Payment Fraud Drill: A 30-Minute Tabletop for Finance Teams

Run a short tabletop exercise with accounts payable and leadership so everyone knows what to do when a fraudulent bank-change request arrives.

3 min readBy Ironfield Cyber Team

Most finance teams have a policy for verifying banking changes. Fewer have practiced it. In a real attempt, the request arrives on a busy day, from a trusted name, with a plausible reason and a deadline. Under that pressure, even careful people skip steps.

A tabletop exercise is a simple way to rehearse. You gather the people involved, walk through a realistic scenario, and see where the process holds or breaks. It takes about thirty minutes, requires no technology, and often reveals gaps that a written policy hides. This article gives you a script you can run this week.

Who Should Attend

  • Accounts payable and accounts receivable staff
  • The controller or CFO
  • A project manager or two who communicate with vendors
  • The person who approves payments
  • IT or your provider's representative
  • Optionally, the owner or president

Keep the tone relaxed. The purpose is learning, not testing individuals.

Set Up the Scenario

Read this hypothetical aloud. It is invented for the exercise.

A mid-size commercial contractor receives an email that appears to come from the accounts receivable contact at a long-time concrete subcontractor. It says the company has changed banks and asks that the next progress payment, due in two days, go to a new account. A signed form is attached, and the sender notes that the old account is being closed. The message is polite and refers to a recent project by name.

Walk Through the Questions

Pause after each prompt and let people answer.

Minutes 0 to 10: Detection

  1. Who receives this message first, and what do they do?
  2. What details make it look legitimate? What details might be wrong?
  3. Do we have a documented procedure for bank changes? Does everyone know where it is?
  4. Who is allowed to change vendor payment details in our system?

Minutes 10 to 20: Verification

  1. How do we confirm the request? What phone number do we use, and where does it come from?
  2. Who makes the call, and who documents it?
  3. What if the vendor contact is unavailable? Do we pay to the old account or wait?
  4. Who must approve the change before payment?
  5. What if the project manager pushes for speed because the vendor needs cash?

Minutes 20 to 30: Response

Add a twist: An employee reveals that a payment was already sent last week to a new account on a similar request.

  1. Who do we notify first, and in what order?
  2. How quickly can we contact our bank to request a recall or hold? Who has the number?
  3. Who contacts the vendor and law enforcement, and who gathers the emails and records?
  4. How do we preserve evidence, and who tells our insurer?
  5. How do we check whether our own email was compromised?

The FBI's Internet Crime Complaint Center encourages prompt reporting of wire fraud incidents, and speed with the bank is often critical. Know your bank's fraud contact in advance.

Capture What You Learn

Assign a note-taker. Record:

  • Steps that were unclear or skipped
  • Points where people disagreed on who decides
  • Missing contacts or documents
  • Tools or approvals that would help, such as a callback log or a second approver in the payment system

Turn Findings Into Actions

Within a week, assign owners and dates for improvements. Typical results include:

  1. A one-page verification checklist posted where payables staff work
  2. A contact sheet with bank fraud numbers, insurer contacts, and key vendor phone numbers, stored outside email
  3. A rule that vendor banking changes require two approvals
  4. A standard callback script and a log
  5. Changes to email protections, such as external sender warnings
  6. A short briefing for project managers on why finance asks questions

Variations to Try Later

  • A fake request that appears to come from the CEO
  • An invoice from a real vendor with altered bank details
  • A request that arrives while the controller is on vacation
  • A compromised vendor mailbox that replies to your callback email

Make It a Habit

Repeat the drill every six months, changing the scenario. New hires should experience one within their first few months. Keep it short and lighthearted enough that people look forward to it.

Support for the Exercise

If you would like an outside facilitator or help turning the results into procedures and email protections, Ironfield Cyber can run the session with your team and follow up with practical improvements to your payment controls.