Skip to main content
All guides
9 min read·

Wire transfer fraud and fake invoices in SMEs: dual-authorisation controls, approval workflows, and accounting safeguards in Switzerland

Protect liquidity and reputation with structured internal controls, accounting traceability, and approval processes suited to the realities of Swiss small and medium-sized enterprises.

Why Swiss SMEs are a prime target

Wire transfer fraud and fake invoices do not affect large companies alone. In Swiss SMEs, where one or two people often handle accounting, payments, and supplier relationships, a single mistake or fraudulent email can cause losses of tens or hundreds of thousands of francs within hours. The combined effect of lean processes, the absence of mandatory audit requirements, and the growing digitisation of payments amplifies the risk.

The most frequent cases involve CEO fraud (an urgent wire transfer request from someone purporting to be a senior executive), manipulation of supplier bank details (an altered IBAN on a legitimate invoice), and the issuance of phantom invoices for services never rendered. In Switzerland, where e-banking payments are fast and often irreversible, reaction time is minimal: once the transfer is executed, recovering the money is difficult and costly.

This guide explains how to structure dual-authorisation controls, approval workflows, and accounting safeguards compliant with the Code of Obligations (CO) and Swiss accounting standards, with a practical approach for business owners, administrative managers, and fiduciary firms supporting SMEs.

Types of payment and invoice fraud

Understanding the most common methods is the first step in designing effective controls. Here are the three categories that most frequently affect SMEs in Switzerland:

CEO fraud and social engineering

A message appearing to come from the owner or CFO requests an urgent, confidential wire transfer, often to a foreign account. Time pressure and requests for confidentiality are used to bypass usual controls.

Invoices with altered IBAN

A genuine supplier sends an invoice, but an attacker modifies the IBAN or attaches a forged PDF. The goods or services were actually ordered, which makes the fraud harder to detect at the time of payment.

Phantom suppliers and invoices

Non-existent companies or internal staff create fictitious suppliers, record invoices for services never rendered, and authorise payments to accounts controlled by third parties. The damage accumulates over time when cross-checks are missing.

Informal approach vs. structured controls

Many Swiss SMEs still rely on informal practices. The comparison below highlights where risks concentrate and which measures reduce exposure:

Aspect Informal approach (typical SME) Structured controls
Payment authorisation One person verifies and pays Separation between recording, approval, and execution
IBAN verification Visual check on the invoice received Comparison with approved supplier master data and payment history
E-banking transfers Single signature above a high threshold or none at all Dual electronic signature with limits by amount and beneficiary
Accounting traceability Post-payment recording, scattered documents Documented workflow: order → receipt → approval → posting
Supplier data changes Anyone can update IBAN or address Changes subject to confirmation by a second person
Response to urgent requests Immediate payment to avoid delays Anti-fraud procedure: callback on a known number
Internal accountability Undefined or implicit Roles and signing limits formalised in writing
Periodic review Only at year-end closing Monthly bank reconciliation and payment sampling

The four-eyes principle (dual control)

Dual control, or the four-eyes principle, requires that no critical financial transaction can be completed by a single person. In Switzerland, there is no uniform legal obligation for all SMEs to introduce dual control, but Art. 957a CO requires verifiable accounting appropriate to the business, and Art. 716a para. 3 CO (AG) or Art. 810 para. 2 no. 3 CO (GmbH) require the board of directors or managing officers to define the accounting organisation and financial control; Art. 717 CO and Art. 812 CO further require diligent oversight of management. Documented internal controls are the practical response to these duties.

Segregation of duties

Ideal: three distinct roles — the person who records the invoice, the person who approves it, and the person who executes the payment. In SMEs with few staff, at least two roles must be separated: whoever prepares the payment cannot be the sole signatory.

Example: the administrative assistant records the invoice in accounting; the finance manager or owner approves it; only then is the payment entered in e-banking with joint signature.

Dual bank signature

Configure e-banking with joint signature (Z1/Z2 or Z1/Z2/Z3) and differentiated limits by amount. Typical thresholds: up to CHF 5,000 single signature by the owner; from CHF 5,001 to CHF 50,000 dual internal signature; above CHF 50,000 dual signature with documented telephone confirmation.

Periodically verify the list of authorised signatories with the bank and revoke access immediately when staff leave.

Approval workflow: from document to wire transfer

A structured workflow links every payment to verifiable documents and creates a chain of accountability. Here are the recommended stages for a Swiss SME:

1

Receipt and recording

The invoice arrives by email, portal, or post. It is recorded in accounting with reference to the purchase order or contract. If the order is missing, the invoice remains on hold until verified with the relevant department manager.

2

Master data and IBAN verification

Compare IBAN, amount, and supplier details with the approved master data. Any IBAN change requires written confirmation from the supplier on a separate channel (call the number on file, not the one on the suspicious invoice) and approval by a second person.

