accuracy or satisfy legal, privacy, security, audit or internal-control requirements.

  • 04

    National Cybersecurity Center of Excellence

    Software and AI Agent Identity and Authorization concept paper

    Frames identity, authorization, auditing and non-repudiation questions for a potential NCCoE project involving software and AI agents. Its public-comment period closed on 2 April 2026 and it remains an initial public draft, not a final standard. It supports examining scoped financial-tool identity but does not define invoice segregation, validate an integration or prove secure operation.

[ WORKFLOW / SYSTEMS AUDIT ]
THE FIRST ENGAGEMENT

Start with one real workflow

A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.

Show Us the WorkflowStart with the free automation readiness checklist

OBSERVEQUANTIFYDECIDEBUILD