,

Procurement Fraud Schemes: Bid Rigging, Kickbacks and Phantom Vendors, and How to Find Them

Procurement fraud is the corruption branch of the fraud tree with a purchase order attached. It is the most expensive category of occupational fraud per case in most organisations (the ACFE’s Occupational Fraud 2026 report puts corruption in 45 percent of its 2,402 cases with a median loss of 150,000 dollars, half again the median for asset misappropriation), the hardest to find with document tests, because every document in a corrupt purchase is genuine, and the one most likely to involve a manager, because the ability to influence a purchasing decision is what makes the scheme possible. It also has the longest reach outside the organisation: a kickback paid to win a contract is a bribe, and bribery of officials is a crime under the Foreign Corrupt Practices Act, the UK Bribery Act and their equivalents; collusion among bidders is a crime under competition law, and in the United States the Department of Justice’s Procurement Collusion Strike Force has pursued bid rigging in public contracting since 2019; and fraud in public procurement can trigger civil liability under the False Claims Act far beyond the value of the purchase.

This guide covers the three families of procurement fraud, bid rigging, kickbacks and phantom vendors, and the five schemes that cluster around them (conflicts of interest, price creep, split purchases, change-order abuse and subcontractor substitution), with how each works, who runs it, the indicators competition authorities and fraud examiners have catalogued, the controls that prevent each, and the analytics that detect them. It then gives the legal frame in plain terms, a twelve-test audit program, a worked example from Brightwater Foods’ first procure-to-pay fraud analytics run, and the findings that recur. It is the purchasing branch of the fraud tree guide; the process audit it sits inside is how to audit procurement, the payments side is how to audit accounts payable, and the cross-table tests are catalogued in the procurement fraud analytics guide.

In this guide

The procurement fraud map: schemes by stage of the cycle

Procurement fraud is easiest to understand by where in the cycle it operates, because the stage determines who can do it and what record it leaves. The need stage (someone decides what to buy) is where specifications are tailored and unnecessary purchases originate. The sourcing stage (bids, quotes, tenders) is where bid rigging and leaking happen. The award and contracting stage is where kickbacks are agreed and terms are written to favour the vendor. The ordering stage is where purchases are split to avoid approval and orders are raised after the fact. The receiving stage is where short deliveries, substitutions and receipt-before-arrival live. The invoicing and payment stage is where inflated invoices, phantom vendors and duplicate payments operate. And the contract management stage, the longest and least watched, is where price creep, change-order abuse and scope drift accumulate for years.

StageSchemesWho typically runs itWhat the record looks like
Need and specificationSpecification tailoring; unnecessary or excessive purchases; requirements written by the vendorRequester, technical lead, with a favoured vendorA legitimate requisition with a specification only one vendor can meet
SourcingBid rigging (cover bidding, suppression, rotation, market allocation); leaking of competitors’ bids; sham competitive quotesBuyer with colluding vendors; or vendors aloneA competition with the right number of bids and the wrong outcome
Award and contractingKickbacks agreed for the award; favourable terms (payment, price escalation, exclusivity) inserted; sole-source justifications written to fitBuyer, budget owner, executiveA signed contract, approved through the delegation
OrderingSplit purchases to stay under approval limits; orders raised after the invoice; orders to unapproved vendors under approved onesRequester, buyerMany small orders; purchase orders dated after invoices
ReceivingShort deliveries accepted; product substitution; receipts posted without inspection; goods diverted at the dockReceiver, with or without the vendorA receipt that matches the order and not the goods
Invoicing and paymentInflated invoices; phantom vendors; duplicate and pass-through invoicing; payment redirectionApprover, payables clerk, vendorInvoices that match, from vendors that exist on paper
Contract managementPrice creep at renewals; change orders and scope drift; unindexed escalations; subcontractor substitution; expired contracts still paidContract owner, buyer, vendorA contract file nobody has opened since signature

