See AP Express in action August 27th @ 2 p.m. ET – Click here to register.
AP Express by Nivo1 Meet with an Expert

How to Prevent Check Fraud: AP Controls That Work


Read time: minutes July 14, 2026 | leanne Table of Contents
    Add a header to begin generating the table of contents

    Check Fraud Is Still an AP Problem – And Weak Controls Make It Worse

    Many finance leaders assume check fraud is fading as organizations move to ACH, virtual cards, and broader AP automation. The video makes the opposite point: check fraud remains active, common, and expensive, even for organizations that issue only a fraction of payments by paper.

    That matters for CFOs, AP leaders, and Oracle application teams because fraud risk is rarely just a banking issue. It is also a process design issue. When check handling, vendor master maintenance, approvals, and bank reconciliation are loosely controlled, fraudsters do not need a sophisticated opening. They need a weak spot.

    The core message is simple: you may not be able to avoid being targeted, but you can make it much harder to become a victim.

    This article breaks down the most practical controls from the video and adds operational context for enterprise AP environments, especially those running Oracle EBS, Oracle ERP Cloud, or JD Edwards.

    Why Check Fraud Persists Even in Modern AP Environments

    A useful point in the video is that company size offers little protection. Small organizations may believe they are too insignificant to attract criminals. Large ones may assume their scale and banking relationships insulate them. Neither assumption holds up.

    Checks remain vulnerable because they expose several pieces of usable information:

    • Bank routing and account numbers
    • Payee details
    • Authorized payment timing
    • Signature formats
    • Mailing patterns

    Once a paper check enters the mail stream, control weakens significantly. A stolen or altered check can be deposited, washed, or redirected. Even when fraud is detected later, recovery can be difficult and time-sensitive.

    For enterprises, the issue is magnified by volume and complexity. A company may have:

    • Multiple bank accounts
    • Decentralized payment operations
    • Shared service centers
    • Exception-based payment approvals
    • High supplier turnover
    • Legacy workflows alongside newer automation tools

    In that environment, check fraud prevention is not one control. It is a stack of controls that must work together.

    The Real Risk: Fraud Is Often Enabled by Internal Practices

    One of the strongest themes in the video is that external criminals are only part of the problem. Internal process weaknesses – and sometimes internal bad actors – create the opening.

    That is an important distinction for finance leaders. Fraud prevention is often framed as a perimeter issue: secure the mail, send files to the bank, reconcile accounts. But many payment losses begin much earlier, with policy exceptions and operational shortcuts.

    Examples highlighted in the video include:

    • Not using positive pay
    • Turning off positive pay
    • Returning checks to requisitioners
    • Rushed check handling
    • Management overrides
    • Weak vendor master controls
    • Poor segregation of duties
    • Payment stretching that leads to duplicate invoice resubmissions

    These are not exotic failures. They are common AP “workarounds” that emerge under pressure to pay quickly, satisfy internal stakeholders, or manage cash flow. Over time, they normalize risk.

    For CFOs, this is the bigger lesson: fraud control maturity often depends less on written policy and more on whether exceptions are tolerated in practice.

    Key Takeaways

    • Check fraud is not obsolete. Even organizations reducing check usage still face meaningful exposure.
    • Size does not protect you. Both small and large organizations are targets.
    • Positive pay is foundational. If available, payee name positive pay offers stronger protection than standard positive pay alone.
    • Dual signatures do not stop bank-side check fraud. They may help internally, but banks typically do not verify signatures in the way many AP teams assume.
    • Segregation of duties still matters. Check signers should not have access to blank check stock.
    • Secure physical handling is essential. Keep check stock and printed checks locked down until the last possible moment before mailing.
    • Daily or near-daily account review improves recovery odds. The faster unauthorized payments are detected, the better the chance of bank intervention.
    • Vendor master controls are fraud controls. Weak supplier governance can enable both internal and external payment diversion.
    • Cash-management tactics can create AP risk. Payment delays may trigger duplicate invoice submission and unintended duplicate payments.
    • The strategic answer is fewer checks. The video supports moving toward lower-risk payment methods, though specific migration methods were not detailed.

    The Most Effective AP Controls for Preventing Check Fraud

    1. Make Positive Pay Non-Negotiable

    The video treats positive pay as the primary defense, and that is a sound position.

    At a basic level, positive pay works by matching checks presented for payment against a file sent by the company to the bank. That file typically includes the check number and amount. If a presented item does not match, it is flagged as an exception.

    The video also distinguishes among versions of positive pay:

    Standard positive pay

    The company transmits issued-check data to the bank after each run.

    Reverse positive pay

    The bank posts checks presented for payment, and the company must review them within a limited time window.

    Payee name positive pay

    The bank also validates the payee name, not just the check number and amount.

