The AP Team's Guide to Vendor Fraud Prevention
Vendor fraud is one of the most costly and preventable risks facing accounts payable teams today. According to the Association of Certified Fraud Examiners (ACFE), billing schemes are among the most common forms of asset misappropriation and can produce six-figure losses. For small and mid-market businesses, a single successful fraud can be existential.
The good news is that vendor fraud almost always exploits the same handful of weaknesses: inadequate vendor vetting, lack of segregation of duties, and no systematic monitoring of vendor record changes. Understanding these patterns is the first step toward stopping them.
What Is Vendor Fraud?
Vendor fraud occurs when a fraudster — whether an external attacker, a compromised vendor, or an internal employee — manipulates the accounts payable process to divert payments. The manipulation can happen at any point in the payment lifecycle: during vendor onboarding, when vendor bank details are updated, or when invoices are submitted for payment.
The term covers a wide spectrum of schemes, from sophisticated business email compromise (BEC) attacks that trick AP staff into updating bank account numbers, to simple ghost vendor schemes where an employee creates a fictitious supplier and approves payments to themselves.
The 5 Most Common Vendor Fraud Schemes
1. Business Email Compromise (BEC) — Bank Account Fraud
BEC is one of the most financially damaging forms of payment fraud affecting businesses. In a typical attack, a fraudster impersonates a vendor — often by spoofing or compromising the vendor's email domain — and sends a convincing request to update the vendor's bank account details. An AP team member updates the record in good faith. The next payment goes to the attacker's account.
The FBI's Internet Crime Complaint Center received 24,768 business email compromise complaints involving more than $3.0 billion in reported losses in 2025. The average loss per incident is far higher than most other fraud types because payments are often large and the fraud is not discovered until the legitimate vendor follows up on a missed payment — weeks or months later.
Key warning signs:
2. Ghost Vendor Schemes
A ghost vendor is a fictitious supplier created in the AP system — usually by an employee with both the ability to add vendors and the ability to approve payments. The employee creates the vendor, submits invoices for services never rendered, and approves payment to an account they control.
Ghost vendor fraud is an insider threat and is almost always enabled by a failure of segregation of duties (SoD) — the principle that no single person should control the full payment cycle from vendor creation to payment approval.
Key warning signs:
3. Invoice Fraud and Duplicate Payments
Invoice fraud takes several forms: a fraudster submits inflated invoices for legitimate services, submits invoices for services never delivered, or submits the same invoice multiple times hoping that one slips through. Duplicate payments are also a common form of accidental loss that fraudsters can deliberately exploit by submitting slightly altered versions of the same invoice.
Key warning signs:
4. Vendor Master File Manipulation
The vendor master file is the single most important data asset in your AP process — and one of the most vulnerable. Any employee with write access to the vendor master can change a legitimate vendor's bank account, address, or payment method to redirect payments. Unlike BEC, this is an insider attack, but the mechanics are identical: the payment goes to the right vendor name but the wrong account.
Key warning signs:
5. Fictitious or Inflated Expense Reimbursements
While not strictly a vendor fraud, expense reimbursement fraud follows the same pattern: an employee submits claims for expenses that were never incurred, or inflates legitimate expenses. In companies where expense reimbursements flow through the AP system alongside vendor payments, the same controls apply.
The Root Cause: Why AP Teams Are Vulnerable
Most vendor fraud succeeds not because the attackers are sophisticated, but because the target organization lacks basic controls. The three most common root causes are:
1. No segregation of duties. When the same person can add a vendor, approve an invoice, and release a payment, fraud is trivially easy. SoD violations are the single most reliable predictor of fraud risk in an AP environment.
2. No systematic monitoring of vendor record changes. Most AP teams have no automated way to know when a vendor's bank account, payment method, or contact details have been changed. Changes happen silently, and the first sign of fraud is a missed payment complaint from the legitimate vendor.
3. Reactive rather than proactive compliance. Many teams only review vendor records during an annual audit. By then, fraud may have been occurring for months. Real-time monitoring and mandatory sign-off on critical changes are far more effective than periodic reviews.
The Vendor Fraud Prevention Framework
Effective vendor fraud prevention is built on four pillars: Verify, Monitor, Control, and Audit.
Verify: Rigorous Vendor Onboarding
Every new vendor should go through a documented onboarding process before they are added to the vendor master file. At minimum this should include:
Monitor: Real-Time Change Detection
Once a vendor is in your system, the risk does not go away — it shifts to the ongoing management of that vendor's record. Every change to a vendor's bank account, payment method, billing address, or contact details should trigger an alert and require a documented sign-off before the next payment is released.
