Are employees with financial/accounting responsibility given social engineering and phishing training?
General awareness training does not prepare someone for a well-researched request from a supplier they recognise. Carriers ask about finance separately because the losses are concentrated there.
What the carrier is actually asking
The carrier is asking whether people who can move money or change payment details receive training aimed at the attacks they specifically face: invoice fraud, supplier bank detail changes, executive impersonation, and payroll diversion.
Why it is underwritten
Business email compromise loss lands on the person who processes the payment. That person is targeted with research, urgency, and plausible context, and generic phishing training does not cover it. Carriers underwriting funds transfer fraud cover ask about this because it directly precedes the loss they are pricing.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Training records live in your learning platform, so this is attested. The technical controls that support it are visible in the tenant.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Training platform | Role-specific training assignment and completion for finance staff | Targeted content, not the general module with a finance label. Attested |
| Simulation platform | Finance-specific simulation scenarios | Supplier bank change and executive request scenarios, which is what these roles actually face |
| Microsoft 365 | External sender identification on inbound mail | External tagging enabled, which is the control that makes impersonation visible at the moment of reading |
| Microsoft 365 | Anti-phishing impersonation protection for executives and finance staff | Named users protected, since impersonation protection works from a list someone has to maintain |
| Finance process | Callback verification and dual authorisation procedures | The procedural control that training reinforces, which the governance section asks about directly |
The control that stops invoice fraud is out-of-band callback verification to a previously known number, applied every time regardless of urgency. Training is what makes people follow it under pressure. Answering this question well means describing both.
What a defensible yes requires
- Finance and accounting staff receive content specific to payment fraud, not the general module.
- Training covers supplier bank changes, executive impersonation, and urgency as a pressure tactic.
- Simulations include finance-specific scenarios.
- The procedural control exists: callback verification to a known number, and dual authorisation above a threshold.
- New joiners in these roles are trained before they gain payment authority.
How this answer goes wrong
The organisation runs annual awareness training for everyone and answers yes. The finance team received the same module as everyone else, covering password hygiene and suspicious links, and nothing about a supplier emailing new bank details from a domain one character different from the real one.
Frequently asked
Who counts as financial responsibility?
Anyone who can initiate, approve, or change a payment, plus payroll and anyone who maintains supplier records. It is usually a wider group than the finance department.
How often?
At least annually, and at onboarding into the role. Short, frequent reinforcement works better than a long annual session for this specific risk.
Does this affect funds transfer fraud cover?
It can. Some policies condition that cover on verification procedures, and training is the evidence that the procedure is understood and followed.
What is the single most effective measure?
Mandatory callback to a number already on file, for every bank detail change, with no exception for urgency. Urgency is the attack.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture