IntelliPay is a PCI DSS Level 1 certified payment processor working with cities, counties, utilities, courts, and school districts nationwide. This guide covers the controls that stop vendor payment fraud, business email compromise, and insider theft in small government finance offices. Learn more about government payment solutions.
Quick Answer
Most fraud losses in small government finance offices come from two places: outsiders who talk someone into changing where money goes, and insiders who work with no independent review.
Five habits close most of that gap:
- Verify every vendor or payroll bank change by calling a number you already had on file.
- Adopt a written “no bank changes by email” policy.
- Keep a vendor and payroll change log that a second person reviews.
- Have someone who never touches the money review bank statements every month.
- Reconcile processor settlements to the bank to the general ledger on a fixed schedule.
None of this requires new staff or new software.
Why This Is a Small Government Problem
Business email compromise (BEC) caused $3,046,598,558 in reported losses in 2025, from 24,768 complaints, according to the FBI’s Internet Crime Complaint Center. Local governments are regular victims:
- Baltimore lost more than $800,000 after a fraudster tricked accounts payable staff into changing a vendor’s bank account.
- In May 2026, the town of Harpswell, Maine, reported that staff sent $189,199 to a scammer posing as a legitimate vendor.
- Arlington, Massachusetts, lost $446,000 in 2024 after criminals monitored email and sent fraudulent payment requests posing as a vendor.
- Eagle Mountain, Utah, lost nearly $1.13 million in 2022 after criminals impersonating a road-project contractor in an email exchange persuaded city staff to change the contractor’s payment bank-account details. The city then sent the funds via ACH to a fraudulent account.
Insiders are a second, quieter risk. In 2025, the Washington State Auditor reported an increase in fraud investigations at small local governments where employees have access to public funds without appropriate reviews. One case was a town of fewer than 100 residents that lost more than $79,000 to its own clerk-treasurer.
That figure is not an outlier. The Association of Certified Fraud Examiners (ACFE), the global body that certifies fraud examiners and publishes the largest study of occupational fraud, analyzed 2,402 real cases from 143 countries for its 2026 Report to the Nations. Government and public administration cases carried a median loss of $100,000, close to the $104,000 median across all industries. Broken out by level of government, local governments came in at a $79,000 median, almost exactly what that one small town lost.
One set of controls covers both risks. GFOA advises that whoever enters or approves a vendor change should not also verify it, and that a supervisor should review vendor changes. A second set of eyes stops an employee from acting alone, and it gives a fake bank-change request one more place to fail.
Small organizations are also the least likely to have a safe way to report concerns, and tips are how 43% of frauds get caught. In a small office the problem is easy to see: when the clerk-treasurer handles the money, an employee may have no one to report to except the person they suspect. Only about a quarter of organizations with fewer than 100 employees have a formal reporting mechanism, versus 85% of larger ones, the widest gap among the 18 controls the ACFE studied. The gap is costly. Organizations without one lost 50% more per case ($150,000 versus $100,000) and took six months longer to catch it (17 months versus 11). GFOA recommends every government offer a confidential, anonymous channel, such as a hotline, and consider an outside vendor to receive tips. For a small agency, that can be an outside hotline vendor, or a designated elected official or outside CPA who sits outside the finance office. Part 4 covers how.
Part 1: Vendor Payment Fraud and BEC
How it works
- Research. The attacker finds a real vendor from your public contracts, board packets, or a compromised email account.
- The request. You receive a polite email, a “voided check” or a change form asking to update the vendor’s bank account.
- The payment. Your office pays the fraudster on the next ACH or wire run. The real vendor calls weeks later asking why they haven’t been paid.
What it looks like in practice
In Baltimore, the fraudster submitted a fake supplier contact form using a real vendor employee’s name and a personal email address. An employee approved it without verifying the identity, because policy didn’t require that at the time. Fake voided checks and bank change requests followed, and the vendor’s account was switched to the fraudster’s by Feb. 19. The city sent $803,384.44 on Feb. 21 and $721,236.60 on March 10. The scheme diverted $1.52 million, and about $721,000 was recovered. The inspector general noted that policies did not require phone verification of vendor contacts or bank changes.
