Payment Diversion Policy: A Template Outline for Finance Teams

Use this outline to write a short, enforceable policy for vendor banking changes, payment approvals, and wire requests that protects contractors from fraud.

3 min readBy Ironfield Cyber Team

Most contractors know payment fraud exists. Fewer have written down exactly what the accounts payable team should do when a vendor asks to change bank details or when an executive appears to request an urgent wire. Without a written rule, the process depends on whoever happens to be at the desk, and under pressure people skip steps.

This post outlines a one-to-two-page policy you can adapt. It is intentionally short, because policies that are too long do not get followed.

Purpose and scope

State in a couple of sentences what the policy protects: company funds from fraudulent or mistaken payments. Say who it covers: accounts payable, payroll, project managers who approve pay applications, controllers, and executives who can authorize payments. Include all payment methods: checks, ACH, wires, and virtual cards.

Section 1: Vendor setup and banking changes

Write these rules as plain requirements:

  1. Every new vendor must provide a signed W-9 and banking details on a company form, not only by email.
  2. Banking details are confirmed by phone, using a number from an independent source, such as a prior contract, not from the request itself.
  3. The person who confirms the change is recorded, along with the date and the name of the vendor contact who confirmed it.
  4. A second employee reviews and approves the change before it is active.
  5. Requests received by email that appear to come from executives or vendors are never sufficient on their own.

What counts as a change

Define it broadly: new account numbers, new routing numbers, a change in account name, a move from check to ACH, or a different remittance address.

Section 2: Payment approval and release

  • Payments above a stated threshold require two approvers.
  • The person who creates or edits a vendor record cannot release payment to that vendor.
  • Wire transfers require approval from a named officer and a callback to the requester when the request came by email or text.
  • No payment is released based on a request that says the matter is confidential or urgent without verification through a second channel.

Choose thresholds that match your business. The point is that an unusual amount triggers more scrutiny.

Section 3: Executive and internal requests

Impersonating the owner or CFO is a common tactic. Include a rule such as: any request to pay, buy gift cards, change payroll deposits, or share financial information that arrives by email or text is verified by phone or in person, regardless of who appears to have sent it. State plainly that employees will never be penalized for taking the time to verify, even when the request appears to come from the owner.

Section 4: Payroll direct deposit changes

Direct deposit changes are a frequent target. Require that employees submit changes through a verified system or in person, and send a confirmation to the employee at their existing contact details.

Section 5: Subcontractor and pay application payments

For pay applications and lien waivers, confirm that the payee matches the contract and that remittance details have not changed since the last payment. If they changed, apply the Section 1 verification.

Section 6: Reporting and response

Define what to do if fraud is suspected:

  1. Contact the bank immediately to request a recall.
  2. Notify the controller and the owner or CFO.
  3. Preserve emails and records, and avoid deleting anything.
  4. Notify IT so that mailboxes can be reviewed and passwords reset.
  5. Report to the FBI's IC3 and to your insurance carrier.

Include the bank's fraud line and your insurer's claims contact right in the policy so nobody hunts for them in a crisis.

Section 7: Training and review

Commit to short annual training for everyone who touches payments, with at least one realistic example. Review the policy once a year and after any incident or near miss. Record who read it and when.

Making it stick

  • Keep it short, and give a one-page checklist to the AP team.
  • Get the owner or president to sign it, which signals that it applies to everyone.
  • Practice with a simulated request once a year.
  • Pair the policy with technical controls: multi-factor authentication, email filtering, and alerts for forwarding rules.

Support from Ironfield Cyber

Ironfield Cyber helps contractors and energy firms pair written payment policies with the email security and monitoring that back them up. If you would like a review of your draft policy or a short training session for your finance team, get in touch.