Skip to main content

IMS, ITC and Invoice Fraud: The New Compliance Math for Indian Finance Teams in 2026

By Vaibhav Rane, Founder, Cresolv One

The most expensive gap in Indian finance operations this year isn't a missing control — it's the distance between when an invoice arrives and when anyone checks whether it's clean. In 2026, two changes have made that gap far more costly, and they land on the same desk at the same time: tighter GST compliance and smarter invoice fraud.

1. IMS is mandatory, and provisional ITC is over

From 1 April 2026, the Invoice Management System (IMS) applies to regular GST-registered taxpayers who file GSTR-3B. Under IMS, you accept, reject, or keep each inbound invoice pending before it flows into your GSTR-2B — and only accepted invoices become eligible Input Tax Credit. Take no action, and an invoice is treated as accepted by default.

The bigger shift is what disappeared: the era of provisional ITC. If what your supplier reported in GSTR-1 doesn't line up with what you're claiming in GSTR-3B, the portal can hard-block the return. There's no more "claim now, reconcile later." Reconciliation has moved from a month-end clean-up task to a gating condition for filing at all.

For AP and finance teams, that has a simple, uncomfortable implication: your Input Tax Credit is now only as reliable as your invoice data is clean and matched — continuously, not at quarter-end.

2. The e-invoicing window keeps tightening

E-invoicing obligations have widened and the reporting clock has shortened. Larger taxpayers must report invoices to the Invoice Registration Portal within a fixed window (30 days for higher-turnover businesses); miss it and the invoice can be rejected for reporting, and your buyer can't claim ITC against it. An invoice without a valid IRN and QR code simply isn't valid for tax purposes.

The practical effect is that "we'll get to it" is no longer a workable posture. Late reporting isn't just an operational delay — it converts directly into lost credit and downstream disputes with the counterparties you most want to keep.

3. Invoice fraud got smarter at exactly the wrong time

While the compliance floor rose, the threat got more sophisticated. AI-generated fake invoices and vendor impersonation are increasingly convincing, and the old rule-based checks that catch exact duplicates miss the near-duplicates fraudsters now use — the same invoice resubmitted with a changed number or a tweaked amount. And this is on top of honest error: duplicate payments alone are estimated to run between 0.1% and 1.5% of total AP spend, the kind of leak that only surfaces in an audit.

Fraud and compliance feel like two different problems owned by two different teams. They're not. Both are downstream of the same root cause: invoice data that is messy, unmatched, or checked too late.

What actually helps — whatever tools you run

You don't need a specific platform to start closing this gap. You need a few non-negotiables: reconcile against GSTR-2B continuously, actioning IMS decisions as invoices arrive rather than in a month-end scramble; make three-way / GRN matching mandatory before any payment run, so exceptions surface early when they're cheap to fix; run duplicate and vendor-bank-change checks on every invoice, not a sample, because near-duplicate detection matters more than exact-match now; put a clock on IRN reporting so nothing slips past the window; and limit manual overrides while logging every one, because most duplicate leakage hides behind a well-intentioned override with no trail.

Where automation earns its place

This is exactly the work automation is built for, because it's high-volume, rule-bound, and unforgiving of lateness. A modern AP automation layer captures every invoice on arrival, matches it against the PO and GRN, screens it for duplicates and fraud signals, keeps the data e-invoicing- and IMS-ready, and posts approved invoices straight into your ERP — SAP, Oracle, Dynamics, Tally or Zoho — with an audit trail at every step.

The point isn't the technology for its own sake. It's that compliance and fraud control have quietly merged into a single requirement — clean, matched, on-time invoice data — and manual AP can no longer meet it reliably at volume.

Cresolv One's AP automation was built by people who've run finance, audit and supply-chain functions, so it's designed around the exception queue and the audit trail, not just the easy invoices.

The question worth asking your team this quarter: since April, what's tripped you up more — the IMS/ITC reconciliation, or catching duplicates and fraud before they're paid?

See what tightening this up is worth for your volumes with the ROI calculator, or check where you stand with the AP readiness assessment.