The Four Eyes Principle Isn't Enough to Stop Payment Fraud
- Team Svenry

- Aug 26
- 3 min read
The four eyes principle is a fundamental internal control in accounting and finance. Requiring two people to review or approve important financial actions helps organizations reduce errors, enforce segregation of duties, and strengthen accountability. There is however an important limitation:
Two people can approve the same fraudulent information.
This is particularly relevant for payment fraud such as Business Email Compromise, invoice fraud, and fraudulent supplier bank account changes. If both the preparer and the approver rely on the same manipulated email, invoice, or supporting document, having two people involved does not necessarily prevent the fraud.
The four eyes principle remains an important governance control. But effective payment fraud prevention requires something more: independent verification of the information being approved.
What Is the Four Eyes Principle?
The four eyes principle requires two independent people to participate in a sensitive financial process.
For example, when a supplier's bank account is changed:
One employee enters the new information.
A second employee reviews and approves the change.
The system records who made and approved the change.
This creates segregation of duties and prevents one individual from having complete control over the process. However, it does not automatically confirm that the information itself is legitimate.
Payment Fraud Often Starts Before Payment
Payment fraud frequently begins before a payment enters the banking system.
A fraudster may:
Impersonate a supplier
Compromise an email account
Submit fraudulent bank details
Manipulate an invoice
Create a fictitious supplier
Request an urgent change shortly before a large payment
If the information is accepted into the ERP or payment system, the fraud can become difficult to detect. This is why payment controls should extend beyond the final approval step.
Independent Counterparty Verification
A stronger approach combines the four eyes principle with independent counterparty screening. Instead of relying only on information supplied by the employee or supplier, organizations can verify the counterparty against external sources.
Depending on the use case, this can include:
Company registration data
VAT registration
Legal Entity Identifier information
Insolvency records
Sanctions lists
Ownership information
Bank account information
Internal risk and blacklist data
This provides the checker with independent information when reviewing a supplier or payment.
Screening During the Payment Workflow
Counterparty screening should not stop at supplier-onboarding. A supplier's risk profile can change after the relationship has already been established. A company may become insolvent, change ownership, become subject to sanctions, or have its bank details changed before a significant payment.
Svenry can monitor counterparties throughout the payment workflow and check relevant information against external registries and risk sources. If a new risk indicator is identified, the payment can be flagged for additional review before it reaches the bank.
How Svenry Strengthens the Four Eyes Principle
Svenry helps organizations add independent data verification to their existing approval processes.
Within payment and finance workflows, Svenry can verify counterparties and identify risk indicators such as:
Unexpected bank account changes
Duplicate or potentially fictitious suppliers
Inconsistent company information
Insolvency events
Sanctions exposure
Ownership changes
By automating these checks, Svenry gives the second reviewer additional information to support the approval decision. The goal is not to replace the four eyes principle. It is to make it more effective.
What Companies Should Consider
Organizations should review whether their four eyes process provides genuine independent verification or simply adds another approval step.
Consider asking:
Are supplier bank account changes automatically flagged?
Is counterparty information checked against external sources?
Are suppliers continuously monitored?
Are sanctions and insolvency events detected?
Does the checker receive independent risk information?
Are high risk payments subject to additional verification?
If not, the organization may have strong segregation of duties but still have gaps in its payment fraud controls.
From Approval to Verification
The four eyes principle remains an important part of financial governance. But modern payment fraud requires organizations to look beyond approval workflows.
Two people reviewing the same information does not make that information true.
Independent counterparty verification, continuous monitoring, and intelligent risk screening can provide the additional layer needed to identify fraud before payments are executed.
Svenry helps organizations bring these controls directly into their finance and payment workflows, giving finance, procurement, and compliance teams better information when it matters most.




