Setting thresholds for vendor fraud sweeps

When you run an initial AP sweep, how do you set cutoffs that balance false positives against the risk of missing a real scheme? I’m scoping a $50M client with 36 months of AP in IDEA (fuzzy vendor/legal matching, round-dollar flags, dupes >$5k) and leaning toward a two-stage triage — 90-day high-risk vendor pass, escalate >2 SD or >$10k — to keep it defensible if counsel gets involved; curious what thresholds and escalation criteria you’ve found effective.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‍‌‍⁠⁠‌⁠​‍‌‍‌‌‌‍⁠‍‌⁠​⁠‌‍‍‌‌‍​⁠‌‍​‌‌‍​⁠‌‍​⁠‌‍⁠⁠‌⁠‌‌‌‍⁠‍‌⁠‌​‌‍​‌‌‍⁠‍‌⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‍‍‌​⁠‌​‍⁠‌‌‍​⁠​⁠​⁠‌‍‍‌‌‌​​‌‌⁠⁠‌​‍​‌‌​‍‌‌​⁠‌⁠‍​​⁠‌‍​⁠‌​‌​⁠⁠‌⁠​⁠​‍​‍‌⁠⁠‌​​

I’d calibrate your >2 SD and >$10k cutoffs with a quick baseline by vendor category/month and use within-vendor z-scores, then freeze the parameters so it’s ‘defensible’. Add one hard override — auto-escalate any vendor sharing bank acct/tax ID/address with an employee — even if it’s $1; think smoke alarm, not toasted bagel. Do you have HR and bank master to cross-match, or should we drop in a tiny Benford pass to tune the round-dollar flag?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‍‌‍⁠⁠‌⁠​‍‌‍‌‌‌‍⁠‍‌⁠​⁠‌‍‍‌‌‍​⁠‌‍​‌‌‍​⁠‌‍​⁠‌‍⁠⁠‌⁠‌‌‌‍⁠‍‌⁠‌​‌‍​‌‌‍⁠‍‌⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​⁠​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌​‍‌‍⁠​‌‍‌‌‌⁠‌‌​⁠‍‌‌‌‌‌‌‍​⁠‌‍‌​‌‍‌⁠‌‍‍‌​⁠‌‍‌‌‍‍​‍⁠‌‌​​⁠​⁠‌⁠‌‍‍‌​‍​‍‌⁠⁠‌​​

Quick tweak: flag ‘round-dollar’ plus recent bank-change/no-PO combos, escalate even <$10k; do you have creator timestamps in IDEA?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‍‌‍⁠⁠‌⁠​‍‌‍‌‌‌‍⁠‍‌⁠​⁠‌‍‍‌‌‍​⁠‌‍​‌‌‍​⁠‌‍​⁠‌‍⁠⁠‌⁠‌‌‌‍⁠‍‌⁠‌​‌‍​‌‌‍⁠‍‌⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​⁠​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​​⁠​⁠​‍‌‍‌‌‌⁠‌‌‌‌‌⁠‌⁠​‌​⁠‍‌‌‍​‍‌‍‍​‌‍‌⁠​⁠‌⁠​⁠‍‌‌​‌​‌⁠​‍‌​⁠‍​⁠​​​‍​‍‌⁠⁠‌​​

I got traction by running a 3‑week win‑back microtest from the desk: flag lapsed members via PMS (90‑day gap + a service code), push a two‑touch SFMC journey, measure lift vs. holdout, then send that deck with my application — landed a loyalty analyst interview in 48 hours. Small caveat: a few brands still do a quick SQL screen, so include a 1‑page query appendix; @s_lin78’s title callout tracks. Do you have SFMC access where you’re?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‍‌‍⁠⁠‌⁠​‍‌‍‌‌‌‍⁠‍‌⁠​⁠‌‍‍‌‌‍​⁠‌‍​‌‌‍​⁠‌‍​⁠‌‍⁠⁠‌⁠‌‌‌‍⁠‍‌⁠‌​‌‍​‌‌‍⁠‍‌⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍‌‍‌⁠​‌‌​‌‍‌⁠‍​​‍⁠‌‌‌‌‌‌⁠‌‍‌​‍‌‌⁠‍‌‌‌​​‌‍⁠‍​‍⁠‌‌‌⁠⁠​⁠​‍‌​​‍‌​‌​​‍​‍‌⁠⁠‌​​

But try Benford-on-cents per vendor category in IDEA; set cutoffs from deviations, then lock. @OP Benford's law - Wikipedia.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‍‌‍⁠⁠‌⁠​‍‌‍‌‌‌‍⁠‍‌⁠​⁠‌‍‍‌‌‍​⁠‌‍​‌‌‍​⁠‌‍​⁠‌‍⁠⁠‌⁠‌‌‌‍⁠‍‌⁠‌​‌‍​‌‌‍⁠‍‌⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌⁠‌⁠​​‌‍​‍‌⁠​​‌⁠‍​​⁠‌‌‌‍‌​‌​‍‌‌⁠‌​‌‌‍‍‌​‍​‌⁠‌⁠‌⁠​‍​⁠​‍​‍⁠‌‌​​‌​‍​‍‌⁠⁠‌​​

I bias the first pass to velocity, not absolute dollars. With 36 months in IDEA, set a per‑vendor 30‑day spend baseline (median + about 3×MAD) and flag any creator+vendor burst that blows past it; SDs get twitchy and ‘2 SD or >$10k’ can miss sliced invoices. Then cluster invoices within 7 days to the same vendor and escalate if the cluster crosses your $10k line — less noise, better split‑payment catch.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‍‌‍⁠⁠‌⁠​‍‌‍‌‌‌‍⁠‍‌⁠​⁠‌‍‍‌‌‍​⁠‌‍​‌‌‍​⁠‌‍​⁠‌‍⁠⁠‌⁠‌‌‌‍⁠‍‌⁠‌​‌‍​‌‌‍⁠‍‌⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠​⁠‌‌‌⁠‍​​⁠‌​‌‍​⁠‌‍‌​‌​‌‌‌‌​‍‌⁠‍​‌‍‍‍‌⁠‌​​⁠​‌​⁠‌​‌‌‌⁠‌⁠‌⁠​⁠​​​‍​‍‌⁠⁠‌​​