3

Formal approval

The authorised manager approves the payment according to defined limits (e.g. manager up to CHF 10,000, owner above). Approval is tracked in accounting software with date, user, and any notes. Payments outside budget or to new suppliers require additional approval.

4

Execution and reconciliation

The payment is entered in e-banking and signed according to the signing rules. At month-end, bank reconciliation verifies that every outgoing payment corresponds to an approved, posted invoice. Discrepancies trigger a detailed review.

Accounting safeguards: traceability and compliance

Fraud prevention is not only an IT or banking issue: accounting is the alert system and the evidential basis in the event of a dispute. Recognised accounting standards (Art. 962a CO), in particular Swiss GAAP FER for SMEs and, where applicable, IFRS, require complete, understandable, and verifiable records.

Document retention: under Art. 958f CO, accounting documents must be retained for ten years. Invoices, orders, approval confirmations, and bank statements form the dossier for every payment and are essential for insurance claims, reports to cantonal police, or civil proceedings.

Controlled supplier register: maintain a supplier master file with IBAN verified at first payment. Subsequent changes must generate an audit log. Accounting software such as Accountex allows every invoice to be linked to the master supplier record and flags inconsistencies in bank details or recurring amounts.

Reconciliation and analysis: monthly bank reconciliation is not a formality: it identifies payments without supporting documentation, duplicate payments, and unusual amounts. A quarterly analysis of the top ten suppliers by payment volume helps detect phantom suppliers or unusual concentrations.

Audit and fiduciary support: SMEs subject to ordinary or limited audit benefit from additional external oversight. Even without mandatory audit (opting out under Art. 727a para. 2 CO, if the company does not exceed an average of 10 full-time equivalent positions per year and all shareholders or members consent), a fiduciary firm can define an internal control plan and verify its application once or twice a year.

Red flags to monitor

Some indicators warrant immediate review, regardless of amount:

Signal Possible fraud Recommended action
Urgent, confidential payment request CEO fraud Call back the sender on an official number; do not pay until confirmed
IBAN different from supplier's historical record Invoice manipulation Verify with supplier on an independent channel; block payment
New supplier with high amount Phantom invoice Verify existence (UID, commercial register), contract, and references before first payment
Duplicate invoices or irregular numbering Double payment or internal fraud Compare with received invoice register; report to manager
Payments to unusual foreign accounts Fraudulent transfer Enhanced approval; verify AMLA compliance where applicable
Resistance to approval procedures Possible internal fraud Internal investigation; involve fiduciary firm or legal counsel if necessary

Practical implementation: from paper to digital

Even an SME with limited resources can introduce effective controls within a few weeks, combining internal rules, banking tools, and accounting software:

Weeks 1–2: rules and roles

  • Draft an internal payment policy (limits, signatures, exceptions)
  • Define who approves, who pays, and who reconciles
  • Configure dual e-banking signature with amount thresholds
  • Train staff on CEO fraud and IBAN verification

Weeks 3–4: accounting digitisation

  • Centralise supplier invoices in a single flow (dedicated email, scanning)
  • Link every payment to invoice and purchase order in Accountex
  • Enable alerts on supplier master data changes
  • Start systematic monthly bank reconciliation

Digitisation does not replace human judgement, but it reduces errors and creates verifiable trails. A digital workflow makes the status of every invoice visible — received, pending approval, ready for payment, paid — and prevents suspicious documents from slipping through the cracks.

Operational checklist for Swiss SMEs

Use this list to assess the state of your internal payment controls:

  • Internal payment policy drafted and communicated to all involved staff
  • Dual e-banking signature active with defined and verified amount thresholds
  • Segregation: the person who records, approves, and pays are different individuals (where possible)
  • Supplier master data with verified IBAN; changes subject to dual confirmation
  • Invoice → approval → payment workflow tracked in accounting
  • Anti-CEO fraud procedure: mandatory callback for urgent payments
  • Monthly bank reconciliation completed and documented
  • Periodic staff training on fraud and red flags
  • Annual review of bank signatory list and IT access
  • Insurance coverage verified for losses from cyber fraud

Conclusion: prevention as investment, not cost

Wire transfer fraud and fake invoices affect SMEs of every sector and size in Switzerland. Dual-authorisation controls, approval workflows, and accounting safeguards are not superfluous bureaucracy: they are the most effective barrier between company liquidity and often irreversible losses.

Starting with a few clear rules — segregation of duties, IBAN verification, dual bank signature, accounting traceability — and strengthening them with digital tools such as Accountex makes it possible to build solid defences without unduly burdening the organisation. The cost of implementing these controls is negligible compared with the average damage from a single successful fraud.

For business owners and fiduciary firms, payment fraud prevention is today an integral part of responsible business management and the accounting compliance required under Swiss company law.

Simplify your Swiss accounting

AccountEX handles VAT, QR-invoices and bookings with AI. Start for free.