Most procurement fraud is not dramatic. It is a supplier that does not quite exist, an invoice slightly higher than it should be, or a bank account that changed by email.
It is also slow. The Association of Certified Fraud Examiners studied 1,921 real cases across 138 countries, with losses over $3.1 billion. The typical fraud ran for a full year before anyone caught it.
That is the single most useful fact in this article. You are not going to prevent every attempt. Detection speed is what decides the cost.
What it costs
The ACFE's headline figures: a median loss of $145,000 per case, an average of $1.7 million, and an estimate from fraud examiners that organisations lose around 5% of revenue to fraud each year.
Broken down by type, the pattern is worth understanding because it runs opposite to intuition.
| Category | Share of cases | Median loss |
|---|---|---|
| Asset misappropriation (stealing or misusing assets) | 89% | $120,000 |
| Corruption (kickbacks, bid rigging, conflicts of interest) | 48% | $200,000 |
| Financial statement fraud | 5% | $766,000 |
The most common category is the least costly per case, and the rarest is the most expensive. Procurement sits mainly in the first two rows.
The schemes that target procurement
Billing schemes
Someone causes the organisation to pay for goods or services it did not receive, or overpays deliberately. In practice: a supplier that exists only on paper, an inflated invoice, or a personal purchase run through a company account.
This is the scheme most tied to procurement, and it takes a median of 18 months to detect.
It is also more common at smaller organisations. In the ACFE's data, billing schemes appeared in 31% of cases at organisations with fewer than 100 employees, against 22% at those with 100 or more.
Payment tampering
Altering or redirecting payments. The gap by company size here is the widest in the whole study: 23% of cases at organisations under 100 employees, against 9% at larger ones.
The reason is not that small companies employ worse people. It is that small teams cannot separate duties as easily, so one person often raises, approves and pays.
Corruption: kickbacks and bid rigging
A buyer steers work to a supplier in exchange for something. Bids are shared, specifications are written around one supplier, or a tender is run as theatre with the winner already chosen.
Corruption featured in 48% of all cases, with a median loss of $200,000. It is harder to spot than a false invoice because every individual document looks legitimate.
Bank detail fraud, from outside
This one is not an employee at all. Someone impersonates a supplier and asks you to update the bank details. The next genuine invoice is paid to a criminal.
Business email compromise was only the seventh most reported crime type by volume, but second by money lost. These are not scattergun scams. They target the person who can change a payment.
How fraud actually gets found
Not by auditors, mostly. By people telling someone.
| How it was first detected | Share of cases |
|---|---|
| A tip | 43% |
| Internal audit | 14% |
| Management review | 13% |
| Document examination | 6% |
| Account reconciliation | 5% |
| By accident | 5% |
| External audit | 3% |
Tips found more than three times as many cases as the next method. And where tips came from matters for procurement: 52% came from employees, 21% from customers and 11% from vendors.
Roughly a third of tips came from outside the organisation. Your suppliers often know before you do — which is an argument for giving them somewhere to report concerns.
Why it happens
The ACFE attributes more than half of cases to two causes: a lack of internal controls (32%) and the override of existing controls (19%).
Both are design problems rather than people problems. The second one matters especially in smaller companies, where a senior person can wave something through and nobody questions it.
Seniority also changes the scale. Frauds by employees ran a median of 8 months before detection. Those by owners and executives ran 24 months.
The controls that work
The ACFE compared organisations that had each of 18 anti-fraud controls against those that did not. Every single control was associated with both lower losses and faster detection.
Four stood out, each associated with at least a 50% reduction in both loss and duration: surprise audits, financial statement audits, reporting hotlines, and proactive data analysis.
Two of those four — surprise audits and proactive data analysis — were among the least commonly implemented. That is where the easy gains sit.
Separate the four roles
The person who requests a purchase, the person who approves it, the person who sets up the supplier, and the person who releases payment should not all be the same person. If you can only split some of these, split supplier setup and payment release first. Those two together are what make a fake supplier possible.
Control the supplier master
New suppliers should be created by someone who cannot also pay them, using evidence rather than an email. Duplicated supplier records make this much harder, which is one more reason a clean supplier master is a control and not just tidiness.
Verify bank changes out of band
Never change bank details from an emailed request alone. Call the supplier on the number you already hold — not the one in the email — and confirm with someone you have spoken to before. Log who verified it and when.
This single rule prevents most of the $2.77 billion category above.
Match three documents, not two
The purchase order, the goods receipt and the invoice should agree before payment. Two out of three is how paid-for-but-never-delivered works.
Run the boring data checks
- Supplier bank accounts or addresses matching employee records.
- Suppliers with sequential invoice numbers to you and nobody else.
- Round-number invoices that sit just under an approval threshold.
- Duplicate invoice numbers, or the same amount to the same supplier twice in a month.
- Suppliers created and paid within a very short window.
- Payments to accounts changed in the last 30 days.
None of this needs specialist software. It is a handful of queries run monthly, and it is what the ACFE calls proactive data analysis — one of the four highest-impact controls.
Give people a way to report
Given that 43% of cases are found by tips, a reporting route is not a formality. It should be available to suppliers as well as staff, and it should allow anonymity — 15% of tips were anonymous.
If you are too small to separate duties
Many mid-sized companies genuinely cannot split four roles across two people. The answer is compensating controls rather than pretending.
- Have someone outside the process — a director, the owner, an external accountant — review the new supplier list monthly. It takes ten minutes.
- Require two people to release any payment above a threshold you set deliberately.
- Run the data checks above monthly and keep the evidence that you ran them.
- Use surprise checks rather than a predictable annual audit. Unpredictability is the point.
- Make bank-detail changes a two-person job, always.
Outsourcing the transactional work can also help here, because it naturally separates who processes from who approves. That is a side effect worth having, not a reason on its own.
Where to start this month
Pull a list of every supplier created in the last twelve months and every bank detail changed in that period. Check each against evidence. Then set the rule that neither can happen again without a second person.
That exercise usually finds something — most often a dormant duplicate rather than a fraud. Either way, you end it with a control you did not have before.
Common questions
What is procurement fraud?
Fraud that targets buying and paying: fake or non-existent suppliers, inflated or duplicate invoices, payments redirected to the wrong account, kickbacks for steering work to a supplier, and personal purchases put through company accounts. It sits mainly in two of the ACFE's categories — asset misappropriation, found in 89% of cases with a median loss of $120,000, and corruption, found in 48% of cases with a median loss of $200,000.
How long does procurement fraud usually go undetected?
The ACFE's 2024 study of 1,921 cases found a median duration of 12 months across all occupational fraud. Billing schemes and payment tampering specifically ran a median of 18 months. Duration drives cost: frauds caught within six months had a median loss of $30,000, against $250,000 for those running two to three years and $875,000 beyond five years.
How is fraud usually discovered?
By someone telling. Tips accounted for 43% of cases — more than three times the next method, internal audit at 14%, followed by management review at 13% and external audit at just 3%. Of those tips, 52% came from employees, 21% from customers and 11% from vendors, so roughly a third came from outside the organisation.
Are smaller companies more exposed to procurement fraud?
To certain schemes, yes. The ACFE found billing schemes in 31% of cases at organisations with fewer than 100 employees against 22% at larger ones, and payment tampering in 23% against 9% — the widest gap in the study. The cause is structural: smaller teams cannot separate duties as easily, so one person often requests, approves and pays.
What controls reduce fraud losses most?
The ACFE tested 18 anti-fraud controls and every one was associated with both lower losses and faster detection. Four were associated with at least a 50% reduction in both: surprise audits, financial statement audits, reporting hotlines, and proactive data analysis. Notably, surprise audits and proactive data analysis were among the least commonly implemented, so they offer the easiest gains.
How do we prevent supplier bank detail fraud?
Never act on an emailed request alone. Call the supplier on a number you already hold — not one supplied in the email — speak to someone you have dealt with before, and record who verified it and when. Make bank-detail changes a two-person job without exception. The FBI recorded $2.77 billion of business email compromise losses in 2024 across 21,442 complaints.
What is a three-way match and why does it matter?
It means the purchase order, the goods receipt and the invoice must agree before payment is released. Matching only two of the three is how organisations end up paying for goods that were never delivered, because nothing independently confirms that anything arrived.
Why do frauds happen even in companies with controls?
The ACFE attributes more than half of cases to two causes: a lack of internal controls (32%) and the override of existing controls (19%). Override matters most in smaller organisations, where a senior person can push something through unchallenged. Seniority also affects duration — frauds by employees ran a median of 8 months, those by owners and executives 24 months.
What can a small team do if it cannot separate duties?
Use compensating controls. Have someone outside the process review new suppliers monthly, require two people for payments above a set threshold, run monthly data checks and keep evidence that you ran them, use surprise rather than predictable checks, and always require two people for bank-detail changes. If you can only separate two duties, separate supplier setup from payment release.
What data checks find procurement fraud?
Simple queries run monthly: supplier bank accounts or addresses matching employee records; suppliers whose invoice numbers to you run sequentially; round-number invoices just below an approval threshold; duplicate invoice numbers or repeated identical amounts; suppliers created and paid within a very short window; and payments to accounts changed in the last 30 days. This is what the ACFE calls proactive data analysis, one of the four highest-impact controls.
Sources
- Association of Certified Fraud Examiners, Occupational Fraud 2024: A Report to the Nations, 106-page report read directly. 1,921 cases, 138 countries, $3.1bn+ losses; median loss $145,000, average $1.7m. Categories Figure 2 p.10; duration Figure 7 p.15 and scheme duration Figure 8 p.16; detection Figures 13–14 p.24; size comparison Figure 24 p.34; controls and control weaknesses p.39; perpetrator seniority p.52.
- FBI Internet Crime Complaint Center, 2024 Internet Crime Report, 47-page report read directly. Business email compromise $2,770,151,146 across 21,442 complaints (crime types by loss, p.10); total 859,532 complaints and $16.6bn losses, up 33% on 2023 (p.5).
Want this run for you?
We take on the transactional half of procurement — invoices, purchase orders, supplier data and indirect spend — inside your own systems and under your approval rules. Start with a free spend audit: we measure your volumes, cycle times and exception rates, and the report is yours whether or not you go further.
Book a free spend audit


