29th Jul 2026

Latest insights from Cifas and ACFE: How to stop fraud before funds leave the business

Most fraud defence is built to catch the external threat trying to break in. The harder problem to solve, and the one that can cost businesses even more, is the fraud executed by internal threat actors within their own payment runs. I want to walk through what the latest data tells us, how AccessPay’s Payment Screening addresses it, and why layered controls matter more than any single rule or tool.

 

The UK picture

Starting with the Cifas Fraudscape 2026 report, a few numbers stand out.

  • 444,993 fraud risk cases were filed to the National Fraud Database in 2025, a record.
  • In monetary terms, Cifas members prevented £2.4 billion in fraud losses over the year.
  • Insider threat filings rose 21%: ghost employees on payroll, invoices misdirected internally, people exploiting weaknesses in workflows.
  • Payment fraud itself rose 239% across 2025 and now accounts for 40% of misuse filings.

Those are large numbers, and they point at the kind of risk Payment Screening is built to address.

 

The global picture: fraud from the inside

The ACFE’s Occupational Fraud 2026 Report to the Nations looks at 2,402 cases across 143 countries. Whether you operate in the UK only or across Europe, there are lessons in it, because it specifically examines internal fraud: handover and control gaps between teams, synchronisation issues between platforms, weak controls and superficial approvals processes.

Its headline finding has not changed in 30 years. Organisations lose around 5% of annual revenue to fraud.

The methods of attack and defence have both grown more sophisticated, but that 5% has stayed consistent over the years. The median loss is $78,000 – per incident, not per year. The report also makes an even more interesting point: once you have fallen victim to fraudulent activity once, you become more likely to see it again, and at greater value. Asset misappropriation, which includes payment fraud, is present in 90% of cases.

Internal occupational fraud typically runs for 17 months before anyone detects it in environments that are missing controls. With some controls it falls to 11 months, and with layered controls it can fall even further than that.

External fraud, such as APP fraud, infiltrates a workflow, pushes out as much money as it can, and disappears before the bank can stop or trace it. Occupational fraud is lower in individual employee who cannot make the numbers add up, or the introduction of something like Payment Screening or an audit that finally casts a magnifying glass over the process. Undetected, fraud keeps exacerbating in the background, and that is exactly why it requires a different kind of control – always on, and unimpeachable.

 

How AccessPay Payment Screening works

Here is what happens in practice: A payment file comes into the Payments Hub and is submitted to AccessPay. Among the checks we run to make it bank-ready, the Payment Screening rules engine kicks in. Automated screening checks every transaction instantly, against whatever rules you have set for that specific type of payment, so it applies where you want it and nowhere you don’t.

A flag is raised immediately: red, amber or green. Red is high alert, something to be actioned. Green means everything looks fine. What counts as each is entirely configurable, down to the business. Once the flags are up, your finance team reviews and approves. You can let a transaction through once you are satisfied it is legitimate, you can suppress the ones you do not want reaching the bank, or, if the problem sits upstream, you can stop the whole submission and address it higher up before anything leaves the Payments Hub.

Payment Screening is not just a single rule, or a fixed set of rules applied to every submission. It works surgically, applied in exactly the right place, in exactly the right way, to close the specific control gaps in a workflow or the visibility gaps between systems.

Take the creditor unrecognised rule, which addresses the most common attack vector: funds misdirected to an unknown account. The first time an unknown creditor appears in a submission, it is red-flagged and can be dealt with before it reaches the bank. If it turns out to be a legitimate new supplier, the second and third payments raise an amber flag, worth keeping an eye on. Once you have paid them a few times, it moves to green and passes through unencumbered.

 

Layered controls

A single rule on a single submission is useful. Payment Screening becomes far more powerful when you layer rules together to build a barrier around a workflow end to end.

 

Example: The Payroll run

You are very unlikely to want to pay someone you do not recognise in a payroll file, so you apply creditor unrecognised. You want to be sure no payment has slipped in as a duplicate, so you add a duplicate third party rule. You know you pay a fairly consistent number of employees each month, so you apply a transaction count rule. Each rule adds a layer of protection.

Applied together, they build a much stronger barrier against the kind of occupational fraud the ACFE data describes, and they cut into the share of fraud cases that exploit weak or absent internal controls, which sits at around 50%. An attempt that bypasses one rule is caught by another, and it does consistently, at scale, what a manual review cannot, particularly on something like payroll.

 

The bank robber and the getaway car

An analogy I find useful is picturing a bank robber escaping in a getaway car. The police know roughly which roads he will use. One option is to throw a cordon around the whole area and stop every vehicle. It works, in that nothing gets out, but it also stops all the legitimate traffic. Apply that to payments, and now every payment is held for review, legitimate transactions are delayed or blocked, the finance team is overwhelmed with additional manual checks, and fraud still slips through, because there is no intelligence to tell fraud, error and legitimate payment apart, and attention slips the more payments require review.

Now give the police an intelligence briefing instead: the road to watch, the make of car, its colour, its speed, the direction of travel. Legitimate cars keep moving, and the one you are looking for is far easier to spot. That is what Payment Screening does for our customers. Fraud is stopped at the point of submission, before funds leave the business, while legitimate payments flow uninterrupted and only flagged transactions are held for review.

 

Meeting the recommendations

Both reports point out that the strongest fraud prevention results come from multiple controls being used together.

The ACFE data on its top three controls is striking:

  • Surprise audits are associated with 50% lower losses and 50% faster detection; in AccessPay you achieve this through the audit module and by ensuring you have one single platform centralising and running controls on all payments, including ad hoc ones.
  • Management review is associated with 55% lower losses and 44% faster detection; in AccessPay this is achieved through approval groups that enforce multi-level sign-off, so no single person can authorise and send a payment.
  • Proactive data monitoring is associated with 53% lower losses and 44% faster detection; in AccessPay this is achieved via Payment Screening rules.
  • In addition, Cifas recommends stronger internal controls and segregation of duties to counter the rise in insider threat; which can be set up granularly in AccessPay.

 

In short

Audits alone are not proactive enough. Payment Screening, sitting alongside approvals, roles and permissions, and auditing on a single platform, is what turns a reactive process into a proactive one, and stops fraud before funds leave the business rather than chasing it afterwards.

If you would like to see where your own payment controls stand, and where Payment Screening would add a layer, your AccessPay account manager can walk you through a short review.

Request a demo

Related Content

How a construction company’s Treasury Manager tackled fraud and streamlined their treasury operations

How a construction company’s Treasury Manager tackled fraud and streamlined their treasury operations

The Company Founded in 1800’s, this company has always been forward thinkers.  A privately-ow...

New Failure to Prevent Fraud Offence:  Compliance Essentials for Finance Leaders

Webinar

New Failure to Prevent Fraud Offence: Compliance Essentials for Finance Leaders

Operational constraints. Siloed digital systems. Undertrained staff. Unaware leadership. What once m...

Maria Mallaband preserve efficiency & increase security

Maria Mallaband preserve efficiency & increase security

After switching banks and needing to find a third-party system that could offer a smooth transition,...