Skip to main content
Category: Fraud Risk Management

Billing Scheme

Also known as: False Billing Scheme, Billing Fraud
Simply put

A billing scheme is a type of fraud in which someone causes an organization to make a payment by submitting false or manipulated invoices. This may involve bills for goods or services that were never provided, inflated invoices, or other manipulation of the billing and payments process to obtain money that is not owed. It typically targets an organization's disbursement or payments system.

Formal definition

A billing scheme is a fraudulent disbursement technique in which a perpetrator manipulates an organization's billing or payment processes to cause it to issue a fraudulent payment. Common variants include submitting bills for bogus or nonexistent goods or services and presenting inflated invoices. Such schemes attack the payments system and are frequently enabled by weaknesses in internal controls, including inadequate controls over computer and system access; conversely, proper access controls and disbursement controls can help deter and prevent them. This entry is educational and general in nature; the specific classification, controls, and remedies applicable to a given situation depend on the facts, the organization, and applicable jurisdiction, and it is not legal, audit, or compliance advice.

Why it matters

Billing schemes strike at the disbursement process, one of the most direct pathways by which an organization loses money to fraud. Because the payments system is designed to move funds out of the organization, a perpetrator who can introduce a false or inflated invoice into that flow can convert a routine business process into a source of illicit gain. This makes billing schemes a persistent concern for management, which owns the design and operation of disbursement controls, and for assurance functions such as internal audit, which test whether those controls operate effectively.

The threat is often enabled by weaknesses in internal controls, including inadequate controls over computer and system access. When access to billing or payment systems is not properly restricted or segregated, an individual may be able to create, approve, or alter payments without independent oversight. Conversely, proper access controls and disbursement controls can help deter and prevent these schemes, which is why they are a recurring focus of control assessments and fraud risk evaluations.

For governance and oversight purposes, billing schemes illustrate the practical link between fraud risk management and the everyday accounts-payable process. Boards and audit committees generally rely on management to maintain controls in this area and on assurance functions to provide independent evidence about their effectiveness. This entry is educational and general in nature; whether a particular arrangement constitutes a billing scheme, and what controls or remedies apply, depends on the facts, the organization, and the applicable jurisdiction.

Who it's relevant to

Chief Compliance and Risk Officers
Billing schemes are a recognized category of occupational fraud that typically feature in fraud risk assessments. Risk and compliance leaders generally consider where an organization's disbursement processes are exposed and whether preventive and detective controls address the risk of false or inflated invoices. Ownership of the underlying controls, however, usually sits with management rather than the compliance function itself.
Internal Auditors
As an independent assurance function, internal audit is often positioned to test whether controls over billing and payments are designed appropriately and operating effectively, including access controls and segregation of duties. Investigations into false billing schemes commonly yield lessons learned and recommendations to help prevent recurrence, which internal audit may track and follow up on.
Management and Finance Functions
Management owns the design and operation of disbursement and payment controls, including controls over computer and system access that these schemes frequently exploit. Accounts-payable and finance teams are generally responsible for the day-to-day processes, invoice validation, approval, and system access, that determine whether a fraudulent payment can enter the disbursement flow.
Boards and Audit Committees
Boards and their audit committees typically exercise oversight of fraud risk rather than operate controls directly. They generally rely on management to maintain effective disbursement controls and on assurance functions to provide independent evidence about how well those controls address risks such as billing schemes.

Inside Billing Scheme

Definition
A billing scheme is a type of asset misappropriation fraud in which a perpetrator causes the organization to issue a payment by submitting or manipulating invoices or other billing documents for fictitious, inflated, or personal purchases. It is generally classified within occupational fraud typologies as a disbursement fraud.
Shell company schemes
A common variant in which a fraudster sets up a fictitious vendor entity and submits invoices for goods or services that were never provided, causing payments to flow to an account the fraudster controls.
Non-accomplice (pass-through) vendor schemes
A variant in which purchases are made through an intermediary at inflated prices, or a legitimate vendor's invoices are used improperly, resulting in the organization paying more than the true cost.
Personal purchases schemes
A variant in which an employee causes the organization to buy goods or services for personal benefit and processes them as legitimate business expenses through the accounts payable or purchasing process.
Control environment relevance
Billing schemes typically exploit weaknesses in the procure-to-pay cycle, such as inadequate segregation of duties, weak vendor master file management, and insufficient approval or matching controls. These are generally the ownership of management as part of internal control over financial reporting and operations.
Lines of accountability
Prevention and detection responsibilities are distributed: management (first line) owns the design and operation of controls; risk and compliance functions (second line) may monitor and set policy; and internal audit (third line) provides independent assurance. The board or audit committee typically holds oversight responsibility rather than operational duty.

