Basware signing an agreement to acquire Trustpair is one of the smartest moves I have seen from an accounts payable software company in a long time.
Not because it is another AP automation deal. That is the shallow read.
The real point is much more important: the AP workflow exists because money is eventually going to leave the building. If the software owns invoice intake, matching, approval, coding, and exception handling, but stops before supplier identity, bank-account validation, and payment authorization, it is stopping at exactly the moment where the risk gets most expensive.
That is the gap Basware is moving to close.
The invoice is not the end of the workflow
Basware and Trustpair announced on August 26, 2026 that Basware signed a binding agreement to acquire Trustpair, extending its Invoice Lifecycle Management platform into payment fraud prevention. The transaction is expected to close later in 2026.
The companies framed it correctly: Basware confirms that the invoice is legitimate and approved. Trustpair confirms that the payment reaches the intended supplier.
That second sentence is the whole strategy.
Most AP software has historically been built around the invoice. Capture the invoice. Route it. Match it. Approve it. Remove duplicates. Reduce leakage. All of that matters, but it still leaves the final and most dangerous question sitting on the desk of the AP team: are we paying the right party, at the right bank account, for the right business purpose?
In the companies I have reviewed and the operators I have spoken with, that answer is still too often handled through email threads, vendor-master updates, callbacks, screenshots, manual portal checks, and someone in a back office trying to decide whether a bank-account change looks legitimate.
That is not a fraud strategy. That is hope with a workflow around it.
AP teams are carrying risk they were never equipped to carry
This is the part the software market does not like to say plainly. The actual payment risk is often left to understaffed, undertrained, tool-poor AP teams.
They are not bad operators. They are being asked to defend against a professional fraud environment with manual controls.
Forrester described the same issue in its note on the deal: genAI is changing the economics of B2B fraud by making supplier impersonation, executive impersonation, fabricated documents, and personalized business email compromise cheaper and faster. An attacker does not always need to change the invoice. They can leave the invoice alone, impersonate the supplier, change the payment details, and redirect a valid payment to the wrong account.
That is the nightmare scenario for an AP platform that only thinks in invoices.
Whether the exact loss number is higher or lower in any one company is not the point. The direction is obvious: the attack surface is getting cheaper, faster, and more automated, while the finance team is still trying to protect the payment with a person, a spreadsheet, and a policy binder.
That breaks.
Fraud prevention is not one feature
At Finexio, we were maniacal about payment fraud prevention. We ran with a single-digit basis point fraud loss rate across a decade-long history, and getting there was not the result of one magic product.
We had to buy, install, integrate, customize, and maintain multiple third-party fraud solutions. We had to build payment controls into the actual operating workflow. We had to validate suppliers, validate accounts, monitor changes, create escalation paths, decide when the machine had enough confidence, and decide when a human needed to step in.
That is the reality of fraud prevention in payments.
I am constantly asked about fraud prevention solutions, and the honest answer is that there is no single thing you can buy that does it for you. You need data sets. You need bank-account validation. You need identity signals. You need transaction context. You need history. You need rules, models, operations, exceptions, and human judgment in the loop at the right point.
The value is in making all of that feel like one product.
That is why the Trustpair acquisition matters. Trustpair validates supplier identity and bank-account ownership during onboarding, when account details change, and before payment authorization. According to Basware’s announcement, its network spans more than 2.5 billion invoices and 20 million suppliers. Forrester noted that Trustpair brings more than 10 million validated supplier-to-bank-account pairs and nine years of fraud history.
Put those two data sets together and you can catch things neither side sees alone.
Where the control belongs
The product question is not “do you have fraud prevention?” That is too broad to mean anything.
The real questions are much more specific.
First, do you validate a supplier when it is onboarded, or do you assume the vendor master is right because somebody typed it in?
Second, do you revalidate when bank details change, which is one of the obvious attack moments, or does that change move through the same approval path as an address update?
Third, do you check the payment file before funds move, or do you discover the problem after the bank has released the money?
Fourth, do you connect invoice behavior, supplier identity, and payment-destination data, or are those signals sitting in separate systems that never talk to each other?
Fifth, when the signals are unclear, do you have a trained exception workflow, or does the decision fall back to whoever happens to be working the queue?
That is the operating difference between a feature and a control stack.
None of this is turnkey. The hard work is integration, false-positive management, jurisdiction-by-jurisdiction validation coverage, exception handling, and the operating discipline to keep supplier data clean after the first implementation. But that is exactly why it becomes valuable. A workflow button is easy to copy. A trusted payment control stack is not.
The payment is where AP software becomes strategic
This is also why the move is commercially powerful.
For years, a lot of AP software companies have sold workflow efficiency: fewer touches, faster approval, better coding, cleaner matching, lower processing cost. Fine. Useful. But efficiency alone eventually commoditizes, especially when AI agents start doing more of the transactional work.
The next layer is value-added service around the transaction.
Can you prevent fraud? Can you validate the supplier? Can you tell whether the account actually belongs to the business the buyer thinks it is paying? Can you detect whether a bank-account change is normal, suspicious, or clearly fraudulent? Can you approve the payment with confidence before funds move?
Those are not back-office nice-to-haves. Those are CFO-level outcomes.
This is the frame I took away from my Mastercard years under Ajay Banga, who is now President of the World Bank Group. The payment transaction can look like a commodity if all you see is the rail. The job is to add more value around every transaction.
Basware is living that out.
It is taking what could be an invoice automation workflow and extending it toward the moment of truth: the actual payment.
The lesson for every platform
The implication for other AP, procurement, ERP, and finance platforms is direct. If your product owns the workflow but not the risk around the outcome, you are leaving the highest-value service layer open for someone else.
In AP, the outcome is not an approved invoice. The outcome is a good payment.
That means the winners over the next three to five years will not just automate tasks. They will add bespoke capabilities that can still scale: fraud prevention, supplier validation, payment optimization, and agent-driven exception handling.
Some of that will be machine-led. Some of it will require third-party data. Some of it will still require a trained human making a judgment call when the signals do not fully resolve.
That is fine. The point is not to remove every person from the loop. The point is to stop asking an AP clerk to be the whole fraud prevention stack.
Basware saw the workflow, saw the payment at the end of it, and bought the capability that makes the last mile safer.
That is exactly how AP software companies should be thinking.
Processing invoices is the entry point.
Owning the confidence behind the payment is the business.
Sources