Switch on the duplicate checks in your accounting and bill-capture tools, then run a monthly AI sweep of your bills export for near-duplicates (same supplier and amount, slightly different reference or date) and fraud signals such as changed bank details, brand-new suppliers and amounts just under approval limits. Confirm every bank detail change by phone.
Built-in checks catch the easy cases because they need an exact match on supplier, reference and amount. Real duplicates slip through on tiny differences: "INV-001043" against "1043", a supplier set up twice, a scanned copy entered alongside the emailed one. Fraud is different again. It rarely looks like a duplicate; it looks like a normal invoice with new bank details.
How duplicates and fraudulent payments actually get through
| Pattern | What it looks like | Why exact-match checks miss it |
|---|---|---|
| Same bill entered twice | Emailed PDF and paper copy both processed | Caught only if every field is identical |
| Near-identical reference | "INV-001043" and "1043" | References differ as text |
| Supplier set up twice | "Northgate Office Supplies Co." and "Northgate Office Supplies" | Different contact records |
| Statement paid as well as invoices | A statement total paid, then the invoices on it paid individually | Different references and amounts |
| Re-sent invoice | Supplier resends an unpaid-looking invoice with a new date | Date and sometimes reference changed |
| Split invoices | Two invoices of $2,450 instead of one of $4,900, just under a $2,500 limit | Not duplicates at all |
| Bank detail change fraud | A genuine-looking email saying the supplier has changed bank | The invoice is real, only the account differs |
| Fictitious supplier | A new supplier, paid quickly, for vague services | No duplicate to find |
The first five are errors, usually innocent and often recoverable. The last three are control problems, where the defence is a rule followed every time, with AI helping to spot the cases where it wasn't.
Start with the checks your software already has
These cost nothing and catch the obvious cases, so make sure they're on before building anything:
- QuickBooks Online has a setting called "Warn if duplicate bill number is used", under Account and settings, Advanced, Other preferences. Once on, it warns when you save a bill with a number already in the system for that supplier. It isn't available on Simple Start.
- Xero compares the contact, reference and amount across bills and credit notes and shows a notification on the purchases overview when it finds possible duplicates, which you review and either keep or delete. Two limits: the bill still posts unless someone acts on the warning, and bills created from a repeating template aren't flagged.
- Dext checks for duplicates as documents are processed. For invoices and credit notes, supplier, total amount and document reference must all match; for receipts, supplier, date, total and document owner. You choose automatic mode (suspected duplicates are deleted and kept in submission history), review mode (flagged with an amber icon) or off. The Dext help article on duplicates notes that if a key field such as the reference is missing from one copy, it may not recognise the pair.
Notice the common thread: all of them need several fields to match exactly. That's sensible for preventing false alarms, and it's exactly why a monthly sweep that tolerates small differences is worth adding.
The monthly AI sweep for near-duplicates
The running example is an illustrative accountancy practice that runs payables for 30 small-business clients, processing about 1,400 supplier bills a month across their ledgers. Bills arrive by email, through a capture app and occasionally on paper. It ran its first sweep over 13 months of data.
The export. From each ledger: bill ID, supplier name, supplier ID, reference, bill date, due date, amount, payment date, the last four digits of the bank account paid, date the supplier record was created, date its bank details last changed, and who entered and approved the bill. Remove full bank account numbers; the last four digits are enough for the checks.
Normalise the references first. Most near-duplicates are formatting differences. Ask the AI to create a cleaned reference column: uppercase, strip spaces and punctuation, remove prefixes such as INV, INVOICE and NO, and drop leading zeros. So "INV-001043", "Inv 1043" and "1043" all become "1043", while "INV1043/A" becomes "1043A" and is flagged as a possible part or credit rather than merged.
The sweep prompt.
Using the attached bills export, find possible duplicate pairs.
Work in Python and show the code.
1. Create clean_ref as described (uppercase, remove spaces and
punctuation, remove prefixes INV/INVOICE/NO, strip leading
zeros).
