Deepfake CFO Fraud: APES 110 & Internal Controls for NSW Firms

Deepfake CFO Fraud in Australia: Governing Synthetic BEC Risks Under APES 110

Protect treasury payments with APES 110-aligned verification, banking-token separation and dual authorisation.

GC
Graham CheePrincipal and Founder, Local Knowledge
FCPA
CPA
GRCP
GRCA
Published 26 August 2026
Expert Content Verification

Content reviewed and verified by Graham Chee, with FCPA-led practice at Local Knowledge, Mascot NSW. Continuous CPA Australia member since 1986. Prior career at Goldman Sachs, BNP Investment Management and Merrill Lynch.. Last reviewed August 2026. Next review scheduled for November 2026.

TL;DR

Protect treasury payments with APES 110-aligned verification, banking-token separation and dual authorisation.

CPA Australia

When an Executive’s Voice Is No Longer Evidence

Deepfake CFO fraud in Australia converts a familiar business email compromise into a more convincing treasury attack. A finance employee may receive an urgent email, followed by a video call or telephone instruction apparently delivered by the CFO, director or trusted adviser. Synthetic audio and video can imitate tone, appearance and organisational context. If the organisation treats recognition of the person as authentication, the attacker may be able to redirect a supplier payment, replace bank details or initiate an exceptional transfer.

This is not merely an IT problem. It is a financial-control, professional-ethics and board-governance issue. APES 110 requires members to apply professional competence and due care, maintain objectivity and use a conceptual framework to identify, evaluate and address threats to compliance with the fundamental principles. It does not prescribe a particular deepfake control, but known impersonation risks should inform how a professional accountant designs and follows payment procedures [APESB: APES 110 Code of Ethics for Professional Accountants].

Principal Advisor Graham Chee, FCPA, CPA, leads Local Knowledge’s principal-led practice in Mascot, NSW. This guide explains how synthetic media BEC works, why familiar approval methods fail, how to separate banking-token powers, and how directors and finance leaders can establish evidence-based, out-of-band verification. The objective is not to identify every fake. It is to prevent an unverified communication from becoming an irreversible movement of money.

The Anatomy of Synthetic Media BEC Attacks Targeting Australian Finance Teams

Synthetic media BEC usually combines identity imitation with process knowledge. An attacker may first compromise an email account, monitor invoice cycles, identify authorised officers and learn when a decision-maker is travelling. Public interviews, webinars and social content can provide material for a synthetic voice or video. The resulting call does not need to be flawless; urgency, authority and a plausible transaction can suppress scrutiny.

The attack often moves through four stages. First, the offender gathers identity and payment-process information. Second, an email or messaging account introduces a confidential acquisition, tax payment, supplier issue or urgent transfer. Third, a cloned voice or manipulated video appears to confirm the instruction. Fourth, the offender pressures the employee to bypass normal review, add a new beneficiary or disclose authentication information.

The balance-sheet exposure is immediate because authorised push payments may be difficult to reverse. The event can also create accounting, insurance, contractual and disclosure questions. A lodged recovery claim should not automatically be treated as recovered cash; recognition and disclosure depend on the facts and applicable accounting standards [AASB: AASB 137 Provisions, Contingent Liabilities and Contingent Assets].

Warning signs include secrecy, changed bank details, unusual payment timing, resistance to call-back procedures, requests to share one-time codes and instructions to use a new communication channel. None proves a deepfake. Collectively, however, they should trigger an enforced stop-and-verify response.

APES 110 Ethical Obligations: Professional Due Care Amidst AI Impersonation

APES 110 applies to members and establishes fundamental principles including integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour. For accountants involved in treasury, accounts payable or control design, synthetic impersonation is relevant because it can create pressure, intimidation, self-interest and familiarity threats. A familiar-looking executive may cause an employee to place personal recognition above contradictory evidence.

Professional competence and due care under section 113 includes maintaining the knowledge and skill required for competent professional service and acting diligently in accordance with applicable technical and professional standards. It does not mean an accountant guarantees that fraud will never occur. It does mean that emerging threats should not be ignored where they are relevant to the work [APESB: APES 110, Section 113 Professional Competence and Due Care].

The conceptual framework in section 120 requires a member to identify, evaluate and address threats to compliance with the fundamental principles. In practice, safeguards may include mandatory call-backs, segregation of duties, transaction limits, independent beneficiary verification and documented exceptions. If pressure from a director or executive would require a member to override a control without adequate evidence, the member should escalate the matter and document the professional judgement applied.

Confidentiality also matters. A verification process should not expose passwords, token responses, payroll data or sensitive transaction information unnecessarily. APES 110 supports disciplined judgement; it should not be represented as prescribing particular software or making a business immune from AI wire fraud.

Flaws in Traditional Controls: Why Standard Email and Phone Authorisations Fail

Designing Multi-Tiered Dual Authorisation for AI-Resilient Treasury Operations

Effective dual authorisation is a design principle, not simply a bank setting. It requires two genuinely independent people to review defined transaction attributes before release. Their authority should be appropriate to the amount and risk, and neither should be able to complete every critical step alone.

