Start collecting feedback in 5 minutes.Try the no-code surveys your customers actually answer — free, no credit card.
Get started free

Interview with Erika McClellan, VP of Supply-Chain Analytics, HexaEarth Equipment

Erika McClellan has spent 18 years in the trenches of industrial-equipment supply chains. Her teams have prevented millions in fraud losses for both OEMs and rental giants. She sat with us to dissect the data-driven tactics that actually move the needle for senior leaders, especially amid the persistent fraud risks facing North American construction distributors and rental platforms.


How do you frame supply-chain fraud today—what's changed in 2024?

Fraudsters have gotten smarter, but so have we. In 2019, we saw mostly invoice manipulation and false vendor setups. By Q1 2024, according to a KPMG survey, 43% of equipment distributors reported attacks using sophisticated spear-phishing, up from just 27% two years prior. That’s a 59% increase, driven by attackers targeting data gaps in procurement and logistics workflows.

The difference now is data. The teams that win are those that structure, cleanse, and analyze their spend, order, and supplier data at scale. This lets us spot not just clear fraud, but subtle anomalies too—a difference of catching a $2M ghost invoice before it hits versus after.


What's the first mistake you see when supply-chain execs "go data-driven" on fraud?

Assuming more dashboards equals better detection. I’ve watched a team deploy four overlapping fraud dashboards in 2023, each with its own data logic. Result: the detection rate barely budged—false positives tripled, and actual fraud slipped through.

The root cause? They never validated which indicators actually predicted fraud in their context. For example, we ran an A/B test: one plant flagged all POs above $500K, the other only flagged those with vendor mismatches (bank details changed, address anomalies). The first had a 21% false positive rate—the second, just 7%. More isn’t better; targeted, iterative analytics are.


What are your "top 6" tactical strategies for data-driven fraud prevention in construction equipment supply chains?

Let’s get straight to numbers and edge cases.

1. Transaction Pattern Analysis with Feedback Loops

Spotting fraud means knowing what’s "normal." We ingest three years of PO, delivery, and invoice data, then run clustering algorithms. For example: in 2022, we found that 87% of legitimate orders from a major supplier landed between $60K-$80K—anything outside triggered review.

But algorithms alone aren't enough. We use Zigpoll and SurveyMonkey to get monthly feedback from branch managers on flagged transactions. Sometimes, what looks like fraud is just a legitimate rush order. Last year, feedback led us to adjust our alert thresholds by 15%—cutting false alarms in half.

2. Supplier Risk Scoring (and Continuous Updates)

Not all vendors are equal. We score them monthly, weighing factors like time in business, payment term deviations, and cross-matches with public sanction lists. In Q2 2023, introducing dynamic scores (not static annual reviews) reduced onboarding of high-risk suppliers by 31%.

Mistake to avoid: ignoring indirect suppliers. We once missed a fraud ring because they operated through a Tier 2 supplier, not a Tier 1.

3. Segregation of Duties—Monitored by Data, Not Just Policy

Everyone touts SoD, but few use data to enforce it. We analyze system logs: who approves POs, who receives goods, who triggers payments. When one person crossed three roles in the same month, audit flagged it. In one Northeast rental business, this found a $280K siphon from just two employees.

Downside: Monitoring increases data privacy risks. We now anonymize logs and review only when anomalies arise.

4. Real-Time Anomaly Detection—But Calibrated

We use machine learning models to flag anomalies—like sudden spikes in expedited shipping requests or serial-number mismatches on remanufactured parts. In 2023, after calibrating our model with six months of historical data, we caught a $94K fraud attempt involving duplicate serials, with only 6 false alarms (down from 22 before recalibration).

Mistake: Teams that "set and forget" their models. Continuous backtesting is non-negotiable.

5. Multi-Source Data Validation

Relying on ERP data alone is dangerous. We triangulate with bank transfer records, 3PL shipment data, and even public permit filings (where legal). For a $420M heavy-equipment distributor, this surfaced $1.6M in fraudulent "phantom deliveries"—deliveries marked as complete, but with no 3PL scan or permit activity.

