Checklist
Fund Transfer Fraud Prevention Checklist
Phishing-based fund transfer scams succeed when urgency overrides process, and the defense is governance rather than software: documented authorization, verification that is normal to perform, and a record that survives the person who made it. Work through this checklist with your finance or audit committee, download the editable Word file, or print it.
Corporate board — protecting funds from phishing-based transfer scams
Organization
Prepared by
Date
Next board review date
1. How to use this checklist
Work the sections in order, then use the two tables at the end to record where the organization stands today. The point is not to score well; it is to find the one or two controls that are missing before an attacker finds them. Bring the completed sheet to the finance or audit committee and agree owners and dates.
2. Authorization and dual approval
Every movement of funds — wire, ACH, check, or card — requires two named approvers, and no officer, director, or employee may override the rule by email or text. Set dollar bands so the second approver is clear before anyone is under pressure, and confirm that treasury, payroll, and vendor payments all follow the same rule.
- Current rule for dual approval (state it in one sentence):
- Bands and approvers that need board action:
3. Communication rules
Financial instructions — payment requests, bank-detail changes, account updates — are not accepted from personal email accounts or text messages, and staff are told in writing to treat them as unverified. Official payment requests come from organizational addresses, and role-based addresses such as treasurer@ or finance@ are used instead of a single person's inbox.
- Addresses authorized to request payment:
- Message to staff and volunteers about personal-email requests:
4. Verification of unusual or urgent requests
Any request that is new, urgent, or out of pattern is verified by phone or in person using a number or contact already on file — never a number or link inside the message itself. Verification is a routine step, not an accusation, and no deadline justifies skipping it.
- Who verifies, and with what contact list:
- Requests that trigger verification (list the patterns):
5. Vendor and invoice controls
New vendors and changed bank details are confirmed before the first payment, invoice bank details are compared to the signed contract or purchase order, and one person cannot both enter a vendor and release payment.
- Who confirms new vendor details:
- Where vendor changes are logged:
6. Documentation and audit trail
Every approval is recorded with the amount, payee, both approvers, and the verification performed, so the file answers the question later without anyone's memory. Keep the record in the accounting system or a shared folder that survives staff turnover, and review the log of flagged and refused requests at least quarterly.
- Where approvals are recorded:
- Who reviews the exception log, and how often:
7. Training and culture
Directors and volunteers get short annual training on what these scams look like, and leaders say out loud that being questioned about a payment is expected. If saying “I need to confirm this before I pay” feels awkward or risky, the policy will quietly stop being followed.
- Date of the next training for directors and volunteers:
- How leaders signal that verification is welcome:
8. What the board should see each year
The board receives the policy itself, the exception log, any attempted or completed fraud, and confirmation that training happened. Near misses belong in the report — they are the cheapest lessons an organization will get.
- Next board review date for this policy:
- Items the committee will report:
Controls self-assessment
| Control | In place | Owner | Gap or action |
|---|---|---|---|
| Written funds-transfer policy, no email or text overrides | |||
| Two approvals required for every transfer | |||
| Bank-change and payment instructions refused from personal email or text | |||
| Unusual or urgent requests verified on a second channel | |||
| Role-based addresses (treasurer@, finance@) instead of personal inboxes | |||
| Vendor bank details confirmed before first payment | |||
| Approvals documented with amount, payee, and both approvers | |||
| Annual fraud-awareness training for directors and volunteers |
Funds-transfer authority
| Amount band | Approvers required | Verification method |
|---|---|---|
| Under $1,000 | ||
| $1,000 – $10,000 | ||
| $10,000 – $50,000 | ||
| Over $50,000 |
Guidance notes
- Two approvals on every transfer is the single control that prevents most phishing losses — write it down and make exceptions impossible.
- Urgency is the attacker’s lever. A request that cannot wait for verification is the request that most needs it.
- Verification has to be normal, not awkward: staff and volunteers must be able to question an instruction without offending a senior leader.
- Keep the detail in policies and procedures the board reviews and updates, not in bylaws.
- Report near misses to the board. They show where the next attempt will land.
- This checklist is a board tool, not a substitute for advice from your accountant, insurer, or counsel.
Before you use this checklist
- Legal counsel review is recommended
- Have qualified legal counsel licensed in your state or jurisdiction review and adapt this material before your board adopts or relies on it.
- Educational model language only
- This is a general model provided for educational purposes. It is not legal, tax, accounting, compensation, or compliance advice, and it does not create an attorney-client or advisory relationship.
- Tailor to your governing documents and law
- Align it with your articles of incorporation, bylaws, applicable state corporate or nonprofit statutes, employment law, and any regulatory requirements that apply to your organization.
- Adopt and record formally
- Approve the process by board vote or resolution, record it in the minutes, keep sensitive material confidential, and review it annually.
This resource is provided for educational purposes only and does not constitute legal, tax, accounting, compensation, or compliance advice, nor does it create an attorney-client or advisory relationship. Adapt it to your organization's governing documents and applicable law, and have qualified legal counsel review it before your board adopts or relies on it.
Want an experienced voice in the controls conversation?
Boards do not need to become fraud investigators; they need to know which two or three controls matter most and whether anyone is actually following them. If that conversation would be useful, I’d be glad to talk.
Request a consultation