Guide · AP & Payment Fraud

Accounts Payable Fraud: 8 Schemes Targeting Your AP Process (2026)

July 2026 AP Clerks Bookkeepers Small Business 9 min read

Accounts payable is where money leaves the building. It's also where fraud hides. Some of it comes from outside — scammers impersonating vendors or intercepting payment instructions. Some of it comes from inside — employees with AP system access exploiting gaps in oversight. Either way, the AP process is the target, and the playbook is more consistent than most business owners realize. This guide covers the 8 schemes most likely to hit a small business AP process, what each one looks like in practice, and the controls that stop them before a payment goes out.

76%
of US organizations experienced attempted or actual payments fraud in 2025, per the 2026 AFP Survey
5%
of annual revenue lost to occupational fraud on average — ACFE 2024 Report to the Nations
12 mo
median time before AP fraud is detected — it typically runs for a full year before anyone notices

Internal vs. External AP Fraud

AP fraud divides into two broad categories, and understanding which you're dealing with changes which controls matter most.

External fraud Internal (occupational) fraud
Committed by outsiders — scammers, fraudulent vendors, criminals intercepting payments Committed by employees with AP system access — often the person processing payments
Relies on impersonation, social engineering, or intercepted communications Relies on system access, weak controls, and lack of oversight
Often a single large payment or a short, intensive campaign Often small recurring amounts designed to stay below review thresholds for months
Defense: verify payment requests independently before acting Defense: segregation of duties, mandatory review, audit trails

According to the ACFE, more than half of occupational fraud cases are enabled by a lack of internal controls — or by employees who can override the controls that do exist. For small businesses, where one person often handles vendor setup, invoice approval, and payment processing, this gap is structurally built in.

⚠️ The small business problem

Small businesses with fewer than 100 employees had a median fraud loss of $141,000 per case in the ACFE's 2024 study — the second highest of any organization size. Smaller teams mean fewer people reviewing the same transactions, and that gap is exactly what internal and external fraudsters exploit.

8 AP Fraud Schemes — How Each One Works

Each card below includes a risk rating, whether the scheme is typically internal, external, or both, and the specific control that stops it.

1
Ghost vendor / fictitious supplier
Internal Critical

An employee with access to the vendor master file creates a fictitious supplier — sometimes using a name that closely resembles a real one — and begins submitting invoices for goods or services that were never delivered. Payments flow to a bank account the employee controls, directly or through a shell company. Ghost vendors typically submit small, recurring invoices specifically to stay below approval thresholds, and can run undetected for a year or more.

Documented case
A school principal and his brother-in-law established a fake cleaning company and invoiced a school district for $1.4 million in maintenance services that were never performed. The vendor passed system checks because the invoices looked routine and no one cross-referenced the vendor's tax ID against existing suppliers.
Defense → Separate vendor setup from invoice approval. The person who creates a vendor should never be the person who approves that vendor's invoices. Periodically audit the vendor master file for entries with shared addresses, phone numbers, or bank accounts, and verify any new vendor against public business records before the first payment.
2
Vendor banking detail change (payment diversion)
External Critical

An email arrives claiming to be from an existing vendor, notifying the AP team of a bank account change. The new routing and account numbers belong to an attacker-controlled account. The next legitimate payment to that vendor — sometimes a large one — goes to the wrong place. By the time the real vendor follows up on a missed payment, the funds are gone. This scheme is the external mirror of ghost vendor fraud: instead of creating a fake supplier, the attacker hijacks a real one.

Why it works
The request arrives by email, looks routine, and targets a process most AP teams handle without a callback requirement. Attackers often research the real vendor relationship first — knowing invoice amounts, billing cycles, and the AP contact's name — to make the request harder to question.
Defense → Require a voice callback to a number from your existing vendor file — never the number provided in the change request — before updating any banking detail. Treat any email-only banking change as unverified regardless of how official it looks. Run the new routing number through PaySentinel before processing the first payment to the changed account.
3
Fictitious or inflated invoice
Internal / External Critical

Either a fraudulent vendor submits invoices for goods or services never provided, or an internal employee collude with a real vendor to inflate legitimate invoices and split the difference. Fictitious invoices from outside are common when vendor onboarding has no verification step. Inflated invoices from inside are common when the same person who receives goods also approves the invoice — there's no one to catch the discrepancy.

