Case Study
Automating supplier invoice handling without opening a data route
A finance team was spending most of a full-time role on manual invoice processing while staff quietly pasted documents into consumer AI tools. We replaced both with a controlled, auditable workflow.
Client situation
A construction and property services group with a central finance function processing several thousand supplier invoices a month across four trading entities, each with different approval rules.
The problem
Invoice handling consumed most of a full-time role, and the finance team had begun pasting invoice PDFs into a free public AI tool to speed up data extraction.
What we found
- Roughly a quarter of finance staff were using consumer AI tools for work, including with supplier documents containing bank details and commercially sensitive pricing.
- There was no AI policy, no approved tool, and no logging — so the business had no way of establishing what had already been shared.
- The invoice process itself was well understood by the people doing it but written down nowhere, and the exception handling varied by entity.
- Approval routing depended on one person's knowledge of which manager covered which cost centre.
- The existing finance system had an unused API and a document store that already held correct per-entity permissions.
What we changed
- Established an approved AI position: a business-tier tool with data-retention controls, tenant-bound identity, and a short written policy staff could actually follow.
- Built an extraction and routing workflow that reads invoices from the existing mailbox, extracts structured data, matches supplier and cost centre, and drafts the finance system entry.
- Gave the automation its own service identity with access scoped to the invoice mailbox and the finance system endpoints it needs — nothing else.
- Kept a human approval step: nothing posts to the ledger without a person confirming it, and any low-confidence extraction is escalated rather than guessed.
- Logged every document processed, every field extracted and every approval, so the finance manager can reconstruct any transaction.
Outcome
- The finance team reviews exceptions rather than keying every invoice, and the time released has gone into supplier query resolution and month-end.
- Sensitive supplier data is no longer leaving the business through consumer AI tools, and staff have a sanctioned tool that is faster than the workaround they were using.
- The undocumented approval knowledge that sat with one person is now encoded in the workflow and written down.
- Every automated action is attributable and auditable, which satisfied both the finance director and the group's external auditor.
Two problems that were really one
The finance director came to us about efficiency. The shadow AI use only came up in passing, in a conversation with a member of the team about how she was already speeding things up.
These were not separate issues. Staff were using unapproved tools because the sanctioned process was slow. Banning the tools without fixing the process would have driven the behaviour further underground; automating the process without addressing the tools would have left the data exposure in place.
Why a human stayed in the loop
It would have been technically straightforward to post directly to the ledger. We did not, for two reasons.
The first is ordinary financial control: an automated route into the ledger with no human confirmation is a fraud risk as well as an error risk, and it is exactly the sort of thing an auditor will want to discuss.
The second is adoption. A finance team that has watched the system make and correct a few low-confidence extractions under supervision develops a calibrated sense of when to trust it. A team that has been told to trust it does not.
Relevant services
Make your technology safer — and more useful.
A short conversation is usually enough to establish whether there is something worth doing, and what it would involve. No obligation, and no sales script.