Questions

Payment fraud questions, answered

Answers to the questions finance teams ask about payment fraud, verification and payment controls, each linked to the research behind it.

Wire fraud

Why is wire fraud so hard to recover from?

Wires settle quickly and are generally final once the receiving bank releases funds, so prevention before sending matters far more than recovery afterward.

From: Wire fraud topic

What is the most common way businesses are tricked into a fraudulent wire?

A changed payment instruction, usually delivered by a compromised or spoofed email that appears to come from a known vendor or executive.

From: Wire fraud topic

How does executive impersonation fraud usually reach AP?

It often arrives as an email, text, collaboration message, or call that appears to come from a senior leader or someone acting for that leader. The request pushes urgency, secrecy, or both.

From: The boss made the wire feel late before it was due

Why can dual approval miss executive impersonation fraud?

Dual approval can miss the fraud when both approvers accept the same false premise. A second signature helps only if someone independently verifies the payment instruction through a known channel.

From: The boss made the wire feel late before it was due

What should AP verify before releasing an urgent executive payment?

AP should verify the source of the instruction, the beneficiary, the bank account, any account change, the reason for the deadline, and the approval trail using records that are independent of the request.

From: The boss made the wire feel late before it was due

What should CFOs tell staff about urgent executive requests?

CFOs should state plainly that staff are expected to pause and verify executive payment requests that trigger risk conditions. A delayed legitimate payment is easier to defend than a rushed fraudulent one.

From: The boss made the wire feel late before it was due

What is payroll diversion fraud?

Payroll diversion fraud occurs when wages are redirected to an account the intended worker does not control. In payroll operations, it often appears as a direct deposit change or routing update shortly before release.

From: The direct deposit change that should stop the batch

Why are last minute routing changes risky?

They arrive when payroll teams are under pressure to protect the pay date. That pressure can shorten verification, especially when the request appears to come from a known employee, client administrator, or established channel.

From: The direct deposit change that should stop the batch

Does identity verification stop payroll diversion fraud?

It helps, but it is not enough on its own. A valid login or known email thread does not always prove that the destination bank account belongs to the intended payee.

From: The direct deposit change that should stop the batch

Where should a payroll provider place the control?

The control should sit before release, where a new or changed bank account is allowed into a funded batch. The approver should see the change history, risk signals, and verification evidence before the file moves.

From: The direct deposit change that should stop the batch

What is invoice manipulation fraud?

Invoice manipulation fraud is a payment redirection scheme where a genuine or plausible invoice is altered so payment goes to an account controlled by the attacker.

From: You approved the invoice. The account field did the damage.

Why can invoice manipulation pass normal AP review?

It can pass because the vendor, amount, purchase order, and approval path may appear valid. The corrupted element is often the bank account or remittance instruction.

From: You approved the invoice. The account field did the damage.

Does invoice approval verify bank ownership?

No. Invoice approval confirms the business obligation. Bank ownership needs a separate verification step using trusted contact data or other independent evidence.

From: You approved the invoice. The account field did the damage.

What should trigger added review?

Any new or changed payment detail should trigger review, including account number, routing number, beneficiary name, remittance contact, or payment country.

From: You approved the invoice. The account field did the damage.

Is business email compromise only an email security issue?

No. Email is often the entry point, but the finance loss happens when a fraudulent instruction is accepted and used for payment.

From: The inbox was the pretext, not the control failure

Why can dual approval fail in business email compromise cases?

Dual approval can fail when both approvers review the same unverified payment details. A second approval does not prove bank-account ownership.

From: The inbox was the pretext, not the control failure

Where should controllers place the strongest control?

The strongest control belongs at the payment-instruction change point, before a new bank account enters the vendor record or a wire template.

From: The inbox was the pretext, not the control failure

What does Coffr cover?

Coffr covers the structured exchange and verification of payment instructions before payment. It does not process payments, monitor email, or recover funds after release.

From: The inbox was the pretext, not the control failure

Why are title companies exposed to real estate wire fraud?

They sit near large funds, tight deadlines and several outside parties. A fraudster who alters payment instructions can redirect closing money before the error is visible.

From: The wire looked right until the deed recorded

Is a phone callback enough to verify wiring instructions?

Only if the number comes from a trusted record created outside the suspect message. Calling a number inside the email that requested the change can confirm the fraudster's own instruction.

From: The wire looked right until the deed recorded

Does dual approval prevent a fraudulent closing wire?

Not by itself. If both approvers review the same compromised instruction package, the second approval can document the wrong evidence.

From: The wire looked right until the deed recorded

Where should the control sit in the closing workflow?

The control should sit before payment release, when wiring instructions are received, changed, verified and approved. Waiting until the wire desk has a complete package may be too late.

From: The wire looked right until the deed recorded

Which payment controls should new cyber spend improve first?

Start with controls that hold money before settlement. The priority paths are vendor bank account changes, executive payment instructions, help desk resets tied to payment authority, and payment file release. Each path needs a finance owner, a clear hold point, and required evidence that is retained before the bank receives the instruction.

From: Spend the fraud budget where it can still stop a payment, not after it's too late

What does a board security program miss in a BEC loss scenario?

A board program may fund detection, patching, backups, or security operations without changing the payment decision. BEC losses often turn on whether finance accepted a changed beneficiary, urgent instruction, reset request, or batch release. If the program cannot name that decision, it may be valid cyber work but weak fraud control.