2. Create clean_supplier: lowercase, remove "ltd", "limited",
"inc", "llc", "co" as a whole word, punctuation and extra spaces.
3. Compare every pair of bills within 90 days of each other
where the amounts are within 1% OR the clean_ref matches.
4. Score each pair with the rubric below and return pairs
scoring 6 or more, highest first, with bill IDs, suppliers,
refs, dates, amounts, paid dates and the score breakdown.
Rubric: [paste rubric]
An illustrative slice of the output:
| Bill A | Bill B | Why flagged | Score | Status |
|---|---|---|---|---|
| Northgate Office Supplies Co., INV-001043, 12 Mar, $1,284.60 | Northgate Office Supplies, 1043, 19 Mar, $1,284.60 | Same clean supplier, ref and amount; two supplier records | 10 | Both paid |
| Fleetline Couriers, 88213, 3 Jun, $412.00 | Fleetline Couriers, 88213-R, 1 Jul, $412.00 | Resent invoice with suffix; same amount | 9 | B unpaid |
| Brightside Cleaning, 5521, 28 Apr, $960.00 | Brightside Cleaning, 5584, 26 May, $960.00 | Same amount, one month apart | 6 | Both paid |
The third row shows why every flag needs a person. A cleaning contract billed at the same amount every month produces pairs that look like duplicates and are perfectly genuine. After the first review, the practice added a rule: pairs of bills from the same supplier roughly a month apart with different references are skipped if the supplier is marked as a regular monthly supplier. That removed most of the noise without hiding real duplicates, which usually sit days or a few weeks apart.
A scoring rubric so the right flags get looked at first
A sweep that returns 200 possible pairs gets ignored. Scoring puts the likely duplicates at the top:
| Signal | Points |
|---|---|
| Cleaned references identical | 3 |
| Amounts identical | 3 |
| Amounts within 1% (tax or rounding differences) | 2 |
| Same supplier ID | 2 |
| Different supplier IDs but cleaned names identical or nearly so | 2 |
| Bill dates within 30 days | 1 |
| Both bills paid | 1 |
| Supplier marked as regular monthly, dates about a month apart | −3 |
Review everything at 6 or above. A score of 9 or 10 is almost always a real duplicate; 6 to 8 needs a look at the two documents side by side. Adjust the weights after the first two months based on what turned out to be real.
Fraud signals AI can spot in payment data
Fraud checks look at the pattern around a payment rather than pairs of bills. Add these to the monthly sweep as a separate list:
- Bank details changed, then paid within 30 days. The single most important list. Every item on it should have a recorded callback.
- The same bank account on two different suppliers. Occasionally genuine (a group of companies), sometimes a sign that a fraudster has redirected two suppliers to one account.
- New suppliers paid within a week of being set up, especially for services with vague descriptions such as "consultancy" or "support".
- Invoices just under an approval limit, or several from one supplier on the same day that together exceed it.
- Round amounts from suppliers who normally bill odd figures. $5,000.00 from a supplier whose invoices usually look like $4,317.28 is worth a question.
- Bills entered and approved by the same person, where your process says they should be different people.
Here's how one of them looked in practice. At one of the practice's clients, with an approval limit of $2,500, a facilities supplier billed $2,450 twice on the same day, both for "reactive repairs". The sweep flagged it under signal 4. The explanation was innocent (the supplier raises one invoice per call-out, and there had been two call-outs), but the client's manager hadn't known about the second call-out, and the combined $4,900 should have gone to the director. The fix was a rule rather than an accusation: same-day invoices from one supplier are added together for approval.
None of these signals proves anything. They're the cases a manager should look at, and the AI's job is to make the list short enough that they actually do. Keep the approval side tidy as well; approvals and payment runs without chaos covers how to structure who approves what.
The bank detail change rule that stops most payment fraud
Most payment fraud against small firms works the same way: an email, apparently from a real supplier, says their bank details have changed and asks you to pay the next invoice to the new account. The email may come from a lookalike domain, or from the supplier's real mailbox after it has been compromised. The defence is a rule, not a tool:
No change to a supplier's bank details takes effect until someone has phoned the supplier on a number already on file (never one given in the email or on the new invoice), confirmed the change with a named person, and recorded the date, the number called and who they spoke to. A second person then updates the record.