Bid rigging: the four forms and the indicators

Bid rigging is an agreement among bidders, sometimes with an insider, to decide who wins a competition that is supposed to decide it. Competition authorities describe four forms, and they combine. Cover bidding (or complementary bidding) is the most common: competitors submit bids that are intended to lose, priced too high or with terms the buyer cannot accept, to create the appearance of competition. Bid suppression is an agreement by one or more bidders not to bid, or to withdraw, so that a designated bidder wins. Bid rotation is an agreement to take turns winning across a series of contracts, which keeps every conspirator in business. Market allocation is a division of customers, territories or product lines so that competitors do not bid against each other at all. An insider adds two mechanisms: leaking competitors’ bids or the buyer’s budget to the favoured bidder, and writing specifications or evaluation criteria that only the favoured bidder can meet. The OECD’s guidelines for fighting bid rigging in public procurement and the Department of Justice’s Antitrust Division both publish indicator lists, and the ones below are the ones that survive contact with real tender files.

IndicatorWhat it looks like in the fileWhat it suggestsTest
Bid documents that resemble each otherIdentical arithmetic errors, formatting, typefaces, phrasing; the same courier or metadata author; bids submitted from the same address or IPCover bids prepared by the winner for the losersCompare bid documents’ metadata and text across bidders; check submission logs
The same winner, or a rotationOne vendor wins every tender in a category; or wins rotate in a pattern; losing bidders never lower their prices over timeRotation or allocationWinner concentration by category and buyer over three years; bid price trends by bidder
Bid prices that make no senseLosing bids far above the winner; identical bids; a bidder’s price higher for a nearby delivery than for a distant one; prices that drop sharply when a new bidder appearsCover bidding; the true competitive price is the one the new entrant forcedBid spread analysis; price response to new entrants
Few bidders in a market with many suppliersThree invitations every time, the same three; qualified suppliers never invited; bidders withdrawing after submissionSuppression; a buyer controlling the invitation listInvitation list against the approved supplier base; withdrawal analysis
Losers as subcontractors or suppliers to the winnerA losing bidder is paid by the winner for the same scope; invoice line descriptions reveal itCompensation for a cover bidBid-loser-as-subcontractor test across tenders and invoices
Specifications only one bidder can meetBrand names, proprietary features, delivery windows or certifications that fit one supplier; specifications drafted by that supplierTailoring by an insiderSpecification review by someone independent of the requester; author metadata on specification documents
Late changes and short windowsTender periods too short for a new bidder; specification changes late in the process known to one bidder; evaluation criteria changed after bids openedLeaking and manipulationTimeline reconstruction from the tender log; who accessed the bid documents and when

Kickbacks, price creep and the tolerance band

A kickback is a payment from a vendor to the person who can send it business, funded by the organisation’s own money through inflated prices, inflated quantities, unnecessary purchases or accepted substandard goods. It is the fraud tree’s invoice-kickback scheme, and it is the hardest procurement fraud to prove because the payment happens outside the organisation’s records: cash, a job for a relative, a holiday, a share of a side business. What the organisation’s records do show is the price, and the price is where the scheme is found. Three patterns recur. Price creep: the favoured vendor’s prices rise at every renewal, a few percent at a time, never enough to trigger a re-bid, managed by one buyer who always has a reason; over four renewals a 5 to 7 percent step each time compounds to a quarter above market, which is where the kickback lives. The tolerance band: three-way match tolerances (5 percent or a fixed amount per line are common) exist to stop the payables team chasing rounding differences, and a vendor who prices every invoice 4 percent above the order, with a buyer who never objects, is inside the band and outside the control; MidState’s 5 percent or 250-dollar tolerance, unchanged since 2019, is the example in the RCM guide. And quantity and quality games: over-delivery accepted and paid, short delivery not deducted, a lower grade received against a higher grade ordered, each of which passes the match because the receiver is the buyer’s colleague or the buyer.

