Stop paying ghost employees before ACH clears. — on continuous audit.
A ghost-employee scheme rides on a master-data + approver-rights co-move that legacy post-payment sampling never sees — the ring is small in count and short in window. VeraStream runs the same eight production detectors against every vendor onboarding, approver grant, and disbursement your business posts, and detectGhostEmployee reads the co-move at the queue. The same pipeline held a $94,700 ghost-employee ring pre-payment — five detectors fired on two invoices, one workpaper, zero dollars out.
Why ghost-employee rings slip past post-payment audit
Three real patterns of ghost-employee control failure
Each citation below is drawn from public Inspector General reports, IIA published findings, and the ACFE fraud handbook — not invented hypotheticals.
A payroll-misroute scheme bled a federal program for years before sampling caught it
A long-running ghost-employee scheme at a federal payroll office routed disbursements to fictitious employees on the master-data roster for several fiscal years before an Office of Inspector General audit surfaced it. The detection was a sampling exercise conducted after the funds had left the account — recovery ran through a multi-year forensic accounting cycle rather than a pre-payment hold.
Source: Council of the Inspectors General on Integrity and Efficiency — payroll fraud findings
Internal audit flagged payroll master-data SOD as a material weakness across business units
A multi-BU manufacturer documented — in an internal audit report — that the segregation-of-duties between vendor onboarding and approver-rights granting was insufficient across several shared-services centers. The auditors recorded instances where the same individual introduced a new vendor to the master file and granted themselves sign-off authority on the same vendor within the same work-week. The remediation was a quarterly master-data reconciliation; the loss continued in the gaps.
Source: IIA Global — payroll master-data & SOD control deficiencies
Ghost-employee schemes accounted for a measurable share of occupational-fraud losses in the ACFE 2024 report
The Association of Certified Fraud Examiners reports that ghost-employee and payroll- misroute schemes persist at scale across mid-market and enterprise alike, with median losses landing in the six-figure range and median duration exceeding two years before detection. Detection almost always arrives via tip or post-payment sampling — not a pre-payment control that holds the disbursement while the master-data change is reviewed.
Source: ACFE Occupational Fraud 2024 — payroll disbursement schemes
What breaks during a ghost-employee scheme
Six specific failure modes across vendor-master, duplicate-invoice, and approver-rights
- Duplicate vendor master (legacy + re-onboarded). The same fictitious employee ends up under two vendor IDs — one carried from a prior system, one created during a recent re-onboarding. Until a reconciliation catches the collision, both IDs pay into the same scheme.
- Typosquat vendor (one-character delta from an approved payee). A new vendor name with a Jaro-Winkler near-miss of an approved master-data entry — Beacon Strategy LLC vs. Beacon Strategies LLP, Microsot vs. Microsoft. The master has no fuzzy-match dedup at onboarding; the disbursement clears to the ghost-employee beneficiary.
- Two-invoice ring to a first-seen vendor inside a short window. The first invoice clears the master-data + approver onboarding geometry; a near-duplicate second invoice queues within days. Without a pre-payment detector pipeline, the ring pays itself off in two legs.
- Structured sub-threshold payroll cluster. A stream of small-dollar disbursements, each below the approver threshold, routed to one first-seen vendor over a work-week — the shape that pre-payment sampling never samples, but a continuous detector pipeline reads at the queue.
- Introducer is also the approver (right-of-first-approval abuse). A new vendor is added to the master by the same individual who is granted sign-off authority on that vendor within the same work-week. The introduce-and-approve co-move is the ghost-employee signature — the same person built the entry and holds the right of first approval on it.
- Round-cent clone-template invoice from a first-seen payee. A no-cent invoice amount and a memo template the customer had migrated off two quarters earlier — a clone-template signature that a ghost-employee ring uses by construction, flagged pre-payment as a script-gen pattern rather than catching it in a post-payment sample.
Detector → ghost-employee pattern → sample finding
How VeraStream maps each of the eight production detectors to ghost-employee risk
The same eight production detectors that run across every VeraStream audit — mapped to the specific ghost-employee failure mode each one reads, with a one-line sample finding from the $94,700 pre-payment hold.
