About Services Team Reviews Partners Blog Contact (423) 779-8196

How to Build a Fraud Verification Policy for Your Small Business

← Back to Blog

A fraud verification policy is a short written document that defines exactly how your team confirms any request to move money, change banking details, or share credentials before acting on it. The core rule fits in one sentence: every such request gets verified through a second channel you already trust, using contact information you already have, every time, with no exceptions for urgency or seniority.

That one page of paper is the cheapest security control your business will ever deploy. It requires no software, no subscription, and no technical skill. And it defeats the two fraud types draining small business accounts right now: business email compromise and AI voice scams that clone a real person’s voice.

The numbers explain why this matters. The FBI’s Internet Crime Complaint Center logged $2.77 billion in business email compromise losses in a single year, and the Association for Financial Professionals found that 79% of organizations were targeted by payment fraud in 2024. Most of the small business losses inside those numbers happened because one employee acted on one convincing request without a second check.

This guide walks you through the five rules every fraud verification policy needs, gives you a one-page template you can adapt this afternoon, and covers how to train your team so the policy holds up under pressure.

> Key Takeaways
> – A fraud verification policy is one page: it lists which requests require verification, how to verify them, and who has authority to approve exceptions (nobody).
> – The callback rule does most of the work: confirm every money or banking-change request by calling the requester on a number you already have, never the number that contacted you.
> – Banking detail changes deserve a mandatory 24-hour hold on top of the callback. Vendor impersonation is the most expensive scam category for small businesses.
> – The policy only works if the boss follows it too. Most successful fraud impersonates an owner or executive and exploits employees’ reluctance to question authority.
> – Practice beats paper. A ten-minute drill twice a year does more than any signed acknowledgment form.

What a Fraud Verification Policy Is (and What It Isn’t)

A fraud verification policy is not a cybersecurity plan, an insurance document, or an IT configuration. It’s a set of human rules for the moments when technology has already been beaten, when the fake email looks real, the cloned voice sounds real, and the only defense left is what your employee does next.

Think of it as a pre-decision. Instead of asking a stressed bookkeeper to judge whether an urgent Friday-afternoon request is legitimate, the policy decides for them: this category of request always gets verified this way. Judgment is replaced with procedure.

That distinction matters because fraud works by manufacturing pressure. Scammers create urgency, invoke authority, and demand secrecy precisely so their target won’t stop and think. A written policy removes the thinking from the moment entirely. The employee isn’t deciding whether to trust the request; they’re following the same steps they follow for every request.

Rhonda handles payables for a 14-person engineering firm in Ooltewah. Last August, she received an email from a supplier they’d used for six years: new bank, updated remittance details, invoice attached for $18,400. The email address was perfect. The invoice matched a real open order. Under her firm’s policy, banking changes require a callback to the contact number in the vendor file, not the one in the email signature. The real supplier answered, confused. Their email had been compromised for three weeks, and the same fake change notice had gone to every customer in their address book. Two of those customers paid. Rhonda’s firm didn’t.

The Scams a Verification Policy Stops

The same short policy blocks several fraud patterns at once, because they all funnel through the same choke point: someone on your team acting on a request without confirming it.

| Scam | How It Arrives | What the Policy Catches |
|——|—————-|————————-|
| Vendor banking change | Email from compromised or spoofed vendor account | Callback to known number reveals the fraud |
| Fake owner/executive request | Email, text, or AI-cloned voice call | Callback plus code word exposes the impostor |
| Invoice fraud | Real-looking invoice for goods never ordered | Purchase order match requirement |
| Payroll diversion | “Employee” emails HR to change direct deposit | In-person or known-number confirmation |
| Gift card request | Urgent text or call from the “boss” | Policy bans gift card purchases outright |

Notice that none of these require hacking your network. Every one of them can succeed against a business with perfect firewalls and patched computers, because the target is a person, not a system. That’s also why they pair so well with the voice cloning tools we covered in our AI voice scams guide: a fake email plus a confirming phone call in the boss’s real voice defeats almost anyone who doesn’t have a procedure to fall back on.

