Dafydd Llewellyn at HICX argues that, with generative AI making it ever easier for bad actors to infiltrate supply chains, strictly governed supplier data is now the front line of defence

The mechanics of fraud have changed rapidly in the past decade. Setting up a convincing fake company, complete with a plausible registration number and a bank account that passes a cursory glance, is no longer the preserve of organised criminal networks with time and resources. Generative AI tools have made forged documentation, spoofed domains and convincing impersonation available to anyone with an internet connection and a motive.
If the global rise in fraud cases has shown us one thing, it is that the risk is no longer limited to the finance function. Instead, it has migrated to the operational heart of business, and the front door for many companies is through their supply chain.
More than three in four organisations faced attempted or actual payment fraud last year, and close to two-thirds were hit specifically by vendor or third-party impersonation scams. Global e-commerce fraud losses topped $48 billion in 2025. In the vast majority of these cases, an untrustworthy supplier record was the chink in the armour. The systems many companies still rely on to admit new suppliers were built for a slower, more trusting era; one where fraud diversified far more slowly than it does now.
In most organisations, suppliers still enter through multiple channels, often relying on a form here or a spreadsheet update there in operational siloes that rarely talk to one another. In such a convoluted and fragmented system, it is easy to see how fraudsters can embed themselves into company supply chains.
Over half of all fraud cases involve controls that were either missing or overridden and weak governance processes, but only 58% of organisations currently screen third parties for regulatory risk, and just a third use anything resembling a risk-weighted approach. Most organisations cannot prove a given supplier was validated before first payment, even when the check was performed, because it went unrecorded. And where fraud does eventually occur, the median time to detection sits at twelve months.ibid
This is a serious issue for regulatory compliance as much as it is for the balance sheet. Without a proper audit trail, it is easy to end up in hot water, unable to demonstrate to a regulator or an insurer that the checks a business believes it ran were ever actually completed and verified.
What is incredibly exciting is the coming introduction of ISO 25500, a new standard developed by the Electronic Commerce Code Management Association, which could dramatically change how companies can protect themselves against fraud. It offers something the industry has lacked until now: an international gold standard for what verified, trustworthy supplier data should look like, and a benchmark that organisations can be held to rather than a patchwork of internal policies applied unevenly from one team to the next.
ISO 25500 is built around the International Business Identifier, or IBID, which links a supplier’s legal registration number to a verifiable identifier tied to the government’s primary-source registry data rather than a commercial database. It pushes organisations toward continuous monitoring rather than a one-off check at onboarding, so a change in legal status is picked up as it happens, not discovered when a payment bounces or an auditor asks an uncomfortable question.
Insulating against fraud risk now requires treating supplier data as a governed asset rather than an administrative afterthought. Every organisation needs one entry point for new suppliers, not five. Mandatory checks- address, tax, bank and sanctions- need to hard-block submission when they fail, rather than relying on someone catching the problem later. Bank detail changes need controlled approval, not a quick update from an unverified email. Revalidation needs to happen on a schedule, because a supplier that passed every check at onboarding can be sanctioned, dissolved or compromised within months.
If we are serious about stopping fraud, we need to stop it at the front door, the point where fragmented supplier data and lax verification processes let it in unchallenged. ISO 25500 will set the industry standard for doing exactly that, demanding rock-solid data foundations and watertight verification in place of good intentions and crossed fingers.
In an age of multiplying and diversifying fraud risk, supplier data has stopped being a back-office concern. It is both a company’s key vulnerability and its primary line of defence. Get it wrong, and the front door stays open to every new threat that comes next. Get it right, and that same door becomes a barrier the rest of the business can stand behind.
Dafydd Llewellyn is CEO at HICX
Main image courtesy of iStockPhoto.com and da-kuk
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543