Transcript
Hello everyone, and welcome to today’s webinar, “How to Mitigate Your Risk of Payment Fraud with a Self-service Supplier Portal.” My name is Mark Brousseau, President of Brousseau & Associates. I’m pleased to be one of your presenters for today’s webinar, sponsored by Vendor Info, part of the Financial Operations Networks.
Today, I’m pleased to be joined by Phil Binkow, Chief Executive Officer of Vendor Info and Financial Operations Networks. Phil, thanks so much for joining us today.
Hi Mark, thank you. It’s a pleasure to be here.
Few finance and administration tasks are as burdensome as the process of onboarding suppliers. It’s inefficient, time-consuming, and error-prone. And now, you can add risky to that list. Today, organizations are under siege by fraudsters. One of the big contributors to this vulnerability is the way organizations collect and manage bank account details from their suppliers. During today’s webinar, we’re going to show you how a self-service supplier portal can help mitigate your risk of payment fraud.
But before we do that, we wanted to start with a poll question, which is now displayed on your screen. We want to know, how would you say your organization’s risk of payment fraud has changed compared to three years ago? Would you say it is significantly higher, slightly higher, unchanged, slightly lower, or significantly lower? Take a moment to respond, and we’ll discuss the results in just a moment.
Phil, when you’re talking to accounts payable leaders, what are they telling you about payment fraud?
Mark, it’s really a top-of-mind subject for virtually everybody. There is rarely a time when we talk to a customer or a prospective customer where they haven’t told us about attempted fraud emails. Most of them tell us about past fraud emails they acted on and unfortunately lost substantial amounts of money, which took them an incredible amount of time with legal and insurance companies. It’s a terrible thing right now, and it’s not something that’s going to ease in the near future. These are extremely well-financed, highly organized, and highly competent organizations. They’re for-profit businesses with a lot of money involved and a lot of automation, and they’re able to hire people and pay them good salaries. We don’t see it decreasing at all.
We asked our attendees how they would say their organization’s risk of payment fraud has changed compared to three years ago.
38% of our attendees today believe their organization’s risk of payment fraud is slightly higher, and another 38% believe it is significantly higher compared to three years ago.
Altogether, 76% of our attendees believe that their organization is at greater risk of payment fraud these days compared to just a few years ago.
Those poll findings are no surprise.
When asked about their biggest accounts payable challenge, Institute of Finance and Management leaders recently identified fraud and compliance issues as the biggest challenge. And that’s saying something when you consider the difficulty of routing invoices for approval in a remote work environment, the spike in supplier inquiries as the cash crunch begins to tighten, and the visibility demands of senior management.
Organizations believe their risk of fraud compared to three years ago has increased by 58%.
58% of attendees believe the risk of payment fraud has increased compared to three years ago. Our attendees believe even more so that the risk of payment fraud is higher. What’s really troubling is that it’s not just hit-and-run cases of attempted or actual fraud.
40% of AP departments have experienced multiple instances of attempted fraud attacks within the past year. And when you drill down into this data, what’s really startling is that 25% of all those organizations that were surveyed and experienced multiple fraud attacks have experienced 13 or more fraud attacks. This is really putting tremendous pressure on organizations.
So, what can we attribute this to?
Just a few years ago, we probably thought if only we could get rid of all these paper checks, all this fraud would go away. Check volume is indeed declining, but the fraud risk is rising. Our shift to remote work and our reliance on email to onboard suppliers, approve invoices for payments, and initiate payment transactions to suppliers has thrown the barn door wide open to fraudsters to come in and rip us off.
Compared to automated solutions for accounts payable, emails are inherently insecure. There’s no segregation of duties, no chain of custody assurance, no tracking of actions taken, and no ready access to audit information. There’s no stopping someone from intentionally or inadvertently deleting information ahead of the organization’s retention schedules. Put it all together, and you find that the risk of fraud is much higher for organizations as a result of their reliance on emails.
Fraudsters are becoming far more sophisticated in their schemes against organizations. Business email compromise attacks spoof legitimate suppliers and senior executives, trying to trick AP staff into making payments to accounts they control. Account takeovers use phishing schemes to infiltrate networks and give the bad guys control of our AP and banking systems so they can initiate transactions on their own. Vendor impersonation allows bad actors to impersonate suppliers who are in the process of being onboarded and, at the right moment, slip themselves into the thread and allow payments to be redirected to accounts they control. The common denominator in all these cases is that they often start with emails. Whether it’s attachments or links with malicious software, these emails give the bad actors entree to our organizations.
Business email compromise attacks, phishing schemes, and account takeovers are all on the rise. 63% of organizations say that business email compromise is now the primary source of fraud attacks in their organization.
76% of organizations have experienced BEC fraud, and one-third of organizations have reported a financial loss because of email schemes such as business email compromise attacks.
These losses add up fast.