A practical model uses risk tiers. Routine payments to established beneficiaries may follow standard maker-checker controls. A first payment, changed bank account, unusual jurisdiction, amount outside normal patterns or executive-directed exception should move to enhanced verification. High-risk transactions may require a director-level approver who is not the requester, plus bank release by another authorised officer.

A control sequence for AI voice-clone scams is:

  1. The preparer matches the payment to the invoice, contract, purchase approval and supplier master record.
  2. A separate person verifies new or changed bank details through a known contact using independently sourced details.
  3. The first approver reviews the beneficiary, amount, purpose, timing and exception flags.
  4. The second approver independently reviews the same transaction in the banking platform rather than approving from an email summary.
  5. The bank releaser uses an individually assigned token or secure banking credential and confirms the transaction shown on the trusted device.
  6. Evidence of verification, approvals and any exception is retained with the payment record.

Delegations should specify limits, prohibited self-approval, temporary coverage and emergency procedures. Dormant users and former employees should be removed promptly. These measures also support reliable financial records under section 286 of the Corporations Act 2001 [legislation.gov.au: Corporations Act 2001, section 286].

Establishing Cryptographic and Out-of-Band Verification Protocols in NSW Firms

Out-of-band verification uses a trusted path that is separate from the channel carrying the payment request. If an instruction arrives by email, verification should use a pre-registered telephone number, an approved internal workflow or direct contact initiated from a controlled directory. Employees should never use contact details supplied in the suspicious message.

The verification should be transaction-specific. A generic question such as whether the CFO requested a payment can be manipulated. Confirm the legal payee, amount, bank-account suffix, purpose and deadline. For highly sensitive transfers, an internal challenge phrase may support the process, but a static secret should not be the only safeguard because it can be disclosed or replayed.

Cryptographic controls can strengthen identity and transaction integrity. Examples include phishing-resistant authentication for email and banking access, digitally signed approval workflows, and bank applications that display the payee and amount before approval. The business should verify what the credential actually authenticates: logging into a system is different from signing a specific transaction.

Banking tokens must remain individually assigned. An executive must not read a one-time code to another person, and finance staff should not store token devices with shared passwords. Access reviews should compare banking users with current employment, delegations and leave arrangements. Cyber guidance for businesses also supports multifactor authentication, access control, backups, staff awareness and incident planning [business.gov.au: Protect your business from cyber threats].

If fraud is suspected, contact the financial institution immediately through a trusted number, suspend affected access, preserve evidence and follow the organisation’s incident-response and reporting obligations.

Governance Checklist: Audit-Proofing Internal Controls Against Deepfake Attacks

No control framework is literally audit-proof or fraud-proof. The defensible objective is an audit-ready system that shows how the organisation identified the risk, assigned accountability, implemented controls, tested operation and remediated deficiencies. Minutes, policies and system logs should agree with actual practice.

Directors should oversee material cyber-enabled financial risks as part of their broader governance responsibilities. Section 180 of the Corporations Act requires directors and officers to exercise care and diligence. Whether conduct satisfies that duty depends on the circumstances; installing software alone does not discharge it [legislation.gov.au: Corporations Act 2001, section 180]. Boards should obtain enough information to challenge concentrated payment powers, repeated exceptions, shared credentials and unresolved audit findings.

An audit-ready governance file should include the payment-authority matrix, supplier master-data procedure, banking-user register, token allocation, training records, exception log, incident plan and periodic control-test results. Sample testing should trace transactions from obligation to bank release and verify that both approval and beneficiary checks occurred.

Management should also decide how a suspected loss will be escalated, investigated and reflected in the accounts. Material events arising after the reporting period require assessment under AASB 110, while possible insurance or recovery assets require careful analysis rather than automatic recognition [AASB: AASB 110 Events after the Reporting Period].

At least annually—and after a banking, personnel or system change—the control owner should test whether a convincing executive impersonation could still cause payment without independent verification.

Frequently Asked Questions

Q.How can an NSW business stop deepfake executive voice wire fraud?

Do not make detection of the fake the primary control. Require every unusual, urgent, new-beneficiary or bank-detail-change request to pass an independent verification process. Call the executive or supplier using a pre-registered number, confirm transaction-specific details, and record who completed the check. Separate beneficiary creation, payment preparation, approval and bank release so that one compromised person or account cannot move funds alone. Banking credentials and tokens must be individually assigned and never shared. Apply enhanced approval thresholds to first payments and exceptions, then test the procedure with realistic simulations. General Australian cyber guidance also recommends multifactor authentication, access management, staff awareness and an incident-response plan [business.gov.au: Protect your business from cyber threats].

Q.Does APES 110 specifically require dual authorisation for payments?

