---
title: "Accounts Receivable Fraud: Warning Signs and Internal Controls"
canonical: "https://searchreceivables.com/blog/accounts-receivable-fraud-warning-signs-internal-controls"
date: "2026-10-02"
author: "Jeffery Hartman"
categories: ["Receivables Management"]
---

# Accounts Receivable Fraud: Warning Signs and Internal Controls

> A B2B receivables risk can surface in customer records, billing, payments, credits, or reporting. Learn which warning signs to verify and how to document practical controls.

Accounts receivable (AR) fraud is the deliberate manipulation of a business’s billing, customer or remittance records, payment application, adjustments, or supporting documents for improper gain. In B2B credit-to-cash, risk can arise before an invoice is issued, while a payment is handled, or when a credit, refund, or write-off is approved. An overdue balance, ordinary billing error, customer dispute, or unusual entry is not proof of fraud; it is a reason to verify the facts.

> Key Takeaways 
> 
> 
> 
> - Treat unusual payment or account changes as verification triggers, not accusations.
> 
> - Review receipts, cash application, credits, write-offs, and reconciliation, not invoices alone.
> 
> - Separate authorization, custody, posting, and review where practical; use documented independent checks when team size limits full separation.
> 
> - Keep the evidence trail: source documents, approvals, change history, bank or lockbox records, and exception follow-up.

## What counts as accounts receivable fraud?

For this article, accounts receivable fraud means deliberate misuse or manipulation of a B2B receivables process or its records to obtain an improper advantage or conceal a diversion. This is an operational description, not a universal legal or accounting definition. Legal treatment depends on the parties, transaction, governing documents, jurisdiction, and facts.

The cited FBI, FTC, and GAO materials below are U.S. sources. These examples are general education, not a legal conclusion, accounting opinion, or investigation manual.

A missed posting can be an error. A disagreement over delivery, price, or contract terms can be a dispute. A customer paying late is a credit or collection issue. A write-off may be an ordinary accounting action. None of those facts, alone, establishes intent. The [Accounts Receivable Management glossary entry](https://searchreceivables.com/glossary/accounts-receivable-management) covers the broader discipline; the [Commercial Receivables glossary entry](https://searchreceivables.com/glossary/commercial-receivables) explains the B2B context.

A fake supplier invoice that a company is tricked into paying is usually an accounts-payable control problem. The [FTC’s small-business scam guide](https://www.ftc.gov/business-guidance/resources/scams-your-small-business-guide-business) describes phony invoices and recommends clear approval procedures. A similar impersonation tactic can affect AR if a customer is directed to pay an impostor or the creditor’s remittance instructions are changed. The FBI’s [Business Email Compromise guidance](https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise) includes a vendor invoice with changed payment details; that is an adjacent payment-fraud example, not evidence of AR-fraud frequency.

## Where can fraud risk enter the B2B credit-to-cash process?

These are practical risk surfaces, not claims that fraud is common at each stage.

### Customer and remittance records

Review who can create or edit customer records, payment instructions, addresses, credit limits, and refund details. An unexpected remittance change warrants independent verification. Check who requested, approved, and entered it, and whether the system retained the old and new values. A customer’s payment credentials and a seller’s instructions for where customers should remit are different records; do not treat them as interchangeable.

### Invoice creation and support

Connect each invoice to an approved customer relationship and supporting evidence, such as an order, contract, delivery record, or accepted service. Investigate duplicates, numbering gaps, altered terms, and invoices that do not match their source documents. A mismatch may be a clerical or system issue; establish which record governs before concluding anything.

### Receipt, cash application, and adjustments

Trace receipts from bank, lockbox, or processor records into the cash log and customer ledger. Then trace selected ledger entries back to the source payment. Look for missing or misapplied receipts, unexplained unapplied cash, refunds that do not return to the original payer, and later credits or write-offs without support. Each can have an ordinary explanation, such as timing, incomplete remittance detail, a short payment, or a real dispute.

### Reconciliation and reporting

Compare the AR subledger with the general-ledger control account, and reconcile relevant bank or lockbox activity to recorded receipts. Review unusual manual entries, aged unapplied receipts, late-period credits, repeated reversals, and overrides. The [aging-schedule audit guide](https://searchreceivables.com/blog/the-aging-schedule-audit-forensic-analysis-of-delinquency-buckets) addresses aging analysis in more depth; this article focuses on the control questions behind an exception.

