Follow-ups and renewals

Asking a client to pay over WhatsApp: bank details, fraud and client money

Bank details in a chat message are how brokers get impersonated. Safe premium reminders, the APP reimbursement limits and what CASS 5 risk transfer changes.

Published on 6 min readFCB.ai
Contents
  1. Why the payment message is the risky one
  2. Who carries the loss when the client pays a fraudster
  3. What CASS 5 changes and what it does not
  4. What a safe payment reminder looks like
  5. When a client says they have paid and you cannot see it
  6. Frequently asked questions

Every brokerage sends a version of this message: the premium is due on Friday, here is what is owed, here is where to send it. It is the single most valuable message in your outbox to somebody else. A fraudster who can guess that a payment is expected, and who can send a message that looks like yours, does not need to break into anything.

The exposure is not theoretical and it is not the client's problem alone. When a policyholder pays the wrong account after a conversation with their broker, the argument about who bears the loss lands on your desk long before it lands anywhere else.

Why the payment message is the risky one

Impersonation works because the real message and the fake one look alike. If your firm's genuine practice is to type bank details into a chat, then a message containing bank details is normal, and the client has no way to tell the two apart. If your practice is that account details never travel in a message, the fake one stands out immediately — and that is the whole defence.

So set the rule and repeat it. Bank details are given once, on your invoice or terms of business, through the route the client already uses. Every payment reminder says, in the same words each time, that your details never change and that you will never message new ones. Clients learn the pattern faster than firms expect, and it costs nothing.

Who carries the loss when the client pays a fraudster

Since 7 October 2024 the Payment Systems Regulator's reimbursement requirement has applied to authorised push payment scams over Faster Payments and CHAPS. The headline terms matter to a broker because they determine what a client will and will not get back.

  1. Up to £85,000 per claim, with the cost shared equally between the sending and the receiving payment service provider.
  2. Reimbursement within five business days, extendable while the payment firm investigates, up to 35 business days.
  3. An optional excess of up to £100, which cannot be applied to a customer who is vulnerable.
  4. Eligibility is narrow. The regime covers consumers, microenterprises and charities below the stated thresholds. A mid-sized commercial client sits outside it entirely.

Read the fourth point twice if you write commercial business. Your haulage client who pays a fabricated invoice for a fleet premium has no reimbursement right to fall back on; they have their own bank's goodwill, their crime insurance if they bought it, and whatever they can say about the broker whose message they thought they were answering. That is the conversation to prevent, and prevention is a habit rather than a control.

What CASS 5 changes and what it does not

Brokers sometimes reassure clients that "as long as you have paid, you are covered". That is a compressed version of a real rule, and the compression is where it goes wrong. Under CASS 5 a firm may hold premium either as client money in a statutory or non-statutory trust, or as agent of the insurer under a written risk transfer agreement. Where risk transfer applies, the premium becomes the insurer's money the moment your firm receives it, and the client is protected from that point even if the money never reaches the insurer.

The condition is receipt by your firm. Money paid into an account controlled by a fraudster has not been received by anyone acting as agent of the insurer, and no amount of risk transfer converts it into a paid premium. This is worth saying to clients in plain terms, because the belief that "the payment went out" is what stops people telephoning their bank in the twenty minutes when it might still be stopped.

What a safe payment reminder looks like

IncludeNever include
The client's name and a partial policy referenceFull bank details typed into the message
The amount and the due dateAny account that differs from the one on your invoice
The payment route already agreed — direct debit, the insurer's portal, the invoice you issuedA payment link the client has not seen before
A standing line that your bank details never changeManufactured urgency, or a cancellation threat with no contractual basis
A number to call back on, which the client can check on the FCA RegisterA request for card numbers, a photograph of a card, or a one-time passcode

The sequence itself is ordinary: a reminder in good time before the due date, a short one as it approaches, then a factual arrears message whose consequences match what the policy and the credit agreement actually say. Our premium reminder workflow sets out the cadence, and the ten-day reminder template shows the tone that gets answered. Where the premium is financed, the lender's process governs the timetable and the wording — that ground is covered in our note on missed premium finance payments.

Two mechanics are worth setting up once. Reminders that leave the 24-hour window have to go as approved utility templates, so build the "our details never change" line into the template itself rather than relying on whoever is typing. And keep the whole exchange in a shared inbox rather than on a personal phone: in ORIS the reminder, the client's reply and the confirmation sit against the customer record, which is what you will want in front of you if a payment goes astray. ORIS does not take payments and will not tell you whether one has landed — that reconciliation stays with your accounts system, and the reminder should point to the route that system expects.

When a client says they have paid and you cannot see it

Move quickly and do not debate it in the thread. Call the client on the number you hold, not one supplied in the conversation. Ask which account they paid — beneficiary name, sort code, last four digits — and compare it against yours without reading yours out first. If it does not match, tell them to contact their bank immediately and report it to Action Fraud, and note the times of each step.

Then deal with the policy. Tell the insurer that the premium has not been received and find out where that leaves cover, rather than assuming. Treat the client's complaint as a complaint if that is what it is, with the DISP timetable running from the day it was made. And look at your own thread honestly: if any message in it could have been read as inviting a payment to a new account, that is a finding for your own file before it is one for anybody else's.

Frequently asked questions

Can we ever send bank details over WhatsApp?

You can, and the point is that you should not, because a firm that never does gives its clients a simple test for spotting a fake. Put the details on the invoice or in the terms of business, refer to them in the reminder, and keep the message itself free of anything a fraudster would want to imitate.

Is a client who is tricked automatically reimbursed?

No. The reimbursement requirement applies to eligible consumers, microenterprises and charities, up to £85,000, and payment firms may apply an excess and assess whether the customer met the standard of caution expected of them. Commercial clients above the thresholds are outside the regime altogether.

If we hold risk transfer, is the client covered once they have sent the money?

Only once your firm has received it. Risk transfer means premium held by you is treated as the insurer's money from receipt; it says nothing about money that went somewhere else. If a payment has gone astray, raise it with the insurer rather than assuring the client that cover is unaffected.

Should we ask clients for a screenshot of the payment?

It is a reasonable prompt and a poor proof. A screenshot tells you the client believes they paid and, usefully, shows which account they used — which is how mispayments get caught early. It is not confirmation of receipt, and reconciliation still has to happen in your accounts system.

Do we need to warn the whole book about this?

A short, calm standing line in your renewal and payment communications does more than an occasional alert. Firms that only warn clients after an incident train them to expect unusual messages about money, which is the opposite of what you want.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo