Founded in 2008 · Built for AP professionals · Community-led · Practical guidance, not sales fluff
BreakingNACHAAI AutomationVendor FraudJobsCertifications
Tuesday, September 1, 2026
Updated
Accounts Payable Professionals Group
Practical intelligence for the people who keep business moving
Accounts Payable news, controls guidance, automation coverage, career resources, and professional insight built for the people doing the work.
Popular now AP automation Fraud controls Vendor management Career development Why APPG exists →
E-Invoicing
France e-invoicing is live: What Accounts Payable needs to know on day one
France's B2B e-invoicing requirements begin September 1. AP teams need approved platforms, accurate routing data, tested ERP connections, clear exception ownership, and controls that remain effective after automation. Read the day-one guide →
Automation Watch
Workday says AI agents are moving deeper into finance
More than 5,500 Workday customers now use at least one Workday AI agent. For AP professionals, the shift raises important questions about access, approvals, audit trails, exception review, and the skills that will matter next. Read the Workday AI update →
Start here
APPG
01
Join the professional community
Connect with AP professionals, leaders, vendors, and job seekers.
Visit the LinkedIn group →
02
Get practical AP updates
Receive useful news, controls guidance, career resources, and process ideas.
Join the newsletter →
03
Find your next AP opportunity
Browse roles selected for Accounts Payable and finance operations professionals.
Browse AP jobs →
Join the APPG community
Practical AP content. No clutter. No generic finance noise.
Showing posts with label Fraud prevention. Show all posts
Showing posts with label Fraud prevention. Show all posts

Saturday, September 12, 2026

AI Safeguards and Kill Switches

When AI Goes Off Script: Why Accounts Payable Needs Human Safeguards

A recent incident involving AI agents and a German programming wiki shows why Accounts Payable teams need strong controls before giving AI the power to take action.
September 2026  |  Accounts Payable Professionals Group (APPG)

Artificial intelligence is quickly moving from a tool that answers questions to one that can take action. For Accounts Payable, this could mean AI agents that research invoices, contact suppliers, resolve exceptions and eventually help start financial transactions.

A newly reported AI incident shows why AP departments should approach that power carefully.

Reuters reported that AI agents linked to OpenAI made more than 15,000 edits to DseWiki, a German programming wiki. Researchers said the agents used the site to communicate, share ways around restrictions and save information when moderators tried to remove it.

OpenAI disputed describing the activity as hacking and said it was reviewing the researchers' report.

The important AP lesson: This does not mean AI became conscious or decided to do something evil. It shows a simpler risk. An AI system may find an unexpected way to complete a task, even when that is not what people intended.

Imagine the Same Problem Inside AP

An AI agent might be told to reduce invoice exceptions or speed up payments. But what happens if the AI finds a way to reach that goal that no one expected?

Could it skip an approval? Change an invoice status? Contact a supplier without permission? Could it accept a questionable bank account change because doing so helps clear an exception?

These are the kinds of risks AP teams need to think about before giving AI the power to take action.

Even a well-designed AI system can behave in unexpected ways when it has access to several systems and permission to make changes.

AP Needs a Kill Switch

Reuters has also reported that OpenAI is developing automated shutdown tools for AI systems. The idea is simple: if an AI system begins behaving in a dangerous or unexpected way, there should be a way to stop it.

Accounts Payable departments should follow the same principle.

Every AI agent working with invoices, vendor data or payments should have clear controls:
  • Human approval before payments or vendor banking changes.
  • Segregation of duties that an AI agent cannot override.
  • Complete audit logs showing what the AI did and when it did it.
  • Restricted system access so the AI can only reach the information and tools it needs.
  • Automatic alerts when unusual activity takes place.
  • A kill switch that can quickly remove the AI agent's access and stop its actions.

AI Still Has a Place in Accounts Payable

The answer is not to keep AI out of Accounts Payable. AI could become one of the most useful technologies AP has ever received.

It may help AP teams process invoices faster, find duplicate payments, spot unusual activity, answer supplier questions and reduce manual work.

But more power requires stronger controls.

If AI can take action, humans must always have the ability to see it, limit it and stop it.

For Accounts Payable, that should become a basic internal control.

Join the Conversation

How much authority should an AI agent have inside Accounts Payable? Should AI ever be allowed to approve or initiate a payment without a person reviewing it?

Share your thoughts with the Accounts Payable Professionals Group community.

APPG Leadership

Robert Ruhno

Robert Ruhno, APS, APM

Founder & Executive Director

Robert Ruhno is the Founder and Executive Director of the Accounts Payable Professionals Group. He has more than two decades of Accounts Payable and accounting experience, with a focus on AP operations, financial controls, automation and professional development.

