Key takeaways
- Tech-enabled fraud: Generative AI and other technologies allow fraud perpetrators to manipulate identity checks and bypass voice authentication, leaving European businesses open to exploitation, particularly through Know Your Customer identity verification.
- Impact of AI and fraud legislation: Corporate AI governance demands are accelerating under the EU AI Act, while UK businesses face greater liability under the Failure to Prevent Fraud offence, introduced by the Economic Crime and Corporate Transparency Act (ECCTA).
- Document verification methods: New documents should be checked against historical, verified ones from the same vendor, to detect any signs of digital forgery. Matching metadata creation timestamps against corresponding emails or system logs allows accountants to check documents against an established timeline.
Today’s fraud landscape is defined by accessible, cheap, powerful technology. As Gomez Igbo, Director at Forensic Risk Alliance, notes on emerging trends: “Scam toolkits and fraud-as-a-service phishing kits are making deepfakes a lot easier for your average Joe to create.”
Generative AI allows fraud perpetrators to manipulate identity checks, construct realistic WhatsApp or email screenshots, and bypass voice authentication.
For example, Know Your Customer (KYC) identity verification, which may include asking new customers to send photos of themselves when opening an account, can be bypassed: “Companies that develop KYC tools are trying to catch up, but AI is moving faster and faster every day, so we’ve got more sophisticated models.”
“Perpetrators can also leverage AI to manipulate organisations into generating content that might falsify a claim,” says Igbo. He cites the example of a large-scale motor insurance fraud where the scammer made 25 fraudulent claims worth over £440,000. The offender, a motor insurance insider, used AI to repurpose legitimate claim documentation, such as photos of wrecked vehicles and invoices.
AI governance is also a challenge for businesses, adds fellow Forensic Risk Alliance Director James Norden. “With stricter legislation, such as the EU AI Act, and increased enforcement across regulated industries, such as financial services and healthcare, the extra level of scrutiny adds considerable pressure for in-house teams.”
Norden adds that the proliferation of scams, such as deepfakes, has created a “general erosion of digital trust among the public.”
Impact on accountants and auditors
Igbo recommends that as well as using tools to identify red flags in real time, internal accountants need to ensure multi-factor authentication and greater care is taken when verifying digital counterparty identities and documents.
Norden, meanwhile, reminds external auditors to take note of the revised ISA (UK) 240 standards regarding ‘The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements’, which come into effect in December 2026.
Crucially, using AI-enabled technology does not shift accountability away from financial professionals. Norden emphasises that blind trust in automated systems has serious consequences: "Relying on technology when using AI without independently checking its outputs will constitute negligence, which could result in professional negligence claims and regulatory penalties."
Prevention measures that finance teams and firms should consider include:
- Leveraging technology: Organisations must adopt robust control frameworks to combat modern fraud mechanics, using a combination of fighting technology with technology.
- Enhancing core technical controls: Implement mandatory multi-factor authentication and dual access controls across all accounting software and communication channels, where possible.
- Maintaining human-in-the-loop safeguards: Ensure critical decision points – especially payment authorisations and vendor onboardings – require human verification and approval.
- Segregation of duties: Segregate build from approval: whoever builds an automated workflow should not also approve its financial outputs.
Document and data verification
When assessing documents for potential manipulation, Norden and Gomez Igbo advise applying a systematic, multi-layered approach:
Baseline checks mean accountants and auditors compare new documents, such as invoices, against historical verified documents from the same vendor. Gomez Igbo recommends inspecting details such as whether fonts, alignment and formatting are consistent.
“Metadata is an item that people rarely check, but it’s actually a pretty quick way to see if something is unusual,” says Igbo. He urges checking file properties for unusual authors, creation software and creation dates. Matching metadata creation timestamps against corresponding emails or system logs means a timeline can be developed and checked to ensure it is logical.
“This is where you start to enter forensic territory, but there is a lot that accountants can do to see if there is an early version of a document based on the Adobe history, for example,” Igbo adds. “If you’re looking at a PDF or Word document history, try to see if there’s potential hidden text in a file. A PDF or Word file isn't a flat picture; it's a container with a history.”
Identifying fraud using large-scale data analytics
Dynamic technology solutions can also be used to review large datasets.
Interactive dashboards help accountants spot hidden transaction patterns and anomalies, such as multiple entries posted just below approval thresholds, across entire accounting ledgers.
To avoid alert fatigue, accountants should shift from rigid rules (such as reviewing transactions above certain monetary values) to context-aware machine learning to identify red flags. As datasets grow, teams must continuously calibrate sensitivity thresholds to keep detection mechanisms sharp and reduce false positives.
In investigations, AI platforms such as Relativity aiR helps forensic accountants pick out fraud patterns such as unusual payment paths, accounting inconsistencies and policy breaches, taking this task down to hours rather than weeks, which was the case when these tasks were performed manually by humans.