Executive summary
AI has made established fraud tactics faster, more personalized and harder to detect, including email compromise, synthetic identities, account takeovers and deepfakes. Because AI conceals traditional warning signs, organizations need to reassess anti-fraud controls and expand monitoring to meet evolving risks. They need a broad approach that integrates existing processes with expanded sampling, enhanced detection and customized controls. That’s where organizations can use AI on their side, to map existing controls, test vulnerabilities and design responses, combining human expertise with automation to further strengthen resilience against sophisticated fraud threats.
Less visible, more dangerous
AI fraud tactics are not necessarily new — they’re just more effective.
When fraud is empowered by generative AI capabilities, it can apply proven tactics more quickly and convincingly:
- Email compromise: Phishing and other business email compromise attacks can use AI to efficiently and precisely personalize convincing messages that request invoice redirection, payroll diversion or other fraudulent activities.
“The days of receiving a clumsy email replete with broken English and typos are over,” said Grant Thornton Forensic Advisory Services Partner Johnny Lee. “Anyone can ask AI to recast an email draft as if they’re a midlevel accounts payable clerk from a Midwestern town sending an invoice. An elementary prompt can help anyone mimic colloquial language and attach a flawless duplicate of a legitimate invoice, and none of it's real.” - Synthetic identities: Fake personal or vendor identities are more convincing when AI combines real and fabricated data to gain access for opening accounts, securing credit, passing onboarding checks and other activities that create losses before detection.
- Account takeovers: Credential stuffing and adaptive login attacks can find successful patterns and quickly scale with AI, using account access to redirect funds, re-route scheduled payments and/or access and leverage other sensitive data.
- Fake invoices, claims and expenses: Fake invoices, claims and expenses are more convincing when AI generates supporting documents that replicate legitimate formats and transaction histories, readily integrating into otherwise established and legitimate workflows.
“You can flawlessly clone an invoice with information that takes as little as 10 minutes to glean by scraping LinkedIn,” Lee said. “In our investigative work, we have seen evidence of threat actors doctoring invoices using data that we traced to public mentions our client made on a website or social media. Whether it’s something innocuous as a press release or meaningful as a 10-K disclosure, this information about vendors and ecosystems is out there. The paperwork can look bulletproof, but that doesn’t mean it is.” - Chatbot engineering: Fake customer service messages or internal communications can apply AI-driven chatbots to manipulate employees into revealing credentials or approving transactions, with authentic-feeling interactions that persist across multiple touchpoints. These can be very damaging compromises with the potential to cause reputational harm and accrue costs by siphoning a large number of AI tokens.
- Deepfakes: One relatively new tactic is the use of AI-generated video and audio to impersonate executives or vendors, bypassing recognition verification to trick people into authorizing payments or sensitive data transfers.
Now that GenAI can enhance each of these fraud tactics, your anti-fraud processes must evolve to keep up.
You might not be using AI, but your attackers are.
“For example, your accounts payable process might not be AI-enabled, but you have to recognize that inbound documentation can be fraudulently produced with AI capabilities,” Lee said. “So, you need to look at the controls you normally use. What are the linchpin concerns?”
“It doesn't mean you rip out the plumbing and start over,” Lee said. “But you might have to introduce some manual controls, even if it's just spot-checking, sampling from a monitoring perspective or doing a deep dive on a random selection. Get back to how you improve the control environment when you have a new risk that your original control design didn't contemplate. Return to risk-management basics: prevent what you can, detect what you can’t prevent.”
The real threat of AI-driven fraud is that it often doesn’t have surface-level indicators. “This is a new category of risk that has people rethinking how they protect against it — not just how they identify it,” Lee said.
Get a broad perspective
To protect against AI-powered fraud, organizations need to think about protection broadly.
“Rather than thinking about a traditional red-flag pattern, understand that the landscape has shifted,” Lee said. “Organizations might need to move from sampling to look at full-population testing, with trending and controls that let them see where their money is going — and whether that’s a departure from contractual expectations or historical spending, or both.”
“Retrospective monitoring is table stakes here,” Lee said. “If you can't prevent the loss because the forgeries are so convincing, how are you detecting that they were forgeries after the fact? So, if you send a check to the wrong person, that is regrettable — but how proximate in time can you catch this — a few days, a week, or several months?”
This broad perspective should inform updates to (and integrate with) the internal controls that organizations already have in place. However, those controls were originally created to manage risks at a point in time, and they’ve become embedded in routine processes and even automated workflows. Now, the risks have changed. “So, you need to revisit some of the controls that may have matured over time through automation,” Lee said, noting that controls must address the risks that AI-powered fraud introduces. “That's the difference here.”
With AI, bad actors can quickly and precisely adapt fraud tactics to your unique business — so make sure your risk assessments and internal controls adapt, too.
Tailor controls with AI
To fight AI-powered fraud, you can use AI.
AI-powered fraud is becoming too sophisticated and dynamic to fight with controls that haven’t been tailored to protect your unique business model and processes. Remember that AI can quickly understand, analyze and build upon data to produce relevant outputs. So, use that capability on your side.
