Forensic Deep Dive: Using Supplier Intelligence to Detect Advanced Invoice Fraud Patterns
An email arrives from a supplier you've paid a dozen times, asking you to update their bank details. The logo is right. The invoice number follows the sequence. Only the BSB and account number are new
An email arrives from a supplier you've paid a dozen times, asking you to update their bank details. The logo is right. The invoice number follows the sequence. Only the BSB and account number are new.
This isn't a case of overlooked controls. It's a precision strike exploiting the rhythm of high-volume processing: the moment trust becomes automatic. Fraudsters no longer need to forge documents—they simply wait for the gap between payment cycles and slip in a change that looks like routine maintenance.
What makes these attacks effective isn't technical sophistication—it's behavioural exploitation. They weaponise the very routines designed to ensure efficiency: the trusted supplier, the predictable invoice cadence, the assumption that a change in banking details after months of consistent payments is merely administrative. The deception lies in its banality, slipping through because it asks nothing extraordinary of the process—only that you continue as normal.
This shifts the focus from control failure to signal detection. Traditional checks—matching PO numbers, verifying ABNs, confirming invoice totals—assume the supplier identity is genuine. When the fraud mirrors legitimacy so closely that only the destination of funds differs, those checks become ceremonial. The vulnerability isn't in the steps taken, but in the assumptions left unchallenged: that familiarity equates to safety, and that repetition negates risk.
Deconstructing the Payment Path: Sequencing, Anomalies, and Timing
Invoice fraud often hides in plain sight by exploiting the rhythm of routine payments. A fraudster might submit an invoice with a number just one digit off from the last legitimate one—INV-00452 instead of INV-00451—or jump ahead to INV-00460 to mimic a bulk batch. These sequencing anomalies are easily overlooked when AP teams process hundreds of invoices daily, especially if the amount aligns with historical spend and the supplier name matches.
More insidious are timing deviations. A supplier who always invoices on the 5th of the month suddenly sends a request on the 20th, marked "urgent." Or a payment that typically clears in three days is now routed to a new account with instructions to expedite. These temporal shifts trigger no flags in basic three-way matching because the goods or services may genuinely exist—the deception lies solely in the redirected funds, exploiting trust in established patterns rather than fabricating documents from scratch.
Sudden banking detail changes are another vector that slips through when verification relies solely on document matching. A fraudulent invoice may arrive with updated BSB and account numbers, yet the invoice format, purchase order reference, and even the contact name remain identical to prior legitimate requests. In high-volume environments, AP staff often compare the new details only against the immediately preceding invoice—not the supplier’s master file on record—allowing the change to appear as a routine update.
The deception is amplified when the fraudster times the banking shift to coincide with a genuine operational change, such as a supplier’s advertised bank merger or system upgrade. Without an independent confirmation step—like a callback to a known, pre-verified number—the altered payment instructions are processed as routine, diverting funds before any discrepancy in goods receipt or service delivery can be investigated.
Invoice numbering gaps are frequently overlooked as mere administrative errors when, in reality, they can signal a duplicate or fabricated invoice designed to exploit sequential trust. Fraudsters often submit a fake invoice with a number just outside the expected range—say, skipping from INV-0045 to INV-0047—knowing that busy AP teams may assume the missing number was lost in transit or voided, not that it never existed. This relies on the cognitive bias that sequential numbering implies legitimacy, even when the gap itself is the anomaly.
Payment timing deviations compound the risk: a legitimate supplier paid monthly on the 15th suddenly submitting an invoice for immediate payment on the 2nd raises no alarm if the amount matches historical averages and the PO reference checks out. Without temporal profiling—comparing not just *what* is requested but *when*—AP systems validate the document while missing the behavioral outlier. The fraud succeeds not by forging paperwork, but by mimicking the rhythm of real transactions just enough to avoid triggering manual review.
Beyond the ABN: Verifying the True Corporate Footprint
An ABN is a starting point, not a verification. Shell suppliers often present a valid ABN that matches a deregistered entity, a dormant trust, or a business operating far outside the declared industry scope—such as a residential address listed as a mining equipment supplier. The fraud lies not in the absence of an identifier, but in the mismatch between the identifier and the operational reality it purports to represent.
