Fraud Prevention
Protecting your business and its transactions
Fraud is an evolving risk for every business that sends, receives or manages money online. As payment services become faster and more connected, fraudsters continue to develop new methods of impersonation, social engineering, account takeover and payment manipulation.
At Railor, fraud prevention is an important part of how we approach the security of our services. We work to identify suspicious activity, strengthen our controls and support our clients in making informed and secure payment decisions.
Effective fraud prevention is a shared responsibility. Technology and internal controls are essential, but employee awareness, clear procedures and careful verification are equally important.
Why fraud prevention matters
Fraud can affect more than an individual transaction. It may lead to financial losses, operational disruption, regulatory concerns, reputational damage and reduced trust among customers and business partners.
Business payment activity can also be more complex than personal banking. Companies may have multiple users, approval levels, payment channels, suppliers and counterparties. This makes it important to implement controls that reflect the organisation’s size, structure and risk profile.
- A strong fraud-prevention framework can help your business:
- reduce the risk of unauthorised payments;
- identify unusual activity at an earlier stage;
- protect sensitive business and customer information;
- establish clear responsibilities for payment approval;
- respond more effectively when suspicious activity is detected;
- maintain confidence in digital payment processes.
Railor’s approach to fraud prevention
Railor takes a risk-based approach to fraud prevention. Depending on the service, transaction and circumstances, our controls include customer and business verification, transaction monitoring, security checks and the review of unusual activity.
We continuously assess fraud risks and work to improve our procedures as threats and fraud patterns develop. Where appropriate, we may request additional information, delay the processing of a transaction or take other proportionate steps to verify that an instruction is legitimate.
These checks are intended to protect our clients and the wider financial ecosystem. No control can eliminate fraud entirely, but careful monitoring, strong processes and timely cooperation can significantly reduce exposure.
Fraud risks businesses should be aware of
Fraud can take many forms. Common examples include:
Business email compromise
A fraudster impersonates a director, employee, supplier or business partner and requests an urgent payment or a change of bank account details.
Invoice fraud
Legitimate payment instructions are replaced with fraudulent account information.
Account takeover
Login credentials or authentication details are obtained and used without authorisation.
Phishing and social engineering
Employees are encouraged to disclose confidential information, open malicious attachments, follow fraudulent links or approve payments.
Malware and compromised devices
Malicious software may be used to capture credentials, alter payment details or gain unauthorised access to systems.
Internal fraud
An employee, contractor or other trusted person misuses their access or acts together with an external party.
Fraudulent customers or counterparties
A business may receive payments connected to stolen identities, compromised accounts, false documentation or unlawful activity.
How your business can reduce fraud risk
Introduce strong payment controls
Use clear approval limits and, where possible, require more than one authorised person to approve significant or unusual payments. Avoid allowing a single employee to create, approve and release the same transaction.
Verify changes independently
Treat requests to change a supplier’s, customer’s or employee’s bank details with caution. Confirm the request through a separate and trusted communication channel, using contact information already held by your organisation rather than details included in the request.
Be cautious with urgent requests
Fraudsters frequently create pressure by claiming that a payment is confidential, overdue or required immediately. Employees should feel able to pause, verify and escalate unusual instructions, even when they appear to come from senior management.
Protect access credentials
Use strong, unique passwords and enable multi-factor authentication wherever available. Railor login credentials, authentication codes and security information must not be shared with colleagues or third parties.
Keep devices and software secure
Regularly update operating systems, browsers and business applications. Use reputable security and anti-malware tools, and restrict payment access on public or shared devices.
Review user access
Provide employees only with the permissions required for their responsibilities. Remove or update access promptly when an employee changes role or leaves the organisation.
Monitor activity
Review transactions, account activity and user access regularly. Investigate unexpected beneficiaries, unusual payment values, unfamiliar login activity and changes in normal transaction patterns.
Train employees
Fraud prevention should be part of regular employee training. Staff involved in finance, procurement, customer service and account administration should understand common fraud indicators and know how to report concerns.
Protecting sensitive information
Never disclose passwords, authentication codes or full security credentials in response to an unexpected call, email or message.
Be cautious when anyone claiming to represent Railor asks you to take urgent action. Railor personnel should not ask you to disclose your password or authentication code, or instruct you to move funds to a so-called “safe account”.
When in doubt, stop the interaction and contact Railor through a verified communication channel.
Warning signs that may indicate fraud
Pause and verify the situation when:
- a payment request is unexpected or unusually urgent;
- bank account details have changed without prior notice;
- the sender asks you to ignore normal approval procedures;
- the wording or email address differs from previous correspondence;
- an individual asks for passwords, authentication codes or confidential account information;
- you are pressured to keep a transaction secret;
- a new beneficiary is introduced shortly before payment;
- the offer or explanation appears unusually favourable or inconsistent;
- the person refuses independent verification.