AI helps around the edges. It can read an incoming email and point out warning signs: a sender domain one character different from the one on file, a new reply-to address, urgency ("must be paid today to avoid suspension"), or a request for secrecy. Staff who know the signs catch more of these emails, and training staff to spot AI-written phishing emails is worth an hour of everyone's time. But no AI check replaces the callback, because a compromised real mailbox passes every test an email scanner can run.
An illustrative law firm shows why the rule matters. Its accounts team received an email from what looked like the practice manager of an expert witness the firm often instructs, attaching a genuine-looking invoice and "updated" bank details. An AI check flagged that the sender's domain had one letter doubled compared with the address on file. The team phoned the expert's office on the number in its own records; the practice manager had sent no such email. Payment fraud aimed at law firms is particularly damaging because client money may be involved, so the same callback rule should apply to any change of payment details from a client, another firm or a supplier.
A second, smaller case: an illustrative insurance broker received a "change of remittance details" letter supposedly from an insurer it pays monthly. The letter was on convincing letterhead. The callback to the insurer's accounts team, on the number in the broker's own agreement with that insurer, confirmed it was fake. The rule worked because it didn't depend on anyone judging whether the letter looked real.
What the first sweep found
For the accountancy practice, the 13-month sweep across 30 client ledgers, about 18,400 bills, produced 212 pairs scoring 6 or more before the regular-supplier rule, and 41 after it. Of those 41 (illustrative figures):
- 9 were real duplicates worth $14,260, of which 7 had been paid twice. Six came from bills processed both from email and from the capture app; three from suppliers set up twice.
- 4 supplier records were duplicates and were merged, which will stop future pairs at the source.
- 1 bank detail change had no callback recorded. The change turned out to be genuine, but the practice treated it as a failure of the rule and briefed the team again.
- 27 were genuine separate bills, mostly regular suppliers not yet marked as monthly.
Recovering the paid duplicates took one email per supplier. The AI drafted them from the pair details:
Hello, while reviewing our payments we found that invoice 1043 ($1,284.60) was paid twice, on 26 March and 2 April, to your account ending 4471. Could you refund the second payment, or credit it against our next invoice, and confirm which you'll do? Remittance details for both payments are below. Many thanks.
What to check before sending: that both payments really left the account (a payment voided after the run can still show as paid in the ledger), and that the supplier hasn't already issued a credit note. In the practice's case, one of the seven had been credited months earlier and simply not matched, so no email was needed for that one.
What an AI sweep can't catch
- A fake invoice from a real supplier to its real bank account for goods that never arrived. Only matching bills to orders and deliveries catches this; see matching supplier invoices to purchase orders.
- Collusion between a staff member and a supplier, where invoices are genuine in form and approved by the person involved. Separation of duties and a second approver for new suppliers are the defence.
- Anything outside the export. Card payments, petty cash and payments made directly from online banking without a bill in the ledger don't appear. Reconcile those separately.
- A first-time fraud that fits the normal pattern. The sweep finds anomalies; a well-made fake that looks exactly like a normal bill from a normal supplier to the normal account is, by definition, not an anomaly.
A 30-minute monthly routine
- Export the last 90 days of bills and payments, with the fields listed above.
- Run the near-duplicate sweep and review every pair scoring 6 or more.
- Run the fraud-signal list; confirm a callback record exists for every bank detail change paid in the month.
- Merge any duplicate supplier records found.
- Send recovery emails for paid duplicates and log them.
- Note anything that changed the rules (a new regular supplier, a false alarm pattern) and update the prompt or rubric.
After three or four months, the numbers usually fall sharply, because the fixes (merged suppliers, one capture route per client, the callback rule) remove the causes rather than just catching the results. That fall is the sign the sweep is working.
Duplicate invoices and payment fraud: more questions
How far back should a duplicate payment sweep go?