## Which warning signs should a team verify?

A useful red-flag list points to evidence that can confirm or rule out a concern. It does not label a person or customer as dishonest.

- Payment or remittance instructions change unexpectedly, arrive through a new channel, or come with pressure to bypass normal approval.

- A sender address, domain, or contact detail differs slightly from the established record.

- An invoice, credit memo, refund, or write-off is duplicated, out of sequence, backdated, altered, or missing its usual support.

- One user can initiate and approve a material change, post receipts, issue refunds, and reconcile the balance without an independent check.

- Bank, lockbox, processor, and AR records do not agree; cash remains unapplied without a documented reason.

- Manual entries, unusual credits, repeated reversals, customer-master changes, or credit-limit exceptions cluster around an account or period.

- A customer says it paid, but the ledger has no matching receipt or the payment instructions used differ from the verified record.

Urgency and lookalike contact details are recognized impersonation signals in the [FBI’s BEC guidance](https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise). Verify a change through a known contact channel already on file or independently sourced, not by replying to the request or using a phone number it supplies.

Employee behavior alone is not a sound basis for an accusation. A late login, unusual schedule, or reluctance to take leave may have ordinary explanations. Focus on transaction evidence, permissions, approvals, system logs, and independent confirmations, then use the organization’s established review process.

## Which controls help reduce exposure?

Control design should fit transaction volume, systems, staffing, and risk. These are adaptable examples, not a guarantee that fraud can be prevented or a universal legal requirement.

### Separate duties, or add a compensating review

Where staffing permits, separate customer-master changes, invoice approval, receipt custody, cash application, credits or refunds, and bank reconciliation. If one small team cannot divide every task, document an independent review. For example, an owner or controller who did not post the transaction can review the reconciliation and a report of manual adjustments.

Syracuse University’s [cash-receipt and revenue control guidance](https://finance.syr.edu/audit/general-internal-controls/internal-controls-for-cash-receipts-and-revenue/) illustrates separation of collection, deposit, and reconciliation, and management review where staff limits full segregation. It is university-specific guidance, not a rule for every business.

### Verify changes independently

For a new or changed payment instruction, use a contact method already verified in the organization’s records or an independent source. Record who verified and approved the change, the channel used, and when the system record changed. Do not let an email thread authenticate itself.

[The FBI recommends independent confirmation of changed account numbers or payment procedures](https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise) and prompt contact with a financial institution if a BEC-related transfer may have occurred. Apply that guidance to the scenario it describes; a changed instruction is not automatically fraud.

### Keep evidence and approvals with adjustments

Require support for invoices, credit memos, discounts, refunds, write-offs, and manual journals. Apply the organization’s approval limits; avoid giving the same user the ability to initiate and approve a material adjustment. Retain the request, supporting records, decision, and posting history. [Syracuse’s guidance on cash-receipt and AR controls](https://finance.syr.edu/audit/general-internal-controls/internal-controls-for-cash-receipts-and-revenue/) offers institution-specific examples, including pre-numbered invoices, an AR subsidiary ledger, review of aging, and management authorization of credits and write-offs.

### Reconcile, review exceptions, and limit access

Set a documented schedule for reconciling receipts and the AR subledger to the relevant control accounts. Frequency should reflect transaction volume, payment channels, and risk. The reviewer should sign off, assign unresolved differences, and confirm they were cleared with evidence. Review aging and unapplied-cash reports; an ending balance that looks reasonable does not prove the underlying transactions were valid.

Use role-based permissions for customer records, payment instructions, refunds, write-offs, and manual journals. Review privileged access and overrides, remove access promptly when roles change, and retain logs showing who changed a record and when. Multifactor authentication can reduce account-takeover exposure where available, but it does not replace approvals or reconciliations.

GAO’s 2025 [Standards for Internal Control in the Federal Government](https://www.gao.gov/products/gao-25-107721), known as the Green Book, describes risk-based control design, preventive and detective activities, and segregation of duties. It became effective beginning with federal fiscal year 2026 and sets standards for federal agencies. A private business may use it as a reference, but it is not a private-company mandate.

For related process context, see the site’s [accounts receivable control framework](https://searchreceivables.com/blog/the-ar-management-protocol-the-5-c-s-the-lifecycle-and-the-golden-rules) and [receivables optimization guide](https://searchreceivables.com/blog/the-liquidity-engineering-mandate-protocols-to-optimize-receivables). Faster processing is useful only when supporting records and review remain reliable.

