The AP Team's Guide to Vendor Fraud Prevention

By ApprovedAP Team · July 9, 2026 · 13 min read

Vendor fraud is one of the most costly and preventable risks facing accounts payable teams today. According to the Association of Certified Fraud Examiners (ACFE), billing schemes are among the most common forms of asset misappropriation and can produce six-figure losses. For small and mid-market businesses, a single successful fraud can be existential.

The good news is that vendor fraud almost always exploits the same handful of weaknesses: inadequate vendor vetting, lack of segregation of duties, and no systematic monitoring of vendor record changes. Understanding these patterns is the first step toward stopping them.


What Is Vendor Fraud?

Vendor fraud occurs when a fraudster — whether an external attacker, a compromised vendor, or an internal employee — manipulates the accounts payable process to divert payments. The manipulation can happen at any point in the payment lifecycle: during vendor onboarding, when vendor bank details are updated, or when invoices are submitted for payment.

The term covers a wide spectrum of schemes, from sophisticated business email compromise (BEC) attacks that trick AP staff into updating bank account numbers, to simple ghost vendor schemes where an employee creates a fictitious supplier and approves payments to themselves.


The 5 Most Common Vendor Fraud Schemes

1. Business Email Compromise (BEC) — Bank Account Fraud

BEC is one of the most financially damaging forms of payment fraud affecting businesses. In a typical attack, a fraudster impersonates a vendor — often by spoofing or compromising the vendor's email domain — and sends a convincing request to update the vendor's bank account details. An AP team member updates the record in good faith. The next payment goes to the attacker's account.

The FBI's Internet Crime Complaint Center received 24,768 business email compromise complaints involving more than $3.0 billion in reported losses in 2025. The average loss per incident is far higher than most other fraud types because payments are often large and the fraud is not discovered until the legitimate vendor follows up on a missed payment — weeks or months later.

Key warning signs:

  • A vendor requests a bank account change via email, especially if the request comes from a slightly different email address than usual
  • The request is marked urgent or asks you to process a payment before the change is "officially" confirmed
  • The new bank account is at a different institution than the existing one, or is a personal account rather than a business account
  • 2. Ghost Vendor Schemes

    A ghost vendor is a fictitious supplier created in the AP system — usually by an employee with both the ability to add vendors and the ability to approve payments. The employee creates the vendor, submits invoices for services never rendered, and approves payment to an account they control.

    Ghost vendor fraud is an insider threat and is almost always enabled by a failure of segregation of duties (SoD) — the principle that no single person should control the full payment cycle from vendor creation to payment approval.

    Key warning signs:

  • Vendors with no physical address, no EIN, or contact details that match an employee's personal information
  • Vendors that receive payments but have never been through a formal onboarding or approval process
  • Invoices that are round numbers, just below an approval threshold, or submitted at regular intervals with no supporting documentation
  • 3. Invoice Fraud and Duplicate Payments

    Invoice fraud takes several forms: a fraudster submits inflated invoices for legitimate services, submits invoices for services never delivered, or submits the same invoice multiple times hoping that one slips through. Duplicate payments are also a common form of accidental loss that fraudsters can deliberately exploit by submitting slightly altered versions of the same invoice.

    Key warning signs:

  • Invoices with sequential numbers that suggest a small vendor is submitting a high volume of invoices
  • Invoices that lack a purchase order number or do not match an existing PO
  • The same vendor submitting invoices from multiple email addresses
  • 4. Vendor Master File Manipulation

    The vendor master file is the single most important data asset in your AP process — and one of the most vulnerable. Any employee with write access to the vendor master can change a legitimate vendor's bank account, address, or payment method to redirect payments. Unlike BEC, this is an insider attack, but the mechanics are identical: the payment goes to the right vendor name but the wrong account.

    Key warning signs:

  • Changes to vendor bank accounts or payment methods made by AP staff without a documented approval process
  • No audit trail showing who changed what and when in the vendor master
  • Vendor records that have been updated shortly before a large payment is processed
  • 5. Fictitious or Inflated Expense Reimbursements

    While not strictly a vendor fraud, expense reimbursement fraud follows the same pattern: an employee submits claims for expenses that were never incurred, or inflates legitimate expenses. In companies where expense reimbursements flow through the AP system alongside vendor payments, the same controls apply.