Thirteen months for the first sweep, so you catch duplicates that straddle a year end, then monthly with a rolling 90-day window. Suppliers often send an invoice again weeks later when they haven't matched your payment, so a window shorter than about 60 days misses a lot. If the first sweep finds several paid duplicates, extend it back another year.
What should I do if we've paid an invoice twice?
Contact the supplier promptly with both payment dates, amounts and references, and ask for a refund or a credit against the next invoice. Most suppliers will cooperate if you're specific. Record the recovery against the original bill so the ledger stays clean, and look at why it happened, because the same route will produce another duplicate unless it's closed.
Can AI tell whether an email from a supplier is genuine?
It can point out warning signs, such as a sender domain that differs slightly from the one on file, sudden urgency or a request to change bank details. It can't confirm an email is genuine, because a compromised supplier mailbox sends real-looking emails from the real address. Only a call to a phone number you already hold can confirm a change.
Is it safe to upload our payables data to an AI tool?
Payables exports contain supplier bank details and sometimes personal data about sole-trader suppliers. Use a business plan that doesn't train on your content by default, remove bank account numbers you don't need for the check, and delete uploaded files when the sweep is finished. For bank detail analysis, compare a masked version, such as the last four digits.
Further reads
- AI Invoice Processing: Stop Typing Supplier Bills by Hand — Capture supplier bills cleanly so fewer duplicates get in.
- Dext vs Hubdoc: Which Receipt Capture Tool Saves More Time? — Compare capture tools, including how they handle duplicates.
- How to Spot Deepfake Voice and Video Scams Aimed at Your Business — When the fraudster phones or joins a video call instead.
- How to Set Spending Rules and Approvals for Business Purchases — Approval limits that make split invoices easier to spot.
- How to Automate Bank Reconciliation With AI and Check the Matches — Reconciliation catches payments with no matching bill.
- Is It Safe to Connect AI Tools to Your Business Bank Account? — What to check before connecting AI tools to bank data.
- AI Receipt Capture and Bank Categorisation: A Bookkeeper's Setup — Set up receipt capture and bank coding in six stages per client, with supplier rules, ledger AI suggestions and a weekly review that catches duplicates.
- How Accountants Use AI to Spot Errors in Client Books — The error checks worth running on every client file, the tools that run them, and how to turn thirty flags into the six corrections that matter.
- Best AI Accounting Software for Small Businesses in 2026 — Seven accounting platforms compared on what their AI actually does, what it costs at list price, and which kind of small business each one suits.
- AI Email Triage for Shared Inboxes: Sales, Support, and Invoices — Split a hello@ inbox into sales, support and invoice lanes with AI labels, confidence thresholds and a fraud check on anything asking to be paid.
- How to Check a New Customer's Credit Before Offering Terms — Check a new business customer before giving 30-day terms: the application, identity checks, credit report and references, with AI summarising the evidence.
- How to Categorise Transactions With AI and Check Its Work — A category guide, bank rules for the routine 60%, AI for the rest, and a monthly sampling check that tells you when its coding has drifted.
- AI Supplier Management: Track Prices, Lead Times, and Risk — A supplier register AI can keep up to date: price histories from invoices, measured lead times, delivery performance and a simple risk score, reviewed monthly.
- What Finance Tasks Can AI Automate in a Small Business? — Fifteen finance jobs AI can take over in a small business, each with an example, a first step and the check that stops it going wrong.
- Xero vs QuickBooks AI: Which Saves More Bookkeeping Time? — A costed month in both products, the plan-by-plan AI features at list price, two wrong matches to learn from, and a two-week trial scorecard.
- QuickBooks AI Features: What Intuit Assist Can Automate for You — What QuickBooks Online's AI automates on each plan, from ready-to-post bank transactions to invoice reminders and inbox leads, and how to keep control.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: QuickBooks Online help and partner help pages (Warn if duplicate bill number is used, under Advanced settings; not on Simple Start); Xero Central (review duplicate bills or credit notes: contact, reference and amount compared; repeating bills not flagged); Dext Help Centre (duplicate detection fields and modes).