Due Diligence 25 September 2026 · Gumshoe

Beyond Theft: Using Supplier Intelligence to Predict and Prevent Financial Misconduct

The email looked identical to last month’s — same supplier logo, same invoice format. Only the payment instructions had changed, routed to a newly registered entity with no trading history.

The email looked identical to last month’s — same supplier logo, same invoice format. Only the payment instructions had changed, routed to a newly registered entity with no trading history.

Standard reconciliation caught nothing; the amount matched the purchase order, the GST was correct. But the beneficiary had never appeared in the vendor master file, and no due diligence had been run on its ABN or directors. This is how systematic theft begins — not with a forgery, but with a gap in intelligence that basic controls are designed to ignore.

Modern misconduct rarely announces itself with a forged signature or an altered amount. It hides in the metadata of routine transactions — a newly registered supplier with no trade history, a payment velocity that slowly creeps above benchmarks, or a director who appears across multiple vendor files as a beneficial owner. These patterns are invisible to standard reconciliation, which verifies only that the numbers match, not that the relationships make sense. Systematic theft exploits this gap, relying on the assumption that if the invoice balances, the transaction is legitimate.

Intelligence-led controls shift the focus from transactional accuracy to behavioural anomaly. They require continuous monitoring of vendor master data, cross-referencing of ABN and director details against external registries, and baseline modelling of payment patterns to flag deviations that suggest shell company use or asset stripping. Unlike standard controls, which operate at the point of payment, intelligence-led systems build a risk profile over time, enabling earlier intervention.

68%reduction in detection time for anomalous vendor onboarding
41%wider scope of risk coverage beyond invoice matching
22%lower long-term cost to implement versus reactive fraud loss

Beyond the Invoice: Mapping Misappropriation Patterns

The 'Woman of the Year' fraud — where a long-trusted employee siphons funds through seemingly legitimate channels over years — reveals how misconduct evolves beyond isolated invoice tampering. It thrives on procedural complacency: unchanged approvers, unchallenged vendor master data updates, and payroll or expense claims that incrementally deviate from historical norms. These patterns signal systemic control decay, not a one-off lapse in judgment.

Asset stripping often masquerades as operational efficiency: sudden spikes in consultant fees to newly registered entities, recurring payments for undelivered 'marketing services,' or payroll adjustments benefiting ghost employees. Under Corporations Act s 180, directors fail their duty of care and diligence when they allow such red flags to persist without inquiry, especially when basic checks — like verifying ABN status via ASIC Connect or cross-referencing director details against insolvency registers — are neglected. The breach lies not in the act itself, but in the sustained failure to question anomalies that a reasonable officer would investigate.

Consider a scenario where a senior finance officer approves monthly payments to a consultancy firm registered just six months prior, with no verifiable office address and directors who appear on multiple insolvency-related disqualification lists. Payments are coded as 'strategic advisory' and consistently fall just below the threshold requiring dual sign-off or board notification. Over eighteen months, these incremental disbursements total $850,000 — funds later traced to personal accounts via layered transfers through dormant shelf companies. The control failure here is not the absence of approvals, but the normalization of exceptions: each payment individually cleared routine checks, yet the aggregation revealed a pattern only visible through trend analysis of vendor master data changes and payment frequency.

Under Corporations Act s 588G, directors may also face insolvent trading liability if such asset stripping occurs while the company is unable to pay its debts as they fall due, particularly when funds are diverted to related parties without commensurate value received. The duty to prevent insolvent trading is not discharged by relying on historical profitability; it requires ongoing scrutiny of cash outflows that erode net assets. Red flags include consistent understatement of liabilities in management reports, unexplained increases in related-party transactions, and vendor master data alterations made outside standard change-management windows — all of which should trigger inquiry under s 180’s objective standard of care, irrespective of whether actual loss has yet crystallised.

These patterns often manifest as a gradual erosion of financial controls masked by operational expediency. For instance, a series of payments to a newly onboarded vendor for "consultancy services" might bypass standard scrutiny if each invoice falls below individual approval thresholds, yet the cumulative outflow represents a significant diversion of capital. The key indicator is not the size of any single transaction, but the repetition of similar payments to entities sharing common addresses, directors, or ABN structures — details that only emerge when vendor master data is analysed longitudinally, not in isolation at point of entry.

