The bank transfer was authorised.
Yet it was fraudulent.
The invoice was genuine. The supplier existed. The amount matched an expected transaction.
The employee had the necessary authorisation, and the payment followed the usual process.
Yet the funds never reached the supplier’s account.
Between receipt of the invoice and execution of the bank transfer, the supplier’s bank details had been replaced. The transaction appeared legitimate because the fraudster had not fabricated it: they had inserted themselves into an existing exchange.
This situation highlights a major shift in risk. Bank transfer fraud no longer relies solely on a crude message or an obviously unusual request. It can replicate the name of a known contact, the amount of a genuine invoice, the timing of an expected payment and even the tone normally used in communications.
According to Cybermalveillance.gouv.fr’s 2025 Activity Report, approximately 13,000 requests for assistance concerned payment fraud, representing a 170% increase. Such cases accounted for 12.8% of assistance requests from professionals and ranked as their third most frequently encountered threat.
In response to this development, checking whether an invoice appears consistent is no longer enough. Companies must assess the robustness of the process used to authorise, prepare and execute payments.
Successful fraud does not always bypass procedures.
Sometimes, it exploits procedures that were not robust enough in the first place.
Five breakdowns in control that should raise a red flag

1. The same person can create a supplier and prepare the payment
When an employee can create a supplier, enter their bank details, record the invoice and prepare the payment, a single set of access rights covers several sensitive stages of the process.
This does not mean that fraud is taking place. It means that an error or fraudulent action could pass through the entire process without encountering an independent control.
Where a complete segregation of duties is not possible, this concentration of responsibilities should be offset by separate approval, periodic supplier reviews and documented controls over sensitive changes.

2. A change to bank details can be approved solely by email
An email is not sufficient evidence when email itself is one of the channels most commonly exploited by fraudsters.
Any change to bank details should be confirmed through a separate channel, with a known contact and using contact details already held on file.
The number provided in the message requesting the change should not be used for verification. It may also belong to the fraudster.
The verification should also be documented, including the date, the identity of the person contacted, the number used and the name of the employee who performed the check.

3. The second approval does not verify anything different
Clicking “approve” twice does not automatically create an effective two-level control.
Two people may authorise the same payment while relying on a single compromised source of information. The second approval can also become little more than a formality when its purpose has not been clearly defined.
Controls should be complementary :
- One person verifies that the invoice and the underlying service are genuine.
- A second person checks the beneficiary and any changes to their bank details.
- Final authorisation is based on independent, traceable evidence.
The number of approvals matters less than the independence of the checks being performed.

4. Access rights do not reflect changes in roles
Access rights often accumulate as an organisation evolves.
An employee changes role but retains their previous permissions. A temporary replacement remains authorised. A former employee continues to appear in accounting software or on a banking platform.
Access rights should be reviewed following every departure, internal move, reorganisation or change in delegated authority. Periodic reviews should also ensure that the combination of permissions does not allow a single individual to initiate and complete a sensitive transaction.
The company should be able to identify who created or amended a supplier record, when the change was made and what verification supported it.

5. Exceptional transactions fall outside the normal process
Procedures generally work well for recurring payments.
Risk increases when transactions are unusual : a significant advance payment, a new supplier, an international payment, an acquisition, or a payment requested by an executive while travelling.
Yet the largest amounts are often associated with precisely these exceptional situations.
A robust procedure should define in advance :
- The thresholds requiring enhanced approval.
- The individuals authorised to act when the usual approver is unavailable.
- The controls applicable to new beneficiaries.
- The process for urgent or confidential requests.
- The evidence that must be retained.
An exceptional situation should never result in improvised controls.
A written procedure does not guarantee that the control actually works
Having a procedure is necessary, but it does not demonstrate that the control is effective in practice.
A control may be properly documented yet rarely performed, inadequately evidenced or easily circumvented. It may also depend on a single individual, whose absence leads teams to adapt the rules under time pressure.
An audit should therefore go beyond simply reviewing written procedures. It should follow a transaction from beginning to end and test the situations in which the control framework is most likely to fail :
- A supplier submits new bank details
- An urgent invoice arrives while the usual approver is absent
- A payment falls just below an authorisation threshold
- A confidential request appears to come from senior management
The right question is not simply : “ Does the procedure exist ? ”
The decisive question is : ” Does it withstand a transaction that appears credible, urgent and consistent with the company’s usual practices ? “







What Kaerus analyses within the payment cycle
Preventing bank transfer fraud is not solely an IT security issue. It also depends on how financial internal controls are designed and applied.
Kaerus analyses the entire payment cycle :
- Supplier onboarding
- Receipt and approval of the invoice
- Any changes to bank details
- Preparation of the payment
- Bank authorisation
- Post-payment review
At each stage, our analysis looks in particular for :
- Excessive concentration of responsibilities
- Approval based on a single source of information
- Excessively broad access rights
- A lack of evidence or audit trail
- Exceptions that allow the normal process to be bypassed
This approach does not claim to eliminate all risk.
Its purpose is to reduce the likelihood that a fraudulent transaction could be created, approved, paid and recorded without triggering an alert.
Frequently asked questions about bank transfer fraud
Fraudulent bank details substitution involves replacing the legitimate beneficiary’s bank details in order to divert a payment to an account controlled by a fraudster.
It can affect a genuine invoice or take place within a genuine email exchange after an email account has been compromised.
The change should be confirmed through an independent channel by contacting a known representative using contact details already held on file.
Verification should not rely solely on the contact details contained in the email requesting the change.
The verification should be documented and retained.
Not necessarily.
It is effective only when the two approvals involve separate checks and rely on independent sources of information.
Two approvals based on the same compromised email may simply confirm the same fraudulent information twice.
At Kaerus, an audit is not limited to checking that transactions have been correctly recorded. It also involves understanding how an unusual transaction could be authorised, paid and recorded without triggering an alert.
Kind regards,
Rabah Lamraoui
Chartered Accountant
www.kaerus.fr
Sources
-Cybermalveillance.gouv.fr, 2025 Activity Report, published in March 2026.
-Cybermalveillance.gouv.fr, What to do in the event of payment fraud or fraudulent bank details?
-Compagnie nationale des commissaires aux comptes, NEP 240, Consideration of the possibility of fraud in the audit of financial statements.
-Compagnie nationale des commissaires aux comptes, NEP 315, Understanding the entity and its environment and assessing the risk of material misstatement in the financial statements.



