
A family office should authorize transfers so that no single instruction can both move money and define where it goes, and so that verification always travels over a channel the requester does not control. Those two properties are where we would concentrate effort. Everything else, including thresholds, documentation and exception handling, exists to keep them intact under pressure.
Why the corporate answer does not transfer
The corporate control is segregation of duties. The GAO Green Book, which sets the federal standard for internal control, defines it as dividing key duties among different people, separating authorization, processing and recording, review, and asset handling “so that no one individual controls all key aspects of a transaction or event.”
Two things complicate that in a family office. First, arithmetic: a small office often cannot divide a payment among enough independent hands to satisfy that description and still function. Second, and more awkward, the person best positioned to bypass the control is frequently the principal, and an employee is rarely in a position to refuse them.
The standard names the general problem. Management override “circumvents existing control activities,” and while segregation of duties mitigates it, the standard is explicit that it “cannot absolutely prevent it.” That describes management in any organization; our observation is that in a family office the risk concentrates in one person to a degree a corporation rarely faces.
It is easy to conclude that proper controls are unavailable at this size. The standard says otherwise. Where segregation of duties “is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse” (paragraph 10.23). The objective is not waived because the office is small. It is met a different way, which is also why a family office cannot simply run a scaled-down corporate program.
What the attacker is exploiting
Not the network. The instruction. Analyzing how criminals target real estate transaction processes, FinCEN identified “a common lack of strong authentication processes for verifying identity and validity of instructions in associated communications.” That weakness is not specific to real estate, and closing it is the substance of this article.
Federal reporting does not segment this by family office, so the scale is sector-wide: business email compromise produced 24,768 complaints and $3,046,598,558 in reported losses in 2025, second only to investment fraud among cyber-enabled fraud categories, and up from 21,442 complaints and $2,770,151,146 the year before, according to the FBI’s 2025 Internet Crime Report. Speaking to this audience directly, FinCEN found in 2019 that criminal groups conduct the fraud “against individuals, particularly and increasingly those with high net worth.”
Three details shape the design. First, FinCEN describes attackers impersonating senior figures “to discourage employees receiving the fraudulent payment instructions from challenging or confirming the order,” and found roughly half the business email compromise fraud it observed targeting financial institutions used emails impersonating a chief executive or president. That measured population is financial institutions, not family offices, but the design consequence carries over: impersonation is chosen partly to make verification feel insubordinate, so a control resting on a junior person’s willingness to question a senior one is pressed at a weak point.
Voice alone is also no longer a reliable authenticator. IC3 records voice cloning “can also be used to request wire payment,” and that businesses reported over $30 million in business email compromise losses involving AI in 2025, a floor rather than a measure, since it counts only complaints where an AI element was identified. Our resulting rule: treat a phone call as a request, never as a verification.
Finally, FinCEN distinguishes business email compromise, which targets an operating entity, from email account compromise, which “targets personal email accounts belonging to an individual.” A principal’s personal account typically sits outside the office’s controls, so instructions originating there can look entirely legitimate. Why verification protocols are so often absent in trust-based offices we have written about separately.
The two properties that do the work
Verification must run over a channel the requester does not control
FinCEN’s guidance is to verify payment instructions “by using multiple means of communication or by contacting others authorized to conduct the transactions.” The FBI puts it more concretely in a public service announcement on business email compromise: “Use secondary channels and/or two-factor authentication to verify requests for changes in account information.”
Those establish the principle. The three rules below are how we implement it; the guidance does not specify them, and an office may reasonably implement the same principle differently.
- Call a number your office already holds in its own records, not one contained in the request or offered helpfully in a follow-up. If the requester supplied the contact details, the requester controls the verification.
- Never verify an email by replying to it. A compromised account answers its own mail.
- Treat an inbound call as the thing to be verified, not the verification. Given synthetic voice, recognizing a voice is not evidence of identity. Broader channel discipline, including family business conducted through personal accounts, sits alongside these rules.
The destination must be confirmed against a record the instruction cannot change
Offices commonly merge two decisions worth separating: whether a payment should happen, and where it should go. In our experience a successful attempt often leaves the first intact and alters the second, consistent with both FinCEN and the FBI singling out changes to account information as the thing requiring independent verification.
