Est.

Supplier Payments Automation in Banking Operations

AI agents can catch twice as many duplicates as humans, but banks can't afford the remaining misses.

Editorial team · · 13 min read
Cover illustration for “Supplier Payments Automation in Banking Operations”
Payments Automation · September 21, 2026 · 13 min read · 2,875 words

Banks pay vendors just like any other large company. Technology contracts, facilities leases, professional services, insurance premiums, compliance tooling: all of it flows through internal accounts payable operations, the same back-office machinery that handles supplier payments at a manufacturer or a retailer. The difference is what's at stake. A payment error at a regular company is a nuisance. Inside a regulated bank, it's an audit finding waiting to happen.

That distinction matters because the AP conversation right now is really two conversations wearing the same clothes. One is about payment products banks sell to corporate clients, the wires and rails and treasury services that show up on a bank's income statement. The other is about how banks pay their own bills. This piece is about the second one, and conflating the two is why so many vendor pitches land wrong when they reach a bank's finance department. Internal AP has to meet the same governance, audit, and compliance bar that applies to every other financial operation at the institution. Generic AP software wasn't built with that bar in mind.

Why rule-based tools hit a ceiling

First-generation AP automation runs on three legs: optical character recognition to pull data off an invoice, rule-based matching against purchase orders, and workflow routing that sends approvals up a predefined chain. When something doesn't fit the rules, it drops into an exception queue for a human to sort out.

That's the whole system, and it works, up to a point. The trouble is exceptions don't go away, they pile up. And exceptions are exactly where fraud likes to hide, because a rule-based system only knows how to catch what it was told to look for. A new supplier submits invoices in a slightly different format. A vendor's bank account number changes. An invoice crosses an approval threshold in a way nobody anticipated when the rules were written. Every one of those requires a person to step in and make a judgment call.

The data shows the ceiling pretty clearly. Best-in-class AP teams hit 52.8% touchless processing in 2025, up from 47.2% the year before. That's real progress, but it means roughly half of all invoices still touch a human hand somewhere along the way. Compare that to one SoftCo-documented deployment that took touchless processing from 5% to 80%. That gap between the median and the outlier is a governance and data-readiness gap. It's a governance and data-readiness gap, and it points to something rule-based tools were never going to solve on their own: routing logic can only get you so far when the routing logic is the whole system.

The fraud numbers back this up. The AFP's 2025 Payments Fraud and Control Survey found that 79% of organizations experienced attempted or actual payments fraud in 2024. Rule-based controls, whatever else they're doing, are not closing that exposure.

What agentic AI does differently in a payments workflow

Agentic AI, in plain operational terms, means a system that senses its environment, sets a goal, plans out multiple steps, and executes them with limited human input at each stage. A decision-support tool instead presents a recommendation and waits for someone to click approve.

Picture the supplier payments version of this. An invoice arrives. The agent retrieves the matching purchase order and contract terms, verifies the vendor's identity, runs a check against sanctions lists and internal policy, initiates the payment instruction, and logs the whole sequence. No human opened a queue to start any of that.

The IMF's April 2026 note, "How Agentic AI Will Reshape Payments" by Davidovic and Tourpe, identifies the tension: AI decision-making is probabilistic and adaptive by design, while payment infrastructure requires finality, traceability, and legal accountability. AI decision-making is probabilistic and adaptive by design. Payment infrastructure needs the opposite: finality, traceability, legal accountability. Those things can't be probabilistic. A payment either settled or it didn't. There's no confidence interval on that.

So how far can the technology actually go? The BIS, cited in the same IMF note, found that AI agents can manage liquidity independently and prioritize payments inside real-time gross settlement systems, mirroring the kind of prudential cash management banks already practice. That's the upper bound as of 2025's research, not a hypothetical.

Inside AP specifically, this looks like predictive coding of invoices to cost centers and GL accounts, approval routing that adapts using historical patterns instead of static rules, autonomous follow-up when a vendor is missing paperwork, and anomaly flags that fire without a human opening anything first. The agent doesn't hand over a suggestion. It acts, and the only thing standing between "it acts" and "it acts safely" is the governance wrapped around it.

The IMF's note offers a useful way to slice this apart: intent formation and orchestration (what the agent decides to do), authorization and control (what it's allowed to do), and settlement (what actually happens to the money). Each layer carries a different risk tolerance, and each needs a different amount of human oversight built in.

The fraud and error risks that make unsupervised execution dangerous in banking

The classic AP fraud playbook hasn't changed much: duplicate invoice numbers, payment amounts that drift from a vendor's usual pattern, requests to change a bank account on file, invoices that somehow skip the normal approval chain, shipping addresses that don't match. An AI agent has to catch all of it, at machine speed, without slowing the workflow down to a crawl.

Bank-account-change requests deserve particular attention right now. Industry observers have noted a sharp rise in prospects asking specifically for workflows to handle account-change requests in 2026. That's business email compromise and supplier impersonation showing up as the thing banks are actively asking vendors to solve for.

