Deepfake CFO Fraud: ASCR & APES 110 Risk for Sydney SMEs

Deepfake CFO Fraud: Safeguarding Sydney SMEs Under ASIC Duties and APES 110

Build verifiable payment controls that reduce AI impersonation risk and support defensible director oversight.

GC
Graham CheePrincipal and Founder, Local Knowledge
FCPA
CPA
GRCP
GRCA
Published 26 August 2026
Expert Content Verification

Content reviewed and verified by Graham Chee, with FCPA-led practice at Local Knowledge, Mascot NSW. Continuous CPA Australia member since 1986. Prior career at Goldman Sachs, BNP Investment Management and Merrill Lynch.. Last reviewed August 2026. Next review scheduled for November 2026.

TL;DR

Build verifiable payment controls that reduce AI impersonation risk and support defensible director oversight.

ASICCPA Australia

Why a Familiar Voice Is No Longer Proof of Authority

Deepfake CFO fraud uses synthetic voice, video or identity material to impersonate a director, finance executive, supplier or adviser. A convincing caller may know the target's name, current transactions and reporting lines. The fraud succeeds when urgency and apparent seniority override the organisation's normal payment controls.

For Sydney SMEs, this is not merely an information-technology problem. A significant fraudulent transfer can create solvency pressure, disrupt tax and payroll obligations, expose personal information and trigger scrutiny of how directors supervised financial risk. Accountants and finance personnel must also consider APES 110's fundamental principles and conceptual framework, including professional competence and due care.

This principal-led analysis explains how deepfake CFO fraud in Australia intersects with section 180 of the Corporations Act 2001, APES 110 and practical treasury governance. It sets out dual-control payments, mandatory out-of-band verification, evidence retention and incident-response steps suitable for owner-operated and middle-market enterprises.

References to ASCR should not be confused with ASIC. The Australian Solicitors' Conduct Rules concern legal practitioners and do not govern accountants. Where a solicitor handles trust money or advises on a suspected fraud, separate professional obligations may arise. This article focuses on corporate governance and APES 110, with legal advice required for potential director liability or negligence claims. [Legislation: Corporations Act 2001, s 180] [APESB: APES 110 Code of Ethics for Professional Accountants (including Independence Standards)]

The Anatomy of Synthetic Payment Scams in Middle-Market Enterprises

Synthetic payment fraud normally combines impersonation with genuine commercial context. Criminals may obtain information from compromised email, public announcements, social media, invoices or a supplier's systems. Generative AI can then reproduce a recognisable voice or create a plausible video meeting in which an apparent CFO orders an urgent transfer.

The decisive vulnerability is usually procedural rather than visual. A payment request moves outside the approved workflow, a supplier's bank details are changed without independent verification, or one employee can create and release the transaction. Video presence, caller identification and knowledge of confidential details are treated as authentication even though none independently proves authority.

AI invoice fraud prevention should therefore begin with transaction pathways. Management should map who can create suppliers, amend bank details, upload payment files, approve transfers and change banking permissions. It should also identify workarounds used during travel, leave or time-sensitive acquisitions. Controls must apply to directors and founders as well as employees; otherwise an attacker can exploit the most senior person's ability to demand an exception.

ASIC Director Duties: Section 180 Care and Diligence in the AI Era

Section 180(1) of the Corporations Act requires a director or officer to exercise the degree of care and diligence that a reasonable person would exercise in the corporation's circumstances and in the same office. The provision does not prescribe a particular deepfake product or mandate a universal approval threshold. Its application depends on matters including the company's size, operations, financial exposure and the director's responsibilities. [Legislation: Corporations Act 2001, s 180]

As synthetic impersonation becomes a foreseeable payment risk, directors should be able to show that they considered the exposure and implemented proportionate safeguards. Relevant evidence may include board or management risk reviews, banking access registers, approval matrices, staff training, tested escalation procedures and periodic control monitoring. Simply delegating banking administration does not remove the need for informed oversight.

The statutory business judgment rule in section 180(2) has specific elements and should not be assumed to excuse a failure to establish or supervise basic controls. Whether it applies is fact-dependent and requires legal analysis. Sections 181 to 184 may also become relevant where conduct involves improper purpose, dishonesty or misuse of position, but a fraud loss does not automatically establish a statutory contravention.

