Accounts Payable Fraud & Payment Control Review in India: Duplicate Invoices, Vendor Master, Bank Changes, PO Matching & Approval Controls 2026
A CFO and audit-committee framework for protecting the payment cycle from duplicate invoices, fabricated vendors, bank-detail manipulation, approval bypass, split purchases and unsupported disbursements.
Accounts payable is one of the highest-volume financial-control environments in many companies. Weaknesses can generate both accidental leakage and deliberate fraud because vendor creation, invoice processing, approval and payment release often pass through different systems and teams.
A strong review therefore looks beyond whether an invoice exists. It asks whether the vendor is genuine, the goods or services were actually received, the price and quantity agree with the contract or purchase order, the approval is valid, the bank account is independently verified and the payment cannot be released by one individual acting alone.
1. Map the procure-to-pay lifecycle
Document requisition, vendor selection, purchase order, receipt of goods or services, invoice booking, approval, payment proposal, bank release, accounting and vendor reconciliation. Identify manual touchpoints, emergency routes, non-PO purchases and users with privileged master-data access.
For a wider procurement-integrity framework, see Vendor & Procurement Fraud Risk in India.
2. Vendor-master integrity
Review legal name, registration details, tax identifiers, addresses, contact details, authorised signatories, bank account, business owner, category, creation date and change history. Search for duplicate or near-duplicate vendors, shared bank accounts, repeated addresses, personal email domains, dormant vendors suddenly reactivated and vendors created immediately before large payments.
Where lawful and proportionate, compare vendor information with employee or promoter conflict declarations. A match is an exception to investigate, not automatic proof of collusion.
3. Bank-detail change controls
Bank changes should never rely only on the email or message requesting the change. Require independent verification through an established contact channel and retain a record of requester, verifier, approver, old account, new account and effective date.
High-risk patterns include bank changes shortly before payment, multiple vendors moved to the same account, changes initiated from a new email domain and requests to bypass the ordinary verification process.
4. Duplicate invoice testing
Exact duplicates are only the starting point. Test same vendor + invoice number, same amount + date, altered punctuation, leading zeros, repeated PDF, same invoice booked to different entities or branches, same amount paid twice after cancellation/re-entry and one invoice split across multiple vouchers.
System duplicate blocks should be tested for bypass through minor invoice-number changes.
5. PO, receipt and invoice matching
Where the business uses purchase orders and goods-receipt or service-entry records, test price, quantity, tax and description across the three records. Exceptions should require documented approval and evidence of actual receipt.
For services, the evidence may be milestone certification, timesheets, completion reports, campaign reports, transporter records, legal deliverables, maintenance logs or user acceptance. A signed invoice by itself does not prove performance.
6. Split purchases and threshold avoidance
Analyse multiple purchases from the same vendor on the same day or short period that individually fall below approval or competitive-bid thresholds. Review whether the split reflects genuine operational needs or a control bypass.
Repeated post-facto POs and emergency purchases by the same cost centre also deserve attention. Link these exceptions with the Delegation of Authority & Approval-Control Audit.
7. Payment proposal and bank release
Payment files should be generated from approved liabilities, independently reviewed and released through maker-checker controls. Test whether the bank release can be altered after approval, whether beneficiary changes are visible to approvers and whether payment files can be uploaded outside the approved workflow.
Privileged banking access, shared credentials, dormant tokens and excessive signing authority should be reviewed periodically.
8. Advance payments
Vendor advances create exposure because cash leaves before performance is complete. Maintain an ageing of advances, supporting contract or PO, performance security where applicable, expected adjustment date, business owner and recovery status.
Old advances should not remain indefinitely outside management visibility. Repeated advances to the same vendor without settlement should trigger review.
9. Payment analytics
- same bank account used by multiple vendors;
- duplicate or near-duplicate invoice numbers;
- payments just below approval limits;
- weekend or after-hours vendor changes;
- round-amount invoices with limited description;
- new vendor followed quickly by large payment;
- repeated emergency or non-PO purchases;
- high-value manual payment vouchers;
- credit balances or duplicate recoveries not adjusted; and
- concentration of exceptions around one user or approver.
10. Accounts payable risk matrix
| Risk | Indicator | Response |
|---|---|---|
| Vendor identity | Opaque ownership or duplicate bank/address | Enhanced KYC and conflict review |
| Invoice | Duplicate, unsupported or mismatched invoice | Hold, validate receipt and investigate root cause |
| Approval | Split purchase or post-facto approval | Threshold analytics and escalation |
| Payment | Unverified bank change or single-user release | Independent verification and maker-checker |
11. Evidence and documents
Vendor master, onboarding files, bank-change logs, conflict declarations, purchase requisitions, bids, POs, GRNs, service entries, invoices, approval workflows, payment proposals, bank statements, user-access reports, ERP audit logs, advances ageing and vendor reconciliations form the core evidence set.
12. CFO and board deliverables
- vendor-master exception report;
- duplicate invoice recovery schedule;
- bank-change control report;
- split-purchase and threshold analysis;
- PO/receipt/invoice mismatch report;
- advance ageing and recovery plan;
- payment-access conflict matrix;
- estimated financial exposure; and
- 30/60/90-day remediation tracker.
13. 30/60/90-day remediation
0–30 days: lock high-risk vendor edits, verify bank-change process, recover obvious duplicates, review privileged payment access and clear unsupported urgent payments.
31–60 days: clean vendor master, automate duplicate checks, strengthen PO matching, introduce threshold analytics and age vendor advances.
61–90 days: implement recurring vendor recertification, dashboard exceptions, quarterly access review and independent closure testing.
14. Frequently asked questions
Does a duplicate invoice always mean fraud?
No. Duplicates can arise from processing error, cancellation/re-entry or system migration. The payment history and supporting evidence must be checked.
Should vendor bank changes require phone verification?
Independent confirmation through a trusted existing channel is a strong control. The precise procedure should fit transaction risk and internal policy.
Can data analytics replace invoice review?
No. Analytics prioritise exceptions; documents and business evidence establish what actually occurred.
Who should own vendor-master changes?
Ownership varies, but creation, approval and payment release should be segregated or supported by strong compensating controls.
Authoritative references
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.