Payment fraud has become a persistent operational risk, with controllers increasingly responsible for protecting vendor data, payment processes, and internal controls. During the Controllers Council and VendorInfo webinar, The 4-Step Blueprint for Reducing Payment Fraud Risk, Mark Brousseau, President of Brousseau & Associates, and Phil Binkow, CEO of VendorInfo, outlined practical steps finance leaders can take to reduce exposure before fraudulent payments ever leave the organization.

Payment Fraud Has Changed Faster Than Many Finance Processes

The discussion opened with a clear assessment of today’s fraud environment. Rather than relying on traditional hacking techniques, fraudsters increasingly exploit weaknesses in vendor onboarding, bank account changes, compromised email accounts, and social engineering.

As Mark Brousseau explained: “AP has become ground zero for fraud. It is under attack.”

The speakers noted that payment fraud is no longer driven primarily by individual bad actors. Organized criminal groups now employ sophisticated technology, including artificial intelligence, to imitate emails, phone calls, and even video communications. As these tactics continue to improve, finance teams cannot depend on procedures that were designed years ago.

Phil Binkow summarized the challenge this way: “It’s really an ongoing battle between the good guys and the fraudsters. It’s an arms race almost in many respects.”

Understanding the Four Stages of Fraud Prevention

One of the central themes of the webinar was the fraud prevention maturity model. Rather than treating fraud controls as either adequate or inadequate, organizations should evaluate where they currently operate and identify the next stage of improvement.

The four stages include:

1. Reactive

Organizations rely on manual vendor setup, email communication, inconsistent procedures, and limited documentation. Human judgment drives most decisions, creating opportunities for mistakes and fraudulent activity.

2. Controlled

Basic internal controls begin to appear through documented procedures, segregation of duties, approval workflows, and manual verification processes. While these improvements reduce risk, many activities still depend heavily on employees performing repetitive manual work.

3. Standardized

Organizations establish consistent enterprise-wide policies, centralized oversight, standardized verification requirements, and stronger audit readiness. Supplier onboarding and payment controls become uniform across the business.

4. Proactive

The highest level of maturity incorporates continuous monitoring, automated validation, transaction scoring, predictive analytics, and complete visibility across the vendor lifecycle. Rather than identifying fraud after a payment occurs, organizations detect unusual activity before funds are released.

Vendor Onboarding Is Often the Weakest Link

Many finance departments concentrate heavily on reviewing payments before they are approved. The speakers argued that the greater risk often exists much earlier in the process.

Fraudsters commonly target:

  • Vendor onboarding
  • Bank account change requests
  • Vendor master data
  • Employee email accounts
  • Supplier email accounts

Once attackers gain access to legitimate communications, they frequently observe invoice activity for weeks or months before submitting fraudulent payment instructions.

Brousseau explained the process: “They lie in wait and they see what the nature of invoices are between two entities.”

By studying normal payment activity first, fraudsters make later requests appear legitimate.

Verification and Validation Are Not the Same

A particularly valuable section of the webinar focused on the distinction between verification and validation, two terms that are often used interchangeably but represent very different levels of protection.

Verification confirms that information has been provided.

Validation confirms that the information is accurate, authentic, and trustworthy before payments are issued.

Validation should include activities such as:

  • Confirming bank account ownership
  • TIN matching
  • OFAC screening
  • Sanctions checks
  • Authorized representative verification
  • Ongoing monitoring throughout the supplier relationship

Brousseau cautioned that organizations frequently confuse these two concepts:

“If you think you’re validating information, but you’re really just verifying it, it’s going to give you a false sense of security.”

That false confidence may allow fraudulent payment requests to pass through existing controls unnoticed.

Why Email and Phone Calls No Longer Provide Enough Protection

Poll responses during the webinar showed that many organizations still depend on email or phone calls to confirm vendor banking changes.

The speakers explained why these methods have become increasingly unreliable.

Email accounts can be compromised without either party realizing it. Likewise, fraudsters have begun intercepting or redirecting business phone systems, making voice verification less dependable than many organizations assume.

Phil Binkow observed: “It’s tedious, it’s time consuming, it’s not secure, it’s becoming more and more old school.”

The recommendation was to replace manual verification with independent bank account validation tools that confirm ownership directly rather than relying solely on communications that could be compromised.

Building Stronger Internal Controls

Technology alone does not eliminate payment fraud. The speakers emphasized that organizations also need disciplined internal controls supported by consistent execution.

Key recommendations included:

  • Maintain segregation of duties.
  • Establish approval hierarchies based on transaction risk.
  • Standardize supplier onboarding procedures.
  • Create formal exception management processes.
  • Document every approval and change.
  • Continuously monitor supplier records and bank account changes.

Automation supports these controls by reducing repetitive manual work while creating a more complete audit trail.

Four Practical Actions Controllers Can Take

The webinar concluded with a practical roadmap that finance leaders can begin implementing immediately.

The recommended priorities were:

  1. Review current supplier onboarding controls and identify weaknesses.
  2. Evaluate existing bank account change procedures and replace manual verification where appropriate.
  3. Strengthen validation practices through bank account ownership verification, TIN matching, OFAC screening, and sanctions monitoring.
  4. Implement continuous monitoring to identify unusual activity before payments are processed.

These improvements allow organizations to identify gaps earlier, reduce payment fraud exposure, and improve confidence in vendor data.

Final Thoughts

Payment fraud continues to evolve alongside advances in technology, making static controls increasingly difficult to defend. As fraud schemes become more organized and sophisticated, controllers must evaluate whether existing processes remain suitable for today’s environment.

Moving from reactive procedures toward proactive monitoring requires more than additional policies. It requires stronger validation, better visibility into vendor data, and controls that operate continuously rather than periodically. Organizations that modernize these processes place themselves in a stronger position to detect suspicious activity before fraudulent payments occur.

Want to explore the complete four-step framework and hear the speakers’ recommendations in greater detail? Watch the full webinar here.

ABOUT OUR SPONSOR:

VendorInfo, part of Financial Operations Networks (FON), provides specialized self-service vendor portals that bring focused, comprehensive and timely tools and support for collecting, verifying and managing vendor information. VendorInfo meets the changing internal and external requirements for security, controls, compliance, efficiency and scalability. FON was founded by the leadership team behind PayTECH and The Accounts Payable Network and has been instrumental in helping thousands of senior financial professionals keep their operations ahead of the risk, efficiency and cost-avoidance curves since 2001. Learn more at www.vendorinfo.com