Shocked man in office being tricked by hacker emerging from laptop holding bank transfer document.

The Familiar Request That Breaks the Control You Thought You Had

July 20, 2026

The Familiar Request That Breaks the Control You Thought You Had

Most CPA firms do not lose money because a scam looks suspicious.

They lose money because it looks routine.

A vendor sends updated ACH details. A controller sees an invoice that matches prior billing. A partner is out, so someone else approves it. Four minutes later, the payment is gone.

This is Business Email Compromise, or BEC. It remains one of the most costly financial attacks businesses deal with. Last year alone, it drove 24,768 reported complaints and more than $3 billion in reported losses. Nearly three quarters of organizations reported BEC incidents, and spoofed emails were the most common version.

That matters for CPA firms because your business runs on trust, timing, and financial accuracy. Those are the exact conditions BEC is built to exploit.

The gap is not awareness.

The gap is operational discipline when the request looks normal.

How This Actually Happens Step by Step

A payment-change attack usually follows the same pattern.

  1. A vendor mailbox is compromised, or a lookalike domain is created
  2. The attacker waits for a normal billing cycle, a filing rush, or a vacation gap
  3. A message arrives with updated bank details or revised payment instructions
  4. The tone, signature, and formatting match prior emails closely enough to pass a quick glance
  5. The record is updated without independent verification
  6. The payment is released
  7. The real vendor follows up later asking why they were never paid

This is why BEC keeps working.

It does not need a noisy breach. It only needs one believable message and one rushed decision.

We see this pattern repeatedly during busy periods because the attack is built around normal business behavior, not technical sophistication.

Why This Hits CPA Firms Harder

In a CPA firm, a payment mistake is never just a payment mistake.

It becomes:

  • A direct financial loss
  • A control failure
  • A trust issue
  • A client confidence problem
  • A leadership problem, because someone now has to explain how it happened

You are already carrying responsibility for client money, client data, and your firm's reputation. That is why this kind of fraud feels personal when it lands.

The firms that struggle most are not careless.

They are busy, lean, and relying on familiar workflows that have not been tightened where they need to be.

Payment Change Verification Policy Minimum Standard

If you want a control your team can actually follow, start here.

Payment Change Verification Policy

  • Any banking or ACH change must be verified by phone using a known number already on file
  • Email reply cannot be used as verification
  • Two separate roles must approve the change before payment is released
  • The person who updates vendor banking information cannot approve or release the payment alone
  • Same-day processing is blocked unless the exception rule below is met
  • Every verification must be documented in a required note field before the payment can move forward
  • The note must include who verified it, when it was verified, what number was called, and who approved it
  • Backup approvers follow the same policy with no shortcuts

This is what turns a policy into a control.

It removes judgment calls in the middle of a busy day.

How This Gets Enforced Day to Day

A policy only matters if the system supports it.

Here is what strong enforcement looks like in practice.

In the AP System

  • Bank detail changes trigger a flag for secondary review
  • Required fields prevent the change from being saved without a verification note
  • Same-day banking changes are routed into an exception queue
  • Approval logs capture who changed the record, who approved it, and when

In the Accounting Workflow

  • Segregation of duties is enforced so one person cannot create, approve, and release the same payment
  • Vendor record changes and payment approvals sit with different roles
  • Payment batches cannot be released if the change history is incomplete

In Management Review

  • Exception requests are reviewed weekly, not just approved in the moment
  • Vendor banking changes are spot-checked against approval logs
  • Repeated exception use by the same team or person is treated as a process problem

That is what control looks like when it is real.

Not a written rule buried in a handbook. A workflow that holds under pressure.

Exception Handling Rule

Every firm has urgent payments. That is exactly why exceptions need their own control.

What Qualifies as an Exception

  • A documented client deadline that cannot be moved
  • A legal or contractual obligation with a same-day payment requirement
  • A genuine operational disruption where delay creates immediate business harm

Who Approves the Exception

  • The finance manager or controller
  • One additional leader who is not the person processing the payment

What Still Must Happen

  • Phone verification to a known number is still required
  • The exception reason must be logged before release
  • The amount, vendor, date, and approvers must be recorded
  • The exception is reviewed in the next weekly control review

Urgency cannot mean process disappears.

