Business Invoice Fraud Risk Calculator
Score a vendor invoice or payment-change request against 5 patterns common to Business Email Compromise (BEC) and invoice fraud before approving payment.
Inputs
- Did the vendor's bank/payment details recently change?
- Was the change requested by email only, with no phone confirmation?
- Is there unusual urgency to process this payment quickly?
- Does the sender's contact info differ from your vendor records?
- Has the change NOT been verified by calling a known, independently-sourced number?
Paste this into any page — the widget stays live and updates automatically as this calculator improves. Using WordPress or Notion? See the embed guide.
Saved Scenarios
— select 2+ to compare| Metric | |
|---|---|
Invoice Fraud Risk Score
0
Invoice Fraud Risk
Safe
Risk Level
Safe
Recommendation
No major red flags detected — standard verification for any payment-detail change is still good practice.
Spark says
How it's calculated
What is the Business Invoice Fraud Risk Calculator?
This calculator scores a vendor invoice or payment-change request against 5 patterns central to Business Email Compromise (BEC) and invoice fraud — consistently one of the highest-dollar-loss cybercrime categories the FBI tracks. It's built for accounts-payable staff and small-business owners processing vendor payments.
Use this any time a vendor requests a change to payment or bank details, or when an invoice looks slightly different from what you'd expect from that vendor — before processing payment, not after.
How to use it
- 1 Answer the 5 questions about the specific invoice or payment-change request you're reviewing.
- 2 Read the resulting fraud risk score and recommendation before processing payment.
- 3 Treat 'bank details changed' plus 'not phone-verified' as a hold on payment regardless of the total score — this specific combination is the core of nearly every reported case.
Understanding Business Invoice Fraud Risk Calculator
Business Email Compromise consistently ranks among the highest-dollar-loss categories in the FBI's Internet Crime Complaint Center annual report, frequently exceeding the combined losses of many other cybercrime categories — not because any individual scam email is especially sophisticated, but because the target (a real, pending payment a business already intended to make) means a successful attempt can redirect a large, legitimate sum in a single transaction.
The mechanism is almost always the same regardless of the specific story: an attacker gains access to, or closely spoofs, a real vendor's or executive's email account, then sends a request — usually a bank-detail change for an upcoming payment, or an urgent wire request — that looks like it's coming from a trusted, already-established business relationship. This is precisely why BEC bypasses the skepticism people apply to obviously unfamiliar scam emails: the sender name, the invoice format, even the writing style can all look exactly right, because in a compromised-account scenario, they often are.
The payment-detail change is the highest-value moment to catch this, because it's the single point where the fraud actually converts into stolen money — everything before it (the email compromise or spoofing itself) causes no financial harm on its own. This is why the recommended defense concentrates entirely on this one moment: any change to where money is sent gets verified through a channel independent of the request itself, specifically a phone call to a number the business already had on file before the request arrived, not a number provided in the email.
Urgency plays the same role here it does in every other scam category — a deadline, a threat of late fees, or an appeal to not wanting to hold up an important vendor relationship, all designed to make skipping verification feel like the reasonable, fast choice rather than the risky one. 'CEO fraud,' a close cousin of standard BEC, adds a social-hierarchy pressure on top: a request that appears to come from a company's own executive, sent to someone junior enough to feel uncomfortable pushing back or delaying to verify.
What ultimately defeats BEC isn't spotting bad grammar or an obviously fake-looking email — well-executed BEC attempts often have neither — it's a mandatory, no-exceptions process: any payment-detail change gets an independent phone call before money moves, regardless of who's asking or how urgent it sounds. Businesses that treat this as a hard policy, not a judgment call, consistently avoid the losses that make BEC one of the costliest cybercrime categories for businesses of every size.
Worked examples
Classic BEC vendor-impersonation email
Scores 100/100 — 'Critical'. Every classic BEC element is present — this exact combination is responsible for billions in reported US business losses annually.
Try itRoutine, verified vendor update
Scores 30/100 — 'Suspicious', despite a real bank-detail change, because it was properly phone-verified against known vendor records — the process, not the change itself, is what determines risk.
Try itAdvantages
- •Targets the exact mechanism (email-only payment-detail changes with no independent verification) behind the large majority of reported BEC losses.
- •Runs entirely in your browser — nothing about your vendor relationships or invoices is sent anywhere.
- •Gives a repeatable checklist accounts-payable staff can apply consistently, rather than relying on individual judgment call by call.
Limitations
- •This can't verify a specific invoice, vendor or email is fraudulent — it scores the process red flags around the request.
- •This isn't a substitute for a documented, mandatory phone-verification policy for any payment-detail change — the process matters more than any single checklist run.
- •If a fraudulent payment has already been sent, time is critical — contact your bank immediately, since wire recalls are only sometimes possible within a narrow window.
Common mistakes
- ⚠️ Verifying a payment-detail change by replying to the same email thread or calling a number provided in the request — both can be controlled by the same attacker.
- ⚠️ Treating an urgent-sounding request from someone claiming to be an executive ('CEO fraud') as exempt from normal verification because of their apparent seniority.
- ⚠️ Focusing only on obviously bad grammar or formatting — sophisticated BEC emails are often well-written and use a genuinely compromised or closely spoofed account.
- ⚠️ Processing a payment quickly specifically because it's below an approval threshold designed to avoid an extra layer of review — a pattern some fraud attempts are deliberately structured around.
Tips
- 💡 Require phone verification, using a number from your own existing records (never one provided in the request), for any change to vendor bank or payment details, without exception.
- 💡 Establish a documented policy that no one — regardless of title or urgency — can bypass verification for a payment-detail change.
- 💡 Check sender domains character-by-character when a request involves money — look-alike domains (e.g. an extra letter, a swapped character) are a common BEC technique.
- 💡 If you discover a fraudulent payment was sent, contact your bank immediately to request a wire recall, and file a report with the FBI's IC3 (ic3.gov) — recovery is time-sensitive.
Real-life uses
- Reviewing a vendor's request to update their bank account for future payments
- Evaluating an urgent invoice that arrived close to a payment deadline
- Screening an email claiming to be from an executive requesting an unusual payment
- Setting up a repeatable verification checklist for a small business's accounts-payable process
Frequently asked questions
What is Business Email Compromise (BEC)?
A scam where an attacker compromises or spoofs a real business email account (a vendor or executive) to redirect a legitimate payment, most often by requesting a change to bank/payment details.
What's the single most important defense against invoice fraud?
A mandatory phone-verification policy for any payment-detail change, using a number from your own existing records — never one provided in the request itself.
What should I do if I already sent a fraudulent payment?
Contact your bank immediately to request a wire recall (time-sensitive) and file a report at ic3.gov.
Should I trust an urgent request from someone claiming to be an executive?
Apply the same verification regardless of claimed seniority — 'CEO fraud' specifically relies on juniors feeling uncomfortable questioning an apparent executive request.
Are well-written, professional-looking invoices proof they're legitimate?
No — sophisticated BEC attempts are often well-written, sometimes from a genuinely compromised real account. Verification process matters more than how the email looks.
Sources & references
calixo.cloud/scam/business-invoice-fraud-risk-calculator/ — free calculator, no signup required.