← All discussions

Other Discussion

Our summer intern just redirected a 拢2.3m supplier payment to their personal Starling account and we only caught it because Monzo's fraud algorithm flagged the sort code mismatch

Damilola Joshi 路 26 Jul 2026

I'm still shaking. We brought on six interns through the LSE summer programme in June, gave them standard finance system access with supervisor approval controls. Someone in Accounts Payable rubber-stamped a payment run without checking the amended bank details buried in the supplier master file. The intern, clever kid, clearly, changed the sort code and account number at 5:47pm on a Friday, waited for the usual end-of-week batch, and it sailed through. Monzo's system flagged the payment before it landed because the account had been opened 14 hours earlier and had zero transaction history. Barclays would've let it through. So now I'm staring at a conduct risk nightmare: Do I report this to the FCA as an operational resilience failure? Do I call the Met's economic crime unit and torpedo a 19-year-old's life? And more practically, how are you all verifying supplier bank detail changes when even the two pairs of eyes rule clearly doesn't work once someone's fatigued on a summer Friday?
馃憤 875 馃挰 8

8 replies

Tariq Roberts 路 26 Jul 2026

I've tried implementing a 7-day delay on all new supplier payments using our Oracle system, but it didn't catch this type of issue as the payment was flagged as a routine update. We also used Splunk to monitor system logs, but the intern's changes didn't raise any red flags until Monzo's algorithm kicked in, so it's back to the drawing board for us.

Ayaan King 路 26 Jul 2026

Fortunately our company's moved to a four-eye approval process for any changes to supplier details, it's an extra layer of admin but clearly worth it considering what could've happened. We've also started doing regular audits of user access permissions to make sure they're still relevant.

Margaret Hawkins 路 26 Jul 2026

Given that 80% of companies I've consulted for use SAP for their finance systems, I'm surprised this wasn't caught by a more basic audit rule. Implementing a tool like NetSkope to monitor user activity might've helped identify this issue earlier, as it can flag suspicious changes to sensitive data.

Sade Park 路 26 Jul 2026

I always make sure to check the audit logs daily, it's a pain but it's caught a few dodgy changes for me in the past, might be worth someone reviewing those to see if there were any other tweaks made around the same time.

Enitan Gray 路 26 Jul 2026

I tried using a machine learning based anomaly detection tool but it didnt catch this kinda thing as its mostly looking for patterns in spend volumes not payment detail changes.

Tobi Thomas 路 26 Jul 2026

We limit new staff to view only access for their first month so they can't make any changes to our systems.

Evelyn Sullivan 路 26 Jul 2026

Honestly I think you're lucky to have caught this so quickly, Monzo's fraud team must be on the ball. We've been using a separate tool called Confirmation.com to verify supplier bank details and it's been a big help in reducing this kind of risk. I'm not sure what your process is for onboarding new suppliers but we've found that doing regular checks on their company registration and VAT numbers helps to prevent this kind of thing from happening in the first place.

Bennett Jimenez 路 26 Jul 2026

I set up a weekly review of all supplier payments over 10k with our finance team, but we still managed to miss a similar issue last year. We've since switched to using Google Workspace to collaborate on payment reviews, and I'm hoping the added visibility will help us catch anything suspicious.

Log in or create a free account to join the conversation.