Decoding Modern Fraud: Lessons from Tax Evasion and Scam Cases for Supply Chain Due Diligence
An email arrives from a supplier you've paid monthly for eighteen months, requesting an update to their bank details. The branding matches, the invoice number continues the sequence, only the BSB and
An email arrives from a supplier you've paid monthly for eighteen months, requesting an update to their bank details. The branding matches, the invoice number continues the sequence, only the BSB and account have changed.
This isn't a sophisticated cyber heist exploiting firewalls; it's a manipulation of trust built through routine. Modern payment fraud succeeds not by bypassing controls, but by exploiting the gaps between them – the assumptions made when a process feels familiar, the verification step skipped because "we know this supplier." The core vulnerability isn't the transaction itself, but the due diligence process that fails to confirm the entity behind the request remains the same one originally vetted.
This is where the fraudster wins: not by forging a signature, but by exploiting the moment when familiarity overrides verification. The email lands in an inbox already primed to accept it – the supplier name is recognised, the timing aligns with the usual cycle, and the request mirrors dozens of previous, legitimate updates. No alarm bells ring because the process itself has been conditioned to trust the pattern, not scrutinise the substance. The gap isn't in the technology; it's in the human assumption that repetition equals legitimacy.
Modern payment fraud thrives in this cognitive blind spot. It doesn't require breaking into systems; it relies on the accounts payable team processing the request as just another routine task, skipping the critical step of confirming that the entity requesting the change is still the same legal entity originally onboarded and risk-assessed. The theft occurs not at the point of payment, but earlier, in the due diligence process that failed to evolve beyond a initial checklist.
Beyond the Bank Account: Deconstructing Supplier Financial Red Flags
Changing a supplier’s bank details is often the final act in a longer con. The real vulnerability lies upstream, in the failure to monitor shifts in the supplier’s underlying financial stability or corporate integrity. A company that was financially sound when onboarded can deteriorate rapidly, or worse, be a shell set up for a single fraudulent invoice.
Superficial compliance — ticking the ABN box, confirming the BSB matches the invoice — misses these deeper risks. Financial red flags include sudden changes in directors or shareholders, especially if linked to known high-risk entities, or billing rates that spike 30-50% above industry benchmarks without a corresponding change in scope or quality. These aren’t proof of fraud, but they are signals that the due diligence process needs to trigger, not just file away.
Consider a scenario where a long-standing maintenance contractor suddenly begins submitting invoices for specialised engineering work at rates 40% above market. The ABN is valid, the bank details unchanged, and the purchase order references a valid project code. Yet the shift in service type and pricing lacks any corresponding change in contract scope, staff qualifications, or equipment hire. This mismatch between invoiced activity and operational reality is a classic red flag that superficial checks ignore.
Another signal is accelerated corporate churn: three director changes in six months, or a new shareholder appearing who also controls a string of recently deregistered entities. While not illegal on its own, such volatility — especially when combined with inconsistent financial reporting or an inability to provide basic solvency statements — indicates elevated risk. Due diligence must treat these not as administrative updates, but as triggers for enhanced verification, lest the payment process becomes an unwitting conduit for distressed or deliberately opaque operators.
These financial signals are rarely captured in standard onboarding questionnaires or annual compliance refreshers. A supplier might pass every KYC checkbox — ABN active, bank account verified, insurance certificates current — while simultaneously exhibiting financial behaviours that suggest distress, misrepresentation, or deliberate obfuscation. The gap lies in treating compliance as a point-in-time artefact rather than a continuous assessment of operational and financial plausibility.
Effective due diligence requires linking invoice patterns to underlying business health: Are revenue concentrations shifting abruptly without explanation? Are profit margins implausibly high given the stated cost base? Is there a persistent mismatch between turnover reported to the ATO and the volume of invoices presented for payment? Answering these questions moves verification beyond document hygiene into the realm of financial intuition — the kind that flags when something is not just non-compliant, but economically incoherent.
Mapping the Paper Trail: Tracing Ownership and Phoenix Activity
Corporate registry data is often treated as a static lookup — ABN active, address current, directors named — when it should be a dynamic map of control and risk. A supplier presenting a new director or a change in registered office isn’t necessarily suspect, but when those changes cluster around liquidation events, debt defaults, or sudden invoice surges, they form a pattern worth interrogating. The immediate signatory on an invoice is rarely the beneficial owner; tracing who ultimately controls the entity requires drilling past nominee directors and trustee structures.
