Procurement fraud is the corruption branch of the fraud tree with a purchase order attached. It is the most expensive category of occupational fraud per case in most organisations (the ACFE’s Occupational Fraud 2026 report puts corruption in 45 percent of its 2,402 cases with a median loss of 150,000 dollars, half again the median for asset misappropriation), the hardest to find with document tests, because every document in a corrupt purchase is genuine, and the one most likely to involve a manager, because the ability to influence a purchasing decision is what makes the scheme possible. It also has the longest reach outside the organisation: a kickback paid to win a contract is a bribe, and bribery of officials is a crime under the Foreign Corrupt Practices Act, the UK Bribery Act and their equivalents; collusion among bidders is a crime under competition law, and in the United States the Department of Justice’s Procurement Collusion Strike Force has pursued bid rigging in public contracting since 2019; and fraud in public procurement can trigger civil liability under the False Claims Act far beyond the value of the purchase.
This guide covers the three families of procurement fraud, bid rigging, kickbacks and phantom vendors, and the five schemes that cluster around them (conflicts of interest, price creep, split purchases, change-order abuse and subcontractor substitution), with how each works, who runs it, the indicators competition authorities and fraud examiners have catalogued, the controls that prevent each, and the analytics that detect them. It then gives the legal frame in plain terms, a twelve-test audit program, a worked example from Brightwater Foods’ first procure-to-pay fraud analytics run, and the findings that recur. It is the purchasing branch of the fraud tree guide; the process audit it sits inside is how to audit procurement, the payments side is how to audit accounts payable, and the cross-table tests are catalogued in the procurement fraud analytics guide.
In this guide
- The procurement fraud map: schemes by stage of the cycle
- Bid rigging: the four forms and the indicators
- Kickbacks, price creep and the tolerance band
- Phantom vendors and conflicts of interest
- Split purchases, change orders and substitution
- Preventing it: the eight controls that matter most
- The legal frame in plain terms
- The 12-test audit program
- Worked example: Brightwater Foods’ first procurement fraud run
- The findings that recur, and wording that lands
- Where to go next
The procurement fraud map: schemes by stage of the cycle
Procurement fraud is easiest to understand by where in the cycle it operates, because the stage determines who can do it and what record it leaves. The need stage (someone decides what to buy) is where specifications are tailored and unnecessary purchases originate. The sourcing stage (bids, quotes, tenders) is where bid rigging and leaking happen. The award and contracting stage is where kickbacks are agreed and terms are written to favour the vendor. The ordering stage is where purchases are split to avoid approval and orders are raised after the fact. The receiving stage is where short deliveries, substitutions and receipt-before-arrival live. The invoicing and payment stage is where inflated invoices, phantom vendors and duplicate payments operate. And the contract management stage, the longest and least watched, is where price creep, change-order abuse and scope drift accumulate for years.
| Stage | Schemes | Who typically runs it | What the record looks like |
|---|---|---|---|
| Need and specification | Specification tailoring; unnecessary or excessive purchases; requirements written by the vendor | Requester, technical lead, with a favoured vendor | A legitimate requisition with a specification only one vendor can meet |
| Sourcing | Bid rigging (cover bidding, suppression, rotation, market allocation); leaking of competitors’ bids; sham competitive quotes | Buyer with colluding vendors; or vendors alone | A competition with the right number of bids and the wrong outcome |
| Award and contracting | Kickbacks agreed for the award; favourable terms (payment, price escalation, exclusivity) inserted; sole-source justifications written to fit | Buyer, budget owner, executive | A signed contract, approved through the delegation |
| Ordering | Split purchases to stay under approval limits; orders raised after the invoice; orders to unapproved vendors under approved ones | Requester, buyer | Many small orders; purchase orders dated after invoices |
| Receiving | Short deliveries accepted; product substitution; receipts posted without inspection; goods diverted at the dock | Receiver, with or without the vendor | A receipt that matches the order and not the goods |
| Invoicing and payment | Inflated invoices; phantom vendors; duplicate and pass-through invoicing; payment redirection | Approver, payables clerk, vendor | Invoices that match, from vendors that exist on paper |
| Contract management | Price creep at renewals; change orders and scope drift; unindexed escalations; subcontractor substitution; expired contracts still paid | Contract owner, buyer, vendor | A contract file nobody has opened since signature |
Bid rigging: the four forms and the indicators
Bid rigging is an agreement among bidders, sometimes with an insider, to decide who wins a competition that is supposed to decide it. Competition authorities describe four forms, and they combine. Cover bidding (or complementary bidding) is the most common: competitors submit bids that are intended to lose, priced too high or with terms the buyer cannot accept, to create the appearance of competition. Bid suppression is an agreement by one or more bidders not to bid, or to withdraw, so that a designated bidder wins. Bid rotation is an agreement to take turns winning across a series of contracts, which keeps every conspirator in business. Market allocation is a division of customers, territories or product lines so that competitors do not bid against each other at all. An insider adds two mechanisms: leaking competitors’ bids or the buyer’s budget to the favoured bidder, and writing specifications or evaluation criteria that only the favoured bidder can meet. The OECD’s guidelines for fighting bid rigging in public procurement and the Department of Justice’s Antitrust Division both publish indicator lists, and the ones below are the ones that survive contact with real tender files.
