Preface
The fraud landscape grows more complex every day. Not just in the level of technical sophistication among bad actors, but in how fraudsters attack their targets.
For treasury and finance teams, this requires a shift in how they think about their payment fraud controls. It’s no longer solely a question of whether you have the right controls in place (although that is still essential), it’s also a matter of whether those controls will hold up in real-world conditions.
The fraud control fundamentals provided in this article—design, practice, and testing—include actionable steps treasury teams can take to ensure their antifraud measures consistently work as designed.
Combatting Fraud in the Current Landscape
Treasury teams have spent decades strengthening payment controls through segregation of duties, dual approval, callback procedures, and system-based restrictions. Yet many of today’s fraud schemes succeed because fraudsters no longer focus solely on attacking technology. Increasingly, they target the people and processes behind those controls.
Bad actors understand that bypassing a well-designed payment system may be more difficult than persuading an employee to act quickly, trust a familiar-looking request, or deviate from an established procedure. Treasury departments must therefore address a fundamental question: Will their controls perform as intended under real-world pressure?
Building resilience against today’s fraud threats requires three distinct but related disciplines:
Control design: Establish controls that appropriately address the risk.
Control practice: Execute those controls consistently in day-to-day operations.
Control testing: Validate that the controls remain effective under realistic conditions.
Each discipline plays a different role. Design establishes the safeguard, practice embeds it into operations, and testing provides evidence that it works. A weakness in any one of the three can undermine the entire control environment.
Control Design: Are the Right Safeguards in Place?
Control design begins by identifying the fraud risk and determining what must happen to prevent or detect it. A well-designed control should establish clear ownership, separate incompatible responsibilities, require independent verification, preserve evidence, and define how exceptions must be escalated.
Historically, organizations have often focused on whether a control exists. Audits, compliance reviews, and internal assessments may begin by confirming that policies are documented, procedures are established, and approval processes are in place. While this is an important starting point, the existence of a control does not guarantee that it is appropriately designed for the risk.
Fraudsters may find opportunities in situations where employees are distracted, rushed, overloaded with competing priorities, or overly confident in familiar processes. Rather than exploiting weaknesses in system architecture, fraudsters may attempt to manipulate decision-making and influence human behavior.
Business email compromise is an illustrative example. Fraud losses may occur not because verification controls are absent, but because the control design allows employees to rely on information contained in the request, assume that verification occurred earlier in the process, or approve an exception without sufficient escalation.
A callback procedure, for example, is generally considered a strong control. However, the procedure must be designed to require employees to:

Use previously established contact information from an independent internal source.

Complete the callback regardless of urgency or familiarity.

Document who was contacted, when the contact occurred, and what was verified.

Escalate discrepancies or unsuccessful verification attempts.

Prevent the transaction from proceeding until verification is complete.
The strength of the control therefore depends not only on requiring a callback, but also on defining how the callback must be completed and what happens when verification fails.
Vendor Master Data as a Strategic Control Point
Vendor master data is another important area of control design. Many organizations treat vendor master updates primarily as administrative activities, with an emphasis on processing changes efficiently so business operations can continue without disruption. While efficiency is important, it can unintentionally understate the risks associated with changing vendor information.
A change to a vendor’s banking instructions can redirect both current and future payments. Ownership of vendor master data may also be fragmented across procurement, accounts payable, treasury, and business units. This fragmentation can make accountability less clear and increase the risk that suspicious activity goes unnoticed. Organizations can strengthen the design of vendor master controls by:

Establishing clear ownership and governance for vendor master maintenance.

Separating vendor maintenance from payment initiation and approval.

Restricting access based on job responsibilities.

Requiring enhanced approval for banking instruction changes.

Monitoring changes to banking and beneficiary information.

Applying heightened scrutiny to the first payment following an account change.

Periodically reviewing recent vendor account changes for unusual activity.
Treating vendor master changes as high-risk treasury events, rather than routine administrative requests, helps protect the integrity of future payments.
Control Practice: Are the Safeguards Followed Consistently?
Control practice is the disciplined execution of a control in day-to-day operations. A control can be appropriately designed and still fail if employees apply it inconsistently, misunderstand their responsibilities, or make exceptions when facing operational pressure.
The verification of vendor banking changes illustrates this distinction. Callback requirements, confirmation through a separate communication channel, and review by authorized personnel may all be part of a strong control design. Problems often emerge, however, during execution:

An employee assumes that another team completed the verification.