Phoenix activity leaves traces in the public record that manual checks miss: identical business names resurfacing under new ACNs, the same address housing dozens of deregistered entities, or IP addresses linked to multiple company lodgements. Cross-referencing ASIC’s register with bankruptcy notices, PPSR security interests, and even ATO payment default data reveals whether a supplier’s corporate history is a legitimate evolution or a cycle designed to shed liabilities while retaining revenue streams. This isn’t about proving fraud — it’s about identifying when the corporate veil is being used as a procedural loophole rather than a legitimate business tool.
Start with the ABN Lookup — it’s the baseline, not the endpoint. An active ABN and a current address tell you the entity exists on paper, not whether it’s being used as a conduit. The real signal lives in the cadence of changes: a director appointed two weeks before a BAS lodgement lapse, or a registered office shifted to a virtual address in a co-working hub shared with ten other newly registered entities. These aren’t anomalies in isolation; they become significant when clustered around financial stress — think multiple ASIC Form 484s lodged within a 30-day window, each tweaking ownership or address, coinciding with a spike in invoice volume from a previously dormant supplier.
Beneficial ownership isn’t found in the director field alone. Trace the chain: is the nominated director also a secretary for five other companies lodged from the same IP address? Does the shareholder listed on the ASIC extract match a known phoenix operator from insolvency notices? Cross-referencing with the Personal Property Securities Register (PPSR) can reveal if assets supposedly owned by the supplier are actually secured against loans tied to individuals with adverse credit histories or prior bans under the Corporations Act 2001. This layered approach turns registry data from a compliance checkbox into a risk-scoring mechanism.
ASIC’s public registers offer more than a name and address; they reveal behavioural patterns that precede collapse. A supplier lodging Form 484 to change its registered office to a mail-forwarding service in a different state, while simultaneously updating its principal place of business to a residential address, warrants scrutiny — especially if this follows a failed insolvency appointment for a related entity. These moves often precede the clean sheet of a new ABN, where the same individuals re-emerge under a fresh corporate veil to continue trading.
Detecting phoenix activity requires linking these registry shifts to financial distress signals. Cross-referencing ASIC data with the Australian Financial Security Authority’s (AFSA) insolvency notices or the ATO’s director penalty notices can expose a history of avoided liabilities. When a supplier’s principals appear as directors in multiple companies that have all entered external administration within a short period, and the new entity immediately invoices for work previously performed by the old one, the pattern suggests asset stripping rather than legitimate succession. This is where registry data stops being a static record and starts forecasting risk.
Tracing beneficial ownership means following the chain from the invoicing entity to the individuals who ultimately control or benefit from it. Start with the current ABN lookup via ASIC Connect, then examine historical extracts for changes in officeholders and shareholders. Look for nominee directors or shareholders — individuals with no apparent industry connection or whose other directorships cluster in high-risk sectors like labour hire or construction. A shell company often shows minimal activity: no website, no physical premises beyond a virtual office, and financial statements that reveal little beyond invoicing and payments to related entities.
When the same individuals appear as directors across multiple newly incorporated entities with overlapping addresses and identical bank details, particularly after a pattern of insolvencies, the corporate structure is likely being used to obscure liability rather than facilitate legitimate business. This level of scrutiny transforms registry data from a compliance checkbox into an active risk-assessment tool, one that catches the financial engineering behind fraud long before a false invoice is submitted.
The CFO's Liability: Governance Failures and the Corporations Act
When a fraudulent payment slips through, the immediate focus is often on the accounts payable clerk who processed it. Yet ASIC and the courts increasingly look upstream, questioning whether the CFO and finance team failed in their duty to implement and monitor adequate internal controls under the Corporations Act 2001 (Cth).
This isn't about prosecuting honest error; it's about whether the organisation had reasonable systems to prevent foreseeable fraud. A pattern of bypassing verification steps, ignoring red flags in supplier data, or relying solely on annual audits without real-time monitoring can constitute a failure to exercise the care and diligence required of an officer under section 180.
