Invoice fraud and duplicate payments rarely make headlines the way a major cyberattack does, but they quietly cost businesses far more, far more often. They’re also two of the most preventable losses in finance, not because the fraud attempts are unsophisticated, but because the controls that stop them are well understood and simply aren’t applied consistently in manual AP processes. Here’s a practical checklist for closing the gaps, and how PaperLess builds most of it in by default.
Why This Keeps Happening
Duplicate payments and invoice fraud both exploit the same underlying weakness: a manual AP process that relies on people remembering, checking, and cross-referencing information under time pressure. When a finance team is processing a high volume of invoices, in different formats, from different suppliers, arriving through different channels such as email, post, and supplier portals, small inconsistencies are easy to miss.
Fraudsters know this. Common tactics include invoices sent from a domain that looks almost identical to a genuine supplier’s, “updated bank details” emails timed to intercept a real payment run, and invoices for goods or services that were never ordered, sent in the hope that a busy AP team processes them without querying it.
Duplicate payments, meanwhile, are usually not fraud at all, they’re simple process failure. The same invoice is entered twice because it arrived via two channels, or a supplier resubmits an unpaid invoice that was actually already paid but not marked as such in the system.
The Checklist
1. Verify supplier bank detail changes independently. Any email requesting a change to a supplier’s bank details should be verified through a separate, known contact channel, such as a phone call to a number you already have on file, not one provided in the email itself. This single habit prevents the majority of successful invoice-based payment fraud.
2. Match every invoice against a purchase order and goods receipt where applicable. 3-way matching, checking the invoice against the PO and confirmation of delivery, catches both fraudulent invoices for goods never ordered and genuine but incorrect invoices from real suppliers.
3. Check for duplicate invoice numbers automatically, not by memory. Relying on someone recognising an invoice number from a few days or weeks ago doesn’t scale past a small handful of transactions. Every invoice should be checked against previously processed invoice numbers before it’s approved.
4. Flag invoices that break a supplier’s normal pattern. A supplier who typically invoices monthly for a consistent amount suddenly sending a second invoice mid-month, or one for a significantly higher amount, is worth a second look, even if every individual detail on the invoice looks correct.
5. Separate the people who approve invoices from the people who set up or amend supplier records. This is a basic segregation of duties control, but it’s frequently overlooked in smaller finance teams where the same person handles both. If one person can add a new “supplier” and approve payment to them, that’s a control gap.
6. Keep a single source of truth for what’s been paid. Duplicate payments often happen because an invoice exists in two places, such as a spreadsheet and an accounting system, or two different email inboxes, with no single record showing its true status. Every invoice needs one definitive status, visible to everyone involved in processing it.
7. Require documented approval before any invoice is paid, regardless of value. Low-value invoices are sometimes waved through without the same scrutiny as larger ones, on the assumption the risk is low. In practice, low-value fraudulent invoices are specifically designed to fly under the radar for exactly this reason.
8. Review your AP audit trail periodically, not just when something goes wrong. Most finance teams only dig into their audit trail retrospectively, after a problem is discovered. Periodic review, checking who approved what and whether the pattern looks normal, catches issues earlier.
Where Manual Processes Break Down
Every item on that checklist is good practice. The problem is that manual AP processes make consistent application of all eight genuinely difficult, especially at volume. Checking every invoice number against every previously processed invoice by hand doesn’t scale. Verifying bank detail changes independently is easy to skip when a payment run is due and everyone’s under time pressure. Segregation of duties is hard to enforce when a small team is stretched across multiple responsibilities out of necessity.
How PaperLess Closes the Gap
PaperLess addresses most of this checklist structurally, rather than relying on individual diligence every single time:
- Automatic duplicate detection checks every incoming invoice against previously processed invoices, by number, supplier, amount, and date, before it enters the approval workflow, catching duplicates a person would likely miss.
- 3-way matching happens automatically against PO and goods receipt data pulled directly from Sage, SAP Business One, Xero, or Orderwise, rather than requiring someone to manually pull three documents together.
- Approval workflows enforce segregation of duties by design. PaperLess can require that the person who processes an invoice isn’t the same person who approves it, without relying on anyone remembering the policy.
- Full audit trails record who did what and when, for every invoice, automatically, making periodic review something that takes minutes rather than a significant manual exercise.
The point isn’t that people become careless once PaperLess is in place. It’s that the controls stop depending entirely on individual vigilance under pressure, and start happening consistently, on every invoice, every time, across Sage 50, Sage 200, Sage Intacct, SAP Business One, Orderwise and Xero alike.
Don’t leave duplicate payments and invoice fraud to chance. Book a free PaperLess demo and see how automated checks close the gaps manual processes miss.