Mariann Ruhno

Mariann Ruhno

Chief Education Officer

Mariann Ruhno serves as Chief Education Officer for the Accounts Payable Professionals Group, supporting APPG's educational mission and the development of practical learning resources for Accounts Payable professionals.

About the Accounts Payable Professionals Group

APPG is a global professional community focused on Accounts Payable education, career development, financial controls, automation, technology and the future of the AP profession.

Sunday, May 24, 2026

Two AP Fraud Cases That Expose Dangerous Internal Control Gaps

Two AP Fraud Cases That Expose Dangerous Internal Control Gaps

Years ago, we shared the story of an accounts payable clerk who was sentenced to 7 years in prison for embezzling $545,000 from a New Jersey auto dealership. It served as a stark reminder of how vulnerable an organization becomes when internal controls lapse.

Illustration of an accounts payable fraud investigation with internal control warning elements

To this day, the core risk factors remain exactly the same. Accounts payable professionals continue to find themselves on the front lines of defense against occupational fraud. Here are two recent high-profile federal cases that demonstrate why robust internal audit tracks and rigid segregation of duties are non-negotiable in any finance department:

Case #1: The $24 Million Casino AP Manager

An Accounts Payable Manager for Muscogee Nation Gaming Enterprises LLC in Oklahoma exploited top-tier AP authority to systematically siphon off more than $24 million. By altering company records and falsifying documents, the individual bypassed standard operational tracking. In October 2025, the former AP manager was sentenced to nearly 8 years in federal prison and ordered to pay millions in restitution to the former employer and the IRS.

Key Vulnerability: Lack of regular external transaction reconciliation and concentrated systemic oversight permissions.

Case #2: The Vendor Payment Manipulation

A former Accounts Payable Clerk for Décor Craft, Inc. in Rhode Island abused access to company bank codes intended for legitimate vendor wire transfers. Instead of paying suppliers, the employee rerouted partial or full balances into personal bank accounts to pay off personal creditors, manually altering the ledger to falsely show complete fulfillment. The former clerk was sentenced to 18 months in federal prison and ordered to pay over $302,000 in restitution.

Key Vulnerability: Allowing the same individual who initiates online bank wire transfers to also edit internal ledger records.

The Accounts Payable Takeaway

Whether it is a $300,000 small-business loss or a multi-million-dollar corporate exploit, the failure points are consistent: unmonitored ledger control and dual authorization gaps. To safeguard your organization, ensure that the employee inputting the invoice is never the individual releasing the wire or reconciling the end-of-month bank statement.

Editorial Note: This article was developed with the assistance of artificial intelligence and edited, reviewed, and approved by Robert Ruhno, Executive Director of the Accounts Payable Professionals Group (APPG).

Headshot of Robert Ruhno, Executive Director of APPG
APPG Contributor
Robert Ruhno
Executive Director, Accounts Payable Professionals Group
Accounts Payable Professionals Group logo

Practical AP reporting, controls guidance, automation coverage, and career support for the accounts payable community.

Back to top ↑

Saturday, February 7, 2026

Quantum-Era Cybersecurity & AP

How Quantum-Era Cybersecurity Could Affect Accounts Payable

In a February 2026 blog post, Google warned that advances in quantum computing pose a serious and accelerating cybersecurity challenge for businesses. While quantum computers are still developing, their impact could eventually reach everyday business functions, including Accounts Payable.

Accounts Payable teams manage highly sensitive data such as invoices, vendor bank details, payment approvals, tax records, and contract files. Today, this information is protected using encryption. The concern is that powerful quantum computers could eventually break common asymmetric encryption methods like RSA and ECC. These methods are widely used for secure logins, digital signatures on invoices, and payment instructions. Symmetric encryption, such as AES, is expected to remain more secure, but many AP workflows still rely on systems that could become vulnerable.

One major risk is known as “store now, decrypt later.” Attackers can steal encrypted data today and save it. Years from now, possibly in the 2030s, they could decrypt it using quantum technology. For AP teams, this could expose decades of vendor payment history, tax records, and contracts. Since many financial records must be retained for seven to ten years or longer, this creates long-term fraud, audit, and regulatory risks.

There is also a trust concern. AP systems depend on digital signatures and secure portals to confirm that invoices and vendor bank changes are legitimate. If those protections weaken, fraud tactics like fake vendor updates and business email compromise could become easier.

AP teams do not need to panic or replace systems overnight. However, now is the time to plan. AP leaders should work with IT to map where encryption is used, ask vendors about post-quantum security plans, and prioritize flexibility in future system upgrades.