From: Spend the fraud budget where it can still stop a payment, not after it's too late

Who should own the hold on a suspicious payment change?

Finance should own the hold because finance owns the payment consequence. Security should provide signals such as risky login behavior, device changes, malware findings, or identity events. The AP manager, treasury lead, or finance application owner then needs authority to stop the vendor change, payment instruction, or file release.

From: Spend the fraud budget where it can still stop a payment, not after it's too late

Are clean logs enough evidence to release a payment file?

Clean logs are useful but incomplete. They can show that an approved user acted inside the system, but they do not prove the instruction was genuine or the beneficiary was correct. Payment release evidence should include batch details, approver identity, beneficiary support, and the business purpose before transmission.

From: Spend the fraud budget where it can still stop a payment, not after it's too late

What should finance collect before calling the bank about a fraud wire?

Finance should collect the payment initiation time, release time, settlement reference, amount, originator account, beneficiary name, beneficiary account, receiving bank, and any intermediary bank details. The packet should also include the approval trail, the changed payment instruction, the source message, and the moment the company discovered the fraud.

From: Your BEC wire recovery evidence has a deadline. Ensure you meet it.

Why do mailbox artifacts matter if the wire details are already known?

Mailbox artifacts help prove whether the payment instruction came from a compromised account, a lookalike domain, a forwarding rule, or a deleted message. Banks may need transaction facts, but law enforcement and insurers often need the surrounding evidence that explains why the company accepted the instruction and which control failed.

From: Your BEC wire recovery evidence has a deadline. Ensure you meet it.

Who should own the first-hour fraud payment file inside the company?

Ownership should be assigned before an incident. Treasury should own payment facts, AP or vendor management should own vendor-change records, IT should preserve mailbox and login artifacts, and the controller should own the approval chronology. Legal or risk should maintain the evidence hold and the external contact log.

From: Your BEC wire recovery evidence has a deadline. Ensure you meet it.

How should a company handle a recovery offer after it has paid?

A recovery offer should be treated as a new incident contact. The company should preserve the message, log the caller or sender identity, verify the party through a known bank, insurer, counsel, or law enforcement channel, and block any second payment unless it follows the same approval and verification controls as any other disbursement.

From: Your BEC wire recovery evidence has a deadline. Ensure you meet it.

Who should be allowed to speak after a company reports a wire loss?

The company should name specific incident contacts before any outside communication begins. Treasury or the controller should handle the bank. Counsel should handle law enforcement and recovery firms. Risk or claims should handle insurers. The vendor owner should handle vendor contact. AP should not accept new instructions from inbound callers during the recovery period.

From: After a BEC wire loss, you risk a second incident while under investigation

Can we trust a law enforcement case number without a callback?

No. A case number, badge line, agency title, or government email format is not enough. Counsel should initiate contact through a known agency switchboard, prior agent contact, or documented reporting channel. The file should capture the office, matter number, person contacted, requested records, and why the company released or withheld information.

From: After a BEC wire loss, you risk a second incident while under investigation

What proof belongs in the file before paying a recovery firm?

The file should show who approved the engagement, how the firm was selected, how its identity was verified, what it is authorized to do, and how its payment details were confirmed through an independent channel. A retainer or emergency fee should not move because the firm knows the loss details or claims to work with an agency.

From: After a BEC wire loss, you risk a second incident while under investigation

Why is the week after the BEC loss a separate control problem?

The first fraud creates urgency and a real case file. That makes later callers sound more credible, especially if they cite the loss, the bank recall, an insurer, or law enforcement. Standard vendor change controls may not apply to recovery activity unless the company assigns owners and proof rules before the incident.

From: After a BEC wire loss, you risk a second incident while under investigation

What should we check first when a capital call notice arrives?

Check the source before checking the amount. The sender, domain, portal, administrator, and contact method should match a controlled source registry. Then match the call to the subscription or fund documents and compare the beneficiary account to the approved record. If the account is new, hold the wire until a preapproved contact confirms it.

From: The capital call was right. The bank account was not. Now what?

How should we verify a payoff letter before releasing the wire?

Verify the payoff letter against the credit agreement, agency provisions, assignment records, and internal approval file. The letter can support the amount and date, but it should not be the only source for wire instructions. Treasury should call a preapproved contact using the registry number and confirm the beneficiary account before release.

From: The capital call was right. The bank account was not. Now what?

Who should own the source registry for private credit payments?

Ownership should sit with legal, credit operations, or fund operations, with treasury using the record for release. The registry should contain approved agents, administrators, lender contacts, borrower contacts, domains, portals, phone numbers, and allowed notice channels. Edits should require approval and create a record that treasury can rely on.

From: The capital call was right. The bank account was not. Now what?

When should a lender bank account change be put on hold?

A lender bank account change should be held whenever it appears near a payment deadline, arrives through a new sender, changes the beneficiary, or comes with a new agent or administrator. The hold should stay in place until a registry contact confirms the change and the governing documents support that party's authority to redirect funds.

From: The capital call was right. The bank account was not. Now what?

Why is business email compromise hard for accounts payable teams to detect?

Business email compromise often looks like a routine vendor request, not a dramatic breach. A vendor the company has paid for years may appear to ask finance to update bank details. The team updates the record, the next invoice is paid on time, and the money lands in an account controlled by the attacker.