The FBI has been warning about these schemes for years. Their public service announcement is worth two minutes of your next staff meeting:

Not sure which of these your business is most exposed to? Our cybersecurity team in Chattanooga walks through fraud scenarios as part of every security assessment. The assessment is free for local businesses.

The Five Rules Every Fraud Verification Policy Needs

You can write a working fraud verification policy with just these five rules. Each one closes a specific gap scammers exploit.

1. The callback rule

Any request to send money, change banking or payroll details, or share credentials gets confirmed by contacting the requester through a channel and contact you already have on file. Call the cell number in your phone, the vendor number in your accounting system, or walk down the hall. Never verify using a number, email, or link provided in the request itself, because the scammer controls those.

2. The 24-hour hold on banking changes

Vendor and payroll banking changes take effect no sooner than one business day after the callback confirms them. Real vendors survive a one-day delay without complaint. Scammers, who know compromised email access is temporary, push hard against any delay. The pushback itself is a red flag.

3. The dual-approval threshold

Pick a dollar amount, $5,000 works for many small businesses, above which two people must approve any payment. The second approver’s only job is to ask: was this verified per the policy? This protects you when the first person is rushed, new, or being socially engineered.

4. The no-exceptions clause

The policy applies to everyone, including the owner, and no one can waive it by phone or email. This is the clause that actually stops fraud, because nearly every scam impersonates someone with authority. Your team needs it in writing that “the boss said skip the callback” is itself the signal to do the callback.

5. The no-blame guarantee

Employees who delay a payment to verify it will never be criticized, even when the request turns out to be real. One sentence in the policy, said out loud at a staff meeting, removes the fear that makes people skip verification when the request sounds angry or urgent.

Your One-Page Policy Template

Copy this, adjust the numbers and names, and you have a working fraud verification policy today.

> [Company Name] Payment and Credential Verification Policy
>
> Effective [date]. Applies to every employee, including owners and managers.
>
> – [ ] All requests to transfer money, pay a new payee, or change any bank account details must be verified by callback to a phone number already in our records before any action is taken. Numbers, emails, or links contained in the request itself are never used for verification.
> – [ ] Bank account and direct deposit changes take effect no sooner than one business day after callback verification.
> – [ ] Payments over $[5,000] require approval from two authorized people: [Name 1] and [Name 2].
> – [ ] We do not purchase gift cards for business purposes. Any request to do so is treated as fraud and reported to [Name].
> – [ ] Passwords and MFA codes are never shared by phone, text, or email with anyone, including IT support and management.
> – [ ] No one can waive these rules by phone, email, or text. Urgent or confidential requests to skip verification are treated as fraud attempts.
> – [ ] No employee will ever be penalized for delaying a transaction to verify it.
> – [ ] Suspected fraud attempts are reported immediately to [Name] and our IT provider at [number].

Laminate it. Post it where payments happen. The policy that lives in a drawer protects nobody.

Rolling It Out Without the Eye-Rolls

A policy announcement email gets skimmed and forgotten. A ten-minute demonstration gets remembered. Here’s the rollout that works:

Show, don’t memo. At your next staff meeting, play a 30-second AI voice clone (your IT provider can generate one, or use a news clip). Then hand out the one-page policy. The clone makes the “why” self-evident in a way no memo can.

Have the owner say the magic words. The owner personally tells the team: “If you ever get a call or email from me asking you to skip these steps, that’s not me. Hang up and call my real number. I will never be upset about it.” Hearing it directly removes the authority pressure scammers depend on.

Notify your vendors. Send your regular vendors a two-line email: banking changes now require callback confirmation and take one business day. Legitimate vendors appreciate it. You’ve also just warned them their own customers are being targeted.

Drill it twice a year. Run a tabletop test: a fake urgent request, walked through out loud. Ten minutes.

