All Posts

Procure Tech

Invoice Fraud in Procurement: How It Actually Works, and What Catches It

Invoice Fraud in Procurement: How It Actually Works, and What Catches It

Bhavika J

Editorial Team

Invoice fraud is not one problem. It is at least two, and procurement teams that treat it as one tend to buy the wrong control.

The first is internal: an employee sets up a fictitious vendor, or inflates a real one's invoices, and routes payment to an account they control. The second is external: a fraudster impersonates a real supplier, usually by email, and asks accounts payable to redirect payment to a new bank account. Both show up as "invoice fraud" in a postmortem. Neither is stopped by the same control.

Why this is still a live problem

Payments fraud has not become rare as automation has spread. In the Association for Financial Professionals' 2026 Payments Fraud and Control Survey, 76% of organizations reported attempted or actual payments fraud in 2025, and 74% said they were affected by business email compromise specifically. Just 17% of respondents said they use AI to help combat it, which means most of the fraud detection burden still sits on manual review and static rules.

The internal side is documented separately. The Association of Certified Fraud Examiners' 2026 Report to the Nations, drawn from 2,402 cases across 143 countries, found asset misappropriation, the category that includes billing schemes, is present in 90% of occupational fraud cases, with a median loss of $100,000 per case. Across all fraud types in the study, the median case ran 12 months before anyone caught it, and organizations without a formal reporting mechanism took 17 months to detect a scheme and lost a median of $150,000, 50% more than organizations that had one.

Why three-way matching doesn't close this gap

Three-way matching checks that a purchase order, a receipt and an invoice agree on what was ordered, received and billed. That catches a supplier billing for goods that never arrived. It does not catch a real invoice, for real goods, with someone else's bank details attached to it. A vendor impersonation scam produces a document that matches a genuine PO on every field except the payment instruction. The match passes. The money leaves.

This is the specific blind spot invoice fraud tooling is built to address, and it is why the control layer looks different from standard AP workflow.

The three approaches, and how they differ

Out-of-band payment verification: any change to a supplier's bank details triggers a callback to a phone number on file before the change takes effect, not a reply to whatever email requested it. This is the single control most directly aimed at BEC-style vendor impersonation, and it is procedural as much as it is software.

Anomaly and duplicate detection: software that flags near-duplicate vendor records (same tax ID, similar address, a name one character off an existing supplier), duplicate invoice numbers, and payments that deviate from a vendor's historical pattern. This is where AI-assisted AP tools have made the most visible progress, though adoption is still the minority case.

Segregation of duties in the workflow itself: the person who can add a vendor cannot also approve payment to that vendor. This is the oldest control on this list and the one fraud case data keeps validating: internal billing schemes require a single point of control failure, and segregation of duties removes it.

What to check before buying

Does the tool verify bank detail changes through a channel the requester doesn't control, or does it just log the change. Does it flag vendor records that resemble existing ones, not just exact duplicates. Can it integrate with the existing source-to-pay stack, or does it become a second system nobody checks under deadline pressure. What is the false positive rate, since a tool that flags every invoice trains staff to ignore the flags. Is there an audit trail that would hold up if the case became a real investigation.

What commonly goes wrong

Teams buy a duplicate-invoice detector and treat the fraud problem as solved. It solves one pathway. Vendor impersonation fraud, the kind behind most business email compromise losses, runs through a completely different door: the bank detail change, not the invoice line. A control set that only checks invoices and never checks payment instruction changes will pass an audit and still lose money.

The other common failure is treating this as a one-time implementation. Detection time correlates directly with loss size, which argues for continuous monitoring over periodic review. A control that only runs at quarter close catches the fraud that has already run for a quarter.

Sources: Association for Financial Professionals: 2026 Payments Fraud and Control Survey · AFP press release · ACFE: Occupational Fraud 2026