Accounts receivable fraud involves deliberately manipulating invoices, customer records, receipts or collections so money is misappropriated, concealed or diverted. In the UK, invoice scams caused £50.3 million in losses in the past year, with 70% affecting non-personal accounts, so a receivables irregularity deserves prompt attention rather than a routine correction.
The problem often arrives disguised as an ordinary finance task. A customer disputes an invoice, a balance appears overdue, or a payment lands in an unfamiliar account. The team wants to correct the ledger and move on, especially when month-end is approaching and nobody wants to accuse a colleague or valued customer without proof.
That hesitation creates risk. Employees, customers, suppliers and external fraudsters can all exploit gaps between invoicing, payment instructions, cash allocation and reconciliation. For SMEs, law firms, insurers and boards, the practical question isn't whether money has gone missing. It's whether the event represents an isolated payment diversion, systematic receivables leakage or collusion that has distorted the records.
When a Receivables Problem Becomes a Crisis
A 60-person distribution business in the Midlands first noticed a problem through its aged-debt report. The credit controller flagged a customer balance that should have disappeared after payment. The sales team treated it as a dispute, because the customer had a history of querying delivery dates. Finance then blamed a posting error, since the bank statement showed a receipt close to the expected amount.
The finance lead asked for the remittance advice. It matched the invoice number, but the payment had gone to a bank account that nobody recognised. A second review found a duplicate invoice with almost identical wording and formatting. The legitimate customer had paid one version, while the duplicate directed funds elsewhere.
The first anomaly looked manageable. The surrounding details were harder to dismiss. The customer had never queried an understated balance, the monthly bank reconciliation had been rushed, and one employee who handled invoicing and cash posting repeatedly resisted taking holiday or allowing colleagues to cover the process.
Practical rule: A correcting journal doesn't explain a missing payment. It only explains how someone changed the books afterwards.
Expand the review and protect the evidence
The finance lead expanded the review beyond that customer. The team compared invoice creation dates with dispatch records, traced payment instructions through email chains and checked who approved customer-master-data changes. They found a pattern of manual intervention around disputed accounts, but they didn't assume every irregularity had the same cause. Some entries reflected genuine delivery disputes. Others lacked supporting evidence.
That distinction matters during a crisis. A business needs to protect cash and evidence without turning an unresolved concern into an unsupported accusation. A structured response, like the approach used in crisis management consulting, can help leaders make decisions while operations continue.
The rest of this guide focuses on the practical work: defining accounts receivable fraud, recognising schemes, investigating suspicious transactions, quantifying loss and building controls that expose leakage earlier.
Understanding Accounts Receivable Fraud
Think of the receivables cycle as a chain. The business raises an invoice, delivers the goods or services, receives money, posts the receipt and clears the customer balance. Fraud occurs when someone deliberately interferes with one or more links to take money, hide a shortfall, redirect a payment or create a misleading financial picture.
The actor may sit inside the finance team, but the risk doesn't stop there. A customer might submit altered remittance details, a supplier or intermediary might redirect funds, and an external fraudster might impersonate a customer or employee through compromised email. Collusion can combine these behaviours, allowing one person to alter records while another benefits from the diverted payment.
An honest error can look similar on a ledger. A payment may remain unapplied because the remittance advice arrived late. A commercial dispute may leave an invoice open while the customer withholds payment. Deliberate manipulation adds intent and concealment. Investigators therefore examine the source documents, authorisation trail, communication history and benefit received, rather than treating an unusual balance as proof of wrongdoing.
Four pressure points in the cycle
Invoice creation creates an opportunity for fictitious customers, duplicate invoices, inflated quantities or altered bank instructions. The supporting question is simple: did the underlying sale happen, and did the customer receive the correct invoice through an independently verified channel?
Cash collection becomes vulnerable when staff handle payment instructions, receipts or bank details without a second check. Payment diversion may follow an email change that looks routine, particularly if the customer or finance employee expects a new account to be used.
Receipt posting allows lapping, skimming and concealment. A person who receives cash, applies it to customer accounts and performs the reconciliation can move payments between balances and make timing differences appear harmless.
