Would Your AP Get Scammed?
5 questions. Takes 2 minutes. Tells you how exposed your AP process is to invoice fraud — the kind that costs US businesses $2.9 billion a year. Answer honestly; the score is for you, not me.
Business Email Compromise (BEC) fraud — where a scammer impersonates a vendor and requests a bank account change before a large payment — is the number-one financial fraud vector for businesses under $100M. The attacks are simple. The controls that stop them are also simple. Most AP processes just don't have them.
This isn't a formal audit. It's five practical questions drawn from the same control framework I use when I build or evaluate AP automation. If you're honest with your answers, you'll know in two minutes where your real exposure is.
Note: Results are based on your self-reported answers. They are directionally useful — not a formal risk assessment, not a regulatory opinion. If your result concerns you, take it to your auditor or your AP controls team as a starting point for a real conversation.
When a vendor requests a bank account change, what does your process require before the new account is entered?
How are large payments (above your threshold) authorized in your AP process?
A vendor you paid last quarter sends an invoice from a slightly different email address than usual. What does your process require?
Who can modify your vendor master record — the file that holds vendor bank accounts and contact information?
If AI or automation is part of your AP process, which best describes how payments are authorized?
What do the results actually mean?
Is this test comprehensive enough to replace a real AP audit?
No — and it doesn't claim to be. Five questions can't replace a full controls review. What this does is surface the highest-probability failure modes in AP fraud exposure: bank-change verification, dual approval, vendor master access, and what happens when AI is in the loop. If you fail two or more of these, a real audit is going to find problems. Start here, take it to your auditor.
We're a small team. Are controls like this really practical for us?
Yes — and small teams are actually more exposed, not less. Larger firms have IT controls and periodic audits enforcing these things. Small teams rely on trust and familiarity, which works fine until someone spoofs a familiar vendor. Dual approval and out-of-band verification aren't enterprise controls — they're two-person habits that take about 10 minutes to establish.
We've never been defrauded. Does that mean our controls are fine?
Not necessarily. BEC fraud is opportunistic — you haven't been targeted yet, or you've been targeted and the attacker decided someone else was easier. Controls matter most before the fraud attempt, because the window to catch it after the payment clears is very short. "We've never had a problem" is not a control.
What does AI have to do with AP fraud?
Two things. First, AI that processes AP invoices without the right controls is a new attack surface — if the AI can approve and release a payment without a human check, a fraudulent invoice doesn't need to fool a human, just the model. Second, AI with the right controls — including a rule that says "bank-account-change requests always stop for a human" — can actually catch fraud faster and more consistently than a manual process. The proof page shows a live example of this.
Want to see what a protected AP process actually looks like?
I'll show you a live demo of an AI catching a fake bank-change invoice before it routes for payment — and walk through exactly how the controls work. Takes 30 minutes. Free intro call, no obligation.
Book a free intro call