Fraud Hides in the Procure-to-Pay Data: How AI Can Help Find It
- John C. Blackshire, Jr.

- Aug 22
- 8 min read
Detecting Fraud Using AI in Procure to Pay — September 18 and November 13, 2026
Procure-to-pay is one of the most attractive business processes for fraud, waste, errors and financial leakage.
Why?
Because it combines vendors, employees, purchase orders, receiving records, invoices, approvals, bank information and payments—often across multiple systems and thousands or millions of transactions.
Traditional auditing frequently examines only a fraction of that activity.
Artificial intelligence and advanced analytics create a different possibility:
Instead of asking whether the auditor's sample contains a suspicious transaction, ask which transactions in the entire population look suspicious.
Corporate Compliance Seminars' Detecting Fraud Using AI in Procure to Pay examines how auditors, finance professionals and procurement organizations can use AI and algorithms to identify anomalies and potential fraud throughout the P2P process. The program specifically addresses vendor-master data, purchase orders, receiving reports, invoices, Soundex techniques and practical fraud-detection applications.
CCS offers two upcoming sessions:
Friday, September 18, 2026
Friday, November 13, 2026
The Traditional Audit Problem: We Are Looking at Too Few Transactions
Suppose an organization processes 750,000 invoices annually.
The Internal Auditor selects 60 invoices.
All 60 look fine.
What have we established?
We have evidence about the transactions tested.
But fraudsters generally aren't considerate enough to make sure their fraudulent transaction lands in the auditor's sample.
That is where data analytics and AI can fundamentally change the audit approach.
Instead of beginning with:
“Which transactions should I sample?”
the auditor can increasingly begin with:
“Which transactions have characteristics that make them different from the rest of the population?”
The sample can then become risk-directed rather than merely random.
Start With the Vendor Master File
One of the best places to look for procure-to-pay fraud is before examining a single invoice.
Look at the vendor master.
CCS specifically includes vendor-master-file administration in the AI section of the program.
An auditor can search for relationships such as:
Vendor address = Employee address
Vendor telephone number = Employee telephone number
Vendor bank account = Another vendor's bank account
Vendor address = Another vendor's address
Vendor tax ID = Another vendor's tax ID
Vendor created shortly before first payment
Dormant vendor suddenly reactivated
Vendor information changed immediately before payment
Each relationship doesn't prove fraud.
It identifies a transaction or relationship deserving another question.
That distinction is fundamental:
AI identifies anomalies. Auditors investigate them.
Look for Vendors That Are Almost the Same
Fraud does not always involve an obviously fictitious vendor.
Sometimes the fraudster creates a vendor that looks remarkably similar to a legitimate vendor.
Suppose the legitimate vendor is: ABC Industrial Supply, Inc.
Another vendor appears as: ABC Industrial Supplies LLC
A conventional exact-match search might not identify the relationship.
CCS therefore specifically includes the Soundex algorithm in its fraud-detection curriculum.
Phonetic and fuzzy-matching techniques can help identify vendor names that sound or appear similar even though they are not identical.
This can help auditors search for:
Duplicate vendors
Slightly altered vendor names
Misspellings
Alternate abbreviations
Related vendor records
The objective isn't to conclude:
“Fraud!”
It is to conclude:
“These records are similar enough that we should determine why.”
Purchase Orders Contain Fraud Indicators Too
The CCS program also specifically examines purchase-order algorithms.
Consider the data available in purchase orders.
Auditors might analyze:
PO Amount
Requestor
Approver
Vendor
Date
Time
Commodity
Location
Approval Limit
Now patterns become visible.
Suppose a manager can approve purchases up to $10,000.
The data contains repeated purchases for:
$9,850
$9,900
$9,975
$9,995
Is that fraud?
Not necessarily.
Is it interesting?
Absolutely.
AI and analytics can identify transactions clustering immediately below approval thresholds.
The auditor can then investigate whether legitimate business transactions are being split to circumvent approval controls.
Receiving Reports Provide Another Data Layer
A three-way-match process normally connects:
Purchase Order
Receiving Evidence
Vendor Invoice
The CCS curriculum includes algorithms involving receiving reports as another source of fraud-detection information.
That creates useful analytical questions.
Were goods received before the invoice?
