Hi Mary -
I am not that familiar with eCMS, but this is something that a lot of contractors are worried about these days. We had a client not too long ago that had a $250k check sent to a fraudulently changed account after a vendor of theirs got "hacked" via social engineering.
I'll describe what we're building for clients who are on Trimble ERPs (Spectrum + Vista), but the overall thought process here could be applied anywhere. I'm sure you have an eCMS expert you work with that can assist if you (or anyone else) would want to go down this path.
At a high level, we're adding an audit process using Trimble's integration platform AppXchange, because it's secured from the normal AP users. AP does ACH updates for Vendors etc. using their existing internal process, which includes whatever verifications you have in place today. The technical part is that we then scrape all bank/ACH/EFT related changes and secure send those to a separate repository and then automatically email the Controller/CFO/Compliance/whoever needs to be notified as a secondary check that someone's bank details have changed.
The key is that there is no way for a run of the mill AP clerk or back office employee to get at that secondary repository and automation to disable it or override it there. It adds a secure way for a second or even third level validation that the change was:
- Intentional
- Properly documented
Again, we are not an eCMS shop but the above process could be replicated for any accounting/ERP system by your trusted technology partner. The mechanics of it would change, but the theory is applicable to everyone.
------------------------------
Chris Lounsbury
Director of Development & Data Architecture
Business Information Group, Inc.
Sherwood OR
(717) 659-2737
------------------------------