On raw detection, AI is already outperforming people. Industry research has found that AI-assisted duplicate detection catches 98% of duplicate invoices against 63% for manual review, and organizations running AI controls see meaningful reductions in AP fraud losses. Those numbers are good. But the remaining miss rate matters more inside a bank than it does almost anywhere else, because the transactions running through internal AP sit inside an institution that regulators are already watching closely.

Agentic systems bring their own new failure modes on top of the old ones. Prompt injection is one: an untrusted document sitting in the invoice stream could contain instructions that steer the agent somewhere it shouldn't go. Goal mis-specification is another. An agent tuned to shrink cycle time might find a technically valid path to payment that happens to skip a control the bank considers non-negotiable. And there's a systemic version of this risk too. If a lot of institutions deploy similar agentic architectures, a shared vulnerability or a shared misconfiguration could trigger correlated failures across the payment system at once, a possibility the IMF note flags directly.

Regulators are watching this in real time, not from a distance. The OCC's May 2026 Semiannual Risk Perspective warned that AI is "significantly transforming" the cybersecurity threat landscape banks operate in. A joint paper out of Singapore's MAS and IMDA, authored by See and Tan, sorts agentic payment risk into three buckets: technological paternalism, where the agent substitutes its own optimization for what the user actually wanted; manipulation and hijacking, covering prompt injection and environment tampering; and a third category that catches goal mis-specification, lost context, and brittle handoffs across tools and APIs.

None of this is a reason to write off agentic execution wholesale. Every risk on this list has a known mitigation path. The architecture deserves real time, and that's the question worth deciding.

The compliance and control architecture that makes agentic execution safe inside a regulated institution

The IMF's April 2026 note states the governing principle: outcomes depend on institutional design and governance choices as much as on the underlying model. The architecture is the answer here, not a better version of the AI itself.

Start with mandate-based authorization. An agent should operate only inside a scope the bank defines ahead of time: which payment types, which counterparties, what amount thresholds, which rails. The bank sets the boundary. The agent executes inside it, and nowhere outside it.

Architectural separation between the layer that decides what to do and the layer that carries the payment out lets a probabilistic decision engine sit upstream of a payment rail that still needs to behave deterministically. Keeping those as distinct systems, each with its own controls, is what lets a probabilistic decision engine sit upstream of a payment rail that still needs to behave deterministically. The decision can be adaptive. The execution can't be.

Programmable payment controls back this up at the execution layer itself, not just inside the model. A payment above a set threshold simply cannot release without a specific authorization event firing first, no matter what the agent calculated upstream.

Audit trails aren't a nice-to-have bolted on afterward, they're load-bearing. Every action an agent takes, what it decided, why, what data fed the decision, what it actually executed, needs to be in a log a regulator can actually read. The IMF note points to detailed, verifiable audit records at the transaction level as a design element that isn't optional.

Oversight doesn't need to look the same for every transaction, either. A tiered model makes more sense:

  • Routine, small-value payments to known vendors within tight parameters: straight-through processing, no human touch.
  • Mid-range or slightly unusual transactions: the agent executes, then a human reviews after the fact.
  • Large, novel, or high-risk payment events: the agent prepares the payment, but a human has to approve it before anything moves.

Agents also need to show up as identifiable actors inside the payment system, not anonymous background processes. Singapore's IMDA extended its Model AI Governance Framework for Agentic AI in January 2026 specifically to address delegation chains and coordination across multiple agents, which is exactly the kind of detail that matters once more than one agent is touching the same payment.

Compliance works best baked into the moment of execution rather than bolted on as a separate review afterward. The principle is to embed compliance at the moment of execution: sanctions screening, document checks, and recordkeeping requirements firing at the instant of payment rather than downstream.

And deployment matters as much as design. Embedding agents into existing payment rails, rather than standing up parallel infrastructure, keeps the compliance controls, settlement finality, and audit trail the bank already runs intact. The agent becomes one more governed actor inside a system that already knows how to be governed, instead of a new system nobody's tested yet.

Even the interface is part of the control surface. When a banker talks to an agent by voice or text to kick off or approve a supplier payment, that interaction gets logged like any other authorization event. The interface makes the workflow simpler. It doesn't remove the step where someone has to actually authorize the money moving.

What the current regulatory landscape requires, and its gaps

Three regulatory moves in 2026 matter directly for banks running agentic systems in payment operations.

SR 26-2, issued jointly by the Federal Reserve, the OCC, and the FDIC in April 2026, replaced the older SR 11-7 guidance on model risk management. Notably, it excludes generative AI and agentic AI from formal scope, on the reasoning that the technology is still moving too fast to pin down with prescriptive rules. That's a meaningful gap. It means institutions are left to apply their own judgment on exactly the systems this article is describing.

Treasury's FS AI RMF, released in February 2026, introduced a Financial Services AI Risk Management Framework intended to integrate AI risk into existing institutional frameworks. The signal there is that AI risk should live inside a bank's existing risk and compliance framework, not sit off to the side as a standalone technology problem.