Caveat: Data sharing is tricky. Some 3PLs balk at real-time integration—build into contracts, or you’ll hit a wall.

6. Internal "Red Team" Fraud Simulations

Every quarter, we stage real-life fraud scenarios—fake invoices, social-engineered payment requests, dormant supplier reactivation. We measure response times and where red flags are missed. One 2023 simulation: 14 out of 54 branch admins failed to detect a rogue ACH update request. After follow-up training and process tweaks, that dropped to 2 in the next round.

Limitation: Simulation fatigue. Teams tune out if scenarios aren’t refreshed and made relevant.


What data sources do you see as most underutilized in the industry?

Three stand out:

  1. Telematics and IoT on Equipment: Most use this for asset tracking. We use usage anomalies (e.g., machine hours post-sale) to flag potential inventory fraud.
  2. Bank Confirmation APIs: Direct account ownership checks, not just wire instructions. Adoption is still under 25% in our segment, yet it stopped a $340K external diversion last January.
  3. Employee Expense Data: Cross-referencing field expenses with supplier records surfaced double billing in two regions last year—$61K recovered.

How do you balance false positives and missed fraud in high-volume environments?

You can’t aim for zero fraud without blowing up operations. It’s a trade-off.

We use a tiered review system:

  • Transactions < $20K: Only flagged if two anomalies detected
  • $20K–$200K: Manual review if one anomaly
  • >$200K: Always dual-verified, plus algorithmic scoring

After implementing this, our Houston branch’s “false stop” rate dropped from 8.7% to 3.1% (quarter-over-quarter), with no increase in missed fraud. It’s about prioritizing your limited investigator resources.


Are there approaches you advise against, even if data-driven?

Three common traps:

  1. Overfitting models to last year’s fraud patterns: Fraud evolves. A team got burned when a new scheme, not in the 2022 data, bypassed their tuned model.
  2. Relying on "black box" AI: If you can’t explain why something’s flagged, business buy-in collapses. We require model explainability before deploying.
  3. Ignoring employee feedback: We tried a dashboard-only review in 2021. Fraud went undetected for two months because local insights weren’t surfaced. Now, we use Zigpoll to get quarterly feedback on what’s being missed or misflagged.

How do you measure ROI on these strategies?

Pure fraud loss avoidance is one metric, but it doesn’t capture the operational cost. We model ROI as:

[ ROI = \frac{(\text{Fraud Losses Prevented} - \text{Cost of Controls})}{\text{Cost of Controls}} ]

For example, deploying anomaly detection and continuous scoring at one branch cost us $180K/year. In 2023, it prevented $1.43M in fraud—an ROI of 6.9x.

But we track secondary metrics: supplier onboarding cycle time, payment delays, and morale (via Zigpoll). In one case, we saw payment cycle time rise by 1.4 days. Not fatal, but worth monitoring. The trade-off: too much friction, and you lose supplier goodwill.


What do you see coming next in North American construction supply-chain fraud?

Real-time inter-company data sharing. I expect more distributors to share anonymized fraud flags (like the banking sector does with suspicious transactions) by 2025.

Downside: privacy and trust issues. But the upside is massive—one networked alert about a fraudulent supplier can save multiple firms six figures each.

Also, I expect more generative AI scams—fraudulent RFQs that mimic a genuine customer. Our 2024 pilot flagged two attempts originating from lookalike domains—something only detectable with advanced pattern analysis.


Closing Advice: What should senior teams do tomorrow?

  1. Audit your existing fraud indicators—do they actually predict fraud in your context?
  2. Run a red-team simulation this quarter.
  3. Make data sources speak to each other—particularly ERP, bank, and 3PL.
  4. Get direct feedback from local teams with Zigpoll, at minimum quarterly.
  5. Treat models as iterative experiments—not finished products.
  6. Balance controls with operational flow. Monitor unintended friction.

Don’t chase every new tool—optimize for transparency, continuous learning, and real business fit. The teams that do this outperform—not just in fraud prevention, but in speed and agility across the board.

Start collecting feedback in 5 minutes.

Try our no-code surveys that visitors actually answer.

Questions or Feedback?

We are always ready to hear from you.