01
Why this framework matters now
For the last decade, the conversation about payables has been about speed. Throughput, automation rate, touchless processing, invoices per head, days to pay. Most finance teams have moved those numbers a long way, and they were right to. The efficiency gains were real.
But speed was never the thing that kept finance leaders awake. Ask a CFO what they worry about and the answer is rarely the volume getting through. It is the audit.
“If an auditor asked how a payment was approved, could you explain it, end to end?”
The question that really matters
Throughput is a number to be managed; a failed audit is a conversation with the board. The person who signed off the process is the one who answers for it, often long after the people who ran it have moved on. So when external auditors examine how a particular, potentially fraudulent, payment came to be made, the explanation has to hold from start to finish, without anyone reconstructing it after the fact. That is the test this framework is built around.
The relevant question is not whether the invoice can be located. It is whether the full path can be traced, each step evidenced in sequence:
- Who the supplier is, and how that was verified.
- What they were approved to supply, and at what price.
- What the invoice was matched against.
- How the receipting was validated.
- Who released the payment, and whether that was the same person who entered it.
When that explanation comes together cleanly, the lifecycle is controlled. When it has to be pieced together across several systems, and there is a gap no one can quite account for, the lifecycle is not. That gap is the subject of this framework.
Why the gap exists
The cause is structural. For most of the last decade, the unit of control was the invoice: a document moving through the system, checked at the point it arrived. That model is no longer enough. The unit of control is now the supplier behind the invoice, its bank details, its tax status, its approval path, its inclusion on any sanctions list, and whether it is still the supplier that was onboarded or has since changed in ways no one recorded.
Trace almost any fraud, duplicate payment, or audit gap back to its origin and the root is seldom a bad invoice. It is a supplier whose details, status, or behaviour stopped being watched. This is compounded by a simple fact: automation has moved faster than oversight. Many controls in place today were designed for a manual, invoice-by-invoice era and validated once, on the day they went live. They still run. Whether they still hold is a question rarely revisited since.
The cost lands downstream
A weak control rarely fails where it was set. It fails downstream, at the most expensive possible point. A supplier changes its bank account and gives notice, but the record is never updated. Weeks later an invoice arrives, the details do not match, and a task that should take thirty seconds takes thirty minutes, corrected under pressure with a payment waiting. The control worked. It simply fired far too late to be cheap.
And what is true of one bank detail is true across the lifecycle: the longer a problem goes unseen, the more it costs to put right.
What a controlled lifecycle is
Most organisations treat control as a final gate, with checks accumulating toward the moment of payment. It is the wrong shape. By the time a payment is ready to be made, almost every decision has already been made, and reversing any of them is slow, expensive, and often impossible.
A controlled supplier lifecycle is not a gate. It is a continuous thread, running from the first commitment to the moment the books are reconciled. It is a bit like airport security, where the bag, the person, and the passport are each checked separately: no single check carries the whole load, and the strength of the system lies in the sequence, not in any one point of it.
“A controlled lifecycle is not the absence of risk. It is the presence of evidence: the ability to stand over every step, in sequence, when asked to.”
This is a standard for what good looks like, not a description of any single system that delivers it. No vendor, SoftCo included, delivers every element today. It is offered as a reference point for finance leaders building toward continuous, supplier-centric control. What follows sets out each stage in turn. The process runs in a line, from contracting to post-payment, but the control model laid over it does not: the same kinds of control recur at stage after stage.