From: You approved the PDF. Nobody verified the bank account

How do attackers use vendor bank detail changes in BEC fraud?

A typical attack starts with a real vendor relationship found through sources such as a LinkedIn post, press release, or leaked email thread. The attacker may register a look alike domain or compromise the vendor mailbox. They wait for a real invoice, then request payment redirection because of a claimed banking change.

From: You approved the PDF. Nobody verified the bank account

Why are PDFs and screenshots of bank details risky for vendor payments?

Bank details often move through email as a PDF attachment, screenshot, or plain text. These formats do not prove who created them or whether they were altered. PDFs of voided checks can be edited, screenshots can be reconstructed, and account and routing numbers in plain text have no provenance, signature, or verification.

From: You approved the PDF. Nobody verified the bank account

What is the strongest control against BEC payment redirection?

Callback verification remains the single most effective control. The company should call the vendor at a known number, not the number in the email signature. However, this process does not scale well for companies paying dozens of vendors each week, and a callback can be intercepted if the vendor phone system is compromised.

From: You approved the PDF. Nobody verified the bank account

What process change reduces BEC risk in vendor bank account updates?

The structural fix is to remove bank details from email entirely. If routing and account numbers never travel through an inbox, an attachment cannot be edited and a message cannot be spoofed. The process requires a shared, verifiable channel with cryptographic proof of who sent what and when.

From: You approved the PDF. Nobody verified the bank account

Payments infrastructure

Do payment rails verify who owns the receiving account?

Most rails route funds by account and routing number, so confirming that the account belongs to the intended recipient is usually the sender's responsibility.

From: Payments infrastructure topic

Is account takeover the same as payment instruction fraud?

No. Account takeover concerns access to an account, mailbox, or application. Payment instruction fraud concerns whether a bank account, beneficiary, or payment change should be trusted before funds are released.

From: Your mailbox control did not verify the payment instruction

Can payment fraud happen without account takeover?

Yes. A fraudulent instruction can arrive through spoofed email, altered invoices, compromised vendor communications, phone pretexts, or documents that look routine without the attacker controlling an internal mailbox.

From: Your mailbox control did not verify the payment instruction

Do MFA and email security stop payment instruction fraud?

They reduce important access risks, but they do not verify bank-account ownership or counterparty trust. Payment instruction controls need to sit inside the finance workflow before approval and release.

From: Your mailbox control did not verify the payment instruction

Where should an organization start?

Start by mapping the payment workflow. Identify where instructions arrive, where bank details change, who approves them, what evidence is checked, and whether verification happens before release.

From: Your mailbox control did not verify the payment instruction

Why does verified identity not equal a trusted payment?

Identity verification can show who entered or controls a relationship, but payment release asks a later question. A genuine customer, known business or authenticated administrator can still add a wrong bank account, change a beneficiary or submit a payout file. The platform needs evidence that the destination and authority are right for that payment at that point in time.

From: The user was verified. The payout instruction was not.

Where does fintech payment fraud usually enter the workflow?

Fintech payment fraud often enters when a new or changed payment instruction is accepted through a normal channel. That can include settlement account updates, beneficiary creation, payroll files, API calls, CSV uploads, ERP integrations, support tickets, webhooks or internal operations queues. The credentials, customer ID and format may be valid while the payment destination is wrong.

From: The user was verified. The payout instruction was not.

What control should a fintech review first?

A fintech should first find the exact step where its platform turns a payment instruction into an accepted instruction. That is the point where a new bank account, changed beneficiary, payout file or settlement update becomes eligible for release. If that step trusts the known user more than it tests the destination, the control is sitting too early.

From: The user was verified. The payout instruction was not.

Which payment instruction changes should fintechs slow down?

Fintechs should slow down changes that alter financial control, not every ordinary profile edit. The higher risk changes include bank accounts, routing details, payout schedules, remittance contacts, beneficiary names, wallet addresses, authorized administrators, ownership records, phone numbers, email addresses, MFA devices, API keys and business addresses. A sequence of changes can matter more than any single action.

From: The user was verified. The payout instruction was not.

What controls help verify a new payout account or beneficiary before release?

Controls should test the instruction before funds move by binding identity, account ownership, authority and retained evidence. Examples include bank account ownership checks, KYB refresh at material change, instruction risk signals, step up approval, callbacks using contact paths already on file, segregation of duties and records of who changed, checked and approved the instruction.

From: The user was verified. The payout instruction was not.

Where does payroll fraud usually enter the workflow?

A common entry point is the bank-account change. The request may arrive through email, a portal, a branch office, a PDF form, or a spreadsheet, then become trusted payroll data before the ACH file is created.

From: You approved the payroll batch. Nobody verified the bank account.

Why are staffing companies exposed?

Staffing companies handle frequent onboarding, worker changes, branch activity, and pay deadlines. Those conditions create many legitimate reasons for new or changed payment instructions.

From: You approved the payroll batch. Nobody verified the bank account.

Can payroll batch approval stop direct deposit diversion?

It can help, but it may be too late. If the fraudulent account is already stored as an accepted payroll record, the batch can appear normal during release review.

From: You approved the payroll batch. Nobody verified the bank account.

How does W-2 theft connect to payroll fraud?