A team facing an operational deadline feels pressure to process the change quickly.

The employee contacts the vendor using a phone number or email address included in the change request.

A familiar name, writing style, or executive reference discourages further questioning.

An exception is approved without the required evidence or escalation.
In these circumstances, the control exists but is not executed as designed. Verification gradually becomes a procedural step rather than an independent challenge of the request.
Organizations can strengthen control practice by:

Training employees in both the required procedure and the fraud risk it addresses.

Assigning clear responsibility for each verification step.

Requiring documented evidence that callbacks and other verification procedures were completed.

Reinforcing that established procedures apply regardless of urgency, seniority, or familiarity.

Prohibiting the use of contact information supplied in the change request.

Defining escalation paths for unusual or unverifiable requests.

Reviewing exceptions and near misses with employees.

Holding control owners accountable for consistent execution.
Managers also play an important role in control practice. Employees are less likely to bypass procedures when leaders consistently reinforce that security takes priority over speed. Conversely, employees may make unsafe exceptions if they believe missed deadlines will be viewed more negatively than control failures.
Effective control practice requires a culture in which employees are expected, equipped, and supported to pause, question, verify, and escalate.
Control Testing: Can You Demonstrate Effectiveness?
Control testing provides objective evidence that a control is appropriately designed and consistently performed. It is distinct from routine execution because it evaluates the control rather than carrying it out as part of normal operations.
Treasury organizations may stress-test liquidity positions, forecasting assumptions, and market risk exposures. Fraud controls deserve a similar level of scrutiny. Applying a similarly structured approach to fraud controls can help identify weaknesses before they are exploited. A complete testing program should evaluate two dimensions:
1. Design effectiveness. This determines whether the control, if performed as documented, is capable of addressing the identified fraud risk.
Testing should consider questions such as:

Is the control linked to a clearly defined risk?

Are ownership and decision rights clear?

Are incompatible responsibilities appropriately separated?

Does the procedure require information from an independent source?

Are evidence requirements clearly defined?

Are escalation and exception procedures adequate?

Could an employee technically follow the procedure without meaningfully verifying the request?
2. Operating effectiveness. This determines whether the control was performed consistently, by the appropriate individuals, and with sufficient evidence. Testing should consider questions such as:

Was independent verification completed?

Was previously established contact information used?

Did the approver challenge unusual circumstances?

Were escalation procedures followed?

Were exceptions appropriately authorized and documented?

Did employees understand who was responsible for the final decision?

Was the control performed consistently across different teams, locations, and time periods?
Control testing should evaluate the quality of the investigation and decision-making behind the approval. Practical testing activities may include:

Conducting periodic control effectiveness assessments.

Reviewing samples of completed vendor account changes.

Performing targeted spot checks of callback evidence.

Simulating executive or urgent payment requests.

Evaluating responses to after-hours requests.

Reviewing payroll direct-deposit change procedures.

Testing escalation and exception management processes.

Assessing how approvers respond when information is incomplete or inconsistent.

Reviewing manual processes and handoffs for unclear responsibilities.

Tracking recurring exceptions, root causes, and remediation.
Testing results should lead to specific action. A design weakness, for example, may require the control itself to be revised. An execution failure may require clearer procedures, additional training, stronger supervision, or better system enforcement. Repeated failures may indicate that the issue is systemic rather than isolated.
Testing closes the loop by using observed results to improve control design and strengthen control practice.
Fraud Control Effectiveness Is Becoming the New Standard
Today’s fraud landscape increasingly exploits human behavior, organizational complexity, and operational pressure. Well-designed controls remain essential, but control design alone is not enough. Resilient treasury organizations take a three-part approach:

Design controls that directly address the risk.

Practice those controls consistently during normal and high-pressure situations.

Test the controls periodically to determine whether they actually work.
This is not a set-it-and-forget-it exercise. It is a continuous discipline requiring consistent execution and ongoing testing. Fraudsters are relentless, which means treasury teams must be equally tenacious in making sure their controls are up to the challenge. The sooner organizations implement the measures described here, the better.
