
The headline AP fraud stories tend to feature six-figure losses, suspicious wire transfers and clear control failures. Those cases happen and they matter. They are also a fraction of the actual loss volume inside most mid-market AP functions. The dominant pattern in 2026 is the opposite: small invoices, well below the four-eyes threshold, processed at volume, often automated. The cumulative loss is large. The individual losses sit below the cadence of any control regime designed around high-value risk.
Why control regimes are calibrated for the wrong invoices
AP control regimes carry historical assumptions about where fraud sits. Three assumptions dominate.
That fraud is large in individual value. Hence threshold-based approval: payments above a defined amount require additional review. The threshold model assumes attackers will target the high-value invoices because that is where the money is.
That fraud is rare per supplier. Hence sample-based audit: a fraction of supplier records are reviewed in detail per period, with the assumption that anomalies will surface in the sample.
That fraud is event-driven. Hence the focus on supplier onboarding, where the controls are concentrated, and the lighter ongoing review of suppliers already on the master.
All three made sense in 2010. None match the 2026 attack pattern set out in why AP fraud will explode in the AI era.
The maths of small-volume, high-frequency fraud
The economics changed when the cost of producing a credible invoice fell to near zero. Generative AI lowered the cost of impersonation, document production and pattern variation. The attacker no longer needs a six-figure target to make the operation profitable.
The new attack pattern looks like this. Twenty fake invoices for £1,800 each, distributed across the AP queue over a month. Each invoice is plausible, generated against the buyer's known supplier patterns. None individually triggers the four-eyes threshold. None individually appears in a sample audit. The cumulative loss is £36,000 per month, per attacker, per buyer.
At scale, automated attacks against multiple buyers run this pattern continuously. The aggregate loss across the UK is meaningfully higher than the headline cases suggest, because the headline cases are reported and the small-volume pattern often is not.
Where the controls actually break
Three specific control failures matter.
The four-eyes principle. Two reviewers approve payments above a threshold. The control works as designed for high-value payments. It does not engage for sub-threshold payments, which is precisely where the attack now sits.
Threshold approval. The threshold itself becomes the attacker's design parameter. The attacker calibrates each invoice to sit below the buyer's known threshold. The control creates a clear target.
Sample audit. Sampling assumes random distribution of fraud. Modern attacks cluster, both within a buyer's queue and across buyers. Random samples miss clustered patterns by construction. The open banking layer closes some of this gap but not all of it.
What a behavioural layer adds
The control that catches what threshold and sample models miss is behavioural. It compares each invoice, regardless of value, against the supplier's verified pattern. Three patterns trigger review.
Invoicing frequency change. A supplier that previously invoiced monthly is now invoicing weekly. The pattern shift is the signal.
Invoice value distribution change. A supplier whose invoices typically sit in a defined range now shows invoices clustering just below the buyer's approval threshold. The clustering itself is the signal. Supplier trust scoring turns this into an operational input.
Cross-buyer behavioural anomaly. A supplier's pattern changes across multiple buyers at once. The cross-buyer dimension is the highest-confidence signal in the dataset.
Each of these requires data the buyer does not own internally. The supplier identity graph is the data source.
A control upgrade pattern that does not slow AP down
The instinct of finance leaders reading this is to assume the upgrade requires reviewing every invoice. It does not. The upgrade replaces threshold review with behavioural review, then lets the threshold review continue alongside.
The operational pattern is straightforward. Behavioural scoring runs on every invoice automatically. Where the score sits below a defined threshold, the invoice flows through normal processing. Where the score sits above the threshold, it routes to exception review. The volume of exception review depends on the model's calibration, but is typically in the range of 3 to 7 per cent of the queue for a well-calibrated model.
The threshold-based control regime stays in place. Behavioural scoring sits in parallel. The combined regime catches what either would miss alone, without forcing the AP team to review every invoice.
Where to start
The pragmatic first move is to pull a sample of sub-threshold invoices from the last quarter and pattern-match them manually against the supplier's behaviour history. Most teams find at least one anomaly in the first sample, usually involving a supplier with recent bank-detail change activity. The anatomy of an AP fraud walkthrough shows what one of these patterns looks like in practice. The size of the find usually justifies the model upgrade on its own.
.jpg)