Credits and write-offs can hide a missing receipt or favour a customer. A valid debt may receive an unsupported credit, or a fictitious receivable may disappear through a write-off that nobody independently approves.
The same ledger balance can result from very different events. A customer dispute requires commercial resolution. A posting error requires correction. A fraud investigation requires evidence preservation, scope assessment and careful escalation.
Recognising Common Fraud Schemes
The paper trail usually provides more useful answers than the ledger alone. Start with the invoice, delivery evidence, customer correspondence, remittance advice, bank transaction and approval record. Then compare who created, changed, posted and reconciled each item.
The following table provides a practical starting point. A warning sign doesn't prove fraud, but repeated signs linked to the same user, account, customer or period deserve targeted testing.
Common Accounts Receivable Fraud Schemes, Warning Signs and Control Weaknesses
| Scheme | Warning Sign | Control Weakness |
|---|---|---|
| Fictitious receivables | Invoices lack delivery, contract or customer confirmation | Inadequate sales-to-invoice verification |
| Altered or duplicated invoices | Similar invoices use different payment instructions or numbering | Weak invoice approval and master-data controls |
| Lapping | Repeated payment reapplications and unexplained timing differences | One person controls receipts, posting and reconciliation |
| Write-off abuse | Frequent credits or write-offs with vague explanations | No independent approval or threshold review |
| Payment diversion | Customer says it paid, but funds went to an unfamiliar account | Changes to payment details receive no secondary confirmation |
| Staff and customer collusion | Unusual discounts, delayed collection or coordinated explanations | Poor conflict checks and limited independent customer contact |
Test the records behind each warning sign
Fictitious receivables often leave operational gaps. The invoice may exist, but the dispatch note, signed delivery record or contract doesn't. Investigators should test the transaction outside the accounting system, because a convincing invoice proves only that someone entered data.
Duplicate and altered invoices require comparison. Look for near-identical descriptions, unusual numbering, changed bank details and messages that pressure staff to act quickly. Email compromise and payment diversion can sit alongside classic AR manipulation, not replace it.
Lapping moves one customer's payment to cover another customer's missing receipt. Reapplications, backdated postings and unexplained timing differences matter because the fraud depends on continuous concealment.
Write-off abuse can be harder to spot where managers approve adjustments informally. Review the reason, supporting correspondence, user history and subsequent customer activity. A write-off that resolves a genuine dispute should have a commercial record.
Payment diversion also connects receivables risk with wider cyber controls. Finance leaders reviewing ways to reduce disruption from cyber incidents should include email verification, access control and recovery procedures in the receivables process, not leave them solely to the IT team.
UK evidence shows why leaders should take invoice manipulation seriously. The Office for National Statistics recorded around 4.2 million fraud incidents in England and Wales in the year ending March 2025, up 31% from the previous year, and around 3 million involved a loss. The figures cover fraud broadly, rather than AR fraud alone, but they show the scale of the environment in which payment diversion operates. A wider view of business exposure is available in the five main fraud risks in business.
Investigating Suspicious Transactions
The first response should protect evidence and cash without alerting a potential suspect. Finance leaders often want to confront the employee immediately, delete the fraudulent bank instruction or “fix” the invoice. Those actions can destroy context, trigger data deletion or make later findings harder to defend.
Contain the immediate risk
Begin with the flagged transaction and preserve the original records. Save the invoice, remittance advice, bank entry, relevant emails, system audit logs and approval history in a controlled location. Don't rely on screenshots alone, and don't overwrite the original file with a corrected version.

Restrict access where necessary, but coordinate the decision with legal advisers and the person responsible for systems administration. Freeze further changes to payment instructions, write-offs or affected customer records. Keep ordinary collections and cash controls operating, because stopping all receivables activity can create unnecessary business interruption.
Create a contemporaneous decision log. Record what triggered the review, who authorised each action, what evidence the team secured and why the investigation's scope changed. A disciplined log helps insurers, regulators and courts understand the decisions made at the time, rather than relying on reconstructed memories.
Establish scope without tipping off
Request statements or payment confirmations from counterparties through independently verified contact details. Don't use the suspicious email chain as the sole source for a telephone number or bank instruction. Review linked transactions, user access, manual journals, customer-master-data amendments and periods where reconciliations fell behind.