ASIC's cyber-resilience material emphasises governance, risk management and response capability. Directors should consequently treat treasury authentication as part of enterprise risk rather than leaving it entirely to an external IT provider. [ASIC: Cyber resilience good practices]

APES 110 Code of Ethics: Professional Competence and Internal Controls

APES 110 establishes fundamental principles of integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour. Its conceptual framework requires professional accountants to identify, evaluate and address threats to compliance with those principles. Section 113 addresses maintaining professional knowledge and skill and acting diligently in accordance with applicable technical and professional standards. [APESB: APES 110 Code of Ethics for Professional Accountants (including Independence Standards), s 113]

APES 110 does not prescribe a particular deepfake detection tool or state that every SME must use the same internal controls. However, an accountant responsible for treasury, supplier records or payment approval should not treat a familiar voice as sufficient evidence once impersonation risk is known. Appropriate action may include raising the threat with management, recommending safeguards, documenting limitations in the engagement, obtaining specialist assistance or declining an instruction that cannot be adequately verified.

The Code should not be presented as automatically creating civil liability. A professional negligence claim ordinarily requires a legal assessment of duty, the applicable standard of care, breach, causation and loss. Nevertheless, failure to recognise an obvious control weakness or to act diligently may create ethical, disciplinary, contractual and evidentiary consequences.

Accountants should also evaluate confidentiality risks before uploading recordings, identification documents or transaction data to AI-detection services. Provider terms, access controls, retention settings and the necessity of disclosure need consideration rather than assuming that an automated tool is harmless.

Dual-Control Treasury Protocols: Mitigating Real-Time Voice Cloning

Establishing Irrevocable Out-of-Band Verification and Multi-Party Approval Workflows

An irrevocable verification rule is an internal policy that cannot be waived merely because a caller appears to be the CFO, a director or an important customer. Out-of-band verification uses a trusted channel separate from the one carrying the request. A phone number printed in the suspicious email is not independent; the verifier should use a number already held in approved master data or obtained from an independently validated source.

The policy should cover new beneficiaries, changed bank details, unusual international transfers and payments above a risk-based threshold. It should also specify what happens when the expected person is unavailable: the transaction waits or follows a documented alternate-authority route. Urgency must not become an authentication method.

A practical mandatory process is:

Remediation and Incident Reporting: Managing Breaches with Banking Partners

Speed matters after a suspected fraudulent transfer, but the response should be coordinated and documented. Contact the sending bank immediately through its verified fraud channel, request a hold or recall, and provide accurate beneficiary and transaction information. Recovery is not guaranteed, particularly once funds have moved through other accounts or jurisdictions.

The business should secure relevant email and banking accounts, revoke suspicious sessions, reset compromised credentials and preserve logs, messages, invoices, recordings and approval evidence. Avoid deleting or editing source material. Establish a single incident lead and maintain a decision log recording when the fraud was discovered, who was notified and what instructions were received.

Reporting obligations depend on the entity, information affected and surrounding conduct. Obtain legal advice about regulatory, privacy, employment, insurance and contractual notifications rather than assuming every incident follows the same pathway. If financial statements may be materially affected, management and the accountant should consider appropriate recognition, disclosure and subsequent-event requirements under the applicable Australian Accounting Standards. [AASB: AASB 110 Events after the Reporting Period]

After containment, directors should commission a root-cause review. The purpose is not limited to identifying the employee who acted. It should determine why authentication failed, whether access rights were excessive, whether warnings were ignored and whether the control design matched the organisation's risk.

Frequently Asked Questions

Q.Can an Australian director be personally liable for a deepfake transfer scam?

A company losing money to a deepfake does not automatically make a director personally liable. Section 180(1) requires directors and officers to exercise the care and diligence a reasonable person would exercise in the corporation's circumstances and in the same office. The assessment may consider whether the risk was foreseeable, the potential loss, available controls, the director's responsibilities and how payment systems were supervised. Evidence of risk reviews, dual approval, access monitoring, training and incident response can therefore be important. The business judgment rule has defined statutory elements and should not be assumed to cover every operational omission. Liability depends on the facts, causation and applicable law, so directors facing a material incident should obtain legal advice. [Legislation: Corporations Act 2001, s 180]

Q.Does APES 110 require accountants to implement deepfake detection software?

APES 110 does not prescribe a particular deepfake detector or mandate identical technology for every practice or SME. It requires professional accountants to comply with fundamental principles and apply the conceptual framework to identify, evaluate and address threats. Professional competence and due care include maintaining relevant knowledge and acting diligently, but safeguards should be proportionate to the accountant's role and the circumstances. A robust response may rely more on independent callbacks, restricted supplier-master access, dual release and documented escalation than on software attempting to judge whether a voice is genuine. If an accountant lacks the competence or authority to address the risk, appropriate steps may include obtaining specialist assistance, advising management of limitations or declining an unverifiable instruction. [APESB: APES 110 Code of Ethics for Professional Accountants (including Independence Standards), s 113]

Q.How can a Sydney SME prevent AI voice cloning payment fraud?

