5. Putting it into practice
Workplace scenarios
Scenario 1: The supplier's new bank details
An email arrives in accounts payable from a long-standing supplier, mid-thread and referencing a genuine outstanding invoice. It explains that the supplier has switched banks and asks for the account details on file to be updated before the next payment run. It helpfully includes a phone number to call with any questions.
What good looks like: nobody updates anything on the strength of the email, however genuine it looks, because a compromised supplier mailbox produces emails that are real in every respect except the bank details. The clerk calls the supplier on the number already held in the firm's own records, never the one in the email, confirms whether the change is genuine, and records that the call was made. Only then is anything updated.
Scenario 2: The Friday afternoon instruction
At 4.45pm on a Friday, a finance assistant receives an email appearing to come from the managing director, who is travelling. It asks for an urgent payment to secure a confidential acquisition, stresses that nobody else must be told, and says the MD cannot take calls until Monday.
What good looks like: the assistant treats the combination of urgency, secrecy, and a request to bypass the normal process as the biggest red flag in the message. She does not reply or pay. She verifies through a different channel, calling the MD's known number or speaking to another senior colleague, knowing that no genuine manager will object to a payment being checked. The attempt is then reported so colleagues can be warned.
Scenario 3: The colleague who is always there
A purchase ledger supervisor has not taken more than the odd day of leave in three years, resists cross-training anyone on supplier records, is short-tempered whenever audit asks about his area, and has recently started driving a car that seems well beyond his salary.
What good looks like: a colleague recognises that no single flag proves anything, but a cluster of flags around one person and one process is exactly when to act. She does not confront him, search his files, or share her suspicion around the office. She makes a private note of what she has observed, with dates, and raises it through the proper route, such as her manager or the whistleblowing channel, and then lets the organisation investigate.
Scenario 4: The payment that already went
On Monday morning, the finance team realises that Friday's payment run included an invoice paid to a fraudulent account after a convincing mandate fraud.
What good looks like: the firm contacts its bank immediately, before anything else, to attempt recovery, because speed matters more than anything. It then reports to Action Fraud, preserves the fraudulent emails with their headers rather than deleting them, and reviews how the change got through so the verification gap is closed. Staff involved are supported, not scapegoated, so the next near-miss gets reported quickly.
› Course contents
What fraud is and the law
Common frauds against organisations
Internal fraud and red flags
Prevention and reporting
Putting it into practice