Common tell
Invoices for intangible or difficult-to-verify services — consulting, IT support, cleaning, maintenance — where there's no physical delivery to confirm. Amounts just below approval thresholds. Invoices submitted without a corresponding purchase order.
Defense → Match every invoice to a purchase order before approving payment. Require a second sign-off for invoices without a PO match, for services that can't be physically verified, and for any invoice amount above a defined threshold. Flag vendors who submit only for intangible services with no prior relationship.
4
Duplicate invoice submission
Internal / External High

The same invoice is submitted more than once — sometimes by an external vendor testing whether the AP process has automated duplicate detection, sometimes by an internal employee submitting a real invoice and a copy to a personal account. Duplicate invoices are often modified slightly: the invoice number might be incremented by one digit, the date changed, or the amount rounded up or down to avoid triggering an exact-match flag.

Detection gap
Most manual AP processes check for exact invoice number matches but miss near-duplicates — same vendor, same amount, different invoice number. A payment made twice to the same vendor in a short window for similar amounts is the signal to investigate.
Defense → Before approving any invoice, search your payment history for the same vendor, similar amount, and similar date range. Require original invoice documentation rather than photocopies or re-submissions. Flag any invoice that arrives without a purchase order match.
5
Business email compromise targeting AP
External Critical

An attacker impersonates an executive (CEO fraud) or a known vendor via a spoofed or lookalike email address and requests an urgent wire transfer or instructs AP to update a vendor's bank details. The email may cite a time-sensitive deal, a pending audit, or a confidential acquisition. BEC affected 74% of organizations in 2025 according to the AFP's 2026 survey — a significant increase from prior years — making it the single most common vector for AP payment fraud.

Classic pattern
An AP manager receives an urgent email appearing to come from the CFO's address, asking for an immediate wire to a new account for a deal that must stay confidential. The email address differs from the CFO's real address by one character. No phone confirmation is requested.
Defense → Establish a firm policy: any payment request that arrives only by email — regardless of who appears to have sent it — requires voice confirmation before execution. Urgency and confidentiality language in a payment request are themselves red flags, not reasons to skip verification.
6
Shell company billing scheme
Internal High

An employee sets up a legitimate-looking shell company — sometimes registering it as an actual business entity — and then approves invoices from that company within the AP system. Because the vendor has a real tax ID, business address, and bank account, it passes basic checks. The scheme typically runs for months or years before a vendor audit or employee departure uncovers it. The ACFE identifies this as a pass-through scheme variant of ghost vendor fraud.

Warning signs
A vendor with a recently registered business address, a PO box, or a residential address. A vendor whose invoices are always approved by the same AP employee. A vendor who has never been visited, called, or referenced by anyone outside the AP department.
Defense → Verify the physical address of any vendor receiving significant payments — a residential address or PO box warrants a phone call. Require that new vendors above a threshold be approved by someone outside AP. Rotate who approves invoices from specific vendors when possible.
7
Kickback and collusion scheme
Internal High

A vendor offers an employee a kickback — cash, gifts, or a percentage of contract value — in exchange for favorable treatment: approving inflated invoices, selecting the vendor for contracts, or overlooking overbilling. Collusion is harder to detect than solo schemes because both parties are motivated to conceal it, and the vendor relationship appears legitimate. The ACFE reports that corruption schemes, which include kickbacks, cause a median loss of $200,000 — higher than asset misappropriation schemes.

What to watch for
An AP employee who consistently champions a specific vendor, resists competitive bidding, or becomes defensive when a vendor's invoices are questioned. A vendor relationship where prices have drifted upward over time without a clear explanation. Vendor invoices that are always approved quickly without the scrutiny applied to others.
Defense → Require competitive bidding for contracts above a threshold. Rotate vendor relationships periodically. Implement a clear conflict-of-interest policy requiring employees to disclose personal relationships with vendors. Mandatory vacation for AP staff can surface irregularities — fraud often depends on the perpetrator staying continuously in place.
8
Check tampering and ACH redirection
Internal / External High

Check tampering involves altering a legitimate check — changing the payee name or amount — before it's deposited. Check fraud was reported by 58% of organizations in the 2026 AFP survey, making it the most common payment method targeted despite declining check usage overall. ACH redirection is the electronic equivalent: an attacker or insider alters ACH payment instructions to redirect funds to a different account. Both exploit the same gap — payment details that can be changed after authorization.

