← Back to blog

AP Playbook: Low friction controls, email protections, and escrow

October 6, 2026
AP Playbook: Low friction controls, email protections, and escrow

Invoice fraud is preventable when accounts payable teams combine segregation of duties, strict verification of any bank detail change, three-way matching, and a culture that stops and verifies before paying. If you do nothing else today, pause any non-routine payment and verify bank changes by calling a contact number already on file, never one supplied in the request itself. The rest of this guide covers how these schemes work, which technology genuinely helps, and what to do if you have already been hit.


TL;DR:

  • Keep supplier setup separate from payment release, require dual approval for bank detail edits, and document exceptions with a reason and second signature.
  • For bank changes, require a signed request, call a number already on file, hold the update briefly, and obtain two approvals before activation.
  • Configure duplicate checks across prior batches and route anomaly alerts to human reviewers; never let one approver bypass a flagged invoice alone.
  • If fraud is suspected, stop pending payments, request a bank recall, preserve original emails and invoices, and report promptly so funds may be frozen.

Aurasocial
Hire Freelancers With Payment Protection
Aura Social connects businesses with verified freelancers and provides escrow payment protection, with a straightforward pricing structure and no hidden fees.
Explore the marketplace

Table of Contents

How invoice fraud works and why teams need controls

Most invoice fraud follows a handful of patterns. A criminal redirects payment on a legitimate invoice by changing bank details, sets up a fake supplier that mimics a real one, compromises an employee's email account to send convincing requests, quietly edits the vendor master file, or works with an insider who approves payments to an account they control.

  • Invoice redirection through a spoofed or compromised email thread
  • Fake suppliers invented to collect payment for work never done
  • Vendor-master edits that reroute an existing supplier's payments
  • Internal collusion between an employee and an outside accomplice

These schemes succeed because they borrow urgency and authority: a message that appears to come from a finance director, a supplier claiming an "updated" bank account before month end, a tone that discourages questions. That pressure is exactly what segregation of duties and verification protocols are designed to counter.

Billing schemes make up a significant portion of occupational fraud cases, often resulting in substantial median losses per case. That median loss is large enough to justify dedicated controls even at smaller organizations, and the same report notes that consistent enforcement of existing controls, not simply buying more software, is what stops most of these cases before money leaves the building.

Internal controls that stop fraud before it starts

Operational controls catch more fraud than any single piece of software, largely because they remove the single point of failure that criminals rely on.

  1. Separate vendor setup from payment execution. The person who adds a new supplier to the system should never be the same person who approves or releases payment to that supplier.
  2. Require three-way matching for every invoice above a defined threshold, comparing the purchase order, the goods receipt note, and the invoice itself before payment is released; document any exception with a reason code and a second signature.
  3. Lock down the vendor master file so new entries and bank-detail edits require dual sign-off, with a full audit trail and a monthly reconciliation against the prior period.
  4. Restrict manual overrides to a named group of approvers, log every override, and review the log monthly rather than only during an annual audit.

Dual sign-off and audit trails sound bureaucratic until you remember that most vendor-master manipulation succeeds precisely because one person had unsupervised edit rights. Industry guidance from ICAEW points to exactly this combination: tighter onboarding, segregated duties, three-way matching, duplicate checks, and staff empowered to pause and verify anything unusual.

Pro Tip: Set your three-way match exception threshold low enough that it catches real anomalies, but review the exception list weekly so legitimate small variances don't train your team to click through warnings.

Supplier onboarding and secure bank-change procedures

Most invoice fraud that gets through has nothing to do with sophisticated hacking. It exploits a gap in how a new supplier was added or how a bank-detail change request was handled.

  • Verify company registration independently before the first invoice is ever entered.
  • Call the supplier using a phone number found independently, not one listed in the onboarding email, to confirm the contact is real.
  • Match the first invoice format and letterhead against any sample provided during registration.
  • Collect tax identification or equivalent documentation appropriate to the supplier's jurisdiction.

