02-347-7730  |  Saeree ERP - Complete ERP System for Thai Businesses Contact Us

47% of Companies Hit by Invoice Fraud — How AP Automation Prevents It (2026)

47% of Companies Hit by Invoice Fraud — How AP Automation Prevents It (2026)
  • 19
  • August

Invoice fraud is what happens when someone impersonates a supplier — sending a forged invoice or quietly changing the destination bank account — to get accounts payable to pay the wrong party. The AP Automation Trends 2026 report puts the figure at 47% of companies worldwide hitting a fake-invoice scam in the past year, while the AFP 2025 Payments Fraud Survey found 79% of organizations experienced attempted or actual payment fraud. What makes this dangerous is not sophistication — it is that the fraud rides on ordinary approval routes that look entirely normal.

In short: Invoice fraud is among the top risks facing finance teams in 2026, arriving as forged invoices, changed vendor bank details (business email compromise), and duplicate payments. What actually works against it is an ERP that enforces a three-way match (PO + goods receipt + invoice), an approval workflow with genuine separation of duties, and controlled changes to vendor master data.

The Numbers Keeping CFOs Awake in 2026

Before talking about prevention, it helps to understand just how big the invoice fraud problem has become in 2026:

Figure What it means Source
47% of companies encountered a fake invoice scam in the past year Quadient AP Trends 2026
79% of organizations experienced payment fraud (attempted or successful) AFP Payments Fraud Survey 2025
66% of AP teams still handle supplier invoices largely by hand Quadient AP Trends 2026
77% of AP teams have some automation in place already, but not end to end Quadient AP Trends 2026
~9% only this many achieve true "Touchless AP" — no human touches any invoice Industry survey 2026

The most striking figure is the gap between "companies with some automation" (77%) and "companies using automation fully" (9%) — most sit in the "installed but not fully adopted" state, and that is exactly where fraud slips through, because people still make decisions at multiple steps and email remains the primary channel.

The 3 Most Common Attack Patterns in 2026

Fraudsters have many ways to deceive an AP team, but these three patterns account for more than 80% of reported cases.

Pattern 1 — Fake Invoice (Vendor Impersonation)

The attacker poses as a vendor the company has bought from before and sends a fake invoice complete with a convincing logo, signature, and tax invoice number. The timing is rarely random:

  • At month-end or quarter-end — a large backlog of unpaid invoices means staff cannot check them all in time
  • Just before a long holiday — staff approve "let's pay it now" so nothing is left outstanding
  • Near the end of the fiscal year — when there is pressure to spend the remaining budget

A real-world case: a forged tax invoice identical to the genuine one in every visible detail, but with a different destination bank account — sometimes reusing the same tax invoice number as the genuine document, which makes verification difficult (see also the e-Tax Invoice system and how to verify it)

Pattern 2 — Business Email Compromise (BEC) / Bank Account Change Fraud

This is the fastest-growing pattern of 2026 — the fraudster does not send a fake invoice at all, but inserts themselves into communication with a genuine vendor and sends an email requesting a bank account change just before the payment date:

  1. Hack or spoof the vendor's email (using a lookalike domain, for example vendor.co.thvend0r.co.th)
  2. Send a message such as "our new account goes live today, please transfer to the new number attached"
  3. Attach a forged "change of payee details" letter
  4. AP pays against the original genuine invoice but to the new destination — the money lands in the fraudster's account

Why it is so dangerous: the invoice is genuine, the goods or services are genuine, and the vendor is genuine. Only the bank account changed, which means the 3-way match passes cleanly. If the system does not scrutinize vendor master changes specifically, the fraud stays invisible until the vendor follows up asking "why haven't we been paid?"