| Indicator | What it looks like in the file | What it suggests | Test |
|---|---|---|---|
| Bid documents that resemble each other | Identical arithmetic errors, formatting, typefaces, phrasing; the same courier or metadata author; bids submitted from the same address or IP | Cover bids prepared by the winner for the losers | Compare bid documents’ metadata and text across bidders; check submission logs |
| The same winner, or a rotation | One vendor wins every tender in a category; or wins rotate in a pattern; losing bidders never lower their prices over time | Rotation or allocation | Winner concentration by category and buyer over three years; bid price trends by bidder |
| Bid prices that make no sense | Losing bids far above the winner; identical bids; a bidder’s price higher for a nearby delivery than for a distant one; prices that drop sharply when a new bidder appears | Cover bidding; the true competitive price is the one the new entrant forced | Bid spread analysis; price response to new entrants |
| Few bidders in a market with many suppliers | Three invitations every time, the same three; qualified suppliers never invited; bidders withdrawing after submission | Suppression; a buyer controlling the invitation list | Invitation list against the approved supplier base; withdrawal analysis |
| Losers as subcontractors or suppliers to the winner | A losing bidder is paid by the winner for the same scope; invoice line descriptions reveal it | Compensation for a cover bid | Bid-loser-as-subcontractor test across tenders and invoices |
| Specifications only one bidder can meet | Brand names, proprietary features, delivery windows or certifications that fit one supplier; specifications drafted by that supplier | Tailoring by an insider | Specification review by someone independent of the requester; author metadata on specification documents |
| Late changes and short windows | Tender periods too short for a new bidder; specification changes late in the process known to one bidder; evaluation criteria changed after bids opened | Leaking and manipulation | Timeline reconstruction from the tender log; who accessed the bid documents and when |
Kickbacks, price creep and the tolerance band
A kickback is a payment from a vendor to the person who can send it business, funded by the organisation’s own money through inflated prices, inflated quantities, unnecessary purchases or accepted substandard goods. It is the fraud tree’s invoice-kickback scheme, and it is the hardest procurement fraud to prove because the payment happens outside the organisation’s records: cash, a job for a relative, a holiday, a share of a side business. What the organisation’s records do show is the price, and the price is where the scheme is found. Three patterns recur. Price creep: the favoured vendor’s prices rise at every renewal, a few percent at a time, never enough to trigger a re-bid, managed by one buyer who always has a reason; over four renewals a 5 to 7 percent step each time compounds to a quarter above market, which is where the kickback lives. The tolerance band: three-way match tolerances (5 percent or a fixed amount per line are common) exist to stop the payables team chasing rounding differences, and a vendor who prices every invoice 4 percent above the order, with a buyer who never objects, is inside the band and outside the control; MidState’s 5 percent or 250-dollar tolerance, unchanged since 2019, is the example in the RCM guide. And quantity and quality games: over-delivery accepted and paid, short delivery not deducted, a lower grade received against a higher grade ordered, each of which passes the match because the receiver is the buyer’s colleague or the buyer.
