Three-way matching is a verification control that compares the purchase order, the goods or services received, and the invoice before payment is released. It prevents mismatches and fraudulent billing by requiring independent evidence to align before a transaction moves forward.
Expanded Definition
Three-way matching is a payment control that requires the purchase order, receipt record, and vendor invoice to align before funds are released. In finance operations, it is used to confirm that the organisation ordered the item, actually received the item or service, and is being billed correctly.
For NHI governance, the same control logic helps explain why a single assertion is rarely enough when automation can initiate procurement, approvals, or payment workflows. Three-way matching is not an identity protocol, but it reflects a broader assurance pattern: independent evidence should converge before an action is authorised. That distinction matters because in agentic environments, a tool call, ticket update, or invoice submission may be machine-generated rather than human-reviewed. Industry usage is still evolving when teams apply the term beyond accounts payable, so it should be treated as an analogy for control design, not as a formal NHI standard. The NIST Cybersecurity Framework 2.0 frames this discipline as a verification and governance issue, while the NHI Management Group guidance on Ultimate Guide to NHIs shows why independent checks are essential when non-human actors operate at scale. The most common misapplication is treating invoice approval as sufficient evidence, which occurs when teams do not reconcile the receipt record against the original order.
Examples and Use Cases
Implementing three-way matching rigorously often introduces workflow friction, requiring organisations to weigh faster payment cycles against stronger fraud and error detection.
- A procurement system matches the PO, warehouse receipt, and supplier invoice before accounts payable approves payment for hardware or cloud services.
- An autonomous purchasing agent submits a request, but a finance workflow requires a separate receipt signal and invoice validation before settlement.
- A shared services team uses the control to detect duplicate billing when an invoice reflects quantities that differ from the goods received.
- Security teams adapt the same logic to NHI activity by comparing a tool-initiated request, an execution log, and an approval record before granting spend or access changes.
- Auditors review exception queues where one record is missing, because gaps can indicate process failure, rushed approvals, or intentional billing abuse.
For procurement-heavy environments, the control is most effective when paired with documented exception handling and strong record retention. NIST Cybersecurity Framework 2.0 supports the broader governance principle of controlled verification, and the NHI Management Group’s Ultimate Guide to NHIs reinforces why machine-generated actions need the same skepticism as human-initiated ones. Where services, APIs, or agent workflows can create spend requests, the control boundary should be explicit enough that no single system can complete the transaction alone.
Why It Matters in NHI Security
Three-way matching matters in NHI security because agentic systems and service accounts can initiate transactions faster than humans can spot anomalies. When procurement, billing, and execution evidence are not cross-checked, organisations open the door to duplicate payments, fabricated services, and unauthorised spend initiated through compromised automation. That same gap becomes dangerous when a non-human identity can approve its own actions or trigger downstream financial workflows without independent validation. NHI Management Group reports that only 5.7% of organisations have full visibility into their service accounts, which shows how often machine-driven activity is poorly observed. In practice, three-way matching is a governance pattern for insisting on corroboration before trust is extended, especially where spend, access, and execution are linked. The NIST Cybersecurity Framework 2.0 and the control mindset behind procurement reconciliation both point to the same outcome: evidence must be independently verified before action proceeds. Organisations typically encounter the need for this control only after a fraudulent invoice, billing dispute, or agent-triggered overspend has already surfaced, at which point three-way matching becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV | Three-way matching supports oversight by requiring independent evidence before payment or action. |
| NIST AI RMF | Risk governance for AI systems favors corroborated inputs before consequential actions. | |
| OWASP Agentic AI Top 10 | Agentic systems need guardrails so tool actions are not treated as self-validating evidence. |
Separate request, execution, and approval signals before agents can trigger business outcomes.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org