Pattern 3 — Internal Fraud (Duplicate Payment / Ghost Vendor)

This is fraud from the inside — committed by employees themselves, often in AP or procurement:

  • Ghost Vendor — creating a fake vendor master record with the employee's own bank account (or that of someone close to them), then raising POs and invoices under that vendor
  • Duplicate Payment — deliberately paying the same invoice twice using slightly different tax invoice numbers (for example I001 and I001A) and pocketing the difference
  • Inflated Invoice — colluding with a genuine vendor to issue an over-stated invoice and split the excess. This is hard to detect without contract pricing

This category runs deepest, because the perpetrator holds legitimate access to the system — the defenses are segregation of duties + audit trail + periodic review

5 Layers of Invoice Fraud Defense (Defense in Depth)

What actually works is layering several defenses rather than relying on one, because a fraudster may find a loophole in any single layer — a sound system needs at least five.

Layer Control Fraud type blocked
1. Vendor Master Dual approval to add or edit a vendor + verification call Ghost vendor + BEC
2. PO Required Every invoice must reference an approved PO — no "non-PO invoice" Fake invoice
3. 3-Way Match PO + Goods Receipt + Invoice must agree on every line Inflated invoice + duplicate
4. Approval Workflow Authority split by value + no one person approves both the vendor and the payment Internal fraud
5. Audit Trail Log every action — who changed what, when, and from which IP All types (used for retrospective investigation)

Layer 1 — Vendor Master Control

This is the most important layer because almost every fraud starts at the vendor master — control this and you cuts the attack surface by nearly half:

  • Dual approval — the person who creates or edits a vendor and the person who approves it must be two different people
  • Verification call — for a new vendor, call back on the number held in the existing master data (never the number given in the change-request email)
  • Bank account history — keep a record of every bank account change, who made it, and when
  • Cooling period — a newly added vendor must wait 24-48 hours before it can be used

Layer 2 — PO-Based Procurement

The rule is simple: "no PO, no payment" — every invoice must reference an approved Purchase Order in the procurement system first. A fake invoice is blocked immediately because no matching PO exists.

Layer 3 — 3-Way Match

Matching PO ↔ Goods Receipt ↔ Invoice — all three documents must agree at line level, not merely on the total:

  • Item or service codes match
  • Quantities match (or fall within a defined tolerance)
  • Unit prices match the contract or PO
  • Tax and discount amounts are calculated correctly

If all four of those checks fails, the system must block automatically, not merely warn because a "warning" gets clicked away as "ignore" whenever people are in a hurry

Layer 4 — Approval Workflow by Value

Define approval authority in tiers, for example:

Value Approver Additional condition
< 50,000 THB Department head PO + Invoice
50,000 - 500,000 Manager + Accounting 3-way match
500,000 - 5,000,000 CFO + senior executive Contract / quotation
> 5,000,000 Two executive directors Board resolution

Layer 5 — Audit Trail and Periodic Review

Retain a log of every action for at least the trailing 12 months and require internal audit to run monthly spot checks on:

  • Vendor master changes (who / when / IP / old value / new value)
  • 3-way match overrides (how many / by whom / with what justification)
  • Invoices paid on holidays or outside business hours
  • Payments made to a recently changed bank account

The Role of AP Automation in Breaking the Fraud Cycle

AP automation is not only about speed — it is about consistency of checking. Tired humans skip steps; a system never gets tired:

Task Manual Automation
Checking PO ↔ Invoice Spot checks — things get missed 100% of invoices checked
Duplicate checking Relies on memory — often missed SQL query across every hash / document number
Vendor data changes Recorded in Excel, or not recorded at all Automatic audit log on every field
Approval routing Email / paper — hard to track Workflow with a timestamp at every step
Anomaly detection None — depends on the human eye Rule + ML alerts (e.g. an invoice 3x larger than the vendor's average)

AI / Agentic AP — The New Layer in 2026

The AP trend in 2026 is the arrival of Agentic AI to assist with exception handling by:

  • OCR + LLM invoice reading — extracting data from invoice PDFs and images without manual keying
  • Pattern matching — fuzzy-matching vendor names to catch fake vendors whose names closely resemble genuine ones
  • Anomaly detection — flagging unusual invoices (prices above average, orders placed outside business hours, and so on)
  • Auto-routing exceptions — forwarding cases to the right person automatically, along with the reason for the flag