PatternIndicatorsControl that prevents itAnalytic that detects it
Price creep at renewalSole-source renewals; increases at every renewal with no index; one buyer owning the relationship for years; a supplier whose prices to the organisation exceed its list prices or market benchmarksRe-bid or benchmark cycle for every contract above a threshold; indexed escalation clauses; buyer rotation on key categories; renewal approval outside purchasingUnit price trend by item and vendor against contract and index; renewal step analysis; buyer-vendor tenure
Inside the tolerance bandInvoice prices consistently above order prices but within tolerance; the same vendor and buyer every timeTolerance set as low as the process can bear; price variance within tolerance reported by vendor and reviewed monthly; buyers cannot change order prices after the factCumulative in-band variance by vendor and buyer; share of a vendor’s invoices priced above order
Quantity and qualityOver-receipts accepted; short deliveries never claimed; grade substitutions; returns rare for a vendor with quality complaintsReceiver independent of the buyer; over-receipt blocks; quality inspection on receipt with sampling; claims process for shortagesReceived against ordered by vendor; shortage claims by vendor against deliveries; quality complaints against returns
Unnecessary purchasesStock of an item rising while consumption is flat; services invoiced without deliverables; consultants with no outputRequisition justification and budget check; consumption-based reorder; deliverable acceptance before payment for servicesPurchases against consumption; service invoices without acceptance records
The payment outside the recordsA buyer living beyond their means; a vendor’s employee related to the buyer; hospitality and gifts from one vendor; the buyer refusing rotation or leaveConflict-of-interest and gifts registers with attestation; mandatory leave; rotation; vendor hotlineGifts register against awards; HR data on leave patterns; hotline analysis by vendor

Phantom vendors and conflicts of interest

A phantom or shell vendor is a supplier that exists on paper and in the vendor master and nowhere else: the perpetrator creates it, submits its invoices for goods or services never provided, approves them, and collects the payments through a bank account they control. It is the fraud tree’s shell-company billing scheme, it sits in the asset-misappropriation branch rather than corruption because no genuine vendor is involved, and it is the scheme every vendor-master control exists to stop. Its cousin is the pass-through vendor, a real intermediary the perpetrator owns that buys from the genuine supplier and resells to the organisation at a markup. Conflicts of interest are the corruption-branch version: the vendor is real and provides real goods, but the employee who steers the business owns it, or a relative does, and has not disclosed it; the loss is the margin the organisation would not have paid a stranger, and the risk is that the relationship becomes a kickback or a phantom over time. All three are found in the vendor master and the employee master, joined.

IndicatorPhantom vendorPass-through vendorUndisclosed conflict
Vendor-master profilePO box or residential address; no tax ID or a personal one; free email domain; no website; created by or at the request of the approverRecent incorporation; no manufacturing or service capability; address matching an employee or a registered-agentGenuine business; address, phone, bank or officer matching an employee or a relative
Invoice patternRound amounts; sequential invoice numbers (the organisation is the only customer); generic descriptions; no purchase order or always under the PO thresholdPrices above what the genuine supplier charges others; invoices that reference the genuine supplier’s part numbersPrices at or above market; renewals without competition; volumes rising with the employee’s tenure
Approval patternOne approver every time; the approver created or requested the vendor; payments urgentOne requester; sole-source justification citing “relationship”The related employee approves or requests; competing quotes obtained from firms that never win
Control that prevents itVendor creation independent of requesting and approving; verification of existence, tax ID and bank; screening against the employee master at creationBeneficial ownership check for new vendors above a spend threshold; price benchmarkingConflict-of-interest disclosure with annual attestation and cross-check to the vendor master; recusal enforced
Analytic that detects itVendor-employee matches (bank, address, phone, tax ID); shell-profile scoring; sequential invoice numbers; single-approver vendorsPrice against the genuine supplier’s list; vendor incorporation date against first orderVendor-employee matches including relatives’ surnames and shared addresses; single-requester vendors; renewal without competition

