Where supplier fraud exploits control assumptions 

Killian McCarthy
Killian McCarthy
Where supplier fraud exploits control assumptions 

In Brief

  • Supplier records can end up spread across two or three finance systems. 
  • Fraud hides in the gap between them, where no single record reconciles what is true. 
  • The controls are already there. The work is joining them into one lifecycle.

 
Consider a scenario that is more common than most finance teams would like. 

A company grows by acquisition. It buys another business, and now it is running two finance systems instead of one. Sometimes that is deliberate, they plan to dispose of one entity later, so there is no point folding it into the main platform. Sometimes it is just bandwidth, an ERP consolidation is a multi-year project and there are ten other things in the queue. Either way, the end state is the same. There is a supplier master record in ERP one and a supplier master record in ERP two. Same supplier, two data sets, potentially two different sets of bank details, two different transaction histories. 

Nobody did anything wrong. The controls are good. But the picture is now split across two systems, and nobody owns the whole of it. That gap, the space between the systems, is where the risk lives. 

This is a pattern I keep seeing in conversations with finance teams. The teams raising it are not teams with weak controls. They are teams who have realised their control points exist but do not join up, and who want to do something about it before it costs them. 

One supplier record becomes three, and control weakens 

When the same supplier exists across two or three systems, created at different times, with details that may or may not match, you lose the ability to reconcile what is actually true. A change comes in, and you cannot cleanly answer the questions that matter: 

  • Is it legitimate? 
  • Should it apply across all environments, or just one? 
  • Where is the evidence that it happened? 

If you cannot answer those cleanly, you are in exactly the environment a fraudster wants you in. 

And most of the time, while this is going on, you have no idea. They are watching. They may be copied on emails, they may have run a phishing campaign months ago, they have a full view of your process that you do not know they have. Then they find the gap, change the bank details, and send in an invoice that looks completely legitimate. 

This is worth saying plainly, because it is the whole point. The control points exist. Onboarding has controls. Approval has controls. Payment has controls. But they were validated once, at a moment in time, and never revisited, and they do not talk to each other across systems. Controls validated once aren’t controls, they’re assumptions. 

Fraud hides inside routine changes 

The thing people get wrong about supplier fraud is they picture a single dramatic event. It is not like that. It is slow, and it is made of small, boring changes. 

A fraudster setting you up will not start with the bank details. That is the last move. First they change the phone number. Then they change the contact person. Then, maybe, the bank details. And they might space those three changes across a twelve-month period, so each one looks like a routine, innocuous update. Then they wait. They might not even send an invoice for another three months. They are lining you up from a long way out. 

Each individual change looks like normal AP activity. A bank-detail update, a supplier reactivation, a new supplier setup, a request to move a bit quicker than usual because a payment is overdue. You think you are doing something routine. You may be walking into something else entirely. 

The dormant supplier nobody is watching 

Here is one that sits in the background and catches people out. An old supplier, inactive for months, suddenly gets reactivated with an urgent payment attached, and it turns out the bank or contact details are out of date. 

Why is that attractive to a fraudster? Because it does not look like a new supplier setup, which is the thing everyone scrutinises. The supplier already exists. Someone is just making a few minor edits to an existing record. It looks harmless. It carries real risk. 
 
The scale of this surprises people. I have spoken to businesses with thousands of suppliers active in their ERP, where a large share of them had not had an invoice against them in months. Reactivating one of those can look like the simplest thing in the world. It is often exactly where you need to be most careful. 

The bank-detail change is a test, not an update 

When a supplier asks to change their bank details, that is not an administrative task. It is a test of every control you have. 

A bank-detail change is not an update. It is a test of every control you have.
– Killian McCarthy, SVP Sales, SoftCo.

The good version of this is well understood. You validate the request through the original channel and contact before you open anything. You identify the supplier. You check the bank ownership. You capture the approval and the evidence. Plenty of teams do exactly that. What has changed is how hard it has become to do it consistently. With remote working, callbacks are harder, people are harder to reach, and the manual process that used to hold does not always cover every control. 