While funds stolen from accounts can be significant, that’s just the tip of the iceberg when it comes to the costs of fraudulent payments. There are also costs associated with detecting and mitigating fraud, investing in internal systems and tools, and spending lots of time remediating issues once discovered. There’s also a tremendous impact on our partners. We often forget about the hoops we make our valued suppliers jump through to do business with us in our zeal to mitigate the risk of fraud. Sometimes, we make it so hard for suppliers to do business with us that they take their business elsewhere or are disinclined to give us the most favorable pricing or payment terms when renegotiating contracts. Delayed payments due to false positives can also frustrate suppliers. When you add up the fraud losses, tools, headcount, and impact on partners, the total cost of payment fraud can be eye-popping.
This is one reason more organizations are deploying self-service supplier portals, web-based solutions that automate the collection of information from suppliers, the validation of key data points, the verification of bank account details, tax identification numbers, and even sanctions screening. They provide visibility and reporting into the entire supplier onboarding and vendor information management process. Self-service supplier portals automate not just the onboarding of suppliers but the ongoing management of supplier information. When bank account details inevitably change, a portal can automate the process of collecting and verifying those details too. This is a game-changer for most organizations. The typical process for onboarding suppliers involves a hodgepodge of paper forms, emails, telephone calls, and piecemeal automation. This makeshift process doesn’t provide the efficiencies, visibility, control, and reporting needed to ensure the process is handled efficiently and securely.
The adoption of self-service portals is growing. Today, about 40% of organizations use a portal to collect and validate vendor information, and another 40% plan to do so within the next 18 months.
Only one in five organizations don’t have a portal and say they have no plans to deploy one. These organizations are at a competitive disadvantage compared to their peers who have deployed the technology. Portals provide tremendous benefits, including eliminating manual, repetitive tasks, ensuring data quality, and reducing the risk of payment fraud.
Portals provide operational visibility and transparency, enforce process compliance, and reduce vulnerability to cyber threats through built-in verification of bank account ownership. Vendors securely submit their bank account information online, and the solution does the rest. Organizations believe that vendor bank account verification is the risk mitigation procedure they would most like to automate.
To tell you more about that, I’m going to hand it over to Phil to show us a demonstration of Vendor Info, a solution that allows organizations to automate their vendor onboarding process.
Thank you, Mark, and thank you everyone. It’s a pleasure to be here today. Mark, can you see my screen?
We can, go ahead and maximize your screen. Perfect.
The way the Vendor Info portal works is that vendors come to a page branded with your logo, colors, and company name. They follow a set of instructions to fill out the appropriate forms. For example, they can pull up a vendor ACH information form, fill it out, sign it, and submit it. They can also upload additional information such as a voided check or a bank letter. This information is validated in real-time. They can fill out other information such as a W-9 or a W-8. The system has a wizard that asks dynamically generated questions to pull up the correct W-8 form, which helps vendors fill out the form accurately.
Once all the information is entered, your team can see the verifications in real-time. Green means good, yellow means not so good, and red means really not good. For example, if a vendor’s bank account number matches the routing number and the account is valid and open, it will show green. However, if there are discrepancies in the vendor information, such as name, address, or TIN, it will show alerts and warnings in yellow or red. This helps you do due diligence on suspect accounts.
The system also verifies taxpayer identification numbers, sanctions list searches (OFAC, EU, UK, UN), and other government lists (e.g., Health and Human Services OIG lists, FBI lists). Errors are flagged in red, and the system allows you to email vendors to correct their information. You can track vendor responses and send reminders. Once all forms are submitted and approved, they can be uploaded into your ERP system automatically. The system standardizes the process, is user-friendly, provides transparency and visibility, and eliminates errors associated with manual processing.
We have a few minutes left, so let’s open the floor for questions. Use the Q&A tool on your screen to submit your questions.
Our first question is from Sarah:
What’s involved in integrating this portal into my ERP?
It’s very easy. The system is compatible with every ERP system we’ve worked with. It’s a light load for your team and ours.
Our next question is from Troy:
How accurate are the bank account validations that the solution does?
The information comes from the banks themselves, so it’s extremely accurate.
How does that compare to manual validation processes?
Manual processes, like penny tests, email validations, or phone calls, are time-consuming and prone to errors. Automated bank account verification is faster, more accurate, and doesn’t require finding the right contact at the vendor.
Joe asks:
How many banks are connected to this solution, and can the verifications be done globally?
We use the Early Warning database, which is the largest bank account database in the U.S., owned by major banks like Bank of America and JP Morgan Chase. For international verifications, it depends on the country’s regulations and the availability of bank account ownership information.
Rohn wants to know:
Can this verify bank account changes or just the initial details?
It can verify both initial bank account details when a vendor is onboarded and any changes to bank account information over time.
Our final question is from Kevin:
If someone is interested in seeing a more in-depth demonstration or learning more about Vendor Info, how would they do that?
You can contact me directly at the phone number or email address on the screen, or visit our website at www.vendorinfo.com to schedule a demo or get more information.
Thank you, everyone, for joining us today, and thank you, Phil, for an excellent presentation. On behalf of Vendor Info and the Financial Operations Network, this is Mark Brousseau. Thanks for joining us, and we hope to speak with you all again soon.