Bank-detail changes deserve their own protocol, separate from general onboarding. Require a written change request plus a signed change form, then call a contact number already on file, never a number included in the change request itself, to confirm the update before it takes effect. The National Crime Agency's invoice fraud guidance specifically flags lookalike domains and impersonation as common tactics behind these requests, which is why the callback has to go through a channel the fraudster cannot control. Hold any change for a short freeze window and require two approvers before it goes live, then re-verify your full vendor contact list annually so stale or compromised contact details don't linger in the system.

Pro Tip: Keep your verified callback numbers in a separate, access-controlled file rather than inside the vendor record itself, so a compromised vendor-master entry can't also hand over the number used to confirm changes.

Technology and automation: what to deploy and how to pair it with process

Software catches what tired eyes miss, but only when it is configured so no one can quietly click past it.

  • Invoice OCR paired with structured data capture reduces manual entry errors that often mask duplicate or altered invoices.
  • Automated duplicate-invoice checks compare invoice number, amount, and vendor across a rolling window, not just the current batch.
  • Three-way matching between purchase order, goods receipt, and invoice should be enforced in the system, not left to memory.
  • Bank-detail-change alerts should fire automatically to a second approver the moment a vendor record is edited.
  • Payment-velocity monitoring flags unusual spikes in volume or amount to a single vendor.

Email and domain protections matter just as much as invoice-level checks. SPF, DKIM, and DMARC authentication, combined with lookalike-domain monitoring and anti-phishing filters, cut off the delivery channel that most impersonation schemes depend on. NIST's guidance on digital identity recommends phishing-resistant authentication and risk-based authentication as part of a broader fraud mitigation strategy, which applies directly to the email accounts AP staff use every day.

AI and machine-learning anomaly detection can score unusual invoices for review, but it works best paired with a human who checks the flagged items rather than a system that quietly approves everything else. False positives erode trust in the tool; false negatives let fraud through, so explainable scoring and a logged human review step both matter. Route every alert into your ticketing system rather than a side channel, and make sure no approver can bypass a flagged invoice without a second sign-off on record.

Flagged invoice routed through human review and approval

Training and culture: building a stop-and-verify workplace

Controls fail when people feel pressured to skip them, so the culture around verification matters as much as the policy itself.

  1. Define a clear trigger list: any bank-detail change, any urgent request to skip normal approval, and any invoice from a vendor not yet in the master file should automatically pause payment.
  2. Give staff a short phone script for verification calls: confirm the requestor's name, the amount, and the reason, using a number pulled from the verified contact file, never from the request.
  3. Train on a regular cadence: onboarding for new hires, quarterly refreshers, and at least one annual phishing simulation or tabletop exercise.
  4. Make reporting mistakes safe. A non-punitive policy for near-misses means staff flag a suspicious invoice instead of quietly processing it to avoid admitting they almost got fooled.

A workplace where pausing a payment to make a phone call is treated as good judgment, not as slowing things down, catches far more fraud than any single software tool. That cultural shift is one of the higher-return defenses against impersonation attacks precisely because it removes the time pressure the scheme depends on.

Incident playbook: what to do after suspected fraud

Speed determines whether money is recoverable, so the first hour after discovery matters more than the investigation that follows.

  1. Stop any pending payment immediately and contact your bank with the transaction details to request a recall.
  2. Ask your bank about fund recovery processes available for the transaction type, since fast action sometimes allows a receiving account to be frozen before funds move further.
  3. Preserve evidence: save email headers, the fraudulent invoice, and any related correspondence exactly as received, without forwarding or altering them.
  4. Report the incident to law enforcement. The FBI's IC3 annual reporting shows that fast reporting through its recovery process can sometimes help freeze fraudulent accounts and assist recovery, so speed matters more than certainty before filing.
  • Notify internal compliance or finance leadership the same day.
  • Run a forensic review of the affected vendor record and any related approvals.
  • Audit the full vendor master file for similar tampering.
  • Notify your insurer and legal counsel where a policy or regulation requires it.
  • Document lessons learned and update the control that failed.

Printable daily and weekly checklist AP teams can use

Run these checks before, not after, payment goes out.

