Corporate Risk Mitigation • Accounts Payable • India • 2026

Accounts Payable Fraud & Payment Control Review in India: Duplicate Invoices, Vendor Master, Bank Changes, PO Matching & Approval Controls 2026

A CFO and audit-committee framework for protecting the payment cycle from duplicate invoices, fabricated vendors, bank-detail manipulation, approval bypass, split purchases and unsupported disbursements.

Vendor MasterIdentity, ownership, bank, KYC and change logs
Invoice ControlsDuplicate checks, PO/GRN match and evidence
PaymentsMaker-checker, bank files, release rights and reconciliation
AnalyticsSplit POs, round amounts, repeat accounts and overrides

Accounts payable is one of the highest-volume financial-control environments in many companies. Weaknesses can generate both accidental leakage and deliberate fraud because vendor creation, invoice processing, approval and payment release often pass through different systems and teams.

A strong review therefore looks beyond whether an invoice exists. It asks whether the vendor is genuine, the goods or services were actually received, the price and quantity agree with the contract or purchase order, the approval is valid, the bank account is independently verified and the payment cannot be released by one individual acting alone.

Corporate standard: exceptions should be classified as process error, control gap, policy deviation, suspicious pattern or substantiated misconduct. Data anomalies are leads for verification, not findings of guilt.

1. Map the procure-to-pay lifecycle

Document requisition, vendor selection, purchase order, receipt of goods or services, invoice booking, approval, payment proposal, bank release, accounting and vendor reconciliation. Identify manual touchpoints, emergency routes, non-PO purchases and users with privileged master-data access.

For a wider procurement-integrity framework, see Vendor & Procurement Fraud Risk in India.

2. Vendor-master integrity

Review legal name, registration details, tax identifiers, addresses, contact details, authorised signatories, bank account, business owner, category, creation date and change history. Search for duplicate or near-duplicate vendors, shared bank accounts, repeated addresses, personal email domains, dormant vendors suddenly reactivated and vendors created immediately before large payments.

Where lawful and proportionate, compare vendor information with employee or promoter conflict declarations. A match is an exception to investigate, not automatic proof of collusion.

3. Bank-detail change controls

Bank changes should never rely only on the email or message requesting the change. Require independent verification through an established contact channel and retain a record of requester, verifier, approver, old account, new account and effective date.

High-risk patterns include bank changes shortly before payment, multiple vendors moved to the same account, changes initiated from a new email domain and requests to bypass the ordinary verification process.

4. Duplicate invoice testing

Exact duplicates are only the starting point. Test same vendor + invoice number, same amount + date, altered punctuation, leading zeros, repeated PDF, same invoice booked to different entities or branches, same amount paid twice after cancellation/re-entry and one invoice split across multiple vouchers.

System duplicate blocks should be tested for bypass through minor invoice-number changes.

5. PO, receipt and invoice matching

Where the business uses purchase orders and goods-receipt or service-entry records, test price, quantity, tax and description across the three records. Exceptions should require documented approval and evidence of actual receipt.

For services, the evidence may be milestone certification, timesheets, completion reports, campaign reports, transporter records, legal deliverables, maintenance logs or user acceptance. A signed invoice by itself does not prove performance.

6. Split purchases and threshold avoidance

Analyse multiple purchases from the same vendor on the same day or short period that individually fall below approval or competitive-bid thresholds. Review whether the split reflects genuine operational needs or a control bypass.

Repeated post-facto POs and emergency purchases by the same cost centre also deserve attention. Link these exceptions with the Delegation of Authority & Approval-Control Audit.

7. Payment proposal and bank release

Payment files should be generated from approved liabilities, independently reviewed and released through maker-checker controls. Test whether the bank release can be altered after approval, whether beneficiary changes are visible to approvers and whether payment files can be uploaded outside the approved workflow.

Privileged banking access, shared credentials, dormant tokens and excessive signing authority should be reviewed periodically.

8. Advance payments

Vendor advances create exposure because cash leaves before performance is complete. Maintain an ageing of advances, supporting contract or PO, performance security where applicable, expected adjustment date, business owner and recovery status.

Old advances should not remain indefinitely outside management visibility. Repeated advances to the same vendor without settlement should trigger review.

9. Payment analytics

  • same bank account used by multiple vendors;
  • duplicate or near-duplicate invoice numbers;
  • payments just below approval limits;
  • weekend or after-hours vendor changes;
  • round-amount invoices with limited description;
  • new vendor followed quickly by large payment;
  • repeated emergency or non-PO purchases;
  • high-value manual payment vouchers;
  • credit balances or duplicate recoveries not adjusted; and
  • concentration of exceptions around one user or approver.

10. Accounts payable risk matrix

Risk Indicator Response
Vendor identity Opaque ownership or duplicate bank/address Enhanced KYC and conflict review
Invoice Duplicate, unsupported or mismatched invoice Hold, validate receipt and investigate root cause
Approval Split purchase or post-facto approval Threshold analytics and escalation
Payment Unverified bank change or single-user release Independent verification and maker-checker

11. Evidence and documents

Vendor master, onboarding files, bank-change logs, conflict declarations, purchase requisitions, bids, POs, GRNs, service entries, invoices, approval workflows, payment proposals, bank statements, user-access reports, ERP audit logs, advances ageing and vendor reconciliations form the core evidence set.

12. CFO and board deliverables

  • vendor-master exception report;
  • duplicate invoice recovery schedule;
  • bank-change control report;
  • split-purchase and threshold analysis;
  • PO/receipt/invoice mismatch report;
  • advance ageing and recovery plan;
  • payment-access conflict matrix;
  • estimated financial exposure; and
  • 30/60/90-day remediation tracker.

13. 30/60/90-day remediation

0–30 days: lock high-risk vendor edits, verify bank-change process, recover obvious duplicates, review privileged payment access and clear unsupported urgent payments.

31–60 days: clean vendor master, automate duplicate checks, strengthen PO matching, introduce threshold analytics and age vendor advances.

61–90 days: implement recurring vendor recertification, dashboard exceptions, quarterly access review and independent closure testing.

14. Frequently asked questions

Does a duplicate invoice always mean fraud?

No. Duplicates can arise from processing error, cancellation/re-entry or system migration. The payment history and supporting evidence must be checked.

Should vendor bank changes require phone verification?

Independent confirmation through a trusted existing channel is a strong control. The precise procedure should fit transaction risk and internal policy.

Can data analytics replace invoice review?

No. Analytics prioritise exceptions; documents and business evidence establish what actually occurred.

Who should own vendor-master changes?

Ownership varies, but creation, approval and payment release should be segregated or supported by strong compensating controls.

Authoritative references

Firm & Correspondence Information
Fastrack Legal Solutions LLP
Office: B1/32 Basement, Malviya Nagar, New Delhi – 110017
Telephone: +91 76976 71219
Email: advgovind@fastracklegalsolutions.com
Contact / Information Form: Submit Information / Documents
The particulars and form link above are provided solely for identification, correspondence and voluntary transmission of information. They do not constitute an advertisement, solicitation, invitation or inducement to engage legal services. Submission of the form does not by itself create an advocate-client relationship.
General corporate-risk information only. Accounting, tax, employment and legal consequences depend on the facts and applicable framework.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *