Bank transfer fraud in business – Why your controls are no longer enough ?

The bank transfer was authorised.
Yet it was fraudulent.

The invoice was genuine. The supplier existed. The amount matched an expected transaction.
The employee had the necessary authorisation, and the payment followed the usual process.
Yet the funds never reached the supplier’s account.

Between receipt of the invoice and execution of the bank transfer, the supplier’s bank details had been replaced. The transaction appeared legitimate because the fraudster had not fabricated it: they had inserted themselves into an existing exchange.

This situation highlights a major shift in risk. Bank transfer fraud no longer relies solely on a crude message or an obviously unusual request. It can replicate the name of a known contact, the amount of a genuine invoice, the timing of an expected payment and even the tone normally used in communications.

According to Cybermalveillance.gouv.fr’s 2025 Activity Report, approximately 13,000 requests for assistance concerned payment fraud, representing a 170% increase. Such cases accounted for 12.8% of assistance requests from professionals and ranked as their third most frequently encountered threat.

In response to this development, checking whether an invoice appears consistent is no longer enough. Companies must assess the robustness of the process used to authorise, prepare and execute payments.

Successful fraud does not always bypass procedures.
Sometimes, it exploits procedures that were not robust enough in the first place.

Five breakdowns in control that should raise a red flag

Montagnes rocheuses brumeuses avec sommets escarpés et neige.

1. The same person can create a supplier and prepare the payment

When an employee can create a supplier, enter their bank details, record the invoice and prepare the payment, a single set of access rights covers several sensitive stages of the process.

This does not mean that fraud is taking place. It means that an error or fraudulent action could pass through the entire process without encountering an independent control.

Where a complete segregation of duties is not possible, this concentration of responsibilities should be offset by separate approval, periodic supplier reviews and documented controls over sensitive changes.

Vue panoramique de montagnes enneigées et forêt automnale.

2. A change to bank details can be approved solely by email

An email is not sufficient evidence when email itself is one of the channels most commonly exploited by fraudsters.

Any change to bank details should be confirmed through a separate channel, with a known contact and using contact details already held on file.

The number provided in the message requesting the change should not be used for verification. It may also belong to the fraudster.

The verification should also be documented, including the date, the identity of the person contacted, the number used and the name of the employee who performed the check.

Lac paisible entouré de montagnes enneigées et de forêts.

3. The second approval does not verify anything different

Clicking “approve” twice does not automatically create an effective two-level control.

Two people may authorise the same payment while relying on a single compromised source of information. The second approval can also become little more than a formality when its purpose has not been clearly defined.

Controls should be complementary :

  • One person verifies that the invoice and the underlying service are genuine.
  • A second person checks the beneficiary and any changes to their bank details.
  • Final authorisation is based on independent, traceable evidence.

The number of approvals matters less than the independence of the checks being performed.

Montagnes majestueuses au coucher du soleil avec des roches escarpées.

4. Access rights do not reflect changes in roles

Access rights often accumulate as an organisation evolves.

An employee changes role but retains their previous permissions. A temporary replacement remains authorised. A former employee continues to appear in accounting software or on a banking platform.

Access rights should be reviewed following every departure, internal move, reorganisation or change in delegated authority. Periodic reviews should also ensure that the combination of permissions does not allow a single individual to initiate and complete a sensitive transaction.

The company should be able to identify who created or amended a supplier record, when the change was made and what verification supported it.

Vue panoramique de montagnes et forêts en automne.

5. Exceptional transactions fall outside the normal process

Procedures generally work well for recurring payments.

Risk increases when transactions are unusual : a significant advance payment, a new supplier, an international payment, an acquisition, or a payment requested by an executive while travelling.

Yet the largest amounts are often associated with precisely these exceptional situations.

A robust procedure should define in advance :

  • The thresholds requiring enhanced approval.
  • The individuals authorised to act when the usual approver is unavailable.
  • The controls applicable to new beneficiaries.
  • The process for urgent or confidential requests.
  • The evidence that must be retained.

An exceptional situation should never result in improvised controls.

