- 19
- August
Invoice fraud is what happens when someone impersonates a supplier — sending a forged invoice or quietly changing the destination bank account — to get accounts payable to pay the wrong party. The AP Automation Trends 2026 report puts the figure at 47% of companies worldwide hitting a fake-invoice scam in the past year, while the AFP 2025 Payments Fraud Survey found 79% of organizations experienced attempted or actual payment fraud. What makes this dangerous is not sophistication — it is that the fraud rides on ordinary approval routes that look entirely normal.
In short: Invoice fraud is among the top risks facing finance teams in 2026, arriving as forged invoices, changed vendor bank details (business email compromise), and duplicate payments. What actually works against it is an ERP that enforces a three-way match (PO + goods receipt + invoice), an approval workflow with genuine separation of duties, and controlled changes to vendor master data.
The Numbers Keeping CFOs Awake in 2026
Before talking about prevention, it helps to understand just how big the invoice fraud problem has become in 2026:
| Figure | What it means | Source |
|---|---|---|
| 47% | of companies encountered a fake invoice scam in the past year | Quadient AP Trends 2026 |
| 79% | of organizations experienced payment fraud (attempted or successful) | AFP Payments Fraud Survey 2025 |
| 66% | of AP teams still handle supplier invoices largely by hand | Quadient AP Trends 2026 |
| 77% | of AP teams have some automation in place already, but not end to end | Quadient AP Trends 2026 |
| ~9% | only this many achieve true "Touchless AP" — no human touches any invoice | Industry survey 2026 |
The most striking figure is the gap between "companies with some automation" (77%) and "companies using automation fully" (9%) — most sit in the "installed but not fully adopted" state, and that is exactly where fraud slips through, because people still make decisions at multiple steps and email remains the primary channel.
The 3 Most Common Attack Patterns in 2026
Fraudsters have many ways to deceive an AP team, but these three patterns account for more than 80% of reported cases.
Pattern 1 — Fake Invoice (Vendor Impersonation)
The attacker poses as a vendor the company has bought from before and sends a fake invoice complete with a convincing logo, signature, and tax invoice number. The timing is rarely random:
- At month-end or quarter-end — a large backlog of unpaid invoices means staff cannot check them all in time
- Just before a long holiday — staff approve "let's pay it now" so nothing is left outstanding
- Near the end of the fiscal year — when there is pressure to spend the remaining budget
A real-world case: a forged tax invoice identical to the genuine one in every visible detail, but with a different destination bank account — sometimes reusing the same tax invoice number as the genuine document, which makes verification difficult (see also the e-Tax Invoice system and how to verify it)
Pattern 2 — Business Email Compromise (BEC) / Bank Account Change Fraud
This is the fastest-growing pattern of 2026 — the fraudster does not send a fake invoice at all, but inserts themselves into communication with a genuine vendor and sends an email requesting a bank account change just before the payment date:
- Hack or spoof the vendor's email (using a lookalike domain, for example
vendor.co.th→vend0r.co.th) - Send a message such as "our new account goes live today, please transfer to the new number attached"
- Attach a forged "change of payee details" letter
- AP pays against the original genuine invoice but to the new destination — the money lands in the fraudster's account
Why it is so dangerous: the invoice is genuine, the goods or services are genuine, and the vendor is genuine. Only the bank account changed, which means the 3-way match passes cleanly. If the system does not scrutinize vendor master changes specifically, the fraud stays invisible until the vendor follows up asking "why haven't we been paid?"