Maintain confidentiality and take advice on tipping-off risks under UK anti-money-laundering rules. Solicitor involvement may help preserve legal privilege for appropriate communications, although the business should agree the investigation structure with legal counsel rather than assume every document attracts privilege.
External forensic accountants can test the records independently and quantify the loss. Legal counsel can advise on employment action, civil recovery, reporting and disclosure. Action Fraud or the police may become relevant depending on the facts, and the business should preserve the full email, invoice and communication trail. The National Crime Agency notes that only 14% of fraud cases are reported to Report Fraud or police, so internal records often carry significant importance when deciding how to escalate.
A specialist resource on payment fraud detection can help finance leaders frame the initial review. If an external party has disappeared or counterparties need independent contact, businesses may also consider regulated UK tracing agents, subject to legal advice and data-protection requirements.
Quantifying the Financial Loss
A credible loss figure starts with reconstruction, not estimation. Investigators should obtain the receivables ledger, invoice register, credit notes, write-off reports, bank statements, remittance information, delivery records and relevant contracts. They then test the movement from sale to receipt and identify where the expected cash diverged from the accounting record.
The analysis should match invoices to goods or services delivered. A valid invoice with no delivery evidence may represent a fictitious receivable. A delivered order with no corresponding receipt may indicate collection failure, diversion or a customer dispute. Bank tracing then tests whether money reached the company, a legitimate intermediary or an unauthorised account.
Separate the components of loss
A report should distinguish gross misappropriation from sums that may be recovered. If a customer or bank returns money, that recovery reduces the net loss, but it doesn't erase the original transaction or the cost of investigating it.
The working papers may need separate schedules for:
- Gross loss: the value of receipts diverted, assets misappropriated or valid balances written off without authority.
- Recoveries: money returned by a bank, customer, employee, insurer or other counterparty.
- Consequential effects: interest, bad-debt releases, collection costs, professional fees and operational disruption where the evidence supports inclusion.
- Tax treatment: VAT, corporation tax effects and the accounting treatment of bad debts or credit notes.
VAT needs particular care. A fraudulent invoice, a genuine supply followed by a theft, and a credit note issued to conceal a diversion can produce different tax consequences. The investigator should identify the accounting entry and leave legal or tax conclusions to the appropriate adviser where needed.
Make the figure defensible
Every amount should trace back to a source document and a reproducible calculation. Investigators should explain assumptions, exclude unsupported claims and show alternative scenarios where causation remains uncertain. Insurers, opposing lawyers, the Crown Prosecution Service and civil courts need to understand not only the final number but how the number was built.
Fraud involving inflated sales, false invoices or hidden receipts can also create tax concerns. HMRC provides an online route for reporting tax fraud and a hotline on 0800 788 887, with overseas callers able to use +44 203 080 0871 on weekdays from 9am to 5pm, except bank holidays, as set out in its tax fraud reporting guidance. HMRC may use data analysis, compliance checks, criminal investigations, COP9 or discovery assessments, with tax-geared penalties where applicable.
Management must also consider disclosure, accounting and reporting obligations under UK GAAP and the Companies Act. The correct treatment depends on the facts, materiality, reporting period and advice received, so the forensic schedule should support, rather than replace, that decision.
Building Defensible Preventative Controls
Controls work best when they interrupt both the act and the concealment. Segregate sales order entry, invoicing, credit control, cash posting and bank reconciliation wherever staffing permits. If an SME can't assign every task to a different employee, add compensating reviews by a director, external accountant or manager who doesn't prepare the underlying entry.
Payment-detail changes need independent verification. Call the customer using a trusted number already held in the master file, not a number supplied in the change request. Dual authorisation should cover new customers, bank-detail amendments, credit notes, write-offs and unusual refunds.
