
- Membership
- Certification
- Resources
- Events
- Community
- About
- Help
In this episode, AP expert Debra Richardson joins host Grace Berube to walk through the five sessions she is presenting in 2026 on vendor management and fraud prevention — four of which are new. All five connect in some way to fraud, covering everything from hands-on workshops on vendor authentication and process design, to a specialist-focused session on daily fraud prevention, a cross-departmental look at how other teams can inadvertently undermine vendor controls, and a crowd-sourced session where attendees share their own real fraud experiences and get peer and expert feedback in real time. Debra also makes the case for networking as seriously as you take formal learning, because peer connections often turn out to be just as valuable as the sessions themselves.
WHAT YOU’LL LEARN IN THIS EPISODE

Debra Richardson
Accounts Payable Consultant | Speaker | Trainer – Debra R. Richardson, LLC
Debra is an Accounts Payable speaker, consultant, and trainer with over 20 years of experience in AP, AR, general ledger, and financial reporting for Fortune 500 companies including Verizon, General Motors, and Aramark.
For over a decade, Debra has focused on Global Vendor Maintenance. As an Senior AP Manager at a Global 15 company she lead a team of 17 that over 2,000 vendor requests per month and maintained 140k+ global vendors across seven ERPs. In her consultancy, she focuses on working with vendor teams to add authentication techniques, internal controls best practices and vendor validations to reduce the potential for fraud, compliance fines and bad vendor data in the vendor master file. She is the President of the Central Atlantic Region IOFM Chapter and the IOFM Ask the Expert for the Vendor Master File Category.
A Certified Fraud Examiner (CFE), Debra works with vendor management teams to clean their vendor data and update their vendor processes so they pay the right vendor.
She has a YouTube channel where she posts vendor master file tips every Tuesday and hosts a weekly podcast: “Putting the AP in hAPpy”.

Grace Berube
Senior Content Manager, IOFM
Grace is the Senior Content Manager at the Institute of Finance & Management (IOFM), where she has led content strategy and development since 2022. In this role, she oversees all aspects of IOFM’s digital and event-based content, ensuring it remains timely, relevant, and actionable for all financial operations professionals.
Grace manages IOFM’s robust library of site content, leads the organization’s editorial and member webinar programming, and hosts IOFM’s podcast series. She also oversees a team of subject matter experts who contribute thought leadership and educational articles. In additional, Grace curates and manages all speaker content for IOFM’s in-person and virtual events, ensuring consistency and quality across every touchpoint. With nearly three years in the role, Grace brings a deep understanding of the financial operations landscape and a passion for delivering content that empowers professionals to excel in their roles.
Grace Berube: Welcome to the IOFM podcast. This is a podcast for accounts payable and accounts receivable professionals who want to stay in the know with current AP and AR trends and ideas. We’ll be interviewing professionals in this space on a wide variety of subjects, including automation, artificial intelligence, career growth, compliance, leadership, and much more.
00:00:31
Hey, Debra. How's it going?
Debra Richardson: It is going just fine, and I will tell you, I am looking forward to something this spring. You might remember it, 'cause it came up in our podcast that we did at the spring conference last year, and it had smell.
Grace Berube: I know! That was my favorite, favorite thing. Amazing smell in this lobby at Universal. I agree. I feel like now that we've pointed it out, people will recognize it, and I am very excited—both for the warm weather and that smell.
00:01:08
Debra Richardson: And I can't believe somebody snapped a picture of my mouth at like 110% open 'cause I was laughing so hard. We were—
Grace Berube: You and me both. Those photos now of us in that podcast booth have been used in a ton of IOFM material and also Diversified's townhall meeting that we had last week. They used that photo. They loved those photos.
Debra Richardson: When I saw it on LinkedIn, I went, "Oh, why couldn't I look poised or whatever?" But it was funny.
