Accounts Payable Fraud Lives in the Seams of Your Process

Accounts Payable Fraud Lives in the Seams of Your Process
10:13

Summary: How can finance teams prevent accounts payable fraud at the gaps between vendor requests, invoices, and approvals? This blog explores how fraudulent bank changes, duplicate or inflated invoices, and rushed approvals exploit disconnected AP processes. Learn how vendor verification, three-way matching, duplicate detection, and segregation of duties help reduce payment fraud risk, and how keeping document capture, supporting records, and approval routing connected embeds those controls into daily work. Use three practical checks to identify weaknesses in your AP process before fraudsters exploit them.

 

What would it take to get a fraudster through your AP process? Not a hacker in a hoodie, just a convincing email and a busy Thursday.

About 76% of U.S. organizations dealt with attempted or actual payments fraud last year. That covers companies of every size, so a few sketchy emails have probably already crossed your team's inbox.

Most people picture fraud as a dramatic break-in, but AP teams know it's far quieter. It slips in at the seams: the handoffs where work passes from one system or person to the nex

Three seams show up again and again, and each has a telltale sign: a bank detail that changed slightly, an invoice that seems familiar, and an approval clicked in a hurry. Each one has a control that closes it, and those controls hold up best when they live in the same place.

Why Vigilance Isn't a Control


Picture a Thursday at month end. Your AP lead has a queue twice its normal size, two approvers are out of the office, and the controller wants the close checklist by noon. Then an email arrives from a vendor you pay every month, asking to update their remittance details before the next payment run.

The logo looks right, the signature looks right, and the tone sounds like the rep who always signs off with "cheers." Nothing about it feels off enough to make anyone slow down, and that's by design.

Most finance teams respond to moments like that by telling everyone to stay alert. Vigilance is a great habit but an unreliable control, because it depends on a busy person catching a small detail right when volume peaks.

Part of the problem is where the work happens. Invoices arrive in an inbox, vendor details live in the ERP, contracts sit on a shared drive, and payments run through a bank portal. Every handoff between those places is a seam, and fraudsters will keep looking until they find the one nobody can see.

Know What It Costs

Business email compromise alone cost victims $3.05 billion in reported losses across 24,768 complaints in 2025, up from $2.77 billion the year before.

The tactics keep getting smarter, too. Spelling and grammar mistakes used to tip teams off. Now fraudsters can run a message through an AI writing tool and send something polished. More than $30 million of 2025 BEC losses involved AI.

The same three seams keep showing up, so here's how each one works and what closes it.

Tie the Email to the Vendor Record

The first seam sits between an email and the vendor record. A request lands in one place, the record lives in another, and nothing forces anyone to compare the two.

That Thursday email is the classic version: a real vendor's hijacked account asking to update banking details before the next run. One organization paid three invoices totaling $150,000 after a request like that, and only $915 came back. Several similar incidents involved teams that skipped callback verification or confirmed the change on the same email thread that started it.

The fix is to build vendor verification into the workflow instead of leaving it to memory, especially now that criminals can use AI to build fake vendor identities complete with W-9s and professional websites.

Every change request needs a voided check or bank letter, and every change follows the same steps:

  • A hold on payments until the change is verified
  • A callback to a number already on file, never one from the request
  • Supporting documents attached to the vendor record
  • A second approver and a timestamped log (the same two-person check that holds up at audit time)

Match the Invoice to the Order and the Receipt

The second seam sits between the purchase order and the invoice. Purchasing and receiving sit with operations while the invoice lands with finance, so the two rarely meet unless something makes them.

Duplicate and inflated invoices work because they look boring, and they get through when the only check is whether the bill looks right. A vendor resubmits last month's invoice with a new date, someone splits one large invoice into several small ones, or a ghost vendor sends a tidy invoice for goods nobody ordered.

Three-way match covers this seam by comparing the invoice, the purchase order, and the receiving record before anyone approves payment.