Common questions

Answers to the questions practitioners most commonly ask about Billing Scheme.

Is a billing scheme the same as a corruption or bribery scheme?
No. A billing scheme is generally classified as a form of asset misappropriation, in which a fraudster causes an organization to issue payments through submission of false or inflated invoices (often via shell companies, non-accomplice vendors, or personal purchases). Corruption schemes, by contrast, typically involve the misuse of influence in a transaction, such as bribery or kickbacks. The two can overlap in practice, but they are distinct categories, and treating them as interchangeable can misdirect both prevention and investigation efforts. Which category applies depends on the specific facts.
Does detecting billing schemes fall to the internal audit function alone?
Not exclusively. Prevention and detection of billing schemes typically involve several distinct roles. Management generally owns the design and operation of controls over the procure-to-pay process as a first-line responsibility. Compliance and risk functions may monitor and assess fraud risk as part of a second-line role. Internal audit generally provides independent assurance over the effectiveness of those controls as a third-line function, but it does not own the controls themselves. Attributing sole responsibility to any one function can create gaps in accountability. The precise allocation of duties varies by organization.
What controls are commonly used to reduce the risk of billing schemes?
Organizations commonly rely on segregation of duties (for example, separating vendor setup, invoice approval, and payment functions), independent verification of new vendors, matching of purchase orders, receiving records, and invoices, and approval thresholds. Periodic vendor master file reviews and analysis for duplicate or sequential invoice numbers are also frequently used. The suitability and design of any control depend on the entity's size, sector, and risk profile, and management is responsible for determining which controls are appropriate. This is educational information, not audit or compliance advice.
How can an organization assess whether its anti-billing-scheme controls are working?
Assessment typically distinguishes between control design and operating effectiveness. Evaluating design considers whether a control, if operating as intended, would prevent or detect the scheme; evaluating operating effectiveness considers whether the control actually functioned consistently over the relevant period. Testing may include sampling transactions, reperformance, and reviewing exception reports. Because inherent risk and residual risk differ, an organization generally assesses the risk remaining after controls are applied. Conclusions depend on the facts and the judgment of those performing the assessment.
What red flags might indicate a possible billing scheme?
Indicators frequently discussed include vendors with addresses matching employee addresses or P.O. boxes, invoices lacking detail or purchase order references, amounts consistently just below approval thresholds, sequential or unusually round invoice numbers, and vendors with no verifiable business presence. These are potential warning signs rather than proof of wrongdoing; each may have a legitimate explanation. Any conclusion generally requires further inquiry and professional judgment, and identification of red flags does not itself establish that fraud has occurred.
How should billing scheme risk be reflected in an organization's fraud risk assessment?
Billing scheme risk is often addressed as one component of a broader fraud risk assessment, which typically considers the likelihood and potential impact of identified risks and maps them to existing controls. This work is generally a management responsibility, with oversight commonly provided by the board or an audit committee, and it may draw on frameworks such as those addressing fraud risk management. The depth and format of the assessment vary by entity, sector, and jurisdiction, and no single approach is universally required.

Common misconceptions

Billing schemes are primarily an external threat carried out by outside vendors.
Billing schemes are generally categorized as occupational fraud and often involve or are enabled by insiders who understand and can circumvent the organization's purchasing and payment controls, sometimes in collusion with external parties.
Preventing billing schemes is the responsibility of internal audit.
Under commonly used three-lines models, prevention and detection through control design and operation is typically owned by management (the first line). Internal audit provides independent assurance over those controls but does not own them, and the board or audit committee provides oversight rather than day-to-day control.
A clean external financial statement audit means billing schemes are not occurring.
Financial statement audits are generally designed to obtain reasonable, not absolute, assurance about material misstatement and are not primarily designed to detect all fraud, particularly smaller or well-concealed billing schemes. Their scope and objectives differ from fraud-specific investigations or continuous monitoring.

Best practices

Enforce segregation of duties across the procure-to-pay cycle so that no single individual can create a vendor, approve a purchase, and authorize payment.
Maintain disciplined vendor master file governance, including verification of new vendors, periodic review for duplicate or dormant entries, and controls over changes to vendor bank details.
Apply matching controls (such as purchase order, receiving, and invoice matching) and set thresholds that require appropriate independent approval for exceptions.
Use data analytics and continuous monitoring to identify red flags such as invoices just below approval limits, duplicate payments, vendors sharing addresses or bank accounts with employees, and unusual invoice patterns.
Establish and publicize confidential reporting channels, recognizing that tips are frequently a leading route to detecting occupational fraud, and ensure allegations are triaged by an appropriate function.
Ensure the audit committee or board receives periodic reporting on fraud risk in disbursements and confirms that management maintains, and internal audit periodically tests, the relevant controls.