It means the exception path is already defined before the pressure shows up.

What Strong Firms Do Differently

Strong firms do not rely on heroics.

They rely on repeatability.

Payments

  • Every payment-detail change is verified outside email
  • Trusted vendors are not exempt from control
  • Verification is documented every time

Approvals

  • Dual approval is enforced for all vendor bank changes
  • Backup approvers use the same rules as primary approvers
  • Urgent requests move through the exception path, not around it

Access

  • Vendor and contractor access is reviewed every quarter
  • Access removal is logged when projects end
  • Each vendor has a named internal owner

Oversight

  • Approval logs are reviewed, not just stored
  • Exceptions are counted and discussed
  • Missing documentation is treated as a control failure, not an administrative issue

That is how firms stay calm and audit-ready at the same time.

The Vendor Access Control Most Firms Skip

Payment fraud is one risk.

Unmanaged vendor access is the other one that quietly grows in the background.

A former contractor still has SharePoint access. An old software vendor still has credentials. An API connection remains active because nobody wants to break anything.

The simplest fix is a vendor access register.

Vendor Access Register

Track these five fields for every outside party:

  • Vendor name
  • System or data they can access
  • Level of access
  • Internal owner
  • Last reviewed date

If your firm cannot produce that list quickly, your access control is not mature yet.

That does not mean you need a giant project.

It means you need a simple register and a quarterly review habit.

A Failure Point That Happens Fast

Here is a realistic example.

A controller receives a payment-change request from a long-time vendor. The email thread looks legitimate. The primary approver is out. The invoice amount is expected.

The banking record is updated.

The payment is released in four minutes.

Two days later, the real vendor calls.

Nothing about that event looked dramatic while it was happening. That is the point. In cases like this, the loss is often in the tens or hundreds of thousands. The damage starts with speed and ends with a missing verification step.

What an Outside Evaluator Notices Immediately

An outside evaluator does not start by asking how many security tools you own.

They ask whether the control actually works.

They look for:

  • Proof that banking changes were independently verified
  • Evidence that duties are separated in the accounting system
  • Approval logs that show who changed what and who approved it
  • A clear exception process for urgent payments
  • A current vendor access register with named owners and review dates

If those things exist, the firm looks controlled.

If they do not, the issue is not just cyber risk. It is a process maturity problem.

For a CPA firm, that affects how confident you sound when a client, auditor, insurer, or partner asks how you protect financial workflows.

Score Your Firm in 30 Seconds

Answer yes or no.

  1. Do all vendor banking changes require phone verification using a known number
  2. Are two people required to approve every banking change
  3. Does your AP system require a verification note before the change can move forward
  4. Can the person who edits vendor banking details also release the payment
  5. Do you have a written exception rule for urgent same-day payments
  6. Do you review vendor access every quarter
  7. Do you maintain a current vendor access register

Your Score

  • 0 to 2 yes answers means high risk
  • 3 to 5 yes answers means moderate risk
  • 6 to 7 yes answers means controlled

This is not about perfection.

It is about whether your controls hold when the day gets busy.

What To Do Next Week

Block 30 minutes next week with the people who own accounts payable, vendor setup, and outside vendor relationships.

Use that time to do four things:

  1. Write down your current payment-change workflow exactly as it happens now
  2. Compare it to the minimum standard in this article
  3. Define your exception path for urgent payments
  4. Build your first vendor access register, even if it starts as a simple spreadsheet

Do not widen the project.

Do not wait for a full audit.

Just fix the first control gap you can already see.

Take the Next Step

Schedule your 10 minute discovery call.

Use that time to walk through your payment-change workflow, exception path, and vendor access register. 911 IT will help you identify the first control gap worth fixing so you can tighten the process without turning it into a bigger project than it needs to be.