W-2 data gives criminals personal details that can support tax fraud, identity fraud, and more convincing impersonation when they later seek payroll changes.

From: You approved the payroll batch. Nobody verified the bank account.

Who can call the bank when online banking is suspect?

Only people named in the treasury escalation roster should contact the bank during a suspected payment fraud event. The roster should include primary and backup company officers, known bank contacts, verified phone numbers, and limits on what each person may request. A hold request can have broader authority than a release instruction.

From: Bank branch fraud escalation controls need a name, not a lobby

Can a branch officer release a held business payment?

A branch officer should not release a held business payment unless the company and bank already assigned that authority in writing. The safer procedure requires bank-side confirmation from a named officer and company-side approval from treasury or the controller. The evidence file should show why the hold was placed and what supported release.

From: Bank branch fraud escalation controls need a name, not a lobby

What belongs in the evidence file after a payment exception?

The file should contain the trigger, payment details, company approver, bank contact, verified callback method, hold or recall instruction, and release decision if funds later move. It should also preserve emails, phone logs, ticket numbers, screenshots, vendor master records, invoices, and bank correspondence connected to the event.

From: Bank branch fraud escalation controls need a name, not a lobby

What should after-hours recall authority allow?

After-hours recall authority should let named officers request a hold or recall support through preapproved bank numbers. It should not let one person release funds without stronger review. The next business day should reconcile the bank record, the company payment file, and any messages received during the incident.

From: Bank branch fraud escalation controls need a name, not a lobby

Who owns proof of a loyalty profile edit before a refund?

Controllership should own the evidence standard, even when the data sits elsewhere. CRM or commerce operations may hold the profile log, fraud may hold device history, and treasury may own cash release. The review file should show actor, device, old value, new value, approval path, and how the edit affected the later credit.

From: Your loyalty payment fraud control looked for the wrong file. Now what?

What should controllers sample when rewards affect credits?

Start with credits, refunds, goodwill awards, stored value releases, and returns that had a customer account change before the transaction. The sample should include manual reward awards, tier changes, account recovery events, device binding changes, tender switches, and refund destination changes. Amount based samples alone may miss the earlier manipulation.

From: Your loyalty payment fraud control looked for the wrong file. Now what?

Why are processor reports weak evidence for this risk?

Processor reports show authorization, settlement, fees, and exceptions inside the payment rail. They may not show who changed the customer profile, merged an account, added a device, altered reward eligibility, or changed the refund route before the transaction. For this risk, the decisive evidence often sits in commerce, identity, and CRM logs.

From: Your loyalty payment fraud control looked for the wrong file. Now what?

How does bundled financing change the control test?

Bundled financing can put identity, credit terms, payment choice, and merchant acceptance inside one checkout path. The control test should confirm that the customer was eligible for the selected financing or refund route before the transaction completed. Finance should match checkout choices to account history, device signals, approval rules, and later settlement.

From: Your loyalty payment fraud control looked for the wrong file. Now what?

Who owns the veto when a hub selects a different rail?

The final release owner should hold the decisive veto, with earlier gates at payee setup, payee change, approval, routing, and exception review. A rail screening team may stop a transaction, but it should not be the only authority gate if it cannot see the original instruction, payee evidence, and approval record.

From: Whoever gives the final "go" to release a payment needs to be approving the payment method that's actually being used

Does payee verification solve the routing fraud issue?

No. Payee verification may support the payee record, but it does not prove that the current instruction, route choice, exception clearance, and release were authorized. The control problem is broader than identity matching because a hub can change how the same obligation is sent.

From: Whoever gives the final "go" to release a payment needs to be approving the payment method that's actually being used

What evidence should follow a payment into a new rail?

The payment should carry a compact authority packet with the instruction identifier, payee identifier, approved settlement instrument, approval chain, selected route, route change reason, screening result, exception case reference, and final release identity. The point is not more attachments. It is enough evidence for the release owner to stop the payment.

From: Whoever gives the final "go" to release a payment needs to be approving the payment method that's actually being used

When should a routed payment go back for approval?

A payment should return for approval when routing changes the settlement instrument, beneficiary data, currency handling, finality profile, exception outcome, or release authority. If an earlier approval was based on a different route or different payee detail, that approval may no longer answer the release question.

From: Whoever gives the final "go" to release a payment needs to be approving the payment method that's actually being used

Who is the customer if an agent initiates the payment?

The customer is the party named in the contract, invoice, purchase order, or customer master record. The agent is a messenger that may execute a payment instruction. It should not become the buyer, the approver, or the party allowed to change invoice terms unless a separate legal agreement says so.

From: AI agent payment controls should require a close file that proves the named customer authorized the specific invoice before release

Can instant USDC settlement close the receivable by itself?

No. Settlement shows that value reached the seller, but AR still needs evidence that the customer intended to pay that invoice. The file should connect the receipt to the customer, invoice number, approved amount, payment credential, screening result, and refund path before goods or services are released.

From: AI agent payment controls should require a close file that proves the named customer authorized the specific invoice before release

What should AR retain before releasing goods or services?

AR should retain the invoice match, customer authority record, payment reference, buyer details captured at checkout, ownership status for the paying account or wallet, screening result, and refund instructions. The record should show that the customer authorized payment on the same terms AR is about to close.

From: AI agent payment controls should require a close file that proves the named customer authorized the specific invoice before release

How should refunds work when a wallet paid the invoice?

