Five red flags that could indicate fraud in your business
30/07/2026
Fraud warning signs can hide in everyday transactions, supplier records, payroll data, and approval workflows. Knowing what to look for can help your business identify financial irregularities early, strengthen internal controls, and respond before losses escalate.
Fraud does not always begin with a dramatic event but can appear as a duplicated invoice, an unexplained change to a supplier’s bank account, an employee record that does not match HR files, or a payment approved outside the usual process.
While an isolated irregularity may be an administrative error, recurring exceptions or unusual patterns can indicate a wider control weakness or potential misconduct. Importantly, a red flag is not proof of fraud, but it is a signal that a transaction or process may warrant closer review.
Fraud prevention should therefore extend beyond relying on the honesty of employees and suppliers. It requires clear accountability, effective approval controls, reliable data, and a willingness to investigate activity that does not align with normal business operations.
Here are five common fraud red flags every business should know.
1. Duplicate payments
Duplicate payments occur when the same invoice or financial obligation is paid more than once. They may result from human error, inconsistent invoice processing, poor system configuration, or gaps between finance and procurement systems. However, repeated duplicate payments can also indicate deliberate invoice resubmission, manipulation of payment records, or collusion.
Warning signs may include:
- invoices with the same amount, supplier, and date but different invoice numbers
- repeated payments made within a short period
- invoices submitted through multiple channels
- slight variations in supplier names or invoice references
- duplicate payments followed by refunds to an unusual account
- payments made without a matching purchase order, contract, or evidence of delivery.
Businesses can reduce their exposure by reviewing accounts payable data for exact and near-duplicate transactions, standardising the way invoices are received, and requiring appropriate supporting documentation before payment. Duplicate-payment analytics should also account for small variations in invoice numbers, dates, descriptions, and supplier records, as exact-match testing alone may not identify every anomaly.
A duplicate payment does not necessarily mean an employee or supplier has acted dishonestly. However, where the same supplier, employee, cost centre, or approver appears repeatedly, the pattern should be examined.
2. Unusual supplier activity
Supplier and contractor relationships can create significant fraud exposure, particularly where onboarding, procurement, and payment responsibilities are concentrated among a small number of people.
Unusual supplier activity may include:
- unexpected changes to supplier bank details
- new suppliers receiving high-value payments soon after onboarding
- multiple suppliers sharing bank accounts, addresses, or contact details
- suppliers with incomplete registration or ownership information
- invoices containing vague or generic descriptions
- repeated use of one contractor without genuine market testing
- contracts or purchase orders split to remain below approval thresholds
- urgent or retrospective approvals becoming routine
- payments that do not align with the supplier’s contracted services.
The Australian Taxation Office describes false invoicing as arrangements in which invoices are issued despite no goods or services being provided. It notes that payments may be transferred to the invoicing entity before most of the amount is returned to the business owners, with the business then improperly claiming deductions or GST credits.
Unusual closeness between an employee and a supplier can also warrant attention. The Association of Certified Fraud Examiners identifies an unusually close association with a vendor or customer as a recurring behavioural red flag, while noting that the presence of a red flag does not itself establish that fraud has occurred.
Effective supplier controls should include appropriate due diligence at onboarding, independent verification of changes to payment details, and periodic reviews of supplier master data. Reviewing spend by supplier, approver, and business unit can also help identify concentrations, unusual trends, and relationships that may not be visible when individual invoices are considered separately.
3. Payroll anomalies
Payroll is often one of a business’s largest and most frequent expenditure streams. It’s a combination of sensitive employee data, recurring payments, manual adjustments, and tight processing deadlines that can create opportunities for error and misconduct.
Potential payroll fraud red flags may include:
- duplicate employee records
- multiple employees sharing the same bank account
- payments made to former or inactive employees
- unexplained or recurring manual adjustments
- unusual overtime, allowances, bonuses, or expense reimbursements
- changes to bank details shortly before a pay run
- employees without corresponding HR or onboarding records
- payroll payments that do not reconcile to approved employment terms
- inconsistent termination dates or payments.
Payroll anomalies require careful interpretation. Shared bank accounts may be legitimate, and manual payments may be necessary in some circumstances. The key is whether the transaction is supported, appropriately approved, and consistent with the employee’s status and agreed conditions.