That’s the lesson. The staff weren’t careless. The process had no verification step.
Control 1: Call-back verification checklist
Use this for every request to add or change bank details, mailing addresses, or payee names.
- ☐ Do not reply to the email or use any phone number, link or contact in the request.
- ☐ Look up the vendor’s number from your original contract, W-9 file, or a vendor record created before the request.
- ☐ Call and speak to a person you have dealt with before. Ask them to confirm the change, the new bank name, and the last four digits of the new account.
- ☐ Confirm the caller has authority. Compare against the vendor’s signatory list on file.
- ☐ Record who you called, at what number, when, and who confirmed it.
- ☐ A second employee reviews the record before the change goes live.
- ☐ Send a small test payment or hold the first payment 24 hours after a change, if your process allows.
GFOA recommends governments revise vendor forms to require both old and new bank routing and account numbers or billing addresses when a vendor requests a change. Adding the old account number makes a stranger’s request much harder to fake.
Control 2: A “no bank changes by email” policy
Adopt it in writing, adopt it by board or council action if you can, and send it to your vendors. Sample language for your attorney to review:
“The [Agency] will not change vendor banking or remittance information based on email, text, or phone requests alone. All changes require a signed change form, submission through [portal/mail], and verbal verification by [Agency] staff using contact information already on file. Requests that do not follow this process will be declined regardless of urgency or the identity of the requester.”
Two rules make it work:
- No exceptions for urgency or seniority. Fraudsters impersonate department heads and council members to create pressure. The policy protects staff who say no.
- Tell vendors in advance. Add a line to purchase orders and contracts, so honest vendors expect the call.
Control 3: Vendor master file change log
Every change to a vendor record should leave a trail someone else reviews.
| Log field | Why it matters |
|---|---|
| Vendor name and ID | Ties change to the record |
| Date and time of request | Spots after-hours or rushed requests |
| Who requested it, and how (email, phone, form) | Shows whether policy was followed |
| Old and new bank info (last four digits only) | Shows what changed |
| Call-back date, number called, person confirmed | Proof of verification |
| Who made the change | Accountability |
| Who reviewed it, and when | Independent check |
Three rules:
- The person who edits the vendor master file should not be the person who approves or releases payments.
- Someone independent runs a monthly change report and compares it to the log.
- Review any vendor whose bank account changed within 30 days of a payment.
Control 4: Treat a Familiar Voice as One More Thing to Verify
Call-back verification assumes the voice on the other end proves who they are. In 2026, that assumption is weaker than it used to be. AI voice-cloning tools can recreate a real person’s voice from a few seconds of audio pulled from a public meeting recording, a council video, or a voicemail, and video deepfakes have been used to impersonate executives on live calls well enough to move tens of millions of dollars at a private company. A department head’s voice, or even their face on a video call, is no longer proof by itself that the request is genuine.
The good news: the callback method in Control 1 still works, for one specific reason. A cloned voice can sound like anyone, but it cannot make your outbound call ring on the fraudster’s line. As long as you dial a number you already had on file, rather than answering an incoming call or dialing a number supplied in the request, you are still reaching the real person or the real vendor, whoever answers.
- Never approve a bank change, wire, or urgent payment based on a phone call or video call alone, however convincing the voice or face. The call confirms; it does not replace the change log and second-person review in Control 3.
- For your highest-value or most frequent payments, agree on a shared verification phrase with key vendors and department heads in advance, something never said over email or in a public meeting.
- Treat a request to skip the normal process because a caller is “too busy” for the change log as a red flag on its own, regardless of whose voice is asking.
- If something feels off during a call, hang up and call back on the number you already had, rather than continuing the conversation.
How to Recognize the Phishing Email
Every scheme in this guide starts the same way: a fraudulent email or text message built to look genuine. Phishing just means sending fake messages designed to trick the recipient into revealing information, clicking a malicious link, or acting on a fake instruction, and BEC is phishing aimed specifically at a payment. Cybercriminals often build the message using information they found online: a vendor’s name from a public bid document, a department head’s title from your website, an employee’s name from a board packet or LinkedIn. None of that requires hacking your systems, only reading what’s already public.
