United Kingdom flagIndependent UK business banking research
UK Business Banking Research · BanksGB
Business typesCards & expensesCash flowSecurityDigital bankingMerchant servicesFX & tradeInsightsAll topics
BanksGB · Security

Invoice fraud controls that work before the payment leaves

Practical controls for UK businesses to prevent invoice and payment diversion fraud, including bank-detail verification, dual approval, MFA, Confirmation of Payee and incident response.

Invoice fraud succeeds when a believable email causes a genuine employee to send real money to the wrong account. The strongest defence is therefore a payment process that assumes email alone is not enough evidence to change bank details.

Understand why a fraudulent invoice can look completely genuine

Business Email Compromise and payment diversion fraud do not always arrive as badly written spam. The NCSC warns that criminals can impersonate people an organisation regularly deals with, use compromised email accounts and request payment to a different bank account. If an attacker can read an email thread, the message may contain correct project details, genuine invoice numbers and the normal writing style of the supplier.

The red flag is often not the invoice itself but the requested change in payment destination or urgency. A fraudster may wait until a real invoice is due and then insert new bank details. Staff should therefore be trained to treat a change of beneficiary details as a security event, even when every other part of the email looks normal.

Verify every supplier bank-detail change outside the email that requested it

The NCSC recommends verifying important email requests using another communication method. For supplier bank changes, use a telephone number already held in your supplier master data, a known contact, an authenticated supplier portal or another independently established channel. Do not call the number printed on the email requesting the change because the attacker can change that too.

Record who requested the change, who verified it, the method used and when the verification occurred. For high-value suppliers, consider requiring two people to complete the change. The control should be easy enough to use every time. If staff routinely bypass it because it takes half an hour to find a contact number, the process needs redesign rather than another reminder email.

Use payment approval rules that increase with risk

Apply the principle of least privilege. The NCSC advises limiting privileged access to people who need it and regularly reviewing permissions. A junior accounts user may need to enter invoices but not add beneficiaries or release £100,000 payments. A director may approve large payments but should not be the only person capable of making payroll work when they are unavailable.

Use dual approval for payments where a mistake would materially hurt the business, especially first payments to a new beneficiary, changed bank details and unusually large transfers. A simple control could require a second approver above £10,000 and for every beneficiary change regardless of amount. The exact threshold is a business decision. The principle is that the riskiest action should not depend on one person reading one email correctly.

Protect finance email accounts because payment controls start before online banking

Enable multi-factor authentication for email and other finance systems, remove leavers promptly and review forwarding or mailbox rules if compromise is suspected. The NCSC has documented incidents where attackers created rules that diverted messages containing words such as payment, invoice and bank details, allowing the criminal to manipulate the conversation while hiding warnings from the genuine supplier.

Teach staff to report unusual requests without embarrassment. A culture where employees feel pressured to satisfy a supposed chief executive immediately is ideal for the attacker. A good policy gives them permission to slow down, verify the request and challenge a senior colleague. Fraud prevention is partly a technical control and partly a management behaviour.

Use Confirmation of Payee as a warning system, not as permission to stop checking

Confirmation of Payee compares the account details entered for a payment with the name held on the recipient account where the service is available. UK Finance advises users to be particularly cautious when they receive a no-match response and warns against being told to ignore it. A mismatch should stop the payment until the beneficiary is independently checked.

A match is useful but does not prove the invoice itself is legitimate or that the person asking for payment has authority. Criminals can control accounts in plausible names, and some payments or providers may not support a full check. Confirmation of Payee should reinforce the supplier-verification process, not replace it.

If a fraudulent payment may have been sent, act immediately

The NCSC advises contacting the bank directly as soon as possible after a suspected fraudulent payment. Use the bank's official contact details rather than anything in the suspicious email. Tell the bank it may be a scam transfer and provide the payment amount, time, beneficiary and reference. Speed matters because the receiving account may move the funds onward quickly.

At the same time, notify whoever manages IT or email security, preserve the relevant messages and account logs, and reset compromised credentials where appropriate. Report the incident through the official UK fraud and cyber reporting routes that apply to your location. Then identify the control that failed. If the answer is simply "the employee should have noticed", the business has not fixed the process that allowed one deceptive email to authorise a real payment.

Editorial Verdict

The most effective invoice-fraud control is independent verification of beneficiary changes before money moves. Combine that with individual user access, multi-factor authentication, proportionate dual approval and a culture that allows staff to challenge urgent payment requests.

Do not rely on email appearance, seniority or Confirmation of Payee alone. Design the process so one compromised mailbox cannot change a supplier record and release a material payment without a second piece of evidence. If a suspicious payment has already been sent, contact the bank immediately and treat the event as both a fraud incident and a possible account compromise.

Sources

Keep the banking structure tied to the business model

Use the provider directory, comparisons and practical guides to narrow the questions before choosing products.

Start comparison