Match the control to the exposure
| Control Area | Primary Fraud Risk Mitigated | Typical Implementation for SMEs |
|---|---|---|
| Role separation | Lapping, skimming and concealed adjustments | Split invoicing, cash posting and reconciliation, or add independent owner review |
| Customer master data | Payment diversion and unauthorised changes | Restrict edit rights and verify amendments outside email |
| Credit notes and write-offs | Concealed shortages and collusive discounts | Require documented reasons and approval above defined thresholds |
| Bank reconciliation | Missing or redirected receipts | Reconcile independently and review aged unreconciled items |
| Customer confirmations | False balances and lapping | Send periodic statements or circularisations from a separate contact |
| Exception reporting | Repeated manual intervention | Review reapplications, unapplied cash, late postings and unusual journals |
Positive pay and bank alerts can support payment controls where the bank offers them. Independent bank confirmations add another check, particularly during an investigation or external review. Technology helps when it produces audit trails, role-based access and exception reports. It doesn't compensate for weak ownership or approvals.
Start with the controls you can sustain
Cost and headcount objections are reasonable. A small business may not afford a new ERP system or a dedicated internal audit team. It can still rotate responsibilities, review a weekly exception report, send debtor circularisations, require a second approval for changes and have an external accountant inspect reconciliations periodically.
The maturity path should remain practical:
- Essentials: document the process, assign owners and remove single-person control over cash and reconciliation.
- Structured review: analyse adjustments, unapplied cash, aged debt and customer complaints for patterns.
- Independent challenge: rotate reviewers, confirm balances externally and test access rights.
- Continuous monitoring: automate matching and alerts as transaction volume and risk justify the investment.
The objective isn't to make fraud impossible. It's to make unauthorised action harder, concealment shorter and detection more likely.
Scenarios for SMEs, Law Firms and Insurers
A small UK retailer discovers diverted customer payments after migrating to new accounting software. The old remittance records sit in email folders, while the new system shows several receipts applied manually. The owner should preserve both systems, export audit logs before access changes and compare customer confirmations with bank statements. Staff interviews should follow the documentary review, not replace it. The immediate move is to restrict payment-detail amendments and appoint an independent reviewer for the migration period.
A law firm receives a referral involving alleged management override. The client believes a director manipulated credits, but the records could also reflect a one-off system error. The forensic accountant should map the approval chain, compare user activity with source documents and test similar transactions across customers and periods. Interviews then address the gaps and explanations identified in the records. The immediate move is to agree the investigation question, scope and privilege arrangements with solicitors.
An insurer receives notification of a sustained fake-invoice scheme. The policyholder supplies a headline loss but hasn't separated diverted receipts, recoveries, VAT, write-offs and investigation costs. The loss adjuster needs timely notification records, policy wording, a transaction schedule and evidence showing how the scheme operated. The immediate move is to preserve the accounting environment and build a document-indexed loss calculation before arguments about quantum harden.
The wider UK context supports prompt action. The Home Office estimated fraud cost at £14.4 billion in the year ending March 2024, including £5.2 billion affecting businesses, according to the Office for National Statistics fraud release. Those figures cover fraud broadly, but they show why insurers, boards and professional advisers need a clear evidential process.
Getting Clear Answers and Taking Action
Start this week by mapping the receivables process from order entry to bank reconciliation. List every control owner, system permission, approval point and manual workaround. Then identify the largest exposure points, especially customer-master-data changes, unapplied cash, write-offs, refunds and duties concentrated in one person.
If you suspect fraud, use this sequence:
- Secure evidence before correcting records or confronting anyone.
- Maintain normal cash controls while restricting risky changes.
- Engage qualified forensic support to test scope, causation and loss.
- Notify insurers and legal counsel within applicable policy and procedural terms.
Early scoping doesn't have to prolong disruption. It often prevents an unfocused review, clarifies which records matter and improves the chance of recovering funds or presenting a defensible claim.
Lighthouse Consultants supports SMEs, law firms and insurers with independent forensic accounting, fraud investigation, financial analysis and loss quantification. Its structured approach can help turn an unexplained receivables gap into a documented answer that stakeholders can assess.
Lighthouse Consultants can investigate suspected accounts receivable fraud, trace transactions, quantify recoverable and consequential losses, and prepare clear analysis for insurers, solicitors, boards or court. Visit Lighthouse Consultants to start a discovery conversation and clarify the right scope before committing to a full engagement.