Train staff to look for the same handful of signs on every payment-related email, not just ones that look obviously suspicious:
Red flags for finance staff
- A new “urgent” request from a vendor you haven’t heard from in months
- A sender address that is a lookalike domain or a free email account
- A request to keep the change “confidential” or to skip normal approvals
- A new account at a different bank, in a different state, or in a different name
- Refusal to take a phone call
Secure the Devices Used for Payments
The email is the trick. The device is where it lands. A computer or phone that is out of date, unlocked, or used for both payments and everyday browsing gives a phishing attempt more room to succeed.
- Keep software current. Software updates patch real, documented weaknesses, including the ones phishing links are built to exploit. Turn on automatic updates for every computer and phone used to send or approve payments, and check the device’s settings, usually under “System,” for any update that was missed.
- Lock every device. Require a PIN, password or biometric lock on any phone, laptop or tablet used for finance work, never a default or shared code such as 1234. A lost or stolen device with no lock hands a stranger everything on it.
- Separate payment devices from everyday browsing where you can. A computer used to enter or approve vendor payments is a poor choice for checking personal email or browsing the web; that mix is exactly how a phishing link reaches a payment system.
These habits protect the device a phishing email is trying to reach. Part 5 covers the equivalent controls for payroll and HR portals specifically.
Check Fraud Hasn’t Gone Away
Every control above focuses on electronic payments, but paper checks remain, by several recent surveys, the single most commonly defrauded payment method nationally, ahead of both ACH and wire fraud. Check washing, chemically or otherwise altering a legitimate check’s payee or amount after it’s mailed, along with counterfeiting and forgery, has been rising for several years running, largely driven by mail theft.
One small New England town saw this directly: a resident spotted more than a dozen checks flagged as fraudulent in a monthly register and raised it at a public meeting. Finance staff explained that fraudsters had altered previously issued checks, and that the bank’s positive pay system, together with the treasurer’s monitoring, caught and recovered most of the funds before they were lost for good.
- Ask your bank about positive pay (sometimes called payee positive pay). It matches every check presented for payment against the check number, amount and payee your agency actually issued, and flags or returns anything that doesn’t match, before the money leaves your account.
- Don’t leave outgoing checks in an unlocked or curbside mailbox. Drop them at the post office or in a USPS collection box instead.
- Reconcile your issued-check register daily against what clears, the same discipline described in Part 6, so an altered check is caught in days, not months.
- Where it makes sense, move recurring vendors to ACH, using the same call-back verification in Control 1. This trades check-washing risk for BEC risk, so the same controls, not fewer controls, still apply.
What Your Insurance Will and Won’t Cover
Assume you will still need to answer for part of a loss even if every control above works as designed. Cyber-enabled fraud, including BEC and vendor impersonation, has become a bigger worry for many organizations than ransomware, and coverage for it is often thinner than agencies expect. A crime policy’s social-engineering coverage, or a cyber policy’s social-engineering sub-limit, is commonly capped between $100,000 and $250,000, even when the policy’s overall limit is much higher.
Many of those policies also only pay out if the agency can show it followed a defined verification procedure, often specifically a call-back to a previously known number, before releasing the payment. That’s exactly the discipline in Control 1, which is one more reason to have it in writing rather than relying on informal habit. Ask your insurance agent or broker for written answers to three questions:
- Is a fraudulent vendor or payroll transfer covered under our crime policy, our cyber policy, or neither?
- What is the specific dollar sub-limit for social-engineering or funds-transfer fraud, separate from the policy’s overall limit?
- Does the policy require documented verification steps before it pays a claim, and if so, does our written procedure meet that standard?
If a payment goes to the wrong account
Speed matters more than anything else. Do these in order:
- ☐ Call your bank immediately and ask for a recall or freeze. Then confirm in writing.
- ☐ File at ic3.gov and contact your local FBI field office.
