Preface 


The fraud landscape grows more complex every day. Not just in the level of technical sophistication among bad actors, but in how fraudsters attack their targets. 


For treasury and finance teams, this requires a shift in how they think about their payment fraud controls. It’s no longer solely a question of whether you have the right controls in place (although that is still essential), it’s also a matter of whether those controls will hold up in real-world conditions.  


The fraud control fundamentals provided in this article—design, practice, and testing—include actionable steps treasury teams can take to ensure their antifraud measures consistently work as designed. 


Marc-Andre Bergeron

Marc-Andre Bergeron, Managing Director & Head, Global Corporate Transaction Banking


Combatting Fraud in the Current Landscape 


Treasury teams have spent decades strengthening payment controls through segregation of duties, dual approval, callback procedures, and system-based restrictions. Yet many of today’s fraud schemes succeed because fraudsters no longer focus solely on attacking technology. Increasingly, they target the people and processes behind those controls. 

 

Bad actors understand that bypassing a well-designed payment system may be more difficult than persuading an employee to act quickly, trust a familiar-looking request, or deviate from an established procedure. Treasury departments must therefore address a fundamental question: Will their controls perform as intended under real-world pressure? 

 

Building resilience against today’s fraud threats requires three distinct but related disciplines: 

 

  1. Control design: Establish controls that appropriately address the risk. 

  2. Control practice: Execute those controls consistently in day-to-day operations. 

  3. Control testing: Validate that the controls remain effective under realistic conditions. 

 

Each discipline plays a different role. Design establishes the safeguard, practice embeds it into operations, and testing provides evidence that it works. A weakness in any one of the three can undermine the entire control environment. 

 

Control Design: Are the Right Safeguards in Place? 


Wooden blocks showing envelope and lock icons, symbolizing cybersecurity controls.

Control design begins by identifying the fraud risk and determining what must happen to prevent or detect it. A well-designed control should establish clear ownership, separate incompatible responsibilities, require independent verification, preserve evidence, and define how exceptions must be escalated. 

 

Historically, organizations have often focused on whether a control exists. Audits, compliance reviews, and internal assessments may begin by confirming that policies are documented, procedures are established, and approval processes are in place. While this is an important starting point, the existence of a control does not guarantee that it is appropriately designed for the risk. 

 

Fraudsters may find opportunities in situations where employees are distracted, rushed, overloaded with competing priorities, or overly confident in familiar processes. Rather than exploiting weaknesses in system architecture, fraudsters may attempt to manipulate decision-making and influence human behavior. 

 

Business email compromise is an illustrative example. Fraud losses may occur not because verification controls are absent, but because the control design allows employees to rely on information contained in the request, assume that verification occurred earlier in the process, or approve an exception without sufficient escalation. 

 

A callback procedure, for example, is generally considered a strong control. However, the procedure must be designed to require employees to: 

 

  • checkmark icon

    Use previously established contact information from an independent internal source. 

  • checkmark icon

    Complete the callback regardless of urgency or familiarity. 

  • checkmark icon

    Document who was contacted, when the contact occurred, and what was verified. 

  • checkmark icon

    Escalate discrepancies or unsuccessful verification attempts. 

  • checkmark icon

    Prevent the transaction from proceeding until verification is complete. 

 

The strength of the control therefore depends not only on requiring a callback, but also on defining how the callback must be completed and what happens when verification fails. 

 

Vendor Master Data as a Strategic Control Point 


Vendor master data is another important area of control design. Many organizations treat vendor master updates primarily as administrative activities, with an emphasis on processing changes efficiently so business operations can continue without disruption. While efficiency is important, it can unintentionally understate the risks associated with changing vendor information. 

 

A change to a vendor’s banking instructions can redirect both current and future payments. Ownership of vendor master data may also be fragmented across procurement, accounts payable, treasury, and business units. This fragmentation can make accountability less clear and increase the risk that suspicious activity goes unnoticed. Organizations can strengthen the design of vendor master controls by: 

 

  • checkmark icon

    Establishing clear ownership and governance for vendor master maintenance. 

  • checkmark icon

    Separating vendor maintenance from payment initiation and approval. 

  • checkmark icon

    Restricting access based on job responsibilities. 

  • checkmark icon

    Requiring enhanced approval for banking instruction changes. 

  • checkmark icon

    Monitoring changes to banking and beneficiary information. 

  • checkmark icon

    Applying heightened scrutiny to the first payment following an account change. 

  • checkmark icon

    Periodically reviewing recent vendor account changes for unusual activity. 

 

Treating vendor master changes as high-risk treasury events, rather than routine administrative requests, helps protect the integrity of future payments. 

 

Control Practice: Are the Safeguards Followed Consistently? 


Wooden blocks with an envelope and telephone icons are stacked to represent callback requirements as a risk management practice.

Control practice is the disciplined execution of a control in day-to-day operations. A control can be appropriately designed and still fail if employees apply it inconsistently, misunderstand their responsibilities, or make exceptions when facing operational pressure. 

 

The verification of vendor banking changes illustrates this distinction. Callback requirements, confirmation through a separate communication channel, and review by authorized personnel may all be part of a strong control design. Problems often emerge, however, during execution: 

 

  • checkmark icon

    An employee assumes that another team completed the verification. 