Say a longtime supplier bills $4,950 when the purchase order says $4,500 and the receiving record shows only part of the order arrived. A busy reviewer might approve it, but a match flags it instantly, and a bill with no order or no proof of delivery stops right there.

Duplicate detection adds a second layer by flagging repeat invoice numbers, amounts, and vendors, including the slightly altered ones like 1001 and 1001A. Manual teams catch some by memory, but automated checks run the same way on every invoice.

That consistency pays off fast. The typical fraud scheme runs about 12 months before anyone notices, and schemes caught within six months cost a median of $40,000 while those lasting more than five years passed $1.1 million.

Give Every Approver the Full Picture

The last seam sits between the approver and the context behind the invoice. A busy approver sees an amount and a vendor name, but not the purchase order, the receiving record, or the last three invoices from the same supplier.

This is how a manager ends up rubber-stamping anything under a set dollar amount, or clicking through ten invoices at 5:50 p.m. on the last day of the month. Anyone trying to slip a bad invoice through knows to stay under those limits, whether they sit inside or outside the company.

Multi-location teams feel this most, because inconsistent approval habits across locations hand fraudsters a map of the softest spots.

Segregation of duties sounds like jargon, but the idea is simple. The person who adds a vendor should not approve that vendor's invoices, and neither of them should release the payment. Otherwise, one person can set up a fictitious vendor and pay it without anyone noticing.

Approval routing enforces that split. It sets the rules once, sends each invoice with its supporting documents to the right approver by amount, department, vendor, or GL code, and logs every action with a name and a timestamp. The effort pays off, since organizations with internal controls lost 37% less on average than those without.

Test Your Own Seams This Week

You don't need a new system to find out where you stand. Pull three reports from your ERP or AP workflow and ask these questions.

  1. Of the vendor bank changes from the last 90 days, how many have a callback and a second approver on record?
    Verify any that don't, starting with the most recent, and hold the next payment to those vendors until you do.
  2. Does your duplicate check catch invoice numbers that differ by a trailing letter, a leading zero, or a stray space?
    Run last quarter's paid invoices through a report that normalizes invoice numbers (dropping trailing letters, leading zeros, and spaces) and see how many pairs appear.
  3. How many approvals landed just under a threshold, or in the final hour of the close?
    Pull the supporting documents on a few of them and confirm a purchase order and receiving record exist.

Then ask one more thing. If someone on your team spotted something off tomorrow, would they know who to tell? Tips uncover 43% of fraud cases, more than any other method, so that answer matters as much as the reports.

Put AP and Documents Under One Roof

The reports show where you stand, but keeping the seams closed is a different job. A control that relies on someone remembering will eventually meet a day when nobody does.

Running each control in a separate tool just moves the seams around. Your ERP records what happened, but controls have to live where the work happens. A verification step in one system and an approval step in another still leave a seam between them.

A single platform that handles intelligent document capture, document management, and approvals keeps the controls embedded in the workflow, from the moment an invoice arrives to the moment it is approved for payment.

Document management keeps vendor contracts, W-9s, voided checks, and receiving tickets right alongside the invoice, so a reviewer can check a bank detail against the paperwork in seconds instead of hunting through inboxes.

Take the results of those three reports to finance leadership. The CFO and controller own the risk when fraud gets through, which makes them the natural sponsors for closing the gaps.

Close the Seams Before Someone Tests Them

The vendor email on that busy Thursday looked like every other request, and AP fraud depends on that. Vendor verification, three-way match, duplicate detection, and approval routing close the seams it slips through, and they work best when they’re embedded in the workflow, running automatically on every invoice.

Closing them comes down to keeping capture, documents, and approvals connected in one place, which is what onPhase has spent more than 25 years helping finance teams do. Under Attack: How Accounts Payable Leaders Can Outpace Cybercriminals and Payment Fraud shows how AP leaders are getting ahead of these threats.

Prev Article