- ☐ Notify your insurer. Many policies have notice deadlines.
- ☐ Preserve the emails, headers, forms and logs.
- ☐ Contact the real vendor and check that your own systems weren’t compromised.
Part 2: A Nacha Rule Your ACH Payments Now Fall Under
What ACH and Nacha are. ACH (Automated Clearing House) is the electronic network that moves money between U.S. bank accounts. Direct deposit and many vendor payments run on it. Nacha is the nonprofit that writes and enforces the rules for that network. It doesn’t move money itself. Banks follow Nacha’s rules, and so does any organization that sends ACH payments, including your agency if it pays vendors or employees this way. Nacha calls an organization that sends ACH payments an “originator.”
What changed. Nacha now requires every organization that sends ACH payments to have a process for spotting payments that are unauthorized or that someone was tricked into making. Nacha calls the second kind “false pretenses”: a payment induced by someone lying about who they are, who they represent, or who owns the account. That covers business email compromise, vendor impersonation and payroll impersonation. The rule started with the largest senders in March 2026. It reached everyone else, regardless of size, on June 19, 2026. That day was a federal holiday, so Nacha set Monday, June 22 as the practical date. It is now in effect.
What it requires, and what it doesn’t.
- A process suited to your risks, reviewed at least once a year.
- It does not require checking every payment, checking before payments go out, or any particular software.
- “Risk-based” doesn’t mean “none.” At a minimum, identify which payments are higher risk, such as vendor and payroll bank-account changes, and which are lower.
- It does not change who bears the loss if fraud happens.
Who does what.
| Who | What they typically cover |
|---|---|
| Your bank | Watches the payment files it sends for you and can hold or question a suspicious payment |
| Your payment processor or ACH software vendor, if you use one | May review the volume, speed and dollar amounts of the payments it sends |
| Your agency | Whatever only you can see: is this request to change a vendor’s or employee’s bank account genuine? |
Receiving banks now monitor incoming payments too. Nacha says that does not reduce your duties as the sender.
What’s left for your agency.
- Write a short procedure covering your call-back verification, change log and second-person review. Nacha doesn’t require a written format, but it’s the practical way to show you have a process.
- Note which payments are higher risk. Vendor and payroll bank changes belong on that list.
- Put an annual review on the calendar.
- Ask your bank or processor in writing what they monitor and what they expect from you.
- Ask whether your payroll files use the description “PAYROLL.” Nacha has required it on wage and salary payments since March 20, 2026.
If your agency sends vendor ACH payments or direct-deposit payroll, this likely includes you. Confirm with your bank.
Part 3: Segregation of Duties for One- and Two-Person Offices
The principle
In a well-staffed office, four jobs belong to different people:
- Authorizing a transaction
- Having custody of cash or payment tools
- Recording it in the books
- Reconciling the accounts
The Washington State Auditor says segregating duties isn’t all or nothing. You separate as much as you can, then fill the gaps with oversight controls performed by a mayor, another qualified council member, or a paid third party. Indiana’s State Board of Accounts adds that where separation isn’t feasible, you should document which areas lack it and which compensating controls you put in place.
Compensating controls that work
| If one person does this… | Add this compensating control |
|---|---|
| Receives cash and makes deposits | A second person opens mail or reviews the daily receipt log; deposits are compared to receipts independently |
| Prepares and releases payments | Online banking with dual approval; an elected official approves payment batches |
| Records transactions and reconciles the bank | Bank statements go unopened to an elected official or contracted CPA who reviews them first |
| Sets up vendors and pays them | Monthly vendor change report reviewed by someone else |
| Runs payroll and edits employee bank info | Payroll change report reviewed before every payroll run |
The New York State Comptroller suggests having a board member periodically review the treasurer’s work, especially monthly bank reconciliations, when hiring another employee isn’t cost-effective. Tennessee’s municipal advisory service describes the same idea for small cities: an elected official reviews daily and monthly reports, reviews reconciliations, and conducts unannounced spot-checks.