| Pattern | Indicators | Control that prevents it | Analytic that detects it |
|---|---|---|---|
| Price creep at renewal | Sole-source renewals; increases at every renewal with no index; one buyer owning the relationship for years; a supplier whose prices to the organisation exceed its list prices or market benchmarks | Re-bid or benchmark cycle for every contract above a threshold; indexed escalation clauses; buyer rotation on key categories; renewal approval outside purchasing | Unit price trend by item and vendor against contract and index; renewal step analysis; buyer-vendor tenure |
| Inside the tolerance band | Invoice prices consistently above order prices but within tolerance; the same vendor and buyer every time | Tolerance set as low as the process can bear; price variance within tolerance reported by vendor and reviewed monthly; buyers cannot change order prices after the fact | Cumulative in-band variance by vendor and buyer; share of a vendor’s invoices priced above order |
| Quantity and quality | Over-receipts accepted; short deliveries never claimed; grade substitutions; returns rare for a vendor with quality complaints | Receiver independent of the buyer; over-receipt blocks; quality inspection on receipt with sampling; claims process for shortages | Received against ordered by vendor; shortage claims by vendor against deliveries; quality complaints against returns |
| Unnecessary purchases | Stock of an item rising while consumption is flat; services invoiced without deliverables; consultants with no output | Requisition justification and budget check; consumption-based reorder; deliverable acceptance before payment for services | Purchases against consumption; service invoices without acceptance records |
| The payment outside the records | A buyer living beyond their means; a vendor’s employee related to the buyer; hospitality and gifts from one vendor; the buyer refusing rotation or leave | Conflict-of-interest and gifts registers with attestation; mandatory leave; rotation; vendor hotline | Gifts register against awards; HR data on leave patterns; hotline analysis by vendor |
Phantom vendors and conflicts of interest
A phantom or shell vendor is a supplier that exists on paper and in the vendor master and nowhere else: the perpetrator creates it, submits its invoices for goods or services never provided, approves them, and collects the payments through a bank account they control. It is the fraud tree’s shell-company billing scheme, it sits in the asset-misappropriation branch rather than corruption because no genuine vendor is involved, and it is the scheme every vendor-master control exists to stop. Its cousin is the pass-through vendor, a real intermediary the perpetrator owns that buys from the genuine supplier and resells to the organisation at a markup. Conflicts of interest are the corruption-branch version: the vendor is real and provides real goods, but the employee who steers the business owns it, or a relative does, and has not disclosed it; the loss is the margin the organisation would not have paid a stranger, and the risk is that the relationship becomes a kickback or a phantom over time. All three are found in the vendor master and the employee master, joined.
| Indicator | Phantom vendor | Pass-through vendor | Undisclosed conflict |
|---|---|---|---|
| Vendor-master profile | PO box or residential address; no tax ID or a personal one; free email domain; no website; created by or at the request of the approver | Recent incorporation; no manufacturing or service capability; address matching an employee or a registered-agent | Genuine business; address, phone, bank or officer matching an employee or a relative |
| Invoice pattern | Round amounts; sequential invoice numbers (the organisation is the only customer); generic descriptions; no purchase order or always under the PO threshold | Prices above what the genuine supplier charges others; invoices that reference the genuine supplier’s part numbers | Prices at or above market; renewals without competition; volumes rising with the employee’s tenure |
| Approval pattern | One approver every time; the approver created or requested the vendor; payments urgent | One requester; sole-source justification citing “relationship” | The related employee approves or requests; competing quotes obtained from firms that never win |
| Control that prevents it | Vendor creation independent of requesting and approving; verification of existence, tax ID and bank; screening against the employee master at creation | Beneficial ownership check for new vendors above a spend threshold; price benchmarking | Conflict-of-interest disclosure with annual attestation and cross-check to the vendor master; recusal enforced |
| Analytic that detects it | Vendor-employee matches (bank, address, phone, tax ID); shell-profile scoring; sequential invoice numbers; single-approver vendors | Price against the genuine supplier’s list; vendor incorporation date against first order | Vendor-employee matches including relatives’ surnames and shared addresses; single-requester vendors; renewal without competition |
Split purchases, change orders and substitution
Three schemes cluster around the main families and are found by the same analytics program. Split purchases divide a requirement into orders that each sit under an approval limit or a tender threshold, so that a buyer or requester can commit spend they are not authorised to commit; the pattern is a cluster of orders to one vendor from one requester within days, each just under the limit, and the finding is a control finding about the threshold logic whether or not a kickback sits behind it. Change-order abuse is the contract-management version of bid rigging: a vendor wins a competitive tender with a low price and recovers the margin through change orders, scope additions and claims approved by a contract owner who does not compare the final cost with the losing bids; the indicator is a contract whose final value exceeds the second-lowest bid, and the control is change-order approval outside the project with a running comparison to the tender. Substitution is delivery of something other than what was contracted, a lower grade of ingredient, a counterfeit component, an uncertified subcontractor; it is a quality-control and receiving failure until someone benefits from it, and then it is fraud, and in public contracting it is the classic False Claims Act case. Product substitution is found by inspection and testing, not by data, which is why the receiving controls in the inventory guide include quality inspection on receipt.
