Accounts payable fraud is any scheme that gets your company to pay money it should not, and a large share of it is an inside job. The external version, where an attacker poses as a supplier or an executive to redirect a payment, gets the headlines. But much of the loss comes from within: employees who set up fake vendors, inflate invoices, or alter checks. The Association of Certified Fraud Examiners, in its 2024 Report to the Nations, found that billing schemes account for 22 percent of asset-misappropriation cases with a median loss of $100,000, and check tampering for 11 percent with a median loss of $155,0001. This guide covers the internal side of accounts payable fraud: the common schemes, what they cost, how they slip past the books, and how to prevent them. For the external side, where a fraudster impersonates a vendor or your CEO, the companion guide on vendor payment fraud covers the same ground, because the defense converges on one control. Effective accounts payable fraud prevention has to address both, but the internal schemes are the ones most guidance skips for the small and mid-sized business, even though smaller organizations are hit nearly as hard per case as large ones. The honest short version is that segregation of duties and verifying a payment before it is released stop most of it, and neither requires a dedicated fraud department.
What accounts payable fraud is, and the line between inside and outside jobs
Accounts payable fraud splits cleanly into two categories, and confusing them leads to defending against the wrong one. External AP fraud is committed by an outsider: a fraudster who impersonates a supplier to change bank details, or an executive to demand an urgent wire. Internal, or occupational, AP fraud is committed by someone inside the organization who exploits the payment process itself, usually because they can both create a payee and get a payment approved. The external attacks make headlines, and the FBI put reported business email compromise losses, much of it redirected accounts payable money, at $3.046 billion in 20253. The internal ones are quieter, and they run for months because they look like ordinary business.
The distinction matters because the two need different first lines of defense. External fraud is defeated by out-of-band verification of any change to where money goes. Internal fraud is defeated by separation of duties, so no single person can both create a vendor and release a payment to it. What they share, and where they converge, is the final control: a payment that is verified before it is released, against records and approvals that a single insider cannot quietly manufacture. This guide focuses on the internal schemes, which are the ones most small-business guidance leaves out.
The most common AP fraud schemes, by the numbers
Internal AP fraud clusters into a few well-documented schemes, and the ACFE’s Report to the Nations, which analyzes thousands of real occupational fraud cases, gives the clearest picture of how common and how costly each one is. Two dominate accounts payable: billing schemes and check or payment tampering. The table below shows what the 2024 report found for each.
The pattern in the numbers is worth noting: billing schemes are more common but tampering is costlier per case, because altering or forging a payment usually requires more access and produces a larger single hit. Both depend on the same weakness, which is one person controlling too much of the payment process. The ACFE also found that the longer a scheme runs before detection, the more it costs, and internal schemes often run for a year or more precisely because they are camouflaged as normal payments. If you want a payment checked against an authorized approval before it clears, you can request access.
| Scheme | Share of asset-misappropriation cases | Median loss per case | Typical method |
|---|---|---|---|
| Billing schemes | 22% | $100,000 | A fake or shell vendor, or an inflated or duplicate invoice from a real one |
| Check and payment tampering | 11% | $155,000 | Altering, forging, or intercepting a payment the company issues |
What AP fraud costs a small business
The most damaging myth about internal fraud is that it is a big-company problem. The data says the opposite in per-case terms. The ACFE 2024 report found that organizations with fewer than 100 employees suffered a median loss of $141,000, close to the $145,000 median across all organizations1. A large enterprise can absorb a six-figure loss; for a small business it can be existential. Smaller organizations are exposed for a structural reason: they rarely have enough staff to separate the person who sets up a vendor from the person who approves the payment, so the single control that stops most billing schemes does not exist by default.
External pressure compounds the internal risk. The 2026 AFP Payments Fraud and Control Survey found that 76 percent of organizations faced attempted or actual payments fraud2, so an understaffed AP function is fighting insider risk and outsider risk at the same desk. The result is that the controls meant to catch a fake vendor also have to catch a deceived approver, and a team of two or three cannot run either one reliably by hand. That is the case for making the control automatic rather than depending on headcount a small business does not have.
How internal AP fraud slips past the books
Internal schemes survive because they are designed to look like legitimate activity, not because the numbers are obviously wrong. A billing scheme starts with a payee: the fraudster adds a vendor to the master file, often with a name close to a real supplier, and points it at an account they control. From there the invoices look normal, the amounts are plausible, and the payments run on the regular schedule. Nothing in the transaction data is anomalous, because at the record level the payment is exactly what the system was told to make.
Check and payment tampering works a layer lower, at the point where a payment is created or issued. Someone with access alters a payee or amount, forges an authorized signature, or reroutes a legitimate payment to their own account. The common thread with billing schemes is control: one person who can create or change a payee and also cause a payment to be released. When that separation is missing, the books reconcile and the fraud is invisible until a vendor complains, an audit lands, or the person leaves. The longer it runs, the more it costs, which is why detection after the fact is always the expensive way to find it.
The red flags that surface a billing scheme
Because internal AP fraud is built to look normal, it is usually caught by patterns in the vendor master and the invoices rather than by a single obvious error. A handful of red flags recur across cases: a vendor whose address is a PO box or matches an employee’s home, invoices that land just under an approval threshold, suspiciously round amounts, a payee that only ever bills and never delivers anything tangible, or sequential invoice numbers that suggest your company is the vendor’s only customer. None of these proves fraud on its own, but a cluster of them on one payee is worth a hard look.
Timing and access add more signals. Billing schemes often spike near period-end when review is rushed, run through a vendor that was added by someone who also approves payments, or involve a dormant vendor that suddenly reactivates. The most reliable structural tell is the one the schemes are built to hide: the same person controlling both the vendor record and the payment approval. Reviewing the vendor master for these patterns on a schedule, and requiring an independent approver for any new payee, turns detection from an annual audit surprise into a routine check. It also shortens the time a scheme can run before it is caught, which the ACFE data ties directly to how much it ultimately costs.
How to prevent AP fraud: segregation of duties and verifying before release
The single most effective internal control is segregation of duties: the person who sets up or edits a vendor must not be the person who approves or releases payments to it. Pair that with vendor-master governance, meaning new vendors and bank-detail changes require independent verification and a documented approval, and with a review of the master file for duplicates, lookalike names, and dormant vendors that suddenly reactivate. For checks, Positive Pay at your bank catches altered or forged items by matching them to a file you authorized. These controls are well understood; the problem is that a small AP team cannot run them by hand on every payment without slowing the business to a stop.
That is where verifying the payment before release closes the gap. RankShield Financial sits in the authorization path as a verification and attestation layer, not a wallet or a processor, and it never takes custody of your funds; your bank and rails still move the money. It checks the payee, amount, and purpose against records you trust and requires proof that a real, authorized person, separate from whoever entered the payment, approved this specific release, then holds anything that does not match. It seals a signed, tamper-evident record of who approved what, so a single insider cannot quietly manufacture both the vendor and the approval. Unlike a private fraud score you must trust, that verdict is independently verifiable, the shared signal compounds as members join rather than claiming a scale we have not yet reached, and the signing is quantum-safe by construction, not quantum-proof. It turns segregation of duties from a policy that depends on having enough people into a control that runs before every payment settles, which is the version a small AP team can actually enforce.