Back to all articles
Financial Controls

Payment Fraud Controls: The Gaps That Survive in Otherwise Well-Run Finance Teams

Most payment fraud in UK SMEs exploits process gaps, not technology failures. Here are the controls that actually hold.

Payment fraud losses in UK businesses continue to be dominated by authorised push payment scams and internal supplier manipulation, not sophisticated system compromise. The attacker rarely breaks a control. They find the point where a control was assumed but never operated.

Finance teams that would describe themselves as well run routinely carry two or three of the gaps below.

Gap one: supplier bank detail changes

This is the single most exploited weakness. An email arrives from a known supplier contact requesting a change of bank details. It looks legitimate because the sender has been compromised or the domain is nearly right.

The control that works is boring: no bank detail change is actioned without independent verbal verification using a phone number already held on file, performed by someone other than the person who received the request, and logged with the date, the person called and the outcome.

The control that fails is a policy that says changes must be verified without specifying who verifies, using which number, and where the evidence is kept.

Gap two: the payment run reviewer who does not review

Dual authorisation is nearly universal. Meaningful dual authorisation is not. If the second approver is presented with a total and a payment count rather than a payee-level listing, they are approving an aggregate, not the payments.

Ask what the second approver actually sees. If they cannot identify a new payee added since the last run, the control is decorative.

Gap three: standing data that nobody owns

The supplier master file accumulates duplicates, dormant accounts and records created for one-off payments. Each dormant record is an opening for a payment that looks routine.

A quarterly review of new and amended supplier records, run by someone outside accounts payable, takes under an hour and removes most of this exposure. Auditors increasingly ask for it.

Gap four: urgency as an override

Almost every payment fraud involves time pressure. A deal will collapse, a supplier will stop shipping, the director is travelling and unreachable.

The mitigation is cultural as much as procedural: an explicit rule, communicated by the board, that no payment is ever made outside the standard authorisation route regardless of who requests it or how urgent it appears. Staff need to know they will be supported for delaying a payment, not criticised.

Gap five: no reconciliation between approval and execution

Approval controls sit in one system. Execution sits in the banking platform. If nobody compares the approved payment file to what actually left the bank, an amendment between approval and release is invisible.

A same-day or next-day comparison of the approved run to the bank statement closes this. It is also strong audit evidence that the payment cycle operates end to end.

What this looks like in an audit

Auditors testing the purchases and payments cycle will sample payments and ask who approved them, on what basis, and whether the payee was verified. Where bank detail changes occurred in the period, expect those to be selected specifically.

Businesses that can produce a verification log, a payee-level approval record and a payment-to-bank reconciliation pass this quickly. Businesses that rely on the finance team remembering what happened do not.

Where to start

Pick the last three months of payments. Identify every new payee and every bank detail change. Try to evidence how each was verified. Whatever you cannot evidence is your control gap, and it is also what a fraudster would target.