Vendor fraud is any scheme in which a fraudster uses a supplier relationship to extract money from an organization. Five shapes cover most of it. Those are a fictitious vendor, a bank account change request, a shell entity billing scheme, over-billing or duplicate billing, and collusion between an employee and a real supplier. Nearly all of them start with an email.
Key takeaways
- Sort schemes by whether the fraudster is an outsider, an insider, or both. An outsider impersonating a supplier is defeated by out-of-band verification, an insider is defeated by segregation of duties and vendor master hygiene, and collusion needs analytics over time.
- Verify every bank account change against a number already held in the vendor master, at every dollar value. The FBI recorded $3.05 billion in business email compromise losses in 2025.
- Dollar thresholds make a poor sole trigger, because a long-running fraudster deliberately bills below them. A control that fires above $10,000 is a published threshold for anyone submitting $9,400 invoices.
- Expense-side and AP-side controls solve different halves. Buying one and assuming it covers both leaves the other half exposed.
Vendor fraud rarely announces itself as fraud. It starts with a routine email from a supplier you already pay, asking for something ordinary. Here is what the five schemes look like in an accounts payable (AP) queue, and which control stops each one.
Why vendor fraud starts in the inbox before the ERP
The entry point is almost always a message rather than a system. It might be a remittance question, a new bank letter, or a chase for a late payment. By the time a fraudulent transaction exists in the enterprise resource planning (ERP) system, a person reading email already made the decision that allowed it.
The FBI Internet Crime Complaint Center recorded the scale in its 2025 Internet Crime Report. Business email compromise produced 24,768 complaints and $3,046,598,558 in losses in 2025, up about 10 percent from $2,770,151,146 in 2024. Across all crime types the center logged 1,008,597 complaints and $20.877 billion in losses, with cyber-enabled fraud accounting for 85 percent of all 2025 losses.
Business email compromise is the outside version of the problem. The inside version looks similar in the ledger and different in origin. The Association of Certified Fraud Examiners studied 2,402 occupational fraud cases for its Report to the Nations 2026, finding a median loss of $104,000 per case. Corruption appeared in 45 percent of cases, the category covering kickbacks and bid rigging with a supplier.
Duration is the number that should shape the control design. ACFE found a median of 12 months before discovery in 2026. Schemes caught within six months cost a median of $40,000, while schemes that lasted more than five years cost a median of $1.1 million. A fraudster who clears one invoice a month for four years does more damage than a single large fraudulent payment.
Two of the AP pain points finance teams rank highest are exactly these. Bank account change requests are high-risk, time-sensitive, and error-prone when handled by hand. Invoice fraud and policy exceptions usually start with an email before anyone keys them into the ERP, where nobody owns them and no audit trail records who decided what.
How to think about vendor fraud risk
Sort the schemes by whether the fraudster is an outsider, an insider, or both. That single question determines which control has any chance of working.
An external actor impersonating a real supplier is defeated by verification. The attacker controls the message and the reply address, so any check that stays inside the email thread validates nothing. Out-of-band verification against a number you already held is the entire control.
An internal actor creating or steering payments is defeated by separation of duties and data hygiene. Verification does not help when the person verifying is the person running the scheme. The vendor master becomes the control surface, because a fraudulent vendor record makes every later invoice look legitimate.
Collusion between an employee and a real supplier defeats both of those. The vendor exists, the services exist in some form, and the approvals are genuine. What remains is analytics over time, comparing prices, volumes, and award patterns against peers.
Two more principles are worth stating before the list. Dollar thresholds are a poor sole trigger, because a long-running fraudster deliberately bills below them. A control that only runs on purchase-order-backed invoices also leaves the non-PO-backed population uncovered, and that population is where most of these schemes operate.
Five vendor fraud schemes finance teams face
Fictitious vendor schemes
An employee with access to the vendor master creates a supplier that does not exist, then submits invoices against it. The record often mirrors a real employee's address, a mail drop, or a bank account already on file for payroll. Invoices are usually for services, because services need no receiving document.
The tells are in the vendor master itself. They include bank details shared with an employee record, a tax ID that fails validation, an address matching another vendor, or a vendor created and paid inside one short window. Vendor master hygiene is the control, meaning periodic deduplication, dormancy review, and a creation workflow separated from payment.
Bank account change request fraud
A message arrives from a known supplier contact saying banking details have changed and the next payment should go to a new account. The formatting is right, and the thread sometimes includes real prior correspondence taken from a compromised mailbox. This is the highest-value request in the AP inbox.
The control is out-of-band verification, without exception and without a dollar threshold. Call the supplier on a number already stored in the vendor master, never one supplied in the request, and confirm with a named contact you have dealt with before. Log the verification against the vendor record so the audit trail survives the person who made the call. The IC3 2025 loss figure of just over $3 billion from business email compromise is what this one control prevents.
Billing schemes and shell entities
A shell entity inserts itself between the organization and a real service, adding a margin nobody authorized. It differs from a purely fictitious vendor because something is genuinely delivered, often consulting, staffing, or logistics. The paper trail is complete, which is what makes it durable.
