Home · Solutions · Other solutions
Solution · Other solutionsOne risk view across invoices, expenses and cards, so the schemes in the gaps stop hiding
The vendor who is also an employee, found across AP and T&E
Invoices, expenses, cards, vendors and employees meet in one governed model; rules and anomaly scores rank cases, and internal audit decides every one of them.
Executive summary
Three controls, three thirds of the picture, and the schemes live in the gaps between them.
We build the cross-process view once and keep it current, which is the part that has always defeated the quarterly approach.
Coverage moves from a quarterly sample to every transaction daily, because the data assembly that limited audit is done by robots.
the Microsoft Fabric lakehouse; the Power BI semantic model; the case record with its evidence
Business problem
Fraud analytics
Fraud that crosses processes is designed to. A vendor created by a colleague, invoices kept just under a manager's approval limit, a dinner claimed on an expense report and invoiced again by the supplier, a receipt produced to order: each is small and plausible inside its own process, and each process owner sees only their own.
The data makes it worse. Accounts payable lives in SAP, expenses in SAP Concur, cards arrive as monthly bank files, and employees sit in the HR system, each with different identifiers, currencies and entity codes. Bringing them together is a quarterly project done by hand, so the tests are the few that fit a spreadsheet and the coverage is a sample.
Image tools have changed the last defence. A generated receipt survives the visual check that used to catch a forgery, and the skill needed to produce one has fallen to nothing. What keeps all this in place is ownership: no function owns the view across processes, and a finding every few years reads as bad luck rather than as a control gap.
How it works today
- SystemEach process runs its own checks: payables on invoices, the expense team on receipts, the card programme on merchant categories
- PersonInternal audit requests extracts from SAP, the expense system, the card provider and HR each quarter
- PersonAnalysts align identifiers, currencies and formats by hand in spreadsheets
- SystemA short list of tests is run: employee-vendor address matches, round amounts, threshold patterns
- WaitingResults are reviewed weeks after the transactions took place
- Risk of errorSuspicious receipts are checked by eye, which is exactly what a generated receipt is built to survive
- PersonCases are investigated one at a time; most are false positives or too old to pursue
- Risk of errorFindings are reported, the extracts are discarded, and next quarter the same request goes out again
Why the current process costs more than it appears
The budget shows headcount, not what it is spent on.
- Cross-process schemes are small per month and long-lived, so the total is large by the time anyone finds one. What follows costs more than the loss: the investigation, the legal process, the insurance claim, the disclosure to the auditor and months of management attention.
- Controls known to be per-process invite exactly the behaviour they cannot see. People inside a company generally know which checks look where.
- Audit capacity goes into the wrong work. Most of the quarterly effort is spent aligning identifiers, which means fewer tests, a sample rather than a population, and judgement applied to whatever survived.
- Every acquisition adds an entity with its own identifiers, so the assembly slows each year while the schemes get easier.
- Reliance on management's controls is a number the external auditor sets. When the answer to "how do you detect this" is a quarterly sample, reliance falls and the fee rises.
Cost of inaction
Four years is not a worst case in this scenario; it is what the last two cases actually took, and the first row multiplies the same assumed leakage by the time it ran. Whether your own number is larger or smaller is what the discovery answers, which is why we would rather run the rule library over your history than defend a percentage.
Everything else moves in one direction. Generated documents improve every quarter, so the visual check catches less next year than this. Each acquisition adds identifiers, so the assembly takes longer and covers less. And when internal audit asks for headcount, the honest answer to what they do with their time is spreadsheets, which does not win budgets.
A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.
An industrial services group with about 11,000 employees across seven European countries; accounts payable on SAP S/4HANA, travel and expenses on SAP Concur, and a corporate card programme delivered as monthly files from the bank.
Around 9,000 vendor invoices, 14,000 expense lines and 22,000 card transactions a month, with combined addressable spend of roughly €140,000,000 a year.
Internal audit has four people who spend about three days each per quarter assembling extracts and running a short list of tests. Two cross-process cases have surfaced in five years, both by chance, both several years old by then.