Split purchases, change orders and substitution

Three schemes cluster around the main families and are found by the same analytics program. Split purchases divide a requirement into orders that each sit under an approval limit or a tender threshold, so that a buyer or requester can commit spend they are not authorised to commit; the pattern is a cluster of orders to one vendor from one requester within days, each just under the limit, and the finding is a control finding about the threshold logic whether or not a kickback sits behind it. Change-order abuse is the contract-management version of bid rigging: a vendor wins a competitive tender with a low price and recovers the margin through change orders, scope additions and claims approved by a contract owner who does not compare the final cost with the losing bids; the indicator is a contract whose final value exceeds the second-lowest bid, and the control is change-order approval outside the project with a running comparison to the tender. Substitution is delivery of something other than what was contracted, a lower grade of ingredient, a counterfeit component, an uncertified subcontractor; it is a quality-control and receiving failure until someone benefits from it, and then it is fraud, and in public contracting it is the classic False Claims Act case. Product substitution is found by inspection and testing, not by data, which is why the receiving controls in the inventory guide include quality inspection on receipt.

Preventing it: the eight controls that matter most

Procurement controls multiply easily and most of them are paperwork. Eight carry the weight, and a procurement fraud audit tests whether these eight operate before it tests anything else. Independent vendor creation: nobody who requests or approves purchases can create or change a vendor, and every new vendor is verified (existence, tax identifier, bank account ownership) and screened against the employee master and the conflicts register before its first payment. Competition with teeth: a threshold above which competition is mandatory, an invitation list drawn from the approved base rather than the buyer’s contacts, sealed bids opened by a panel, evaluation on criteria published before bids are received, and losing bids kept. Re-competition on a clock: every contract above a threshold re-bid or benchmarked on a fixed cycle, with renewals approved outside purchasing and price steps indexed. Threshold logic that aggregates: approval limits applied to the vendor-requester total over a window, not to each order, and after-the-fact orders reported. Receiving independent of buying: receipts posted from a dock count by someone who did not order, over-receipts blocked, quality inspected on a sampling basis for ingredients and components. Tolerances that are watched: match tolerances set as low as the process bears, with cumulative in-band variance reported by vendor. Disclosure that is checked: annual conflict-of-interest and gifts attestations cross-matched to the vendor master and the award log, with recusals enforced in the workflow. And a channel for vendors: a hotline that suppliers know about, because the losing bidder who was asked for a cover bid is the witness every bid-rigging case needs, and the vendor asked for a kickback is the one who knows the buyer’s price.

The legal frame in plain terms

Four bodies of law reach into procurement fraud, and the auditor needs them at the level of knowing when to call counsel. Anti-bribery law: the US Foreign Corrupt Practices Act criminalises bribes to foreign officials and requires accurate books and records and internal accounting controls of issuers; enforcement was paused by executive order on 10 February 2025 and resumed under Department of Justice guidelines issued on 9 June 2025 that prioritise cases connected to cartels and transnational criminal organisations, harm to US competitiveness, national security, and serious misconduct, while de-emphasising routine business courtesies and facilitation payments; the SEC’s civil enforcement priorities were not announced as changed. The UK Bribery Act 2010 goes further, covering private-sector bribery and creating a corporate offence of failing to prevent bribery with an adequate-procedures defence, which is why UK-connected companies audit their procurement against those procedures. Competition law: bid rigging is a criminal cartel offence in the United States under the Sherman Act and in most jurisdictions, pursued against the colluding vendors and against insiders who facilitate; an organisation that discovers rigging in its own tenders is a victim with a decision to make about reporting. Public procurement and false claims: fraud against government buyers carries statutory penalties (in the US, treble damages and per-claim penalties under the False Claims Act, with whistleblower rewards), and contractors’ own procurement fraud can bar them from public work. And the corporate enforcement policies covered in the first-48-hours guide, under which self-disclosure timing decides the outcome. The practical consequence: a procurement fraud finding with a foreign official, a public buyer, or a cartel in it is a legal matter from the moment of predication, and the audit function’s job is to preserve and hand over, not to interview the buyer.

