To PO or Not to PO
It sounds like an easy question. It isn’t. And I learned just how loaded it is the day I nearly got fired in a conference room over a single number.
The presentation that almost ended badly
I was presenting to a VP of Supply Chain, and I told him that 52% of his spend was on purchase orders. That’s it. That was the whole offense.
He did not take it well. In fact, I thought he was going to fire me on the spot: he was convinced I had bad data, because in his mind the number should have been far higher. So instead of arguing, I suggested we test it. Let’s pull up some non-PO invoices, I said, and see if there’s a data problem.
Right there in the meeting, I pulled up an invoice my data flagged as non-PO, and had someone log directly into the ERP and pull the same invoice. It matched. My data was right. Then I said, let’s take one of your largest vendors and see what percentage of their spend is on a PO, and it came back at 78%. Impossible, he said. So we pulled an invoice, and sure enough, it was not PO-related. What made it worse: that invoice was for a surcharge.
We spent the next fifteen minutes doing this: pulling up transaction after transaction that wasn’t PO-related but that the VP was certain should have been. And somewhere in those fifteen minutes, the mood in the room changed. Everyone started believing the data. And that’s when the real conversation finally started: not “is this number right,” but “what should be on a PO, and what shouldn’t?”
That’s the question worth having. So here’s where I land on it. These are my opinions. You may disagree, and that’s fine.
You should never have 100% of spend on a PO
I’ll say the thing nobody expects an audit guy to say: chasing 100% PO compliance is a mistake. If you force a purchase order onto every transaction, you’re creating POs that add no value: work for the sake of a checkbox. There is spend that genuinely doesn’t need one, and pretending otherwise just buries your team in administrative overhead. Again, my personal opinion, but I’ve seen the cost of the alternative.
Categorize the vendor, not the transaction
Here’s the approach I actually believe in: every vendor should be classified as either a PO vendor or a non-PO vendor. Make the decision once, at the vendor level, and stick to it.
The payoff is consistency. If a vendor is supposed to have a PO and an invoice shows up without one, that’s a flag, and you go understand why. AP and Supply Chain don’t have to guess, transaction by transaction, whether this particular invoice needed a PO. Everyone follows the same rule. Even better, you can tell the vendor up front: everything from you needs a PO, or nothing does. That clarity makes it easier for them, too.
Dollar limits miss the point
A lot of companies handle this with a dollar threshold: anything over $X needs a PO. I understand the instinct, but I come back to my vendor rule. A threshold still leaves people guessing at the transaction level, and it splits a single vendor’s activity into “PO” and “non-PO” depending on the amount, which is exactly the kind of inconsistency that lets errors through. I’d rather put the control around the vendor. It’s simpler, and simple controls are the ones that actually get followed.
Report on it. Almost nobody does
Reporting your PO versus non-PO spend should be standard practice for every organization. In reality, very few do it. That’s a shame, because it’s the single best way to see when your business processes are being bypassed. If a vendor you’ve designated as PO-only is suddenly generating non-PO invoices, the report tells you immediately. Without it, you’re flying blind and hoping everyone follows the rules.
Why this matters for duplicates
I’ll leave you with the reason all of this sits so close to my heart. I can’t tell you how many duplicate payments we’ve found where one invoice went through on a PO and the same charge went through again without one. The two paths never see each other, so no control catches the overlap. Consistent rules are what close that gap: this vendor is PO, that vendor is not. (I wrote more about how POs fail to stop duplicates in this post.)
To PO or not to PO isn’t really the question. The question is whether you’ve decided, clearly and consistently, which is which, and whether you’re watching to make sure the rule is actually being followed.
Want to see your real PO vs. non-PO picture, and what’s slipping between them? Start a no-cost Proof of Value. We only get paid a percentage of what we recover.

