Accounts Payable Fraud Protection During and Post COVID-19

Notice: No webinar is currently available in this series.

This webinar is not currently available, new dates coming soon.

Frequently Asked Questions

The COVID-19 pandemic created a perfect storm for AP fraud: remote work broke down traditional physical controls, teams were understaffed and overwhelmed, and established processes were bypassed in the interest of speed. Fraudsters exploited these vulnerabilities through business email compromise schemes impersonating vendors requesting bank account changes, fake invoice schemes targeting remote AP staff, payroll diversion fraud, and phishing attacks designed to harvest credentials. Even as pandemic-era disruptions have faded, the elevated fraud risk they exposed has not fully receded—many of the remote work arrangements and process exceptions introduced during the crisis have become permanent. Organizations should use the post-crisis period to audit the controls that were relaxed or bypassed, verify all vendor bank account changes made during the period, re-establish dual-control authorization requirements, and retrain staff on fraud recognition. A proactive fraud prevention culture—backed by technology controls and regular training—is the most effective long-term defense.
Business email compromise (BEC) is a type of fraud in which criminals impersonate executives, vendors, or other trusted parties via email to trick AP staff into making unauthorized payments or changing bank account information. BEC attacks are highly targeted and convincing—fraudsters research the organization, spoof legitimate email addresses, and time their requests to coincide with real invoice activity. The financial losses from BEC are substantial: it consistently ranks as one of the costliest forms of cybercrime. AP departments defend against BEC by implementing strict call-back verification policies for any payment change request—using a phone number already on file, never one provided in the request. Multi-person approval requirements for high-value payments or bank changes add another layer. Email filtering that flags domain spoofing and lookalike domains helps identify suspicious messages before they reach staff. Regular staff training on BEC tactics—including simulated phishing exercises—keeps the team alert to evolving attack methods.
The most effective internal controls for preventing accounts payable fraud operate at multiple levels—access, process, and monitoring. Segregation of duties is fundamental: the person who approves a vendor should not also be able to initiate payments, and the person who makes payments should not also reconcile bank accounts. Vendor master file access should be tightly restricted with dual-authorization for any changes. Payment controls should include positive pay for checks, ACH filter rules, and defined approval thresholds that escalate high-value transactions. Regular duplicate payment audits, vendor master file audits, and three-way matching controls reduce both error and intentional fraud. Mandatory vacation policies and job rotation for AP staff help surface schemes that depend on one person maintaining continuous control. Monitoring tools—whether in ERP systems or third-party analytics platforms—can flag unusual patterns like payments to new vendors, payments in round dollar amounts, or multiple payments to the same bank account under different vendor names.
Duplicate payments occur when the same invoice is paid more than once—due to data entry errors, system issues, or fraudulent manipulation. They are more common than most organizations realize and can represent a significant financial leakage over time. Detection begins with automated duplicate checking built into AP systems that flags invoices with matching vendor, amount, and invoice number combinations before payment is made. Periodic audits using data analytics tools can identify duplicates that slipped through by looking at payment patterns across slightly varied invoice numbers or amounts. When duplicates are identified, recovery depends on the relationship with the vendor: most legitimate suppliers will credit or refund overpayments promptly when approached professionally. Organizations should track recovery rates and document all duplicates found—both to recover funds and to identify control weaknesses that allowed them to occur. Third-party duplicate payment recovery firms exist for organizations with large historical payment volumes to audit.
Expense reimbursement fraud is one of the most common and persistent forms of internal occupational fraud, ranging from inflated expense claims and fictitious receipts to personal expenses disguised as business costs. Effective prevention starts with a clear, written expense policy that specifies what is reimbursable, documentation requirements, approval authorities, and consequences for policy violations. Receipts should be required for all expenses above a defined threshold, and expense reports should be reviewed by someone other than the submitter. AI-assisted expense management platforms can now flag policy violations, duplicate receipts, and unusual spending patterns automatically—dramatically reducing the manual burden on reviewers. Periodic audits of expense reports—particularly for high-frequency travelers or employees with large expense volumes—serve both a detective and deterrent function. Consistent enforcement of the expense policy across all levels of the organization, including senior management, is essential: exceptions erode the entire control environment.