Vendor fraud has become one of the most persistent financial risks facing organizations, and many successful attacks began with employees trying to be helpful. As fraudsters increasingly exploit familiarity, urgency, and convincing impersonation tactics, finance leaders are discovering that strong internal controls matter far more than good intentions.
For Martin Resch, President and Chief Executive Officer of Cass Information Systems, protecting organizations from vendor fraud starts with one principle: trust the process, not the person. “The key is the control process,” he says. “The internal processes must exist and employees have to follow them even if they feel like they are being bureaucratic, difficult or challenging, because being helpful is the path to fraudulent changes.”
That mindset is reshaping how organizations approach accounts payable, expense management, and fraud prevention, placing disciplined verification ahead of convenience. Below, Resch shares more on how to protect your organization from vendor fraud.
Why Strong Vendor Controls Matter More Than Ever
Every payment represents a potential opportunity for payment or invoice fraud if organizations fail to maintain rigorous oversight of their vendor information. While cybercriminals continue to adopt AI-powered tools and business email compromise schemes, Resch argues that technology alone is rarely the root cause. “It’s the human trying to help the vendor,” he says. “We want them to feel like working with us is easy. But the challenge is that the fraud vectors are just too powerful, and the control structure exists to protect both the vendor and the client.”
This perspective shifts the conversation away from hoping employees do the right thing, toward designing systems that make mistakes difficult to commit. Effective vendor master file controls ensure that critical information, such as banking details, remittance instructions, and contact information cannot be altered without rigorous verification. Rather than assuming familiar names or recognizable email addresses are trustworthy, organizations must embrace a zero trust philosophy where every request is independently validated.
Building Internal Controls That Stop Supplier Fraud
Understanding how to prevent vendor fraud begins with separating responsibilities across multiple people. Resch advocates what he calls a “six-eyes” process, where three different individuals each play a role in validating vendor changes. One employee initiates the request, another independently verifies the information through separate channels, and a third confirms every control has been followed before any change is approved. If these roles are automated with AI agents, the same roles and responsibilities need to be assigned.
“For things like changing remittance information, firms should have at least those three roles involved,” he says. “That feels heavy, but one bad transaction can be significant.” These internal controls that stop supplier fraud are especially valuable, because they eliminate reliance on personal relationships. Fraudsters often target customer service representatives or finance staff by pretending to be trusted executives or long-standing suppliers. “The fraudster is relying on the phone number, the email address, the image, the voice,” Resch explains. “Force the process to work.”
That means using callbacks to verified phone numbers, refusing to rely on inbound requests, and confirming sensitive changes through multiple communication channels. These practices form the foundation of effective supplier verification and reduce procurement risk before payments are ever released.
AI Can Strengthen Controls, But It Cannot Replace Them
Artificial intelligence (AI) is changing both sides of the fraud equation. Criminals are using AI to create convincing emails, cloned voices, and increasingly sophisticated impersonation attempts. At the same time, organizations can deploy AI to identify suspicious behavior before it reaches employees.
“AI should catch it before it ever gets to the human,” Resch says. “If there are red flags, those red flags should be identified by tools, not humans.” AI can identify anomalies such as unusual login locations, unexpected communication times, or mismatched contact information, providing an important first layer of defense against business email compromise payment fraud.
However, Resch believes automation should support human judgment rather than replace it. “When it does get to a human, you’re inside our wall and you follow our process,” he says. “We’re going to validate that the controls have been followed before the change will take place.” This combination of intelligent automation and disciplined governance gives finance teams a practical framework for expense management fraud prevention solutions, while preserving accountability over high-risk transactions.
Payment Speed Should Never Override Risk Management
As faster payment networks continue to expand, many organizations assume speed automatically improves efficiency. “In business to business there’s no necessity for speed,” he argues. “Terms are clearly defined.” Instead, accelerated settlement can remove valuable opportunities to detect fraud before funds become unrecoverable. Requests for immediate payment or same-day settlement should prompt additional scrutiny rather than automatic approval.
“If somebody thinks they need cleared funds in one day, that’s a red flag,” Resch says. The same logic applies to outdated payment methods. Paper checks remain attractive targets for criminals, while vendors that insist on bypassing secure electronic payment methods may introduce unnecessary risk.
Ultimately, what finance leaders should audit in vendor payments extends well beyond individual transactions. They should review vendor master file controls, approval workflows, duplicate payments, recurring invoice processes, and every point where supplier information can be changed. Effective third-party vendor risk management depends on disciplined governance at every stage of the payment lifecycle.
For Resch, the organizations best positioned to prevent duplicate payments, reduce invoice fraud, and strengthen accounts payable are not necessarily those with the newest technology. They are the ones with processes that cannot be bypassed. As he puts it, “If you have not created a control structure for recurring or non-recurring payments, you have put yourself at significant risk.”
Follow Martin Resch on LinkedIn or visit his website for more insights on vendor fraud prevention, internal financial controls, and risk management.