Cross-referencing the ABN against ASIC’s organisational structure reveals whether the entity has active directors, a registered office consistent with its claimed scale, and any history of insolvency or administrative dissolution. A supplier claiming to deliver $500k/month in specialised labour hire but showing zero employees, no lodged financials, and a registered office in a suburban unit raises immediate questions about capacity and legitimacy—questions that standard three-way matching never asks.
Checking the registered office address against Google Street View or council rates data is a low-cost filter that catches many ghost suppliers. A mining services firm listed as operating from a strata-titled apartment in Parramatta, or a heavy machinery supplier using a PO Box in a suburban shopping centre, fails the plausibility test before any invoice is processed. These mismatches are visible in ASIC’s public register but are rarely checked at onboarding because the ABN appears valid and the first invoice seems routine.
Industry benchmarks add another layer: a labour-hire supplier quoting rates 40% below market for specialised welding work, yet showing no certified tradespeople in ASIC’s director disclosures or no history of paying payroll tax, warrants scrutiny. The gap between claimed capability and verified corporate footprint is where shell companies hide—not in forged documents, but in the silence of missing data that no one thinks to query.
Cross-referencing supplier ABNs against ATO GST registration status adds a critical filter many teams overlook. An ABN that is active but not GST-registered raises immediate questions for suppliers claiming to provide taxable services above the $75,000 threshold—especially in industries like construction or IT contracting where almost all legitimate operators are registered. This discrepancy often signals a supplier set up solely to invoice and disappear before BAS lodgment deadlines.
Director history checks via ASIC Connect reveal patterns invisible at the entity level. A supplier with three directors, each of whom has been disqualified or associated with two or more deregistered companies in the past five years, presents a high-risk profile even if the current entity appears clean. These connections are buried in the ASIC register’s ‘Relationships’ tab but can be automated via API checks during onboarding.
Project scope alignment provides a final plausibility check. A supplier registered for ‘retail floristry’ suddenly invoicing for civil earthworks on a infrastructure project fails the industry logic test—no amount of invoice sequencing or banking detail verification can overcome this fundamental mismatch. Recording the ANZSIC code at onboarding and flagging deviations creates a systematic control that catches ghost suppliers before the first payment is made.
Ghost suppliers often exploit the lag between ABN activation and GST registration, issuing invoices that appear compliant but fall outside ATO monitoring windows. A supplier claiming to provide taxable services above the $75,000 threshold—especially in industries like construction or IT contracting where almost all legitimate operators are registered. This discrepancy often signals a supplier set up solely to invoice and disappear before BAS lodgment deadlines.
Director history checks via ASIC Connect reveal patterns invisible at the entity level. A supplier with three directors, each of whom has been disqualified or associated with two or more deregistered companies in the past five years, presents a high-risk profile even if the current entity appears clean. These connections are buried in the ASIC register’s ‘Relationships’ tab but can be automated via API checks during onboarding.
Project scope alignment provides a final plausibility check. A supplier registered for ‘retail floristry’ suddenly invoicing for civil earthworks on an infrastructure project fails the industry logic test—no amount of invoice sequencing or banking detail verification can overcome this fundamental mismatch. Recording the ANZSIC code at onboarding and flagging deviations creates a systematic control that catches ghost suppliers before the first payment is made.
Uncommon Insights
When a fraudulent payment exceeds $10,000, the purchasing entity’s liability shifts from a procedural lapse to a potential breach of duty under Corporations Act section 180. Directors and officers may face civil penalties if they failed to exercise reasonable care in verifying supplier legitimacy, particularly when red flags like altered banking details or mismatched ANZSIC codes were present in the documentation. This isn’t theoretical—ASIC has issued infringement notices for inadequate payment controls in cases where losses exceeded $500,000, treating weak verification as a failure of financial management oversight.
The mandatory 'Suspicious Payment Alert' protocol requires three stages: initial anomaly detection (e.g., new bank details or invoice sequencing gaps), secondary verification via independent channel (such as a call to the supplier’s known contact), and tertiary review by a senior finance officer before release. Skipping any stage voids the defence of due diligence, especially when processing volumes exceed 150 invoices weekly—a threshold where manual checks consistently fail to catch sophisticated spoofing attempts.