Section 180 liability hinges on whether the CFO took reasonable steps given their position and the organisation's circumstances. Simply having a policy on supplier verification is insufficient if the policy is not actively monitored, exceptions are not investigated, or the finance team lacks the resources or authority to enforce it. ASIC's approach in recent enforcement actions has scrutinised board minutes and internal audit reports for evidence that known control weaknesses were reported but not remedied, treating inaction on escalated risks as a breach of duty.
The duty under section 180 is not static; it requires ongoing assessment of whether controls remain fit for purpose as fraud tactics evolve. Relying on annual supplier re-certification while ignoring real-time changes in ABN status, frequent alterations to banking details, or adverse ASIC register extracts (like repeated director disqualifications) demonstrates a failure to maintain an adequate system. The law expects officers to adapt their oversight to the material risks they know or ought to know exist, not to treat compliance as a periodic exercise.
This expectation of active, evolving oversight is where many organisations falter. A CFO who delegates supplier verification to an overburdened accounts payable team without ensuring they have access to real-time ASIC register checks or adverse media monitoring tools may find their reliance on process alone insufficient to meet the standard of care. The law looks not for perfection, but for a demonstrable, proportionate response to known risks — such as implementing tiered due diligence where high-risk suppliers trigger enhanced verification steps, including direct contact with known principals or cross-checking against insolvency registers.
Ultimately, section 180 liability arises not from the fraud itself, but from the governance failure that allowed it to persist undetected or unchallenged. When payments flow to entities with obscured ownership, rapidly changing details, or links to previously disqualified individuals — and the finance function had the means to uncover these patterns but did not deploy them — the CFO’s defence of having “followed procedure” collapses under scrutiny. The duty is to know the limits of your controls and to strengthen them before the loss occurs, not to explain why they failed after the fact.
Uncommon Insights
Annual audits are a rear-view mirror check; they confirm what already happened, not what is happening right now in your supply chain. The counter-intuitive insight is that the most effective fraud prevention isn't found in deeper annual reviews, but in continuous, automated mapping of supplier relationships. Relying solely on periodic financial statements misses the rapid shifts in ownership, control, and risk that occur between audit cycles.
Modern supplier intelligence platforms ingest live data from ASIC registers, adverse media feeds, and global watchlists to build a dynamic network diagram of each supplier. This reveals hidden connections — such as a newly appointed director who was previously disqualified, or a parent company suddenly linked to a high-risk jurisdiction — that static due diligence blindly accepts. The goal isn't to replace the audit, but to make the annual check a formality because exceptions are flagged and resolved in real time.
One overlooked mechanism is the use of supplier intelligence to detect circular invoicing schemes, where a single entity creates multiple supplier entities to bill for the same service at inflated rates. These schemes often evade traditional checks because each entity appears legitimate on its own — separate ABNs, different addresses, and seemingly independent bank details. However, intelligence platforms can flag shared directors, identical IP addresses used for portal logins, or recurring patterns in invoice timing and amounts across the network. This isn't theoretical; it's a common tactic in industries with fragmented subcontracting, where the fraud relies on volume and the assumption that no one is connecting the dots between approved vendors.
Another angle is the exploitation of changes in beneficial ownership that don't trigger ASIC notification thresholds. A supplier might sell 24% of its shares to a new party — below the 25% threshold requiring disclosure — yet this shift could introduce significant risk if the new holder has links to sanctioned entities or a history of phoenix activity. Continuous monitoring catches these sub-threshold shifts, allowing procurement to reassess risk before the next invoice is processed, rather than waiting for an annual review that assumes stability based on last year's snapshot.
The real value of supplier intelligence platforms emerges when they detect behavioural anomalies that static data misses. For example, a vendor might consistently lodge invoices exactly 29 days after month-end — just inside standard payment terms — but only when a specific project manager is on leave. This timing pattern, invisible to annual audits, can signal an attempt to exploit approval gaps or route payments through dormant entities. Platforms that correlate invoice metadata with HR calendars, access logs, or even weather disruptions (to test legitimacy of delay claims) turn passive vendor lists into active risk sensors.
Another underutilised mechanism is network velocity mapping. Legitimate suppliers show stable growth in transaction volume and invoice size aligned with announced contracts or public tenders. Fraudulent networks, however, often display sudden, synchronized spikes across multiple newly onboarded entities — all billing similar amounts for vague "consultancy" or "logistics" services within the same week. This coordinated scaling, especially when tied to shared digital fingerprints like identical invoice PDF metadata or recurring payment reference formats, is a strong indicator of orchestrated fraud rather than organic business expansion.
