Request access
RankShield Financial · Accounts payable

Accounts payable fraudis mostly an inside job.Fake vendors, duplicate payments, altered checks, and one trusted person who onboards, approves, and pays. Most AP fraud does not come from a hacker. It comes from a process where a single person can complete a payment unchecked. RankShield makes that impossible.

payee-verifiedindependent approvalno self-payment
From the ACFE, 1,921 real cases
22%
of occupational fraud is billing schemes: fake vendors, inflated and duplicate invoices. $100k median loss (ACFE 2024)
12 mo.
median time an AP scheme runs before anyone catches it; losses grow to $875k at five years (ACFE 2024)
01 // two families
Where AP fraud comes from

An outside deception, or an inside process failure

Accounts payable fraud splits in two. Most guides only cover the loud one.

The external family is the one that makes headlines: a fraudster poses as your vendor and emails new banking details, and your team pays the wrong account. That is business email compromise, and it has its own page here, invoice and vendor payment fraud. It is real and growing, but it is not where most accounts payable losses actually come from.

The internal family is quieter and, by the numbers, larger. Someone with access to the payables process, alone or working with a vendor, exploits the fact that no one is independently checking. The ACFE’s 2024 Report to the Nations, drawn from 1,921 real cases, finds asset misappropriation in 89 percent of occupational-fraud cases, and the two schemes that live specifically inside accounts payable, billing schemes and check tampering, together account for a third of all cases. This page is about that internal side, because it is the part your bank’s fraud tools and a BEC checklist do not touch.

02 // the schemes
How the money leaves

The internal AP schemes, named

Shell vendor

a company that isn't real

An employee creates a fictitious vendor in the master file and submits invoices for goods never delivered. Payment routes to an account they control. The most common branch of the 22 percent billing-scheme category.

Duplicate & pay-and-return

the excess diverted

A real invoice paid twice, or a deliberate overpayment to a genuine vendor, with the “refund” intercepted. It hides inside legitimate activity.

Check & payment tampering

$155k median

Forged or altered checks, or changed banking details in the vendor master to redirect real disbursements. The highest median loss of the payables schemes, and 23 percent of cases at small firms.

Collusion

two people, no controls

An insider and a vendor split the take. The ACFE found 54 percent of frauds involved multiple people, precisely because collusion is how you get around separation of duties.

03 // why SMBs
The control you can’t staff

Small firms get hit harder because one person does it all

Separation of duties is the defense, and it is the exact thing a lean AP function does not have.

23% vs 9%
Check and payment tampering strikes firms under 100 employees at 23% of cases, versus 9% at large firms — the biggest small-vs-large gap of any scheme (ACFE 2024).
40% vs 90%
Only 40% of small firms have an internal audit function, against 90% of large ones. Fewer eyes, longer-running schemes.
Half
More than half of frauds occurred due to an insufficient system of internal controls: 32% a lack of controls, 19% an override of them (ACFE 2024).

The ACFE states the cause plainly: smaller organizations have fewer checks and balances and less segregation of duties. When the same trusted person onboards a vendor, approves its invoice, and releases the payment, there is no independent step where a fake vendor or a padded invoice would be caught. It is not that small businesses hire worse people. It is that they cannot afford the three-person process that makes the fraud hard, so a single point of trust becomes a single point of failure.

04 // the fix
One control, both families

Verify the payee, and require an approval one person can’t self-satisfy

Internal and external AP fraud collapse to the same two failures. Close both and you close most of the exposure.

Strip the schemes down and they share a root. A shell-vendor scheme works because the person who set up the vendor also approved its invoices. A vendor-impersonation email works because the changed banking details were never checked against a trusted record. Both come down to (1) the payee was not independently verified, and (2) no genuine, independent human approved the payment.

Verify the payee

against a trusted record

Every payment’s payee is checked against the vendor record you already trust, before it moves. A new or changed account does not clear on an email’s say-so.