“The secret to all of this is that you can use tools to help you think through it, but it’s ultimately an intellectual exercise for a human being with an understanding of the process and risk — more specifically, an understanding of how the process really works, not just how it may happen to be documented today,” Lee said. “The key human-in-the-loop vetting comes from the process owner’s mastery and understanding of inputs, risks and outcomes.”
Articulation
First, identify your current controls. AI can be a powerful tool for augmenting the control activities that exist in your current process.
“The vernacular of risks and controls is not native to many people,” Lee said. “Process owners get processes done — they do their jobs well, and they employ a certain level of rigor, but many can’t enumerate abstract risks against which they’re mitigating every day. So, have the person with the actual mastery of a process articulate, to a GenAI tool or another person, what the process is — and what they do to avoid errors and/or to prevent fraud within that process.
Lee said, “The tool can help identify, for instance, that your process requires that someone verify payment details on an invoice against approved records in your vendor master. That prepayment verification is a key control. AI tools can help you identify that control and brainstorm on other controls that might be preventive or detective for this same risk of paying an unauthorized party.”
Essentially, internal auditors and compliance professionals can use AI tools to help translate a process owner’s perspective into the vernacular of risk and controls. Once you’ve achieved risk identification and control mapping, you can use GenAI tools to assist with control improvements. Tools like CompliAI even provide a field-tested library of potential control activities that address a particular risk.
Control improvements
Once you’ve updated the relevant risk controls you have today, you can combine human-based and GenAI expertise to improve your outlook on both.
For example, Lee said, “Go to your AP manager and ask, ‘If you were trying to commit fraud with a synthetic invoice, how would you do it? How would you circumvent our controls? What would dupe you, as a highly skeptical professional with knowledge of this and context of the process?’ That’s a great way to start.”
“You can also interrogate GenAI tools to help you think of similar scenarios,” Lee said. “You can say, ‘Our controls are typically focused on ensuring that we pay only vendors that are in our vendor master file. What else can we do to ensure that we don’t add a new vendor into this approved whitelist?’ This might lead you to adjacent controls related to how to establish a new vendor or to change critical information about an existing vendor.”
How we can help you
SERVICES
SERVICES
Human-in-the-loop interaction
To analyze and tailor your controls, you need interaction and input from process owners and risk managers alike. Automation can play important roles in the control process, but start with human-informed conversations rather than relying on automation alone to enumerate, analyze and create controls.
“There are plenty of tools that purport to do these things,” Lee said. “But the reality is that it’s remarkably different to provide the context needed for such tools to provide meaningful insights here.
Lee said, “You can ask an AI tool to provide the top five risks related to invoice fraud for an organization like yours, and you will get plausible answers as to industry risks, financial reporting, risks, and so on. But that doesn't mean the insights will be properly tailored to your unique control environment. Worse, you might gain unfounded assurance and move on to other things, if such a tool names five things you already manage well.”
“Tools that address governance, risk and compliance holistically are only beneficial and capable of providing insights when they’re highly tailored to your unique risk landscape and your actual control activities,” Lee said. “And, even for companies in the same industry, of the same size, public or private — no two companies really operate their controls in exactly the same way. Their systems, personnel, experience, key vendors, partners, culture, key controls and compensating controls are going to be different.”
Once you have tailored your controls, you can move toward deprecating the ones that don’t directly address risk and automating the key controls that make sense.
Move to automation
As organizations develop or revise anti-fraud controls, they often do so through evolutionary phases.
Controls typically begin as manual tasks that can seem tedious and limited to retrospective evaluations. Lee said the manual nature of these control activities is a common issue exploited by sophisticated and automated frauds.
“Many might know what best practices are, but that doesn’t mean everyone’s following them — as there is always a trade-off between cost and benefit, and some control activities may be poorly designed and seen as tedious and/or inconvenient. Quite often, the inconsistency of a key control activity results not from a knowledge gap but an implementation gap.” When controls are poorly designed or partially implemented, fraud can exploit those gaps.
Over time, teams attuned to emerging risks can test, refine and ultimately automate previously manual detective controls to transform them into mechanized preventive measures that stop issues before they start. “That’s the best of all worlds,” Lee said. “You have controls that prevent most of the threats, so the machines are doing the heavy lifting and you’re just periodically checking to ensure they operate as designed. That evolution is easy to talk about, but it's a very difficult thing to do, especially across a complex function like procurement.”
Articulate, investigate and evolve
Once you enumerate the controls you have today and identify the risks you’re mitigating as a result, you can investigate vulnerabilities and use a fraud control framework to help identify controls for your organization’s unique business model and controls maturity. Armed with that information, you can then refine those controls, moving as many as possible from manual processes to automation and from detective to preventive functions. This effort, done well, leverages the process expertise within your organization, informs everyone of emerging risks and empowers effective responses.
“The key is to get the right risk managers focused on inflection points where fake evidence — AI-generated or not — could be inserted to set up a new vendor, issue a payment to the wrong place, ship a product to the wrong place, create a fake customer or whatever your high-risk scenarios are,” Lee said. “You might already have those scenarios planned, so revisit them with this new threat model in mind. That’s the key to remaining risk-informed and to updating controls that address these emerging risks.”
Content disclaimer
This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.
Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.
For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.
Share with your network
Share