The business should make voice and video insufficient, by policy, to authorise a payment. Require out-of-band confirmation through contact details stored before the request, particularly for new beneficiaries, bank-detail changes and unusual transfers. Separate supplier creation, payment preparation and bank release, and require two authorised users for material transactions. Banking limits and multi-factor authentication should support this workflow, although MFA alone cannot stop an authorised person being deceived. Staff should be permitted to delay a payment when verification fails, even if the apparent caller is a director. Directors should periodically review user access, exceptions and failed verification attempts, then test the process using realistic scenarios. [ASIC: Cyber resilience good practices]

Q.What should a business do immediately after paying a fraudulent AI invoice?

Contact the sending bank immediately through a verified fraud channel and ask whether the payment can be held, recalled or traced. Record the bank's instructions and provide accurate transaction details. Secure affected banking and email accounts, revoke suspicious sessions, preserve logs and retain the original invoice, messages, recordings and approval evidence. Notify appropriate directors and check insurance, contractual and legal reporting requirements. Do not conceal the loss through unsupported entries or delete material that may be evidence. Management and the accountant should assess whether the event affects financial reporting, including whether recognition or disclosure is required under applicable standards. Recovery is not assured, so rapid containment should be followed by a documented root-cause and control review. [AASB: AASB 110 Events after the Reporting Period]

Q.Is two-person approval enough to prevent synthetic identity theft and invoice fraud?

Two-person approval is valuable but is not sufficient if both approvers rely on the same compromised email, synthetic video or altered invoice. Effective segregation of duties should separate supplier maintenance, verification, payment preparation and bank release. At least one reviewer should independently confirm the commercial basis and beneficiary details through a trusted channel outside the request. Each approver should use separate credentials, and the banking platform should enforce appropriate limits where available. The business should also monitor administrator access and urgent exceptions. For a small team, compensating controls can involve a director, internal employee and external accountant performing distinct steps, provided responsibilities and evidence are clear. The objective is independent challenge, not merely two clicks on the same false information. [ASIC: Cyber resilience good practices]

Expert Insight: Design Controls That Work Under Pressure

In principal-led practice, the most useful question is not whether staff can recognise a perfect deepfake. It is whether the payment process remains reliable when the request sounds authentic, confidential and urgent. Training helps, but a control dependent on one employee detecting synthetic media is fragile.

A stronger protocol assumes that voices, video meetings, email chains and documents may all be manipulated. It then requires independently sourced contact details, transaction-specific verification, separate bank users and retained evidence. Directors should make compliance with that process part of normal commercial discipline rather than treating it as mistrust or unnecessary delay. The same architecture also helps address conventional supplier impersonation, compromised email and unauthorised bank-detail changes.

Strengthen Your Treasury Approval Framework

Deepfake CFO fraud converts familiar voices and faces into unreliable evidence. Sydney SMEs can reduce the exposure by combining director oversight, APES 110-informed professional conduct, out-of-band verification, segregated duties and technically enforced bank approvals.

Local Knowledge can help review payment pathways, authority matrices, supplier-change procedures and control documentation in the context of your operating model. For a principal-led discussion about practical treasury governance and accounting implications, speak with our principal. Legal advice should be obtained where an incident may involve director liability, litigation or regulatory reporting.

About the Author

Graham Chee

Graham Chee, FCPA, CPA, GRCP, GRCA

Principal and Founder, Local Knowledge

Graham Chee is the principal and founder of Local Knowledge, an FCPA-led Australian practice that brings institutional-grade compliance, investment-structure and intellectual-property experience directly to owner-managed businesses. Graham is a Fellow of CPA Australia (FCPA since November 2005, continuous CPA member since 1986) and holds the OCEG Governance, Risk & Compliance Professional (GRCP) and Governance, Risk & Compliance Auditor (GRCA) designations. His prior career includes senior roles at Goldman Sachs, BNP Investment Management and Merrill Lynch. Graham was previously portfolio manager of the Asian Masters Fund (IPO December 2007 – 31 December 2009), which returned +29% in AUD terms versus the MSCI Asia Pacific (ex Japan) benchmark. He signs off on 100% of client files personally.

Areas of Expertise:

Strategic Business Advisory
Taxation Planning & ATO Compliance
Business Valuation
Succession Planning
Investment-Structure Governance
Governance, Risk & Compliance
Australian Financial Reporting (AASB)
Intellectual Property Protection
Experience: FCPA-led practice at Local Knowledge, Mascot NSW. Continuous CPA Australia member since 1986. Prior career at Goldman Sachs, BNP Investment Management and Merrill Lynch.
This insight was generated by our AI intelligence engine

Contact Us Today

General information only. Speak to us for advice specific to your situation. Every file is signed off by our principal under CPA Code of Ethics.

Graham Chee FCPA, CPA, GRCP, GRCA · Principal, Local Knowledge · Mascot NSW · CPA-signed files