- Before approving a payment
- Ask the following questions:
- Do I know and trust the recipient?
- Was this payment expected?
- Have the beneficiary details been independently verified?
- Does the request follow our normal internal process?
- Is anyone pressuring me to act immediately?
- Could the sender’s email account or device have been compromised?
- Have I confirmed the instruction using a trusted contact method?
- Taking a few additional moments to verify a payment can prevent a significant loss.
What to do if you suspect fraud
If you believe that your Railor account, credentials or payment instructions may have been compromised:
- Stop communicating with the suspected fraudster.
- Do not approve or send any further payments.
- Contact Railor immediately through an official communication channel.
- Inform your organisation’s authorised security, compliance or finance personnel.
- Change any credentials that may have been exposed.
- Preserve relevant emails, messages, payment instructions and other evidence.
- Consider informing your bank, relevant authorities or law-enforcement bodies, where appropriate.
Early reporting may improve the ability of all parties involved to investigate the incident and limit potential harm.
Our commitment
Railor understands that businesses rely on payment services that are not only efficient, but also supported by responsible security and fraud-prevention practices.
We are committed to maintaining appropriate controls, reviewing suspicious activity and helping our clients understand the risks associated with digital payments. We also encourage open communication: when something does not look right, we want our clients to feel confident raising it with us.
Fraud methods will continue to change. By combining effective technology, careful verification, employee awareness and timely cooperation, Railor and its clients can build a stronger defence against financial crime.
Onboarding guide
Introduction
Ensuring a smooth onboarding and KYC (Know Your Customer) process is essential for your account approval and IBAN issuance. To help with this, the Railor team has set clear requirements to thoroughly review your information, evaluate your application, and make a final decision. Please note that Railor cannot enter into a business relationship with anyone who has not completed the KYC requirements during onboarding.
Online registration form
When filling out the online registration form, please provide accurate and up-to-date information. Double-check your entries if needed. Paying attention to details like contact information, company managers’ data, and documentation will help ensure a smoother and faster onboarding process for your account.
ID Verification
Our ID verification system allows you to confirm your identity, which is an essential part of the onboarding and KYC process. This procedure involves taking a live photo of yourself and either your international passport or EEA national ID card. Please ensure the following when performing ID verification:
- Take a photo showing your face and shoulders.
- Use a valid document for verification (only an EEA national ID card or an international passport is acceptable).
- If using an ID card, take one photo of the front and one of the back.
- If using a passport, take a photo of the main page with your photo.
- Ensure all text on the document is visible and readable; otherwise, we cannot accept it.
Guidelines for Corporate Documentation
Please be aware that all documents provided to Railor must be in English or Lithuanian languages or officially translated to English/Lithuanian accordingly (proof of the official translation must be visible in the submitted document). The documents provided must be visible and readable, none of the parts can be covered, redacted or hidden. The documents must be provided by replying to the Railor team’s initial email request.
Depending on your business industry and jurisdiction the Railor‘s AML team may request you to provide additional Corporate Documents.
Source of Wealth
In some cases, to understand how and which activities generated your source of wealth, our AML team will send you a separate questionnaire to fill out and provide supporting documentation. If you receive one, please make sure that:
- You indicate your Name, Surname, Date of Birth, and Occupation;
- You provide a clear explanation of how the source of funds has been accumulated;
- Based on your explanation, you provide supporting documentation from the list mentioned in the form.
Our Risk Appetite
Restricted countries and industries list
We are not able to open accounts for residents and businesses of the following countries and jurisdictions:
American Samoa, Angola, Anguilla, Botswana, Burkina Faso, Burundi, Cambodia, Cameroon, Chad, Comoros, Congo, Cote d’Ivoire, Democratic Republic of Congo, DPRK, Equatorial Guinea, Eritrea, Fiji, Ghana, Guam, Guatemala, Guinea Bissau, Haiti, Honduras, Iran, Iraq, Jamaica, Kenya, Lebanon, Libya, Madagascar, Mali, Mongolia, Morocco, Mozambique, Myanmar, Namibia, Nepal, Nicaragua, Nigeria, North Korea, Pakistan, Palau, Palestinian Territory, Panama, Russia, Samoa, Senegal, Seychelles, Somalia, South Sudan, Sudan, Syria, Tajikistan, Tanzania, Trinidad and Tobago, Turkmenistan, Turks and Caicos, Uganda, US Virgin Islands, Vanuatu, Venezuela, Vietnam, Yemen, Zimbabwe.
We do not service companies of the following industries:
- Unlicensed or unregistered financial services;
- Weapons, defense and dual use goods;
- Unlicensed gambling;
- Illicit drugs and related paraphernalia;
- Adult entertainment;
- Unauthorized crypto-asset activity;
- Pseudo – pharmaceuticals;
- Unauthorized crypto-asset activity.
