top of page

AI in duplicate and fraudulent payment detection for small firms

  • 6 days ago
  • 3 min read

Updated: 4 days ago

Introduction


The standard defence against payment fraud is segregation of duties: the person who sets up a supplier is not the person who approves the payment, and neither is the person who reconciles the bank. In a business with three administrative staff this is not available, and the controls that large organisations rely on simply do not exist.

Detection is therefore a substitute for prevention rather than a supplement to it, which makes it more important rather than less. The characteristic losses in small businesses are mundane: the same invoice paid twice, a supplier bank change that was a fraudulent email, a subscription nobody uses, a payment to a supplier that no longer exists. All are detectable by comparison against your own history.


1. AI in duplicate and fraudulent payment detection compensates for missing segregation


Understand the role.

Where you cannot separate the duties, automated checks across every payment provide a form of independent review. It is not equivalent, and it is considerably better than nothing.


2. Detect duplicates on amount and date, not reference


Reference matching misses most of them.

The same charge arriving as an invoice and then on a statement, or reissued with a new number. Matching on supplier, amount and date proximity catches what a reference check does not.


3. Verify every bank detail change independently


The single most important control.

A request to change supplier bank details, however plausible the email, is verified by telephoning a known number for that supplier. Not the number in the email. This one rule prevents the most common serious loss.


4. Flag payments to new payees


Where the losses concentrate.

Any first payment to a new bank account should be reviewed by someone other than whoever set it up, and ideally confirmed with the supplier. New payees are where the fraudulent ones necessarily appear.


5. Review every recurring payment annually


The quiet leak.

Subscriptions, licences, insurance, standing orders and direct debits. Businesses routinely pay for services they stopped using years ago, and this is a genuinely productive hour once a year.


6. Look for the patterns that indicate a problem


Where analysis adds value.

Round-sum amounts, payments just below an approval threshold, a supplier whose invoices always arrive as images, addresses matching an employee address, or invoice sequences that do not fit a real business.


7. Treat urgency as a warning sign


The behavioural pattern in almost every fraud.

Pressure to pay immediately, a request from a senior person outside normal channels, secrecy, and an excuse for why the usual process cannot be followed. A rule that urgency never bypasses verification is worth more than any system.


8. Reconcile weekly so anomalies surface quickly


Time is the enemy.

A fraudulent payment identified within days can sometimes be recovered. One found at the next quarterly reconciliation cannot. This is the practical argument for frequent reconciliation.


9. Handle any suspicion formally


Not as a conversation.

Data can indicate where a loss occurred; it does not establish who was responsible. Reporting obligations, investigation procedures and employment law considerations apply, they vary by jurisdiction, and taking advice before acting matters.

Be careful about relying on a system as a substitute for basic authorisation limits. Written approval thresholds, dual authorisation on large payments and a payment run reviewed by a director are cheap, and detection works better on top of them than instead of them.


Conclusion


Use automated checking to compensate for the segregation of duties you cannot achieve.

Match potential duplicates on supplier, amount and date rather than reference, verify every bank detail change by telephoning a known number, review the first payment to any new payee independently, audit all recurring payments annually, look for round sums, sub-threshold amounts and address matches, treat urgency and secrecy as warnings that verification is being bypassed, reconcile weekly so anomalies are still recoverable, and handle any suspicion as a formal process with advice.


Related reading


 
 
 

Comments


bottom of page