Pattern 3 — Internal Fraud (Duplicate Payment / Ghost Vendor)
This is fraud from the inside — committed by employees themselves, often in AP or procurement:
- Ghost Vendor — creating a fake vendor master record with the employee's own bank account (or that of someone close to them), then raising POs and invoices under that vendor
- Duplicate Payment — deliberately paying the same invoice twice using slightly different tax invoice numbers (for example I001 and I001A) and pocketing the difference
- Inflated Invoice — colluding with a genuine vendor to issue an over-stated invoice and split the excess. This is hard to detect without contract pricing
This category runs deepest, because the perpetrator holds legitimate access to the system — the defenses are segregation of duties + audit trail + periodic review
5 Layers of Invoice Fraud Defense (Defense in Depth)
What actually works is layering several defenses rather than relying on one, because a fraudster may find a loophole in any single layer — a sound system needs at least five.
| Layer | Control | Fraud type blocked |
|---|---|---|
| 1. Vendor Master | Dual approval to add or edit a vendor + verification call | Ghost vendor + BEC |
| 2. PO Required | Every invoice must reference an approved PO — no "non-PO invoice" | Fake invoice |
| 3. 3-Way Match | PO + Goods Receipt + Invoice must agree on every line | Inflated invoice + duplicate |
| 4. Approval Workflow | Authority split by value + no one person approves both the vendor and the payment | Internal fraud |
| 5. Audit Trail | Log every action — who changed what, when, and from which IP | All types (used for retrospective investigation) |
Layer 1 — Vendor Master Control
This is the most important layer because almost every fraud starts at the vendor master — control this and you cuts the attack surface by nearly half:
- Dual approval — the person who creates or edits a vendor and the person who approves it must be two different people
- Verification call — for a new vendor, call back on the number held in the existing master data (never the number given in the change-request email)
- Bank account history — keep a record of every bank account change, who made it, and when
- Cooling period — a newly added vendor must wait 24-48 hours before it can be used
Layer 2 — PO-Based Procurement
The rule is simple: "no PO, no payment" — every invoice must reference an approved Purchase Order in the procurement system first. A fake invoice is blocked immediately because no matching PO exists.
Layer 3 — 3-Way Match
Matching PO ↔ Goods Receipt ↔ Invoice — all three documents must agree at line level, not merely on the total:
- Item or service codes match
- Quantities match (or fall within a defined tolerance)
- Unit prices match the contract or PO
- Tax and discount amounts are calculated correctly
If all four of those checks fails, the system must block automatically, not merely warn because a "warning" gets clicked away as "ignore" whenever people are in a hurry
Layer 4 — Approval Workflow by Value
Define approval authority in tiers, for example:
| Value | Approver | Additional condition |
|---|---|---|
| < 50,000 THB | Department head | PO + Invoice |
| 50,000 - 500,000 | Manager + Accounting | 3-way match |
| 500,000 - 5,000,000 | CFO + senior executive | Contract / quotation |
| > 5,000,000 | Two executive directors | Board resolution |
Layer 5 — Audit Trail and Periodic Review
Retain a log of every action for at least the trailing 12 months and require internal audit to run monthly spot checks on:
- Vendor master changes (who / when / IP / old value / new value)
- 3-way match overrides (how many / by whom / with what justification)
- Invoices paid on holidays or outside business hours
- Payments made to a recently changed bank account
The Role of AP Automation in Breaking the Fraud Cycle
AP automation is not only about speed — it is about consistency of checking. Tired humans skip steps; a system never gets tired:
| Task | Manual | Automation |
|---|---|---|
| Checking PO ↔ Invoice | Spot checks — things get missed | 100% of invoices checked |
| Duplicate checking | Relies on memory — often missed | SQL query across every hash / document number |
| Vendor data changes | Recorded in Excel, or not recorded at all | Automatic audit log on every field |
| Approval routing | Email / paper — hard to track | Workflow with a timestamp at every step |
| Anomaly detection | None — depends on the human eye | Rule + ML alerts (e.g. an invoice 3x larger than the vendor's average) |
AI / Agentic AP — The New Layer in 2026
The AP trend in 2026 is the arrival of Agentic AI to assist with exception handling by:
- OCR + LLM invoice reading — extracting data from invoice PDFs and images without manual keying
- Pattern matching — fuzzy-matching vendor names to catch fake vendors whose names closely resemble genuine ones
- Anomaly detection — flagging unusual invoices (prices above average, orders placed outside business hours, and so on)