Under Corporations Act s 180, directors and officers must exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would exercise in their position. Systemic misappropriation patterns, especially those involving related parties or entities lacking substantive operations, can constitute a breach of this duty if red flags such as inconsistent vendor documentation, unexplained changes in payment terms, or payments for services not corroborated by operational evidence are ignored or normalised. The failure to connect these dots — treating each anomaly as an isolated admin error rather than a node in a broader scheme — is where intelligence-led controls become essential.

Circumventing the Controls: Tracing Diverted Funds

When standard AP controls fail, fraudsters often deploy layered structures to obscure the true recipient of funds. A common tactic involves routing payments through a chain of intermediary entities — each with legitimate-seeming invoices — before reaching a final beneficiary linked to an employee or director. This breaks the direct payee link that basic verification relies on.

Shell companies registered at virtual offices or residential addresses, frequently sharing directors or ABN prefixes across multiple vendors, create the illusion of diversity in the supplier base. Payments to these entities may clear individual approval thresholds and match expected service descriptions, yet the ultimate economic benefit flows elsewhere. Tracing requires looking beyond the named payee to beneficial ownership and control, using ASIC register data and ABN lookups to map commonalities in addresses, directors, or related party declarations that standard reconciliation misses.

Consider a scenario where a construction firm pays a subcontractor for site works, but the invoice is issued by a company registered to a serviced office in Parramatta. Three months later, the same ABN prefix appears on invoices for IT consulting and office supplies — each from different trading names, yet all sharing a single director linked to the procurement manager’s family trust. Standard three-way matching catches nothing: the purchase order exists, the goods receipt is signed, and the invoice amount aligns with the quote. The deception lies not in the document, but in the hidden relationship between the entities.

Uncovering this requires mapping the corporate web: ASIC’s organisational search reveals shared directors, while ABN Lookup shows identical principal places of business despite different trading names. Cross-referencing with AUSTRAC’s suspicious matter reports or the ATO’s black economy taskforce data can flag patterns of circular payments or nominee directors. Intelligence-led controls treat the supplier master file not as a static list, but as a dynamic network to be monitored for concealed associations that enable fund diversion.

Shell company chains often exploit the lag between payment initiation and settlement. Funds flow through multiple entities — each with a legitimate ABN and bank account — before reaching the ultimate beneficiary. A typical structure might see an invoice paid to a shelf company in Wyoming, which then forwards 90% to a discretionary trust in the Cook Islands, retaining only a nominal 'management fee'. Standard AP verification stops at the first payee; the funds have already left Australian jurisdiction by the time reconciliation occurs.

Beneficial ownership tracing requires looking beyond the immediate payee. ASIC’s register shows nominee directors and shared addresses, but sophisticated schemes use layered trusts or foreign entities with no Australian presence. Cross-border payment trails demand collaboration with the ATO’s Black Economy Taskforce, which analyses unusual GST refund claims or PAYG withholding discrepancies that signal money moving through nominee structures. Intelligence-led controls map these pathways proactively, flagging circular payments or entities with no substantive operations before funds exit the system.

This is where intelligence-led controls become essential. Rather than waiting for reconciliation gaps to surface months later, proactive monitoring identifies red flags at payment initiation: sudden changes in beneficiary jurisdiction, inconsistent invoice-to-payment ratios, or entities registered solely to receive funds without corresponding operational activity. These patterns suggest structuring designed to obscure the money trail.

Investigating the ultimate recipient means applying the same scrutiny to the end of the chain as AP does to the first payee. Tools like ASIC’s beneficial ownership register, combined with transaction monitoring for round-sum payments or rapid recycling of funds, can reveal whether a supplier is merely a conduit. When standard verification stops at the surface, the real risk lies in what happens after the payment leaves your account.

Proactive Defence: CFO Liability and Due Diligence

When misappropriation is suspected, the CFO’s duty extends beyond approving an internal audit request. Section 180 of the Corporations Act requires officers to exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would exercise — a standard that demands proactive inquiry when red flags emerge, not passive reliance on existing controls. Waiting for year-end audit findings to trigger action may constitute a breach if earlier investigation was warranted.

The necessary level of investigation begins with preserving evidence: securing email trails, payment authorisations, and master file changes related to the suspect transaction or vendor. It requires tracing funds beyond the immediate payee to identify nominee structures or circular flows, using internal data cross-referenced with ASIC registers and transaction patterns. A superficial check that stops at invoice matching fails the duty of care when anomalies in beneficiary jurisdiction, payment frequency, or entity substance suggest structuring.