APES 110 does not prescribe dual authorisation as a universal payment rule. It establishes fundamental ethical principles and requires members to use the conceptual framework to identify, evaluate and address threats to compliance. For an accountant responsible for treasury or internal controls, known impersonation and account-compromise risks may make single-person approval inadequate. Dual authorisation, independent beneficiary verification and documented escalation can be appropriate safeguards, depending on the entity’s size, systems and transaction risk. The member should exercise professional judgement and document why the selected safeguards reduce the identified threats to an acceptable level. The relevant obligations include professional competence and due care and the section 120 conceptual framework [APESB: APES 110, Sections 113 and 120].

Q.Is a phone call enough to verify an emailed payment instruction?

Only if the call is independently initiated and forms part of a broader control. Calling a number contained in the suspicious email, signature block or follow-up message does not provide independent verification. Use a number already held in an approved directory, supplier master file or reliable internal record. Confirm the payee, amount, account details, purpose and deadline rather than merely asking whether a payment was requested. A second authorised person should still review the transaction in the banking platform. Caller identification, voice recognition and video appearance are not reliable authentication because they can be spoofed or generated. Layered identity, access and transaction controls are consistent with ASIC’s governance-focused approach to cyber resilience [ASIC: Cyber resilience good practices].

Q.Can directors be liable if a deepfake payment scam succeeds?

A successful scam does not automatically establish personal liability. Directors and officers are, however, subject to the statutory duty of care and diligence in section 180 of the Corporations Act 2001. The assessment is fact-specific and may consider the foreseeable risk, available information, the organisation’s circumstances and the steps taken to govern that risk. Boards should therefore oversee material payment-fraud exposure, approve suitable delegations, obtain reporting on control failures and ensure remediation is followed through. They should not assume that cybersecurity is solely an IT function when the risk includes direct cash loss and unreliable financial records. Legal advice should be obtained on a particular incident or potential breach [legislation.gov.au: Corporations Act 2001, section 180].

Q.What should a finance team do immediately after an AI payment scam?

Contact the bank immediately through a trusted channel and request that the payment be stopped, recalled or traced. Disable or reset affected email and banking access, preserve messages, call records, device logs and approval evidence, and activate the organisation’s incident-response plan. Notify directors, insurers, legal advisers and relevant authorities where required by the circumstances and applicable obligations. Avoid deleting compromised accounts before evidence is secured. The accounting team should separately assess when the loss is recognised, whether any recovery satisfies asset-recognition requirements, and whether the event affects financial statements or subsequent-event disclosures. A recovery request or insurance claim is not itself proof that cash will be recovered [AASB: AASB 137 Provisions, Contingent Liabilities and Contingent Assets].

Expert Insight: Design the Process Around Evidence, Not Familiarity

In principal-led practice, the most useful question is not whether an employee should have recognised a fake voice. It is whether the transaction could move from request to release without independent evidence. Controls should remain effective when the message is persuasive, the apparent executive is senior and the deadline feels genuine. That means giving employees authority to stop, verify and escalate without being penalised for delay. It also means reviewing the actual banking permissions and token custody rather than relying only on written policy. APES 110 supports this disciplined, evidence-based exercise of professional judgement [APESB: APES 110 Code of Ethics for Professional Accountants].

Strengthen Your Payment Controls Before the Next Urgent Request

Deepfake CFO fraud is best addressed through governance, independent verification, banking-token discipline and genuinely separate authorisation. NSW firms should map who can create, approve and release payments, then close any path that depends on voice, video or email recognition alone. For a principal-led review of your finance controls, delegations and APES 110 considerations, speak with our principal.

About the Author

Graham Chee

Graham Chee, FCPA, CPA, GRCP, GRCA

Principal and Founder, Local Knowledge

Graham Chee is the principal and founder of Local Knowledge, an FCPA-led Australian practice that brings institutional-grade compliance, investment-structure and intellectual-property experience directly to owner-managed businesses. Graham is a Fellow of CPA Australia (FCPA since November 2005, continuous CPA member since 1986) and holds the OCEG Governance, Risk & Compliance Professional (GRCP) and Governance, Risk & Compliance Auditor (GRCA) designations. His prior career includes senior roles at Goldman Sachs, BNP Investment Management and Merrill Lynch. Graham was previously portfolio manager of the Asian Masters Fund (IPO December 2007 – 31 December 2009), which returned +29% in AUD terms versus the MSCI Asia Pacific (ex Japan) benchmark. He signs off on 100% of client files personally.

Areas of Expertise:

Strategic Business Advisory
Taxation Planning & ATO Compliance
Business Valuation
Succession Planning
Investment-Structure Governance
Governance, Risk & Compliance
Australian Financial Reporting (AASB)
Intellectual Property Protection
Experience: FCPA-led practice at Local Knowledge, Mascot NSW. Continuous CPA Australia member since 1986. Prior career at Goldman Sachs, BNP Investment Management and Merrill Lynch.
This insight was generated by our AI intelligence engine

Contact Us Today

General information only. Speak to us for advice specific to your situation. Every file is signed off by our principal under CPA Code of Ethics.

Graham Chee FCPA, CPA, GRCP, GRCA · Principal, Local Knowledge · Mascot NSW · CPA-signed files