Dr. Patel’s dental office in East Ridge ran exactly that drill last spring. The office manager played out a “supplier” call demanding same-day payment for an equipment order. The front desk coordinator, three weeks into the job, followed the laminated sheet: took the caller’s name, hung up, called the supplier’s number from the vendor file. In October, the real version of that call came in, an actual scammer, same script. She did the same thing without hesitating. The difference between a trained team and an untrained one isn’t knowledge. It’s reps.

Verification policies work best alongside the technical basics: multi-factor authentication on every account and hardened business email, so fewer fraudulent requests reach your team in the first place.

Keeping the Policy Alive

A fraud verification policy decays if you let it. Three habits keep it working:

Review it annually. Approval thresholds, named approvers, and contact numbers go stale. Put a calendar reminder on the policy’s anniversary.

Update it after every attempt. Each fraud attempt your team catches teaches you where you’re being probed. Fold what you learn into the policy and tell the team about the catch. Celebrating a caught attempt reinforces the behavior better than any training.

Confirm it satisfies your insurer. Many cyber insurance policies now require documented verification procedures for social engineering coverage to apply, and some deny claims when procedures existed but weren’t followed. Our guide to cyber insurance requirements for small businesses covers what carriers look for. Send your one-pager to your agent and ask if it meets the policy’s conditions. That single email can be the difference between a covered loss and a denied claim.

Frequently Asked Questions About Fraud Verification Policies

What should a fraud verification policy include?
Five things: a callback rule for all money and banking-change requests, a waiting period for banking changes, a dual-approval threshold for larger payments, a no-exceptions clause that covers owners and managers, and a no-blame guarantee for employees who verify. One page covers all of it.

How is this different from our accounting controls?
Accounting controls catch errors and internal theft after the fact. A verification policy stops external fraud in the moment, before money moves. You need both, but the verification policy is the one that stops a wire transfer to a scammer’s account.

Do small businesses really need a written policy, or is training enough?
Written beats verbal for two reasons. Under pressure, people follow checklists better than memories. And if you ever file a cyber insurance claim for social engineering fraud, the carrier will ask for your documented procedures. “We trained on it” is a much weaker answer than a dated, signed policy.

What’s a reasonable dual-approval threshold for a small business?
Common choices run between $2,500 and $10,000 depending on your typical transaction size. Pick a number low enough to catch a painful loss and high enough that it doesn’t add friction to daily operations. You can always tighten it later.

Will vendors get annoyed by callback verification and payment holds?
The opposite, in our experience. Legitimate vendors deal with compromised-email fraud constantly and recognize the procedure as professionalism. A vendor who pressures you to skip verification is either having a bad day or isn’t your vendor.

Who should own the fraud verification policy?
Whoever controls payments day to day, usually the office manager or bookkeeper, with the owner’s visible backing. Your IT provider should review it annually alongside your broader security setup, since the policy and your technical defenses cover each other’s gaps.

The Bottom Line on Building a Fraud Verification Policy

Fraudsters don’t beat small businesses with sophisticated hacking. They beat them with a convincing request, manufactured urgency, and an employee who had no procedure to lean on. A fraud verification policy takes an afternoon to write and removes that opening almost entirely: callback on known numbers, a day’s hold on banking changes, two eyes on big payments, no exceptions for anyone, and no blame for anyone who checks.

Write the one-pager this week. Say the magic words at your next staff meeting. Drill it twice a year.

If you’d rather build it with help, ETTC sets up verification policies, staff fraud training, and the technical defenses around them as part of managed IT services for Chattanooga businesses. We’ll tailor the template to how your office actually pays people.

Call us at (423) 779-8196 or schedule a free consultation and we’ll review your fraud exposure together.

Published by Mark Bryant, Owner and Founder of East Tennessee Technical Consultants. ETTC has provided managed IT services to Chattanooga businesses and dental practices since 2010.

cybersecurity fraud prevention policies small business