Vendor fraud red flags every audit should catch (and most manual reviews miss)
Bank-detail changes, near-duplicate invoice numbers, round-number amounts just under an approval threshold — the patterns a systematic audit checks on every document, not a sample.
Vendor fraud does not usually announce itself. It hides inside a document that looks, on a quick read, exactly like every other invoice in the batch — which is precisely why a sampling-based review misses it and a systematic, document-by-document check does not.
The scale of the problem
76% of US organizations experienced attempted or actual payments fraud in 2025, per the AFP Payments Fraud and Control Survey — and only 17% of organizations currently use AI to help fight it, leaving most of the defense to manual vigilance against a threat that specifically exploits inattention at volume. The FBI's Internet Crime Complaint Center recorded $3.04 billion in reported Business Email Compromise losses in 2025 alone, averaging over $122,000 per case. The ACFE's global fraud study adds the baseline every business should know: organizations lose an estimated 5% of revenue to fraud each year, and the median scheme runs 12 months before anyone notices.
The five red flags a systematic audit checks on every document
1. A bank-detail change on a known supplier
The single highest-value signal in accounts payable. When a supplier your business has paid before suddenly asks for a different account — especially with urgent wording ("following our recent change of banking partner...") — that is vendor email compromise until proven otherwise. A phone call to the number already on file, never the one on the suspicious invoice, resolves it in minutes.
2. A near-duplicate invoice number
The classic: the same invoice submitted twice, weeks apart, with a number altered just enough to slip past a human's memory — INV-2024-0891 becomes INV-2024-891. A systematic check compares every invoice against the supplier's full history, not the reviewer's recollection of what they processed last month.
3. An amount that breaks the supplier's pattern
A supplier who typically bills a consistent monthly amount and suddenly invoices multiples of it deserves a question. So does an amount that lands suspiciously just under a known approval threshold.
4. A round number from a supplier who never bills round numbers
Real invoices, built from real line items and real tax calculations, rarely land on perfectly round totals. A pattern of suspiciously clean numbers from one supplier is a signal worth a second look — not proof of anything on its own, but a legitimate prompt for verification.
5. Missing or malformed legal identifiers
An invoice from a supplier whose registration number does not match a valid format, or is missing entirely, is a document that would not survive basic verification against a public business registry — and it is a check almost no manual review performs on every single invoice, because doing it by hand does not scale.
Why sampling misses what systematic checking catches
A human reviewer, however diligent, samples. Under real volume, nobody re-reads every invoice from a supplier they trust — and that is exactly the trust fraud is built to exploit. A systematic audit runs every check on every document in the batch, not a percentage of it, which is the structural reason it catches patterns a sampled manual review cannot: the fraudulent invoice that "looks normal" in isolation looks very different next to the eleven other invoices from the same supplier.
Related reading
- Inside a 55-point audit control framework: what auditors actually check, and why each one has a legal source
- What an AP recovery audit actually costs in 2026: a market comparison
FAQ
Does flagging a red flag mean fraud has been confirmed?
No — and a responsible audit report says so explicitly. A red flag is a discrepancy that warrants investigation; confirming intent requires human judgment and often information outside the documents themselves (a phone call, an internal conversation). No automated check claims to detect fraud with certainty.
Can these checks run on a single batch of historical documents, or only ongoing processing?
Both — the same checks that run on new documents as they arrive can run on a closed batch spanning a full prior period, which is exactly what a one-off audit does: cross-reference an entire period's documents against each other at once.
What's the single highest-priority control to implement first?
Bank-detail change verification, by a wide margin — it is the fastest-growing fraud vector and the most expensive per incident, and it is defeated by one out-of-band phone call if the change is actually detected and flagged, which is the part manual review most often misses under volume.