Five routine supplier changes that can hide fraud

Robert Lynch
Robert Lynch

AP & P2P Analyst

Five routine supplier changes that can hide fraud

In Brief

  • Supplier fraud usually looks like routine admin, not fraud.
  • It hides in the gaps between finance systems, where changes never have to reconcile.
  • The fix is one consistent control standard, not more manual checks.

Supplier fraud rarely looks like fraud. It looks like admin. A bank detail updated here, a dormant supplier switched back on there, an approval that moves a little faster than usual because a payment is overdue. Each change looks like ordinary accounts payable activity, which is exactly why it works. These are the warning signs of supplier fraud hiding in plain sight.

The pattern is clearest when a supplier exists across more than one finance system. When the same supplier sits in two or three ERPs, created at different times, with details that may not match, there is no single record of what is true, and a change in one place does not have to reconcile with the others. That is the space these five changes hide in. None of them is a failure of control. Each is a control point that exists but is not joined up to the others.

For the full breakdown of these warning signs of supplier fraud across a multi-ERP environment, see Where supplier fraud exploits control assumptions.

1. Duplicate supplier records

When one supplier becomes two or three records across different systems, you lose the ability to reconcile what is actually correct. Different bank details, different transaction histories, different points of creation, and no common view that says which is right. A change applied to one record does not have to match the others, and often nobody is positioned to notice the gap. The duplication itself is the weakness, because it removes the single source of truth that every other control depends on.

2. Bank detail changes

A request to change bank details is not an administrative update. It is a test of every control you have. The good version of the process is well understood: validate the request through the original channel and contact before opening anything, identify the supplier, check the bank ownership, and capture the approval and the evidence. What has made this harder to do consistently is that manual checks are difficult to hold together across systems and locations, and a change made in one environment may never be reflected in another. The moment a bank detail changes is the moment most likely to be targeted, and the moment your evidence trail matters most.

3. Dormant suppliers that are suddenly reactivated

An old supplier, inactive for months, is switched back on with an urgent payment attached, and the bank or contact details turn out to be out of date. This is attractive precisely because it does not look like a new supplier setup, which is the thing everyone scrutinises. The supplier already exists. Someone is only making a few minor edits to a record that is already there. It looks harmless, and it carries real risk. Businesses running thousands of suppliers often find a large share of them have had no invoice activity in months, and reactivating any one of those can look like the simplest task in the world.

4. Fragmented approval trails

When approvals are handled one way in one system and another way in another, or governed more tightly in one business unit than the next, the trail breaks apart. Everyone is willing to approve, but afterwards the basic questions are hard to answer:

  • Who made the change?
  • Where was it required?
  • Where is the evidence stored?

A fragmented approval trail is not just an internal-controls problem. It is the difference between being able to account for a payment and not being able to, at the exact moment you most need to.

5. Weak audit evidence

If a fraudulent payment does happen, the bank or the insurer will ask you to account for it: what you did, how you did it, and why you now believe it was fraud. If your process is standardised and evidenced across every system, that is a conversation you can hold. If it is not, it becomes very difficult, and this is an insurance-recovery point as much as an audit one. Evidence gathered after the fact is not evidence. The record has to be built as the work happens, or it is not there when it counts.

6. The common thread

Look back across these five warning signs of supplier fraud and the pattern is the same each time. Supplier fraud appears between systems, in the gaps where something falls between two stools, and the people looking to exploit it are looking for exactly those gaps. The answer is not more manual checks on any single step. It is consistency: one control standard applied the same way across every ERP, every location and every business unit, so that any change to a supplier can be seen, verified, evidenced and validated wherever it happens.

That consistency is what keeps you in good standing with internal controls, compliance and external audit, and it is what lets you stand over a payment if it is ever questioned. The individual controls are probably already in place. The work is joining them up.

The five changes above are drawn from a SoftCo webinar, “The Multi-ERP Blind Spot: Where Supplier Fraud Hides in Fragmented Systems,” presented by Killian McCarthy, SVP Sales. For the full discussion, including how these risks form across fragmented ERP environments and what stronger, standardised control looks like across the supplier lifecycle, watch the webinar on demand.

Robert Lynch

Data Analyst · SoftCo

Robert is a Data Analyst at SoftCo specializing in accounts payable automation, procure-to-pay transformation, and finance technology trends. Drawing on industry research and market insights, he helps finance leaders navigate evolving challenges and identify opportunities to improve efficiency, control, and business performance.

FAQ

Frequently askedquestions

Validate the request through the original channel and contact before making any change, never the number or email on the request itself. Confirm bank ownership and capture the evidence at the moment of the change.