The £270,000 Warning Hidden In Supplier Verification

Warning

Invoice fraud is revealing a costly weakness in the link between supplier onboarding and payment approval. Ivalua research found that 40% of organizations experienced invoice fraud in the past year, with losses averaging £270,000 among those that lost money, putting greater scrutiny on how supplier identities and payment changes are verified before funds are released.

The scale of the losses suggests that invoice controls can fail even when established approval processes appear to be working. Almost a third of affected organizations, 29%, reported losses of at least £368,000, according to Ivalua.

The vulnerability often sits earlier in the process than invoice approval itself. Fraudulent changes to supplier bank details were the leading concern among victims, cited by 41%, while duplicate invoicing and compromised supplier email accounts were each cited by 39%.

That makes the integrity of supplier records increasingly important. A fraudulent vendor or altered payment instruction that enters the approved supplier environment can pass through subsequent controls because the transaction appears legitimate.

Nine-Day Detection Gap Raises the Cost

Ivalua found that organizations take an average of nine days to identify invoice fraud. Only 27% detect it on the day it occurs, while one in five require two weeks or longer.

That lag changes the economics of fraud prevention. Controls designed primarily to identify unusual payments after processing may provide visibility without giving companies enough time to prevent the loss.

Supplier verification remains uneven. Ivalua found that only 25% of organizations conduct mostly automated supplier checks using a standardized workflow and audit trail. Another 19% continue to vet new suppliers manually through emails, documents and spreadsheets, while 6% either lack a consistent verification process or cannot verify suppliers.

Manual processes can be particularly exposed when legitimate supplier information changes. Bank-account amendments, new payment instructions and changes in supplier contacts create points where procurement and accounts payable teams need to distinguish genuine updates from impersonation.

AI adds another dimension because convincing emails, documents and supplier communications can be produced with less effort. Stephen Carter, payments expert at Ivalua, said fraudsters can exploit weaknesses in supplier records rather than having to penetrate corporate systems directly.

The control response therefore extends beyond invoice matching. Verified supplier identities, controlled master-data changes, independent validation of sensitive amendments and auditable approval histories can determine whether a fraudulent instruction reaches the payment stage.

Faster Payments Put More Pressure on Verification

The regulatory environment is adding another reason to examine those controls. The UK’s failure to prevent fraud offence took effect on September 1, 2025. It applies to large organizations where an associated person commits certain fraud offences intending to benefit the organization or, in some circumstances, its clients, unless reasonable prevention procedures were in place.

Separately, the Commercial Payments Bill would impose maximum business-to-business payment terms of 60 days, subject to limited exemptions, as the government seeks to improve cash flow through supply chains.

The two developments create an important control consideration. Companies face pressure to pay legitimate suppliers promptly while ensuring that faster processing does not weaken the checks applied to supplier identities, account changes and payment instructions.

That places more value on verification before an invoice enters the final payment workflow. Adding reviews near the end of the process can slow legitimate payments without addressing weaknesses in the underlying supplier record.

Supplier Data Becomes the First Control

The next stage of fraud prevention may increasingly be built into transaction infrastructure itself. The UK government plans to mandate electronic invoicing for all VAT invoices from April 2029 and has said secure digital systems could reduce interception risks. It is also considering digital company identities to strengthen verification.

That direction matters for procurement because automation alone does not establish that supplier data is trustworthy. As payment cycles become more digital and potentially faster, the quality of the verified supplier record will determine how much confidence organizations can place in automated approvals. The strongest control may therefore be the one applied before an invoice ever reaches accounts payable.

Blueprints

Subscribe to Newsletter

Secret Link