Even when the alert protocol is triggered, the tertiary review often becomes a rubber-stamp exercise under deadline pressure. Finance officers, already managing cash flow forecasts and month-end close, may approve payments based solely on the presence of a checklist tick rather than substantive verification—such as confirming the caller’s identity against a pre-registered supplier contact or validating the new account’s ownership via the PayID directory. This procedural compliance without substantive scrutiny is precisely what ASIC targets in enforcement actions, arguing that a process followed in form but not in function fails to meet the objective standard of care required by section 180.
Consider a scenario where a supplier’s bank details are updated mid-project, triggering the alert. The secondary verification call reaches the supplier’s office, but the person answering is not the authorised contact on file—yet the officer proceeds because the call was “made.” The tertiary reviewer sees the call logged and approves payment. Weeks later, it emerges the number belonged to a fraudster using a VOIP line spoofed to display the supplier’s legitimate prefix. Here, liability hinges not on whether steps were taken, but whether those steps were reasonably calculated to detect deception—a distinction courts are increasingly willing to examine through email timestamps, call recordings, and workflow logs.
Under section 180 of the Corporations Act 2001, directors and officers must exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would exercise. When fraudulent payments exceed $10,000 and stem from a verification process that merely ticks boxes—such as logging a call without confirming the caller’s authority—courts may find this falls short of the objective standard. The liability isn’t automatic, but the process becomes evidence in assessing whether due diligence was genuinely exercised, particularly if red flags like VOIP spoofing or mismatched contact details were ignored in favour of procedural completion.
This is why the ‘Suspicious Payment Alert’ protocol must be designed as a substantive gate, not a ceremonial step. It requires three independent checks: first, validation of the new bank account against the PayID directory to confirm name-ABN alignment; second, a callback to a pre-registered, verified contact using a number sourced independently from the invoice (such as from the original contract or a prior authenticated invoice); third, reconciliation of the updated details against the supplier’s historical payment patterns and project-specific milestones. Only when all three stages are satisfied should payment proceed—transforming the alert from a compliance artefact into a functional detection mechanism.
This procedural rigor matters because, under corporate governance expectations, directors and officers can be held personally liable for failing to implement reasonable fraud prevention systems when losses are material—typically interpreted as exceeding $10,000 in the context of AP fraud. While the Corporations Act does not prescribe specific payment controls, sections 180 and 588G establish that negligence in financial oversight, particularly when red flags are ignored in favour of box-ticking, may constitute a breach of duty to act with due care and diligence. The focus shifts from intent to whether a reasonable person in the same position would have detected the anomaly given the available information.
The ‘Suspicious Payment Alert’ protocol, therefore, is not merely an internal policy but a tangible demonstration of compliance with those duties. By mandating independent validation of banking details, verified re-contact, and pattern reconciliation, it creates an auditable trail that shows due diligence was exercised substantively, not superficially. This transforms the protocol from a procedural checkbox into a defensible component of governance—one that protects both the organisation and its officers when scrutiny follows a payment error.
Compliance Hardening: Integrating Financial Health Checks
Moving beyond ABN validation and invoice matching requires embedding financial health checks directly into the payment workflow—triggered not by volume thresholds alone, but by changes in supplier behaviour or risk profile. This means verifying solvency indicators like lodged financial statements, ongoing ASIC compliance status, and adverse legal actions before releasing payment, especially for new or amended banking details.
These checks cannot be retrospective or reliant on annual supplier declarations; they must be automated, repeatable, and tied to specific payment events. Integrating them creates a defence-in-depth where a single point of failure—such as a forged letterhead or spoofed email—cannot bypass layered verification, aligning operational controls with the due care expectations under Corporations Act sections 180 and 588G.
For high-value or amended payment instructions, the workflow should mandate a dual-path verification: one stream confirms the banking detail change via an out-of-band method (such as a pre-registered phone callback to a known contact), while the second stream runs automated solvency screening—checking for outstanding wind-up notices, disqualified directors, or overdue financial statements lodged with ASIC. This isn't about adding steps; it's about sequencing existing checks so that a change in payment details triggers deeper scrutiny before funds leave the account.
Under Corporations Act section 588G, directors face personal liability for insolvent trading if they authorise payments when reasonable grounds exist to suspect the supplier cannot pay its debts as they fall due. Embedding real-time ASIC registry checks into the payment approval chain transforms financial health verification from an annual audit artefact into an active control—one that can demonstrate directors exercised the informed judgment required by the defence, should a payment later be scrutinised as potentially preferential or made to a known insolvent entity.