Grace Berube: Oh, yeah, we were having a great time. And, yeah, if you're coming to IOFM Spring, which is what this episode is about, you'll probably notice the amazing smell in that lobby. Oh, my gosh. So, yeah, we're talking all about your sessions at IOFM Spring, which is coming right up. Like you said, we're going to be back at Universal, and we have a bunch of new sessions that you're presenting. So we wanted to, obviously, bring back our favorite presenters. You're one of them. But we wanted to do a big refresh on our content to make sure that 2026 was going to be fresh and new for everyone.
00:02:14
So we're going to go through session by session, just to get people excited—not giving away anything that would take away from what you're actually going to present on site, but I'd love to just chat about it, get people excited, and just to say that if you're listening to this and this is sparking your interest, there's definitely still time to sign up for the conference.
Debra Richardson: Yeah. I was looking at the sessions and I didn't realize—well, first of all, I have five, and four of the five are new. Yes. I didn't realize that all five are related in some way, right, to fraud, like in different contexts. So this is going to be good. And I will tell you, too, listeners, stay on until the last one because that is my favorite new one. I'm really excited about that one.
Grace Berube: I'm excited about that one, too. Yeah, I think, in total, we have like 78% new content at IOFM Spring, so we're really excited to bring you all of these sessions. But let's start with authentication, validation, and management on that day one of the conference.
00:03:28
Debra Richardson: Yes. Now, this is the one that is not new, but I do it at every conference. It's a three-hour workshop, so it's on the day before the regular conference starts. And what's unique about this is that—and the interest has continuously built—but what's unique about it is I go through 5 authentication techniques, 28 validation resources, internal controls and best practices. And the reason that I didn't say the number of those is that every year I update what internal controls, best practices, any validation resources, authentication techniques—I update those as needed based on what the fraudsters are choosing to do now, or maybe regulations that have changed.
00:04:30
But this year, for 2026, I added an additional internal control. So I went from 29 internal controls to 30, and then the best practices went from 17 best practices to 18 best practices. And so there are going to be two new things that I'm going to go over. It's a three-hour workshop. We walk through all of these, this framework that can help you and your team avoid fraud, regulatory finds, and just overall bad vendor data, things that you may not think about. I always have folks going away with at least one—multiple, but at least one or two things that they can apply to their vendor setup and maintenance process.
00:05:27
Grace Berube: Yeah, I think that's fantastic. This session is always so highly rated. And I love the workshop format. I feel like all the conferences, just having that longer-form learning, I think is fantastic in this session. It really just hits all the marks that we'd be looking for in a workshop, and I love that you're even bringing new things for this one that you've done a few things. So that's awesome.
Debra Richardson: Yeah. And then the next one is actually related to the authentication validation management workshop, and it's a second workshop that I think is just going to be great. So, in the first workshop, you learn all of the authentication techniques, validations, internal controls, best practices. And in the second workshop you bring all of that, and you look at—we walk through your processes, and you can kind of just plug up the gaps, right?
00:06:34
We can do them in real time. Even if you don't go to the original or to that first workshop—maybe you can't get there, maybe you didn't sign up for it—I still have all that information in the e-guide, and I walk you through it. You won't have like the pre-knowledge of it, but it will be good enough that, as we walk through, you'll be able to see where some of your gaps are. So I really use five workflows, and these are workflows that have fraud prevention built in, but you know not everyone can do everything. People have different processes, different requirements, so we talk about the things that you can add at each step.
00:07:21
The goal is that, when you leave that session, you will have a basis for how to go back to your company, go back to your team, and redesign or put those processes in place, just so you can plug up the gaps that might let in fraud, that might result in compliance fines, or just might result in overall bad vendor data. And so I'm really excited about this one.
Grace Berube: Yeah, that's going to be awesome. And do you find—and I feel like we probably know the answer—that people who will go to the morning sessions of yours will usually attend the afternoon? Do you get a lot of repeats like that?
Debra Richardson: So, this is the first time that the afternoon one is being done. But I will say, though, that there was one conference where I did the workshops. I did one in the morning and one in the afternoon, and I didn't necessarily have folks that stayed through both, but I did have folks come in and ask questions that they didn't think about until after the sessions.