Preventing it: the eight controls that matter most
Procurement controls multiply easily and most of them are paperwork. Eight carry the weight, and a procurement fraud audit tests whether these eight operate before it tests anything else. Independent vendor creation: nobody who requests or approves purchases can create or change a vendor, and every new vendor is verified (existence, tax identifier, bank account ownership) and screened against the employee master and the conflicts register before its first payment. Competition with teeth: a threshold above which competition is mandatory, an invitation list drawn from the approved base rather than the buyer’s contacts, sealed bids opened by a panel, evaluation on criteria published before bids are received, and losing bids kept. Re-competition on a clock: every contract above a threshold re-bid or benchmarked on a fixed cycle, with renewals approved outside purchasing and price steps indexed. Threshold logic that aggregates: approval limits applied to the vendor-requester total over a window, not to each order, and after-the-fact orders reported. Receiving independent of buying: receipts posted from a dock count by someone who did not order, over-receipts blocked, quality inspected on a sampling basis for ingredients and components. Tolerances that are watched: match tolerances set as low as the process bears, with cumulative in-band variance reported by vendor. Disclosure that is checked: annual conflict-of-interest and gifts attestations cross-matched to the vendor master and the award log, with recusals enforced in the workflow. And a channel for vendors: a hotline that suppliers know about, because the losing bidder who was asked for a cover bid is the witness every bid-rigging case needs, and the vendor asked for a kickback is the one who knows the buyer’s price.
The legal frame in plain terms
Four bodies of law reach into procurement fraud, and the auditor needs them at the level of knowing when to call counsel. Anti-bribery law: the US Foreign Corrupt Practices Act criminalises bribes to foreign officials and requires accurate books and records and internal accounting controls of issuers; enforcement was paused by executive order on 10 February 2025 and resumed under Department of Justice guidelines issued on 9 June 2025 that prioritise cases connected to cartels and transnational criminal organisations, harm to US competitiveness, national security, and serious misconduct, while de-emphasising routine business courtesies and facilitation payments; the SEC’s civil enforcement priorities were not announced as changed. The UK Bribery Act 2010 goes further, covering private-sector bribery and creating a corporate offence of failing to prevent bribery with an adequate-procedures defence, which is why UK-connected companies audit their procurement against those procedures. Competition law: bid rigging is a criminal cartel offence in the United States under the Sherman Act and in most jurisdictions, pursued against the colluding vendors and against insiders who facilitate; an organisation that discovers rigging in its own tenders is a victim with a decision to make about reporting. Public procurement and false claims: fraud against government buyers carries statutory penalties (in the US, treble damages and per-claim penalties under the False Claims Act, with whistleblower rewards), and contractors’ own procurement fraud can bar them from public work. And the corporate enforcement policies covered in the first-48-hours guide, under which self-disclosure timing decides the outcome. The practical consequence: a procurement fraud finding with a foreign official, a public buyer, or a cartel in it is a legal matter from the moment of predication, and the audit function’s job is to preserve and hand over, not to interview the buyer.
The 12-test audit program
The program below is the fraud-focused overlay on the procurement audit; sample sizes follow the standard conventions, selections go in the sampling memo, and the analytics are those of the procurement fraud catalog, run first so that their hits become the judgmental selections.
