What I don't understand is why a Financial Controller, upon being told to move lots of company money, is not immediately checking the authenticity of that message? I mean, seeing as it's company money, they should NEVER accept that message at face value and should always verify it?

Surely there should be business processes for moving money and it should always rely on verification of the original message?

And anyone who is authorised to make these sort of decisions (i.e. someone who is allowed to ask for money to be moved) should know this?