    The Root Cause: Why AP Teams Are Vulnerable

    Most vendor fraud succeeds not because the attackers are sophisticated, but because the target organization lacks basic controls. The three most common root causes are:

    1. No segregation of duties. When the same person can add a vendor, approve an invoice, and release a payment, fraud is trivially easy. SoD violations are the single most reliable predictor of fraud risk in an AP environment.

    2. No systematic monitoring of vendor record changes. Most AP teams have no automated way to know when a vendor's bank account, payment method, or contact details have been changed. Changes happen silently, and the first sign of fraud is a missed payment complaint from the legitimate vendor.

    3. Reactive rather than proactive compliance. Many teams only review vendor records during an annual audit. By then, fraud may have been occurring for months. Real-time monitoring and mandatory sign-off on critical changes are far more effective than periodic reviews.


    The Vendor Fraud Prevention Framework

    Effective vendor fraud prevention is built on four pillars: Verify, Monitor, Control, and Audit.

    Verify: Rigorous Vendor Onboarding

    Every new vendor should go through a documented onboarding process before they are added to the vendor master file. At minimum this should include:

  • Verification of the vendor's legal name and EIN against IRS records (a completed W-9 is the standard mechanism)
  • Verification of the vendor's bank account details via a callback to a phone number obtained independently — not from the onboarding request itself
  • Collection of a certificate of insurance (COI) for vendors providing services on-site or with liability exposure
  • A documented approval by someone other than the person who initiated the onboarding
  • Monitor: Real-Time Change Detection

    Once a vendor is in your system, the risk does not go away — it shifts to the ongoing management of that vendor's record. Every change to a vendor's bank account, payment method, billing address, or contact details should trigger an alert and require a documented sign-off before the next payment is released.

    The most important changes to monitor are:

    | Change Type | Risk Level | Required Action | |---|---|---| | Bank account number change | Critical | Written sign-off by authorized approver, callback to vendor | | Payment method change (ACH \→ Check, etc.) | Critical | Written sign-off by authorized approver | | Billing address change | High | Acknowledgment by AP manager | | Contact name or email change | Medium | Acknowledgment by AP staff | | Vendor name or DBA change | High | Verification against W-9 or state registration |

    Control: Segregation of Duties

    No single employee should be able to complete the full payment cycle without a second person's involvement. The minimum SoD requirements for a well-controlled AP environment are:

  • The person who adds or edits a vendor record should not be the same person who approves payments to that vendor
  • The person who approves an invoice should not be the same person who releases the payment
  • Bank account changes should require approval by someone who does not have day-to-day AP access
  • In small teams where strict SoD is difficult to achieve, compensating controls — such as mandatory manager review of all bank account changes, or automated alerts to the CFO for any payment above a threshold — can reduce the risk.

    Audit: Continuous Audit Trail

    Every action taken on a vendor record — who changed what, when, and why — should be logged automatically and be available for review at any time. A complete audit trail serves two purposes: it deters fraud by making it clear that actions are being recorded, and it enables rapid investigation when something goes wrong.

    The audit trail should capture:

  • All changes to vendor master data (the available change details, responsible user, and timestamp, depending on the connected system)
  • All invoice approvals and payment releases (user, timestamp, amount)
  • All sign-offs on critical changes (user, timestamp, note)
  • All vendor onboarding approvals (user, timestamp)

  • How Technology Helps: What to Look for in AP Fraud Prevention Software

    Manual controls are a good starting point, but they do not scale. As your vendor count grows, the volume of changes and the complexity of monitoring increases faster than your team's capacity to keep up. AP fraud prevention software automates the most critical controls so that nothing falls through the cracks.

