Skip to content

Checklist

Fund Transfer Fraud Prevention Checklist

Phishing-based fund transfer scams succeed when urgency overrides process, and the defense is governance rather than software: documented authorization, verification that is normal to perform, and a record that survives the person who made it. Work through this checklist with your finance or audit committee, download the editable Word file, or print it.

Organization type

Swaps the content, guidance, and download to fit your board.

Corporate board — protecting funds from phishing-based transfer scams

Organization

 

Prepared by

 

Date

 

Next board review date

 

  1. 1. How to use this checklist

    Work the sections in order, then use the two tables at the end to record where the organization stands today. The point is not to score well; it is to find the one or two controls that are missing before an attacker finds them. Bring the completed sheet to the finance or audit committee and agree owners and dates.

  2. 2. Authorization and dual approval

    Every movement of funds — wire, ACH, check, or card — requires two named approvers, and no officer, director, or employee may override the rule by email or text. Set dollar bands so the second approver is clear before anyone is under pressure, and confirm that treasury, payroll, and vendor payments all follow the same rule.

    • Current rule for dual approval (state it in one sentence):
    • Bands and approvers that need board action:
  3. 3. Communication rules

    Financial instructions — payment requests, bank-detail changes, account updates — are not accepted from personal email accounts or text messages, and staff are told in writing to treat them as unverified. Official payment requests come from organizational addresses, and role-based addresses such as treasurer@ or finance@ are used instead of a single person's inbox.

    • Addresses authorized to request payment:
    • Message to staff and volunteers about personal-email requests:
  4. 4. Verification of unusual or urgent requests

    Any request that is new, urgent, or out of pattern is verified by phone or in person using a number or contact already on file — never a number or link inside the message itself. Verification is a routine step, not an accusation, and no deadline justifies skipping it.

    • Who verifies, and with what contact list:
    • Requests that trigger verification (list the patterns):
  5. 5. Vendor and invoice controls

    New vendors and changed bank details are confirmed before the first payment, invoice bank details are compared to the signed contract or purchase order, and one person cannot both enter a vendor and release payment.

    • Who confirms new vendor details:
    • Where vendor changes are logged:
  6. 6. Documentation and audit trail

    Every approval is recorded with the amount, payee, both approvers, and the verification performed, so the file answers the question later without anyone's memory. Keep the record in the accounting system or a shared folder that survives staff turnover, and review the log of flagged and refused requests at least quarterly.

    • Where approvals are recorded:
    • Who reviews the exception log, and how often:
  7. 7. Training and culture

    Directors and volunteers get short annual training on what these scams look like, and leaders say out loud that being questioned about a payment is expected. If saying “I need to confirm this before I pay” feels awkward or risky, the policy will quietly stop being followed.

    • Date of the next training for directors and volunteers:
    • How leaders signal that verification is welcome:
  8. 8. What the board should see each year

    The board receives the policy itself, the exception log, any attempted or completed fraud, and confirmation that training happened. Near misses belong in the report — they are the cheapest lessons an organization will get.

    • Next board review date for this policy:
    • Items the committee will report:

Controls self-assessment

ControlIn placeOwnerGap or action
Written funds-transfer policy, no email or text overrides   
Two approvals required for every transfer   
Bank-change and payment instructions refused from personal email or text   
Unusual or urgent requests verified on a second channel   
Role-based addresses (treasurer@, finance@) instead of personal inboxes   
Vendor bank details confirmed before first payment   
Approvals documented with amount, payee, and both approvers   
Annual fraud-awareness training for directors and volunteers   

Funds-transfer authority

Amount bandApprovers requiredVerification method
Under $1,000  
$1,000 – $10,000  
$10,000 – $50,000  
Over $50,000  

Guidance notes

  • Two approvals on every transfer is the single control that prevents most phishing losses — write it down and make exceptions impossible.
  • Urgency is the attacker’s lever. A request that cannot wait for verification is the request that most needs it.
  • Verification has to be normal, not awkward: staff and volunteers must be able to question an instruction without offending a senior leader.
  • Keep the detail in policies and procedures the board reviews and updates, not in bylaws.
  • Report near misses to the board. They show where the next attempt will land.
  • This checklist is a board tool, not a substitute for advice from your accountant, insurer, or counsel.

Before you use this checklist

Legal counsel review is recommended
Have qualified legal counsel licensed in your state or jurisdiction review and adapt this material before your board adopts or relies on it.
Educational model language only
This is a general model provided for educational purposes. It is not legal, tax, accounting, compensation, or compliance advice, and it does not create an attorney-client or advisory relationship.
Tailor to your governing documents and law
Align it with your articles of incorporation, bylaws, applicable state corporate or nonprofit statutes, employment law, and any regulatory requirements that apply to your organization.
Adopt and record formally
Approve the process by board vote or resolution, record it in the minutes, keep sensitive material confidential, and review it annually.

This resource is provided for educational purposes only and does not constitute legal, tax, accounting, compensation, or compliance advice, nor does it create an attorney-client or advisory relationship. Adapt it to your organization's governing documents and applicable law, and have qualified legal counsel review it before your board adopts or relies on it.

Want an experienced voice in the controls conversation?

Boards do not need to become fraud investigators; they need to know which two or three controls matter most and whether anyone is actually following them. If that conversation would be useful, I’d be glad to talk.

Request a consultation