The data assembly, which consumes the capacity that would otherwise go into tests, so coverage stays a sample and document authenticity is judged by looking at the picture.
Robots load accounts payable, expenses, cards, vendor master and HR data daily into one governed model in Microsoft Fabric. Cross-process tests run on every load, anomaly scores are added beside them, flagged images are checked for authenticity signals, and each case reaches internal audit as a ranked task in Microsoft Teams with its evidence attached.
Coverage moves from a quarterly sample to every transaction, and the modelled pool is about €131,112 a year: €105,000 of assumed leakage found earlier or deterred, plus €26,112 of audit time returned to investigation. The leakage share is a placeholder, so this is arithmetic on an assumption, not a forecast.
Proposed solution
We build the cross-process view once and keep it current, which is the part that has always defeated the quarterly approach. Robots extract accounts payable, expense, card, vendor master and HR data every day and align identifiers, currencies and entities into one governed model in Microsoft Fabric, with access limited to named investigators. That model outlives the project: once it exists, segregation-of-duties monitoring and spend analysis run on the same foundation.
On every load, deterministic tests written with your internal audit team run over the whole population: employee-vendor matches on address, bank account, phone number and tax identifier; invoices split below an approval threshold, grouped by vendor and approver; expense receipts duplicating an invoice or another employee's claim; round amounts and just-below-limit patterns; requester and approver pairs whose concentration is unusual for their peers. Anomaly models trained in the Fabric Data Science workload score behaviour against peers and history, and their signals are added to the rules rather than replacing them.
Flagged images then go through UiPath Document Understanding so their content can be compared across processes, and through authenticity checks we build: file metadata, creation software, layouts repeated across supposedly unrelated merchants, invoice numbering that runs sequentially from a new vendor. These are questions for a person, not verdicts. Each case is ranked with its evidence and delivered to internal audit as a UiPath Action Center task in Microsoft Teams. Investigators confirm, dismiss or escalate, and their outcomes feed the ranking. Power BI carries coverage, cases by pattern and age, confirmation rate and outcomes.
Microsoft Fabric lakehouse and Data Science workload with row-level security; Power BI semantic model and reports; UiPath Document Understanding extraction with Validation Station; UiPath Action Center tasks with SLAs, assignment and audit; Microsoft Purview sensitivity labels, retention and audit log
The extraction and alignment workflows; the consolidated data model; the cross-process rule library; anomaly model training and monitoring; the document-authenticity checks on metadata, creation software and repeated layouts; case assembly, ranking and the investigator task; the Power BI reports
SAP S/4HANA through BAPI and OData; SAP Concur through its connector; the card provider's monthly files picked up through the UiPath Integration Service connector for Microsoft OneDrive & SharePoint; the HR system through a connector or a scheduled export
How the automated process works
- AutomationRobots extract accounts payable, expense, card, vendor master and HR data daily and align identifiers, currencies and entities
- SystemThe consolidated model in Microsoft Fabric is refreshed with row-level security applied before anyone can query it
- AutomationThe cross-process rule library runs over every transaction, and anomaly scores are calculated beside the rule results
- AutomationImages behind flagged items are read by Document Understanding and passed through the authenticity checks
- AutomationCases are assembled with their evidence and ranked; items below the threshold are retained for pattern analysis rather than discarded
- PersonInternal audit receives a ranked case as an Action Center task in Microsoft Teams and decides: dismiss, monitor, investigate or escalate
- AutomationThe outcome is recorded against the case, feeds the ranking and appears in the monthly coverage and outcome report
Human-in-the-loop model
Automation handles
- Daily extraction and alignment of accounts payable, expense, card, vendor and HR data
- Running the rule library and the anomaly scoring across every transaction, not a sample
- Reading flagged images and adding the authenticity signals
- Assembling the evidence pack, ranking the case and reporting coverage and outcomes
People decide
- What each case actually is: fraud, error, policy breach or noise, and whether to investigate
- Escalation to compliance, legal, HR and, where it goes that far, to authorities
- Thresholds, new tests and which signals are allowed to raise a case at all
- Governance of the dataset: who may see it, for how long the evidence is kept, and on what documented basis
Before and after
Systems and integrations
We do not add technology to make an architecture look serious. Every element below has a specific job in this process.
Inputs
- SAP S/4HANA accounts payable and vendor master
- SAP Concur expense lines and receipts
- the card provider's monthly files
- the HR employee master
Automation layer
- UiPath Orchestrator
- UiPath Robots
- UiPath Integration Service
- UiPath Document Understanding
- UiPath Action Center
Target systems
- the Microsoft Fabric lakehouse
- the Power BI semantic model
- the case record with its evidence
Human touchpoints: investigator tasks in Microsoft Teams; threshold and test approvals; the quarterly review with internal audit and compliance
Technologies used
daily extraction from SAP, SAP Concur, card files and HR; queues, retries, credential store, audit
Aone aligned model of invoices, expenses, cards, vendors and employees, with the anomaly scoring beside it
Areads invoice and receipt images so content, not only totals, is comparable across processes
Aranked cases as investigator tasks completed in Microsoft Teams, with assignment, SLAs, decision record
Awhere an investigator picks up a case, asks a question and records what happened
Acoverage, cases by pattern and age, confirmation rate, losses confirmed and recovered
Alabels, retention and audit on case evidence; access confined to named investigators
Aour design, calibrated on your own history before anything runs live
CIllustrative economic model
What it is worth, with the arithmetic shown.
The leakage rate is the assumption that decides this case, and it is a placeholder rather than a finding: 0.15% of €140,000,000 of addressable spend, halved again because continuous coverage finds or deters part of what is there and not all of it. Audit time is the half that prices cleanly: four auditors, twenty-four hours each per quarter, at €68 an hour fully loaded. Investigation and legal cost avoided, insurance recoveries, Fabric capacity, licences and implementation sit outside the model, and at this scale they are not small. A company that has had a case usually knows its own leakage number, and the first run over twelve months of history replaces the placeholder with findings.
Business benefits
- Coverage moves from a quarterly sample to every transaction daily, because the data assembly that limited audit is done by robots
- Schemes that cross processes become visible: the employee, the vendor, the receipt and the card finally sit in one model
- Generated receipts and invoices are questioned on metadata and repeated layouts rather than on how they look
- Auditors spend their time on investigation instead of spreadsheets, and their findings are months old rather than years
- The existence of the control changes behaviour, because per-process blind spots stop being reliable
- The consolidated model also serves segregation-of-duties monitoring and spend analysis, so its cost is shared
The management view
- A fraud-risk position that can be reported: coverage, open cases by pattern and age, confirmed losses and recoveries, per entity
- A case queue with the evidence assembled and every decision recorded, which is what an external auditor or a regulator asks to see
- Employee-vendor relationships and approval concentrations become a standing report rather than a discovery
- False positives fall over time, because investigator outcomes feed the ranking and the queue concentrates on what matters
Board-level KPIs
Security and governance
Trust in automation is built on the audit trail, not on a promise.
- This dataset links people to money, so its governance is part of the design and not an appendix. Access runs through Microsoft Entra ID groups and row-level security, and only named investigators reach the evidence
- Purpose, tests, legal basis and retention are written down before the first load, employees are informed as data-protection law and works-council agreements require, and consultation is a client decision we plan around
- No automated decision affects any person. Models produce scores, rules produce flags, and an investigator makes every decision, all of it recorded in the Action Center trail
- Robots read and never write to a source system. Service accounts are read-only, their secrets in Azure Key Vault through the Orchestrator credential store
- Case evidence carries Purview sensitivity labels and a retention rule agreed with legal. Any language-model step runs under the UiPath AI Trust Layer or Microsoft Foundry with allow-listed models in EU regions, and processing stays inside the EU Data Boundary and the EU region of UiPath Automation Cloud
Why now
Two things changed at once. Generated receipts and invoices went from rare to routine, which makes visual inspection unreliable, while boards and external auditors began asking internal audit for continuous assurance rather than an annual plan
The platform a cross-process view needs, a governed lakehouse with security, models and reporting in one place, is now part of the Microsoft tenant rather than a data-warehouse programme
Each quarter of waiting keeps 96 audit hours in spreadsheets and leaves the modelled €210,000 of annual leakage where it is, spread thinly enough that no single control notices
Relevant executive roles
Losses that used to run for years are found in months, and the external auditor's reliance on management controls improves
Continuous coverage of every transaction with the evidence assembled, instead of a quarterly sample built by hand
Employee-vendor relationships and approval concentrations become a standing report, not a discovery that has to be explained
Document forensics and impersonation signals join the fraud picture beside the phishing cases the team already investigates
Common questions and objections
Within expenses, and it does that well. It does not know that the same receipt was also paid as an invoice, or that the vendor's bank account belongs to somebody on the payroll. Those are the patterns the cross-process model exists to see.
It is a legal question with an established answer: processing that is proportionate, documented and transparent, consulted where a works council requires it, with a person making every decision. We design for that from the first workshop, and we claim no certification on your behalf.
Rules are calibrated on your own twelve months before anything goes live, anomaly models are added only after that, and investigator outcomes feed the ranking. The queue is meant to get shorter and more accurate, and the reporting shows whether it does.
When this is not the right solution
- A smaller organisation where one controller genuinely sees every invoice, expense claim and card statement; the view adds cost without adding sight
- No internal audit or investigation capacity to act on what is found, in which case the ranked queue simply grows into a report nobody reads
- Per-process controls that are still weak. Basic invoice and expense audits come first, because a model built on unreliable inputs produces confident noise
A question for the next management meeting
Two cross-process cases in five years were both found by accident: what evidence do we have that a third is not running now, and who in this company would be the one to notice?
Implementation approach
What we deliver, and what we need from you to start.
We deliver
- A discovery run of the rule library over twelve months of history for one entity, written up
- The consolidated data model and the daily extraction automation for every source
- The rule library, anomaly models and authenticity checks, agreed with internal audit and compliance
- Case assembly, ranking and the investigator task in Microsoft Teams
- Power BI reporting on coverage, patterns, confirmation rate and outcomes
- Investigator training, model monitoring and run-phase support
We need from you
- Twelve months of accounts payable, expense, card and vendor-master history for one entity
- A data owner and an internal audit owner who decides cases
- Service accounts with read-only access to each source system
- A decision on works-council and data-protection consultation, taken before the build starts
Stages
Discovery
Consolidate twelve months for one entity, run the rule library, let the findings set the scope
Design
Data model, access model, retention, the rule library and the case ranking with internal audit
Pilot
The daily pipeline live for one entity with rules only, so thresholds are calibrated on real cases
Scale
Further entities, anomaly models, authenticity checks and the feedback loop from outcomes
Run
Quarterly review of tests, models and thresholds with internal audit and compliance
Enterprise. Effort is driven by the number of source systems and entities, how far their identifiers diverge, and the consultation the group needs before employee-linked data is brought together.
An address that matched for four years sat in two of our systems the whole time.
Give us twelve months of accounts payable, expense and vendor-master extracts for one entity, anonymised if you prefer. We run the cross-process rule library over them and come back with what it found and an honest taxonomy of the false positives.
Run the rule library on one entityThe neighbouring process usually has the same problem
The auditor finds your role conflicts once a year. By then the oldest of them is twelve months old.
View solution ProcurementP2P process mining: maverick spend and real touchless rateNobody knows what share of purchases bypass contracts and POs, or how often an invoice is touched. Measure it monthly.
View solution Other solutionsEvery expense report audited before the money leavesA sample checked after payment finds errors it cannot recover and misses the duplicates entirely.
View solution Other solutionsEvery card transaction matched to a receipt and a policyCard spend is matched, coded and checked weeks after it posts, and receipts are chased forever.
View solution Case studyInvoice disputes without escalationA disputed invoice is not one task — it is an investigation: order, delivery, contract, correspondence.
View case study Case studyAutomated P2P query handlingInvoice copies, statuses and statements delivered instantly — around the clock.
View case studyIndustries we deliver this in most oftenManufacturing & industryRetail & e‑commerceServices & ITShared services