Accounts Payable Fraud: 8 Schemes Targeting Your AP Process (2026)
Accounts payable is where money leaves the building. It's also where fraud hides. Some of it comes from outside — scammers impersonating vendors or intercepting payment instructions. Some of it comes from inside — employees with AP system access exploiting gaps in oversight. Either way, the AP process is the target, and the playbook is more consistent than most business owners realize. This guide covers the 8 schemes most likely to hit a small business AP process, what each one looks like in practice, and the controls that stop them before a payment goes out.
Internal vs. External AP Fraud
AP fraud divides into two broad categories, and understanding which you're dealing with changes which controls matter most.
| External fraud | Internal (occupational) fraud |
|---|---|
| Committed by outsiders — scammers, fraudulent vendors, criminals intercepting payments | Committed by employees with AP system access — often the person processing payments |
| Relies on impersonation, social engineering, or intercepted communications | Relies on system access, weak controls, and lack of oversight |
| Often a single large payment or a short, intensive campaign | Often small recurring amounts designed to stay below review thresholds for months |
| Defense: verify payment requests independently before acting | Defense: segregation of duties, mandatory review, audit trails |
According to the ACFE, more than half of occupational fraud cases are enabled by a lack of internal controls — or by employees who can override the controls that do exist. For small businesses, where one person often handles vendor setup, invoice approval, and payment processing, this gap is structurally built in.
Small businesses with fewer than 100 employees had a median fraud loss of $141,000 per case in the ACFE's 2024 study — the second highest of any organization size. Smaller teams mean fewer people reviewing the same transactions, and that gap is exactly what internal and external fraudsters exploit.
8 AP Fraud Schemes — How Each One Works
Each card below includes a risk rating, whether the scheme is typically internal, external, or both, and the specific control that stops it.
An employee with access to the vendor master file creates a fictitious supplier — sometimes using a name that closely resembles a real one — and begins submitting invoices for goods or services that were never delivered. Payments flow to a bank account the employee controls, directly or through a shell company. Ghost vendors typically submit small, recurring invoices specifically to stay below approval thresholds, and can run undetected for a year or more.
An email arrives claiming to be from an existing vendor, notifying the AP team of a bank account change. The new routing and account numbers belong to an attacker-controlled account. The next legitimate payment to that vendor — sometimes a large one — goes to the wrong place. By the time the real vendor follows up on a missed payment, the funds are gone. This scheme is the external mirror of ghost vendor fraud: instead of creating a fake supplier, the attacker hijacks a real one.
Either a fraudulent vendor submits invoices for goods or services never provided, or an internal employee collude with a real vendor to inflate legitimate invoices and split the difference. Fictitious invoices from outside are common when vendor onboarding has no verification step. Inflated invoices from inside are common when the same person who receives goods also approves the invoice — there's no one to catch the discrepancy.
The same invoice is submitted more than once — sometimes by an external vendor testing whether the AP process has automated duplicate detection, sometimes by an internal employee submitting a real invoice and a copy to a personal account. Duplicate invoices are often modified slightly: the invoice number might be incremented by one digit, the date changed, or the amount rounded up or down to avoid triggering an exact-match flag.
An attacker impersonates an executive (CEO fraud) or a known vendor via a spoofed or lookalike email address and requests an urgent wire transfer or instructs AP to update a vendor's bank details. The email may cite a time-sensitive deal, a pending audit, or a confidential acquisition. BEC affected 74% of organizations in 2025 according to the AFP's 2026 survey — a significant increase from prior years — making it the single most common vector for AP payment fraud.
An employee sets up a legitimate-looking shell company — sometimes registering it as an actual business entity — and then approves invoices from that company within the AP system. Because the vendor has a real tax ID, business address, and bank account, it passes basic checks. The scheme typically runs for months or years before a vendor audit or employee departure uncovers it. The ACFE identifies this as a pass-through scheme variant of ghost vendor fraud.
A vendor offers an employee a kickback — cash, gifts, or a percentage of contract value — in exchange for favorable treatment: approving inflated invoices, selecting the vendor for contracts, or overlooking overbilling. Collusion is harder to detect than solo schemes because both parties are motivated to conceal it, and the vendor relationship appears legitimate. The ACFE reports that corruption schemes, which include kickbacks, cause a median loss of $200,000 — higher than asset misappropriation schemes.
Check tampering involves altering a legitimate check — changing the payee name or amount — before it's deposited. Check fraud was reported by 58% of organizations in the 2026 AFP survey, making it the most common payment method targeted despite declining check usage overall. ACH redirection is the electronic equivalent: an attacker or insider alters ACH payment instructions to redirect funds to a different account. Both exploit the same gap — payment details that can be changed after authorization.
