South African businesses report high rates of economic crime, and most of it is not sophisticated. It is a trusted person with unchecked access to money over a long period, or an email that persuaded someone to pay a supplier into the wrong account. Both are prevented by controls that cost nothing beyond discipline.
Small businesses are more exposed than large ones because one person usually does everything.
Separate who approves from who pays
The single most effective control is that the person authorising a payment is not the person making it, and neither is the only person who sees the bank statement.
In a very small business that means the owner reviews statements monthly rather than delegating it entirely, and requires two approvals above a set amount. Most internal fraud continues for years because nobody outside the person doing it ever looks.
The email scam that costs the most
An attacker gains access to a mailbox, watches, then sends a supplier or customer changed banking details at the right moment. The money leaves and is almost never recovered.
Verify any change of banking details by phoning a number you already held, never one supplied in the message. Use two-factor authentication on email and banking, and treat urgency in a payment request as a warning rather than a reason to hurry.
Reconcile, and check the things nobody checks
Reconcile bank to books regularly rather than annually. Watch for suppliers nobody recognises, payments just under an approval threshold, and staff who never take leave, since continuous presence is a classic indicator.
Verify new suppliers independently, including confirming registration through the Companies and Intellectual Property Commission, and confirm bank details against documents you obtained yourself.
If it happens
Act immediately: contact your bank, since very fast action occasionally recovers a payment, and report to the police. Preserve the evidence rather than confronting someone and giving them time to delete it.
Where personal information was exposed, data protection obligations apply, including notifying the regulator and affected people, overseen by the Information Regulator. Then fix the control that failed, because fraud repeats where nothing changes.
Frequently asked questions
What does most business fraud look like?
A trusted person with unchecked access to money over a long period, or a fraudulent change of banking details by email.
What is the most effective single control?
Separating who approves payments from who makes them, with the owner reviewing bank statements independently.
How do I prevent the banking details scam?
Verify every change by phoning a number you already had, never one supplied in the message requesting the change.
What are the warning signs internally?
Unrecognised suppliers, payments just below approval thresholds, and staff who never take leave.
What should I do immediately after fraud?
Contact the bank, report to the police, preserve evidence rather than confronting anyone, and notify affected people if data was exposed.
Further reading
Originally published in February 2018. Updated September 2026 into practical guidance on preventing and responding to business fraud.
