The Familiar Request That Breaks the Control You Thought You Had
Most CPA firms do not lose money because a scam looks suspicious.
They lose money because it looks routine.
A vendor sends updated ACH details. A controller sees an invoice that
matches prior billing. A partner is out, so someone else approves it. Four
minutes later, the payment is gone.
This is Business Email Compromise, or BEC. It remains one of the most
costly financial attacks businesses deal with. Last year alone, it drove 24,768
reported complaints and more than $3 billion in reported losses. Nearly three
quarters of organizations reported BEC incidents, and spoofed emails were the
most common version.
That matters for CPA firms because your business runs on trust, timing,
and financial accuracy. Those are the exact conditions BEC is built to exploit.
The gap is not awareness.
The gap is operational discipline when the request looks normal.
How This Actually Happens Step by Step
A payment-change attack usually follows the same pattern.
- A vendor
mailbox is compromised, or a lookalike domain is created
- The attacker
waits for a normal billing cycle, a filing rush, or a vacation gap
- A message
arrives with updated bank details or revised payment instructions
- The tone,
signature, and formatting match prior emails closely enough to pass a
quick glance
- The record is
updated without independent verification
- The payment is
released
- The real vendor
follows up later asking why they were never paid
This is why BEC keeps working.
It does not need a noisy breach. It only needs one believable message and
one rushed decision.
We see this pattern repeatedly during busy periods because the attack is
built around normal business behavior, not technical sophistication.
Why This Hits CPA Firms Harder
In a CPA firm, a payment mistake is never just a payment mistake.
It becomes:
- A direct
financial loss
- A control
failure
- A trust issue
- A client
confidence problem
- A leadership
problem, because someone now has to explain how it happened
You are already carrying responsibility for client money, client data,
and your firm's reputation. That is why this kind of fraud feels personal when
it lands.
The firms that struggle most are not careless.
They are busy, lean, and relying on familiar workflows that have not been
tightened where they need to be.
Payment Change Verification Policy Minimum Standard
If you want a control your team can actually follow, start here.
Payment Change Verification Policy
- Any banking or
ACH change must be verified by phone using a known number already on file
- Email reply
cannot be used as verification
- Two separate
roles must approve the change before payment is released
- The person who
updates vendor banking information cannot approve or release the payment
alone
- Same-day
processing is blocked unless the exception rule below is met
- Every
verification must be documented in a required note field before the
payment can move forward
- The note must
include who verified it, when it was verified, what number was called, and
who approved it
- Backup
approvers follow the same policy with no shortcuts
This is what turns a policy into a control.
It removes judgment calls in the middle of a busy day.
How This Gets Enforced Day to Day
A policy only matters if the system supports it.
Here is what strong enforcement looks like in practice.
In the AP System
- Bank detail
changes trigger a flag for secondary review
- Required fields
prevent the change from being saved without a verification note
- Same-day
banking changes are routed into an exception queue
- Approval logs
capture who changed the record, who approved it, and when
In the Accounting Workflow
- Segregation of
duties is enforced so one person cannot create, approve, and release the
same payment
- Vendor record
changes and payment approvals sit with different roles
- Payment batches
cannot be released if the change history is incomplete
In Management Review
- Exception
requests are reviewed weekly, not just approved in the moment
- Vendor banking
changes are spot-checked against approval logs
- Repeated
exception use by the same team or person is treated as a process problem
That is what control looks like when it is real.
Not a written rule buried in a handbook. A workflow that holds under
pressure.
Exception Handling Rule
Every firm has urgent payments. That is exactly why exceptions need their
own control.
What Qualifies as an Exception
- A documented
client deadline that cannot be moved
- A legal or
contractual obligation with a same-day payment requirement
- A genuine
operational disruption where delay creates immediate business harm
Who Approves the Exception
- The finance
manager or controller
- One additional
leader who is not the person processing the payment
What Still Must Happen
- Phone
verification to a known number is still required
- The exception
reason must be logged before release
- The amount,
vendor, date, and approvers must be recorded
- The exception
is reviewed in the next weekly control review
Urgency cannot mean process disappears.
