Invoice fraud costs UK businesses more than most finance teams realise. Not because the schemes are sophisticated, but because they are designed to look routine. An invoice that matches a real supplier, a plausible amount, a payment reference that blends into the queue: these are not the things that trigger alarm during a busy month-end close.
The Association of Certified Fraud Examiners (ACFE) 2024 Report to the Nations found that billing fraud is the most common form of occupational fraud, accounting for 19% of cases and a median loss of $100,000 per scheme. For mid-market finance teams processing hundreds of invoices a month, the exposure is real.
This guide covers what invoice fraud detection actually looks like in practice: the schemes that cost businesses money, the manual controls that miss them, and how automated AP systems catch them at the point where intervention is still possible.
Most invoice fraud is not dramatic. It does not involve sophisticated forgery or external hacking. The most common schemes are simple, and they exploit the same gaps that exist in almost every manual AP process.
The same invoice is submitted twice, sometimes by a fraudulent actor with access to the original, sometimes by a supplier testing whether the payment runs twice. In a manual AP environment, the second invoice is processed under a slightly different reference number, a different date, or a different format, so it does not match the first in an obvious way.
The payment goes out. The AP team discovers the discrepancy weeks later, usually during reconciliation. Recovery depends on supplier cooperation.
An invoice arrives from a company that looks legitimate but does not correspond to any real goods or services received. In businesses where AP and purchasing operate independently, there is often no systematic check on whether an invoice corresponds to an approved purchase order.
The ACFE report identifies fictitious billing as the highest-value variant of billing fraud. The longer it runs undetected, the more invoices accumulate before anyone notices.
A genuine supplier invoices for more than was agreed, or for services not yet delivered. In a manual environment, this goes unnoticed when the person approving the invoice does not have easy access to the original purchase order or the agreed rate.
Small, consistent overcharges across a high-volume supplier relationship can add up to significant overpayment before anyone investigates.
A supplier's payment details change. A new bank account number is submitted, either by an internal fraudster or through a social engineering attack on the supplier's own team. Payments made to the new account reach the fraudster rather than the supplier.
UK Finance's Annual Fraud Report 2025 identifies authorised push payment fraud as one of the fastest-growing categories affecting businesses. In many cases, the fraud begins with an invoice-level change that passes through AP without additional verification.
Finance teams know fraud is a risk. Most have controls in place. The problem is that manual controls are inconsistent: they depend on individuals applying judgement under time pressure, with incomplete information.
An AP team processing 500 invoices a month cannot give each one the scrutiny required to catch subtle fraud. The volume means that most invoices get a quick scan, not a systematic check. Fraudulent invoices are designed to look routine. Under volume and time pressure, they do.
In a manual process, the person entering an invoice does not have easy access to the full history of that supplier's invoices, the original purchase order, the goods receipt confirmation, and the agreed payment terms simultaneously. These are often in different systems or different folders. Checking all of them for every invoice is not realistic.
Fraud detection that depends on a human doing this cross-reference consistently will miss things.
When an invoice reaches an approver, the approver typically sees the invoice and a brief description. They do not see whether this exact invoice has been submitted before, whether the payment details match the last payment to this supplier, or whether the amount is within the tolerance on the original PO.
Approving on incomplete information is not carelessness. It is the result of a system that does not surface the right context at the right moment.
In most mid-market businesses, reconciliation happens monthly. A fraudulent invoice submitted in the first week of the month may be paid in the second week and not detected until the monthly close. By that point, the money is gone.
The window for low-cost recovery closes fast. Recovering a duplicate payment from a cooperative supplier is straightforward. Recovering funds paid to a fraudulent account is a different matter entirely.
The advantage of automated accounts payable fraud detection is not speed. It is consistency. The system applies the same checks to every invoice, every time, regardless of volume or timing.
An AI-native AP platform checks every incoming invoice against the full database of historical invoices at the moment it arrives. The check covers multiple dimensions: same supplier, same amount, same invoice number, similar reference numbers under different formats, same line items with different totals.
If the invoice matches an existing entry, it is flagged before it enters the workflow. Not after it has been approved. Not after it has been paid. Before it moves at all.
This is the most direct form of duplicate invoice fraud prevention. The second submission never reaches the approval stage.
Three-way matching compares every invoice against the corresponding purchase order and goods receipt note. If an invoice arrives for a supplier with no approved PO, it does not proceed. If the invoiced amount exceeds the PO within the configured tolerance, it is flagged.