    When evaluating tools, look for:

  • Automated change detection that flags supported vendor changes based on data available from connected systems
  • Mandatory sign-off workflows that create a documented review and sign-off workflow before the team proceeds with payment
  • Segregation of duties enforcement that identifies and alerts on SoD violations — for example, flagging when the same user who edited a vendor's bank account is also the approver for the next payment to that vendor
  • Document compliance tracking that monitors COI expiration and W-9 information and COI expiration dates and sends automatic reminders before documents lapse
  • Full audit trail with documented, exportable activity history for auditors and cyber insurance claims
  • Integration with your existing payment platform (BILL and QuickBooks Online) so that monitoring happens where the data lives, not in a separate system that requires manual data entry

  • Vendor Fraud Prevention Checklist

    Use this checklist to assess your current AP controls:

    Onboarding controls:

  • All new vendors complete a W-9 before first payment
  • Bank account details are verified via an independent callback
  • COI is collected for service vendors
  • Vendor onboarding requires approval by someone other than the requestor
  • Change monitoring controls:

  • All changes to vendor bank accounts trigger an immediate alert
  • Bank account changes require a documented sign-off before the next payment
  • All vendor record changes are logged with user, timestamp, and old/new values
  • Segregation of duties controls:

  • No single user can add a vendor AND approve payments to that vendor
  • Bank account changes require approval by someone outside day-to-day AP
  • SoD violations are reviewed at least quarterly
  • Audit and review controls:

  • A complete audit trail is maintained for all vendor master changes
  • The audit trail is reviewed by someone outside AP at least monthly
  • Vendor master file is reconciled against payment records at least quarterly

  • Frequently Asked Questions

    What is the most common type of vendor fraud?

    Business email compromise (BEC) targeting bank account updates is currently the most common and most costly form of vendor fraud. The FBI's IC3 received 24,768 BEC complaints involving more than $3.0 billion in reported losses in 2025. The attack works by impersonating a vendor via email and convincing an AP team member to update the vendor's bank account details before the next payment run.

    How can I verify a vendor's bank account details?

    The safest method is an independent callback: after receiving a bank account update request, call the vendor using a phone number from your existing records (not from the request itself) and verbally confirm the new details. Do not rely on email confirmation alone, as the attacker may control the email thread. For high-value vendors, consider requiring a signed bank letter on the vendor's official letterhead.

    What is segregation of duties in accounts payable?

    Segregation of duties (SoD) in AP means that no single person controls the full payment cycle. At minimum, the person who can add or edit a vendor record should not be the same person who approves payments to that vendor. SoD violations are one of the strongest predictors of fraud risk in an AP environment and are a widely recognized internal-control principle and may also support an organization's audit, security, and cyber-insurance requirements.

    How do I detect a ghost vendor?

    Ghost vendors typically share characteristics with the employee who created them: matching address, phone number, or bank account. Run periodic reports comparing vendor contact details against employee records. Also look for vendors with no EIN, no physical address, or invoices that are always round numbers or just below an approval threshold.

    What should I do if I suspect vendor fraud?

    Immediately freeze any pending payments to the suspected vendor. Do not alert the suspected internal employee if insider fraud is possible. Preserve all email records, system logs, and audit trail data. Contact your bank immediately if a fraudulent payment has already been made — wire recall is time-sensitive. Engage your legal counsel and, if appropriate, law enforcement. Document everything.

    Does cyber insurance cover vendor fraud?

    Many cyber insurance policies include coverage for social engineering fraud (which covers BEC) and funds transfer fraud. However, coverage is often conditional on having documented controls in place — including verification procedures for bank account changes. Review your policy carefully and consult your broker. Implementing the controls described in this guide can both reduce your risk and strengthen your insurance position.


    Summary

    Vendor fraud is not a sophisticated, hard-to-stop threat. It is an opportunistic crime that succeeds when basic controls are absent. The AP teams most at risk are those that rely on trust and manual processes rather than systematic verification, monitoring, and sign-off workflows.

    The four pillars of vendor fraud prevention — Verify, Monitor, Control, and Audit — are achievable for any organization, regardless of size. Start with the highest-risk area (bank account change monitoring and SoD enforcement), implement mandatory sign-off workflows, and build from there.

    ApprovedAP helps teams using QuickBooks Online and connected AP payment systems monitor supported vendor changes, identify segregation-of-duties risks, track compliance documents, and maintain documented review workflows — all in one place.", }, { slug: "quickbooks-online-bill-integration-ap-teams-guide", title: "How QuickBooks Online and BILL Work Together for AP Teams", excerpt: "QuickBooks Online and BILL form one of the most powerful AP stacks available. Here is how the integration works, what it covers, and where the compliance gaps are that every AP team needs to address.

    Ready to tighten your AP controls?

    ApprovedAP gives you vendor compliance tracking, SoD violation detection, and payment controls in one place.

    Get started free