Insider threat cases rose by 21% in 2025, according to Cifas’ Fraudscape 2026 report, providing a timely reminder for finance and treasury teams to review internal payment controls and approval procedures. However, all too often organisations fall into the trap of thinking their payment processes are more secure than they really are.
Standard payments practice
Consider the standard payments operating model in many medium to large organisations. The accounts payable (AP) team prepares a payment file in the enterprise resource planning (ERP) system and emails it to treasury. Treasury then manually uploads the file into the treasury management system (TMS) or to a banking portal, and the payments are sent.
It’s a long-standing model designed before it was possible to connect ERPs and TMSs with each other and with the banking estate that has become embedded across finance and treasury operations. Most finance and treasury leaders are aware of the inefficiencies of this disconnect, but it also introduces risks to payment processes that often don’t become apparent until an audit, a fraud investigation, or an outage.
False sense of security
Indeed, finance leaders often believe they are better protected than they are because each stage of the AP process includes controls and sign-offs. For example, payment files must be approved by the Chief Financial Officer before they can be uploaded to the TMS or bank portal.
However, when handoffs across the payment process occur via email, there is no end-to-end system audit trail. Email does not constitute a system of record, nor does it ensure file integrity. There is no immutable link between the approved file in the ERP and the payment execution; the two files can differ, and there is no live mechanism to track these differences.
Additionally, when bank portals are used to execute payments, shared logins, which are commonplace, can make the transaction trail hard to follow.
Hidden risks
The result is a payments process that, although it seems functional because payments go out, carries many underlying risks.
First, there is an increased risk of insider fraud. Court reports over the years show many examples of fraud in which insiders have exploited weak links in payment processes to divert funds to their accounts, such as the case of an NHS credit controller who authorised £300,000 in fraudulent payments. So, it is essential to always be alive to the possibility of internal deception and to identify gaps in processes.
The email transfer of the approved beneficiary file from the ERP to the treasury team is one such example, creating an opportunity for a rogue employee to amend details without a trace, because file integrity is not checked between approval and submission.
Or that rogue employee might simply sell their login details for someone else to carry out the fraud. Cifas’ Workplace Fraud Trends survey reports that 13% of employees admitted to selling their login details to former colleagues or knew someone who had done so, highlighting the inherent weaknesses of email-based approval chains, where there is no immutable log.
Second, human error is much more likely when manually transferring data between systems and bank portals. Common issues include duplicate payment file submissions, incorrect data entry when retyping information, and payment file version mismatches between systems, which can cause the bank portal to reject the payment file.
Administrative problems such as these have a material impact on payment flows, often delaying invoice payments. Research from the UK’s Department for Business & Trade into late payment practices found that 36% of UK businesses cited administrative errors as the reason behind delayed supplier payments.
Finally, there is the question of operational resilience. Manual file transfers via email fall down when key staff members are absent, and there is no cover. Furthermore, organisations are at the mercy of bank portal availability when uploading data, which isn’t always guaranteed. Data from the UK Parliament’s Treasury Committee shows that between January 2023 and February 2025, nine of the UK’s top banks and building societies experienced more than 803 hours of unplanned outages, totalling 33 days, creating problems for companies accessing those systems.
What better looks like
Mitigating insider fraud risks and strengthening operational resilience in payments are multifaceted and layered exercises. There are no silver bullets, and it is important to establish a strong culture of control and risk management.
From an internal fraud perspective, this includes segregation of duties across the approval chain, controls to verify beneficiaries and confirm bank details, regular reconciliation to spot discrepancies, and an audit and governance process to ensure accountability.
From an operational resilience standpoint, finance and treasury leaders must understand and monitor potential weaknesses and implement plans to mitigate them. For example, if key staff are unavailable, who has been trained to deputise for them? Or, if a bank portal is inaccessible, how else can critical payments be made?
Alongside these elements, bank connectivity can also play a vital role. Bank connectivity solutions provide an agnostic layer between ERPs, TMSs, and other back-office solutions and the banking estate, enabling the flow of payment and statement data and closing that problematic handoff gap in payment flows.
It means there is a structured, system-driven workflow from AP to treasury to banks, with no email dependency or reliance on bank portal logins, and an end-to-end audit trail across the payment lifecycle. File generation and transfer are fully controlled, and manual intervention occurs only to investigate exceptions, not as the default process.
Beyond removing manual steps and email dependencies, bank connectivity can also help to deliver other controls as part of an automated workflow. Examples include multi-factor authentication as standard for payment file submission, sanctions screening for every payment, and account name verification checks before the payment leaves to check the beneficiary, all of which serve to further derisk payment processing.
Rethinking payment processes
When AP payments are not connected to a group payment platform, manual processes often fill the gap. Yet the question for finance and treasury leaders is whether manual handoffs and disconnected approval workflows still have a place in a modern control environment. Redesigning processes around secure, system-driven workflows enabled by bank connectivity and establishing a strong control culture help not only to reduce fraud risk and improve resilience but also provide organisations with greater confidence that payments are authorised, executed and logged as intended.



