Raffles Consulting Services

Family office payment verification against email compromise

Family office payment verification should use independent confirmation, controlled bank-detail changes and a rapid response record for suspicious instructions.

Family office payment verification should never rely on the same email thread that requests a new bank account or an urgent transfer. Use an independently held contact and a different communication channel to confirm the instruction. Then record who requested, checked, approved and released the payment.

This is especially important where a small team handles large transfers, senior principals travel frequently and external advisers exchange sensitive instructions across several jurisdictions.

Recognise the payment-change risk

The Cyber Security Agency of Singapore describes business email compromise as an email-based technique used to obtain confidential information or divert payments. Attackers may impersonate a senior executive, business partner or known contact through a spoofed address, lookalike domain or compromised genuine account.

For this reason, an instruction can therefore appear inside a real conversation and use familiar names, invoices and transaction details. Grammar and visual appearance are weak controls. A genuine account can send a fraudulent message after compromise.

Common warning signs include unusual urgency, secrecy, a request to bypass normal channels, a changed beneficiary, or a reply address that differs from the displayed sender. Treat an unexpected change as a new instruction that needs fresh verification.

Keep a controlled master record of approved counterparties, bank accounts and verification contacts. Access should be limited, changes logged and periodic reviews documented.

Confirm through an independent channel

In practice, the current CSA advisory on business email compromise recommends secondary confirmation for funds transfers, supplier bank-account changes and invoice payments. The confirmation should use a different medium, such as a known telephone number or text contact, so the attacker cannot control both sides of the check through the compromised mailbox.

Do not call the number supplied in the change request. Retrieve the contact from the signed agreement, approved counterparty record or another trusted source established before the request arrived.

Ask the contact to confirm the legal beneficiary name, bank, account ending, currency, invoice reference and reason for change. Avoid reading out every detail first. The verifier should record the time, number used, person reached and result.

At the same time, if voice impersonation is a concern, use a second known contact, secure portal or pre-agreed transaction challenge. The purpose is to create independent evidence, not merely add another message to the same chain.

Separate setup, approval and release

Assign different people to maintain beneficiary details, approve the underlying obligation and release the bank payment where the team size permits. For a lean office, use principal approval plus an external administrator or another authorised reviewer for high-risk changes.

Set thresholds for new beneficiaries, changed accounts, overseas payments and urgent releases. A payment below the monetary threshold may still require enhanced checks if the bank detail changed or the request breaks normal practice.

As a result, Require the payment preparer to attach the invoice, contract, approval, independent confirmation and bank-screen evidence under one transaction identifier. The releaser should compare the beneficiary on the bank screen with the verified record, not with an email pasted into the payment description.

Do not allow seniority to override the process. An attacker often uses a principal’s apparent authority and a confidential tone to stop staff from checking.

Use a short verification record

Control Evidence to keep Failure response
Counterparty identity Signed agreement and approved master record Stop if legal names differ
Bank-detail change Independent call or secure-channel confirmation Freeze the change
Payment purpose Invoice, contract, calculation and owner approval Resolve unsupported amount
Bank entry Maker screen and beneficiary comparison Cancel before release
Final release Authoriser identity, time and bank acknowledgement Escalate any mismatch
Post-payment review Receipt or counterparty confirmation Start incident response quickly

Test the process with realistic cases, including a familiar adviser changing an account, a principal requesting secrecy and a genuine mailbox sending an unusual instruction. Staff should know that stopping a suspicious payment is expected behaviour.

Protect the email environment

For example, CSA recommends strong passwords, two-factor authentication, removal of dormant accounts, monitoring of access logs and review of suspicious forwarding rules. It also identifies SPF, DKIM and DMARC as email-authentication measures that help reduce spoofing.

The CSA organisation advisory links to a detailed response playbook. The playbook recommends restricting automatic forwarding to external addresses, maintaining useful audit logs and training employees to inspect urgent messages closely.

Give finance-related mailboxes stronger controls. Limit administrator rights, require multi-factor authentication, review delegated access and retain logs for investigation. External providers should state how they secure, monitor and return the family office’s data.

In addition, Email security does not replace payment verification. The controls work together because no filter or authentication method proves that every instruction from a genuine account is authorised.

Respond while recovery remains possible

If a suspicious instruction is found before release, freeze the beneficiary and preserve the email with its headers. Contact the apparent sender through a known channel, notify the internal incident owner and check related messages and forwarding rules.

If money has moved, contact the sending bank immediately and ask it to attempt recovery or recall. Notify the receiving bank where advised, preserve the payment trail and make the appropriate reports to the authorities. Speed matters, so the response contacts and authority should be agreed before an incident.

For this reason, Reset compromised credentials, revoke active sessions, enforce multi-factor authentication and review mailbox rules and logs. Search for other payment changes or data access from the same period.

Assess whether personal data was affected and follow the family’s data-breach process. The payment incident, cyber investigation and PDPA assessment may have different owners, but their evidence should use one incident timeline.

Make verification routine

The family office governance operating model is the pillar cornerstone. The family office data-breach guide covers the PDPA response, and the Family Office and UHNW hub connects related guidance.

In practice, Strong family office payment verification is deliberately uneventful. A known contact, separate channel, clear approval trail and prepared response plan make an urgent email less able to turn authority and trust into a loss.