This is the one-page protocol we recommend any finance team adopt before buying any tool — ours included. Copy it, adapt the thresholds, and enforce it.
Free template
The Callback Verification Protocol Template
CALLBACK VERIFICATION PROTOCOL — [Company name]
- Scope. This protocol applies to: (a) every payment request received by phone, video call, email, or message; (b) every change to vendor or employee bank details, from any channel; (c) all amounts — there is no minimum.
- The rule. Before acting, the receiving employee must end the inbound interaction and call the requester back on the number already held in [vendor master / HR system / executive directory]. Numbers supplied within the request itself must never be used for verification.
- Registered numbers. Callback numbers are maintained in [system], changed only with the same verification applied to bank details, and reviewed quarterly.
- The callback. Confirm verbally: the request, the amount, the destination account, and the reason. If the requester is unreachable, the payment waits. Urgency is not an exception — urgency is the attack signature.
- Escalation. Any refusal to accept verification, pressure for secrecy, or mismatch between channels is reported to [role] the same day, and all related pending payments are frozen.
- Evidence. Each verification is logged: date/time, verifier, number called, outcome. Compliance is reported monthly as: verified payments ÷ qualifying payments.
- No-retaliation clause. No employee will ever be criticized for delaying a payment to verify it. Signed: [CEO/CFO], [date].
VerifyTheCall automates steps 2–6 of this protocol: the callback is triggered automatically, the registered number is the only one dialled, the payment is held until verification completes, escalation is routed, and every check is logged as audit evidence. See how enforcement works.
The Callback
The Callback — a short briefing on new scam patterns and payment controls. No more than twice a month.
Unsubscribe anytime.