The 12-test audit program

The program below is the fraud-focused overlay on the procurement audit; sample sizes follow the standard conventions, selections go in the sampling memo, and the analytics are those of the procurement fraud catalog, run first so that their hits become the judgmental selections.

  1. Tender file review. Sample 25 competitive awards above the tender threshold, or all if fewer. Attributes: invitation list drawn from the approved base; sealed bids opened by a panel with a record; evaluation on the published criteria; specification reviewed independently of the requester; award approved by someone outside purchasing; losing bids retained.
  2. Bid pattern analytics. Full population of tenders for three years: winner concentration by category and buyer; bid spreads; identical or near-identical bids; withdrawals; bidders who never win yet keep bidding; losers paid by winners.
  3. Sole-source and single-quote awards. All awards above the threshold made without competition. Attributes: justification documented on policy grounds; approved outside purchasing; re-competed within the policy period; price benchmarked.
  4. Price creep and renewal analysis. Full population of contracts renewed in the period: step at renewal, index provision, re-bid history, buyer tenure; unit price trends by item and vendor for the top 50 vendors.
  5. Tolerance-band analysis. Full population of matched invoices: cumulative in-band variance by vendor and buyer; vendors with most invoices priced above order; tolerance configuration and change history.
  6. Vendor-master screening. Full master against the employee master (bank, address, phone, tax ID, surname and shared address for relatives) and against conflict-of-interest disclosures; shell-profile scoring; vendors created by or at the request of their approvers.
  7. Split-purchase and threshold analysis. Full population of orders: clusters by vendor and requester within a window whose sum exceeds a limit; orders just under limits; orders raised after invoices.
  8. Receiving integrity. Sample 25 receipts at sites chosen from the analytics. Attributes: receiver independent of the buyer; quantity and grade inspected; over-receipts blocked; shortages claimed; receipt not posted before arrival.
  9. Change orders and final cost. All contracts above the threshold closed in the period: final value against the winning and second-lowest bid; change orders approved outside the project; scope additions competed where policy requires.
  10. Gifts, hospitality and conflicts. Inspect the registers and the attestation completion; cross-match gifts to awards by date and vendor; test that recusals were enforced.
  11. Subcontractors and beneficial ownership. For the 20 largest vendors and every tender winner in the period: subcontractor disclosures, beneficial ownership checks, sanctions and adverse-media screening; losers appearing as subcontractors.
  12. Hotline and prior-incident review. Inspect procurement-related hotline reports and incidents for three years; test that each was investigated under the protocol and that control findings from them were implemented; look for vendors or buyers that recur.

Worked example: Brightwater Foods’ first procurement fraud run

Brightwater Foods is the 180-million-dollar food manufacturer used across this site: three plants, about 600 staff, and a co-sourced internal audit function that its first chief audit executive later rebuilt. Its first procure-to-pay fraud analytics run, written up test by test in the procurement fraud analytics guide, covered eighteen months of data: 22,400 invoices, 1,860 active vendors, 9,100 purchase orders and 41 tenders, with a plant approval limit of 10,000 dollars. Data preparation took the co-source analytics specialist eight days, mostly on address normalisation and on reconciling a receiving log that lived in a warehouse system outside the ERP; the tests ran in a day; the triage and corroboration took the rest of the engagement. The table maps the run’s results onto the scheme families above, which is how the results were reported to the audit committee: not as a list of anomalies, but as what each family of procurement fraud looked like at Brightwater and what was done about it.

