
Insights·Fraud and verification
How fund administrators verify LP bank account details
Four methods are currently in use. Three of them, the penny test, the beneficiary name check and the telephone callback, each prove something narrower than the question being asked, and none establishes that the party holding the account is entitled to receive this fund's money. The fourth, checking the details against the subscription documents the investor signed, is the only one that tests entitlement, and it is the one no published standard specifies. All four normally run when a payment is about to leave, rather than when the beneficiary record changed, which is the event that creates the exposure.
What does each method actually prove?
Something narrower than ownership, in every case, and the gaps are different in each.
The penny test proves control, not ownership. It has a formal definition, which surprises most people who run one. Nacha's Micro-Entries Rule defines micro-entries as "ACH credits of less than $1, and any offsetting ACH debits, used for the purpose of verifying a Receiver's account", requires the credit to equal or exceed the debit and settle simultaneously, and requires the Company Entry Description field to carry the value ACCTVERIFY. This came into effect on 16 September 2022. A second phase on 17 March 2023 required originators to apply commercially reasonable fraud detection to their own micro-entry volumes, because the technique is itself abused for account enumeration.
The descriptor is the part worth having, and almost nobody exploits it. ACCTVERIFY makes the verification machine-identifiable in the payment record, which is what an auditable control needs and what a telephone call never produces.
Its limits are severe for fund payments. Proving that someone can read a small deposit proves they control the account, which is a different thing from owning it when the person controlling it is the person who supplied the details. It is ACH-only and United States-only, so it does not reach the cross-border wire flows carrying most institutional fund money. It settles over one to three business days, which does not fit inside a capital call notice period.
The beneficiary name check proves that the name matches. The European scheme rulebook taking effect on 20 September 2026 defines four outcomes: match, no match, close match with the counterparty name disclosed, and verification check not possible. Responses arrive within five seconds at the outside. The United Kingdom vocabulary is equivalent.
Swelv's position is that account matching does not establish that a recipient is entitled to a particular fund payment. The obvious objection is that beneficiary matching exists precisely to verify recipients, and where an account number has been altered under a retained name, it does exactly that. The answer sits in the anchor case. Tillage Commodities' complaint alleges the fraudulent transfers went to Hoaran Technologies at Hang Seng Bank and Away Technologies at HSBC Hong Kong, entities that were not investors and had no relationship with the fund. Where one party supplies both the payee name and the account, the two agree. The check returns a match, correctly, on a payee that should never have been on the file.
The callback proves a conversation happened. Its best-specified version is not in fund operations. The American Land Title Association's Outgoing Wire Preparation Checklist, version 2.0 of 19 August 2019, applies a different control depending on how the instructions arrived, then states the operative requirement: "calling the payee at a phone number obtained independently from any phone number shown in the package/email/3rd party." It enumerates the permitted independent sources and records who was spoken to. ALTA's Best Practices Framework requires the written procedure be "tested at least annually".
What does not copy across is the economics. That model assumes one high-value bilateral settlement with a known human on the other end. A fund administrator releasing two hundred distributions from a single file cannot make two hundred independently sourced calls before the bank cut-off.
The fourth method is the one the other three cannot substitute for. Checking the account details against the subscription documents the investor signed is the only one that asks whether this party is entitled to this fund's money, because the subscription documents are the one record the payee did not supply. It is also the least specified. The other three have rulebooks, effective dates and, in the penny test's case, a machine-readable descriptor. This one has none of that, and no published standard describes how to run it or what evidence it should leave behind.
Why does near-universal policy coexist with a high hit rate?
Because having a policy about verifying is not the same as verifying.
Among the United States organisations surveyed by the Association for Financial Professionals, 96% say they have policies to verify changes to bank details and 94% say they call an authorised contact to verify transfer requests. In the same population, 76% experienced attempted or actual payments fraud in 2025.
Those figures do not prove the controls fail, and the survey establishes no causation. It covers organisations generally rather than fund administrators, and being targeted is not the same as losing money. What the gap does establish is that near-universal stated policy and a high attempted-fraud rate sit together comfortably, which makes the presence of a policy weak evidence about exposure.
