8 Accounts Payable Fraud Controls That Actually Get Used
Controls fail when they're annoying. Eight AP fraud controls teams actually follow — from vendor master hygiene to callback verification and document forensics.

In this list
- 1. Separate who approves from who pays
- 2. Treat the vendor master file like a vault
- 3. Call back on every banking change — on the number you already had
- 4. Run documents through forensics before they enter the workflow
- 5. Keep the three-way match honest
- 6. Put thresholds and velocity limits on autopay
- 7. Hunt duplicates weekly — or automate the hunt
- 8. Read the audit trail like you mean it
- Frequently asked questions
Every AP fraud writeup ends the same way: "have strong internal controls." Thanks. The hard part was never knowing that controls exist — it's picking ones that survive contact with a busy team. A control that adds an hour to every invoice gets bypassed by Thursday, and a bypassed control is worse than none, because it shows up in the audit as if it worked.
So here's a different filter: eight controls chosen because teams actually keep doing them. Each one is specific, cheap relative to what it prevents, and hard to quietly skip.
1. Separate who approves from who pays
The oldest control in the book, still first for a reason. The person who approves an invoice shouldn't be the person who releases the payment, and neither should be able to edit vendor records. Most internal AP fraud runs through one person holding two of those keys. In small teams where true separation is impossible, substitute visibility: every payment run gets a second set of eyes on a summary — payee, amount, bank-change flags — even if the same person clicked the buttons.
2. Treat the vendor master file like a vault
Fake-vendor schemes don't start with an invoice; they start with a vendor record. Lock down who can create or edit vendors, require documentation for every new one, and review the file quarterly for duplicates, near-duplicate names, and vendors with employee-matching addresses or bank accounts. A tidy vendor master makes half the other controls sharper.
3. Call back on every banking change — on the number you already had
When "a vendor" emails new bank details, the change request is the attack. Verify by phone using the contact info already in your records — never the number printed on the request itself. Make this policy absolute, because the fraudulent requests are precisely the urgent, plausible, well-formatted ones. This one habit neutralizes the costliest pattern in AP fraud, the BEC-style banking swap.
4. Run documents through forensics before they enter the workflow
A polished fake sails through matching because matching checks agreement, not authenticity. A forensic pass at intake asks different questions: was this PDF edited after creation? Does its structure match the software it claims? Do the fonts behave like this vendor's previous invoices? Machines do this in seconds, on every document, before anything downstream trusts it — which is the whole point. Nobody's eyeballing the touchless lane.
5. Keep the three-way match honest
Invoice, purchase order, receiving record. The match only protects the spend it covers, so watch the gaps: service categories with no PO requirement, blanket POs that fit anything, and receiving confirmations that get rubber-stamped. If a category is exempt from matching, it should be extra-covered by thresholds and review, not extra-trusted.
6. Put thresholds and velocity limits on autopay
Define the amount above which a human always looks, and alert on bursts — several invoices from one vendor in a week, or a vendor whose average invoice suddenly doubles. Fraudsters probe autopay lanes with small invoices before sending the real one; velocity rules catch the probing.
7. Hunt duplicates weekly — or automate the hunt
Duplicate payments are half fraud tactic, half expensive accident, and entirely preventable. Same vendor + same amount + close dates is the crude version; fuzzy matching on invoice numbers and amounts catches the deliberate near-duplicates ("INV-2041" vs "INV-2041A"). Recovering a duplicate after payment costs many times what catching it before did.
8. Read the audit trail like you mean it
Every modern AP system logs who created, edited, approved, and paid. The log only deters fraud if someone reads it. A monthly half-hour on the anomalies — vendor edits outside business hours, approvals within seconds of submission, the same login approving and releasing — turns the audit trail from archaeology into a control. Insiders behave differently when they know the log gets read.
Frequently asked questions
Which control stops the most fraud?
Callback verification on banking changes, and it isn't close. It's boring, it's five minutes, and it defeats the single most expensive AP fraud pattern outright. If you adopt one thing from this list, adopt that.
How do we do segregation of duties with a three-person team?
Substitute review for separation. One person can operate the process if a second person sees a payment-run summary before release — payee, amount, anything flagged. The control isn't the org chart; it's the guarantee that no payment leaves without a second pair of eyes on the unusual ones.
How often should the vendor master be reviewed?
Quarterly for the full pass — duplicates, stale vendors, employee-address matches. But changes should be reviewed as they happen: a banking edit is an event worth an alert, not something to discover at quarter-end.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
9 Invoice Fraud Red Flags Every AP Team Should Check
The nine warning signs accounts-payable teams see over and over in fraudulent invoices — and the two-minute checks that catch each one before payment goes out.
Purchase Order Fraud: Anatomy of a Fake PO
Invoice fraud targets the buyer; purchase order fraud targets the supplier. An illustrative look at how a fake PO ships goods on credit that will never be paid for — and where it breaks.
Business Email Compromise vs Invoice Fraud: Related, Not the Same
BEC and invoice fraud get lumped together, but they attack different weaknesses and need different defenses. A comparison, plus the document checks that blunt both.