Many payment fraud stories start at the moment a vendor is added to the system, not when money moves. A convincing email arrives from a new supplier with a W-9, a bank letter, and a polite request to get set up quickly. If your onboarding process accepts the paperwork at face value, you may have just created a path for fraud.
Strong vendor onboarding is one of the most effective and least expensive fraud defenses a contractor can build. It also protects against honest errors and duplicates.
How fake vendors get in
Fraud at onboarding generally takes one of a few forms.
- Entirely fictitious vendors created by an outsider or an insider, with fabricated paperwork and invoices for goods or services never delivered.
- Impersonated real vendors where a criminal poses as an existing supplier and asks to change or set up banking details.
- Look-alike companies with names close to a real supplier, hoping an invoice slips through.
- Insider schemes where an employee creates a vendor that routes money to themselves or an associate.
Each is easier when one person controls the whole process.
Build verification into the process
Verify identity independently
Do not rely on documents supplied by the requester. Confirm the business exists using independent sources, such as state business registration records, and confirm the contact details through a number you find yourself. For a vendor claimed to be an existing supplier, use the phone number already in your records, not the one in the new email.
Validate tax and bank information
Compare the taxpayer information with the legal business name and confirm the bank account is in the vendor's name. Many banks and payment platforms offer account validation tools. Ask your bank what verification services are available.
Require a second person
The person who requests or enters a new vendor should not be the person who approves it, and neither should be the person who releases payments. This segregation of duties is a basic control and a strong deterrent.
Check for duplicates and look-alikes
Before creating a record, search for similar names, tax IDs, addresses, and bank accounts. Duplicates and near matches are a classic warning sign.
Set rules for who can be a vendor
Decide in advance what a legitimate onboarding looks like for different vendor types.
- Regular suppliers and subs complete a standard form, supply insurance and tax documents, and pass verification.
- One-time vendors have lower limits and extra review, or are paid through a controlled method like a corporate card.
- Urgent requests follow the same process. Urgency is the most common pressure tactic, and a real vendor will understand a short delay.
Watch the first payments
First payments to new vendors carry the most risk. Consider adding a review step for any first payment above a threshold you choose, and for any payment to an account that changed recently. A first-payee report before each payment run is easy to produce in most accounting systems.
Also look at patterns after onboarding: round-dollar invoices, invoices just under approval limits, vendors with addresses matching employee addresses, and vendors with no phone or website.
Maintain the vendor list
- Review the vendor master file periodically and deactivate vendors with no recent activity.
- Restrict who can edit banking information, and log every change.
- Re-verify banking details when a vendor reports a change, using the same independent process.
- Remove access for employees whose roles no longer require vendor maintenance.
Document it
Write the process on a single page and train everyone who touches vendor records, including backups and temporary staff. A control that depends on tribal knowledge will fail the first time a key person is out.
Where Ironfield Cyber fits
Ironfield Cyber helps finance teams tighten access to vendor records, set up logging and alerts on banking changes, and train staff on current impersonation tactics. If you would like us to review your onboarding workflow, we are glad to help.