Scheme familyWhat the run foundOutcome
Bid rigging: losers as subcontractorsTwo of 41 tenders where a losing bidder was paid by the winner for the same scope, visible in invoice line descriptionsHanded off under the fraud protocol; the investigation found an undisclosed arrangement between the two vendors and no employee involvement; both removed from the approved list
Kickbacks: price creepOne ingredient supplier’s prices rising 5 to 7 percent at each of four renewals without a re-bid, managed by one buyer, among 15 item-vendor pairs with unindexed increasesRe-bid ordered; the incumbent’s renewal price fell 11 percent; no relationship found between buyer and vendor, but the finding on sole-source renewals stood
Conflicts of interest: undisclosed ownershipTwo vendor-employee bank matches: a disclosed family business under the conflicts policy, and a cleaning contractor owned by a plant supervisor’s spouse, undisclosed, with 61,200 dollars paid over the period and the supervisor approving the invoicesHanded off; the matter went to HR and legal; control finding on conflict-of-interest attestation and vendor-master screening at creation
Split purchasesNine order clusters at one plant, one buyer and one packaging vendor, all in the band under the 10,000-dollar plant approval limitControl finding: the buyer split orders to avoid the plant manager’s approval; no vendor relationship found; the threshold logic and the buyer’s authority were changed
Ordering after the fact38 purchase orders raised after the invoice, concentrated in two cost centres with no emergency justificationControl finding on after-the-fact ordering; policy tightened and the cost centres’ approvers changed
Receiving bypass16 match overrides by one accounts payable clerk for one vendor, all with receipts posted days laterInvestigated: the clerk was clearing a backlog under pressure from the plant; the vendor was genuine; control finding on override authority and monitoring
Payment redirection29 bank-detail changes followed by payments within the window, 27 verified by call-backTwo without verification investigated and confirmed genuine; call-back evidence moved to the vendor record

The run produced two referrals and five control findings, and neither referral involved an employee taking a kickback, which is typical: most procurement fraud analytics find the conditions for corruption more often than corruption, and the conditions are the finding. Three things generalise. The bid-loser-as-subcontractor test found collusion that no tender file review would have found, because both tender files were clean; the evidence was in the winners’ invoices. The price-creep finding stood on its own even after the investigation cleared the buyer, because a 25 percent premium accumulated over four uncontested renewals is a loss whether or not anyone was paid for it. And the conflict-of-interest case was found by joining two masters that nobody had joined before, which is the single most productive hour in any first procurement fraud run.

The findings that recur, and wording that lands

Five findings account for most procurement fraud reports, and each lands in five-Cs form with a number attached. Sole-source renewals (“15 contracts worth 4.2 million dollars a year were renewed without competition in the period; one supplier’s prices rose 5 to 7 percent at each of four renewals and fell 11 percent when re-bid; policy requires re-competition every three years”). Threshold logic (“nine order clusters at one plant were split to remain under the 10,000-dollar approval limit; the system permits multiple orders to one vendor from one requester in a day without aggregation”). Vendor-master screening (“the vendor master is not screened against the employee master at creation; the run found an undisclosed vendor owned by a supervisor’s spouse, paid 61,200 dollars over eighteen months on invoices the supervisor approved”). Tender integrity (“two of 41 tenders show a losing bidder subsequently paid by the winner for the tendered scope; the tender procedure has no subcontractor-disclosure requirement”). And override governance (“16 three-way-match overrides were released by one payables clerk for one vendor with receipts posted after payment; override rights are not limited or monitored”). Write the cause as the decision that produced the condition (a renewal policy nobody enforces; an approval logic without aggregation; a vendor-creation process that never asked) and follow the root cause guide.

Where to go next

Audit procurement fraud as patterns rather than documents: join the masters, trend the prices, compare the bids across years, and read the winners’ invoices for the losers’ names. The process audit the overlay sits on is how to audit procurement; the tests are catalogued in procurement fraud analytics; the vendor-master controls are in the vendor master audit; the payments side in how to audit accounts payable; what to do when a hit is real in the first-48-hours protocol; and the taxonomy behind it all in the fraud tree guide.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading