Home · Solutions · Other solutions

Solution · Other solutions

One risk view across invoices, expenses and cards, so the schemes in the gaps stop hiding

The vendor who is also an employee, found across AP and T&E

Invoices, expenses, cards, vendors and employees meet in one governed model; rules and anomaly scores rank cases, and internal audit decides every one of them.

EnterpriseMicrosoft TeamsHuman in the loopAI where it earns its place
45,000invoices, expense lines and card transactions a month reach three separate controls in this illustrative group, and none of them sees the other two.

Executive summary

Challenge

Three controls, three thirds of the picture, and the schemes live in the gaps between them.

What changes

We build the cross-process view once and keep it current, which is the part that has always defeated the quarterly approach.

Business value

Coverage moves from a quarterly sample to every transaction daily, because the data assembly that limited audit is done by robots.

Systems involved

the Microsoft Fabric lakehouse; the Power BI semantic model; the case record with its evidence

Business problem

Fraud analytics

Fraud that crosses processes is designed to. A vendor created by a colleague, invoices kept just under a manager's approval limit, a dinner claimed on an expense report and invoiced again by the supplier, a receipt produced to order: each is small and plausible inside its own process, and each process owner sees only their own.

The data makes it worse. Accounts payable lives in SAP, expenses in SAP Concur, cards arrive as monthly bank files, and employees sit in the HR system, each with different identifiers, currencies and entity codes. Bringing them together is a quarterly project done by hand, so the tests are the few that fit a spreadsheet and the coverage is a sample.

Image tools have changed the last defence. A generated receipt survives the visual check that used to catch a forgery, and the skill needed to produce one has fallen to nothing. What keeps all this in place is ownership: no function owns the view across processes, and a finding every few years reads as bad luck rather than as a control gap.

How it works today

  1. SystemEach process runs its own checks: payables on invoices, the expense team on receipts, the card programme on merchant categories
  2. PersonInternal audit requests extracts from SAP, the expense system, the card provider and HR each quarter
  3. PersonAnalysts align identifiers, currencies and formats by hand in spreadsheets
  4. SystemA short list of tests is run: employee-vendor address matches, round amounts, threshold patterns
  5. WaitingResults are reviewed weeks after the transactions took place
  6. Risk of errorSuspicious receipts are checked by eye, which is exactly what a generated receipt is built to survive
  7. PersonCases are investigated one at a time; most are false positives or too old to pursue
  8. Risk of errorFindings are reported, the extracts are discarded, and next quarter the same request goes out again
SystemPersonWaitingRisk of error

Why the current process costs more than it appears

The budget shows headcount, not what it is spent on.

  • Cross-process schemes are small per month and long-lived, so the total is large by the time anyone finds one. What follows costs more than the loss: the investigation, the legal process, the insurance claim, the disclosure to the auditor and months of management attention.
  • Controls known to be per-process invite exactly the behaviour they cannot see. People inside a company generally know which checks look where.
  • Audit capacity goes into the wrong work. Most of the quarterly effort is spent aligning identifiers, which means fewer tests, a sample rather than a population, and judgement applied to whatever survived.
  • Every acquisition adds an entity with its own identifiers, so the assembly slows each year while the schemes get easier.
  • Reliance on management's controls is a number the external auditor sets. When the answer to "how do you detect this" is a quarterly sample, reliance falls and the fee rises.

Cost of inaction

Four years of a scheme nobody is positioned to see≈ €840,000
One more year of the pool this control would reach≈ €131,112
The 384 audit hours a year that go into aligning identifiers≈ €26,112

Four years is not a worst case in this scenario; it is what the last two cases actually took, and the first row multiplies the same assumed leakage by the time it ran. Whether your own number is larger or smaller is what the discovery answers, which is why we would rather run the rule library over your history than defend a percentage.

Everything else moves in one direction. Generated documents improve every quarter, so the visual check catches less next year than this. Each acquisition adds identifiers, so the assembly takes longer and covers less. And when internal audit asks for headcount, the honest answer to what they do with their time is spreadsheets, which does not win budgets.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

An industrial services group with about 11,000 employees across seven European countries; accounts payable on SAP S/4HANA, travel and expenses on SAP Concur, and a corporate card programme delivered as monthly files from the bank.

Volume

Around 9,000 vendor invoices, 14,000 expense lines and 22,000 card transactions a month, with combined addressable spend of roughly €140,000,000 a year.

Current process

Internal audit has four people who spend about three days each per quarter assembling extracts and running a short list of tests. Two cross-process cases have surfaced in five years, both by chance, both several years old by then.

Bottleneck

The data assembly, which consumes the capacity that would otherwise go into tests, so coverage stays a sample and document authenticity is judged by looking at the picture.

Solution

Robots load accounts payable, expenses, cards, vendor master and HR data daily into one governed model in Microsoft Fabric. Cross-process tests run on every load, anomaly scores are added beside them, flagged images are checked for authenticity signals, and each case reaches internal audit as a ranked task in Microsoft Teams with its evidence attached.

Potential outcome

Coverage moves from a quarterly sample to every transaction, and the modelled pool is about €131,112 a year: €105,000 of assumed leakage found earlier or deterred, plus €26,112 of audit time returned to investigation. The leakage share is a placeholder, so this is arithmetic on an assumption, not a forecast.

Proposed solution

We build the cross-process view once and keep it current, which is the part that has always defeated the quarterly approach. Robots extract accounts payable, expense, card, vendor master and HR data every day and align identifiers, currencies and entities into one governed model in Microsoft Fabric, with access limited to named investigators. That model outlives the project: once it exists, segregation-of-duties monitoring and spend analysis run on the same foundation.

On every load, deterministic tests written with your internal audit team run over the whole population: employee-vendor matches on address, bank account, phone number and tax identifier; invoices split below an approval threshold, grouped by vendor and approver; expense receipts duplicating an invoice or another employee's claim; round amounts and just-below-limit patterns; requester and approver pairs whose concentration is unusual for their peers. Anomaly models trained in the Fabric Data Science workload score behaviour against peers and history, and their signals are added to the rules rather than replacing them.

Flagged images then go through UiPath Document Understanding so their content can be compared across processes, and through authenticity checks we build: file metadata, creation software, layouts repeated across supposedly unrelated merchants, invoice numbering that runs sequentially from a new vendor. These are questions for a person, not verdicts. Each case is ranked with its evidence and delivered to internal audit as a UiPath Action Center task in Microsoft Teams. Investigators confirm, dismiss or escalate, and their outcomes feed the ranking. Power BI carries coverage, cases by pattern and age, confirmation rate and outcomes.

Native capabilities used

Microsoft Fabric lakehouse and Data Science workload with row-level security; Power BI semantic model and reports; UiPath Document Understanding extraction with Validation Station; UiPath Action Center tasks with SLAs, assignment and audit; Microsoft Purview sensitivity labels, retention and audit log

What we build

The extraction and alignment workflows; the consolidated data model; the cross-process rule library; anomaly model training and monitoring; the document-authenticity checks on metadata, creation software and repeated layouts; case assembly, ranking and the investigator task; the Power BI reports

Custom integration

SAP S/4HANA through BAPI and OData; SAP Concur through its connector; the card provider's monthly files picked up through the UiPath Integration Service connector for Microsoft OneDrive & SharePoint; the HR system through a connector or a scheduled export

How the automated process works

  1. AutomationRobots extract accounts payable, expense, card, vendor master and HR data daily and align identifiers, currencies and entities
  2. SystemThe consolidated model in Microsoft Fabric is refreshed with row-level security applied before anyone can query it
  3. AutomationThe cross-process rule library runs over every transaction, and anomaly scores are calculated beside the rule results
  4. AutomationImages behind flagged items are read by Document Understanding and passed through the authenticity checks
  5. AutomationCases are assembled with their evidence and ranked; items below the threshold are retained for pattern analysis rather than discarded
  6. PersonInternal audit receives a ranked case as an Action Center task in Microsoft Teams and decides: dismiss, monitor, investigate or escalate
  7. AutomationThe outcome is recorded against the case, feeds the ranking and appears in the monthly coverage and outcome report
AutomationSystemPerson

Human-in-the-loop model

Automation handles

  • Daily extraction and alignment of accounts payable, expense, card, vendor and HR data
  • Running the rule library and the anomaly scoring across every transaction, not a sample
  • Reading flagged images and adding the authenticity signals
  • Assembling the evidence pack, ranking the case and reporting coverage and outcomes

People decide

  • What each case actually is: fraud, error, policy breach or noise, and whether to investigate
  • Escalation to compliance, legal, HR and, where it goes that far, to authorities
  • Thresholds, new tests and which signals are allowed to raise a case at all
  • Governance of the dataset: who may see it, for how long the evidence is kept, and on what documented basis

Before and after

BeforeAfter
Transactions testeda quarterly sampleevery invoice, expense line and card transaction, daily
Tests actually runthe few that fit a spreadsheetthe full rule library plus anomaly scoring
Receipt authenticityjudged by eyemetadata, creation software and repeated layouts raise the question
Time from transaction to detectionyears, and by chancedays to weeks, by design
Audit effortmostly aligning identifiersmostly investigating ranked cases

Systems and integrations

We do not add technology to make an architecture look serious. Every element below has a specific job in this process.

Inputs

  • SAP S/4HANA accounts payable and vendor master
  • SAP Concur expense lines and receipts
  • the card provider's monthly files
  • the HR employee master

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Integration Service
  • UiPath Document Understanding
  • UiPath Action Center

Target systems

  • the Microsoft Fabric lakehouse
  • the Power BI semantic model
  • the case record with its evidence

Human touchpoints: investigator tasks in Microsoft Teams; threshold and test approvals; the quarterly review with internal audit and compliance

SAP S/4HANA accounts payableUiPath OrchestratorUiPath Robotsthe Microsoft Fabric lakehouseinvestigator tasks in Microsoft Teams

Technologies used

UiPath Robots + UiPath Orchestrator

daily extraction from SAP, SAP Concur, card files and HR; queues, retries, credential store, audit

A
Microsoft Fabric (OneLake lakehouse and Data Science workload)

one aligned model of invoices, expenses, cards, vendors and employees, with the anomaly scoring beside it

A
UiPath Document Understanding (IXP)

reads invoice and receipt images so content, not only totals, is comparable across processes

A
UiPath Action Center

ranked cases as investigator tasks completed in Microsoft Teams, with assignment, SLAs, decision record

A
Microsoft Teams

where an investigator picks up a case, asks a question and records what happened

A
Power BI

coverage, cases by pattern and age, confirmation rate, losses confirmed and recovered

A
Microsoft Purview and Microsoft Entra ID

labels, retention and audit on case evidence; access confined to named investigators

A
The cross-process rule library and case ranking

our design, calibrated on your own history before anything runs live

C
Averified product capability (vendor documentation)Cillustrative model — the figures on this page

Illustrative economic model

What it is worth, with the arithmetic shown.

Illustrative model
€140,000,000 of addressable spend × 0.15% assumed cross-process leakage= €210,000 / year
€210,000 × 50% found earlier or deterred by continuous coverage≈ €105,000 / year
4 auditors × 24 h each × 4 quarters of data assembly= 384 h / year
384 h × €68 fully loaded audit cost≈ €26,112 / year
Annual value pool (illustrative)≈ €131,112

The leakage rate is the assumption that decides this case, and it is a placeholder rather than a finding: 0.15% of €140,000,000 of addressable spend, halved again because continuous coverage finds or deters part of what is there and not all of it. Audit time is the half that prices cleanly: four auditors, twenty-four hours each per quarter, at €68 an hour fully loaded. Investigation and legal cost avoided, insurance recoveries, Fabric capacity, licences and implementation sit outside the model, and at this scale they are not small. A company that has had a case usually knows its own leakage number, and the first run over twelve months of history replaces the placeholder with findings.

Business benefits

  • Coverage moves from a quarterly sample to every transaction daily, because the data assembly that limited audit is done by robots
  • Schemes that cross processes become visible: the employee, the vendor, the receipt and the card finally sit in one model
  • Generated receipts and invoices are questioned on metadata and repeated layouts rather than on how they look
  • Auditors spend their time on investigation instead of spreadsheets, and their findings are months old rather than years
  • The existence of the control changes behaviour, because per-process blind spots stop being reliable
  • The consolidated model also serves segregation-of-duties monitoring and spend analysis, so its cost is shared

The management view

  • A fraud-risk position that can be reported: coverage, open cases by pattern and age, confirmed losses and recoveries, per entity
  • A case queue with the evidence assembled and every decision recorded, which is what an external auditor or a regulator asks to see
  • Employee-vendor relationships and approval concentrations become a standing report rather than a discovery
  • False positives fall over time, because investigator outcomes feed the ranking and the queue concentrates on what matters

Board-level KPIs

share of transactions coveredopen cases by pattern and ageconfirmation ratetime from transaction to detectionlosses confirmed and recovered

Security and governance

Trust in automation is built on the audit trail, not on a promise.

  • This dataset links people to money, so its governance is part of the design and not an appendix. Access runs through Microsoft Entra ID groups and row-level security, and only named investigators reach the evidence
  • Purpose, tests, legal basis and retention are written down before the first load, employees are informed as data-protection law and works-council agreements require, and consultation is a client decision we plan around
  • No automated decision affects any person. Models produce scores, rules produce flags, and an investigator makes every decision, all of it recorded in the Action Center trail
  • Robots read and never write to a source system. Service accounts are read-only, their secrets in Azure Key Vault through the Orchestrator credential store
  • Case evidence carries Purview sensitivity labels and a retention rule agreed with legal. Any language-model step runs under the UiPath AI Trust Layer or Microsoft Foundry with allow-listed models in EU regions, and processing stays inside the EU Data Boundary and the EU region of UiPath Automation Cloud

Why now

01

Two things changed at once. Generated receipts and invoices went from rare to routine, which makes visual inspection unreliable, while boards and external auditors began asking internal audit for continuous assurance rather than an annual plan

02

The platform a cross-process view needs, a governed lakehouse with security, models and reporting in one place, is now part of the Microsoft tenant rather than a data-warehouse programme

03

Each quarter of waiting keeps 96 audit hours in spreadsheets and leaves the modelled €210,000 of annual leakage where it is, spread thinly enough that no single control notices

Relevant executive roles

CFO

Losses that used to run for years are found in months, and the external auditor's reliance on management controls improves

Head of Internal Audit

Continuous coverage of every transaction with the evidence assembled, instead of a quarterly sample built by hand

Compliance Officer

Employee-vendor relationships and approval concentrations become a standing report, not a discovery that has to be explained

CISO

Document forensics and impersonation signals join the fraud picture beside the phishing cases the team already investigates

Common questions and objections

Our expense audit tool already flags fraud.

Within expenses, and it does that well. It does not know that the same receipt was also paid as an invoice, or that the vendor's bank account belongs to somebody on the payroll. Those are the patterns the cross-process model exists to see.

Monitoring employees like this is a legal problem.

It is a legal question with an established answer: processing that is proportionate, documented and transparent, consulted where a works council requires it, with a person making every decision. We design for that from the first workshop, and we claim no certification on your behalf.

False positives will bury internal audit.

Rules are calibrated on your own twelve months before anything goes live, anomaly models are added only after that, and investigator outcomes feed the ranking. The queue is meant to get shorter and more accurate, and the reporting shows whether it does.

When this is not the right solution

  • A smaller organisation where one controller genuinely sees every invoice, expense claim and card statement; the view adds cost without adding sight
  • No internal audit or investigation capacity to act on what is found, in which case the ranked queue simply grows into a report nobody reads
  • Per-process controls that are still weak. Basic invoice and expense audits come first, because a model built on unreliable inputs produces confident noise

A question for the next management meeting

Two cross-process cases in five years were both found by accident: what evidence do we have that a third is not running now, and who in this company would be the one to notice?

Implementation approach

What we deliver, and what we need from you to start.

We deliver

  • A discovery run of the rule library over twelve months of history for one entity, written up
  • The consolidated data model and the daily extraction automation for every source
  • The rule library, anomaly models and authenticity checks, agreed with internal audit and compliance
  • Case assembly, ranking and the investigator task in Microsoft Teams
  • Power BI reporting on coverage, patterns, confirmation rate and outcomes
  • Investigator training, model monitoring and run-phase support

We need from you

  • Twelve months of accounts payable, expense, card and vendor-master history for one entity
  • A data owner and an internal audit owner who decides cases
  • Service accounts with read-only access to each source system
  • A decision on works-council and data-protection consultation, taken before the build starts

Stages

Discovery

Consolidate twelve months for one entity, run the rule library, let the findings set the scope

Design

Data model, access model, retention, the rule library and the case ranking with internal audit

Pilot

The daily pipeline live for one entity with rules only, so thresholds are calibrated on real cases

Scale

Further entities, anomaly models, authenticity checks and the feedback loop from outcomes

Run

Quarterly review of tests, models and thresholds with internal audit and compliance

Enterprise. Effort is driven by the number of source systems and entities, how far their identifiers diverge, and the consultation the group needs before employee-linked data is brought together.

An address that matched for four years sat in two of our systems the whole time.

Give us twelve months of accounts payable, expense and vendor-master extracts for one entity, anonymised if you prefer. We run the cross-process rule library over them and come back with what it found and an honest taxonomy of the false positives.

Run the rule library on one entity

The neighbouring process usually has the same problem

Industries we deliver this in most oftenManufacturing & industryRetail & e‑commerceServices & ITShared services

Browse all 173 solutions