Two habits most small offices skip
Rotating duties. Swap tasks such as deposits and reconciliation between people at least quarterly, or have a second person cover the work when someone is out.
Mandatory vacation. Require at least five consecutive business days away from finance duties every year. Someone else runs the process during that time, without the regular employee’s access. Many schemes depend on the perpetrator being there every day to keep them hidden.
Checklist for the elected official reviewer
- ☐ Receive the bank statement directly from the bank (or with a copy sent to you).
- ☐ Scan for unusual payees, round-dollar amounts, transfers between accounts, and payments outside normal patterns.
- ☐ Confirm the reconciliation ties to the statement and to the general ledger.
- ☐ Sign and date the review.
- ☐ Once a quarter, pick three to five random transactions and trace them to invoices and approvals.
Part 4: Insider Fraud
Why time matters
The average fraud scheme in the ACFE’s 2026 study lasted 12 months before detection, and fraud caught within six months had a median loss of $40,000. The longer a scheme runs, the more it costs, so the goal is to shorten detection time.
Warning signs
Reports on the study say 84% of perpetrators showed behavioral red flags before detection. Watch for:
- Living beyond means, or sudden financial stress
- Refusing vacation, or refusing to share duties or passwords
- Being unusually protective of records, or complaining about oversight
- Unexplained voids, refunds, write-offs or adjustments
- Missing, altered or late receipts and bank statements
- Vendors or payees with no clear business relationship to the agency
Surprise cash count checklist
- ☐ Do it unannounced and vary the day and time.
- ☐ Two people attend, and neither is the cash handler.
- ☐ Count all cash, checks and change funds, and compare to the receipt log, till tapes and the deposit slip.
- ☐ Have the cash handler sign the count sheet.
- ☐ Document who attended, when, the result and any differences explained.
- ☐ Do it at least quarterly for offices handling cash, and more often for high-volume counters.
Periodic independent reconciliation
Once a year, have someone outside the finance office, such as your outside CPA, another agency’s finance staff, or an appointed board member, reconcile a sample month from scratch. They should work from the original bank statement, not from the reconciliation your staff prepared.
Give people a safe way to report
In the 2026 ACFE study, organizations with a formal reporting mechanism had a median loss of $100,000 versus $150,000 without one, and detected fraud in 11 months versus 17. A third-party hotline or a designated elected official is enough. Tell employees, vendors and residents how to use it.
Part 5: Payroll Diversion
How it works
An email arrives that looks like it’s from an employee: “I changed banks. Please update my direct deposit.” The new account belongs to a criminal, often a prepaid card. In another version, criminals phish an employee’s credentials, log in to the payroll system, and add rules to the employee’s mailbox so alerts about the change never arrive.
New Jersey’s cybersecurity center described a case where attackers called the help desk to get a password and MFA reset, then emailed payroll from the real employee’s account. Payroll made the change based only on that email, contrary to the organization’s own policy. The attackers also created an inbox rule to hide replies, but security monitoring caught the rule and the account was locked.
Payroll diversion checklist
- ☐ Direct-deposit changes require in-person confirmation, or a call to a number on file. Never by email alone.
- ☐ Require MFA on the payroll and HR self-service portal.
- ☐ The help desk verifies identity before any password or MFA reset. Use a manager or in-person confirmation for finance, HR and payroll accounts.
- ☐ Send an automatic notice of every bank change to the employee’s existing contact information, not just the new one.
- ☐ A second person reviews the direct-deposit change report before each payroll is released.
- ☐ Review the mailbox rules and login times for payroll and HR staff.
- ☐ Confirm the first payment after any change reached the right person.
- ☐ Train HR and payroll staff to say: “We’ll call you at the number on file.”
Part 6: Reconciliation as a Detection Control
Reconciliation is also your best fraud alarm. A reconciliation that’s prepared late, by the wrong person, or never reviewed doesn’t detect anything.
The three-way match
- Processor settlement report shows what the processor says it collected and owes you.
- Bank deposit shows what actually arrived.
- General ledger shows what your books recorded.
All three should agree, and any difference should be explained in writing.
