Truthring
Tools

Payment verification policy

Most voice fraud against companies does not defeat a control. It defeats a junior person’s willingness to question a senior voice. Written policy is what removes that from the individual.

Why the wording matters more than the rule. Everyone already knows they should check unusual payment requests. What stops them is the social cost of appearing to doubt an executive who says there is no time. A policy fixes that by making verification mandatory and impersonal: the employee is not doubting anyone, they are following a step they are not permitted to skip.

Plain text, ready to paste into your own document.
PAYMENT AND INSTRUCTION VERIFICATION POLICY
Applies to: [VERIFY: teams and roles covered]
Owner: [VERIFY: named policy owner and role]
Approved: [VERIFY: date] · Review due: [VERIFY: date] 1. PURPOSE Recorded and synthesised speech can now imitate a specific person
convincingly enough to survive a telephone call. A voice is therefore
not a form of identification and is not accepted as one under this
policy. This document sets out how instructions are verified, so that
verification is a required step rather than a judgement any individual
has to make in the moment. 2. THIS IS POLICY, NOT PERSONAL JUDGEMENT No employee is required to decide whether a caller sounds genuine, and
no employee may be criticised, overruled or penalised for completing the
verification steps below. Verification is not an accusation. Anyone
asking staff to bypass these steps — including any officer or director
of the company — is to be refused and reported to [VERIFY: named escalation
contact]. Staff who follow this policy in good faith are protected under
it, including where the instruction turns out to have been genuine and
the delay caused inconvenience. 3. WHAT MUST BE VERIFIED Independent call-back verification is required before acting on any
instruction that: (a) creates or changes a payee, bank account or payment detail; (b) requests a payment of or above [VERIFY: threshold amount and currency]; (c) requests any payment described as urgent, confidential, or outside the normal approval route; (d) requests gift cards, cryptocurrency, or a transfer to a personal account; (e) requests credentials, access, multi-factor codes, or the release of personal or payroll data; (f) arrives outside normal hours, near a period end, or while the named approver is known to be travelling or unreachable. This applies to instructions received by telephone, voicemail, voice
note, video call, email, or messaging application, and regardless of who
the instruction appears to come from. 4. HOW VERIFICATION IS PERFORMED 4.1 End the call or close the message before verifying. Do not verify while still connected to the requester. 4.2 Call the requester back on a number taken from [VERIFY: named internal directory or system], not from the caller ID, the message, an email signature, or a number the caller supplies. 4.3 Confirm the specific instruction: amount, payee, account and reason. A general confirmation that the person called is not sufficient. 4.4 Where the requester cannot be reached, verification passes to [VERIFY: named alternate approver]. The instruction does not proceed on the strength of the original contact alone. 4.5 Record the verification in [VERIFY: system of record]: who was called, on what number, at what time, and what was confirmed. 5. WHEN A CALLER OBJECTS Pressure to skip verification is treated as a fraud indicator, not as a
reason to proceed. Where a caller asserts urgency, requests secrecy,
discourages call-back, or invokes seniority, staff must: (a) decline to proceed; (b) end the contact; (c) report it to [VERIFY: named escalation contact] the same day; (d) preserve any voicemail or voice note in its original form, without forwarding it through a messaging application and without editing or enhancing it. 6. EXCEPTIONS Exceptions require written approval in advance from [VERIFY: named
approver or role]. No exception may be granted verbally, and no
exception may be granted by the person making the payment request.
Emergency exceptions, if permitted at all, are recorded and reviewed at
[VERIFY: review forum and frequency]. 7. IF A PAYMENT HAS ALREADY BEEN MADE (a) Contact the bank immediately on the number held in [VERIFY: named internal directory or system] and ask whether recall is possible. (b) Notify [VERIFY: named escalation contact] and [VERIFY: named security or risk contact]. (c) Preserve all recordings, messages and payment records without alteration. (d) Report to the relevant national fraud reporting body. [VERIFY: link national fraud reporting bodies — verify every URL before publishing] (e) Notify the person who was impersonated so they can warn others. (f) Complete an incident record and review within [VERIFY: period]. 8. TRAINING AND TESTING All staff within scope complete this policy at induction and every
[VERIFY: frequency]. Verification behaviour is tested by [VERIFY: named
assurance activity] at [VERIFY: frequency]. Test results are reported to
[VERIFY: committee or forum] and are never used to discipline individuals. 9. RELATED DOCUMENTS [VERIFY: delegation of authority] · [VERIFY: incident response procedure] ·
[VERIFY: data protection policy] · [VERIFY: supplier onboarding procedure] — end of template —
Adapt before use. This is a drafting aid, not legal advice, and must be
reviewed and approved by the people accountable for controls in your
organisation.

Every [VERIFY] is deliberate. A policy that names no owner, no threshold and no escalation contact will not be followed, and the placeholders are there so nobody can publish it without deciding those things.


How to adapt it

Keep section 2. It is the part that actually changes behaviour, and it is the part organisations most often cut for length. Everything else is machinery; that section is the permission structure that lets a payments clerk put the phone down on a director.

Set the threshold in 3(b) low enough that it catches real attempts and high enough that it does not get quietly ignored. A threshold nobody can meet becomes a threshold nobody applies. Whatever you choose, the payee-change rule in 3(a) should apply at any value, because a changed bank account is the single most common route.

Name people, not teams, in the escalation lines. “Report to Finance” is a line that gets skipped at nine in the evening; a named person with a number does not. Then check the names quarterly, because policies outlive the staff listed in them.

Finally, say the quiet part in training: that the company would rather delay a genuine payment than lose a fraudulent one, and that anyone who verifies is doing their job correctly even when it is inconvenient for someone senior.


What this does not cover

This is a drafting aid, not legal advice, and not a compliance product. It has not been written against any particular regulatory regime, and your own obligations may require more than this. Have it reviewed and approved by whoever is accountable for controls where you work. [VERIFY: verify the position in your markets].

It also will not tell you whether a particular recording was synthetic. That is a separate question, answered at /check/ with a probability rather than a proof, and read alongside the published limitations. Preserve the original recording first — forwarding it through a chat app destroys evidence.


FAQ

Questions people ask

Our approvals are already dual-signed. Do we need this?

Dual approval helps, and it is routinely defeated when both approvers act on the same fabricated instruction. This policy adds an out-of-band check on the instruction itself, which is a different control.

Will the copy button send anything anywhere?

No. It copies the text on this page to your clipboard using your browser’s clipboard API. The page makes no network requests and stores nothing.

Can we shorten it?

Yes, and most teams should. Keep sections 2, 3, 4 and 5. Those four carry the behaviour; the rest is administration you may already have elsewhere.

Reviewed