For the past two years, artificial intelligence has dominated conversations about fraud. Headlines about deepfakes, voice cloning and AI-generated phishing attacks have fuelled concerns that businesses are facing an entirely new threat landscape. The technology is undoubtedly making fraud attempts more sophisticated, but focusing solely on AI risks missing a more important point: AI did not create the underlying problem. It exposed weaknesses that have existed within organisations for years.
Many finance and treasury teams still rely on controls that are fundamentally trust-based. An employee receives an email from a supplier requesting a change to bank account details, or a message from a senior executive asking for an urgent payment. The expectation is that the employee will assess whether the request appears legitimate and act accordingly. For years, this approach was considered sufficient because fraudulent communications were often easy to spot. Poor grammar, unusual wording and suspicious email addresses provided clues that something was not right.
That assumption is becoming increasingly difficult to defend. Today, criminals can generate professional emails in seconds, mimic writing styles and create messages that are virtually indistinguishablefrom genuine business communications. Voice cloning technology allows fraudsters to replicate the tone and mannerisms of senior executives with remarkable accuracy. Deepfake technology continues to improve. As a result, employees are being asked to make decisions based on signals that are becoming less reliable every year.
The challenge is not that employees are becoming less vigilant. Rather, the information available to them is becoming harder to assess. Traditional fraud awareness programmes have often focused on teaching people how to identify suspicious communications. While that remains important, it is becoming increasingly unrealistic to expect employees to detect every sophisticated attempt. When fraudulent requests look, sound and feel legitimate, the burden cannot rest entirely on human judgement.
This is why organisations need to rethink what verification actually means. For many years, businesses have focused on validating communications. They have asked whether an email came from the correct address or whether a request appeared genuine. Increasingly, however, the more important question is whether the information contained within that communication can be independently verified.
The distinction matters. A fraudster may be able to create a convincing email or clone a voice, but verifying beneficiary information is considerably more difficult. When organisations rely on independently validated supplier and payment data, they reduce their dependence on subjective judgement and create controls that remain effective regardless of how persuasive a fraudulent request might appear.
What makes this issue particularly important is that fraud itself is becoming more industrialised. A few years ago, organisations could often identify patterns based on geography or industry. Today, that distinction is becoming less relevant. Fraud-as-a-Service models have enabled criminal groups to operate internationally and at scale. Sophisticated fraud attempts can originate from anywhere and target organisations of any size. Industries with large payment volumes, such as construction and energy, remain particularly attractive targets, but no organisation can assume it is outside the scope of modern fraud operations.
At the same time, businesses are accelerating their adoption of automation and AI. Finance teams are rightly looking for ways to process information faster, reduce manual effort and improve efficiency. Yet automation introduces a simple challenge: if the underlying information cannot be trusted, decisions are simply being made more quickly based on flawed assumptions. AI can analyse enormous quantities of information, but it cannot determine whether inaccurate supplier data is suddenly accurate because it has been processed by a sophisticated model.
This is one reason why verification is becoming increasingly important. In our experience, the vast majority of verification failures are not fraud-related. Manual errors account for around 2% of failures, while actual fraud attempts represent a far smaller proportion. Most issues stem from outdated, incomplete or mismatched information that has accumulated over time. That may sound like an operational problem rather than a fraud issue, but it highlights a critical reality: organisations often place significant trust in data they have never independently verified.
Ultimately, AI is forcing organisations to confront a question they have been able to avoid for years. How much of their payment process is built on trust rather than evidence? For many businesses, the answer is uncomfortable. They have relied on employees to identify suspicious requests, trusted that supplier records were accurate and assumed existing controls would be enough to prevent losses.
Those assumptions are becoming harder to sustain. The organisations that will be most resilient in the years ahead will not necessarily be those with the most advanced fraud detection tools. They will be those that build processes around verification, data integrity and objective validation. AI may have changed the tactics available to fraudsters, but it has also revealed weaknesses that were already present. The businesses that recognise that distinction will be far better positioned to protect themselves in an increasingly complex fraud environment.



