AP Fraud Red Flags: A Checklist for Finance Teams
Accounts payable is where money actually leaves the company — which is exactly why it's the function fraud concentrates in.
Most financial fraud that hits a company's bank account directly runs through accounts payable, because AP is the function that actually authorizes money to leave. It doesn't usually look dramatic. It looks like a normal invoice, from what looks like a normal vendor, processed through a normal approval — which is exactly why the controls that catch it have to be specific rather than relying on someone's gut feeling that something's off.
The common patterns
- Fictitious vendor invoices — a fake vendor (sometimes created by an employee) bills for goods or services that were never provided.
- Duplicate invoice submission — the same invoice submitted twice, sometimes with a slightly altered invoice number, hoping it slips past a manual check.
- Vendor impersonation / business email compromise — a convincing email, appearing to be from a real vendor, asks AP to update banking details before the next payment.
- Inflated or padded invoices — a legitimate vendor overbills, counting on volume or complexity to make it hard to notice.
- Invoices split just under an approval threshold — two smaller invoices instead of one, specifically to avoid a required second approval.
Red flags worth building a checklist around
- A vendor requests a bank detail change by email, with no independent verification.
- A new vendor is added with minimal supporting information — no verified tax ID, no physical address that checks out.
- Invoice numbers are sequential or suspiciously round in a way that doesn't match how the vendor normally bills.
- An invoice amount lands just under a manager's approval threshold.
- A vendor's registered address matches an employee's home address.
- Language in the request creates urgency — "needs to go out today" — especially paired with a request to skip the normal process.
- High-value invoices arrive with no associated purchase order at all.
Controls that actually reduce the risk
None of these red flags are proof of fraud on their own — they're reasons to slow down and verify. The controls that consistently reduce AP fraud risk aren't exotic; they're structural:
- Segregation of duties — the person who requests a payment, the person who approves it, and the person who releases it shouldn't be the same person.
- Vendor master file change controls — any change to a vendor's bank details gets verified by phone, using a number already on file, never the number in the email making the request.
- 3-way match on PO-backed spend, to confirm goods or services were actually received before payment.
- Clear approval thresholds that scale with amount, with no easy path to just split an invoice around them.
- An audit trail that records who did what and when, so a suspicious pattern can actually be traced instead of argued about after the fact.
How Vyomiyra helps
Automation is good at surfacing the anomaly — a bank detail that just changed, an invoice number that looks duplicated, a new vendor with a thin file. It's not a substitute for the phone call that verifies a change is real. Vyomiyra is built to flag what needs a second look; the verification itself stays a human step, on purpose.