So keep a standing record of counterparties and their banking details, and treat a change to it as a separate, higher-friction event than a payment. Amended details are verified independently of whatever message proposed them. FinCEN frames the underlying task as hardening three processes: authenticating participants in communications, authorizing transactions, and communicating changes about transactions. The third is, in our experience, the least guarded.
Designing the controls when you do not have the people
The evidence above establishes the risk and the control objective. The design choices below are Annapurna’s recommendations.
Separate initiation from release, even across only two people, and write the second person’s job down narrowly: not to agree the payment looks sensible, but to independently confirm the destination against the counterparty record. A reviewer asked only whether a payment seems reasonable can approve a well-researched fraud.
Where a second person genuinely is not available, the useful compensating controls often sit with the bank or custodian rather than inside the office. Ask what they can configure: pre-registered payee lists so funds reach only destinations established in advance, release controls and dual approval on the institution’s side, per-transaction and daily limits, and holding periods on new beneficiaries. These capabilities vary between institutions, so the answer has to come from yours.
Set thresholds against novelty as well as amount. Tying friction only to size can miss a common case, since a modest payment to a destination never used before may warrant more scrutiny than a large recurring transfer to a known account.
Write down authority. The standard requires transactions be “authorized and executed only by persons acting within the scope of their authority” and that management “clearly communicates authorizations to personnel.” We read that as requiring the scope to exist in writing: who may initiate, who may release, up to what amount, and to which destinations.
Then address the principal directly, because in our experience the design fails otherwise. The mandate has to cover the principal’s own requests, and in practice only the principal can impose it. Equally, whoever declines to release an unverified transfer should be protected by written policy rather than their own nerve in the moment. That is what lets the control survive seniority and urgency. Who sets these thresholds and owns the decision is part of the accountability question we work through in family office cybersecurity governance.
Exceptions, and what happens when someone is in a hurry
Pressure to move quickly recurs in these attempts, and FinCEN describes impersonation used specifically to discourage recipients from challenging or confirming an order. So we think the exception path deserves as much design attention as the main one, and it usually receives less.
It should exist in writing, name who can grant it, and preserve destination verification even when it compresses everything else. Speed can be bought by shortening the approval chain. It should not be bought by skipping confirmation of where the money is going.
Log every exception and review them periodically. A pattern of exceptions is often the first visible sign the process is being worked around, or tested, and contemporaneous records are what a recall request rests on later.
Can a fraudulent wire be recovered?
Sometimes, and only on a clock. The common belief that a wire is simply gone changes how offices behave, so the distinction is worth drawing carefully.
FinCEN is direct that such transactions “are often irrevocable,” and concludes that identifying fraudulent instructions “before payments are issued is therefore essential.” That is the right planning assumption, but not the whole picture. Through the Financial Fraud Kill Chain, the FBI’s Recovery Asset Team handled 3,900 incidents in 2025 covering $1,163,919,846 in attempted theft and froze $679,013,183, a 58 percent success rate. That figure spans every incident type the team handles rather than business email compromise alone, and IC3 notes tech support and account takeover initiations rose in 2025.
Recovery should never be planned on, but it is not hopeless when the response is fast, which is why we treat detection speed as a control.
First, know the two calls in advance. IC3 is unambiguous that on discovering a fraudulent transfer “time is of the essence,” and directs victims to contact the financial institution immediately and “request a recall of the funds along with any necessary indemnification documents.” Then report it, where FinCEN records greater success when such transfers are reported “to law enforcement within 24 hours.” Institutional policies on recovery assistance vary, per IC3, so ask your bank what it will do before you need it.
Someone also has to be positioned to notice: confirmations reconciled at month end arrive well after that window closes.
How loss is ultimately allocated between an office and its bank turns on jurisdiction and your own agreements. That is a question for counsel, worth asking in advance, and not answered here.
Where to start
None of this requires a budget. The order we would take it in: write down who may initiate and who may release, and up to what amount; build the counterparty record and document how a change to it gets verified; agree the callback rule and test it once against a real transfer, so you find the awkward parts before you need it; then ask your bank which release and dual-approval controls it can configure, and what it will do if you call with a recall request.
Many offices can do the first three themselves. Building the full design, and documenting it so it survives a staff change, is work we handle through cybersecurity program development. The parts that decay quietly without an owner, meaning exception reviews, threshold changes and keeping the counterparty record current, are what ongoing advisory is for.
Sources
FBI Internet Crime Complaint Center, 2025 Internet Crime Report