Integrating financial health checks requires more than periodic credit reports; it demands real-time, event-triggered validation tied to specific transaction risks. For example, when a supplier’s ABN details are updated in the master file—even if the change appears routine—an automated workflow should immediately cross-reference the new entity against ASIC’s register for recent administrator appointments, unresolved winding-up applications, or director disqualifications under section 206C of the Corporations Act. This turns a clerical update into a risk event, ensuring that payment approval hinges on current solvency status, not historical performance.
The legal imperative here is clear: under section 588G, authorising a payment to a supplier with known insolvency indicators—such as a creditor’s voluntary liquidation notice lodged just days prior—can expose directors to personal liability for insolvent trading, regardless of whether the supplier ultimately defrauded the buyer. Embedding these checks into the payment sequence, rather than treating them as retrospective audit items, shifts the control from detective to preventive, aligning operational rigor with the informed judgment defence available under the Act.
This integration transforms financial health checks from a procurement gatekeeping function into an active payment control. For instance, a supplier flagged for consecutive BAS lodgement delays or a change in ultimate holding company structure should trigger an automatic payment hold until enhanced due diligence is completed — not merely a note for the next quarterly review. The workflow must enforce segregation: the AP clerk cannot override the hold; only a designated compliance officer, armed with the latest ASIC extract and credit risk score, can release payment after documenting the specific mitigating factors considered.
Critically, this approach satisfies the informed judgment defence under section 180 of the Corporations Act by demonstrating that directors exercised due care and diligence through systems designed to detect insolvency risk at the point of payment, not after loss occurs. When a payment is blocked because real-time data shows a supplier has entered voluntary administration, the control has worked as intended — preventing potential loss and insulating the decision-maker from liability for authorising a transaction to an insolvent entity.

Key Takeaways
The core vulnerability isn't missing paperwork — it's trusting familiar patterns when fraudsters replicate them perfectly. A single changed BSB in an otherwise routine invoice can bypass three layers of approval if verification relies on recognition rather than real-time validation against authoritative sources. Processing 200 invoices weekly by hand guarantees fatigue-driven errors; the solution isn't more vigilance but systematic friction at the point of change.
Implementing a mandatory 'Suspicious Payment Alert' protocol requires embedding automated checks for deviations in banking details, ABN status shifts, and payment timing anomalies directly into the ERP workflow — not as a separate reconciliation step. This must be paired with forensic transaction analysis that maps historical vendor relationships, flagging not just known fraudulent accounts but also new entities sharing infrastructure (IP addresses, device fingerprints, or contact details) with previously blocked suppliers, turning reactive cleanup into proactive prevention.
Embedding the alert protocol means treating every banking detail change as a control point, not a routine update. For a supplier with five years of consistent payments, a sudden shift to a new BSB should trigger an automated hold and require dual-factor confirmation via a pre-registered corporate phone number — not just an email reply to the same potentially compromised address. This shifts the burden from the AP clerk to the system, ensuring human intervention only occurs when the data deviates from the established behavioural baseline.
Forensic transaction analysis extends this by mapping the digital footprint of supplier onboarding. If a new ABN registers using the same email domain, IP subnet, or authorised signatory details as a previously blocked entity, the system should elevate the risk score and require enhanced due diligence — including a search of the ASIC Connect register for disqualified directors or adverse insolvency events — before any payment is released. This turns historical fraud data into a live prevention layer, closing the loop between detection and future risk mitigation.
- Implement automated holds on all banking detail changes — require dual-factor confirmation via pre-registered corporate channels, not email replies to the potentially compromised address on file.
- Deploy forensic transaction analysis to map supplier onboarding footprints — flag new ABNs sharing email domains, IP subnets, or authorised signatory details with previously blocked entities for enhanced due diligence.
- Mandate ASIC Connect checks for disqualified directors and insolvency events — integrate these searches into the pre-payment workflow for any supplier triggering risk elevation rules.
- Treat every payment deviation as a control point — shift the burden from AP clerks to the system by basing interventions on established behavioural baselines, not routine processing.
Run a free supplier check in seconds
Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.
Start verifying →