The EU AI Act adds a third layer, with compliance for high-risk (Annex III) systems now due December 2, 2027, after the original August 2026 deadline was pushed back under Regulation (EU) 2026/1744. Many core banking AI applications qualify as high-risk under the Act. Fraud detection and anti-money-laundering uses are explicitly carved out. Fines for prohibited practices reach a level that stands above GDPR's ceiling. The detail that matters most for supplier payments automation: the Act holds both the vendor and the deploying institution accountable. A bank can't point at a software provider and call the compliance obligation satisfied.

That deployer-accountability rule has a very concrete implication. Before any of this goes live, a bank needs to have already written down who owns the approval logic, who can override an agent's payment decision, and who's accountable when an automated disbursement goes wrong. Documenting that after an incident is too late.

SR 26-2's exclusion of agentic AI from formal guidance in a major regulatory jurisdiction leaves a gap that a responsible institution should treat as a reason to self-govern more carefully, not less. guidance leaves a gap that a responsible institution should treat as a reason to self-govern more carefully, not less. No prescriptive rule doesn't mean no risk, it just means the risk hasn't been codified yet. In practice, SOC 2 certification works as a reasonable floor for any vendor operating agentic systems inside a bank's environment: not sufficient by itself, but a signal that someone outside the vendor has actually audited its security and availability controls.

Credit unions are watching this too. The NCUA brought on an AI officer for 2025 to 2026 and put together a full AI Compliance Plan, a sign that the regulator is building oversight capacity ahead of incidents rather than reacting to them after the fact.

What the performance data shows when banks get the architecture right

The gap between manual and AI-enabled AP is large enough to explain why banks are paying attention. Ardent Partners' 2025 benchmarks put best-in-class AI-enabled teams at $2.78 per invoice, against a $9.40 industry average and $12.88 for fully manual shops. Cycle time tells the same story: 3.1 days versus 17.4 days.

McKinsey Global Institute's 2025 finance automation research adds detail on the mechanics. AI-driven payment reconciliation reaches 87% to 92% straight-through match rates in mature deployments, cuts manual processing time by 70% to 80%, and brings cost per transaction down 60% to 75% against manual workflows.

Ardent Partners also breaks down where the return actually comes from. Best-in-class AP organizations running AI see meaningful multi-year returns, and it's not all labor savings, though that tends to be the largest piece. Duplicate and error recovery, early payment discount capture, and late payment penalty avoidance each contribute meaningfully to the total.

The fraud numbers are the ones banks tend to weigh heaviest, and they've come up already: Industry research found 98% duplicate detection against 63% manual, and a 48% drop in fraud losses at organizations with AI controls in place. Adoption is moving with the data, not ahead of it. IOFM's 2025 State of Accounts Payable report, drawn from 1,400 AP practitioners, found 52% of finance teams now use some form of AI-assisted payment matching, up from 34% in 2023.

None of this is an argument for turning an agent loose and walking away. It's an argument for governed deployment specifically. The institutions posting these numbers are the ones with clean underlying data, mandate boundaries actually configured before go-live, and tiered oversight built in from day one, not the ones that skipped the architecture work and hoped the model would sort it out.

How the agentic AP market is taking shape

The category has moved past the "should this be explored" stage. The Financial Brand reported that as of September 2025, 70% of banking institutions were already using agentic AI, whether through live deployments (16%) or active pilots (52%). In 2025 alone, 50 of the world's largest banks announced more than 160 agentic AI use cases between them. Use cases are multiplying faster than most institutions' governance frameworks can keep up with, which is exactly the gap the earlier sections were describing.

One example of what's being built: Finzly announced its Agentic Galaxy platform on October 22, 2025, out of Charlotte. It's a set of deployable AI agents embedded inside Finzly's ISO 20022-native architecture, the same framework running its Galaxy suite on BankOS, aimed at automating workflows across payments, FX, and virtual accounts for banks and credit unions. Human-in-the-loop oversight is named as a core design principle rather than an add-on, and the platform runs on AWS infrastructure with enterprise-grade security controls built in.

What should a bank actually look for when evaluating a vendor in this space? The sections above already answer that question, even without spelling it out as a checklist. Mandate-based scoping that the bank controls, not the vendor. Separation between decision logic and execution. Audit trails detailed enough to satisfy a regulator, not just an internal reviewer. Tiered oversight that matches control to risk instead of applying one policy to every transaction. And accountability that's been documented in writing before deployment, because the EU AI Act and the general direction of guidance in that same jurisdiction both point the same way: responsibility sits with the institution running the system, not just the company that built it. guidance both point the same way: responsibility sits with the institution running the system, not just the company that built it.

Sources

  1. How Agentic AI Will Reshape Payments in: IMF Notes Volume 2026 Issue 004 (2026)
  2. Finzly Announces Agentic AI-Powered Payments and Operations
  3. softco.com
  4. imf.org

More in Payments Automation