What are the risks related to the PP197 rule related to Create and Maintain PO vs Create and Maintain AP Payments?

The risk in this combination is low because it would require the ability to enter an invoice to complete the process.  An invoice would have to be matched to the PO in order for it to be paid.  However, some audit firms have this in their repository.