Look for round-number invoices, sequential invoice numbers suggesting your company is the entity's only customer, vague line-item descriptions, and a registration date shortly before the first invoice. Matching invoices to a contract and to delivery evidence is what breaks the pattern.
Over-billing and duplicate billing
The same invoice is submitted twice, or a legitimate invoice is inflated by quantity, rate, or an added fee. Duplicates arrive most often through several channels, so one document lands by email, again through a portal, and again on a vendor statement. Rate inflation is harder, because the invoice matches the purchase order (PO) on everything except unit price.
Detection depends on history rather than on any single check. Our own duplicate expense detection work shows duplicates found growing about 700 percent from month one to month twelve on the expense side, for that reason. Line-level matching against the PO and the contract rate catches the inflation a header-level match approves.
Collusion between an employee and a supplier
A buyer steers awards to a favored supplier in return for something of value, or approves inflated invoices knowingly. Every document is real, every approval is authentic, and no verification step fails. This is the hardest scheme in the list to detect through controls that examine one transaction at a time.
The signals are comparative. One supplier wins an unusual share of awards from one approver, or prices drift above peer benchmarks. A single approver signing off on every invoice for that vendor, regardless of routing rules, is the third signal. Approver rotation, competitive quotes above a defined value, and spend analytics by approver-and-vendor pair are the practical controls. ACFE found a median loss of $84,000 per case in 2026 where organizations trained both staff and management. Organizations providing no training had a median loss of $150,000. Collusion is where a colleague noticing something matters most.
Where vendor fraud controls fall short
Most programs verify the wrong thing at the wrong time. Approval workflows confirm that a named person clicked approve, which says nothing about whether the vendor is real. Three-way matching validates an invoice against documents the fraudster creates alongside it.
Coverage is the second gap. Non-PO-backed invoices, service categories, and low-value recurring charges are often exempt from the strict controls, which is exactly the gap a long-running fraudster needs. A control that fires above $10,000 is a published threshold for anyone submitting $9,400 invoices.
The third gap is worth naming plainly, because vendors on both sides of the market blur it. Expense-side controls and AP-side controls solve different halves of this problem. Auditing employee expense reports catches a reimbursement claim for a kickback dinner or personal spend routed through a supplier relationship. It never examines the vendor master or the invoice that pays a shell entity, and AP-side controls do the reverse. A team that buys one half and assumes it owns the whole stays exposed in the half it did not buy.
How we approach vendor fraud
We treat the inbox as part of the control environment rather than as a holding area before controls start. AP Inbox Service Center gives vendor email an owner, a queue, and an audit trail. A bank account change request becomes a tracked item with a required verification step. Autonomous AP applies the same logic to invoice handling, with matching and exception routing extended to non-PO-backed invoices rather than to purchase-order traffic alone.
On the employee side, Expense Audit reads every line of every receipt on every report before reimbursement, at 100 percent coverage rather than a sample. That is the half of the problem that an employee submits as a claim. It includes Foreign Corrupt Practices Act (FCPA) and Sunshine Act screening, plus politically exposed person checks where a supplier relationship involves a government official.
Smart Workflows route what needs a human, and AI Agents resolve the routine items on their own. Read more on proactive expense auditing with agentic AI, or see how our AI Expense Audit software works alongside an existing expense system.
The bottom line
Start with the bank account change request, because one missed verification costs the most and the IC3 2025 figures show the scale. Write the out-of-band rule so it applies at every dollar value, then work backwards through vendor master hygiene and non-PO-backed invoice coverage. Ask us what a full pre-payment review would surface across your AP and travel and expense history together.
Frequently asked questions
What is vendor fraud?
Vendor fraud is any scheme in which a fraudster uses a supplier relationship to extract money from an organization. It covers inventing a supplier, impersonating a real one, inflating or duplicating invoices, and colluding with a genuine supplier to overcharge.
What is the most common way vendor fraud starts?
It usually starts with an email rather than a system entry. A bank account change request, an invoice attachment, or a payment status question is the entry point. The FBI IC3 recorded 24,768 business email compromise complaints and just over $3 billion in losses in 2025.
How do you stop bank account change request fraud?
Verify every change out of band, using a phone number already held in the vendor master rather than any number in the request. Confirm with a named contact you have worked with before, record the verification against the vendor record, and apply the rule at every dollar value.
How long does vendor fraud typically go undetected?
The ACFE Report to the Nations 2026 found a median of 12 months to discovery across occupational fraud cases. Schemes caught within six months had a median loss of $40,000, while those that lasted more than five years had a median loss of $1.1 million.
Do expense audit controls catch vendor fraud?
Expense audit controls catch only part of it. Expense-side controls catch reimbursement claims tied to a supplier relationship, including personal spend and hospitality that signals a kickback. They do not examine the vendor master or the invoice itself, which is where fictitious vendor and shell entity schemes operate.