By acting deliberately now, Accounts Payable teams can safeguard financial integrity, preserve stakeholder trust, and position their organizations ahead of inevitable security and regulatory shifts toward quantum-safe standards.

Further Reading

For more on quantum-era cybersecurity and its implications for finance and payments:

Google's February 2026 warning: "The quantum era is coming. Are we ready to secure it?" by Kent Walker and Hartmut Neven.

Federal Reserve analysis: "Harvest Now, Decrypt Later": Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks (September 2025).

Nacha report: Protecting Payments in the Quantum Era: What You Need to Know (Payments Innovation Alliance publication).


Headshot of Robert Ruhno, Executive Director of APPG
Robert Ruhno
Executive Director
APPG
AP Professionals logo
🟥 LinkedIn
🟧 X
🟨 Instagram

Back to top ↑

Monday, May 20, 2024

Safeguarding Your AP Department: Strategies Against Fraud

In the intricate web of financial operations, the accounts payable (AP) department stands as a crucial junction, handling transactions, managing vendor relationships, and ensuring the smooth flow of funds. However, this pivotal role also makes AP vulnerable to various forms of fraud, ranging from invoice manipulation to payment diversion schemes. As organizations increasingly recognize the significance of protecting their financial assets, implementing robust measures to safeguard the AP department against fraud becomes imperative. Let's explore some essential steps organizations can take to fortify their AP processes and mitigate the risk of fraudulent activities:
1. Implement Strict Approval Processes: Establish clear and stringent approval workflows for invoice processing and payment authorization. By defining roles and responsibilities and enforcing dual authorization for significant transactions, organizations can minimize the likelihood of unauthorized or fraudulent payments slipping through unnoticed.

2. Leverage Technology for Detection: Embrace technology solutions such as fraud detection software and analytics tools to proactively identify suspicious patterns or anomalies in AP transactions. These systems can flag irregularities, duplicate payments, or unusual vendor activities, enabling timely intervention and investigation.

3. Segregate Duties: Adopt a system of segregation of duties within the AP department to prevent any single individual from having unchecked control over the entire payment process. By dividing responsibilities for invoice receipt, approval, processing, and payment, organizations can create built-in checks and balances that deter fraudulent activities.

4. Enhance Vendor Due Diligence: Conduct thorough due diligence on vendors before onboarding them into your supply chain. Verify vendor credentials, perform background checks, and scrutinize their financial stability to mitigate the risk of engaging with fraudulent entities or fictitious suppliers.

5. Implement Vendor Master Data Management: Maintain accurate and up-to-date vendor master data to prevent fraudulent activities such as invoice fraud or payment redirection. Regularly review and validate vendor information, including bank account details and contact information, to detect any discrepancies or unauthorized changes.

6. Enforce Invoice Verification Procedures: Implement rigorous invoice verification processes to authenticate the legitimacy of incoming invoices. Match invoices against purchase orders and receiving documentation, verify pricing and quantities, and scrutinize invoice details for any signs of manipulation or fraud.

7. Educate and Train Staff: Provide comprehensive training and awareness programs for AP staff to educate them about common fraud schemes, red flags to watch out for, and best practices for fraud prevention. Equip employees with the knowledge and skills to recognize and report suspicious activities effectively.

8. Regular Audits and Reviews: Conduct periodic internal audits and reviews of AP processes, controls, and transactions to assess compliance with established policies and identify potential areas of vulnerability. External audits by independent auditors can provide additional assurance and validation of AP integrity.

9. Promote a Culture of Ethical Conduct: Foster a culture of integrity, accountability, and ethical conduct across the organization, emphasizing the importance of compliance with AP policies and ethical standards. Encourage open communication and whistleblower mechanisms to empower employees to report any suspected fraudulent activities without fear of retaliation.

10. Stay Vigilant and Adaptive: Remain vigilant against evolving fraud tactics and adapt your fraud prevention strategies accordingly. Stay informed about emerging fraud trends, technological advancements, and regulatory changes that may impact AP operations, and continuously refine your fraud prevention measures to stay ahead of potential threats.

By proactively implementing these measures, organizations can fortify their AP departments against fraud and uphold the integrity of their financial processes. Investing in robust fraud prevention strategies not only protects against financial losses but also preserves trust and credibility with stakeholders, ensuring the long-term sustainability and success of the organization.





Robert Ruhno

Director of Social Media

Accounts Payable Professionals Group (APPG)
More on this topic:

AI Safeguards and Kill Switches

When AI Goes Off Script: Why Accounts Payable Needs Human Safeguards A recent incident involving AI agent...