Business fraud has always existed, but the way it happens is changing quickly. In the past, many scams were easier to spot. Emails were badly written, sender addresses looked suspicious, and fake invoices often had obvious mistakes. Today, fraud is becoming more convincing.
Criminals can now use artificial intelligence to write professional emails, imitate communication styles, create fake documents, clone voices, and produce deepfake video or audio content. This makes impersonation fraud harder to detect, especially when businesses rely heavily on email approvals, remote working, online payments, and fast decision-making.
For companies, this is no longer only a cybersecurity issue. It is a financial control issue.
AI-Driven Impersonation and Executive Fraud
The European Payments Council's 2025 Payments Threats and Fraud Trends Report warned that fraudsters are using AI to create highly convincing phishing messages, SMS scams, and even voice or video deepfakes. The report specifically noted that these tools can help attackers impersonate executives, bank employees, or trusted contacts with much greater realism. The practical risk for businesses is clear: staff may be persuaded to approve payments, change bank details, disclose information, or bypass normal procedures because the request appears legitimate.
Europol has also highlighted the growing role of AI in organised crime. Its 2025 Serious and Organised Crime Threat Assessment noted that AI-powered voice cloning and live video deepfakes can enable new forms of fraud, extortion, and identity theft. This is particularly concerning for businesses because trust is often built around familiar names, voices, and relationships.
Invoice Fraud and Social Engineering
Invoice fraud is one of the most relevant risks for companies. A fraudster may intercept communication between a business and a supplier, then send updated bank details before payment is made. The invoice may look real, the email may appear to come from the supplier, and the amount may match an expected transaction. If internal controls are weak, the business may only discover the fraud after funds have already been transferred.
This type of fraud is dangerous because it does not always require hacking into complex systems. Often, it relies on social engineering. The criminal manipulates people, not just technology.
Authorised Push Payment Fraud
Authorised push payment fraud is another important example. This occurs when a victim is tricked into sending money to a fraudster. UK Finance's Annual Fraud Report 2025 reported that authorised push payment fraud losses in the UK were just over £450 million in 2024, although overall losses and cases had fallen compared with the previous year. The fact that losses remain so high shows how serious the issue continues to be, even where banks and financial institutions are investing heavily in fraud prevention.
For businesses, the lesson is not only that fraud is increasing or becoming more advanced. The lesson is that traditional controls may no longer be enough.
A payment request may appear to come from the managing director. A supplier email may look normal. A phone call may sound familiar. A PDF invoice may contain the correct branding. A message may refer to real projects, real clients, and real amounts. In this environment, businesses cannot rely only on instinct.
They need process.
Internal Controls and Verification

Strong internal controls are one of the best protections against fraud. This includes proper segregation of duties, payment approval thresholds, supplier verification procedures, dual authorisation for bank detail changes, and clear escalation rules for urgent or unusual requests. If you are unsure whether your current procedures would withstand a convincing impersonation attempt, an accounting health check can help surface the gaps before they are exploited.
One practical control is to verify any change in supplier bank details through a separate communication channel. If new bank details are received by email, the business should not reply directly to that email. It should contact the supplier using a trusted phone number or contact already held on file. This simple step can prevent serious losses.
Another important control is dual approval for payments above a certain value. No single person should be able to create, approve, and release significant payments without review. This is especially important for SMEs, where teams may be small and informal approval habits can develop over time.
The table below summarises how common fraud techniques map to the practical controls that help defend against them.
| Fraud technique | Practical control |
|---|---|
| Changed supplier bank details by email | Verify the change through a separate, trusted channel held on file |
| Impersonated executive or supplier payment request | Segregation of duties and dual authorisation above a set threshold |
| Urgent, confidential or "avoid consequences" pressure | Treat urgency as a warning sign; clear escalation rules |
| Intercepted invoice matching an expected amount | Supplier verification procedures and approval thresholds |
| Fraudulent or incorrect payment slipping through | Regular reconciliation and review of bank payments and balances |
Culture, Training, and Urgency
Businesses should also be cautious with urgent requests. Fraudsters often create pressure by saying a payment is urgent, confidential, delayed, or required to avoid consequences. Staff should be trained to recognise urgency as a warning sign rather than a reason to bypass controls.
This is where culture matters. Employees should feel comfortable questioning unusual requests, even if they appear to come from senior management. A good control environment does not punish staff for checking. It encourages them to verify.
Technology can also help. Email security tools, payment verification systems, accounting software controls, bank alerts, and fraud detection features can reduce exposure. However, technology should support controls, not replace them. A business can still lose money if staff are trained to override warnings or if approval procedures are unclear.
Public Information and Financial Review
The rise of AI-driven fraud also means businesses should review their use of public information. Criminals can use details from websites, social media, LinkedIn posts, company announcements, and public filings to make scams more believable. The more a fraudster knows about a company's staff, suppliers, projects, and communication style, the easier it becomes to create a convincing impersonation.
This does not mean businesses should stop communicating publicly. It means they should understand how public information can be misused and ensure internal procedures are strong enough to withstand convincing requests.
Financial reporting also plays a role. Regular review of bank payments, supplier balances, unusual transactions, and reconciliation differences can help identify issues earlier. If reconciliations are delayed, fraudulent or incorrect payments may remain unnoticed for longer. This is one area where having reliable accounting, tax and advisory support keeps the numbers current enough to spot anomalies quickly.
Governance and the Cost of Fraud
For directors, fraud prevention should be treated as part of governance. The question is not whether staff are trustworthy. The question is whether the business has controls that protect both the company and its employees from manipulation.
A well-designed process protects everyone. It gives staff a clear reason to verify requests, reduces pressure on individuals, and creates a documented trail of approvals.
The cost of fraud can be more than the amount stolen. It can include disruption, legal costs, insurance issues, reputational damage, supplier disputes, management time, and weakened trust inside the business. For smaller companies, even one fraudulent payment can create serious cash flow pressure.
Fraud is becoming more sophisticated, but many of the best defences remain practical. Verify changes. Separate duties. Approve payments properly. Train staff. Review transactions. Keep supplier records updated. Question urgency. Document processes.
Businesses do not need to become experts in every fraud technique. They do need to build a control environment where fake requests are less likely to succeed.
In a world where emails, voices, invoices, and even video calls can be manipulated, trust alone is no longer enough.
Businesses need verification.
If you would like help reviewing your payment and supplier controls, speak to an advisor before the next convincing request lands in your inbox.
