Introduction
Accounts payable fraud isn't a rare event that happens to unlucky businesses — it's a recurring, largely preventable pattern that exploits the exact thing that makes AP efficient: routine invoices getting processed quickly, without every single one getting deep scrutiny. This guide covers how the most common vendor fraud schemes actually work, and the specific controls that close each gap.
Table of Contents
- How Common This Actually Is
- Fake Vendor Invoice Scams
- Vendor Banking Detail Fraud
- Duplicate Payment Fraud
- The Core Controls That Actually Work
- Vendor Master File Hygiene
- Warning Signs Worth Watching For
- FAQ
- Conclusion
How Common This Actually Is
The scale of AP fraud is genuinely underestimated by most business owners. A Creditsafe study found nearly half of US businesses experienced 7 or more invoice fraud incidents in a single year — not one isolated attempt, but a recurring pattern. Separately, a Forbes-cited survey of 2,750 businesses identified over 34,000 cases of invoice fraud in a single year across that sample.
This reframes the right question: it's not "could this happen to us," it's "how many of these attempts are we currently catching versus missing without realizing it."
Fake Vendor Invoice Scams
The most straightforward AP fraud pattern: an invoice arrives for a vendor that either doesn't exist, or exists but didn't actually provide what's being billed. These are specifically designed to look routine — plausible dollar amounts (often just under whatever threshold would trigger additional approval), familiar-looking formatting, sometimes even referencing real project or department names gathered from public information.
Why these succeed: AP teams processing high invoice volumes under time pressure are optimized for speed on routine invoices, which is exactly the condition a fake invoice is designed to exploit. Without a matching control (comparing the invoice against an actual purchase order and confirmed receipt), a well-crafted fake invoice has nothing to fail against.
Vendor Banking Detail Fraud
This is consistently one of the most financially damaging AP fraud patterns, because it doesn't require creating a fake vendor at all — it hijacks a real one. A fraudster, often via a spoofed or genuinely compromised email account, impersonates an existing, legitimate vendor and requests that future payments be redirected to a new bank account.
Why this is so effective: because the vendor relationship is real, it bypasses new-vendor verification entirely — there's no reason for AP to be suspicious of an established supplier's invoice. The single most important defense: any banking detail change must be verified through a separate communication channel (a phone call to a known, previously-verified number — not a number provided in the same email requesting the change) before the new details are used.
Duplicate Payment Fraud
This happens when the same invoice gets paid more than once — sometimes purely accidental (submitted twice, processed by two different people without cross-checking), and sometimes deliberate, where a dishonest vendor or employee resubmits an already-paid invoice hoping the duplicate goes unnoticed in volume.
The most reliable defense: an automated system that checks incoming invoice numbers against payment history before approval — a control that's genuinely difficult to maintain manually at any real invoice volume, since it requires cross-referencing every new invoice against a growing historical record.
The Core Controls That Actually Work
- Segregation of duties — the person who approves or onboards a vendor should not be the same person who processes payments to that vendor; this single structural control closes a meaningful share of internal AP fraud specifically
- Formal new-vendor verification — confirming a new vendor's legitimacy (business registration, an independently-found contact number, not just what's provided in their outreach) before the first payment goes out
- 3-way matching against purchase orders and confirmed receipts — see our complete guide to 3-way matching for how this control specifically works
- Out-of-band verification for any banking detail change, without exception, regardless of how routine or urgent the request seems
- Regular vendor master file audits — reviewing the full vendor list periodically for duplicates, inactive vendors that should be deactivated, or entries with incomplete/suspicious details
Vendor Master File Hygiene
A commonly overlooked source of both fraud risk and simple error: an unmaintained vendor master file accumulates duplicate entries (the same vendor added twice with slightly different names or details), inactive vendors that should have been deactivated, and — in the worst case — fraudulent vendor entries that were never caught at setup and have simply never been reviewed since. A periodic audit of the full vendor list, not just new-vendor screening, catches issues that setup-time controls alone miss.
Warning Signs Worth Watching For
- A new vendor pushing for unusually fast payment, or discouraging standard verification steps ("no need to call, just process it")
- Banking detail change requests with any urgency or pressure attached, especially via email alone
- Invoice amounts sitting just under whatever dollar threshold triggers additional approval — a pattern worth flagging even when each individual invoice looks reasonable
- Vendor details that don't independently verify — an address, phone number, or business registration that can't be confirmed through a source other than what the vendor itself provided
None of these single-handedly confirm fraud, but any of them warrants the kind of follow-up that a routine invoice wouldn't need.
FAQ
Very common. A Creditsafe study found nearly half of US businesses experienced 7 or more invoice fraud incidents in a single year, and a separate Forbes-cited survey of 2,750 businesses identified over 34,000 cases of invoice fraud across just one year — meaning this isn't a rare, catastrophic event businesses occasionally face, but a recurring operational risk most businesses are already dealing with, often without fully realizing it.How common is invoice fraud for small and mid-size businesses?
A fake vendor invoice scam involves an invoice sent to AP for a vendor that either doesn't exist, or exists but didn't actually provide the billed goods or services. These are designed to look routine — plausible amounts, familiar-looking formatting — specifically to blend into the normal invoice flow and get approved without extra scrutiny, especially in AP departments processing high volumes under time pressure.What is a fake vendor invoice scam and how does it work?
This is one of the most financially damaging AP fraud patterns: a fraudster impersonates a real, existing vendor (often via a spoofed or compromised email) and requests that future payments be sent to a new bank account. Because the vendor relationship is genuine, this bypasses new-vendor scrutiny entirely — the only defense is verifying any banking detail change through a separate communication channel, never just replying to the email that requested it.What is vendor banking detail fraud (business email compromise)?
Duplicate payment fraud happens when the same invoice is paid more than once — sometimes through genuine error (an invoice submitted twice, processed by two different people), and sometimes deliberately, where a dishonest vendor or employee resubmits an already-paid invoice hoping it goes unnoticed. Automated matching systems that check invoice numbers against payment history are the most reliable defense against this specific pattern.What is duplicate payment fraud?
Segregation of duties (the person who approves a vendor shouldn't be the same person who pays them), a formal vendor verification process for any new vendor or banking detail change, 3-way matching against purchase orders and receipts, and regular vendor master file audits to catch duplicate or suspicious vendor entries are the core controls. No single control catches everything — the combination is what closes most of the real gaps.What internal controls most effectively prevent AP fraud?
A new vendor requesting unusually fast payment or discouraging standard verification, banking detail changes requested via email with any urgency or pressure attached, invoice amounts just under a threshold that would trigger additional approval, and vendors with addresses or details that don't match any independently verifiable business record are among the most consistent warning signs.What are the warning signs of AP fraud worth watching for?
For the broader internal controls that support this beyond AP specifically, see our guide on fraud prevention and internal controls.
Conclusion
The AP fraud that succeeds isn't usually the sophisticated kind — it's the kind that looks routine enough to slip through a process built for speed rather than scrutiny. Segregation of duties, out-of-band verification for banking changes, and genuine 3-way matching close most of the real gaps, and none of them require enterprise-scale tooling to implement — they require deciding, deliberately, that every invoice gets checked against something, not just approved because it looked plausible.
If you'd like help building AP controls that catch these patterns without slowing down legitimate payments, get in touch for a free consultation.