The Securities and Exchange Commission put the failure mode precisely in its Report of Investigation under Section 21(a) of the Securities Exchange Act, Release No. 84429 of 16 October 2018, covering nine issuers that lost nearly $100 million between them. Their controls, it found, "could be (and were) interpreted by the company's personnel to mean that the (ultimately compromised) electronic communications were, standing alone, sufficient to process significant wire transfers or changes to vendor banking data". That report concerns public companies under Exchange Act Section 13(b)(2)(B), and the Commission determined not to pursue enforcement action, so it binds no private fund. It names the distance between a control that exists on paper and one that constrains what an employee can do.
When should the check run?
At the record change. Every method above normally runs at the payment, which is too late to ask the question that matters.
The exposure is created when a beneficiary is added to the file or its details are amended. It then sits dormant until a payment run walks over it. A check at payment time can ask whether this instruction is consistent with the record. It cannot ask whether the record was ever right.
The message standards make this a real distinction rather than a rhetorical one, and they are the clearest evidence available that the industry has already thought about it and stopped halfway. ISO 20022 publishes acmt.023, a request to verify party and account identification, and acmt.024, the report confirming whether the presented information is correct. Alongside them sits acmt.022, IdentificationModificationAdvice, which exists to carry notice that an identification has changed.
The payment schemes implemented the first pair. Both the European and United Kingdom regimes verify provider-to-provider at the moment a payment is initiated. Neither scheme, on Swelv's reading of their published rulebooks, implements anything for the change event. Note what acmt.022 is and is not: it is an advice message, carrying notice that an identification has changed, rather than a check. So the standards body has published an identifier for the event, and the schemes have built verification only around initiation. That is a narrower claim than saying the control exists and nobody uses it, and it is the one the documents support.
What follows for an administrator that does not want to wait for a scheme is a question of population. The records created or amended since the last payment run are few, and they carry nearly all the risk. A control that would be unaffordable applied to every payee in a distribution file is affordable applied to the handful that changed.
One caution on borrowing the good practice that regulators do record. In a thematic inspection reported on 6 March 2026, the Central Bank of Ireland recorded as good practice among fund administrators that a "maker-checker process was automated with system-generated controls", including a requirement that the checker be of equal or higher grade than the maker. That observation concerns net asset value oversight rather than payment release, so it is not a payment control and should not be presented as one. It illustrates the difference between recording that two people approved something and evidencing that the second approval could have caught the first one's error.
What should an administrator do?
Write down what each method proves, then move the strongest one to the record change.
For a head of payment operations, the place to start is identifying which beneficiary records were created or amended since the last payment run, because that is where the strongest control belongs, and the population is small enough to afford it. For that population, the check worth running is the fourth one, against the subscription documents, since it is the only one the payee could not have staged. Then look at what happens to an unresolved verification response inside a large file, because both scheme vocabularies contain an outcome that is neither a pass nor a fail, and a response nobody adjudicates is not a control.
There is no published standard to point at while doing this. Swelv searched eleven bodies that publish extensively about private funds on 10 September 2026, covering ILPA, Invest Europe, AIMA, the BVCA, the NVCA, ALFI, LPEA, the SEC, the FCA, the CSSF and the Central Bank of Ireland, and found no published standard specifying payment verification controls for capital calls or distributions. That search ran to a budget and could not reach member-only material, so it describes the public record rather than everything that exists. What such a standard would need to contain is set out in the companion piece on wire verification and is not repeated here.
Read more

Fraud and verification
Capital call fraud, how it works and how funds prevent it
A fraudulent capital call arrives when a real one is expected. The best-documented case shows the compromise at the fund, not at the investor who paid.

Verified payments
Capital-call wire fraud, and how verified payments end it
The most exploited opening in private markets is a wire instruction sent over email. Verified payments close it by design.
Frequently asked questions
With four methods: the penny test, the beneficiary name check, the telephone callback, and a check against the subscription documents the investor signed. Only the last one tests whether the party is entitled to the fund's money.
Control of the account, not ownership. It is defined in Nacha's Micro-Entries Rule, is ACH-only and United States-only, and settles over one to three business days.
It proves that the name matches the account. Where one party supplies both the payee name and the account, the two agree, so the check can correctly return a match on a payee that should never have been on the file.
At the record change, when a beneficiary is added or amended. That is when the exposure is created, and the population of changed records is small enough to afford the strongest check.