I keep coming back to a story from my PwC days about a fraudster who sent Google a stream of modest, recurring invoices. Nothing dramatic. Just small enough, over and over, that they got waved through as rounding error. It worked for a long time before anyone caught it.
That story is old. The fraud isn’t. What’s changed is how easy it now is to run that same play, and how much harder it is to spot while it’s happening.
The Old Tells Don’t Work Anymore
For years, you could catch a phishing attempt because it looked cheap. Bad grammar, a slightly off tone, a request that didn’t quite match how your CEO actually writes. AI took that away. It’s relatively easy now to spin up a near-exact clone of a company website in under an hour. Someone sends you a link in an email that matches the real formatting almost perfectly, the link looks legitimate, and it lands you on a page that’s a one-for-one copy of the real thing, just quietly collecting whatever you type in. And if someone has a public LinkedIn profile, which is basically everyone, an attacker can time a request to land right in the middle of month-end close, when you’re least likely to slow down and double-check.
Layer on deepfake voice and video, plus AI-generated synthetic identities, including passable fake ID photos from open-source tools, and you get a threat that doesn’t look or sound fake at all. That’s the shift. Not new fraud. Just fraud with the seams sanded off.
Automation Cuts Both Ways
Here’s the part that should get your attention if you’ve automated any of your AP or AR process, and a lot of finance teams have, because it’s genuinely one of the better ROI use cases for AI. If your system is just checking whether fields match, whether a vendor name, invoice number, and amount line up, it will treat a well-crafted fake exactly the way it treats a legitimate request. Automation isn’t a judgment call. It’s a matching exercise. AI-generated fraud is specifically built to pass that match.
That doesn’t mean don’t automate. It means the controls sitting around the automation matter more than ever, not less.
Three Controls, No New Software
None of what actually works here requires a new tool. It requires deciding these are must-do items instead of nice-to-haves.
- Clean up the vendor master file. A lot of companies are worse at this than they think. Keep the list small and current, flag anything new automatically, and flag anything coming from an email address you don’t recognize.
- Verify out of band. If a payment instruction changes, a new bank account, a new contact, confirm it through a channel other than the one the request came in on. Call a number you already had on file. Not one in the email.
- Require two people in the money-movement step. The person requesting a payment should never be the same person releasing it. This is the one control that doesn’t depend on anyone spotting anything.
If you don’t already have a solid vendor master file, the fastest way to build one is to start with finance. They’re already tracking journal entries for every recurring vendor and subscription, so they usually have a decent list of companies even if nobody’s formalized it. From there you can work with AP and AR to fill in the actual contacts and start layering on the verification steps.
The Part That’s Easy to Miss
AI doesn’t just make individual attempts more convincing. It removes the effort barrier that used to protect smaller companies. If you weren’t a big enough target to be worth a fraudster’s time, that math has changed. Running the same convincing attempt against a hundred companies instead of ten costs almost nothing extra now. Scale is the part of this story that doesn’t get enough attention.
None of this changes what your actual job is in a fraud situation. Detection tools, automated matching, AI-assisted review, all of it can help you find a problem faster. None of it makes the decision for you once you’ve found one. That’s still a judgment call, and it’s still yours. If anything, the more automated the front end of AP and AR gets, the more that judgment matters at the points where a human is actually looking.
Key Takeaways
- Grammar and tone are no longer reliable ways to catch a fake.
- Automated AP/AR matching checks whether fields line up, not whether a request is legitimate.
- Vendor master file hygiene is your cheapest and fastest defense.
- Out-of-band verification defeats a convincing email or voice the same way.
- Two people in the money-movement step, every time, no exceptions.
Want the CPE credit? Take the full lesson on EverydayCPE and earn 0.2 CPE credits: AI-Fueled AP/AR Fraud


Leave a Reply