Skip to content
Back to Blog
April 8, 2026 — Tier2 Systems

Accounts Payable Fraud: A Finance Team's Guide

79% of organizations face payment fraud attempts. Learn where AP fraud happens, why standard controls fail, and what actually works.

financeaccounts-payablefraud-preventioncompliance

79% of organizations experienced attempted or actual payments fraud in 2024, according to the AFP Payments Fraud and Control Survey. That’s not a risk that might affect your business someday — it’s a near-certainty that someone has already tried.

Accounts payable fraud isn’t just an abstract risk anymore. The same AFP survey found that business email compromise (BEC) remains the top attack vector, cited by 63% of respondents. But the methods are more sophisticated, and they’re no longer the only threat.

How Accounts Payable Fraud Has Evolved

Traditional AP fraud relied on insider access — a fake vendor, a duplicate invoice, a tampered check. Those schemes still exist, but the threat landscape has expanded in three directions:

  • BEC is more convincing. Attackers now research your organization’s hierarchy, communication patterns, and vendor relationships before striking. A well-crafted email from what appears to be your CEO requesting an urgent wire transfer to a new account looks nothing like the obvious phishing attempts of five years ago.

  • Deepfakes have entered finance. AI-generated audio and video can impersonate executives on phone calls and even video conferences. A controller who follows proper procedure and calls to verify a suspicious payment request may still be deceived if the voice on the other end sounds exactly like the CFO. The IFOL Finance Leaders’ Fraud Report 2026 highlights deepfakes as one of the most disruptive emerging threats to finance operations.

  • Check fraud remains disproportionate. Despite the shift to digital payments, checks are involved in 63% of attempted or actual fraud cases — by far the most targeted payment method. Virtual cards, by contrast, are targeted in fewer than 10% of fraud attempts. Yet many B2B operations still process a significant share of payments by check.

Why Do Standard AP Controls Fall Short?

Most finance teams have controls in place. The problem isn’t a lack of rules — it’s that the rules were designed for a different threat environment.

Approval chains assume trust in the request. A dual-signature requirement doesn’t help if the payment request itself is fraudulent. When an attacker sends a convincing email with correct vendor details and a plausible reason for a bank account change, the approval process validates a legitimate-looking request rather than catching the fraud.

Segregation of duties protects against insiders, not outsiders. Separating who initiates, approves, and executes payments reduces internal fraud risk. But BEC and impersonation attacks come from outside the organization, bypassing internal segregation entirely.

Manual verification doesn’t scale. Calling to confirm every payment above a threshold is effective in theory. In practice, AP teams processing hundreds of transactions weekly skip verification when workload peaks — exactly when attackers time their attempts.

Only 22% of finance leaders say they feel “very well protected” against fraud, according to IFOL. The gap between having controls and trusting them is wider than most organizations admit.

Controls That Actually Reduce AP Fraud

Effective fraud prevention layers multiple controls so that no single failure creates exposure.

  • Out-of-band verification for payment changes. When a vendor requests new bank details, verify through a separately confirmed channel — a phone number from your original vendor contract, not the one in the email. This single step stops the majority of BEC-driven payment redirections.

  • Shift payment mix away from checks. Every check you eliminate removes the most fraud-prone instrument from your process. ACH and virtual cards offer built-in controls — transaction limits, single-use numbers, and automated reconciliation — that paper checks cannot match.

  • Continuous reconciliation, not monthly. When you reconcile payments daily or weekly, discrepancies surface while the trail is fresh. A duplicate payment or unauthorized transaction caught on day two is recoverable. The same fraud discovered at month-end close may not be.

  • Invest in training that keeps pace. 76% of finance teams say they want more fraud training. The training gap is real — and it matters because every new attack method (deepfakes, AI-generated documents) creates a window where your team hasn’t seen it before. Quarterly tabletop exercises with realistic scenarios are more effective than annual compliance videos.

  • Centralize your audit trail. Scattered systems mean scattered evidence. When your payment initiation, approval, execution, and reconciliation all live in one platform, every action is logged and traceable. If something goes wrong, you can reconstruct exactly what happened — and when your auditors ask, you have the answer.

Frequently Asked Questions

What is the most common type of accounts payable fraud?

Business email compromise (BEC) is the most common external AP fraud vector, affecting 63% of organizations according to the AFP Payments Fraud and Control Survey. Among internal schemes, billing fraud — submitting invoices for fictitious vendors or inflated amounts — is the most prevalent.

How can finance teams detect AP fraud early?

Watch for red flags: sudden changes to vendor bank details, duplicate invoice numbers from different vendors, invoices with round-number amounts or missing tax IDs, and payments to vendors without a purchase order trail. Automated matching between purchase orders, invoices, and receipts catches most of these before payment goes out.

What payment methods are least vulnerable to fraud?

Virtual cards carry the lowest fraud risk among common B2B payment methods, targeted in fewer than 10% of fraud attempts. ACH transfers are next. Checks are the most vulnerable, involved in 63% of payment fraud cases. Shifting your payment mix toward digital methods reduces exposure significantly.

How Tier2 Keel Strengthens Payment Controls

The audit trail problem described above — scattered approvals, disconnected systems, reconstructing events after the fact — is what Tier2 Keel eliminates by design. Every payment follows a traceable path from purchase request through approval, invoicing, and settlement within a single system.

When a vendor invoice arrives, it’s matched against the original purchase context. When a payment is approved, the system logs who authorized it, when, and against what documentation. When the payment settles, reconciliation happens automatically — not at month-end.

This doesn’t replace judgment or training. But it means your controls operate on complete, centralized data instead of scattered spreadsheets and email threads.

See how Keel handles financial workflows or talk to our team.

Strong AP controls aren’t about adding more approval steps. They’re about making sure your team has the right information — verified, centralized, and current — before money moves.


Ready to transform your operations?

Discover how Tier2 Systems can help your company with intelligent ERP, AI agents, and automation built from real-world experience.

Learn How We Can Help