Written policy sounds bureaucratic, but when a suspicious banking change arrives at 4:45 on a Friday, a clear paragraph is worth a lot. A payment controls policy tells your accounting team exactly what to do, gives them authority to pause, and shows insurers, lenders, and auditors that the controls are real.
Below is an outline you can adapt to your own organization. It is meant to be short enough that people will read it. Have your attorney, insurer, or auditor review the final version.
1. Purpose and scope
State in a sentence or two why the policy exists: to prevent payments from being diverted to unauthorized accounts through fraud or error. Define who it covers: accounts payable, project managers who approve invoices, executives with payment authority, and anyone who communicates with vendors about payment.
2. Vendor onboarding
New vendors and subcontractors present the first opportunity for fraud. Require:
- A completed vendor form and tax documentation collected through a controlled process.
- Verification that the business is real, using independent sources such as state business records, licensing, insurance certificates, and references.
- Confirmation of banking details with a call to a phone number obtained independently, not from the form or email.
- A named internal sponsor, usually the project manager who requested the vendor.
- Recording who performed each verification step and when.
3. Changes to vendor information
This is the highest-risk section. Specify that any change to banking details, remit-to address, contact person, or payment method:
- Must be requested in writing by an authorized contact at the vendor.
- Must be verified by a phone call to a number already on file, made by someone other than the person who received the request.
- Must be documented in the vendor record with the date, the verifier, and the number called.
- Triggers a hold period before the first payment under new instructions, for example a defined number of business days.
- Never be accepted solely by email, text, or a call received from the requester.
Add that accounts payable staff are expected to treat urgency as a warning sign.
4. Separation of duties
Define who can do what:
- The person who creates or edits vendor records cannot approve or release payments to that vendor.
- Project managers approve invoices for work performed but do not change banking details.
- Release of payment requires a second approver above a threshold set by management.
- Changes to the approval limits require owner or CFO sign-off.
For small teams where full separation is impractical, describe compensating controls, such as an owner reviewing a weekly report of vendor changes.
5. Payment approval and release
Describe the standard path: invoice received, matched to contract or purchase order, approved by the responsible manager, reviewed by accounting, and released. Include special handling for:
- Wire transfers and same-day payments, which require two approvers and callback confirmation.
- First payments to any vendor.
- Payments that differ significantly from the usual pattern for that vendor.
- Retainage and final payments, which often attract fraud attempts.
6. Systems and access
- Multi-factor authentication for email, accounting software, and bank portals.
- Individual user accounts, never shared.
- Regular review of who has access to banking and vendor master records.
- Alerts from the bank and accounting system when vendor banking details change.
7. Executive requests
Include a rule that requests to pay outside normal process, even from the owner or a senior executive, follow the same verification. Staff are explicitly authorized to ask for confirmation by phone and will not be penalized for doing so.
8. Reporting and response
- Anyone who suspects a fraudulent request reports it immediately to a named contact.
- Do not reply to or click anything in the suspicious message.
- If a payment has gone out, call the bank immediately and follow the incident response steps.
- Notify the insurer and consider reporting to law enforcement and the FBI's IC3.
9. Training and review
New accounting staff review the policy at onboarding. All relevant staff receive refreshers at least annually. Management reviews the policy and a sample of vendor changes yearly, and after any incident or near miss.
10. Exceptions
Exceptions require written approval from a named executive and are recorded. Make exceptions rare and visible.
Implementation tips
- Keep the final version to one or two pages.
- Pair it with a short checklist AP staff can use at their desks.
- Test it with a mock request to confirm it works under pressure.
- Tell your vendors about your verification practices so they are not surprised by a callback.
Help from Ironfield Cyber
Ironfield Cyber helps contractors and energy companies draft practical payment control policies, secure the systems that support them, and train finance teams. If you would like a template adapted to your operation, we can help.