No Per-User Pricing!

Scale your entire team without your software bill going up. Flat-rate means you pay one price, no matter how many users you add.

Back to Knowledge Base Guides & Best Practices

How to Prevent Vendor Fraud: 12 Internal Controls for Finance Teams

Vendor fraud is the most expensive scheme hitting mid-sized companies — and almost every case exploits the same weakness: nobody verifies who they're paying. The average organization loses 5% of revenue to fraud annually, and vendor schemes — fake suppliers, diverted bank details, duplicate invoices — sit at the top of the list precisely because they look like ordinary payments.

The good news: a handful of controls stop the vast majority of them. Here are the twelve that matter, ordered roughly by the fraud type they kill.

Controls 1–4: The Vendor Onboarding Gate

1. Verify every new vendor's bank details with a callback. The single most powerful control in this list. Before the first payment, someone from your team calls the vendor on a number sourced independently (not the one on the invoice or the email signature) and confirms the bank account. Most bank-detail diversion fraud dies right here.

2. Require named-approver sign-off before a vendor enters the master file. A vendor that anyone can add is a door anyone can walk through. New vendors should sit in an approval queue until a finance-authorized person reviews the submission — name, details, banking — and explicitly approves. This one gate stops fake suppliers before a single invoice exists.

3. Collect vendor documentation up front. Trade license, tax registration, W-9 or local equivalent. Fraudsters move fast and hate paperwork — friction is a filter.

4. Check for duplicate and near-duplicate vendors. The same supplier entered twice with slightly different names ("Acme Ltd" / "Acme Limited") is either sloppiness or setup for a duplicate-payment scheme. Your system should flag near-matches at creation.

Controls 5–8: The Payment Process

5. Pay only to bank details from your verified master file — never from the invoice. This is the rule most teams break without realizing it. Invoices carry bank details; fraudsters know this and change them. Payment data must come from your internal verified record, not from the document asking for money.

6. Verify any bank-detail change through a second channel. "We've changed our bank account, please update our details" is the single most common fraud email in existence. Any change request — even a genuine-looking one from a real contact — gets confirmed by phone on a known number before it takes effect.

7. Match before paying. The three-way match — purchase order, goods receipt, invoice — catches payments for things never ordered or delivered. An invoice that can't be matched to a real commitment gets investigated, never "approved with a note."

8. Enforce an approval matrix on value. Higher amounts need deeper approval chains. Fraud thrives on amounts just below the threshold where scrutiny begins — so make sure thresholds match your real risk, and that approval chains can't be bypassed by splitting one purchase into several smaller invoices.

Controls 9–12: The Environment

9. Segregate duties — always. The person who adds a vendor should never be the person who approves it; the person who approves payment should never be the person who executes it. Collusion requires two people, and two-person schemes are dramatically rarer than one-person ones.

10. Keep an immutable audit trail. Every approval, every vendor addition, every bank-detail change — timestamped, attributable, uneditable. Fraud's best friend is a system where evidence quietly disappears. A tamper-evident trail means the scheme leaves fingerprints.

11. Review vendor activity periodically. A quarterly scan of new vendors, payments to recently-changed bank details, and vendors with a single approval chain catches anomalies early. Fraud compounds — catching it in month one costs a fraction of catching it in year three.

12. Train the AP team on the specific schemes. Your team should know bank-detail diversion, fake-CEO emails, duplicate invoices, and shell vendors by name. People spot what they're primed to see.

The Common Thread

Notice what runs through all twelve: verification, separation, and evidence. Vendor fraud isn't beaten by smarter humans catching cleverer scams — it's beaten by processes where the fraud simply can't complete. The vendor that can't enter without sign-off, the payment that can't route to unverified details, the approval that can't happen without a record.

That's also why email-based processes are so dangerous: every one of these controls requires evidence, and email chains are evidence that dissolves.

Frequently Asked Questions

What's the most common type of vendor fraud?

Bank-detail diversion — a fraudster (or a compromised vendor email account) sends a "we've changed our bank" request, and payments route to the criminal's account. It's cheap to execute, looks completely normal, and is caught by controls 1, 5, and 6.

How much do companies actually lose to vendor fraud?

Scheme-specific numbers vary, but occupational fraud overall costs an estimated 5% of revenue annually — for a company doing $10M, that's $500K of exposure. Controls are dramatically cheaper than losses.

Where do mid-sized companies start?

Controls 1, 2, and 5 — the onboarding gate and paying from verified data only. Those three stop the majority of schemes and cost nothing but process discipline.

Approvdit implements the evidence layer of these controls natively — vendor approval queues before any payee enters the master file, bank details pulled from verified records rather than typed, and a tamper-evident audit trail on every action. Book a live demo to see the vendor gate working.