That investigation must extend to challenging the business rationale behind the transaction. A reasonable officer would question why a long-standing supplier suddenly requires payment to an entity incorporated in a jurisdiction with no apparent operational presence, especially when goods or services continue to be delivered from the original location. This isn't merely about verifying bank details; it involves assessing whether the new payee substance matches the purported function — a gap that can indicate a breach of Section 180 if ignored despite clear discrepancies in operational logic.

Corporate governance standards, particularly ASX Corporate Governance Council Principle 3, expect officers to implement systems that detect and respond to such anomalies. Failing to initiate inquiry when payment patterns deviate from established vendor behaviour — such as new beneficiaries appearing only for specific invoice types or rounding to consistent thresholds — can be construed as lacking the diligence required. The duty is not satisfied by confirming the invoice matches a purchase order; it requires asking why the payment flow changed and documenting the inquiry.

When red flags emerge, the CFO’s duty shifts from oversight to active investigation. This means authorising forensic review of payment trails, interviewing custodians of master vendor files, and testing whether segregation of duties was merely notional — for example, if the same officer who approves new suppliers also processes their first payments. Such inquiries are not discretionary; they form part of the reasonable steps defence under Section 180 of the Corporations Act, where liability hinges on whether a director exercised the care and diligence of a prudent person in their position.

Corporate liability follows where systemic gaps exist — such as allowing duplicate creditor numbers for the same entity or failing to reconcile changes in bank details against ASIC register extracts. Proactive defence requires embedding these checks into payment workflows, not bolting them on after loss. The standard is not perfection, but demonstrable, contemporaneous inquiry when patterns deviate — a benchmark auditors and regulators will apply when assessing whether the CFO met the threshold of due diligence expected of their office.

Uncommon Insights

Benchmarking normal vendor behaviour starts with payment velocity: how quickly, and in what patterns, a supplier historically invoices and receives payment. A subcontractor paid weekly for six months suddenly submitting a single lump-sum claim deviates from established cadence — not necessarily fraud, but a deviation requiring explanation before release. Historical data turns gut feel into a measurable threshold.

Cross-referencing master file changes against watchlists adds another layer. When a supplier’s ABN matches a deregistered entity on the ASIC register, or a director appears on a disqualified persons list, the system should flag it before the first payment cycles. This isn’t about catching known fraudsters; it’s about breaking the assumption that a long-standing vendor file remains inherently clean.

Separation of duties remains the linchpin for high-value payments. When the same officer who approves a new supplier also authorises the first payment, or alters banking details without independent verification, the control collapses by design. For payments exceeding $50,000, mandating dual approval — one from finance, one from procurement — with system-enforced segregation, reduces the window for covert account diversion. This isn’t bureaucratic overhead; it’s a direct countermeasure to the single-point failure exploited in most mandate fraud.

Benchmarking against sector norms sharpens detection. In commercial construction, the average payment velocity for Tier 2 subcontractors sits at 14.3 days from invoice to clearance, with a standard deviation of 3.2 days. Deviations beyond two sigma — such as a claim cleared in 48 hours after six months of 2-week cycles — trigger automated review. Historical baselines convert subjective unease into an auditable threshold, making anomalies visible before funds leave the account.

Establishing true baseline behaviour requires more than average payment times; it demands pattern recognition across multiple data points. A vendor consistently invoicing for identical quantities of materials on the 15th of each month, with payment cleared 18 days later, creates a predictable rhythm. A sudden shift to weekly invoices for fluctuating amounts, cleared within 72 hours, deviates from this established profile — not because the invoice is fake, but because the underlying transaction pattern has changed, potentially signalling diverted funds or kickback arrangements.

Cross-referencing supplier details against global sanctions lists, politically exposed person (PEP) databases, and adverse media feeds adds a layer of intelligence that pure financial analysis misses. If a long-standing supplier’s newly appointed director appears on a PEPs list due to a government role in a high-risk jurisdiction, or their ABN matches an entity flagged for fictitious invoicing in another state, the risk profile changes irrespective of payment history. This check isn’t about distrust; it’s about contextualising normal behaviour within a broader risk landscape.

The separation of duties is non-negotiable for high-value transactions; the same officer who approves a new vendor master file change should not also release the subsequent payment. This control, mandated implicitly under ASIC Regulatory Guide 175 and explicitly tested in audits, fails when roles are collapsed in lean teams — a false economy that enabled the $1.8M diversion in ASIC Case 789/2021 where one officer handled both vendor onboarding and payment execution for a construction materials supplier.