Treasury should define the default refund route before accepting the payment, preferably back to the original wallet or account when allowed. If that route fails, the file should name the exception approver, the alternate destination, the customer authorization for that destination, and any screening repeated before funds move.

From: AI agent payment controls should require a close file that proves the named customer authorized the specific invoice before release

Is ACH fraud more common than wire fraud?

Although many finance teams view wires as riskier because they are irrevocable, fast, and often large, the AFP annual Payments Fraud & Control Survey has found for several years that ACH is the most frequently targeted payment rail. ACH can look safer because it is routine, smaller, and reversible, but those assumptions can cause weaker verification.

From: The routine ACH file is carrying more fraud than the wire

Why can ACH account details be more exposed than wire instructions?

ACH account details are stored in more systems, exposed to more employees, and shared through more channels than wire instructions. Because ACH is used for routine payments, companies may treat the information as lower risk. That broader exposure makes the exchange of routing and account numbers before the first payment a central fraud risk.

From: The routine ACH file is carrying more fraud than the wire

How can ACH batch processing hide fraud?

ACH batch processing can allow fraudulent entries to be buried inside a file containing hundreds of legitimate transactions. A finance team reviewing the file may see a routine payment process rather than a single suspicious entry. That makes verification of the recipient's routing and account number important before the first ACH payment is sent.

From: The routine ACH file is carrying more fraud than the wire

Does ACH reversibility make it safe enough without verification?

ACH reversibility can create a false sense of safety. Companies often skip verification on ACH payments that they would perform for a wire, even though both rails depend on the sender having the correct recipient routing and account number. If those details are exchanged over email without verification, ACH and wire payments are both exposed.

From: The routine ACH file is carrying more fraud than the wire

What is the main fraud problem with ACH and wire payments?

The payment rail itself is not the main problem. Both wire and ACH payments rely on the sender knowing the correct routing and account number for the recipient. The key risk is how those account details are exchanged before the first payment. Email exchange leaves both rails exposed, while verified exchange makes both rails equally safe.

From: The routine ACH file is carrying more fraud than the wire

How long is the corporate ACH dispute window?

Companies often misunderstand the corporate ACH dispute window. The 60-day dispute window for corporate ACH is far shorter than most companies realize, even though ACH is commonly viewed as reversible and safer than wire. That misunderstanding matters because companies often skip verification on ACH payments that they would perform for a wire payment.

From: The routine ACH file is carrying more fraud than the wire

Architecture

Why treat payment security as architecture rather than training?

Controls that assume people can be deceived keep working when someone is deceived, while training alone depends on every person catching every attempt.

From: Architecture topic

What evidence belongs in the file after an AI clear?

Save the source data used by the tool, the model version, the reason for clearance, the reviewer or queue disposition, the final payment status, and any callback or investigation evidence. The file should show what was known at the time of the decision, not what the team reconstructed after a loss or dispute.

From: The AI AML audit trail is what survives the override

Who owns the record when a reviewer overrides the tool?

Ownership should be assigned before the first exception occurs. AML operations or compliance should own the disposition rationale, while treasury or payment operations should own the payment status. If AP or vendor management supplied callback evidence, that evidence should be attached to the same case record or linked under a governed retention rule.

From: The AI AML audit trail is what survives the override

How should treasury bind bank portal and ERP evidence?

Treasury should assign one repository as the binding case record, then attach exports or snapshots from the bank portal, ERP, AML tool, ticketing system, and vendor evidence. The case ID should appear in each system. The retention clock should not start until the final payment status and evidence manifest are present.

From: The AI AML audit trail is what survives the override

When should the retention clock start on the case file?

The retention clock should start only after the decision packet is complete. That means the file contains the model event, reviewer action, supporting evidence, and final payment status. Starting retention at alert creation can leave the company with a preserved alert but no defensible record of the release, recall, cancellation, or reissue.

From: The AI AML audit trail is what survives the override

Can bank scam warnings validate a changed supplier account?

No. A bank warning can flag an unusual payment, new beneficiary or risky session, but it cannot prove that the supplier requested the changed account. That proof has to come from the company's own records: the original instruction, verification through a trusted channel, vendor master approval and a release check against the payment file.

From: Even if a bank adds scam warnings, biometrics and extra friction, corporate BEC payment controls still have to prove the changed payee before release.

Who should own proof of a beneficiary instruction change?

AP should own the vendor instruction record because AP receives and maintains the supplier data. Treasury should own the release check because it controls settlement risk. The same person should not receive the change, enter the new account and provide the only evidence that the payment is safe to release.

From: Even if a bank adds scam warnings, biometrics and extra friction, corporate BEC payment controls still have to prove the changed payee before release.

What record should AP keep before releasing a changed payee?

AP should keep the original change request, the verification method, the trusted contact used, the name of the verifier, the vendor master approval and the invoice or mandate affected. The record should sit outside the payment approval screen so a reviewer can test the source of the instruction, not only the payment details.

From: Even if a bank adds scam warnings, biometrics and extra friction, corporate BEC payment controls still have to prove the changed payee before release.

How do faster account-to-account rails change the control?

Faster rails reduce the time available to question, recall or reverse a questionable payment after release. That makes instruction provenance a pre-release control. Before a changed payee reaches the bank, AP and treasury need evidence that the new destination came from the real supplier and applies to the obligation being paid.