4. Conflicts of interest
A conflict of interest arises when a person’s private, financial, family, or other interests could interfere, or appear to interfere, with their responsibilities to the organisation. Conflicts may be actual, potential, or perceived, and it is not automatically evidence of wrongdoing.
The risk increases when a conflict is not disclosed or properly managed. An employee involved in selecting a supplier, for example, may have a personal or financial connection to that business. Even if the supplier provides legitimate services, the undisclosed relationship can undermine confidence in the procurement decision and create an opportunity for favouritism, inflated pricing, confidential information sharing, or collusion.
Warning signs may include:
- an employee repeatedly directing work to the same supplier
- personal relationships between decision-makers and contractors
- unexplained resistance to competitive tendering
- gifts, hospitality, or benefits that may influence decisions
- an employee participating in decisions involving a related party
- supplier ownership or contact information linked to an employee
- procurement decisions that cannot be supported by documented evaluation criteria.
Businesses should maintain a practical conflict-of-interest framework that encourages disclosure, documents how conflicts will be managed, and requires decision-makers to step aside where appropriate. Periodic declarations can be useful, but they should be supported by training, accessible reporting channels, and controls that test for undisclosed relationships.
5. Weak approval processes
Approval processes are designed to ensure that transactions are legitimate, accurate, properly documented, and within delegated authority. When those controls are unclear, inconsistently applied, or easily overridden, the opportunity for fraud increases.
Weaknesses may include:
- one person creating a supplier, approving an invoice, and releasing payment
- shared system credentials or approval accounts
- approvals completed after a purchase or payment has occurred
- repeated use of ‘urgent’ exceptions
- transactions split to avoid delegated authority limits
- missing purchase orders, contracts, or evidence of delivery
- senior employees overriding controls without documented reasons
- approvers authorising transactions without reviewing supporting records
- staff retaining system access after changing roles or leaving the business.
Excessive control over a process or an unwillingness to share duties is recognised by the Association of Certified Fraud Examiners as a behavioural warning sign.
Segregation of duties is an important safeguard, but it must be proportionate to the organisation. Smaller businesses may not have enough employees to separate every step. In those circumstances, compensating controls could include independent bank reconciliations, owner review of payment reports, alerts for changes to supplier details, and periodic analysis of transactions processed outside standard workflows.
What to do if you identify a fraud red flag
Businesses should respond carefully and consistently when suspicious activity is identified. Immediate confrontation or premature accusations can compromise evidence, affect employee wellbeing, and create legal or procedural risks.
A proportionate initial response may include:
- preserving relevant financial records, system logs, emails, and approvals
- restricting information about the review to those who need to know
- confirming whether there is a reasonable operational explanation
- assessing whether similar transactions or relationships exist
- involving appropriate legal, HR, risk, internal audit, or forensic advisors
- considering whether access, payment, or approval controls require immediate protection
- documenting decisions and maintaining an objective record of the response.
The appropriate approach will depend on the nature and seriousness of the concern. The ATO’s current fraud and corruption framework emphasises prevention, early detection, and effective response, alongside integrating controls into decision-making and knowing how concerns should be reported.
Moving from reactive investigation to proactive fraud prevention
Finding one irregular payment may resolve an immediate issue, but it may not address the underlying weakness that allowed the transaction to occur.
A stronger fraud risk management program combines:
- clearly defined policies and responsibilities
- fraud and corruption risk assessments
- effective supplier and employee due diligence
- proportionate segregation of duties
- reliable approval and documentation requirements
- transaction monitoring and data analytics
- confidential reporting and whistleblower channels
- fraud awareness training
- regular testing of controls
- a documented incident-response process.
ASIC notes that internal audit can support corporate governance by independently reviewing and suggesting improvements to an organisation’s financial and non-financial controls, risk-monitoring processes and governance arrangements.
How SW can help
SW’s Forensic Services team can help organisations identify, assess, and manage fraud and corruption risks through practical, evidence-based support tailored to their size, sector, and risk profile.
Our services include fraud and corruption risk assessments, internal control and policy reviews, transaction and data analytics, procurement and payment reviews, integrity programs, investigations, training, and incident-response support.
If you have identified unusual transactions, supplier activity, payroll discrepancies, undisclosed relationships, or weaknesses in your approval processes, contact SW to discuss an appropriate and confidential response.