    For enterprise AP teams, the practical hierarchy is clear:

    1. Payee name positive pay
    2. Standard positive pay
    3. Reverse positive pay
    4. No positive pay

    If your organization still relies on reverse positive pay because your ERP or bank file process cannot easily produce outbound issue files, that is a sign to revisit your payment architecture. In Oracle-based environments, this may involve reviewing payment format configurations, bank communication workflows, or treasury integrations.

    The broader operational insight: a control that depends on manual review is always weaker than one embedded into transaction processing.

    2. Stop Overestimating Dual Signature Controls

    The video makes an especially valuable point for finance teams: requiring two signatures on checks may strengthen internal approval discipline, but it does not necessarily protect against fraud at the bank.

    Why? Because banks generally do not verify signatures the way many organizations imagine they do.

    This is a frequent control misconception. A policy may satisfy internal governance or auditor expectations, yet still fail to prevent a fraudulent item from clearing. That does not make dual signatures useless; it means they should be classified correctly:

    • Useful as an internal authorization control
    • Weak as a bank-side fraud prevention control

    For CFOs and controllers, this distinction is critical when assessing residual risk. A control matrix that overstates the fraud-prevention value of signatures can create false confidence.

    3. Lock Down Check Stock and Separate Duties

    If your organization still uses pre-printed check stock or secure paper, physical security remains essential.

    The video recommends:

    • Keeping check stock under lock and key
    • Maintaining a log of check numbers
    • Ensuring check signers do not have access to blank stock

    These are basic controls, but they often degrade over time, particularly in decentralized offices or during staff shortages.

    In a stronger control environment, you would also expect:

    • Restricted physical access with named custody
    • Documented issuance and void procedures
    • Periodic inventory counts of unused check stock
    • Review of missing sequence numbers
    • Formal escalation for stock discrepancies

    Not all of these items were specified in the video, but they align with the same control logic: if a blank check can be obtained and completed by the wrong person, the fraud event has already progressed too far.

    4. Keep Printed Checks Inside AP Until the Last Possible Moment

    One of the most practical recommendations in the video involves what happens after printing. Many AP teams are eager to move completed checks out of their area and into the mail stream. Operationally, that feels like progress. Control-wise, it may create unnecessary exposure.

    The recommended practice is to hold printed checks securely within AP and release them only immediately before mail dispatch.

    This is a subtle but powerful control. Mailrooms are high-traffic environments. The more time checks spend there, the more opportunities exist for theft, interception, or tampering.

    For organizations still mailing payments, consider these questions:

    • How long do checks sit before pickup?
    • Who has access to outgoing mail bins?
    • Is there a documented chain of custody?
    • Are high-dollar or exception checks handled differently?
    • Is mailing outsourced or done internally?

    In mature environments, the goal is not just secure printing. It is secure custody from print to postmark.

    5. Reconcile Bank Activity Daily, Not Just Monthly

    The video emphasizes daily account reconciliation as a fraud control, and that advice deserves more attention in enterprise AP.

    Many organizations still treat bank reconciliation as a periodic accounting function. That is too slow for fraud response. When unauthorized checks clear, timing matters. The earlier the issue is identified, the better the organization’s chance of working with the bank to mitigate loss.

    Daily review supports:

    • Faster identification of unauthorized items
    • Quicker exception investigation
    • More timely bank notification
    • Better documentation for claims and internal reporting

    This does not necessarily require a fully manual reconciliation every day. In ERP-centered environments, it may involve:

    • Daily bank statement imports
    • Exception dashboards
    • Automated transaction matching
    • Alerts for out-of-pattern check activity
    • Treasury or AP review of unresolved items

    The lesson is broader than checks: speed is a fraud control.

    Weak Internal Controls Invite Both External and Internal Fraud

    The video briefly but importantly notes that internal fraud often traces back to a trusted, long-tenured employee. That observation aligns with many real-world control failures: not because tenure causes fraud, but because trust can erode discipline.

    When organizations make exceptions for experienced employees, executives, or urgent business needs, they create uneven control enforcement. Fraud tends to surface where people believe rules are flexible.

    That is why the video argues for uniform controls with no exceptions. In practice, that means:

    • No approval bypasses without documented escalation
    • No informal vendor changes
    • No signer access to check stock
    • No cancellation of protective bank services for convenience
    • No “temporary” segregation-of-duties breaks without compensating controls

    For enterprise AP teams, this is where systems matter. Oracle and other ERP platforms can enforce workflow, role-based access, and audit trails – but only if the organization chooses to use them consistently.

    Technology cannot compensate for a culture of overrides.

    The Vendor Master File Is a Fraud Surface, Not Just a Data File

    The transcript mentions weak controls around the master vendor file, and that point deserves expansion because it connects directly to both check fraud and broader payment fraud.