Grace Berube: I love that.
00:08:47
Debra Richardson: Yes, that was really good. And that's one of the reasons why, too—and I am very open to this. I try to, when I go to the conferences, always eat lunch and breakfast in the common area and just try to sit with different folks, or let people know that if you want to sit at my table for lunch—maybe you have additional questions that you didn't think about—I just love interacting that way. I really like keeping up-to-date with what the practitioners are doing now, and so it's great for me and it's also great for them to get to talk through some of their issues.
00:09:30
So I try to do that at every conference, and I'll do it at this one, too. That's always a possibility.
Grace Berube: That's wonderful. I think that people, sometimes, if they've taken the certifications before, they're not sure where to turn next and still want that longer-form learning, so these workshops are just a really great option folks who still want a little bit more out of the conference, so these are really, really exciting. But then we do go into our main conference program, and we have a new session on internal controls. So talk to me a little bit about that.
Debra Richardson: Yeah, so this one is for AP specialists, what they can do to prevent fraud daily. And what I really like about this one is, yes, we know we have our IT teams that are there to put in whatever controls or I forget what they call 'em, but they have ways to reduce the number of fraudulent emails that make it to our inbox. But studies have shown that anywhere from 15-22% of fraudulent emails actually do make it to our inbox.
00:10:41
There are some reasons for that, but that means that you still have to have a way to deal with them. There are some reasons for that, but that means that you still have to have a way to deal with them at the user level. I know that cybersecurity awareness training is out there, but the typical cybersecurity awareness training will tell everyone, "Don't click on links or download attachments from senders you weren't expecting something from or that you don't recognize." But, heck, that's all AP gets, from invoices to documents from the vendors—or you hope they're your vendors, right—to get them set up or get updates to their vendor record.
00:11:24
So, cybersecurity awareness training doesn't always cover the things that AP has to deal with, especially right at that user level, and that's what the session is going to do. And so we'll share, or I'll share the tips that are at the user level, and I think it's actually really important to do that because when there is a fraud, right, Grace, all you hear about is the company or the vendor and what they lost.
Grace Berube: Absolutely.
Debra Richardson: But think about the user that actually didn't notice that that was a fraudulent email because it's getting harder now to notice that. If they fall victim to that and it results in a fraudulent payment, there's some things that that user may go through because they're the one that happened to get that email. Nobody ever talks about that, so we definitely need to make sure that the user has all the tools that are out there and available, and that they're up-to-date on how they can not only protect their company and their vendor, but then also protect themselves as well.
00:12:49
Grace Berube: Yeah, I think that's such a really great point. And it's for AP specialists, so another thing that we're doing at this specific conference is we have highlighted tracks for specialists and for managers. This one is obviously for the specialists, and I think that everything that you just said is perfect. We don't think about the people that actually let that come through a lot of the time. It's just at the big company level. So I think this is a really great one.
00:13:17
And another thing, at this conference, too, we're bringing back P2P certification, so we're hoping to bring a little bit more of procurement into our sessions. So talk to me about this next session that you have.
Debra Richardson: Yes. And so we know we're not all—and I think I'm using this term correctly, but we don't process things that may affect the vendor master file, like in a vacuum. We're working with other teams, like IT, procurement, and treasury, too, for some teams. So we need to talk about how adding controls, best practices, validations, authentication techniques in the vendor management function, how that may be viewed or undone by what IT, purchasing, treasury, or maybe other departments can do—most times, that [they] really know nothing about.
00:14:25
And so we'll look at those things that you need to keep top of mind when, let's say, you go back and you put these things into place that you learned at the conference, right, maybe at the workshop, either of the workshops, right? And so you go back and do that, but there may be some things you didn't even think about. So, Grace, one of the examples that I give—and I don't know if I've given it on a podcast in the past, but when I was a practitioner, I was a manager over global vendor setup and maintenance. It took me two years to realize that purchasing had access to update the contact page on the vendor record. I had no idea.