But AI does not replace the basic controls — it is a layer that adds to them, not a substitute for the 3-way match or the approval workflow

Assessing the Risk in Your Own Company — A 10-Point Checklist

Answer these 10 questions — fewer than 7 "yes" answers means significant exposure to fraud:

Question Relates to
1. Does every change to a vendor bank account require dual approval?BEC
2. Must every invoice reference a PO, with no "non-PO" exceptions?Fake invoice
3. Do you match the three documents (PO+GR+Invoice) at line level rather than at total level?Inflated invoice
4. Are the person who creates a vendor and the person who approves payment two different people?Ghost vendor
5. Do you have an audit log that traces who changed what data and when?All types
6. Do you produce a monthly duplicate invoice report?Duplicate payment
7. Do you have a verification call policy for new vendors (using the previously held number)?BEC
8. Is there a 24-48 hour cooling period before a new vendor can be used?Ghost vendor
9. Does a 3-way match override require a justification plus a designated approver?Internal fraud
10. Does internal audit spot-check AP transactions every month?All types

Why This Matters for Organizations Running Saeree ERP

The Saeree ERP AP module is designed with these controls as defaults rather than options you have to switch on because fraud prevention has to start from a setup that is "already correct", not one that "needs someone to go and enable it":

  • Vendor Master Control — an administrator can add, deactivate, and set valid from-to dates for a vendor without a patch, and the system enforces dual approval for bank account changes
  • 3-Way Match enforced by default — an invoice that does not match its PO and GR is blocked and cannot proceed to the payment stage. An override requires a justification and an approver
  • Configurable Approval Workflow — administrators define the value thresholds, the approvers, and the number of steps themselves, with no code changes and no waiting for a vendor patch
  • Audit Trail on every field — every action is recorded with IP, user, and timestamp, ready for internal audit to use in its monthly review straight away
  • Duplicate Detection — the system compares invoice number + vendor + amount + date and warns immediately when a similar invoice already exists
  • Vendor ↔ Payment approval separation — the person who adds a vendor and the person who approves payment must hold different roles by design, closing the ghost vendor route at the schema level

Investment in fraud prevention usually pays for itself quickly — take a mid-sized company with THB 200 million of payables a year: a fraud loss of just 0.1% is THB 200,000 over the year, which typically exceeds the cost of the system, and the system delivers other benefits besides.

Note: actual fraud losses vary enormously from company to company — they depend on volume, industry, and the controls already in place — the 0.1% figure is only an illustration for the calculation, not a Saeree ERP benchmark, but what is certain is that even a single fraud loss often exceeds the cost of an entire ERP project

A fraud that steals THB 200,000 in one go can take a system running every day months to uncover, but with controls in place at the source, that same fraud is blocked on day one, without relying on anyone to "notice" it later.

- Saeree ERP Team

Conclusion — What to Do Now

  1. Run the 10-point checklist — fewer than 7 "yes" answers means you are exposed to fraud
  2. Review vendor master changes for the past 6 months — focus on bank account changes made on the last day before a due date
  3. Set a dual approval policy for vendor bank account changes — even without system support yet, require two signatures for now
  4. Start with a sampled manual 3-way match — pick 10 random invoices a week and compare them against the PO and GR
  5. Assess your current system — does the accounting system you use today support an automatic 3-way match? If not, an upgrade needs to be evaluated

If your organization is assessing its invoice fraud risk, or wants an AP system with these controls built in, the Saeree team is ready to advise on AP module design, approval workflow, and integration with the Revenue Department's e-Tax Invoice system. You can contact our consulting team directly.

References

Interested in an ERP system for your organization?

Talk to the experts at Grand Linux Solution

Request a Free Demo

Tel 02-347-7730 | sale@grandlinux.com

Saeree ERP Author

About the Author

Sureeraya Limpaibul

Managing Director, Grand Linux Solution Co., Ltd. & Founder of Saeree ERP — providing end-to-end ERP advisory and services.