When contractors think about payment fraud, they usually picture a fake email asking for a wire. Accounts payable faces a broader set of threats: altered or stolen checks, fraudulent ACH instructions, fake vendors, duplicate invoices and abuse of vendor portals. Many of these look routine until money is gone.
Strong controls do not need to slow payments. They need to put a deliberate check at the moments fraud actually happens.
Where fraud enters the payment process
- Vendor setup and changes: a new vendor or a changed bank account is the most common entry point
- Invoice approval: fake or inflated invoices that look like normal ones
- Payment release: pressure to pay fast, or approvals that bypass the process
- Check handling: checks stolen from the mail or altered after issue
- ACH and portals: compromised credentials let someone change payment instructions directly
Controls that matter most
Verify changes with a call-back
Any change to bank details or payment instructions should be confirmed using a phone number you already have on file, not one in the request. Document who verified, when and with whom. This single control stops many diversion attempts, including those that follow a compromised vendor email account.
Separate duties
The person who sets up or edits vendors should not be the person who approves or releases payments. Even in a small office, a second person reviewing changes makes a major difference. If staffing is tight, have the owner or controller review a weekly report of vendor changes.
Use positive pay and bank tools
Many banks offer services that match issued checks and ACH debits against what you authorized and flag exceptions. Ask your bank about check positive pay, payee matching, ACH debit blocks or filters, and dual approval for online payments. Terms and availability vary, so confirm with your bank directly.
Protect check stock and handling
- Lock check stock and keep a log of check numbers.
- Limit who can print and sign checks.
- Avoid mailing checks from unsecured boxes where practical.
- Reconcile accounts promptly, and daily when volume warrants.
- Use secure paper and printing practices, as advised by your bank.
Control the vendor master file
- Run periodic reviews for inactive, duplicate or suspicious vendors
- Compare vendor bank accounts against each other to catch duplicates
- Require supporting documents for new vendors, and verify them independently
- Remove vendors who are no longer active
Check invoices before paying
Compare invoices to purchase orders, contracts, delivery records or pay applications. Be alert to:
- Invoices from vendors you rarely use
- Amounts just below approval thresholds
- Sequential or repeated invoice numbers
- Slight changes in company names or addresses
- Urgent requests to pay outside the normal cycle
Secure the tools
- Require multi-factor authentication on your bank portal and accounting system
- Limit and review user permissions regularly
- Use dedicated devices or hardened browsers for banking where practical
- Alert on changes to payment settings and approvals
Build a short AP control checklist
- New vendors require documented verification before the first payment.
- Bank changes require a call-back to a known number.
- Vendor edits and payment releases are done by different people.
- Payments over a set amount require dual approval.
- Bank reconciliations are done promptly by someone who does not release payments.
- Exceptions are logged and reviewed by management.
- Users and permissions are reviewed at least quarterly.
Train the team
Fraud works because people want to help and want to keep vendors happy. Train staff to expect that real vendors will understand verification steps, and give them permission to slow down. Make clear that no executive will punish them for a delayed payment caused by a legitimate check.
A hypothetical example
Consider a hypothetical mid-size contractor that receives an email from a supplier's accounts receivable contact asking to update ACH details effective immediately. The clerk updates the file and the next payment goes to a new account. Weeks later the real supplier asks about the unpaid invoice. A call-back to the number already on file would have exposed the request in minutes.
If something goes wrong
Act immediately. Contact your bank to attempt recall or freeze, preserve emails and records, notify your insurer as your policy requires and consider reporting to law enforcement, including the FBI's Internet Crime Complaint Center for business email compromise. Speed greatly affects whether funds can be recovered.
Strengthening your process
Ironfield Cyber helps contractors and energy companies design payment controls, secure banking and accounting access, and train staff to spot fraud. If you would like a second look at your accounts payable process, we can review it with your finance team.