Calculator and pen on a sheet of figures

Accounts payable is one of the most common routes for fraud because it is where the organisation's money leaves the building. Schemes range from simple duplicate billing to fictitious suppliers set up and approved by insiders, and to kickback arrangements in which a genuine vendor overcharges and shares the excess with an employee.

The ACFE's Occupational Fraud 2024: A Report to the Nations estimates that organisations lose around 5% of revenue to fraud each year, and that a typical scheme runs for about a year before it is detected. The same study found that 43% of frauds were detected through tips, far more than through any other method. Tips and data analysis work best together: the red flags below can be monitored systematically, and they also give employees concrete things to notice and report.

Red flags in the vendor master

  1. Bank account changes shortly before a payment. A change to a vendor's bank details followed quickly by a large payment is a classic sign of both internal fraud and external payment-diversion scams.
  2. Vendor details that match an employee. The same bank account, PAN, address, phone number or email domain as an employee or an employee's relative.
  3. Incomplete or unverifiable registration details. A missing, inactive or mismatched GSTIN, a residential or virtual-office address, or no online footprint for a supposedly established business.
  4. New vendors paid unusually fast. A supplier created, approved and paid within days, especially where the same user created and approved the vendor.

Red flags in invoices and payments

  1. Sequential invoice numbers. A vendor whose invoices to you run 101, 102, 103 over several months may have no other customers.
  2. Round-sum amounts. Invoices for exact round figures, particularly for services that would normally be billed by quantity or time.
  3. Amounts just below approval limits. A cluster of invoices just under the threshold that would require a senior sign-off, or a single purchase split into several smaller orders.
  4. Duplicates and near-duplicates. The same invoice paid twice with a small change: an extra character in the invoice number, a different date or a slightly different amount.
  5. Payments without a purchase order or goods receipt. Frequent overrides of the three-way match between order, receipt and invoice.
  6. Input tax credit that does not reconcile. Purchases on which the supplier's invoices do not appear in the buyer's GST auto-drafted statements may indicate invoices that were never genuinely issued or reported.

Red flags in behaviour and relationships

  1. Spend growing faster than the business. A vendor whose share of spend rises sharply without an operational explanation, or a single-source supplier repeatedly chosen without competitive quotes.
  2. An employee who guards a relationship. A buyer who insists on handling one vendor personally, resists rotation or never takes leave. Behavioural signs rarely prove anything on their own, but together with data exceptions they warrant a closer look.
A single red flag is not proof of fraud. Many have innocent explanations. Their value lies in directing attention: an exception that cannot be explained by the business is a reason to look further.

Controls that close the gaps

  • Separate the people who create or change vendors from those who approve payments.
  • Verify bank account changes independently, by calling back on a number already on file rather than one given in the change request.
  • Validate PAN, GSTIN and bank details when onboarding, and periodically thereafter.
  • Enforce the three-way match and report every override to someone independent of the buyer.
  • Run regular data tests for duplicates, employee matches, threshold splitting and unusual growth in spend.
  • Make it easy and safe to raise concerns, through a well-publicised vigil mechanism.

None of these controls is expensive. Together they make the most common vendor schemes much harder to carry out and much easier to detect.

This article is general information and not professional advice. It reflects the law and practice as understood on the date of publication. Please read our Disclaimer.