    A compromised supplier record can enable:

    • Redirected remittances
    • Payments to shell vendors
    • Duplicate supplier setups
    • Unauthorized address changes
    • Fraudulent banking updates for non-check payments

    Even when the payment itself is made by check, vendor master weaknesses can still increase exposure. A bad address, unauthorized payee change, or duplicate supplier profile may steer physical payments into the wrong hands.

    For AP leaders, vendor master governance should include:

    • Restricted create/change access
    • Independent review of high-risk changes
    • Audit logging
    • Duplicate detection
    • Formal supplier verification procedures

    The video does not go into implementation detail, but the implication is clear: fraud prevention starts upstream.

    Why “Payment Stretching” Can Backfire

    One of the more nuanced observations in the video is that delaying payments can increase duplicate-payment risk.

    When suppliers do not receive payment on time, they may send additional copies of the same invoice. In a poorly controlled AP process, those duplicates can be entered and paid, especially if invoice-matching discipline is weak or exception queues are backlogged.

    This is a useful reminder that fraud and control discussions should not focus only on malicious behavior. Sometimes the trigger is operational strain:

    • Delayed approvals
    • Manual exception handling
    • Unclear invoice status visibility
    • Supplier follow-up pressure
    • Staff working outside the system to clear backlogs

    And once a supplier recognizes that duplicate payments slip through, the incentive for abuse increases.

    For finance leadership, the takeaway is that working-capital strategies and fraud risk are connected. Payment timing decisions should be evaluated not only for cash preservation but also for downstream control impact.

    A Practical Control Framework for AP Leaders

    Based on the video, a useful way to think about check fraud prevention is through four layers.

    Layer 1: Eliminate avoidable check usage

    The safest check is the one never issued. The video clearly supports reducing paper payments, though detailed alternatives were not specified.

    Layer 2: Harden bank controls

    Use positive pay, ideally with payee name validation, and monitor exceptions quickly.

    Layer 3: Secure internal handling

    Protect check stock, separate duties, and maintain controlled custody through printing and mailing.

    Layer 4: Detect fast and investigate consistently

    Review cleared items daily, escalate exceptions, and work with the bank immediately when something looks wrong.

    This layered approach matters because no single control is perfect. A fraudster who bypasses one barrier should encounter another.

    What This Means for Oracle and Enterprise AP Environments

    For teams running Oracle EBS, Oracle ERP Cloud, or JD Edwards, the article’s biggest implication is that fraud prevention should be designed as part of the payment process – not bolted on after the check run.

    That typically means reviewing:

    • Payment file generation capabilities
    • Bank integration quality
    • User-role design and segregation of duties
    • Vendor master maintenance workflows
    • Exception handling paths
    • Reconciliation timing and ownership
    • Physical controls in shared service or distributed print environments

    The video does not discuss ERP configuration specifics, but for this audience, that is where many control gaps either emerge or get resolved. A policy that says “use positive pay” is not enough if the outbound file is inconsistent, delayed, or dependent on manual intervention. Likewise, segregation of duties on paper is not enough if users have overlapping access in production.

    In other words, control design and system design must align.

    Conclusion: Fraud Prevention Is Mostly About Discipline

    The video’s most practical insight is also its simplest: fraud attempts are common, but success is not inevitable.

    Organizations usually become vulnerable through familiar habits:

    • convenience over control,
    • exceptions over consistency,
    • trust over verification,
    • and speed without safeguards.

    For AP and finance leaders, preventing check fraud does not require inventing a new framework. It requires executing the fundamentals well:

    • reduce paper where possible,
    • use the strongest available bank controls,
    • secure physical check handling,
    • enforce segregation of duties,
    • protect the vendor master,
    • and monitor bank activity fast enough to act.

    The strategic goal is fewer checks. Until that goal is fully achieved, disciplined AP controls remain one of the most effective defenses against avoidable financial loss.

    Source: “Check Fraud: Are Your AP Controls Actually Working?” – AP Now, YouTube, Jun 17, 2026 – https://www.youtube.com/watch?v=7pNx46TuFLc

    Related Articles

    Moving suppliers off paper checks to ACH, wires, and virtual cards cuts AP costs, CO2, errors, and speeds payments.

    Solving AP Sustainability Challenges with E-Payments

    July 15, 2026 If you still pay suppliers by check, your AP process is slower,...
    default - banner

    How (and Why) to Avoid an AP Automation RFP

    January 25, 2022 At face value, RFPs seem like a prudent path when selecting an...
    AP automation, cash flow forecasting, accounts payable automation, invoice processing, ERP integration, real-time payables, early payment discounts, payment scheduling

    How AP Automation Improves Cash Flow Forecasting

    June 3, 2026 Accurate cash flow forecasting is critical for making smart financial decisions, but...