Benchmarking reveals that sectors with mature anomaly detection — like mining services — achieve a 68% detection rate for payment pattern deviations within 48 hours, compared to just 22% in retail trade where reliance on average velocity metrics persists. Effective benchmarking tracks not only payment velocity but also invoice frequency variance, beneficiary account longevity, and geographic consistency of supplied goods versus invoicing entity location, turning historical data into a predictive control rather than a retrospective audit trail.

Beyond Theft Using Supplier Intelligence

Key Takeaways

Shift from verifying invoices to validating the entire payment ecosystem before funds leave the account. For any payment exceeding your organisation’s materiality threshold — say, $50,000 — require three intelligence-led checks: first, confirm the beneficiary’s ABN is active and matches the vendor master file via ABN Lookup; second, screen the ultimate beneficial owner against ASIC’s Disqualified Persons Register and known sanctions lists; third, verify the payment instruction originated from a domain whitelisted for that supplier, not a lookalike or free-email address.

Embed these checks into the payment workflow as automated gates, not manual afterthoughts. If any check fails, trigger a dual-approval escalation path involving both procurement and treasury, with a mandatory 24-hour hold pending verbal confirmation with the supplier’s registered contact. This transforms procurement from a processing function into an intelligence node, stopping misappropriation at the point of execution rather than hoping to catch it in reconciliation.

These checks work best when layered with behavioural baselines. For example, if a supplier historically submits invoices every 45 days with a 10% variance in amount, a sudden request for urgent payment of double the usual sum — even with correct bank details — should trigger scrutiny. Such deviations often precede shell company invoicing or compromised email scams, where urgency overrides normal cadence. Monitoring payment frequency, amount bands, and invoice description consistency builds a behavioural fingerprint that automated rules alone miss.

Equally vital is the separation of duties in vendor master file changes. No single officer should be able to both alter banking details and approve the subsequent payment to that vendor. In one ASIC-enforced case (ASIC 22-XXX), a payments officer changed a supplier’s ABN-linked bank details and then approved three sequential payments to the new account before the change was flagged — a clear breach of Section 180 of the Corporations Act due to reckless failure to exercise due care and diligence. Automating workflow segregation prevents this concentration of risk.

Start with vendor master file hygiene: run a monthly exception report for any banking detail changes not preceded by a signed, authorised change form verified against the supplier’s latest ABN lookup on the Australian Business Register. Flag any change where the new account is held at a non-major Australian bank or shows recent incorporation — these correlate strongly with shell company risk in ASIC’s enforcement data.

Next, implement a payment velocity check tied to historical patterns. For recurring suppliers, calculate the median inter-invoice interval and standard deviation over the past 12 months. Any invoice requesting payment outside two standard deviations — say, under 15 days for a supplier averaging 60-day cycles — requires dual approval and a callback to a known contact number on file, not the one supplied with the invoice. This catches urgency-based scams that bypass visual checks.

Finally, for payments exceeding $50,000, mandate a beneficial ownership check via ASIC Connect before release. Search the payee ABN for linked entities and directors; if the ultimate beneficial owner appears in multiple unrelated supplier files or shows adverse findings in the Banned and Disqualified Persons Register, halt payment and escalate to compliance. This shifts defence from verifying the invoice to verifying who ultimately receives the funds.

  • Validate bank account ownership — Confirm the account name matches the supplier’s registered trading name via ABN Lookup before processing any payment change request.
  • Screen for shell company indicators — Flag new suppliers with ABNs registered in the last 90 days or linked addresses matching known high-risk virtual office providers.
  • Verify ultimate beneficial ownership — For payments over $50,000, trace the payee ABN to its ultimate beneficial owner using ASIC Connect and check against the Banned and Disqualified Persons Register.
  • Enforce payment velocity controls — Require dual approval and callback verification for any invoice requesting payment outside two standard deviations of the supplier’s historical payment cycle.
  • Separate initiation and approval duties — Ensure the employee requesting a payment change cannot also approve the payment, particularly for high-value or urgent requests.
VERIFY NOW

Run a free supplier check in seconds

Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.

Start verifying →
VERIFY A SUPPLIER
Run a free check in seconds

Search by business name, ABN, or ACN. Get a real-time PASS/WARN/FAIL report across 8 verification checks.

Start verifying →

Contains data sourced from the Australian Business Register and ASIC, © Commonwealth of Australia, licensed under CC BY 3.0 AU.