It means the exception path is already defined before the pressure shows
up.
What Strong Firms Do Differently
Strong firms do not rely on heroics.
They rely on repeatability.
Payments
- Every
payment-detail change is verified outside email
- Trusted vendors
are not exempt from control
- Verification is
documented every time
Approvals
- Dual approval
is enforced for all vendor bank changes
- Backup
approvers use the same rules as primary approvers
- Urgent requests
move through the exception path, not around it
Access
- Vendor and
contractor access is reviewed every quarter
- Access removal
is logged when projects end
- Each vendor has
a named internal owner
Oversight
- Approval logs
are reviewed, not just stored
- Exceptions are
counted and discussed
- Missing
documentation is treated as a control failure, not an administrative issue
That is how firms stay calm and audit-ready at the same time.
The Vendor Access Control Most Firms Skip
Payment fraud is one risk.
Unmanaged vendor access is the other one that quietly grows in the
background.
A former contractor still has SharePoint access. An old software vendor
still has credentials. An API connection remains active because nobody wants to
break anything.
The simplest fix is a vendor access register.
Vendor Access Register
Track these five fields for every outside party:
- Vendor name
- System or data
they can access
- Level of access
- Internal owner
- Last reviewed
date
If your firm cannot produce that list quickly, your access control is not mature yet.
That does not mean you need a giant project.
It means you need a simple register and a quarterly review habit.
A Failure Point That Happens Fast
Here is a realistic example.
A controller receives a payment-change request from a long-time vendor.
The email thread looks legitimate. The primary approver is out. The invoice
amount is expected.
The banking record is updated.
The payment is released in four minutes.
Two days later, the real vendor calls.
Nothing about that event looked dramatic while it was happening. That is
the point. In cases like this, the loss is often in the tens or hundreds of
thousands. The damage starts with speed and ends with a missing verification
step.
What an Outside Evaluator Notices Immediately
An outside evaluator does not start by asking how many security tools you
own.
They ask whether the control actually works.
They look for:
- Proof that
banking changes were independently verified
- Evidence that
duties are separated in the accounting system
- Approval logs
that show who changed what and who approved it
- A clear
exception process for urgent payments
- A current
vendor access register with named owners and review dates
If those things exist, the firm looks controlled.
If they do not, the issue is not just cyber risk. It is a process
maturity problem.
For a CPA firm, that affects how confident you sound when a client,
auditor, insurer, or partner asks how you protect financial workflows.
Score Your Firm in 30 Seconds
Answer yes or no.
- Do all vendor
banking changes require phone verification using a known number
- Are two people
required to approve every banking change
- Does your AP
system require a verification note before the change can move forward
- Can the person
who edits vendor banking details also release the payment
- Do you have a
written exception rule for urgent same-day payments
- Do you review
vendor access every quarter
- Do you maintain
a current vendor access register
Your Score
- 0 to 2 yes
answers means high risk
- 3 to 5 yes
answers means moderate risk
- 6 to 7 yes
answers means controlled
This is not about perfection.
It is about whether your controls hold when the day gets busy.
What To Do Next Week
Block 30 minutes next week with the people who own accounts payable,
vendor setup, and outside vendor relationships.
Use that time to do four things:
- Write down your
current payment-change workflow exactly as it happens now
- Compare it to
the minimum standard in this article
- Define your
exception path for urgent payments
- Build your
first vendor access register, even if it starts as a simple spreadsheet
Do not widen the project.
Do not wait for a full audit.
Just fix the first control gap you can already see.
Take the Next Step
Schedule your 10 minute discovery call.
Use that time to walk through your payment-change workflow, exception
path, and vendor access register. 911 IT will help you identify the first
control gap worth fixing so you can tighten the process without turning it into
a bigger project than it needs to be.
