Invoice Fraud Prevention: Your Approval Process Was Built Before AI Could Write Emails

Invoice fraud prevention in the UK has quietly become one of the most important process gaps in small businesses. UK Finance has tracked a 75% rise in invoice and payment request fraud over the last three years. Most of that growth is not down to more criminals. It is down to better tools. The phishing email that lands in your bookkeeper’s inbox in 2026 is written by something that can mimic a supplier’s tone, reference a real project, and pick exactly the right week to ask for a bank detail change.

If your payment approval process still relies on email alone, you are using a system built for a threat that does not exist anymore.

What has actually changed

Two years ago, most fake supplier emails were obvious. Bad spelling, odd phrasing, an address one character off the real one. The new generation are different. AI tools now scrape public information about a business, lift writing style from a real exchange, and produce a message that sits inside an existing thread. Recent figures suggest the click-through rate on these is five to ten times higher than the older versions.

The most common attack is not glamorous. A supplier emails to say they have changed banks and asks for the next invoice to go to a new sort code. The finance lead, who has paid that supplier for four years, updates the record and pays the next one. The supplier finds out three weeks later when they chase the unpaid bill. The money is gone, and the bank usually cannot recover it.

11% of UK businesses now experience fake invoice fraud each year. The average loss across reported cases sits in the tens of thousands at the smaller end and runs into six figures higher up. Most cases are never reported.

Invoice fraud prevention is a process change, not a tool

The thing that prevents almost all of this is one rule in your payment workflow. Any change to supplier bank details requires verification by phone, on a number you already had on file before the change request arrived. Not a number in the email. Not a number on the new invoice. The number you already had.

It takes two minutes. It catches every version of this attack. And it does not require any new software.

The same rule applies to first-time payments to a new supplier, internal payment requests that look like they came from a director, and any request that includes urgency language. Real suppliers and real directors do not mind the call. The ones who do mind are the problem.

For a belt-and-braces version, add a second internal sign-off for any payment over a chosen threshold, and a written record of the verification call. That pairs well with the AI features inside your accounting software, which can flag duplicate invoices and unusual amounts but cannot verify a bank change for you.

What to check this week

Ask three questions:

Can the person who pays your invoices update supplier bank details without a second pair of eyes? Is there a written rule on phone verification for bank detail changes? When did you last test it with the team?

If the answer to any of these is uncertain, that is the gap. Closing it costs nothing and removes a category of risk that has grown faster than any other in the last two years. It also sits next to the wider problem of disconnected business software, where supplier data lives in three places.

If you want a wider look at where your business is exposed across payment, supplier and approval processes, the free audit at digilyse.co gives you a clear picture in about ten minutes.

Published by Digilyse. Practical systems for growing businesses.


See where your systems actually stand

Most of these problems trace back to tools that were never joined up properly. The free Digital Maturity Audit scores your business across six areas in five minutes and shows you what to fix first.

Take the free Digital Maturity Audit

Leave a Comment