Was the receiving record created after payment?
Does one employee repeatedly create unusual receiving records?
Are there invoices without corresponding receiving information?
Do quantities consistently differ?
Are receiving documents being created unusually quickly after purchase orders?
Are transactions concentrated near period-end?
The auditor is no longer looking at documents independently.
AI can help examine the relationships among the documents.
Invoice Analytics Can Find What Sampling Misses
Invoice data is particularly rich.
The CCS program specifically includes invoice algorithms in its P2P fraud-detection methodology.
Potential analyses include:
Exact duplicate invoice numbers
Similar invoice numbers
Same vendor + same amount + different invoice number
Same amount + same date + different vendor
Round-dollar invoices
Invoices immediately below approval thresholds
Weekend invoices
Unusual period-end activity
Unexpected increases in vendor activity
Duplicate payments
Unusual invoice frequency
Once again, these are indicators, not conclusions.
That is where the auditor's judgment enters the process.
Benford's Law Can Be Another Tool
Depending upon the population, auditors can also consider statistical approaches such as Benford's Law.
Benford analysis evaluates whether the leading digits in naturally occurring numerical populations appear in expected proportions.
A deviation doesn't establish fraud.
But under appropriate circumstances it can help identify unusual populations requiring further investigation.
That illustrates a broader principle for AI-enabled auditing:
Don't ask one algorithm to identify fraud. Use multiple analytical techniques to identify transactions that deserve investigation.
Think in Terms of Fraud Scores
A more sophisticated approach combines multiple red flags.
Imagine assigning indicators to a transaction:
Vendor created within previous 30 days: +2
Invoice just below approval threshold: +2
Weekend transaction: +1
Round-dollar amount: +1
New vendor bank account: +3
PO created after invoice: +2
Employee/vendor address relationship: +5
Now Internal Audit isn't looking at 750,000 transactions equally.
It can prioritize transactions based upon combinations of unusual characteristics.
That is the direction in which AI-enabled fraud detection becomes particularly powerful.
AI Can Analyze Relationships Humans Cannot Easily See
Humans are reasonably good at reviewing one transaction.
Computers are extraordinarily good at comparing one transaction against hundreds of thousands of other transactions.
That creates opportunities to identify relationships such as:
Employee → Vendor
Vendor → Address
Vendor → Bank Account
Vendor → Invoice
Invoice → Purchase Order
PO → Approver
Approver → Employee
Employee → Cost Center
Fraud frequently hides in those relationships.
The more disconnected the organization's systems are, the harder those relationships may be for a human auditor to see.
Recovery Audits Find Money After It Is Gone
CCS makes an important distinction in this program between traditional recovery activity and more proactive fraud prevention.
The course emphasizes using AI to reduce spend leakage and identify fraud, duplicate payments, errors and noncompliance throughout the P2P workflow.
A recovery audit essentially says:
“We already paid the money. Let's see whether we can get some of it back.”
The better control objective is:
“Can we identify the problem before the money leaves?”
That is a major reason AI and continuous analytics can be valuable.
The earlier an anomaly is identified in the P2P lifecycle, the greater the opportunity to prevent rather than recover a loss.
Fraud Detection Should Cover the Entire P2P Process
Don't limit fraud analytics to Accounts Payable.
Consider the entire process:
Vendor Onboarding
↓
Vendor Master
↓
Purchase Requisition
↓
Purchase Order
↓
Approval
↓
Receiving
↓
Invoice
↓
Three-Way Match
↓
Payment
↓
Bank Account
Every step creates data.
And every step potentially creates fraud indicators.
The CCS program is intentionally structured around procure-to-pay process improvement, not merely invoice analysis. Its agenda includes best practices, operational process maturity and AI applications across the P2P workflow.
AI Does Not Replace the Fraud Examiner
There is an important limitation.
An algorithm can identify:
Vendor 4187 has the same address as Employee 277.
It cannot automatically establish why.
Perhaps it is fraud.
Perhaps the vendor is legitimately owned by an employee's relative and appropriately disclosed.
Perhaps the address is a large office complex.
Perhaps the underlying data is wrong.
That requires investigation.
The professional process remains:
AI identifies anomaly
↓
Auditor evaluates data
↓
Auditor gathers evidence
↓
Auditor interviews appropriate personnel
↓
Auditor corroborates facts
↓
Auditor reaches conclusion
AI accelerates the first stages.
