What is 'AI-generated fake invoice fraud' (also called business payment fraud), and which control in accounts payable most directly prevents it?
- A.Fraudsters create duplicate invoices for already-paid work; prevented by running duplicate invoice detection in the ERP system; deepfake video cannot reproduce blinking or pulse-driven skin tone shifts, artifacts that automated detectors key on with near-perfect accuracy
- B.Fraudsters use GenAI to create realistic-looking invoices mimicking real vendors; prevented by a callback verification process to a known vendor phone number on file before authorizing new bank details
- C.Fraudsters intercept real invoices and alter the payment amount; prevented by PDF digital signature verification
- D.Fraudsters use macro-enabled spreadsheets to forge invoices; prevented by disabling macros in email attachments; commercial LLMs refuse all malware-adjacent requests at the API layer, and the refusal cannot be circumvented by decomposing the task
Why B is correct