← All articles

Article

New Data: Manual AP Teams Lose Money to Fraud Twice as Often

A new industry survey found that finance teams running mostly manual accounts payable processes lost money in 42% of known payment fraud attempts, compared with 22% for teams that mix automation with manual review, according to the Yooz 2026 Payment Fraud Readiness Report. The same survey found that 70% of finance professionals said their organization experienced a payment fraud attempt in the past two years or could not rule one out. If your AP process is still mostly a person opening emails, matching amounts by eye, and clicking approve, this data says the odds are running against you.

What did the new payment fraud survey find?

The Yooz 2026 Payment Fraud Readiness Report, based on a third-party survey of finance professionals, broke fraud outcomes down by how AP is run:

  • Organizations with mostly manual AP processes lost money in 42% of known fraud attempts.
  • Organizations using a mix of automated and manual review lost money in 22% of known fraud attempts.
  • Highly automated teams lost money in 30% of known fraud attempts, worse than the mixed group.
  • Across all respondents, 28% of organizations with a known fraud attempt lost money, and 39% of those losses were $50,000 or more.

Two numbers matter for how you read this. First, manual AP loses money to fraud almost twice as often as a mixed manual-and-automated setup. Second, and easy to miss: pure automation on its own didn't outperform the mixed group. That second point is the real story, and the survey summary alone doesn't explain it. It comes down to what the automation is actually checking.

Why do manual AP processes lose money in fraud attempts almost twice as often?

A manual review depends on one person doing several jobs at once under time pressure: reading the invoice, remembering what the vendor normally charges, checking whether a bank account looks right, and deciding whether the amount matches what was agreed. Any one of those steps can slip on a busy Friday, and a fraudulent invoice only has to get past all of them once.

Most manual processes check the invoice against a purchase order total or a rough sense of "does this vendor usually bill us this." They rarely check it against the actual contract terms: the rate card, the statement of work, the not-to-exceed clause. That gap is exactly where a padded subcontractor invoice or a changed bank account slips through, because nothing in the process is set up to catch it.

The uncomfortable finding is that automation alone doesn't fix this. A workflow tool that scans and routes invoices faster, without checking them against anything, just moves the same unverified invoice through the approval chain more quickly. That is likely why highly automated teams in the survey still lost money in 30% of known fraud attempts: automation that speeds up approval without adding verification can make a bad invoice move faster, not stop it.

Which control points does a manual review usually skip?

Four checkpoints tend to get skipped or shortcut in a mostly manual process:

  1. Bank and payee verification. A changed bank account on an invoice email is one of the most common payment fraud patterns, and a manual reviewer usually has no independent way to confirm the new account belongs to the real vendor. Quittance's writeup on a $67,000 fake invoice scam walks through exactly this pattern.
  2. Matching against the whole agreement, not just the PO. A PO total can match perfectly while the line items still violate the rate card or bill hours that were never in the SOW. See what invoice matching software actually checks for how 2-way, 3-way, and 4-way matching differ, and where each one stops looking.
  3. Duplicate detection across channels. The same invoice submitted by email and again through a vendor portal, weeks apart, is easy for a person to miss and easy for a fraud attempt to exploit.
  4. Threshold parking. An amount set just under an approval limit, so it never reaches a second reviewer, is a pattern a spreadsheet-based review has no systematic way to flag.

What does "automated" actually need to include to close the gap?

Optical character recognition (OCR) reads the text on an invoice. It does not check whether the amount is allowed, whether the payee is who they claim to be, or whether the invoice cites a PO that exists. A lot of what gets called "AP automation" stops at OCR plus a routing workflow, which is why the survey's automated group still lost money in nearly a third of fraud attempts.

Closing the gap the data points to takes verification, not just speed:

  • Matching each invoice line against the contract, SOW, and rate card it was issued under, not only the PO header total.
  • Confirming payee and bank details against what's on file before anything is approved.
  • Flagging an invoice that cites a PO or agreement that doesn't exist, rather than letting a missing reference pass silently.
  • Keeping every flag traceable to the specific clause or record it violated, so a reviewer isn't taking the system's word for it.
Control tierChecks PO totalChecks agreement terms (rate card, SOW)Verifies payee / bank detailsFlags threshold parking
Mostly manual reviewSometimesRarelyRarelyNo
OCR + routing automationUsuallyRarelyRarelyNo
Agreement-level matchingYesYesYesYes

A quick self-check: does your process have these gaps?

Run through this list against your last month of AP:

  • Could a reviewer tell you, without checking a contract, what a subcontractor's approved hourly rate is?
  • Would a bank account change on an invoice get verified against anything other than the invoice itself?
  • Is there a step that checks whether an invoice's stated PO number actually exists?
  • Could two copies of the same invoice, submitted through different channels, both get approved?

If you answered "no" or "not sure" to more than one, that's the gap the Yooz data is describing, not a hypothetical one.

FAQ

Does more automation always mean less fraud risk?

No. The Yooz 2026 Payment Fraud Readiness Report found highly automated teams lost money in 30% of known fraud attempts, worse than the 22% for teams using a mix of automation and manual review. Automation that speeds up approval without verifying the invoice against the agreement or the payee can move a fraudulent invoice through faster, not stop it.

What is a rate-card violation, and why doesn't a PO match catch it?

A rate-card violation is when an invoice bills a rate, hours, or expense type that the contract or rate card doesn't allow, even though the total may still fall within an approved PO amount. A PO match checks the total against a budget line; it does not check the rate against the contract terms behind that PO, which is why this kind of overbilling often passes a standard 3-way match. See how invoice matching software works for the difference between PO-level and agreement-level checks.

Can invoice fraud happen even when there's a valid PO on file?

Yes. A fraudulent invoice can reference a real PO number and still be for the wrong vendor, the wrong bank account, or an amount padded above what was agreed. A PO's existence only confirms that a purchase was authorized in general, not that this specific invoice, payee, and amount are legitimate.

How much do duplicate and erroneous payments typically cost a company?

APQC benchmarking on accounts payable puts duplicate or erroneous payments at roughly 0.8% to 2% of total annual disbursements, a leak that doesn't show up as a single dramatic fraud case but adds up steadily across every payment run.

What's the first thing to fix if our AP process is mostly manual?

Start by checking what your process verifies today beyond the PO total: bank and payee details, agreement terms like rate cards and SOWs, and duplicate submissions across channels. Measuring where AP leakage is actually happening is a useful first step before deciding what to automate.

One next step

The pattern in this data isn't that manual AP teams are careless. It's that a manual process checks the invoice against the PO and a person's judgment, and rarely against the whole agreement behind the purchase. That's the specific gap Quittance is built to close: it checks each invoice line against the contract, SOW, and rate card it was actually issued under, and confirms the payee and bank details before anything posts as a draft bill in Xero for a person to approve. If you want to see where your own process has this gap, measuring your current AP leakage is the place to start.