Money now moves through systems that act faster than any person can review. In a recent Eftsure webinar, Chief Product Officer Ramesh Menon and VP of Customer Operations Michelle Cram took finance leaders through what that shift means for controls, and how people and machines can work together when a payment no longer waits for someone to look.
Menon's role gives him oversight of how these systems are built and designed, while Cram's gives her a front-line view of how fraudsters try to exploit them. Here are their headline takeaways.
Ramesh Menon, Chief Product Officer
- Automating a task quietly automates the trust behind it, so at least one control has to independently verify the facts.
- In an agent-led function the review window collapses to almost nothing, and a single sign-off at the end becomes an illusion of control.
- AI agents can be manipulated through corrupted data, so oversight has to be an independent layer that runs at the speed of the systems it governs.
- The place to start is removing email as a source of truth, deploying multi-layered verification and setting circuit breakers that hold a payment automatically.
Michelle Cram, VP of Customer Operations
- Payment fraud is a trust exploit before it is a technology one: attackers research, build familiarity, then strike at a pressure moment.
- A single check can pass while the payment is still fraudulent, and attempts spike most at financial year end.
- The teams that catch it combine people, process and technology, and verify through a channel independent of the one the request arrived on.
- Any change to a payment should trigger an independent verification, and no one should be penalised for pausing a payment in good faith.
When automation quietly automates trust
Most finance teams already use AI as a copilot, drafting an email or summarising a document while a person does the work. An agent-led finance function is a bigger change. Agents start to initiate, approve and move money across AP, procurement and treasury, and the team's job shifts from doing the work to directing it.
Menon's caution is about what happens to trust along the way. A system recommends the next step, it works reliably for months, and people gradually stop checking the evidence behind the recommendation. The approval is still there, but in practice it becomes a click-through.
He compared it to a border crossing where each officer sees the traveller has already been waved through and assumes someone earlier checked the passport, so no one actually does.
"We automate the task and then we unintentionally automate the trust associated with it," he said. The fix is not another checkpoint. At least one control has to independently verify the facts, rather than confirm that a payment cleared the gate before it.
The early warning signs are ordinary:
- bank detail changes that arrive by email
- an approval that happens unusually fast
- an exception that only one person understands
- a senior request for an urgent workaround outside the normal process
Why one control is no longer enough
Menon's second point was about speed. Finance has always relied on review windows, a few days to catch an error on an invoice or spot a bad journal entry before close. In an agentic system that window collapses to almost nothing. By the time a controller opens a dashboard to check a batch, the money has already left the account.
He called this the control paradox.
"The faster the system decides, the less a single gate will catch."
Ramesh Menon, Chief Product Officer
People are used to sequential gates, where one person approves, another signs off and a manager releases funds. Agents compress those steps into one automated process, so a single sign-off at the end becomes an illusion of control. He pointed to one Australian organisation already running 3,400 agents, many of them unknown to the rest of the business.
The answer he described is a shift from inspecting individual payments to setting parameters around them: thresholds for anomalies, verification of payee, amount and timing, and circuit breakers that pause execution the moment a pattern breaks.
Fraud is a trust exploit before a technology one
Cram sees how these attempts actually unfold. A successful payment fraud is a trust exploit before it is a technology one, and it usually runs in three stages:
- Research. The attacker studies who pays whom, who approves what and how the finance team works.
- Familiarity. They build rapport by mirroring real language, real suppliers and real invoices, so the request feels like the next step in an existing conversation.
- Pressure. They pick the moment when scrutiny is lowest, often a new team member still learning the escalation process, the usual approver on leave or a pay run only hours away.
She sees attempts spike most at financial year end, when teams are processing higher volumes against tight deadlines.
Her illustrative example showed why a single check can fail. A request to change a supplier's bank details arrives from a known contact whose email has been compromised, while the person who owns that relationship is away. It passes a Confirmation of Payee check because the fraudster registered a business using the project name.
Each person completed their step, every document matched, and no one went back to an independent source. In that scenario, an independent verification layer flagged the change and the payment was stopped before it left.
AI makes this cheaper and faster. Menon noted that the expensive part of Business Email Compromise was never the email, it was the homework, and that research has dropped from weeks to hours. Agents introduce a new exposure too.
"Agents can be manipulated and spoofed perhaps more easily than humans," he said, through techniques like prompt injection, where hidden instructions inside an invoice are read by an agent as a legitimate override.
The defence he described is not slowing the system to human speed, but using AI to cross-check what a person cannot, such as whether an account name matches the account number registered at the bank, or whether that account was recently flagged at another organisation.
What separates the teams that catch it
Cram's view is that the stronger teams build controls on the assumption that even experienced people can be deceived when they are busy or under pressure. People, process and technology work together, and no single inbox or approval carries the whole burden.
On people, the best teams train staff to recognise manipulation and give them clear permission to challenge it, so a junior team member can pause a payment requested by a senior executive without feeling obstructive. The process side matters just as much: the escalation path is written down and practised, and any verification runs through a channel independent of the one that delivered the request, because a reply to a compromised email confirms nothing.
Technology then has to verify continuously rather than once at onboarding, since accounts and contact details change after a supplier is first checked. The common gap Cram sees is false confidence created by a check that happened only once.
The rules also have to be visible from the top. "Urgent doesn't override verification, seniority doesn't override verification, and no one should be penalised for pausing a payment in good faith," Cram said.
Start by taking email out of the chain of trust
Menon left leaders with three moves for this quarter:
- Stop treating email or a voice instruction as a source of truth for bank detail changes, and hold AI agents to the same rule regardless of who signed off.
- Deploy multi-layered verification that cross-checks payee identity and account ownership against authoritative bank and network data before money moves, and resist letting Confirmation of Payee alone stand in for it.
- Set circuit breakers with explicit thresholds that place an automatic hold when something deviates, rather than a manual review after the fact.
Cram's rule is simpler.
"Change should always trigger a verification."
Michelle Cram, VP of Customer Operations
That applies whether the change is to the payee, the bank account, the amount, the timing or the person authorising it. In an agent-led finance function, the safest habit is to treat any change to a payment as a reason to verify it independently before the money moves, whether a person or an agent set it in motion.
Want to keep the conversation going? Here are further resources.