Case 022Operational risk and loss eventsWarm up
A company's finance team wires Rs 18 crore to a fraudster after an email that appeared to come from its CEO, and the bank recovers 30%. What is the loss, and which controls would each have stopped it?
1The situation
On a Friday afternoon a finance manager at Paynika Technologies receives an email that appears to come from the CEO, who is travelling. It asks for Rs 18 crore to be paid urgently and confidentially to a new supplier for an acquisition, with bank details attached. The email address differs from the CEO's by one letter.
The manager adds the new beneficiary, approves the payment alone under the company's single-approver limit, and the bank executes it. The fraud is discovered on Monday; the bank recalls what is still in the receiving accounts, 30% of the amount. Paynika has no call-back rule, no second approver for this size and no special check on new payees.
2Your task
What is Paynika's net loss, and where in the payment process would each missing control have stopped it?
Quick check
Which single control would have been most likely to stop this particular fraud?
Worked solution
Try it on paper, then open one step at a time.
30-second answerThe answer to give first
Paynika's net loss is Rs 12.6 crore: Rs 18 crore wired, Rs 5.4 crore recovered. Three process controls were missing, and each alone would have stopped it: a call-back to the CEO on a known number before acting on an emailed instruction, a check and cooling-off on new or changed payee details, and a second, independent approver for large payments. The fraud succeeded on process, not on anyone's carelessness.
Step 1Why does this fraud work on careful people?
Picture a call from someone who sounds like your relative, stranded, needing money right now and asking you not to tell anyone. The urgency and the secrecy are the tools: they stop you checking. Business email compromise works by creating urgency and secrecy so that the victim skips verification, which is why the defence has to be a rule that does not depend on anyone noticing the fake. A one-letter difference in an email address on a Friday afternoon is invisible to most people.
Step 2What is the loss?
Rs 18 crore left the account. By Monday most had been moved on, and the bank recalled 30%, Rs 5.4 crore. The net loss is Rs 12.6 crore, before investigation costs and management time. The recovery rate is itself a lesson: money in fraud accounts moves within hours, so the speed of reporting to the bank matters almost as much as prevention.
Step 3Where would each control have stopped it?
Map controls to steps. A call-back on a number already on file stops it at step 1, because the fraudster controls the email but not the CEO's phone. A payee-change checkAn independent verification, often with a waiting period, before a new or changed beneficiary bank account can be paid. stops it at step 2: new bank details from an email would be verified with the supplier through a separate channel and held for a day. Independent dual approval stops it at step 3, but only if the second approver verifies the instruction rather than trusting the first; two people reading the same forged email can both be fooled.
| Control | Step it acts on | Why it works | How it fails |
|---|---|---|---|
| Call-back on a known number | 1. Instruction | Goes around the forged channel | Calling the number in the email |
| Payee-change check and cooling-off | 2. New beneficiary | Verifies bank details independently | Waived for urgent payments |
| Independent dual approval | 3. Approval | A second person must be convinced | Approver signs without checking |
Close with the design principle. Every one of these controls has an exception route, the urgent confidential payment, and that route is exactly what the fraudster asks for. So the rule has to say that urgency and secrecy trigger more verification, not less, and the CEO has to be seen following it. The limitation: controls add friction to genuine urgent payments, and a policy that is routinely waived is worse than none, because it gives false comfort.
Where candidates lose it
Candidates answer with training and awareness. Training helps, but the loss happened because the process let one person act on one email; the interviewer wants controls that work even when someone is fooled.
The second miss is treating dual approval as sufficient. Two approvers reading the same forged email add little unless the second one independently verifies the instruction.
What the interviewer asks next
- How would you record this in the operational loss database, and which event type does it fall under?
- What would you set as the threshold for mandatory call-backs, and why?
- The bank that received the money had flagged the account before. Does Paynika have a claim against it?
Company names and figures are illustrative.