This catches both external fraud (fictitious invoices for work not ordered) and internal fraud (invoices created for work not delivered). The check is automatic and does not require anyone to remember to look.
When a supplier's payment details change, automated systems flag the change for additional verification before processing any payment to the new account. Payment redirections, which are a common mechanism in social engineering fraud, cannot proceed without deliberate sign-off from someone with the authority to verify the change.
This single control prevents one of the most financially damaging forms of invoice fraud.
Over time, an AI-native platform builds an understanding of what is normal for each supplier: typical invoice amounts, typical frequencies, typical payment terms. When an invoice deviates significantly from the established pattern, it is flagged for review.
Gradual billing inflation, where a supplier consistently invoices slightly above the agreed rate, may not trigger a single-invoice check but does show up in pattern analysis across a larger data set.
No system eliminates fraud risk entirely. The goal is to catch the most common schemes early, reduce the window between fraud and detection, and make fraudulent activity significantly harder to execute.
The person who enters invoices should not be the same person who approves them. The person who approves payments should not be the same person who reconciles the bank. These are basic controls that are worth reviewing regularly, particularly as teams grow or roles change.
Comparing what your AP system shows as outstanding against what suppliers say is outstanding catches discrepancies from both errors and fraud. A payment made to a fraudulent account will show as outstanding on the supplier's statement even after the payment has left your bank.
Monthly supplier statement reconciliation is the control that most consistently catches payment redirection fraud.
Any change to a supplier's bank account details should require verification through a channel independent of the request itself. If a supplier emails to say their account details have changed, call them on a number from your existing records, not the number in the email, to confirm.
This is a process control, not a technology one. But it prevents the most common social engineering vector in AP fraud.
Fraud that is detected in real time is recovered at a fraction of the cost of fraud detected weeks later. Moving from monthly reconciliation to continuous monitoring of AP activity changes the economics of fraud significantly.
Automated AP platforms that integrate with the ERP in real time provide this visibility. Every invoice processed, every payment initiated, every account detail change is logged and searchable at any moment, not just at month-end.
Dost applies fraud controls from the point of invoice receipt. Duplicate detection runs on every incoming invoice before it enters the workflow. Three-way matching against purchase orders and delivery notes is automatic. Supplier payment detail changes require additional sign-off before any payment proceeds.
Every action is logged with a full audit trail: who processed the invoice, when, what it matched to, who approved it, when the payment was initiated. When a discrepancy is identified, the investigation takes minutes rather than days because all the relevant information is in one place.
The result is a control environment that operates consistently across all invoice volume, not one that depends on vigilance during busy periods.
See what a tighter AP fraud control environment could mean for your business. Use Dost's ROI calculator to calculate the potential savings based on your current invoice volume.
More common than most teams realise. ACFE data consistently shows billing fraud as the most frequent category of occupational fraud, and it affects businesses of all sizes. Mid-market companies are particularly exposed because they typically have higher invoice volumes than a small business but less sophisticated controls than a large enterprise. The median loss per billing fraud scheme, according to ACFE's 2024 report, is $100,000 over the life of the scheme.
Intent. Billing errors, whether from a supplier or from an internal process failure, are unintentional discrepancies that cause the same financial harm as fraud in the short term. The distinction matters for how you respond: errors need process fixes, fraud needs a different kind of investigation. In practice, the same controls that catch billing errors also catch fraud, because both result in invoices that do not match purchase orders, or payments that are submitted twice, or amounts that exceed agreed rates.
Yes, and automated controls are often more accessible for small teams than manual ones. A two-person AP function cannot maintain the same level of manual scrutiny at 500 invoices a month as at 100. Automated duplicate detection and three-way matching apply the same check regardless of volume. The controls do not degrade under pressure.
Invoice fraud detection is most effective when it operates continuously and systematically rather than periodically and manually. The common schemes, duplicate submissions, fictitious vendors, inflated billing, and payment redirection, are not hard to catch if the right checks are applied at the right point in the process.
The gap in most mid-market AP environments is not awareness of the risk. It is the absence of controls that run consistently regardless of team size, invoice volume, or month-end pressure.
Automated AP platforms that apply duplicate detection, three-way matching, and supplier verification at the point of invoice receipt change the detection window from weeks to seconds. That is when fraud is cheapest to stop.
Calculate what better AP controls could save your team with Dost's ROI calculator.