- Tender file review. Sample 25 competitive awards above the tender threshold, or all if fewer. Attributes: invitation list drawn from the approved base; sealed bids opened by a panel with a record; evaluation on the published criteria; specification reviewed independently of the requester; award approved by someone outside purchasing; losing bids retained.
- Bid pattern analytics. Full population of tenders for three years: winner concentration by category and buyer; bid spreads; identical or near-identical bids; withdrawals; bidders who never win yet keep bidding; losers paid by winners.
- Sole-source and single-quote awards. All awards above the threshold made without competition. Attributes: justification documented on policy grounds; approved outside purchasing; re-competed within the policy period; price benchmarked.
- Price creep and renewal analysis. Full population of contracts renewed in the period: step at renewal, index provision, re-bid history, buyer tenure; unit price trends by item and vendor for the top 50 vendors.
- Tolerance-band analysis. Full population of matched invoices: cumulative in-band variance by vendor and buyer; vendors with most invoices priced above order; tolerance configuration and change history.
- Vendor-master screening. Full master against the employee master (bank, address, phone, tax ID, surname and shared address for relatives) and against conflict-of-interest disclosures; shell-profile scoring; vendors created by or at the request of their approvers.
- Split-purchase and threshold analysis. Full population of orders: clusters by vendor and requester within a window whose sum exceeds a limit; orders just under limits; orders raised after invoices.
- Receiving integrity. Sample 25 receipts at sites chosen from the analytics. Attributes: receiver independent of the buyer; quantity and grade inspected; over-receipts blocked; shortages claimed; receipt not posted before arrival.
- Change orders and final cost. All contracts above the threshold closed in the period: final value against the winning and second-lowest bid; change orders approved outside the project; scope additions competed where policy requires.
- Gifts, hospitality and conflicts. Inspect the registers and the attestation completion; cross-match gifts to awards by date and vendor; test that recusals were enforced.
- Subcontractors and beneficial ownership. For the 20 largest vendors and every tender winner in the period: subcontractor disclosures, beneficial ownership checks, sanctions and adverse-media screening; losers appearing as subcontractors.
- Hotline and prior-incident review. Inspect procurement-related hotline reports and incidents for three years; test that each was investigated under the protocol and that control findings from them were implemented; look for vendors or buyers that recur.
Worked example: Brightwater Foods’ first procurement fraud run
Brightwater Foods is the 180-million-dollar food manufacturer used across this site: three plants, about 600 staff, and a co-sourced internal audit function that its first chief audit executive later rebuilt. Its first procure-to-pay fraud analytics run, written up test by test in the procurement fraud analytics guide, covered eighteen months of data: 22,400 invoices, 1,860 active vendors, 9,100 purchase orders and 41 tenders, with a plant approval limit of 10,000 dollars. Data preparation took the co-source analytics specialist eight days, mostly on address normalisation and on reconciling a receiving log that lived in a warehouse system outside the ERP; the tests ran in a day; the triage and corroboration took the rest of the engagement. The table maps the run’s results onto the scheme families above, which is how the results were reported to the audit committee: not as a list of anomalies, but as what each family of procurement fraud looked like at Brightwater and what was done about it.