Who and how often
| Frequency | Task | Who |
|---|---|---|
| Daily or each business day | Match card and online settlement batches to bank deposits; review voids and refunds | Someone other than the person handling cash |
| Weekly | Review ACH returns, chargebacks and disputes; review vendor and payroll bank-change reports | Finance staff, reviewed by a second person |
| Monthly | Reconcile bank statements to the general ledger; sign-off by an independent reviewer | Preparer is not the cash handler; reviewer is an elected official or CPA |
| Quarterly | Surprise cash count; sample tracing of transactions to source documents | Independent person |
| Annually | Outside review or audit; update fraud monitoring procedures | CPA and governing body |
Illustrative example
Your online settlement report shows $12,450.00 collected on Tuesday. The bank deposit posted Wednesday is $12,150.00. The $300.00 gap should be traced the same day to a refund, fee adjustment, chargeback or a timing difference. If nobody compares the numbers until month-end, a single unexplained $300 gap can run for weeks. If the same person who processes refunds also reconciles, nobody else will see it.
Your 30-Day Action Plan
Week 1
- ☐ Adopt the “no bank changes by email” policy and tell vendors.
- ☐ Start the vendor and payroll change logs.
Week 2
- ☐ Set up dual approval for ACH and wires at your bank.
- ☐ Have bank statements delivered to an elected official or CPA.
Week 3
- ☐ Assign who reconciles and who reviews. Make sure they’re different people.
- ☐ Write the one-page ACH fraud monitoring procedure.
Week 4
- ☐ Hold your first surprise cash count.
- ☐ Set up a fraud reporting channel.
- ☐ Put mandatory vacation and rotation on the calendar.
The bottom line
Call-back verification, a written no-email-changes policy, a reviewed change log, independent bank statement review, and scheduled reconciliation cover most of what gets small government finance offices into trouble.
Want to know how your payment reporting can support your reconciliation? Talk with an IntelliPay consultant.
Talk to a ConsultantFrequently Asked Questions
What is business email compromise (BEC)?
BEC is fraud where a criminal impersonates a vendor, executive or employee by email to redirect a payment. It often uses no malicious link or attachment, just a believable request.
Is voice-cloning (“deepfake”) fraud something a small agency needs to worry about?
It’s an emerging version of the same con. Criminals now use AI-generated audio to imitate an executive’s or a vendor contact’s voice, often layered on top of an email exchange to make an urgent request feel more real. The defense doesn’t change: verify by calling a number you already had on file, never one supplied with the request, and confirm the change against your own vendor or employee record rather than trusting a voice on the phone.
What is the best control against vendor payment fraud?
Call-back verification using a phone number you already had on file, before any bank change takes effect, with a second person reviewing the record.
Does our vendor-verification policy apply to elected officials, or just staff?
It should cover everyone with authority to approve or release a payment, elected officials included. Fraudsters specifically impersonate department heads and council members to create urgency, and an official who’s allowed to skip the callback becomes the one gap in an otherwise solid process. Adopt the policy by board or council action, not just as a staff memo, so it binds the people who could otherwise waive it.
A legitimate vendor is annoyed that our new verification process is slowing their payment. What do we say?
Tell them the policy applies to every vendor without exception, and that it protects their payments too, since it’s the same process that would catch someone trying to redirect money owed to them. Notify vendors of the policy in your contract and purchase order language up front, so the callback isn’t a surprise the first time it happens. A short delay for a phone call costs far less than a wire that has to be clawed back.
We only have one finance employee. Can we still segregate duties?
Not fully. Separate what you can, then use compensating controls: an elected official’s monthly bank review, rotation, mandatory vacation and surprise counts. Document the gaps and how you cover them.
Do the 2026 Nacha fraud monitoring rules apply to local governments?
They apply to non-consumer ACH originators, which generally includes agencies that send vendor payments or payroll by ACH. Confirm with your bank.
If we approve a fraudulent bank change, does our bank share any responsibility?