From: Even if a bank adds scam warnings, biometrics and extra friction, corporate BEC payment controls still have to prove the changed payee before release.

What part of the business payment process is least protected by banks and ERPs?

The least protected part is the payment instruction. Banks and ERPs protect the payment rails, but the instruction between two parties remains exposed. This is the trust and verification layer, where parties exchange bank details and agree that the account on file is real. Today, that step often happens through email attachments, PDF voided checks, and plain-text account numbers in invoices.

From: You secured the rail. The instruction stayed open.

What is the trust and verification layer in business payments?

The trust and verification layer is the point when two parties exchange bank details and agree that the account on file is real. It sits between origination and the later payment process. According to the article, this layer is still handled through documents and messages that do not provide cryptographic proof of origin or reliable verification after the fact.

From: You secured the rail. The instruction stayed open.

Why are emailed bank details and PDF voided checks a weak payment control?

Emailed bank details, PDF voided checks, and plain-text account numbers pasted into invoices do not carry cryptographic proof of origin. They also cannot be verified after the fact. Origination systems then assume the vendor record is correct, and bank rails assume the routing and account numbers are correct, leaving the instruction itself without authoritative verification.

From: You secured the rail. The instruction stayed open.

What would a payments trust layer verify before execution?

A payments trust layer would sit inline between origination and execution. It would validate counterparty identity, cryptographically bind account details to that identity, and create an immutable audit trail whenever an instruction is created, changed, or verified. The article states that this would add provenance to the instruction without changing the rails or ERPs.

From: You secured the rail. The instruction stayed open.

Why does securing the payment rail not secure the payment instruction?

Securing the rail does not secure the instruction because rails assume the routing and account numbers are correct. Origination systems also assume the vendor record is correct. The gap is the moment when bank details are exchanged and accepted. Without authoritative verification of that instruction, the payment can move through protected systems while relying on unverified account information.

From: You secured the rail. The instruction stayed open.

Vendor risk

When should vendor bank details be verified?

At onboarding and again whenever bank details change, using contact information already on file rather than details supplied in the change request.

From: Vendor risk topic

What has to be in the file if the payee is later tied to fraud?

The file should show what the company knew when funds were released. That means payee authority, ownership review, the goods or service basis, any exception approval, and the source of payment instructions. A cleared payment proves movement of money. It does not prove the counterparty was valid or entitled to receive funds.

From: You cleared the file. You did not prove the payee. Now what?

Does an ERP approval prove the counterparty was payable?

An ERP approval is useful, but it usually proves only that a workflow step was approved. It may not show which ownership record was reviewed, why an exception was accepted, or whether a changed bank account was verified outside the request channel before the payment was released.

From: You cleared the file. You did not prove the payee. Now what?

Who owns the record for changed payment instructions?

AP and treasury should share the record. AP should preserve the request, the original and changed instructions, and the known contact used for verification. Treasury should preserve the release snapshot and confirm separation between the requester, verifier, and approver. The file should show the path, not only the final account.

From: You cleared the file. You did not prove the payee. Now what?

When do trade documents belong in an AP release packet?

Trade documents belong in the packet when payment depends on goods movement, origin, valuation, or an intermediary. The file should connect the invoice, purchase order, receipt, and relevant shipping or inspection record. The point is to preserve the commercial basis for paying that counterparty at release.

From: You cleared the file. You did not prove the payee. Now what?

Which controls should we retest after a fraud vendor acquisition?

Retest the controls that convert a fraud signal into payment approval. Start with administrator roles, service accounts, API token scopes, alert labels, case IDs, evidence retention, support access, and SOC report scope. The test is whether the release file still proves the same approval under the company's payment policy.

From: Payment vendor acquisition controls still trust outdated tools.

Can treasury rely on an unchanged dashboard after the deal closes?

Only after the evidence behind the dashboard has been revalidated. A green status can look the same while the underlying rule, identity source, case system, or data repository has changed. Treasury should require field level mapping that shows what each alert meant before and after the ownership or integration change.

From: Payment vendor acquisition controls still trust outdated tools.

What documents prove that an alert still means the same thing?

The strongest documents are tied to the changed control. Ask for release notes, bridge letters, data processing amendments, customer notices, incident notices, and any SOC report scope changes. Keep the vendor's notice with the payment release evidence, and document who inside finance accepted the mapping.

From: Payment vendor acquisition controls still trust outdated tools.

Who should own signoff before the next payment release?

Ownership should be split, but treasury should make the final payment trust decision. Identity confirms user and administrator access. Payments engineering confirms tokens and integrations. Fraud operations confirms alert meaning. Vendor risk collects assurance documents. Treasury decides whether the release file supports approval under the payment policy.

From: Payment vendor acquisition controls still trust outdated tools.

Why is vendor onboarding a fraud risk for bank account details?

Vendor onboarding is a fraud risk because a finance team may rely on a W-9, a voided check, and an email confirming wire instructions. If any of those documents is forged, the routing and account number can be entered into the ERP and treated as trusted for future invoices, often for years, with no re-verification.

From: You approved the vendor. The bank account came with it

How can forged onboarding documents lead to stolen vendor payments?

If a forged W-9, voided check, or confirmation email is accepted during onboarding, the finance team may enter the wrong routing and account number into the ERP. Once the record is set, every future invoice from that vendor pays to those numbers. The payments can be stolen from the first invoice onward.

