Library / Corporate Governance Principles Framework
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 17:24:51 UTC · snapshot created 2026-10-03 17:30:20 UTC · last check 2026-10-03 18:00:10 UTC

CGOV.9:5.1 - Two approvals that use one unverified instruction

In a constructed payment operation, a clerk can change a supplier’s bank details. A second employee approves the payment but checks only the invoice amount. Both rely on the same incoming message for the new account. The identified exposure is payment to an account that the supplier did not designate.

Adding a third amount approval leaves that exposure. The selected control instead confirms a bank-detail change through a previously established supplier contact and separates that confirmation from release of the payment. The confirmer needs the established contact information and authority to hold the change; the releaser needs the confirmed result.

A walkthrough reveals that confirmation uses the new contact number entered from the same change request. The confirmer could therefore reach a destination supplied by the unverified instruction. The team restores use of the previously established supplier contact and protects its update route before relying on the control. After implementation, observed operation can support the bounded claim that this route is used; it does not prove immunity to every fraud or collusion.