Operational Risk | Insights, Resources & Best Practices

Payment Fraud Is Evolving. Control Architectures Must Evolve With It.

Written by Rami Chahine | September 11, 2026

Amid increasingly global environments and disconnected systems, payment fraud is not simply increasing – it is becoming faster, more distributed and harder to see. AI will play a huge role in combatting fraud attempts, but most accounts payable (AP) and payments leaders are reluctant to adopt these tools despite their capacity to augment and extend traditional fraud prevention approaches and financial controls.

Global Impact

Procurement fraud is one of the three most disruptive economic crimes globally. According to the Association of Certified Fraud Examiners, organizations lose an estimated $5.5 trillion to fraud each year, an average of 5% of revenue. That’s larger than the GDP of most large countries.

Within the wider procurement fraud umbrella, payment fraud attacks have been on the rise for several years now. Over 75% of organizations in the U.S. experienced attempted or successful payments fraud attacks in 2025. Payments fraud thus represents one of the most important sources of financial risk to businesses, with global card payment fraud alone expected to cost them over $400 billion over the next decade.

We can attribute this rise to three things:

-- First, paradoxically, is the incredible improvement in payment technology over the past two decades. The shift to digital payments approaches and the expectation of “instant payments” has armed fraudsters with the ability to scam individuals and organizations much faster and more simply. This trend is only encouraged by the proliferation of digital cards (and, in turn, card-not-present payments) and Authorized Push Payments.

Digital payment architectures can allow for fraud in a host of different ways at multiple points of failure: Fraudsters can make requests more easily, skim cash off transactions by inserting themselves into a payment process, and take over accounts with stolen data.

-- Second, the increasing interconnectedness and scale of global commerce has made tracking payments and detecting fraud a much more challenging task for organizations – and has encouraged fraud to industrialize.

Rami Chahine of Serrala

Criminal groups that specialize in selling stolen data, using AI to automate credential theft and engage in targeted spear phishing attacks against executives at scale, and even in offering “fraud-as-a-service” tools, have made more sophisticated attacks simpler for less skilled criminals. Organizations relying on highly manual processes and disconnected global systems simply cannot compete with this level of advancement.

-- Third, we should be mindful that the new kids on the block haven’t replaced tried and tested approaches. Check fraud continues to account for many payments fraud attempts and old-fashioned vectors like invoice spoofing, using an inside actor to change a supplier’s master data and direct funds to a fraudster’s account, and simple social engineering attacks like phishing emails are more frequent than they’ve ever been.

Cracks in the Foundation

All payment fraud methodologies take advantage of the same organizational blind spots. An enterprise handling hundreds of thousands or even millions of outbound payments in a year is likely reliant on data and processes spread across multiple ERP systems, treasury processes, banking and payment rail providers, and AP systems. These disconnected architectures expose vulnerabilities that fraudsters can exploit, shielded from detection by overstretched AP operators and invoice approvers, fragmented visibility of organizational cash flows, and informal or ad hoc decision-making rules.

Legacy controls can stop most fraud attempts. But under the sheer volume and sophistication of the modern fraud industry, these controls have reached their breaking point. Rules-based approaches aren’t flawed as such, but when the rules have to be applied afresh to every payment by people with hundreds of other more pressing concerns to worry about, errors are inevitable.

In the fragmented environments typical of large international enterprises with hundreds or thousands of different systems, channels, suppliers, and teams working in radically different ways, even a 98% accuracy rating can translate to millions of dollars in annual fraud losses.

AI in the Fraud Management Playbook

To their credit, many AP directors, financial controllers, and CFOs are aware of the risks of payment fraud and its implications for strategic liquidity, organizational health, and decision-making velocity and effectiveness. But few financial leaders are yet to leverage the full capacity of technology to help them mitigate and eliminate this risk.

Only 17% of finance teams and CFOs are implementing essential AI tools to combat payments fraud. As dramatic as this might sound, failing to do so means they might as well be handing their money over to the criminals in a sack.

Working with finance leaders to implement effective fraud controls, it’s easy to see why many of them are hesitant to trust AI with their payment decisions. They equate “trusting AI to handle fraud” to trusting chatbots to handle billion-dollar strategic decisions.

But this picture changes when we demonstrate how both generative AI and non-generative approaches like “traditional” machine learning (ML) find some of their strongest use cases in fraud prevention. Multiple AI tools can be brought to bear to make significant changes to your firm’s risk management model, without introducing new risks of their own.

ML-based behavioral analysis, for example, allows for instant anomaly detection based on typical supplier billing approaches, account information, and device and transaction details. If a payment request deviates from the established pattern, it is flagged for immediate human review. And this process runs 24/7, taking a great deal of pressure off your people as the first line in the detection process.

Contextual Correlation

If we think of this as the “bread and butter” application of AI in the context of fraud detection, generative AI and agentic workflows still have a role to play on top of this. We don’t need to hand the reins over entirely to an LLM (large language model). Instead, we use them where they’re strongest: to handle large volumes of unstructured data outside of the transaction or invoice and provide greater contextual backing for a given denial or escalation.

A great example of this is what’s called cross-channel correlation. Generative AI connects signals across different documents and interactions to identify both single instances of fraud, and more sophisticated fraud schemes. This allows for the detection of modified documents or payment account details, synthetic identities, and convincing deepfakes which would otherwise go unnoticed.

Organizations can therefore block multiple future fraud attempts based on past detection while also using the same contextual correlation analysis to minimize the risk of false positives and ensure that legitimate payment requests aren’t blocked or sent for review.

AI in Fraud Detection

Incorporating AI into fraud detection is a great starting point for incorporating AI into the payments processing workflow. However, this isn’t without its challenges, due to the overall complexity of the architecture behind B2B payments.

As with all things AI, the smart and responsible approach is to start small and build slowly. Select a contained use case where ROI potential is strong, and deploy AI within governance frameworks that establish clear policies for models to execute specific tasks in specific contexts.

Whether in payments fraud detection or anywhere else, any AI workflow should keep humans in the loop and run within a fully governed, explainable and auditable framework.

The organizations that take steps to deploy AI in fraud prevention now will see dividends as attacks become more frequent, organized, and damaging.

 

Rami Chahine is Chief Product and Technology Officer (CPTO) and a member of the executive management board of AI finance platform provider Serrala. A seasoned product executive with over 20 years of experience, he directs the product, technology, and IT functions while driving Serrala’s global advancements in technology and innovation.