| Detector | Ghost-Employee Pattern | Sample Finding |
|---|---|---|
evaluatePolicy | Approval-matrix gap — new approver signs off on a vendor they themselves onboarded in the same week | A new approver granted sign-off authority on a vendor the same individual added to the master-data file 48 hours prior — held before the payment batch cleared. |
findDuplicateInvoices | Two-invoice ring to the same first-seen vendor inside a short window — first pays the ring, second would | Two invoices $48,500.00 and $46,200.00 to "Beacon Strategy LLC" — first cleared ten days after onboarding, second held on queue by the eight-detector pipeline. |
detectExpenseAnomalies | One-cardholder expenses routed through a new merchant category the same week as a master-data vendor change | A ghost-employee expense stream — same cardholder, two merchant categories, conflicting close-name — flagged for confirmation alongside the master-data hold. |
detectVendorRisk | Typosquat / unapproved payee — first-seen vendor with a near-miss legal suffix against an approved vendor | New vendor "Beacon Strategy LLC" — Jaro-Winkler typosquat of approved "Beacon Strategies LLP" — held as a shell-vendor heuristic before payment posted. |
detectThresholdGaming | Structured sub-threshold payroll-style payments — multiple invoices below the approver ceiling in a tight window | $18,400 × 2 to the same first-seen vendor within 3 hours — each below the $25,000 dual-approver threshold — flagged as a split-purchase cluster. |
detectRoundDollar | Round-cent disbursements to a first-seen vendor under 30 days — clone-template / script-gen flag | $48,500.00 and $46,200.00 — both no-cent — to a vendor first-seen within the prior week; memo template matched a clone the customer had migrated off two quarters earlier. |
detectGhostEmployee | SOD weakness — new vendor on a new approver in the same week as a master-data change (the leading indicator) | A new vendor added to the master and a new approver granted sign-off rights within the same 48-hour window — flagged as ghost-employee pre-payment, second invoice held. |
detectDuplicatePayment | Same vendor + same or near amount clustered in a short window (recurring SaaS/rent and refund reversals auto-suppressed) | $48,500 and $46,200 to "Beacon Strategy LLC" within eleven days — flagged for duplicate review; would have surfaced the second leg retroactively had the first cleared unobstructed. |
How VeraStream fits a 90-day ghost-employee audit
Three bands: scan, monitor, deliver
The post-detection window is 90 days. Each band runs the same eight production detectors against the vendor-master + approver-rights population — the format of the output shifts as the engagement moves from baseline to formal findings.
Master-data + approver-rights baseline scan
Full historical scan against the vendor master, the approver-rights grants log, and 90 days of payroll-style disbursements. Output: a master-data + approver co-movement map and a first-seen vendor risk tiering by day 14 — the foundation of the ghost-employee exposure curve.
Monitored detection
Connectors stream new vendor onboardings, approver-rights grants, and first-seen vendor payments from the ERP, corporate card feed, and HRIS (where available). New vendor + new approver co-moves are scanned in real time. Weekly finding roll-ups are delivered to the AP and internal audit leads with the workpaper trail intact.
Formal findings package
Every flagged ghost-employee pattern with the receipt, the rule that tripped (the detector id from the eight, the corroborators that fired on the same receipt), and the override applied. Sized to hand directly to your external auditor under PCAOB AS 2315 — the same evidence package that feeds your SOX 404(b) assessment.
Frequently asked
Common questions from AP, payroll, and internal audit teams
What the agent does for ghost-employee fraud — plain HTML answers, no JavaScript required to read.
What is a ghost-employee AP fraud pattern?
A ghost-employee scheme is a payroll- or vendor-route fraud where a fictitious employee is provisioned in the master-data file and the same (or co-conspiring) individual is granted sign-off rights on payments to that vendor. The two master-data events typically land inside the same work-week — introduced by the same person, approved by the same person. VeraStream's detectGhostEmployee detector reads that exact co-move on every payment and flags it pre-payment rather than sampling it post-quarter.
Where does detectGhostEmployee sit inside the eight-detector pipeline?
detectGhostEmployee leads the hold on a ghost-employee pattern — it fires on the master-data + approver-rights co-move, the unique signal. The other seven detectors run as corroborators on the same receipt: detectVendorRisk on the typosquat, detectDuplicatePayment on the second-leg ring, evaluatePolicy on the SOD gap, detectRoundDollar on the clone-template cents, detectExpenseAnomalies on the corporate-card stream, findDuplicateInvoices on the ring geometry, and detectThresholdGaming on the structured cluster. Five fires, one receipt, one workpaper.
Why does quarterly sampling miss ghost-employee schemes?
A ghost-employee ring is small in payment count (one or two invoices per cycle) and short in window (a week or two before the beneficiary changes). A legacy post-payment sample of 25 to 60 items per quarter — at a sub-1% sample rate — typically sees 0 of the 1–2 ring payments and never trips the master-data + approver-rights co-move signature. VeraStream's 95% pre-payment coverage reads both the master-data event and the approval chain on the day the second invoice queues, so the hold publishes before the disbursement run.
What does the workpaper look like when detectGhostEmployee fires?
Every flagged ghost-employee pattern ships a workpaper with the receipt (the master-data event, the approver-rights grant, the payment that triggered the hold), the rule that tripped (detectGhostEmployee primary, plus the corroborator detector ids that fired on the same receipt), and the override field (empty when held for review). Sized to PCAOB AS 2315 — your external auditor receives the same evidence package they would demand from a manual control test, but produced continuously rather than once a quarter.
Which ERPs, corporate card feeds, and HRIS sources do you connect to?
Live deploys use pre-built connectors to NetSuite, SAP, Oracle, Concur, Expensify, Brex, and Ramp for AP and corporate card; Workday and BambooHR for HRIS (read-only, for headcount cross-check). Vendor onboardings, approver-rights grants, and corporate-card streams are read in real time. If your stack is on a different platform, the /audit page lets you drop a CSV of the AP ledger and see the same eight detectors run in the browser — no integration required.
Test it on your own AP ledger
Catch the ghost-employee ring before disbursement clears
Drop a CSV of your vendor master, your approver-rights log, and 90 days of disbursements at /audit — see the eight detectors run in under 90 seconds in the browser. Use /roi to estimate your ghost-employee exposure, and /pricing to launch continuous monitoring against your live ERP.