## How can a team test whether controls work?

Follow transactions in both directions: from source documents into the ledger, and from bank or lockbox evidence back to the ledger. A focused check can:

- Select items from risk areas in scope, such as payment changes, manual credits, write-offs, refunds, and unapplied cash.

- Trace invoices to the order or contract and evidence of delivery or service. Compare amount, terms, approval, and posting.

- Trace receipts from the bank, lockbox, or processor through the cash log to customer accounts, then trace selected ledger receipts back to source payments.

- Inspect change history and approvals for customer records, remittance details, credits, refunds, and write-offs.

- Check how exceptions were resolved and record the population, sample method, source records, reviewer, and follow-up.

A sample can identify issues; it does not prove that no other issue exists. The [document-management and audit-readiness guide](https://searchreceivables.com/blog/the-chain-of-custody-protocol-ar-document-management-audit-defense) explains how to preserve organized support for a review.

## What should a team do when it suspects a problem?

Do not accuse a customer or employee based on a red flag alone. Preserve original messages, invoice versions, system logs, approval history, bank or processor records, and customer communications. Avoid changing or deleting records that may explain the sequence of events.

Use the organization’s escalation process, which may involve the controller, treasury, internal audit, information security, compliance, or outside counsel. If funds may have moved after a suspected BEC request, contact the financial institution promptly, consistent with the FBI’s public guidance. The next steps can depend on payment method, contract, facts, and applicable rules; this article does not set legal duties or reporting deadlines.

Where policy permits, pause only the affected change or transaction while it is checked. Document the decision, independent verification, and corrective action. Avoid broad account freezes or public conclusions that are not supported by the evidence.

## What do the available fraud statistics say?

[ACFE’s Occupational Fraud 2026: A Report to the Nations ](https://www.acfe.com/-/media/files/acfe/pdfs/rttn/2026/2026-report-to-the-nations.pdf) describes 2,402 usable cases from 10,276 responses to its 2025 Global Fraud Survey. Respondents supplied their single largest occupational-fraud case investigated between January 2024 and September 2025. Cases had to involve occupational fraud, have a completed investigation, and meet respondents’ confidence that the perpetrator had been identified; the report covers 143 countries and territories.

For the question on primary internal-control weaknesses, [the ACFE report lists](https://www.acfe.com/-/media/files/acfe/pdfs/rttn/2026/2026-report-to-the-nations.pdf) lack of internal controls in 33% of responses, override of existing controls in 19%, and lack of management review in 18%. It says denominators vary by question because blank and unknown answers are excluded. These figures describe selected investigated occupational-fraud cases, not a random sample of companies, not an estimate of B2B AR-fraud frequency, and not proof that any one control caused a particular outcome.

## A practical standard: verify, document, review

AR fraud controls work best when they cover the full process, not invoice approval alone. Verify material changes through an independent channel, fit access and review to the team, reconcile receipts and balances, and retain the evidence behind adjustments. An anomaly is a question to investigate, not a conclusion.

Browse the [Receivables & Credit topic hub](https://searchreceivables.com/topics/receivables-and-credit) for related research.

## Sources

- [ACFE, Occupational Fraud 2026: A Report to the Nations ](https://www.acfe.com/-/media/files/acfe/pdfs/rttn/2026/2026-report-to-the-nations.pdf) — case methodology and internal-control findings.

- [FBI, Business Email Compromise](https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise) — payment-instruction impersonation and verification guidance.

- [GAO, Standards for Internal Control in the Federal Government (GAO-25-107721)](https://www.gao.gov/products/gao-25-107721) — federal control framework, scope, and effective date.

- [Syracuse University, Internal Controls for Cash Receipts and Revenue](https://finance.syr.edu/audit/general-internal-controls/internal-controls-for-cash-receipts-and-revenue/) — institutional examples of receipt, reconciliation, AR, and approval controls.

- [FTC, Scams and Your Small Business: A Guide for Business](https://www.ftc.gov/business-guidance/resources/scams-your-small-business-guide-business) — fake-invoice and invoice-approval guidance.

---
*Original canonical URL: [https://searchreceivables.com/blog/accounts-receivable-fraud-warning-signs-internal-controls](https://searchreceivables.com/blog/accounts-receivable-fraud-warning-signs-internal-controls)*