00:15:17
Grace Berube: Yeah, right.
Debra Richardson: And that page is very critical now because that's where you would go to get the information to make that confirmation call, right? And so I definitely got rid of that, but the only reason that I even figured that out was because it wasn't like in the roles, like the purchasing team had a purchasing role. But at some point—I don't even know who asked. It was definitely before my time. Someone had asked to add a function or access to the purchasing role that wasn't initially there, and that was to have access to that one screen. Now, needless to say, I absolutely took that away and we put a process in place. The reason they did it, I'm sure, is because they thought we wouldn't get to their changes quickly.
00:16:12
Yeah, and they wanted to update—I think it was at that time the fax number, because they were doing fax purchase orders, and they didn't think we would update it in enough time. So I gave them a [person] and a separate process to get that done without having to go through the regular process. But yeah, those types of things can come into play, and so you do need to make sure that you understand like what other departments are doing that may affect the vendor function.
Grace Berube: Oh, absolutely. No, I think that's fantastic advice and I think that that cross-communication is really, really important.
Debra Richardson: Yeah. And there was another one, too, and this ended up being a big project because when you set up vendor records you have to set 'em up with the payment terms, either the default payment terms or if, by chance, you get a contract, with the contracted payment terms.
00:17:14
But what we found out—and this was because we had the vendors barking at us when they weren't paid on time—is that when the contracts are updated we never got those updated payment terms because there was no mechanism that had been set up that would notify us of those contract changes. So that ended up being a big project because it was not only that; it was also the item cost, too. So that ended up being a big process. And so, yes, those types of things, right, you have to make sure you understand that effect the vendor master file and maybe even vendor relations as well, because you don't want to call them up when they haven't been paid on time after negotiating a contract.
00:18:12
Yeah, and treasury, too, because sometimes treasury can have a separate platform that they enter banking in, so how do you keep those synced with the accounting system or ERP when that is the system of record or source of truth? We'll go over all of those things, too, and maybe even more. We'll get folks to talk about some things that they may have seen or done. And that just kind of underlines all the sessions, right? I bring this information, get you to some things that you need to think about, but I learn a lot from folks, too. Those of you thinking about coming to that session, bring your issues that you've seen with other departments that affect the vendor master file or the vendor function, and we'll talk about that, too.
00:19:07
Grace Berube: Totally, and I feel like it's really the chance to connect with your peers, to give your own experience, and I learn so much, too. I try to sit in on as many I can also and just get new content ideas. The questions that people ask, the stories that they share, really do inform conversations that I have with Debra later in the year, and our other subject matter experts. So it's really important. Speaking of—this really ties in perfectly to the last session that you were really excited about.
Debra Richardson: Great segue!
00:19:36
Grace Berube: Right? I love that segue. So talk to me a little bit about this one and how important it's going to be for folks to be sharing their own examples here.
Debra Richardson: Oh, my gosh. This one is called "The AP Fraud Bootcamp: Crowdsourced Cases and Expert Solutions," and I love it. Nothing wrong with this, right? In the past, it was really great. I would come. I would do these fraud sessions, and actually look at the scam alerts that came out, the press releases about victims of fraud. I shared examples of those that happened in the last 90 days, and then I would talk about how they could be avoided. Nothing wrong with that, but what you miss is, when you have fraud in the press release, in a scam alert, you don't hear about all the details. You'll hear, "Well, you know, someone got an email that pretended to be the vendor." Well, we know that that happens, but were there any other nuances to it? What did the email say? What was the subject line?" That type of thing.
00:20:48
And then they'll say, well, they put processes in place to make sure it doesn't happen in the future. Well, what processes did you put in place? And I kind of get it because you don't want to alert all the other fraudsters out there of what you're doing now, but, in this setting, we can not only share exactly how the fraud happened or attempted fraud happened. What did that email look like? What did that phone call look like or sound like? What did they say? And then hear about what they put into place in order to mitigate that risk. We'll talk about some other things you could go back and put in place as well, but we'll hear from all different sides, so I love the fact that I'm not bringing this information. This information is coming from everyone's peers about what they're actually experiencing up to that day.