  • checkmark icon

    A team facing an operational deadline feels pressure to process the change quickly. 

  • checkmark icon

    The employee contacts the vendor using a phone number or email address included in the change request. 

  • checkmark icon

    A familiar name, writing style, or executive reference discourages further questioning. 

  • checkmark icon

    An exception is approved without the required evidence or escalation. 

 

In these circumstances, the control exists but is not executed as designed. Verification gradually becomes a procedural step rather than an independent challenge of the request. 

 

Organizations can strengthen control practice by: 

 

  • checkmark icon

    Training employees in both the required procedure and the fraud risk it addresses. 

  • checkmark icon

    Assigning clear responsibility for each verification step. 

  • checkmark icon

    Requiring documented evidence that callbacks and other verification procedures were completed. 

  • checkmark icon

    Reinforcing that established procedures apply regardless of urgency, seniority, or familiarity. 

  • checkmark icon

    Prohibiting the use of contact information supplied in the change request. 

  • checkmark icon

    Defining escalation paths for unusual or unverifiable requests. 

  • checkmark icon

    Reviewing exceptions and near misses with employees. 

  • checkmark icon

    Holding control owners accountable for consistent execution. 

 

Managers also play an important role in control practice. Employees are less likely to bypass procedures when leaders consistently reinforce that security takes priority over speed. Conversely, employees may make unsafe exceptions if they believe missed deadlines will be viewed more negatively than control failures. 

 

Effective control practice requires a culture in which employees are expected, equipped, and supported to pause, question, verify, and escalate. 

 

Control Testing: Can You Demonstrate Effectiveness? 


Wooden blocks with various icons are stacked to represent a fraud controls testing process.

Control testing provides objective evidence that a control is appropriately designed and consistently performed. It is distinct from routine execution because it evaluates the control rather than carrying it out as part of normal operations. 

 

Treasury organizations may stress-test liquidity positions, forecasting assumptions, and market risk exposures. Fraud controls deserve a similar level of scrutiny. Applying a similarly structured approach to fraud controls can help identify weaknesses before they are exploited. A complete testing program should evaluate two dimensions: 

 

1. Design effectiveness. This determines whether the control, if performed as documented, is capable of addressing the identified fraud risk. 

 

Testing should consider questions such as: 

 

  • checkmark icon

    Is the control linked to a clearly defined risk? 

  • checkmark icon

    Are ownership and decision rights clear? 

  • checkmark icon

    Are incompatible responsibilities appropriately separated? 

  • checkmark icon

    Does the procedure require information from an independent source? 

  • checkmark icon

    Are evidence requirements clearly defined? 

  • checkmark icon

    Are escalation and exception procedures adequate? 

  • checkmark icon

    Could an employee technically follow the procedure without meaningfully verifying the request? 

 

2. Operating effectiveness. This determines whether the control was performed consistently, by the appropriate individuals, and with sufficient evidence. Testing should consider questions such as: 

 

  • checkmark icon

    Was independent verification completed? 

  • checkmark icon

    Was previously established contact information used? 

  • checkmark icon

    Did the approver challenge unusual circumstances? 

  • checkmark icon

    Were escalation procedures followed? 

  • checkmark icon

    Were exceptions appropriately authorized and documented? 

  • checkmark icon

    Did employees understand who was responsible for the final decision? 

  • checkmark icon

    Was the control performed consistently across different teams, locations, and time periods? 

 

Control testing should evaluate the quality of the investigation and decision-making behind the approval. Practical testing activities may include: 

 

  • checkmark icon

    Conducting periodic control effectiveness assessments. 

  • checkmark icon

    Reviewing samples of completed vendor account changes. 

  • checkmark icon

    Performing targeted spot checks of callback evidence. 

  • checkmark icon

    Simulating executive or urgent payment requests. 

  • checkmark icon

    Evaluating responses to after-hours requests. 

  • checkmark icon

    Reviewing payroll direct-deposit change procedures. 

  • checkmark icon

    Testing escalation and exception management processes. 

  • checkmark icon

    Assessing how approvers respond when information is incomplete or inconsistent. 

  • checkmark icon

    Reviewing manual processes and handoffs for unclear responsibilities. 

  • checkmark icon

    Tracking recurring exceptions, root causes, and remediation. 

 

Testing results should lead to specific action. A design weakness, for example, may require the control itself to be revised. An execution failure may require clearer procedures, additional training, stronger supervision, or better system enforcement. Repeated failures may indicate that the issue is systemic rather than isolated. 

 

Testing closes the loop by using observed results to improve control design and strengthen control practice. 

 

Fraud Control Effectiveness Is Becoming the New Standard 


Today’s fraud landscape increasingly exploits human behavior, organizational complexity, and operational pressure. Well-designed controls remain essential, but control design alone is not enough. Resilient treasury organizations take a three-part approach: 

 

  • checkmark icon

    Design controls that directly address the risk. 

  • checkmark icon

    Practice those controls consistently during normal and high-pressure situations. 

  • checkmark icon

    Test the controls periodically to determine whether they actually work. 

 

This is not a set-it-and-forget-it exercise. It is a continuous discipline requiring consistent execution and ongoing testing. Fraudsters are relentless, which means treasury teams must be equally tenacious in making sure their controls are up to the challenge. The sooner organizations implement the measures described here, the better.