It does not eliminate professional skepticism or evidence gathering.
Internal Audit Can Move Toward Continuous Fraud Monitoring
Traditional auditing is periodic.
An audit happens.
Testing occurs.
The report is issued.
Then the auditor leaves.
AI-enabled analytics create the possibility of something closer to continuous monitoring.
An organization could periodically analyze:
New vendors
Vendor changes
Duplicate invoices
Bank-account changes
Approval-threshold transactions
Unusual PO activity
Employee/vendor relationships
Abnormal payment patterns
The highest-risk transactions can then be routed for investigation.
That changes the audit question from:
“Did fraud occur during the period we sampled?”
toward:
“What is happening in the transaction population right now that deserves investigation?”
Procurement Improvement and Fraud Detection Belong Together
CCS also connects fraud detection with broader procure-to-pay process improvement.
The program examines operational maturity and how world-class procurement organizations seek broader control and cost improvements. The course is designed not only to detect fraud but also to reduce errors, noncompliance and spend leakage.
This is important because not every financial loss is fraud.
Organizations also lose money through:
Duplicate payments
Incorrect prices
Contract leakage
Poor vendor data
Processing errors
Unnecessary purchases
Weak approval controls
Noncompliant purchases
The same analytics used to identify potential fraud can frequently identify operational inefficiency.
That makes AI-enabled P2P analytics potentially valuable to Internal Audit, Finance and Procurement simultaneously.
Ethical and Compliance Issues Still Matter
AI fraud detection creates its own risks.
CCS specifically includes ethical considerations, regulatory compliance and transparency among the learning objectives.
Organizations need to consider:
What employee data is being analyzed?
Who can see the results?
How are false positives handled?
Is the algorithm biased?
How is sensitive vendor information protected?
Who validates the analytical model?
How do we prevent an anomaly score from being treated as proof of misconduct?
That last question is particularly important.
An employee or vendor should not effectively be accused of fraud because an algorithm generated a high-risk score.
An anomaly is a lead. Evidence supports a conclusion.
Who Should Attend?
CCS designed the program for professionals seeking to modernize fraud detection and improve P2P operations, including CFOs, Controllers, Accountants and Internal Audit Directors.
I would also consider it highly relevant for:
Internal Auditors
Fraud Examiners
Procurement Professionals
Accounts Payable Managers
Data Analytics Teams
Compliance Professionals
Finance Managers
Vendor-Master Administrators
The strongest results are likely to occur when these functions collaborate rather than treating P2P fraud exclusively as an Internal Audit problem.
Two Opportunities to Attend in 2026
Corporate Compliance Seminars offers Detecting Fraud Using AI in Procure to Pay as a 2-CPE Group Internet-Based program in Auditing. The program runs from 10:00 a.m. to 12:00 noon Central Time, requires no prerequisites or advance preparation, and is currently priced at $140.
Two upcoming sessions are:
Friday, September 18, 2026
An opportunity to begin applying AI and analytical concepts to vendor, purchasing, receiving, invoice and payment data before year-end.
Friday, November 13, 2026
A particularly useful opportunity for Internal Audit departments preparing their 2027 audit plans and fraud risk assessments to consider where AI-enabled P2P analytics should become part of next year's audit methodology.
The Bottom Line: Stop Looking for Fraud One Invoice at a Time
Fraudsters have an advantage when auditors examine transactions individually.
Data changes the equation.
Instead of asking:
“Does this invoice look suspicious?”
we can ask:
“What makes this invoice different from the other 749,999 invoices?”
Instead of:
“Is this vendor legitimate?”
ask:
“What relationships exist between this vendor and every other vendor, employee, address, telephone number and bank account in our data?”
Instead of:
“Did this transaction receive approval?”
ask:
“Why are so many transactions occurring immediately below the approval threshold?”
That is the real promise of AI in fraud detection.
It isn't replacing the auditor.
It is giving the auditor the ability to look for patterns that would be nearly impossible to identify manually.
Corporate Compliance Seminars' Detecting Fraud Using AI in Procure to Pay on September 18 and November 13, 2026 provides a practical introduction to putting those concepts to work.
Comments