AI Payment Fraud Detection: What an Agent Watches That a Human Doesn't See
· CompaniesAutomation
What an AI agent watches in your payments that a human cannot see: IBAN changes, duplicate invoices, ghost suppliers, and combined weak signals.
AI payment fraud detection is not a mysterious system that "smells" deception: it consists of an agent that compares every invoice, every change in bank details, and every payment order against the company's entire historical record, every day, without getting tired and without trusting that "this is a long-standing supplier." That's the difference with a human: not in intelligence, but in scale and consistency. A person reviews the invoice in front of them; an agent reviews it against the last five years of invoices, payments, suppliers, and patterns, in seconds.
This article reviews the frauds that cost Spanish SMEs the most money, the specific signals an agent watches for that a human team misses due to pure physics, and how this is integrated into a payment circuit without turning it into a bottleneck.
The five frauds companies pay for the most
Before the solution, the problem. These five patterns concentrate the majority of the losses we see:
- IBAN switching: someone—often from a real supplier's compromised inbox—writes asking to update the collection account. The next legitimate transfer goes to the attacker's account. It is the star fraud because it doesn't require forging anything: just a credible email at the right time.
- The fake invoice: a perfectly formatted document from a fictional (or impersonated) supplier for a modest amount, of the kind approved without looking. Attackers know the typical approval thresholds and bill just below them.
- CEO fraud: an urgent email "from the CEO" asking for a confidential transfer. It sounds crude until it arrives on a Friday at 2:50 PM with the exact tone of the house.
- The duplicate invoice: the same service charged twice, with a different invoice number and a few weeks apart. Sometimes it's fraud; sometimes it's a messy supplier. The money leaves just the same.
- Internal fraud: split payments to dodge the threshold that would require a second signature, suppliers registered by the same person who approves their invoices, credits that are never offset.
What an agent watches that a human cannot see
Comparison against the entire history, not against memory
When an invoice arrives, the agent contrasts it with all previous ones from the same supplier: Is the amount within its usual range? Is the numbering consistent with the series? Is the IBAN the usual one? Does the concept look like what this supplier usually bills? An administrative clerk with 600 invoices a month cannot perform that check even for a fraction; the agent performs it for one hundred percent. Sophisticated duplicates—identical amount, different number, 40 days later—fall precisely here.
Weak signals that only betray when combined
None of these things are suspicious in isolation: a supplier registered two weeks ago, an invoice slightly below the second signature threshold, an email domain that differs from the real one by one letter, a polite rush to collect. Together, they are a classic pattern. The agent scores each operation by combining dozens of signals of this type and escalates those that exceed the threshold; it is the kind of correlation that would require a person to have all the data in their head at once.
The metadata no one looks at
The agent also reads what surrounds the document: the sender's actual domain (not the display name), the consistency between the email sender and the invoice supplier, changes in tax or bank data relative to the vendor master file, and requests for account changes arriving via email instead of the agreed-upon channel. Most IBAN frauds are detected at this layer, even before evaluating the amount.
Continuous surveillance, even in August
Attacks are deliberately concentrated on Friday afternoons, long weekends, and vacation periods, when human review is at its lowest. An agent doesn't take August off: the 10,000th operation receives the same scrutiny as the first. Consistency is not a minor virtue; in fraud, it is half the defense.
How it works in practice: score, hold, explain
A sensible circuit has three pieces. First: every invoice and payment order receives a risk score upon entry, calculated against the history and the vendor master. Second: operations below the threshold continue their normal course—well over 95% of the volume is neither touched nor slowed down—; those that exceed it are held before payment, not after. Third, and this is what distinguishes a good system: the agent explains each alert in plain English ("the IBAN differs from the one used in the last 23 payments to this supplier; the change request arrived from a domain registered 11 days ago"), so that the person reviewing can decide in a minute with the facts in front of them. An agent that only says "high risk" without explaining itself ends up ignored, and an ignored system is a dead system. This ability to reason and act with context is exactly what separates an agent from a rules filter, as we explain in [what is an autonomous AI agent](https://companiesautomation.com/en/blog/what-is-an-autonomous-ai-agent).
What the agent does not replace
Two controls remain human and non-negotiable. One: every bank account change is verified through a different channel than the one the request arrived through—a call to the phone number you already had for the supplier, not the one appearing in the email. The agent detects and holds; the verification is done by a person. And two: dual signatures above a certain amount are never automated. The agent is an extraordinary layer of defense, not an excuse to dismantle the others.
The good news is that this surveillance is not a separate project: it is built on the same agent that processes invoices and prepares payments, as part of the [AI agents in the finance department](https://companiesautomation.com/en/blog/ai-agents-finance-department-automation) circuit. Adding the anti-fraud layer to an already automated accounts payable flow usually costs 2,000-5,000 euros and 1-2 more weeks; the complete map of the area is in our [AI financial automation guide](https://companiesautomation.com/en/blog/ai-finance-automation-guide).
If you want to know what holes your payment circuit has today—thresholds, vendor registration, IBAN changes, duplicates—and what it would cost to monitor them with an agent, request our [diagnosis](https://companiesautomation.com/es/diagnostico): we review your actual process and provide priorities with numbers.
Frequently Asked Questions
How many false alarms does an anti-fraud agent generate?
Well-calibrated, between 2% and 5% of operations end up in review, and each one comes with its explanation to be resolved in a minute. The first month the threshold is adjusted with the team: it's better to start somewhat sensitive and fine-tune than to start permissive and discover the hole too late.
Does this need much historical data to work?
It helps, but years are not necessary: with 6-12 months of invoices and payments, the agent already builds the normal ranges for each supplier. And several defenses—domain verification, consistency of the vendor master, IBAN change requests—work from day one without history.
Can the agent block a payment on its own?
It can hold it before it enters the payment batch, which is different: the operation remains on hold with its explanation until a person decides. Releasing or canceling the payment is always a human decision; the agent provides detection and context, not the final word.
Is it worth it for an SME or is it a big company thing?
IBAN switching fraud and fake invoices hit SMEs precisely, where a single person approves and pays. An average diverted transfer comfortably exceeds what it costs to add this layer to an automated payment flow, so the question is not company size but the volume and value of its payments.