From: You approved the vendor. The bank account came with it

Why are W-9s, voided checks, and confirmation emails weak controls for vendor bank verification?

A W-9 has no cryptographic signature and is only a PDF form. A voided check is a low-resolution image that can be spoofed. A confirmation email arrives from whichever address the sender chose. These documents can be accepted at onboarding, after which the bank details are often treated as trusted.

From: You approved the vendor. The bank account came with it

Why does verifying vendor bank details only at onboarding create long-term payment risk?

When companies verify only at onboarding, the trust decision made in a few minutes can compound across the whole vendor relationship. A single unverified onboarding can leak hundreds of thousands of dollars over a multi-year contract before anyone notices that payments are landing at the wrong destination.

From: You approved the vendor. The bank account came with it

What is a better control than more paperwork for vendor bank detail changes and payments?

The fix described is not more onboarding paperwork. It is a verifiable, revocable channel for exchanging bank details, where the vendor identity and account details are cryptographically bound. The record can then be re-verified on every payment without asking anyone to fill in another form.

From: You approved the vendor. The bank account came with it

Definitions

How is business email compromise different from phishing?

Phishing usually harvests credentials or delivers malware to a broad list. Business email compromise targets a specific payment relationship and often uses a genuine mailbox, so there is no malicious link or attachment to detect.

From: Business email compromise

Can a bank reverse a business email compromise wire?

Rarely. A domestic wire is final once settled, so recovery depends on the receiving bank freezing funds before they are withdrawn or moved onward. Speed of reporting matters more than anything else.

From: Business email compromise

Who inside a company is usually targeted?

Accounts payable staff, controllers, and anyone who can change vendor master data. Attackers also impersonate executives to pressure a single approver into bypassing normal steps.

From: Business email compromise

What is the most common trigger for vendor impersonation?

An emailed request to update remittance details on an existing supplier record, usually justified by a bank change and often arriving from a genuine or near identical domain.

From: Vendor impersonation fraud

How do you stop invoice redirection?

Treat a bank detail change as a privileged change: verify out of band against a number already on file, require a second approver, and hold the first payment for a short review window.

From: Vendor impersonation fraud

Does multi factor authentication prevent account takeover?

It removes the simplest path, password reuse, but token theft, consent phishing, and help desk social engineering all produce authenticated sessions without a password prompt.

From: Account takeover

What is the first sign of a compromised mailbox?

Unexplained inbox rules, especially rules that move or delete messages containing words such as invoice, payment, or remittance.

From: Account takeover

Is check fraud still a real risk for businesses?

Yes. It remains one of the most frequently reported payment fraud types affecting organizations, largely because checks expose account credentials in physical form.

From: Check fraud

What control reduces check fraud most directly?

Positive pay with payee name verification, combined with moving high value disbursements off paper entirely.

From: Check fraud

Is authorized push payment fraud refundable in the United States?

Usually not for business payments. Commercial funds transfers are governed largely by UCC Article 4A, which turns on the agreed security procedure rather than on the fact that a scam occurred.

From: Authorized push payment fraud

Why is APP fraud growing faster than card fraud?

Card networks carry built in dispute rights and issuer liability, while push payments settle to the beneficiary account with no equivalent chargeback path.

From: Authorized push payment fraud

Can a wire transfer be reversed?

Not unilaterally. Once settled, the funds belong to the beneficiary, so recovery depends on the receiving bank voluntarily freezing or returning them before they are moved.

From: Wire transfer

How long do you have to recover a fraudulent wire?

Hours, in practice. Reporting immediately to the originating bank and to the FBI IC3 gives the best chance of a freeze at the receiving institution.

From: Wire transfer

Who is liable for a fraudulent business wire?

Usually the business. Under UCC Article 4A a payment order the customer authorised, or one accepted under an agreed commercially reasonable security procedure, generally remains the customer's loss, and Regulation E consumer protections do not apply to business wires.

From: Wire transfer

What is the difference between a wire and an ACH payment?

A wire settles individually and with finality, usually the same day. ACH settles in batches and has defined return windows, so an ACH credit has limited return paths that a wire does not.

From: Wire transfer

What should you do in the first hour after sending a fraudulent wire?

Call the originating bank and ask for a recall to the receiving institution, file with the FBI IC3 so the Recovery Asset Team can engage, preserve the original instruction and mail headers, and check whether other pending payments used the same account details.

From: Wire transfer

Can an ACH payment be reversed?

Only in limited circumstances defined by the Nacha rules, such as duplicate or erroneous entries, and within short windows. Fraudulently redirected business credits are not automatically returnable.

From: ACH

How long does an ACH payment take to settle?

Standard entries settle in one to two business days, and same day ACH settles within defined processing windows on the same business day.

From: ACH

What is the difference between RTP and FedNow?

They are separate networks with the same shape: RTP is operated by The Clearing House, FedNow by the Federal Reserve. Both settle instantly and both are credit push only.

From: RTP and FedNow

Are instant payments reversible?

No. Both networks settle with finality, so a returned payment requires the receiver to send funds back voluntarily.

From: RTP and FedNow

What number should a callback use?

Only a number obtained independently of the request, such as one already stored in the vendor master record or published on the supplier's official site.

From: Callback verification

Is a callback still effective against voice cloning?

Partially. It still defeats email only attacks, but it should be paired with a shared secret or with verification of the account itself rather than the speaker.

From: Callback verification

Is a reply email out of band verification?

No. A reply travels the same channel as the request, so a compromised mailbox can answer it.

From: Out of band verification

What counts as a truly separate channel?

One that does not depend on the same credentials or identity provider as the original channel, such as a phone call to a previously stored number.

From: Out of band verification

Does text message confirmation count as out of band?

Only when the number came from your own records rather than from the request, and when the number itself is protected against porting or device takeover.

From: Out of band verification

How does out of band verification hold up against cloned voices?

It holds up when the confirmation depends on information the counterparty holds, such as a stored reference or a validated account, rather than on recognising the speaker.

From: Out of band verification

Does positive pay stop business email compromise?

No. Positive pay confirms that a payment matches the issue file, and in a redirection attack the fraudulent account details are already in that file.

From: Positive pay

What is the difference between positive pay and reverse positive pay?

Positive pay compares items against an issue file sent by the company. Reverse positive pay puts the review burden on the company, which examines presented items each day and decides what to return.

From: Positive pay

Does account validation prove ownership?

Only if the method returns an ownership match. Status only checks confirm the account is open, which does not tell you who controls it.

From: Bank account validation

How long do micro deposits take?

Typically one to two business days, which is why many organizations pair them with a faster network based check for time sensitive onboarding.

From: Bank account validation

When should a bank account be validated?

Before first payment and again at every change to bank details, because the change request is the event attackers actually use.

From: Bank account validation

What does a name mismatch mean?

It means the name presented does not match the name associated with the account. That can indicate fraud, or a legitimate difference such as a trading name or a subsidiary, so it should stop the payment and start a check rather than be dismissed.

From: Bank account validation

Is account validation the same as a callback?

No. A callback verifies a person, account validation verifies the destination. The two answer different questions and the strongest processes use both.

From: Bank account validation

Who should be allowed to change vendor bank details?

A role separate from anyone who can approve or release payments, with every change logged and independently verified before it takes effect.

From: Vendor master data

What should happen after a vendor bank change?

Hold the first payment on the new details for review and notify the supplier through a previously known contact that a change was made.

From: Vendor master data

How can a small finance team apply segregation of duties?

Split the highest risk pair first, changing bank details and releasing payments, and use the bank's own approval tiers to enforce a second approver even when only two people are available.

From: Segregation of duties

Is dual approval the same as segregation of duties?

Dual approval is one implementation of it. Segregation of duties also covers who can create records and who can execute, not only who signs off.

From: Segregation of duties

Which duties should never sit with the same person?

Changing a vendor's bank details and releasing payments to that vendor. When one person holds both, a single deception completes the whole fraud.

From: Segregation of duties

How do you handle an absent approver without breaking the control?

Define the exception path in advance with a named alternate approver, require the same verification evidence, and log each use so exceptions can be reviewed rather than repeated quietly.

From: Segregation of duties

How often should payment entitlements be reviewed?

On a fixed schedule and again after every role change, because separated duties on paper are frequently rejoined by leftover access in the banking portal or the accounting system.

From: Segregation of duties

Does UCC Article 4A protect a business from wire fraud losses?

Not directly. It allocates the loss, and the allocation usually favors the bank when a commercially reasonable agreed security procedure was followed.

From: UCC Article 4A

What is a commercially reasonable security procedure?

It is assessed against the customer's circumstances, including the size and frequency of payments and the alternatives the bank offered, so it varies by relationship rather than being a fixed checklist.

From: UCC Article 4A

Does Regulation E cover business bank accounts?

No. It applies to consumer asset accounts, so commercial payments fall under the deposit agreement and UCC Article 4A.

From: Regulation E

Does Regulation E cover scams the customer authorized?

Its core protections address unauthorized transfers, and authorized but induced payments have been the subject of continuing regulatory attention rather than settled coverage.

From: Regulation E

Can a business file a suspicious activity report?

No. Filing is an obligation of financial institutions. A defrauded business reports to its bank and to the FBI IC3.

From: Suspicious activity report

Why does SAR data matter for fraud research?

It is one of the few sources describing incident mechanics at national scale, and FinCEN publishes trend analyses derived from it.

From: Suspicious activity report

Will my bank tell me whether it filed a suspicious activity report?

No. The law prohibits an institution from disclosing the existence of a filing to the subject of the report, so the absence of confirmation says nothing about whether one was filed.

From: Suspicious activity report

Does a suspicious activity report help recover the money?

Not directly. Recovery depends on the receiving institution freezing funds, usually through the originating bank and the FBI IC3, and it runs on a separate and much shorter clock than the reporting obligation.

From: Suspicious activity report

What information should a defrauded company give its bank?

The payment references, the beneficiary account and routing numbers, the amount and settlement date, the channel the instruction arrived through, and who acted on it.

From: Suspicious activity report

How quickly should a fraudulent wire be reported to IC3?

Immediately. Recovery depends on reaching the receiving bank before funds are withdrawn, so the useful window is hours rather than days.

From: Recovery Asset Team

What information does a recovery request need?

The transaction details, the originating and receiving bank information, the account numbers involved, the amount, and the date, filed through the IC3 portal alongside a call to your own bank.

From: Recovery Asset Team