Why checks remain the top target
Checks carry all the information needed to commit fraud on their face — account number, routing number, payee — and paper security features are significantly easier to bypass than electronic authentication controls.
Defense → Reconcile bank statements against issued checks and ACH records weekly, not monthly. Use Positive Pay for checks if your bank offers it — it flags payments that don't match issued check records. For ACH, verify routing and account numbers against your vendor file before initiating any payment, and confirm any changes through a known contact at the vendor.
Received an invoice or banking change request you want to verify? PaySentinel checks routing numbers, vendor details, and invoice signals in under a minute — free, no account required.
Check it now →

The Controls That Actually Stop AP Fraud

Most AP fraud is enabled by the same handful of control gaps. These are the fixes that matter most for small businesses where one or two people handle the full payment cycle.

The one control that compounds everything else

Mandatory vacation for AP staff.

It sounds unrelated to fraud prevention, but the ACFE specifically recommends it: internal AP fraud typically depends on the perpetrator staying continuously present to approve invoices and intercept bank statements. When someone is forced to be away, a substitute often discovers the irregularity. Some organizations make it a policy that AP roles above a threshold require a minimum consecutive vacation period each year.

What a Pre-Payment Check Catches

A structured fraud check before payment is the external equivalent of an internal control — it verifies signals that your AP process can't see from inside your own system.

Signal How PaySentinel checks it Type
Routing / account numberChanged banking detail on a vendor invoice Compared against known routing number records and flagged if it doesn't match the vendor's prior history Mechanical
Vendor domainLookalike or newly registered domain on an invoice email Checked against the vendor's known domain and flagged for typosquatting patterns Mechanical
Urgency & pressure language"Process immediately," "confidential," "bypass normal approval" Flagged against BEC and social engineering language patterns from real fraud investigations AI-assisted
Vendor memoryWhether this routing number matches what you've paid before Compared against previously submitted details for this vendor across your payment history Mechanical
Invoice signalsMissing PO reference, round amounts, no itemization Flagged against patterns common in fictitious and inflated invoice schemes AI-assisted

Frequently Asked Questions

What is accounts payable fraud?

Accounts payable fraud is any scheme that manipulates a business's payment process to divert funds illegally. It can be external — a scammer impersonating a vendor or intercepting payment instructions — or internal, carried out by an employee with AP system access. Common schemes include ghost vendors, fictitious invoices, duplicate payments, banking detail changes, and business email compromise targeting the AP team.

How much does AP fraud cost businesses?

The ACFE's 2024 Report to the Nations estimates that the typical organization loses 5% of annual revenue to occupational fraud, with a global median loss of $145,000 per case. For small businesses with fewer than 100 employees, the median loss was $141,000. The 2026 AFP Payments Fraud and Control Survey found that 76% of US organizations experienced attempted or actual payments fraud in 2025, and 48% of organizations with revenue under $1 billion reported financial losses from fraud.

What is a ghost vendor?

A ghost vendor is a fictitious supplier set up in a company's vendor master file — usually by an employee with AP system access — to receive payments for goods or services never delivered. Ghost vendors often use names similar to real suppliers and submit small, recurring invoices to stay below approval thresholds. Because payments look routine, they can go undetected for months or years.

How do you detect duplicate invoice fraud?

Duplicate invoice fraud involves submitting the same invoice more than once — sometimes with minor changes to the invoice number, date, or amount to avoid automated detection. Detection requires comparing new invoices against payment history for the same vendor, amount, and date range. Invoices that arrive without a matching purchase order should always be held for manual review before payment.

What is the most effective control against AP fraud?

Segregation of duties — making sure the same person cannot both set up a vendor and approve that vendor's invoices — is consistently identified as the most effective single control. The ACFE found that more than half of occupational fraud cases were enabled by a lack of controls or the ability to override existing controls. For small businesses where one person handles multiple AP roles, compensating controls like dual authorization above a threshold and mandatory management review become especially important.

Check a vendor or invoice before you pay

Run the routing number, vendor name, or a suspicious invoice through PaySentinel before authorizing payment. It takes under a minute and it's free to start.

Run a free check →