- Auto-routing exceptions — forwarding cases to the right person automatically, along with the reason for the flag
But AI does not replace the basic controls — it is a layer that adds to them, not a substitute for the 3-way match or the approval workflow
Assessing the Risk in Your Own Company — A 10-Point Checklist
Answer these 10 questions — fewer than 7 "yes" answers means significant exposure to fraud:
| Question | Relates to |
|---|---|
| 1. Does every change to a vendor bank account require dual approval? | BEC |
| 2. Must every invoice reference a PO, with no "non-PO" exceptions? | Fake invoice |
| 3. Do you match the three documents (PO+GR+Invoice) at line level rather than at total level? | Inflated invoice |
| 4. Are the person who creates a vendor and the person who approves payment two different people? | Ghost vendor |
| 5. Do you have an audit log that traces who changed what data and when? | All types |
| 6. Do you produce a monthly duplicate invoice report? | Duplicate payment |
| 7. Do you have a verification call policy for new vendors (using the previously held number)? | BEC |
| 8. Is there a 24-48 hour cooling period before a new vendor can be used? | Ghost vendor |
| 9. Does a 3-way match override require a justification plus a designated approver? | Internal fraud |
| 10. Does internal audit spot-check AP transactions every month? | All types |
Why This Matters for Organizations Running Saeree ERP
The Saeree ERP AP module is designed with these controls as defaults rather than options you have to switch on because fraud prevention has to start from a setup that is "already correct", not one that "needs someone to go and enable it":
- Vendor Master Control — an administrator can add, deactivate, and set valid from-to dates for a vendor without a patch, and the system enforces dual approval for bank account changes
- 3-Way Match enforced by default — an invoice that does not match its PO and GR is blocked and cannot proceed to the payment stage. An override requires a justification and an approver
- Configurable Approval Workflow — administrators define the value thresholds, the approvers, and the number of steps themselves, with no code changes and no waiting for a vendor patch
- Audit Trail on every field — every action is recorded with IP, user, and timestamp, ready for internal audit to use in its monthly review straight away
- Duplicate Detection — the system compares invoice number + vendor + amount + date and warns immediately when a similar invoice already exists
- Vendor ↔ Payment approval separation — the person who adds a vendor and the person who approves payment must hold different roles by design, closing the ghost vendor route at the schema level
Investment in fraud prevention usually pays for itself quickly — take a mid-sized company with THB 200 million of payables a year: a fraud loss of just 0.1% is THB 200,000 over the year, which typically exceeds the cost of the system, and the system delivers other benefits besides.
Note: actual fraud losses vary enormously from company to company — they depend on volume, industry, and the controls already in place — the 0.1% figure is only an illustration for the calculation, not a Saeree ERP benchmark, but what is certain is that even a single fraud loss often exceeds the cost of an entire ERP project
A fraud that steals THB 200,000 in one go can take a system running every day months to uncover, but with controls in place at the source, that same fraud is blocked on day one, without relying on anyone to "notice" it later.
- Saeree ERP Team
Conclusion — What to Do Now
- Run the 10-point checklist — fewer than 7 "yes" answers means you are exposed to fraud
- Review vendor master changes for the past 6 months — focus on bank account changes made on the last day before a due date
- Set a dual approval policy for vendor bank account changes — even without system support yet, require two signatures for now
- Start with a sampled manual 3-way match — pick 10 random invoices a week and compare them against the PO and GR
- Assess your current system — does the accounting system you use today support an automatic 3-way match? If not, an upgrade needs to be evaluated
If your organization is assessing its invoice fraud risk, or wants an AP system with these controls built in, the Saeree team is ready to advise on AP module design, approval workflow, and integration with the Revenue Department's e-Tax Invoice system. You can contact our consulting team directly.
References
- Accounts Payable Automation Trends 2026 — Quadient
- AFP 2025 Payments Fraud and Control Survey — Association for Financial Professionals
- Top Accounts Payable Trends for 2026 — Corcentric
- 15 Essential Accounts Payable Trends for 2026 — MHC
Interested in an ERP system for your organization?
Talk to the experts at Grand Linux Solution
Request a Free DemoTel 02-347-7730 | sale@grandlinux.com


