CurvedSpace Investment Services
·9 min read

Payment Fraud Controls That Actually Work (Beyond Dual Approval)

A mid-market SaaS company lost $340,000 in eleven days last year. Not to a hack—to a PDF. An AP clerk received an email that looked like it came from the CFO, requesting an urgent wire to a "new vendor." The invoice looked legitimate: right logo, right format, even referenced a real project. Policy required a second approval over $10,000—but the "approver" was the same person, logged in under a delegate account that still had override rights from a system migration eight months earlier.

Three things broke, not one: segregation of duties existed on paper but not in the system; the vendor's bank details were never verified out-of-band; and nobody had reviewed access rights after the migration. The fix cost half a day of IT work. The lesson cost $340K.

Dual approval is necessary—but not sufficient

Most treasury teams think they're protected because they have dual approval on wires. They're not. Most payment fraud succeeds not because controls don't exist, but because exceptions get waved through under time pressure. Here's what actually stops it.

The controls that move the needle

  • Callback verification on new or changed payees. Before any new vendor or changed bank instruction goes live, call back on a number you independently sourced—not one provided in the email. Every time, no exceptions for "urgent" requests. Business email compromise is sophisticated enough that recognizing the sender is no longer a control.
  • Out-of-band confirmation above a threshold. Set a dollar limit (say, $50K) above which a second channel—phone, not email—is required. Attackers compromise inboxes; they rarely compromise a phone call to a known number.
  • Positive Pay on every account. ACH and check Positive Pay lets you block unauthorized items before they clear—not after. Most banks offer it; most teams never turn it on. Enable it on every account, not just high-volume ones—fraudsters target low-activity accounts precisely because they draw less scrutiny.
  • Segregate payee master-file access. The person who approves payments should never be the person who can add or edit payees. This single control eliminates a huge class of insider and social-engineering attacks.
  • Segment accounts by function. Payroll, vendor payments, and operating disbursements should live in separate accounts with separate access. Compromise of one shouldn't expose all three.
  • Reconcile daily and audit access quarterly. Most fraud is caught in reconciliation—a seven-day lag gives bad actors time to obscure activity. And stale user access after migrations or departures is one of the most overlooked exposures in treasury.

Build controls into the workflow, not the post-mortem

Most fraud controls are designed to catch fraud after it happens. That's not a control—that's a post-mortem. The companies that actually reduce payment fraud build their defenses into the workflow itself, before funds ever leave the account. None of this is exotic, and most of it costs nothing to implement. The gap isn't technology—it's discipline. Fraud controls aren't IT's job; they're treasury's.

Have you actually tested your dual-approval control lately, or just assumed it works? CurvedSpace can audit your payment controls and close the gaps before they cost you.