A convincing email is not enough to authorize a new payee, changed bank details, an urgent transfer or a release of confidential information. Verify the request through an independent channel, separate approval from entry and release, and keep evidence of what was authorized. Accounting controls work alongside technical security and a prompt incident-response process.

Recognize payment diversion and information theft
Business email compromise can involve impersonation or an attacker using a legitimate compromised mailbox. A request may fit an existing invoice conversation and contain correct names, amounts and history. The FBI’s BEC guidance describes spoofing, compromised accounts and fraudulent payment requests.
Examples include a supplier’s alleged bank change, an executive’s urgent wire request, altered remittance instructions, a payroll direct-deposit change or a request for employee tax records. Harm can occur when money is redirected, but stolen credentials or confidential records can also cause damage before any payment leaves the bank.
Verify the request outside the email thread
Use an established contact and a telephone number obtained independently of the suspicious request. Confirm the reason for the change, the intended beneficiary and the applicable invoice or obligation. Do not use a replacement phone number supplied in the same email as the new bank details. The FBI recommends independently verifying payment requests and changes to account numbers or procedures.
A callback is one control, not proof that the request is safe. Compromised contact records, social engineering, voice impersonation or collusion can undermine a simplistic check. Keep contact changes subject to their own approval and verification, and use an additional established channel or escalation when the facts do not agree. A familiar voice or display name alone does not establish authorization.
Record who verified the request, which established contact method was used, what was confirmed and when. Preserve supporting documents in the designated business record system rather than relying only on the original email chain. Urgency and seniority should not override the verification policy.
Separate vendor changes, payment approval and release
| Step | Responsible role | Evidence to retain |
|---|---|---|
| Log the requested change | Accounts payable or payroll administrator | Original request, affected payee and payment details. |
| Verify independently | Designated verifier | Established contact used and confirmation of the actual request. |
| Approve the change | Authorized manager separate from entry where practical | Approval tied to the specific old and new details. |
| Update the payee record | Designated system user | Change history and supporting approval. |
| Approve and release payment | Authorized banking users under the business policy | Amount, beneficiary, invoice support and release record. |
| Review the completed transaction | Reviewer separate from the preparer where practical | Actual bank beneficiary and amount compared with authorization. |
Define thresholds and transactions requiring two different authorized people. New or changed payment destinations may warrant additional review even for small amounts. Configure the bank’s available controls and check whether the actual service permits one user to bypass them. An approval note in accounting software does not necessarily prevent a bank user from releasing funds.
If the team is small, document the remaining concentration of duties and compensating owner review. An outside accountant is not automatically an authorized banking approver. Any external payment-approval role requires an explicitly agreed service, defined authority and responsibility, and the appropriate banking arrangements. Do not infer that authority from a bookkeeping or financial-report engagement.
Protect accounts without overstating what authentication proves
Use individual accounts and permissions appropriate to each role. Review access when people join, leave or change duties. Restrict who can alter payees, bank instructions, payroll destinations and payment-release settings. Confirm the actual capabilities of the accounting edition, payment platform and bank being used.
The joint CISA, NSA, FBI and MS-ISAC phishing guidance recommends phishing-resistant MFA, including appropriate FIDO or PKI-based methods, and prioritizing privileged accounts. Have qualified IT staff choose and implement the method supported by the systems. MFA improves account protection but does not establish that a particular payment is authorized.
SPF, DKIM and DMARC support email-domain authentication and handling of spoofed messages. They do not prove the sender’s intent, the truth of an invoice or the safety of a message sent from a compromised legitimate account. IT staff should manage these controls, mailbox forwarding rules, account alerts and supported software updates as part of the wider security process.
A balanced reconciliation does not prove a payment was legitimate
Suppose a supplier invoice is $18,000 and an attacker substitutes a new bank destination. If the business sends $18,000 and records that exact payment, the accounting entry can match the bank statement perfectly. The reconciliation may show no difference even though the intended supplier has not been paid.
Compare the actual beneficiary and payment instructions with independently approved records, not only the amount and ledger category. If the destination was unauthorized, preserve the evidence and investigate the supplier obligation and any recoverable funds. Do not automatically mark the valid supplier debt as settled merely because cash left the bank.
Use timely bank alerts and review new payees, changed destinations and unusual transfers close to execution. Monthly reconciliation remains useful, but it is too late to serve as the only response mechanism for a suspicious wire. A pattern of small unusual payments also deserves attention; not every incident begins with a large transfer.
Respond immediately when a transfer may be fraudulent
- Contact the originating financial institution immediately. Use its known fraud contact and request a recall or reversal and contact with the receiving institution. Ask what hold, freeze or indemnification documentation may be available. Recovery is not guaranteed.
- Report promptly to IC3. The FBI’s Internet Crime Complaint Center BEC page explains bank-recall steps and provides its complaint process. Include accurate transaction and beneficiary information through the official reporting channel.
- Preserve the evidence. Retain the original messages and headers where available, invoices, payment confirmations, bank details, timestamps, verification records and relevant system logs. Do not erase the accounting trail while investigating.
- Activate the incident plan. Notify the designated business lead and qualified IT or security responder. Contact the insurer and legal counsel as appropriate to coverage, notification obligations and the facts.
- Contain further harm. Have the responsible bank and technical personnel address pending transfers, compromised accounts, sessions, forwarding rules and exposed information. Use an established communication channel outside a suspected compromised mailbox.
Information theft or account compromise can require response even when no funds were transferred. Technical containment belongs with qualified personnel; an accountant can help trace transactions and preserve financial records within the agreed role.
Test the workflow and define accountability
Maintain a current contact list for the bank, business lead, IT responder, insurer, legal counsel and accounting support. Use a mock request to check whether staff can independently verify a bank change, obtain the required approvals and escalate a discrepancy. Test the procedure without sending real funds or exposing confidential records.
Review failed controls and update responsibilities after staff, bank or software changes. Keep an action log showing the gap, owner, correction and follow-up. Avoid claims that one short call stops most attacks or that a specific control makes fraud impossible.
For help documenting accounting workflows and reviewing transaction evidence, contact CPA Firm South Florida to define the scope. Confirm separately who has payment authority and who leads technical incident response.
Related reading: “Accounting Controls for Professional-Service Firms” covers Professional Service Accounting Controls in more detail.