How a financial fraud or dispute case runs, step by step

A fraud or dispute case moves from first alert to closed file through intake, triage, containment, investigation, recovery, accounting and review. Treasury operations usually owns the case. Bank relationship staff, accounts payable, legal, the controller and the ledger team each act at set points along the way.

The steps in order

  1. Receive the alert. Who: the treasury analyst on duty. Alerts arrive from many directions. A bank sends a chargeback notice. A supplier calls about a payment that never landed. Positive pay flags a cheque that does not match the issue file. An employee reports an odd request to change a vendor's bank details. Whatever the source, the analyst captures what was said and who said it before anything else happens.
  1. Open a case file. Who: the same analyst. Each matter gets its own reference number. The analyst links the original payment or receipt, attaches screenshots and emails, and notes the counterparty. A case with no link to a transaction is very hard to account for later.
  1. Classify the matter. Who: the treasury manager. Three outcomes are possible. A simple processing error goes back to accounts payable to be resolved as an invoice or payment issue. A commercial disagreement or card chargeback is treated as a dispute. Deliberate deception is treated as fraud. This call decides who gets involved next, so it deserves a second opinion when the facts are thin.
  1. Contain the exposure. Who: the treasury manager, with help from master data and IT security. For suspected fraud, speed matters most here. The manager asks the bank to recall or freeze the funds. Master data blocks the vendor record. IT security suspends any user access that may be compromised. For a dispute, containment is gentler: further payments to that counterparty may be held if the contract permits.
  1. Tell the right people. Who: the treasury manager. The controller and legal hear about every fraud case. Internal audit usually does too. If the insurance policy has notice conditions, the risk team files them. Legal alone decides whether to involve law enforcement.
  1. Investigate. Who: internal audit or a designated investigator for fraud; accounts payable or receivable alongside the business owner for disputes. Investigators rebuild the approval trail. They check whether the invoice, purchase order and receiving report ever matched. Bank statements, email headers and system logs often show where the control failed. Dispute work looks different: it centres on the contract, delivery proof and correspondence.
  1. Respond to the bank or counterparty. Who: treasury, with legal for anything contentious. Chargebacks get a formal response with evidence attached. Misdirected payments trigger a claim to the receiving bank. Where a supplier or customer refuses to settle, legal sends a demand letter.
  1. Decide the outcome. Who: the controller, on a recommendation from treasury. The money is recovered, partly recovered or lost. Write offs need the controller's approval, and larger ones often need sign off further up.
  1. Record it in the books. Who: the general ledger accountant. A manual journal voucher is prepared and routed for approval before posting. An expected recovery sits as a receivable, often with an allowance for the amount unlikely to come back. A dispute likely to end in a refund is recorded as a liability. Accounts payable posts any payment adjustment in the subledger so it agrees with the ledger.
  1. Report and reconcile. Who: treasury and the controller's team. Cash accounts are reconciled to confirm every reversal and recovery actually hit the bank. Improper payments and losses are reported to leadership and, where required, to the audit committee.
  1. Fix the gap and close. Who: the process owner, with internal audit. The weakness that let the case happen gets an agreed remedy and an owner. Only after that sign off does the case manager mark the file closed.

Where handoffs tend to slip

Classification is the weak point. Analysts often label a fraud as an error because the error route is faster and needs fewer approvals. The money then sits in an accounts payable queue while the recall window closes.

Accounting also lags. Cases get resolved operationally and nobody tells the ledger team, so a receivable lingers with no allowance against it.

Questions to ask the people who run it

The written procedure and daily practice rarely match. Sit with the staff and ask:

  • When a supplier phones to say a payment is missing, what actually happens next, and who picks up?
  • How does a case get labelled fraud, and has anyone ever changed that label later?
  • Who can call the bank to request a recall outside normal hours?
  • What stops a blocked vendor record from being unblocked by someone in another team?
  • Where does evidence live once the case is open, and could an auditor find it?
  • How does the ledger team learn that a case is resolved?
  • Which cases never reach the case log at all, and why?
  • When was a control last changed because of a case, and who pushed for it?

The answers usually reveal informal shortcuts. Some are sensible and worth keeping. Others are the reason the next case will happen.

Sources

APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.