  • Scan for duplicate invoice numbers, amounts, or vendor names across the current and prior batch.
  • Flag any invoice below your normal approval threshold routed around standard sign-off.
  • Flag any bank-detail change on a vendor record made in the past 30 days.
  • Flag any invoice with a format, logo, or layout that doesn't match the vendor's file.
  • Confirm escalation contacts and callback numbers are current, not pulled from the invoice itself.
  • Save invoice copies, email headers, and approval records for the retention period your investigation or audit policy requires.

Author and platform trust signals

Danell writes on fraud prevention and accounts payable practices for business professionals who need practical, implementable controls rather than theory.

When hiring freelancers or remote suppliers, platform-level protections complement internal AP controls rather than replace them.

  • Escrow-protected payments hold funds until agreed milestones are met, reducing the risk of paying for work that never arrives.
  • Identity verification of freelancers reduces the chance of onboarding a fake or impersonated supplier in the first place.
  • Built-in dispute resolution gives both sides a structured path when a payment or deliverable is contested.
  • Our trust center and security pages document the verification and payment-protection measures behind these claims.

These features reduce the same categories of risk that invoice fraud controls address internally: fake identities, unverifiable payment destinations, and disputes with no documented resolution path.

A short note on prioritizing prevention

The controls that matter most aren't the expensive ones. Segregation of duties costs nothing to implement beyond a policy decision, and a callback to a verified number takes five minutes. What tends to go wrong is skipping the low-friction steps under time pressure, then relying on software to catch what a phone call would have caught for free. Pair every automated check with a human who is empowered to say no.

If you haven't looked at your vendor master file recently, run a 30-day audit now: check for duplicate vendors, stale contact details, and any bank-detail change that wasn't through your dual-approval process. Tighten that one process and you remove the entry point most invoice fraud depends on.

— Danell

Hiring freelancers safely with built-in payment protection

Internal AP controls handle invoices from known suppliers well, but hiring freelancers and remote contractors introduces a different kind of risk: you often can't independently verify a new individual the way you would a registered company. We built our marketplace around closing that specific gap. Payments sit in escrow until agreed milestones are met, verification steps are performed for freelancers before taking on work, and a transparent platform fee on the client side means there are no hidden charges layered into a project's cost.

Aurasocial

  • Escrow holds funds until milestone deliverables are approved, not before.
  • Verified freelancer identities reduce the risk of onboarding a fake supplier.
  • Built-in dispute resolution gives you a documented path if something goes wrong.
  • A single, transparent client-side fee replaces guesswork about what you're actually paying for.

If you're hiring outside talent and want the verification and payment protection built in from the start, post your project and review verified freelancer proposals.

FAQ

What is the 10/80/10 rule for fraud?

The 10/80/10 rule describes a general behavioral pattern: roughly 10% of people will act honestly regardless of controls, about 10% may attempt fraud given the opportunity, and the remaining 80% will follow whichever path is easier, honest or not, depending on the controls in place. The practical takeaway for AP teams is that strong controls shape the behavior of that middle 80%, which is why segregation of duties and verification steps matter more than trying to identify bad actors in advance.

Is it safe to put a bank account number on an invoice?

Bank account numbers appear on invoices routinely and aren't inherently risky to display, since the real danger is a fraudulent change to those details rather than their presence. The risk comes from accepting a bank-detail change without independently verifying it through a callback to a contact already on file, as outlined in National Crime Agency guidance.

How do I check if an invoice is real or fake?

Match the invoice against three-way matching records: the purchase order, the goods receipt, and the vendor's known invoice format and bank details on file. Call the vendor using a verified number, not one listed on the invoice, if anything looks unusual, including a new bank account, an unfamiliar logo, or a request to bypass normal approval.

What are some red flags for a fake invoice?

Common red flags include a sudden bank-detail change, pressure to pay urgently or outside normal approval channels, a vendor name that closely resembles a legitimate supplier, and invoice formatting that doesn't match previous submissions. ICAEW guidance recommends treating any of these as a trigger to pause payment and verify before proceeding.

What should I do immediately if I suspect invoice fraud?

Stop any pending payment and contact your bank to request a recall using the transaction details. Preserve the invoice, email headers, and related correspondence exactly as received, then report the incident to law enforcement, since fast reporting through the FBI's IC3 process can sometimes help freeze funds before they move further.

Sources

Made with help from BabyLoveGrowth