How to stop invoice fraud in a small business
Most guidance on preventing invoice fraud is either a list of software to buy or a vague instruction to be careful. This is neither. Below are the controls that measurably reduce the chance of losing money, ordered roughly by value for effort, and most of them cost nothing.
If you only do two things, do the written policy in the first section and the second-approver rule. Together they prevent a large share of these losses on their own.
Process: the cheapest and most effective layer
- Write down that bank details are never changed on the basis of an email. This costs nothing and its real value is that it gives staff explicit permission to refuse — most people who pay a fraudulent invoice knew something was off but did not feel authorised to slow things down.
- Verify every change by phone, on a number you already held. Not a number from the email, the invoice, or a signature block.
- Require a second person to approve any payment to a new or changed account. The person who received the request should never be the person who releases the money.
- Apply a cooling-off period — 24 hours before the first payment to any new account. Nearly every fraudulent request is urgent; almost no legitimate one collapses because of a day's delay.
- Re-verify key supplier details once a year as routine, so verification is a normal activity rather than an accusation.
Email and identity: stop the compromise upstream
Much of this fraud begins with someone reading a mailbox they should not have access to. These reduce that risk, and most are configuration rather than purchase.
- Turn on multi-factor authentication everywhere, and prefer phishing-resistant methods — passkeys or security keys. SMS codes are better than nothing but can be intercepted or phished in real time.
- Set up SPF, DKIM and DMARC for your domain, and move DMARC to a reject policy once you have checked your legitimate mail passes. This makes it materially harder for anyone to send mail that appears to come from you.
- Alert on the creation of inbox rules and auto-forwarding. This is the single most under-monitored signal: after breaking into a mailbox, attackers almost always create a rule to hide the replies from the real owner.
- Disable legacy authentication protocols in Microsoft 365 or Google Workspace. They bypass MFA and are rarely needed.
- Turn on external-sender banners so mail from outside the organisation is visibly marked.
Banking: controls your bank already offers
Many businesses never ask what their bank can do here, and the answer is often more than expected.
- Use account-name checking where your bank offers it, so a mismatch between the account name and the account number is surfaced before the payment goes.
- Set payment limits that require a second authoriser above a threshold you choose.
- Ask about payee whitelisting, so payments to new accounts require an extra step.
Insurance: check what is actually covered
This is the item most often assumed and least often verified. A standard cyber policy frequently excludes losses where a staff member was deceived into transferring money voluntarily — which is precisely what happens in this fraud.
Cover for it usually requires a specific social engineering or crime endorsement. Ask your broker directly whether funds-transfer fraud arising from a deceptive email is covered, and get the answer in writing.
People: the control that decides the outcome
Training helps, and simulated phishing helps if it is paired with support rather than punishment. But the highest-value cultural control is narrower and more specific than general awareness.
Make it unambiguous that reporting a suspected mistake immediately is the right action and carries no blame. Recovery is dominated by speed, and the delay that kills recovery is almost always someone hoping they are wrong before they tell anyone.
A team that reports in ten minutes recovers money. A team that reports the next morning does not. That difference is cultural, not technical.
What software can and cannot do
Tools can check the structure of a document, compare a sender's domain against ones you trust, spot an account you have seen before under a different supplier, and enforce that a second person approves a payment. Those are real and worth having.
What no tool can do is confirm that a bank account belongs to the business on the invoice. That fact is the foundation the entire fraud is built on, and any product implying otherwise is overselling. Treat the controls above as the substance, and software as the thing that makes them consistent rather than dependent on somebody remembering.
Common questions
We're a two-person business. Is a second approver realistic?
Yes, and it matters more at that size, not less. The second person does not have to be an employee — a business partner, an external bookkeeper, or a co-director works. The requirement is only that the person who received the request is not the person who releases the money.
Which single control gives the most protection?
Verifying every bank-detail change by phone on a number you already held. Nearly every large loss in this category would have been prevented by that one call.
Are small businesses actually targeted, or is this a big-company problem?
Small businesses are targeted heavily, because the controls are usually lighter and a single payment can be large relative to the business. The losses are also proportionally far more damaging.
Related guides
- Is this invoice a scam? Seven checks before you pay
The seven things worth checking on an invoice that doesn't feel right, and the one check that actually settles it.
- A supplier emailed new bank details. What should you do?
The single most common way businesses lose large sums — and a short, repeatable process that stops it.
- You've paid a scammer. What to do in the first hour
If money has already gone, speed decides the outcome. The order of operations that gives you the best chance.