00:21:55
Grace Berube: Yeah. And I think this one, again, is going to be really important. I'm going to love to sit in on this one and hear what your actual questions are, what you're going through. And again, it will really dictate what content we look at to produce for the rest of the year and for other sessions. We're still figuring out how we're going to collect these fraud examples, so be sure to look out for any emails or anything within your mobile app. It might be onsite at the conference or it might be a couple weeks before, but we're definitely going to make sure that your voice is heard.
Debra Richardson: Yeah. Speaking of voices being heard, I'm not that creative, so I didn't come up with this, but I absolutely love it. In all of my sessions, somehow we always get back to fraud anyway because that's what they're dealing with. This is the group that gets the most of it. But I hear attendees of the sessions, of the workshops. They just want to say what happened to them because they want to know: Did anyone else experience it? And if you did, what did you do? This is what we did. Is there anything else that we should've done?
00:23:07
And so I think this is a great way to, like you said, get your voice heard, which is what I think a lot of the attendees that have experienced either attempted fraud or successful fraud really want to gain. Get your voice heard and then get some feedback, and we're going to do all of that in this session.
Grace Berube: I love that. I'm probably, like you said, most excited about this one, but all five of these are going to be fantastic. We're a few short weeks away at this point, so we're really looking forward to having you Debra. Any last thoughts on anything IOFM Spring related?
00:23:48
Debra Richardson: So, the smell—you can't—
Grace Berube: Yeah, I was going to say, it's—
Debra Richardson: You've got to put that in there. But, yeah, I would just say: Come energized. Come with your questions. If you don't want to sit with me at the table and talk to things, fine, but sit with your peers, network. Find your peers that have the same accounting system or ERP that you have, and see what they're doing. Find your peers that are in your same industry, right?
00:24:27
I used to come to these conferences when I was a practitioner, and that was my goal. Sessions were great, but the sessions were how I found the folks that had the same issues, the same industry, same accounting system or ERP in some cases, 'cause that's how you do some of your roundtables. I came there to learn, both from the sessions and also from my peers. So make sure you're never eating alone. I would love to eat with you, but I am sure you can sit at a table and meet new folks, or meet new folks and then sit together and eat. That would be my goal. Actually, that is going to be my goal. Even though I'm a trainer, I still love meeting folks, and I love hearing about their vendor master file journey.
Grace Berube: Having those connections or making those connections on site can lead to friendships and professional relationships that last throughout the year. If you're only coming to one or even two of the conferences, if you have questions throughout the year, tap into those people on LinkedIn or text them, email, whatever. I feel like forming those relationships on site are really, really important, so great advice.
00:25:55
Thank you so much, Debra. We'll see you, like I said, in a few short weeks, and we'll look forward to talking to you again soon.
Debra Richardson: All right, thanks, Grace. I am looking forward to it.
Grace Berube: Me, too.
Thank you so much for listening to the IOFM podcast. Remember to head on over to the Member Forum to discuss today's episode and provide ideas for our next one. And to stay up-to-date on IOFM's current events, both in-person and virtually, head on over to IOFM.com.
Continuing Education Credits available:
Receive 1 CEU per hour of listening time towards IOFM programs:

Receive 1 CEU per hour of listening time towards maintaining any AP and P2P related program through IOFM! These programs are designed to establish standards for the profession and recognize accounts payable and procure-to-pay professionals who, by possessing related work experience and passing a comprehensive exam, have met stringent requirements for mastering the financial operations body of knowledge.
Continuing Education Credits available:
Receive 1 CEU per hour of listening time towards IOFM programs:

Receive 1 CEU per hour of listening time towards maintaining any AP and P2P related program through IOFM! These programs are designed to establish standards for the profession and recognize accounts payable and procure-to-pay professionals who, by possessing related work experience and passing a comprehensive exam, have met stringent requirements for mastering the financial operations body of knowledge.
What are you waiting for?