Treat the instruction as a change event
A new vendor account, revised owner payment direction, or urgent invoice can break a routine approval path. Keep the original instruction, sender details, approvals, confirmation method, payment record, and any later correction. These facts support internal investigation and create the starting point for a policy-specific discussion.
Preserve the operating record
Retain emails, messages, bank confirmations, invoice history, call notes, user access records, and reconciliation reports. Record the chronology while it is fresh: when the instruction arrived, who verified it, who authorized payment, and when the discrepancy was discovered. Avoid editing the source records.
Ask focused policy questions
Identify the relevant crime or cyber form, funds-transfer fraud and social-engineering language, limits, deductibles, discovery and notice conditions, and any verification requirements. Do not assume that a payment made after deception is treated the same way as an unauthorized transfer. The issued form needs to be read against the facts.
Improve the next control cycle
Use the incident record to test call-back procedures, segregated approval, vendor-master changes, and reconciliation timing. FBI Internet Crime Complaint Center guidance can support the operational-control conversation. Policy wording, declarations, and endorsements control; follow the policy’s reporting instructions for an actual loss or notice.
- Original instruction and verification
- Approval and payment timeline
- Policy and notice documents
- Control update owner and date

