Payment Fraud Prevention for Small Businesses
Payment fraud costs small businesses an average of 5% of annual revenue — and the median case goes undetected for 12 months before anyone notices. The AP process is the target. The money leaves through invoices, wire transfers, ACH payments, and vendor payments, and fraud hides in every one of them.
This hub covers every major category of payment fraud targeting small businesses — what each scheme looks like, how it gets past normal review, and the specific controls that stop it. Use it as a reference before you pay, or after something looks wrong.
The most common entry point for payment fraud. Fake invoices, manipulated bank details, and fictitious vendors are responsible for the majority of small business payment losses.
Business email compromise is the costliest category of cybercrime reported to the FBI — bigger than ransomware. It targets AP specifically because email is how most payment instructions arrive.
ACH payments and wire transfers are the two most commonly targeted payment methods — and the hardest to recover. Most wire fraud losses are permanent within hours of the transfer.
Which tools are actually built for small business fraud prevention — and how to use them as part of a broader AP process — rather than enterprise platforms that require months of setup.
Pre-Payment Fraud Prevention Checklist
Use this before every wire or ACH payment above your normal threshold — especially for new vendors, changed banking details, or requests that arrived only by email. Click each item to check it off.
- Invoice matched to a purchase order — no PO match means hold for manual review before paying
- Routing and account numbers match your vendor file — any change triggers a callback requirement
- Banking change verified by phone — called the vendor at a number from your own records, not one supplied by the request
- Sender email domain checked — matches the vendor's known domain exactly, no lookalike variations
- No urgency or confidentiality language — "process immediately" and "don't tell anyone" are red flags, not reasons to skip verification
- New vendor verified independently — physical address, phone number, and tax ID checked against public records before first payment
- Dual authorization obtained — second approver independent of the first for payments above threshold
- Pre-payment fraud check run — submitted through PaySentinel, risk score and flags documented
Never change a vendor's banking details based on an email alone.
The majority of payment fraud — BEC, vendor impersonation, invoice redirect — depends on getting you to act on an email without independent verification. A policy requiring a voice callback to a number already in your records before any banking change defeats the most common schemes regardless of how convincing the email looks.
Frequently Asked Questions
Payment fraud is any scheme that manipulates a business's payment process to divert funds illegally. It includes external attacks — fake invoices, vendor impersonation, business email compromise — and internal schemes like ghost vendors and duplicate billing. The AP process is the most common target because it's where money actually leaves the organization.
The AFP's 2026 Payments Fraud and Control Survey found that 76% of US organizations experienced attempted or actual payments fraud in 2025. The ACFE's 2024 Report to the Nations found that small businesses with fewer than 100 employees had a median fraud loss of $141,000 per case, and that fraud typically goes undetected for 12 months before discovery.
The most effective prevention combines process controls — segregation of duties, purchase order matching, dual authorization — with verification steps before payment: calling vendors at known numbers, checking routing numbers against your vendor file, and running a structured fraud check. No single control stops all fraud. The goal is to make each scheme harder to execute without detection.
Before any wire or ACH payment, verify that the routing and account numbers match your vendor file, that no banking details have changed since your last payment, that the invoice has a matching purchase order, and that the request didn't arrive only by email with urgency language. If any of those checks fail, call the vendor at a number from your own records before proceeding.
Check a payment before it goes out
PaySentinel checks vendors, invoices, routing numbers, and suspicious emails for fraud signals in under a minute. Free to start, no account required.
Run a free check →