This is where relying solely on annual financial statements or basic KYC checks becomes dangerously inadequate. Sophisticated fraudsters exploit the latency between those periodic reviews, knowing that a company deemed "low risk" twelve months ago can rapidly morph into a conduit for illicit payments through seemingly minor, unreported changes.
The counter-intuitive insight is that effective defence requires treating supplier data not as a static compliance artefact, but as a dynamic signal stream. Integrating platforms that continuously monitor for subtle shifts — such as abrupt changes in director/shareholder registers linked to high-risk jurisdictions, sudden spikes in ABN cancellations and re-registrations under similar names, or inconsistencies between lodged financial activity and claimed operational scale — transforms procurement from a gatekeeping function into an active risk sensor.
This continuous mapping of relationships and behaviours is the foundation for the practical steps Procurement Managers need to implement well before the first invoice arrives.

Key Takeaways
The most effective defence against sophisticated payment fraud begins long before an invoice is received. Procurement Managers must treat supplier onboarding as a continuous risk assessment, not a one-off checkbox. This means embedding verification steps directly into the procurement workflow, ensuring due diligence is proportional to the inherent risk of the supplier relationship and the value of the transactions involved.
A practical, actionable approach starts with a structured pre-onboarding checklist. First, validate the supplier’s legal identity by confirming their ABN/ACN against the Australian Business Register and checking for any ASIC disqualifications or insolvency flags on directors. Second, independently verify banking details through a confirmed channel — never using contact information supplied on the invoice itself. Third, assess financial health using available public data, looking for inconsistencies between reported revenue, employee numbers, and operational scale. Fourth, screen for adverse media or sanctions list matches using reliable third-party sources. Fifth, establish and document the rationale for the chosen payment terms and credit limits based on this aggregated risk picture.
This checklist transforms due diligence from a periodic audit task into an embedded control within the procurement workflow. Each step must be documented and retained, creating an auditable trail that demonstrates proactive risk management — not just a hope that nothing went wrong. The strength lies in the sequence: identity verification precedes financial assessment, which precedes external screening, ensuring each layer builds on a verified foundation.
Embedding these checks means the payment lifecycle itself becomes the control mechanism. When a new supplier is added, the onboarding checklist triggers automatically in the procurement system. When transaction values increase beyond a threshold, a reassessment protocol initiates. This shifts the focus from detecting fraud after funds have left the account to preventing the conditions that enable it — making silence from auditors the expected outcome, not a lucky break.
This checklist transforms due diligence from a periodic audit task into an embedded control within the procurement workflow. Each step must be documented and retained, creating an auditable trail that demonstrates proactive risk management — not just a hope that nothing went wrong. The strength lies in the sequence: identity verification precedes financial assessment, which precedes external screening, ensuring each layer builds on a verified foundation.
Embedding these checks means the payment lifecycle itself becomes the control mechanism. When a new supplier is added, the onboarding checklist triggers automatically in the procurement system. When transaction values increase beyond a threshold, a reassessment protocol initiates. This shifts the focus from detecting fraud after funds have left the account to preventing the conditions that enable it — making silence from auditors the expected outcome, not a lucky break.
- Verify legal existence and standing — Confirm the supplier’s current registration with ASIC via ABN Lookup, ensuring the entity is active, not under external administration, and matches the name on invoices and contracts.
- Validate banking details against verified sources — Cross-check BSB and account numbers provided by the supplier against those held in your ERP or verified via a trusted third-party banking validation service before first payment.
- Assess financial health using observable signals — Review recent financial statements for negative equity, declining revenue trends, or inconsistent reporting compared to industry benchmarks, not just relying on credit scores.
- Screen for adverse associations and sanctions — Run the supplier’s ABN, ACN, and key principals through global sanctions lists and adverse media databases using a compliant third-party provider.
- Document and justify payment terms and limits — Record the risk-based rationale for agreed payment terms and credit limits, tying them directly to the verified financial and operational profile established in prior steps.
Run a free supplier check in seconds
Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.
Start verifying →


