Vendor fraud is surging: the AP controls that catch it before the payment leaves
76% of US organizations faced payments fraud attempts last year. The defense is not vigilance — it is document checks that run on every invoice, automatically.
The numbers from the AFP Payments Fraud and Control Survey are blunt: 76% of US organizations experienced attempted or actual payments fraud in 2025. Vendor email compromise — the scam where a fraudster impersonates a known supplier and quietly changes the bank details on file — rose 66% in a single half-year. The ACFE's global study adds the sobering baseline: organizations lose an estimated 5% of revenue to fraud, and the median scheme runs for 12 months before detection.
And the classic schemes never left: duplicate invoices, inflated amounts, invoices from companies that do not exist, the employee-owned "supplier" billing for services never rendered.
What makes AP fraud effective is not sophistication. It is volume. A busy AP clerk processing hundreds of invoices a month cannot memorize every vendor's bank account, catch every near-duplicate invoice number, or notice that this month's amount is oddly rounded. Fraudsters count on that — their business model is your team's attention span.
Which is why the defense is not "be more vigilant". Vigilance does not scale. Controls do.
The four checks that stop most schemes
1. Bank-detail change detection
The single highest-value control in accounts payable. When an invoice from a known vendor arrives with new bank details, that is a red flag worth a phone call — to the number you already have on file, never the one printed on the suspicious invoice itself.
The tell-tale pattern is consistent: an urgent tone ("following our recent change of banking partner, please direct all payments to..."), a plausible-looking letterhead, and timing that exploits month-end pressure. DOXALIO flags any change in payment coordinates on a known supplier automatically, before the invoice reaches the approval queue. The scam that costs companies six figures dies as a two-minute verification call.
2. Duplicate detection across time
The classic, because it works: the same invoice submitted twice, weeks apart, with a slightly altered number — INV-2024-0891 becomes INV-2024-891, or the date shifts by a day. Humans catch duplicates they remember; nobody remembers March in July.
A systematic check compares every incoming invoice against full history — same vendor, same amount within tolerance, close dates — regardless of how the invoice number was massaged. The double payment that used to surface (maybe) at year-end audit gets caught at the door.
3. Anomaly scoring on amounts
Every vendor has a pattern. A supplier who bills ~$2,000 monthly and suddenly invoices $18,500 deserves a question. So does the invoice that lands just under a known approval threshold ($4,990 against a $5,000 sign-off line — fraudsters read your policies too), and the round-number invoice from a vendor who never bills round numbers.
Pattern-breaking amounts get surfaced with their context: the vendor's history, the deviation, the page reference in the document. Not blocked — surfaced. The human decides; the machine guarantees the question gets asked.
4. Segregation of duties, enforced by software
Internal fraud loves a single pair of hands: the same person who enters invoices approving payments is the oldest red flag in the audit literature, and the ACFE data confirms that lack of internal controls contributes to nearly half of occupational fraud cases.
Software can enforce what policy merely requests: four-eyes payment validation (one person marks paid, a different person confirms), threshold-based approval chains (small invoices auto-approve, larger ones require a controller, the largest require two sign-offs), and an immutable audit trail recording who did what, when. The control is not a memo — it is a workflow that cannot be skipped on a busy Friday.
Why document-level AI matters here
Every control above only works if it runs on every document, not a sample. That is the structural change automated document analysis brings: each incoming invoice is extracted, scored and cross-checked on arrival — arithmetic, tax coherence, duplicates, bank details, amount patterns — with every alert citing the exact page and line that triggered it.
Your team reviews the flagged exceptions with evidence attached. The machine reads everything else. Sampling, the auditor's compromise with human capacity, stops being necessary when reading is free.
The cost asymmetry
A four-check pipeline costs minutes of review per week. A single successful vendor email compromise averages six figures; a duplicate-payment habit leaks silently for years; the median occupational fraud runs a full year before anyone notices. Fraud prevention is not about paranoia — it is about making the boring checks impossible to skip.
FAQ
What is the single most important AP fraud control?
Bank-detail change verification, by a wide margin. Vendor email compromise is the fastest-growing scheme and the most expensive per incident — and it is defeated by one out-of-band phone call, if the change is detected. Automated flagging guarantees the detection; policy guarantees the call.
Can small businesses without an AP department use these controls?
They need them most — small organizations suffer disproportionate median fraud losses precisely because informal processes concentrate everything in one trusted person. A pipeline that runs the four checks automatically gives a five-person company the control environment of a fifty-person one.
Do these checks slow down invoice processing?
The opposite. Checks run in seconds on arrival, and clean invoices move faster because reviewers are not squinting at everything equally — attention concentrates on the flagged few. Speed and control stop being a trade-off.