Fraud & assurance

Controls that fire, and that admit what they cannot see.

Every system claims controls. These catch what a value ladder is blind to: a supplier on a sanctions list, a bank account that moved the week before a large payment, patterns across purchases that each looked ordinary on the day.

The commonest loss there is

Invoice redirection is carried out through your own honest people.

The request arrives by email, an honest clerk enters it, an honest colleague confirms it. Every segregation rule is satisfied and the money still leaves for the wrong account. What is left to notice is the timing.

  • WatchesAn account that moved shortly before a large payment, moved twice in a month, or moved away and back to one the supplier held before
  • OrdersBy the amount owed to each supplier, largest first — because there is never time to confirm everything, so the order itself is the control
  • Your choiceWarn and record, or refuse payment until somebody confirms the account. Refusing is stronger and will hold a payment run on the day you switch it on, which is why it is not the default
  • The adviceConfirm by calling a number you already held — never one from the message asking for the change. That substitution is the attack
.../suppliers/bank-changes
Bank detail changes — Recent changes, ordered by what you owe that supplier.
Bank detail changesRecent changes, ordered by what you owe that supplier.
Who you are about to pay

A match is not a finding, and that is the whole design.

These lists are full of common names and most matches are a different party. What makes screening a control is not the matching: it is that every match is looked at once, by a person, with the reason recorded.

  • The listsOFAC, the UN consolidated list and the UK OFSI list, refreshed on a schedule, with the entry count and the date each last changed
  • RefusesA confirmed designation blocks award and payment whatever the mode is set to. Making funds available to a designated party is an offence, not a policy preference
  • Cannot lieAn empty queue with no lists loaded means nothing has been screened, not that nothing was found — and the screen says so
  • AuditableThe score that produced a match is stored with it, so changing the threshold later cannot silently rewrite decisions already made
.../suppliers/screening
Sanctions screening — Three published lists, and the queue of matches awaiting a decision.
Sanctions screeningThree published lists, and the queue of matches awaiting a decision.
Patterns, not single acts

Four checks that read across many purchases at once.

Other controls ask their question at the moment somebody acts. These ask about a pattern across many acts, each ordinary on the day — exactly the shape of the losses that get found late.

  • Duplicate paymentThe same invoice paid twice, compared across orders rather than only within one
  • Retrospective coverA purchase order raised after the invoice it authorises
  • Threshold huggingValues that sit just under an approval band, repeatedly
  • Round-number biasValues rounder than your own ledger usually runs. The screen calls it the weakest of the four, and states each check's blind spots
.../governance/fraud
Fraud indicators — Four checks over the ledger, with the evidence attached to each lead.
Fraud indicatorsFour checks over the ledger, with the evidence attached to each lead.
Getting in, and being shut out

The controls a security questionnaire asks about first.

A second factor, and the ability to cut off access during a live incident, are the first things an insurer asks about. They are also the first things a demonstration never shows.

  • Second factorStandard authenticator codes, built in, with no SMS and no third-party service. Required for administrators, or for everybody except supplier portal accounts
  • Cannot strand youTurning the requirement on locks nobody out — anyone who has not enrolled is signed in and taken to enrolment
  • Lock-outBlock sign-in for everybody, one role, or one named person. Sessions end at once; administrators are never caught, so responders are not stranded
  • Single sign-onOIDC with Microsoft Entra ID, Google Workspace or Okta, and SCIM provisioning from the directory, which never sets anyone's role
.../settings#set-lockout
Emergency lock-out — Three levels, because “everybody” is usually too blunt.
Emergency lock-outThree levels, because “everybody” is usually too blunt.