The Controls That Actually Stop AP Fraud
Most AP fraud is enabled by the same handful of control gaps. These are the fixes that matter most for small businesses where one or two people handle the full payment cycle.
- Segregation of duties — the person who sets up a vendor should not be the person who approves that vendor's invoices, and neither should be the person who initiates payment. Even a partial separation closes the most common internal fraud path.
- Voice verification for banking changes — any request to change a vendor's bank details requires a callback to a number from your existing vendor file, not the number in the change request.
- Purchase order matching — every invoice should match a purchase order. Invoices without a PO match go to a hold queue, not straight to payment.
- Dual authorization above a threshold — payments above a defined amount require a second approver who is independent of the first.
- New vendor verification — before a first payment, verify the vendor's physical address, phone number, and tax ID against public records. A PO box, residential address, or unregistered business name is a reason to investigate before paying.
- Regular vendor master file audit — periodically review the vendor list for shared addresses, phone numbers, bank accounts, or names similar to existing vendors.
- Weekly bank reconciliation — monthly reconciliation means fraud can run for weeks before anyone notices. Weekly catches it faster.
- Pre-payment fraud check — run the vendor, routing number, and any changed banking detail through PaySentinel before authorizing payment, especially for new vendors or changed bank details.
Mandatory vacation for AP staff.
It sounds unrelated to fraud prevention, but the ACFE specifically recommends it: internal AP fraud typically depends on the perpetrator staying continuously present to approve invoices and intercept bank statements. When someone is forced to be away, a substitute often discovers the irregularity. Some organizations make it a policy that AP roles above a threshold require a minimum consecutive vacation period each year.
What a Pre-Payment Check Catches
A structured fraud check before payment is the external equivalent of an internal control — it verifies signals that your AP process can't see from inside your own system.
| Signal | How PaySentinel checks it | Type |
|---|---|---|
| Routing / account numberChanged banking detail on a vendor invoice | Compared against known routing number records and flagged if it doesn't match the vendor's prior history | Mechanical |
| Vendor domainLookalike or newly registered domain on an invoice email | Checked against the vendor's known domain and flagged for typosquatting patterns | Mechanical |
| Urgency & pressure language"Process immediately," "confidential," "bypass normal approval" | Flagged against BEC and social engineering language patterns from real fraud investigations | AI-assisted |
| Vendor memoryWhether this routing number matches what you've paid before | Compared against previously submitted details for this vendor across your payment history | Mechanical |
| Invoice signalsMissing PO reference, round amounts, no itemization | Flagged against patterns common in fictitious and inflated invoice schemes | AI-assisted |
Frequently Asked Questions
Accounts payable fraud is any scheme that manipulates a business's payment process to divert funds illegally. It can be external — a scammer impersonating a vendor or intercepting payment instructions — or internal, carried out by an employee with AP system access. Common schemes include ghost vendors, fictitious invoices, duplicate payments, banking detail changes, and business email compromise targeting the AP team.
The ACFE's 2024 Report to the Nations estimates that the typical organization loses 5% of annual revenue to occupational fraud, with a global median loss of $145,000 per case. For small businesses with fewer than 100 employees, the median loss was $141,000. The 2026 AFP Payments Fraud and Control Survey found that 76% of US organizations experienced attempted or actual payments fraud in 2025, and 48% of organizations with revenue under $1 billion reported financial losses from fraud.
A ghost vendor is a fictitious supplier set up in a company's vendor master file — usually by an employee with AP system access — to receive payments for goods or services never delivered. Ghost vendors often use names similar to real suppliers and submit small, recurring invoices to stay below approval thresholds. Because payments look routine, they can go undetected for months or years.
Duplicate invoice fraud involves submitting the same invoice more than once — sometimes with minor changes to the invoice number, date, or amount to avoid automated detection. Detection requires comparing new invoices against payment history for the same vendor, amount, and date range. Invoices that arrive without a matching purchase order should always be held for manual review before payment.
Segregation of duties — making sure the same person cannot both set up a vendor and approve that vendor's invoices — is consistently identified as the most effective single control. The ACFE found that more than half of occupational fraud cases were enabled by a lack of controls or the ability to override existing controls. For small businesses where one person handles multiple AP roles, compensating controls like dual authorization above a threshold and mandatory management review become especially important.
Check a vendor or invoice before you pay
Run the routing number, vendor name, or a suspicious invoice through PaySentinel before authorizing payment. It takes under a minute and it's free to start.
Run a free check →