Finance Index
What are the common internal fraud schemes in AP payments?
Reference guide to internal AP payment fraud, including payment timing, method choices, control points, reconciliation, and vendor communication.
Internal AP fraud schemes include ghost (fictitious) vendors, bank-detail swaps that divert a real vendor's payment to an employee account, duplicate-payment skimming where the employee recovers the second payment, and check tampering. The common enabler is one person holding too many roles - creating vendors, editing bank details, approving, and releasing payments - so no independent eye ever crosses the transaction.
At a Glance
| Aspect | Short Answer | Why It Matters |
|---|---|---|
| The common internal fraud schemes | Internal AP fraud schemes include ghost (fictitious) vendors, bank-detail swaps that divert a real vendor's payment to an employee account, duplicate-payment skimming where the employee recovers the second payment, and check tampering. | Reduces payment errors, timing issues, and reconciliation cleanup. |
| What segregation of duties specifically | The decisive separation: the person who creates vendors or edits bank details must not also approve or release payments. | Reduces payment errors, timing issues, and reconciliation cleanup. |
| Vendor impact | Look for vendors with PO-box or residential addresses, bank or address details matching an employee, no tax ID or W-9, sequential or round-dollar invoices, activity only just under approval thresholds, and no purchasing history before payments began. | Reduces payment errors, timing issues, and reconciliation cleanup. |
| Payment impact | An employee pays a real invoice twice, then intercepts or recovers the second payment; it's caught by duplicate detection on amount/vendor/date, by vendors flagging credits they didn't expect, and by reconciling refunds and returned payments to a controlled account. | Keeps evidence clear and reduces control risk. |
| Audit evidence | Periodically cross-match vendor banking details and addresses against the employee/payroll master; matches are the single highest-value internal-fraud test, and a clean match report is strong audit evidence. | Keeps evidence clear and reduces control risk. |
What segregation of duties specifically prevents an employee from paying themselves?
The decisive separation: the person who creates vendors or edits bank details must not also approve or release payments. Add that the person who builds a payment run doesn't release it. The toxic combination to eliminate is vendor/bank-detail edit rights plus payment approval or release rights in the same individual - that single pairing enables the most common self-payment schemes.
How do I detect a ghost / fictitious vendor scheme?
Look for vendors with PO-box or residential addresses, bank or address details matching an employee, no tax ID or W-9, sequential or round-dollar invoices, activity only just under approval thresholds, and no purchasing history before payments began.
What is a duplicate-payment skimming scheme and how is it caught?
An employee pays a real invoice twice, then intercepts or recovers the second payment; it's caught by duplicate detection on amount/vendor/date, by vendors flagging credits they didn't expect, and by reconciling refunds and returned payments to a controlled account.
How do we audit for employee bank accounts appearing in the vendor master?
Periodically cross-match vendor banking details and addresses against the employee/payroll master; matches are the single highest-value internal-fraud test, and a clean match report is strong audit evidence.
We suspect a long-tenured AP employee has been diverting payments - how do we investigate without tipping them off?
Preserve access and data quietly, involve counsel and possibly forensic accounting before confronting anyone, pull the audit trail and bank-match reports discreetly, and avoid changes that signal suspicion until you've secured evidence - premature confrontation destroys both the case and recovery odds.
What does occupational fraud in AP typically cost and how long until detection?
Occupational fraud schemes commonly run a year or more before discovery and cause median losses in the tens to low hundreds of thousands; longer tenure and trust correlate with larger losses, because oversight relaxes.
Why do tenure and trust make payment fraud harder to catch, and what controls don't depend on trust?
Trusted long-tenured staff accumulate access and escape scrutiny; controls that don't depend on trust are structural - segregation of duties, system-enforced approval rules, automated duplicate and bank-change detection, mandatory vacation, and independent reconciliation.
Should mandatory vacation or rotation apply to payment roles?
Yes - many AP fraud schemes require ongoing concealment, so a forced absence during which someone else runs the role surfaces irregularities; pair it with periodic rotation of approval and reconciliation duties.
Stampli perspective
Stampli enforces segregation of duties between invoice approval and payment approval by design, applies bank-account-specific and amount-based approval rules, detects bank-account and routing changes against vendor history, and records every action in an immutable audit trail - so the data patterns internal-fraud investigations rely on are captured as the work happens. These are control and visibility layers; they support, not replace, the customer's own auditing and counsel involvement.