Sometimes, but don’t count on it. Under the Uniform Commercial Code, liability for a fraudulent transaction can be split between your agency and your bank based on each party’s own diligence, not automatically assigned to whichever one clicked “send.” GFOA notes that if your bank offers a fraud-prevention service, such as positive pay, and your agency chooses not to use it, your agency, not the bank, generally bears the loss. Ask your bank counsel which services you’re declining and what that means for your liability.
We keep hearing BEC is the top fraud method. Isn't check fraud still a bigger risk for us?
Both matter. Business email compromise is consistently reported as the most common method used in attempted or actual payments fraud, but checks remain one of the most exploited payment types, since a check carries no built-in verification the way an electronic payment can. GFOA calls positive pay, a bank service that flags any check that doesn’t match your issued list, the single best fraud-prevention tool available for check disbursements, and warns that a government that declines the service when its bank offers it typically bears the loss itself, not the bank. If your agency still writes checks, ask your bank whether positive pay, or payee positive pay, is available and enroll.
Should we carry cyber or crime insurance for a BEC loss, and what will it expect from us?
Most public entity crime and cyber policies do cover social-engineering losses, but read the fine print before an incident, not after. Insurers commonly require a call-back or independent verification step as a condition of coverage, and set a notice deadline measured in days. Confirm which of the controls in this guide your policy actually requires, and revisit the policy annually as your procedures change.
How often should we reconcile?
Match settlements to deposits daily or every business day, and reconcile bank statements to the ledger monthly, with an independent reviewer signing off.
What should we do first if we sent money to a fraudster?
Call your bank right away to request a recall or freeze, file a report at ic3.gov, notify your insurer, and preserve all records.
What is “friendly fraud,” and does it affect our agency?
Friendly fraud is a cardholder disputing a card payment they actually authorized, most often on an online utility, court or permit payment. It is a card-processing and chargeback issue for your payment processor to help manage, not the vendor and employee impersonation schemes this guide covers, and it calls for a different set of controls.
Where IntelliPay Fits
IntelliPay handles the payment side of your operation. Role-based permissions let you control who on your staff can issue refunds or change settings, and reporting helps you match settlements to your bank deposits. Its platform offers centralized dashboards with visibility across departments and hierarchical permissions that control access to specific functions.
IntelliPay can’t stop a fraudulent vendor email or a payroll change request. Those controls are yours. Start with the five habits above, and ask your payment provider how its reporting supports your reconciliation.
Related reading on IntelliPay.com: Cybersecurity for Small Government · IntelliPay Merchant Guide: PCI DSS 4.0.1 Made Simple · Government Payment Solutions
Sources
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report (ic3.gov)
- Association of Certified Fraud Examiners, Occupational Fraud 2026: A Report to the Nations
- Nacha, Risk Management Topics: Fraud Monitoring Phase 2, and Summary of Upcoming Rule Changes (nacha.org)
- GFOA, Electronic Vendor Fraud (gfoa.org)
- GFOA, Bank Account Fraud Prevention (gfoa.org)
- Office of the Washington State Auditor, Segregation of Duties Guide
- New York State Comptroller, Management’s Responsibility for Internal Controls
- Tennessee MTAS, Common Audit Finding: Lack of Segregation of Duties
- Indiana State Board of Accounts, Uniform Internal Control Standards
- Baltimore City Office of the Inspector General report, as reported by CBS Baltimore (Aug. 2025)
- NJCCIC, Direct Deposit Scams Continue (April 2025)
- Association for Financial Professionals, 2026 AFP Payments Fraud and Control Survey Report, underwritten by Truist
- Federal Reserve Financial Services, 2026 Risk Officer Report
- Insurance Journal / Hunton Andrews Kurth, reporting on cyber-enabled fraud surpassing ransomware and crime-policy social-engineering sub-limits (June 2026)
- Citizen Portal reporting on a Connecticut town’s positive-pay recovery of altered checks (Aug. 2026)
Disclaimer: This article is for general educational purposes only and is not legal, accounting or compliance advice. Requirements vary by state and agency. Have your attorney, auditor or bank review your policies. Last reviewed: September 2026.