A written procedure does not guarantee that the control actually works

Having a procedure is necessary, but it does not demonstrate that the control is effective in practice.

A control may be properly documented yet rarely performed, inadequately evidenced or easily circumvented. It may also depend on a single individual, whose absence leads teams to adapt the rules under time pressure.

An audit should therefore go beyond simply reviewing written procedures. It should follow a transaction from beginning to end and test the situations in which the control framework is most likely to fail :

  • A supplier submits new bank details
  • An urgent invoice arrives while the usual approver is absent
  • A payment falls just below an authorisation threshold
  • A confidential request appears to come from senior management

The right question is not simply : “ Does the procedure exist ? ”

The decisive question is : ” Does it withstand a transaction that appears credible, urgent and consistent with the company’s usual practices ? “

Montagnes rocheuses brumeuses avec sommets escarpés et neige.
Vue panoramique de KAERUS Staging au crépuscule avec montagnes et ville illuminée.
Vue panoramique de montagnes enneigées et forêt automnale.
Forêt dense avec brume matinale et arbres hauts.
Montagnes majestueuses au coucher du soleil avec des roches escarpées.
Lac paisible entouré de montagnes enneigées et de forêts.
Vue panoramique de montagnes et forêts en automne.

What Kaerus analyses within the payment cycle

Preventing bank transfer fraud is not solely an IT security issue. It also depends on how financial internal controls are designed and applied.

Kaerus analyses the entire payment cycle :

  1. Supplier onboarding
  2. Receipt and approval of the invoice
  3. Any changes to bank details
  4. Preparation of the payment
  5. Bank authorisation
  6. Post-payment review

At each stage, our analysis looks in particular for :

  • Excessive concentration of responsibilities
  • Approval based on a single source of information
  • Excessively broad access rights
  • A lack of evidence or audit trail
  • Exceptions that allow the normal process to be bypassed

This approach does not claim to eliminate all risk.

Its purpose is to reduce the likelihood that a fraudulent transaction could be created, approved, paid and recorded without triggering an alert.

Control before appearance becomes evidence

The most effective financial fraud is not necessarily the fraud that appears extraordinary. It is the fraud that resembles the company’s normal operations closely enough not to interrupt the process.

A genuine invoice, a known supplier and an authorised approval therefore do not guarantee that the beneficiary is the correct one.

Internal controls must be designed around this reality: an email account can be compromised, an identity can be impersonated, and an urgent request can appear entirely credible.

Protection therefore depends on independent verification, segregation of duties, effective management of access rights and a clear audit trail of decisions..

“ A procedure is not robust simply because it is written down. It is robust when it withstands urgency, impersonation and human error. ”

Frequently asked questions about bank transfer fraud

What is fraudulent bank details substitution ?

Fraudulent bank details substitution involves replacing the legitimate beneficiary’s bank details in order to divert a payment to an account controlled by a fraudster.

It can affect a genuine invoice or take place within a genuine email exchange after an email account has been compromised.

How should a change to a supplier’s bank details be verified ?

The change should be confirmed through an independent channel by contacting a known representative using contact details already held on file.

Verification should not rely solely on the contact details contained in the email requesting the change.

The verification should be documented and retained.

Does dual approval of bank payments prevent fraud ?

Not necessarily.
It is effective only when the two approvals involve separate checks and rely on independent sources of information.

Two approvals based on the same compromised email may simply confirm the same fraudulent information twice.

At Kaerus, an audit is not limited to checking that transactions have been correctly recorded. It also involves understanding how an unusual transaction could be authorised, paid and recorded without triggering an alert.

Kind regards,
Rabah Lamraoui
Chartered Accountant
www.kaerus.fr

Sources

-Cybermalveillance.gouv.fr, 2025 Activity Report, published in March 2026.
-Cybermalveillance.gouv.fr, What to do in the event of payment fraud or fraudulent bank details?
-Compagnie nationale des commissaires aux comptes, NEP 240, Consideration of the possibility of fraud in the audit of financial statements.
-Compagnie nationale des commissaires aux comptes, NEP 315, Understanding the entity and its environment and assessing the risk of material misstatement in the financial statements.