| Scheme family | What the run found | Outcome |
|---|---|---|
| Bid rigging: losers as subcontractors | Two of 41 tenders where a losing bidder was paid by the winner for the same scope, visible in invoice line descriptions | Handed off under the fraud protocol; the investigation found an undisclosed arrangement between the two vendors and no employee involvement; both removed from the approved list |
| Kickbacks: price creep | One ingredient supplier’s prices rising 5 to 7 percent at each of four renewals without a re-bid, managed by one buyer, among 15 item-vendor pairs with unindexed increases | Re-bid ordered; the incumbent’s renewal price fell 11 percent; no relationship found between buyer and vendor, but the finding on sole-source renewals stood |
| Conflicts of interest: undisclosed ownership | Two vendor-employee bank matches: a disclosed family business under the conflicts policy, and a cleaning contractor owned by a plant supervisor’s spouse, undisclosed, with 61,200 dollars paid over the period and the supervisor approving the invoices | Handed off; the matter went to HR and legal; control finding on conflict-of-interest attestation and vendor-master screening at creation |
| Split purchases | Nine order clusters at one plant, one buyer and one packaging vendor, all in the band under the 10,000-dollar plant approval limit | Control finding: the buyer split orders to avoid the plant manager’s approval; no vendor relationship found; the threshold logic and the buyer’s authority were changed |
| Ordering after the fact | 38 purchase orders raised after the invoice, concentrated in two cost centres with no emergency justification | Control finding on after-the-fact ordering; policy tightened and the cost centres’ approvers changed |
| Receiving bypass | 16 match overrides by one accounts payable clerk for one vendor, all with receipts posted days later | Investigated: the clerk was clearing a backlog under pressure from the plant; the vendor was genuine; control finding on override authority and monitoring |
| Payment redirection | 29 bank-detail changes followed by payments within the window, 27 verified by call-back | Two without verification investigated and confirmed genuine; call-back evidence moved to the vendor record |
The run produced two referrals and five control findings, and neither referral involved an employee taking a kickback, which is typical: most procurement fraud analytics find the conditions for corruption more often than corruption, and the conditions are the finding. Three things generalise. The bid-loser-as-subcontractor test found collusion that no tender file review would have found, because both tender files were clean; the evidence was in the winners’ invoices. The price-creep finding stood on its own even after the investigation cleared the buyer, because a 25 percent premium accumulated over four uncontested renewals is a loss whether or not anyone was paid for it. And the conflict-of-interest case was found by joining two masters that nobody had joined before, which is the single most productive hour in any first procurement fraud run.
The findings that recur, and wording that lands
Five findings account for most procurement fraud reports, and each lands in five-Cs form with a number attached. Sole-source renewals (“15 contracts worth 4.2 million dollars a year were renewed without competition in the period; one supplier’s prices rose 5 to 7 percent at each of four renewals and fell 11 percent when re-bid; policy requires re-competition every three years”). Threshold logic (“nine order clusters at one plant were split to remain under the 10,000-dollar approval limit; the system permits multiple orders to one vendor from one requester in a day without aggregation”). Vendor-master screening (“the vendor master is not screened against the employee master at creation; the run found an undisclosed vendor owned by a supervisor’s spouse, paid 61,200 dollars over eighteen months on invoices the supervisor approved”). Tender integrity (“two of 41 tenders show a losing bidder subsequently paid by the winner for the tendered scope; the tender procedure has no subcontractor-disclosure requirement”). And override governance (“16 three-way-match overrides were released by one payables clerk for one vendor with receipts posted after payment; override rights are not limited or monitored”). Write the cause as the decision that produced the condition (a renewal policy nobody enforces; an approval logic without aggregation; a vendor-creation process that never asked) and follow the root cause guide.
Where to go next
Audit procurement fraud as patterns rather than documents: join the masters, trend the prices, compare the bids across years, and read the winners’ invoices for the losers’ names. The process audit the overlay sits on is how to audit procurement; the tests are catalogued in procurement fraud analytics; the vendor-master controls are in the vendor master audit; the payments side in how to audit accounts payable; what to do when a hit is real in the first-48-hours protocol; and the taxonomy behind it all in the fraud tree guide.
Related guides
- Procurement fraud analytics — the twenty cross-stage tests and Brightwater’s full run
- How to audit procurement — the process audit this overlay belongs to
- How to audit the vendor master — screening, verification and change control
- How to audit accounts payable — the payments side, with a worked engagement
- The accounts payable analytics catalog — vendor-master and duplicate tests
- The ACFE fraud tree explained — where each scheme sits
- How to run a fraud risk assessment — the purchasing scenarios in the register
- When internal audit finds fraud: the first 48 hours — the hand-off
- Fraud red flags — the behavioural signals around a buyer
- Third-party risk management program — vendor governance beyond fraud
- Vendor due diligence by risk tier — beneficial ownership and screening at onboarding
- Segregation of duties — buy, receive, approve, pay
- The five Cs of audit findings — the structure the findings above follow
- All fraud risk guides and all fieldwork and testing guides
Leave a Reply