Independent approval

not the originator

The payment carries proof that an authorized approver, who is not the person originating it, signed off. The segregation of duties a small team cannot staff, enforced automatically.

No self-completion

no single point of failure

No one person can onboard, approve, and release a payment end to end. That single rule defeats the shell vendor, the duplicate, the self-approval, and the collusion that circumvents manual controls.

A checkable record

who approved what

Every decision leaves a record of who approved what, so a surprise audit, the control the ACFE found cuts loss and duration by half, actually has something to review. See verifiable attestation.

Shared across the network

flagged once, known to all

A payee or account flagged at one member of the RankShield Network is shared across it, so a fake vendor or account seen elsewhere is known before you pay it. Unlike a scoring consortium, every shared verdict is independently verifiable, and the signal compounds as members join.

What we claim, and what we do not

Evidence, not adjectives

Every figure on this page is from the ACFE’s 2024 Report to the Nations, drawn from 1,921 real cases, and we cite it rather than paraphrasing it into folklore. We do not claim a fraud network, customer names, or a sealed build we cannot show you, which our transparency page reports honestly. What we offer is the segregation of duties and payee verification that small AP teams cannot staff by hand, automated and applied before the money moves.

Go deeper

Guides and analysis

Payment fraud controls for accountants & fractional CFOs

The fraud exposure you carry across a book of clients, why manual verification does not scale, and a repeatable control that protects clients and your firm.

Read the guide →

Accounts payable fraud: the numbers

The internal schemes (billing, check tampering), what they cost a small business, and the controls that stop them before release.

Read the guide →

How to stop vendor payment fraud when bank details change

How the bank-change scam works, why call-back advice fails on instant rails, and how to verify the payee before you pay.

Read the guide →

ACH fraud: the return-window myth

Why "ACH is reversible" is consumer advice, how short the real business windows are, and how to verify before it settles.

Read the guide →

Check fraud in 2026: how the schemes work and what stops it

Why check fraud rises as check use falls, the FinCEN mail-theft breakdown, the Positive Pay tiers that stop most of it, and the one gap they cannot close.

Read the guide →

Construction payment fraud: the top BEC target sector

Why federal data ranks contractors first, the four hops where an impostor enters the payment chain, and the check that belongs before a draw funds.

Read the guide →

Nonprofit payment fraud: controls that catch both risks

The minimum control set for a small finance office, why the annual audit misses fraud, and the one step that stops the insider and the impostor.

Read the guide →

Healthcare vendor payment fraud: the AP-side blind spot

The accounts-payable exposure billing compliance does not cover, what the FinCEN advisory actually addresses, and how to verify medical vendor payments.

Read the guide →

Supplier impersonation fraud: comparing the controls

ERP change control, account validation, Positive Pay, and pre-settlement attestation compared on the fraud each stops and the fraud each misses.

Read the guide →

Positive Pay cannot catch this

Exactly what Positive Pay covers, the authorized-payment blind spot it leaves, and how to close the gap it cannot see.

Read the guide →

Payment fraud by industry: the league table

Median fraud losses by sector from FBI, FinCEN, ACFE, and AFP data, and the three traits that make an industry a target.

Read the guide →

Payment fraud statistics 2026, read honestly

The FBI, AFP, and ACFE numbers sorted by what each actually measures, what is only projected, and the one event underneath them all.

Read the guide →

How school districts lose millions to vendor payment fraud

The anatomy of a district vendor impersonation, why building programs are the entry point, and the verification step that stops it.

Read the guide →
FAQ

Accounts payable fraud, answered

Every question buyers ask before they trust a payment-security platform, answered directly.

JAMIE KLONCZ · RANKSHIELD FINANCIAL ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →
Verify, then settle

See your payments verified before they settle.

Most AP fraud runs because one person can complete a payment alone. Verify the payee, require an independent approval, and leave a record — automatically, on every payment. Request access and we will map it to your AP process.

Request accessHow it works