And when people feel exposed on a particular step, the instinct is to pile on more manual checks. More validation, more sign-off, more people in the loop. It makes them feel safer. It also adds time, delays the payment, and does not necessarily verify the thing that actually matters. But effort is not the same as control. 

The evidence problem shows up when it is too late 

Say the worst happens and you are dealing with a fraudulent payment. You go to your bank, or your insurer, and the first thing they ask you to do is account for it: 

  • What did you do? 
  • How did you do it? 
  • Why do you now believe this was fraud? 

If your approval trail is fragmented, one process in one system, a different process in another, one business unit better governed than the next, that conversation gets very difficult. This is not only an internal-controls or audit point, although it is that. It is an insurance-recovery point. Standardised, evidenced process across every environment is what lets you stand over what happened. Because recovery is not a control strategy. You want the controls to hold in the first place, and the evidence to be there if they do not. 

What stronger control looks like 

Step back and look at the whole AP and P2P landscape, not one step of it. Stronger control is not about adding more checks to any single step. It is about joining the steps up, so the supplier is one record moving through one lifecycle rather than three records scattered across systems. 

Start by joining the contract to the onboarding 

It usually starts with a contract. Someone goes to market, agrees terms, the contract gets signed and lands in finance, often as a PDF on a network share, and everyone agrees the deal is done. Then the supplier goes off to be set up. And here is the disconnect: the onboarding process is almost always separate from the contract. The content of the contract, the thing that actually defines the relationship, ends up immaterial to how the supplier is set up and controlled. 

Joining those dots is where better control comes from. Onboarding that verifies bank details, contact details, phone numbers, email addresses, the people involved. A standard approval process through procurement and the supplier master data team. Bank and identity verification at each step. A full audit history on every part of the transaction. And critically, one place where changes to a supplier happen, one workflow, feeding back into the ERP, rather than edits happening independently in three systems with no common record. 

Close the back door with a real offboarding process 

The offboarding side matters just as much, and it closes the dormant-supplier gap. A standard rule that flags any vendor with no invoice activity in six or nine months, a deactivation process, and then a proper reactivation process when a new invoice does arrive, one that re-verifies the bank details and the supporting documentation and captures the audit history, rather than just flipping the record back on. 

Standardise one control across every system 

The through-line across all of it is standardisation. One control standard across the whole function, whatever the ERP, whatever the location. Teams operating across the US and EMEA see this constantly, different behaviours in different regions because they are treated as different functions. The aim is one consistent control, applied the same way everywhere, so that every change can be seen, verified, evidenced and validated. Get there and you are in good stead with your internal controls, your compliance, your external audit, and yes, an insurance claim if it ever comes to that. 

The gap is the whole story 

Come back to the company we started with, the one now running two finance systems after an acquisition. Nothing about that situation is unusual, and nothing about it means the finance team has failed. The controls are there. What is missing is a single view across them. 

That is the blind spot, and it is worth being precise about what it is and is not. It is not that you lack control. It is that your control is fragmented across systems that were never designed to share one record of the truth. Fraud does not need a hole in any single control to get through. It only needs the space between them. 

The direction of travel is clear enough. Control that is continuous, revalidated every time you interact with a supplier rather than checked once at onboarding, is where finance should be heading. Getting there starts with something more basic than any single tool. It starts with seeing the supplier as one record moving through one lifecycle, not three records scattered across systems nobody has joined up. Do that, so every change can be seen, verified and evidenced wherever it happens, and most of what hides in that space has nowhere left to go. 

Take control of the entire supplier lifecycle

Connect supplier onboarding, verification and ongoing changes in one controlled, auditable process.

Killian McCarthy

SVP Sales· SoftCo

Killian McCarthy is SVP of Sales at SoftCo, specializing in purchase-to-pay (P2P) transformation. With more than 21 years of experience, he has guided businesses through major finance transformation projects, partnering with C-suite finance leaders to shape effective P2P strategies. He helps organizations manage change and align procurement and AP processes. The result: measurable value unlocked through automation and best-practice implementation.

FAQ

Frequently askedquestions

Most control failures aren't a broken step, they're the gap between steps. Onboarding, approval, and payment controls are each validated once and rarely revisited, and they don't talk to each other across systems, which is exactly where fraud gets through.