Payment Fraud Is Also a Bookkeeping-Control Problem

A vendor email arrives with new banking instructions. The invoice is familiar, the signature looks correct, and the message asks for the next payment to be sent to a different account. If the change is processed from the email alone, a legitimate expense can become a fraudulent payment.
Cybersecurity tools matter, but many payment schemes succeed during routine bookkeeping work: adding a vendor, editing bank details, approving an invoice, issuing a check, or reviewing bank activity. Controls around those steps can stop a false request before funds move.
Key Takeaways
Treat every vendor banking change as a high-risk event that requires independent verification through a trusted contact channel.
Separate vendor setup, payment approval, and bank reconciliation wherever the size of the team allows.
Configure bank alerts, limits, dual approvals, and payment-method controls around the transactions the business actually uses.
Review bank activity promptly and reconcile every month so suspicious payments are identified while response options may still exist.
Quick Links
What the latest payment-fraud data show
The 2026 Association for Financial Professionals Payments Fraud and Control Survey found that 76% of surveyed organizations experienced attempted or actual payment fraud in 2025. Business email compromise affected 74%. Checks were targeted at 58% of organizations, followed by ACH debits at 30% and wire transfers at 25%.
The survey included 465 treasury practitioners from organizations of different sizes and industries. The 76% result should not be presented as a small-business incidence rate. AFP noted that smaller organizations may encounter fraud less frequently while having fewer resources for recovery when a loss occurs.
The payment methods in the report also matter. Check use remains common, often because a vendor requires it. Electronic payments reduce some risks, but they create other points of exposure when account details are changed without independent verification.
Treat vendor banking changes as high-risk events
A change to payment instructions should trigger a defined process, even when the request appears to come from a long-standing vendor or a senior employee.
Use contact information already stored in the approved vendor record. Call a known representative and confirm the routing and account details. Do not rely on a phone number included in the change request because the message itself may be fraudulent. Record who completed the verification, who confirmed the change, the date, and the last four digits of the approved account.
For a new vendor, collect the business name, remit-to address, primary contact, payment terms, and required documentation before the first payment. Limit the ability to create a vendor and release a payment in the same workflow.
Support4B's guide to business expense documentation explains how invoices, receipts, and transaction notes support a reliable record. The same documentation also creates a trail for payment approval and later review.
Separate setup, approval, and reconciliation where possible
No single employee should control every stage of a payment. A stronger process separates three functions:
Creating or changing the vendor record.
Approving the invoice and payment.
Reconciling the bank account after payment.

Small teams may not have three different employees available. In that case, add an owner or outside reviewer at the highest-risk point. For example, one employee can enter bills, while the owner approves the payment from a separate login. The reviewer can receive bank statements or alerts directly from the bank instead of relying only on a report prepared by the person who initiated the transaction.
Set approval thresholds that match the business. A second approval may be required for every vendor banking change, first payment, wire, ACH addition, unusual request, or payment over a chosen amount. Thresholds should be written down so the process does not change based on who happens to be available.
Use a callback process that fraudsters cannot control
Business email compromise often relies on urgency and authority. The message may claim that an executive is in a meeting, a vendor needs immediate payment, or a confidential transaction cannot follow the normal process.
A callback process works only when the verifier controls the contact channel. Use the phone number in the existing vendor file, on a prior verified invoice, or on the vendor's official website. If an executive requests an unusual payment, confirm through a separate method that the business already uses.
Write the exception rule in advance: no payment instruction changes based solely on email, and no employee can waive the confirmation step for urgency. A legitimate vendor can wait for a short verification. A fraudster will usually push against it.
Configure bank controls around actual payment methods
Ask the bank which protections are available for the accounts and payment types the business uses. Options may include:

Features and fees vary by bank. Choose controls based on the payment volume, typical transaction size, and ability to absorb a loss. Review access whenever an employee changes roles or leaves the business.
Review activity promptly and reconcile every month
Bank alerts and frequent activity reviews can identify an unauthorized transaction while response options may still be available. The person reviewing activity should know the expected vendors, payroll dates, transfers, and typical transaction sizes.
Monthly reconciliation remains a core control and the first step in a reliable close. It matches the accounting records to the bank statement and identifies missing, duplicated, altered, or unexplained transactions. It should support frequent review rather than replace it. A suspicious payment discovered weeks later may be harder to recover.

During reconciliation, investigate unfamiliar payees, duplicate payment amounts, changed check information, stale outstanding checks, unexpected ACH debits, and transfers without support. Do not clear an item simply because the bank balance can be made to agree.
The Support4B bank reconciliation guide describes how to resolve differences and document adjustments. Consistent monthly bookkeeping helps ensure that payment records, vendor details, and bank activity are reviewed as part of the close.
Watch for common payment warning signs
Pause the transaction when a request includes one or more of these conditions:
A vendor asks to change bank details shortly before payment is due.
The sender uses a new domain, a look-alike address, or a personal email account.
An executive requests secrecy or asks an employee to bypass approval.
The request changes the payment method from check to wire or ACH.
An invoice duplicates a prior amount, date, or invoice number.
The remit-to name does not match the approved vendor record.
A vendor says payment was not received even though the bank shows it cleared.
A check clears with a different payee or amount than the accounting record.
One warning sign does not prove fraud. It does justify independent confirmation before another payment is released.
If a suspicious payment has already been sent
Contact the bank immediately using a trusted phone number. Ask whether the payment can be recalled, stopped, or flagged. Disable compromised credentials, preserve the related emails and approval records, and stop additional payments to the affected account until the vendor is reverified.
Document the transaction date, amount, payment method, destination, people involved, and steps taken. Response and reporting requirements depend on the incident, the bank, the payment method, and the business's policies. Prompt documentation gives the bank and the business a clearer timeline.
A 30-minute payment-control review
Use the next payment cycle to check five items:
Confirm who can add vendors, change bank details, approve payments, and reconcile accounts.
Require independent verification for every vendor banking change.
Turn on bank alerts for high-risk transactions and unusual amounts.
Review whether dual approval is active for wires, ACH payments, and large disbursements.
Confirm that bank and credit-card accounts are reconciled through the latest month.
Payment fraud often exploits a routine process that depends on trust and speed. A documented verification step, a second approval, and prompt bank review create practical checkpoints before and after funds move.
If your payment workflow has grown without a formal control review, Support4B can help organize the vendor records, approval documentation, and reconciliation process that support safer disbursements.