The most important changes to monitor are:
| Change Type | Risk Level | Required Action | |---|---|---| | Bank account number change | Critical | Written sign-off by authorized approver, callback to vendor | | Payment method change (ACH \→ Check, etc.) | Critical | Written sign-off by authorized approver | | Billing address change | High | Acknowledgment by AP manager | | Contact name or email change | Medium | Acknowledgment by AP staff | | Vendor name or DBA change | High | Verification against W-9 or state registration |
Control: Segregation of Duties
No single employee should be able to complete the full payment cycle without a second person's involvement. The minimum SoD requirements for a well-controlled AP environment are:
In small teams where strict SoD is difficult to achieve, compensating controls — such as mandatory manager review of all bank account changes, or automated alerts to the CFO for any payment above a threshold — can reduce the risk.
Audit: Continuous Audit Trail
Every action taken on a vendor record — who changed what, when, and why — should be logged automatically and be available for review at any time. A complete audit trail serves two purposes: it deters fraud by making it clear that actions are being recorded, and it enables rapid investigation when something goes wrong.
The audit trail should capture:
How Technology Helps: What to Look for in AP Fraud Prevention Software
Manual controls are a good starting point, but they do not scale. As your vendor count grows, the volume of changes and the complexity of monitoring increases faster than your team's capacity to keep up. AP fraud prevention software automates the most critical controls so that nothing falls through the cracks.
When evaluating tools, look for:
Vendor Fraud Prevention Checklist
Use this checklist to assess your current AP controls:
Onboarding controls:
Change monitoring controls:
Segregation of duties controls:
Audit and review controls:
Frequently Asked Questions
What is the most common type of vendor fraud?
Business email compromise (BEC) targeting bank account updates is currently the most common and most costly form of vendor fraud. The FBI's IC3 received 24,768 BEC complaints involving more than $3.0 billion in reported losses in 2025. The attack works by impersonating a vendor via email and convincing an AP team member to update the vendor's bank account details before the next payment run.
How can I verify a vendor's bank account details?
The safest method is an independent callback: after receiving a bank account update request, call the vendor using a phone number from your existing records (not from the request itself) and verbally confirm the new details. Do not rely on email confirmation alone, as the attacker may control the email thread. For high-value vendors, consider requiring a signed bank letter on the vendor's official letterhead.
What is segregation of duties in accounts payable?
Segregation of duties (SoD) in AP means that no single person controls the full payment cycle. At minimum, the person who can add or edit a vendor record should not be the same person who approves payments to that vendor. SoD violations are one of the strongest predictors of fraud risk in an AP environment and are a widely recognized internal-control principle and may also support an organization's audit, security, and cyber-insurance requirements.
How do I detect a ghost vendor?
Ghost vendors typically share characteristics with the employee who created them: matching address, phone number, or bank account. Run periodic reports comparing vendor contact details against employee records. Also look for vendors with no EIN, no physical address, or invoices that are always round numbers or just below an approval threshold.
What should I do if I suspect vendor fraud?
Immediately freeze any pending payments to the suspected vendor. Do not alert the suspected internal employee if insider fraud is possible. Preserve all email records, system logs, and audit trail data. Contact your bank immediately if a fraudulent payment has already been made — wire recall is time-sensitive. Engage your legal counsel and, if appropriate, law enforcement. Document everything.
Does cyber insurance cover vendor fraud?
Many cyber insurance policies include coverage for social engineering fraud (which covers BEC) and funds transfer fraud. However, coverage is often conditional on having documented controls in place — including verification procedures for bank account changes. Review your policy carefully and consult your broker. Implementing the controls described in this guide can both reduce your risk and strengthen your insurance position.
Summary
Vendor fraud is not a sophisticated, hard-to-stop threat. It is an opportunistic crime that succeeds when basic controls are absent. The AP teams most at risk are those that rely on trust and manual processes rather than systematic verification, monitoring, and sign-off workflows.
The four pillars of vendor fraud prevention — Verify, Monitor, Control, and Audit — are achievable for any organization, regardless of size. Start with the highest-risk area (bank account change monitoring and SoD enforcement), implement mandatory sign-off workflows, and build from there.
ApprovedAP helps teams using QuickBooks Online and connected AP payment systems monitor supported vendor changes, identify segregation-of-duties risks, track compliance documents, and maintain documented review workflows — all in one place.", }, { slug: "quickbooks-online-bill-integration-ap-teams-guide", title: "How QuickBooks Online and BILL Work Together for AP Teams", excerpt: "QuickBooks Online and BILL form one of the most powerful AP stacks available. Here is how the integration works, what it covers, and where the compliance gaps are that every AP team needs to address.
Ready to tighten your AP controls?
ApprovedAP gives you vendor compliance tracking, SoD violation detection, and payment controls in one place.
Get started free