Detect procurement fraud before losses escalate

September 2026 Security Services & Risk Management, News & Events, Financial (Industry), Editor's Choice

Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

This follows SAS’s Continuous Monitoring for Procurement Integrity client session, held at its Johannesburg offices in August, which focused on how continuous monitoring and AI-driven analytics can help organisations identify vulnerabilities earlier, strengthen controls, and improve transparency across procurement operations.

Chris McAuley, director of fraud and security intelligence for SAS EMEA and APAC, says procurement activity often spans fragmented systems and large volumes of data, while many organisations still lack an independent monitoring capability across the procurement environment.

“By the time an irregularity reaches an audit or investigation, the organisation may already be dealing with the financial and operational consequences. Continuous monitoring changes the timing. It gives organisations a way to look across procurement activity as it happens and identify emerging indicators that deserve investigation before the exposure grows,” says McAuley.

Moving the point of detection forward

Traditional audits remain important, but they provide a view at a particular point in time. Fraud, error, waste, and abuse do not follow a schedule. Suspicious behaviour can arise from relationships between employees and suppliers, repeated transactions, unusual purchasing patterns, or attempts to work around established controls.

The SAS Payment Integrity for Procurement solution is designed as an enterprise-wide continuous monitoring capability to detect potential instances of fraud, error, waste, and abuse (FEWA) throughout the procurement cycle. It uses enterprise data, predefined and customised analytical scenarios, modelling and network analytics to surface activity that warrants closer attention. Current and historical activity can be analysed together, with risk scoring helping investigators prioritise where to focus their investigations.

“AI is useful here because procurement teams and investigators are dealing with volumes and relationships that are difficult to assess manually,” says McAuley. “AI can help investigators spot patterns and connections earlier, understand the context around suspicious activity and focus their attention where the risk appears greatest.”

An unusual transaction is not automatically fraudulent, and an anomaly may have a legitimate explanation. Effective monitoring, therefore, has to support investigation rather than replace it.

Turning analytics into action

Yolande Byrd, director at FACTS Consulting, says organisations also need to think beyond detection. Her presentation at the session drew on customer implementations that began in very different procurement environments, but shared the need for better visibility into procurement risk and a clearer way to decide where action was needed.

“The real value of analytics comes from what the organisation does with what it reveals. A long list of alerts is not the goal. Investigators need enough context to understand why something has been flagged, what other activity or relationships may be connected to it, and where the potential risk or financial impact is greatest,” says Byrd.

One example discussed during the session involved a government-funded construction project spanning multiple joint ventures and separate ERP systems. By combining procurement information and analysing activity across vendors and subcontractors, the organisation reported R250 million in savings within six months, including identifying and correcting duplicate payments.

Another customer, a utility provider, began with a proof of value before expanding monitoring. It reported R120 million saved over two years on duplicate invoices alone, alongside actual fraud cases.

“Starting with a defined area of exposure allows the organisation to test what the data reveals and establish how alerts will be investigated before expanding on demonstrated value. Clear ownership and investigative capacity are essential because finding a weakness achieves very little if nobody is responsible for acting on it,” says Byrd.

A broader governance issue

Continuous procurement monitoring can also reveal weaknesses that sit outside a single fraudulent transaction. Repeated circumvention of approval thresholds, concentrated purchasing through particular requisitioners or unusual supplier relationships may point to gaps in processes and controls that require attention. That makes procurement integrity a broader business issue. Financial loss is one consequence, but weak oversight can also expose organisations to regulatory scrutiny and reputational damage, undermining stakeholder confidence.

McAuley says AI and advanced analytics give organisations an opportunity to strengthen that oversight without expecting investigators to manually examine an ever-growing volume of procurement data. “Procurement integrity should be treated as an ongoing management discipline. The objective is to give the organisation enough visibility to investigate risk properly and strengthen the controls around the areas where weaknesses are emerging.”

Byrd agrees that the move towards continuous monitoring is ultimately about changing how organisations use their procurement data. “Organisations already generate enormous amounts of information through procurement. The question is whether they are using it to understand where risk is developing. When monitoring becomes continuous, and the response is properly designed around it, procurement data becomes a tool for stronger governance as well as financial protection.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Dallmeier extends software maintenance up to 10 years
Dallmeier Electronic Southern Africa Surveillance News & Events
Dallmeier is expanding its software maintenance offering and now provides an additional maintenance package for cameras and recorders, enabling customers to keep their video security systems up to date for up to 10 years.

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Nimbus remote fire alarm management
Technoswitch Fire Detection & Suppression Security Services & Risk Management Fire & Safety
Nimbus connects key stakeholders to their fire alarm systems, simplifying compliance with fire safety standards and greatly improving visibility into critical events, thereby augmenting first responder processes that save lives and protect assets.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Video surveillance market faces faster growth, and 2026 price shock
Surveillance News & Events
Novaira Insights has released its 2026 edition of The World Market for Video Surveillance Hardware and Software, highlighting a stronger global growth profile in 2025, tentative improvements in China’s market outlook, and unprecedented price increases in 2026.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.