What the Treasury and SEC Can Teach CFOs About Fraud
The most expensive fraud control is becoming the one that works perfectly, just a few seconds too late.
Highlights
Fraud prevention is moving from detection to prevention at the point of payment. Treasury screened $3.7 trillion in federal payments, stopping $175 million in improper disbursements and demonstrating the value of verifying recipients before money moves.
AI is making traditional payment approvals incomplete. The SEC’s warnings about AI-powered impersonation showed that an authorized payment isn’t necessarily a legitimate one, especially when beneficiary details can be manipulated.
The next competitive advantage for CFOs is integrated payment intelligence. Connecting authoritative identity data, beneficiary verification, and fraud controls directly to ERP and payment execution systems could stop fraudulent transactions without slowing legitimate payments.
The most expensive fraud control is becoming the one that works perfectly, just a few seconds too late.
Two developments from Washington this week, one from the U.S. Treasury Department and the other from the Securities and Exchange Commission, suggest that the next competitive advantage in financial security may come from making it impossible for questionable payments to leave in the first place.
New data from the U.S. Treasury Department’s Fiscal Year 2026 Fraud and Improper Payments Report showed Tuesday (Oct. 6) that the federal agency screened more than 1.1 billion federal payments totaling approximately $3.7 trillion during fiscal 2026, identifying and returning roughly 13,500 payments worth $175 million that would have gone to ineligible individuals, many of them already deceased.
“Treasury continues to transform how the federal government protects taxpayer dollars by using better data, stronger controls, and advanced technology to stop fraud and improper payments before money goes out the door,” Treasury Secretary Scott Bessent said in a statement.
A day earlier, the SEC and fellow regulators warned investors that artificial intelligence is making impersonation convincing, including through fabricated communications, documents and representations of legitimate financial institutions.
The two announcements address different problems. Treasury is focused on preventing improper government disbursements, while the SEC’s bulletin addresses investor protection. Neither establishes new corporate payment requirements.
But together, they expose a vulnerability familiar to enterprise chief financial officers. A payment can pass every internal approval and still be directed to the wrong recipient.
Read also: OFAC Warns Sanctions Risk Can Hide Deep in the Payment Chain
The question for CFOs today is no longer simply whether finance can detect suspicious activity but whether identity, account ownership and payment eligibility can be verified against reliable information at the moment money moves.
The Treasury and SEC developments highlight a disconnect in corporate back-office modernization where enterprises have invested in accelerating invoice processing, automating payment approvals and reducing manual intervention. Yet fraud prevention can remain fragmented across procurement, vendor management, cybersecurity, treasury and banking partners.
Consider a supplier requesting an urgent change to its banking instructions. The email appears authentic. The invoice matches an existing purchase order. The sender references an ongoing commercial relationship. A finance employee follows the established approval workflow. Every element may look legitimate, yet none independently establishes that the destination account belongs to the intended supplier.
This distinction is one that finance teams should watch as AI makes fraudulent communications easier to produce and harder to distinguish from authentic correspondence. Traditional approval controls often establish that an authorized employee approved a transaction. They do not necessarily establish that the underlying payment instructions are genuine.
The PYMNTS Intelligence report “Fraud’s Loyalty Tax: How Scams Cost Banks Their Customers” found in September that first contact from scammers by SMS or text rose 35% since September 2025, reaching 12% of victims in July. Email moved in the opposite direction, falling 30% to 13%. Email led text by 10 percentage points less than a year earlier; the difference is now less than 1.5 points.
“Cybercriminals used to be more targeted,” Katie Elliott, senior risk and fraud officer at Bottomline, told PYMNTS in an interview published Wednesday (Oct. 7). “Now they can do mass spamming, mass phishing.”
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
They are using the technology that’s out there, the AI, every tool available to them in order to make their attempts bigger, broader, faster,” she added.
See also: Federal Approval No Longer Guarantees CFOs a Green Light
Approval establishes permission to pay. Verification establishes whether the payment should proceed. Finance departments need both.
Treasury said in its Tuesday report that it increased Do Not Pay access from 4% of programs to 99%, streamlined access to the program’s fraud prevention tools, added nine new data sources to the program, and deployed a new government-wide payment verification process.
Treasury’s expansion of Do Not Pay illustrates a challenge enterprises face when modernizing financial controls. Verification is only as useful as the information systems can access. The federal program’s expanded reach required more than new analytical tools. Treasury streamlined onboarding, expanded authorized access to datasets and completed data-sharing and privacy compliance work.
Still, corporate finance teams cannot simply consolidate every available supplier, banking and identity record into a single database. Privacy obligations, contractual restrictions, inconsistent data quality and regional regulations complicate information sharing.
Banks, payment providers and verification services therefore have a role in providing reliable information at the point of execution. For ERP and payment technology providers, the opportunity is to integrate these capabilities directly into accounts payable and treasury workflows rather than requiring finance teams to consult disconnected screening tools.
“Payment data is interesting because it really is the digital footprint of business,” Ryan Taylor, SVP Product Management – Mobility & Payments at WEX, told PYMNTS in an interview published Thursday (Oct. 8). “It tells you more than just what was spent. It can tell you about what was happening in the business at that exact moment that a payment occurred.”
For banks, the question becomes whether beneficiary verification and fraud controls can evolve from supplemental services into core payment infrastructure. For CFOs, the relevant performance measures may shift from how many suspicious transactions a system flags to how many invalid payments it prevents without disrupting legitimate disbursements.
For all PYMNTS B2B coverage, subscribe to the daily B2B newsletter.
Get PYMNTS Today, AI, B2B and more.
Own the conversation. Drive demand.
Start a Conversation →