Constance Ibe-Whitmore
Reads the rule, not the summary of the rule. Distinguishes what a regulation requires from what a vendor says it requires, and dates every obligation.
Posts by Constance
The deepfake wire trap: why out-of-band callbacks fail UCC Article 4A
Treasury policy mandates a phone callback to the CFO before releasing a large wire. Voice and video cloning defeat that control, and the commercial reasonableness standar
Time-and-effort certification: the signature at the centre of federal grant fraud
Federal watchdogs told Congress in June 2026 that false time-and-effort certifications are a principal grant-fraud mechanism. The certification is a bulk approval in an a
Proofed once at registration, stolen at the dock: the 2026 cargo theft arithmetic
FMCSA began requiring photo ID and a live selfie for operating authority in January 2026 and retired MC numbers. In the same period cargo thefts fell 26% while losses mor
Regulation S-ID is a detection rule: the SEC's 2026 identity theft priority
The SEC named Regulation S-ID a 2026 examination priority, with attention to red-flag detection during account takeovers and fraudulent transfers. A prepared impersonator
$186 billion in improper payments and the vendor master file nobody signs
GAO reported in April 2026 that fifteen agencies estimated about $186 billion in improper payments across 64 programs for fiscal 2025. Payment integrity spending concentr
Double brokering: making the re-tender a signed, traceable act
A load tendered to carrier A moves on carrier B's truck. Sometimes that is legitimate co-brokerage; sometimes it leaves the shipper uninsured and the actual hauler u
STIR/SHAKEN attests the carrier, not the caller
Attestation level A means the originating carrier knows the customer and their right to use the number. It says nothing about who is speaking, which is the question every
The fake court order: verifying judicial documents without calling the clerk
Banks, registrars and platforms act on court orders daily. Verification is visual — a caption, a seal image, a signature block — because the clerk's office is not st
Replacing the screenshot: audit evidence your auditor can re-perform
An auditor samples twenty access changes and receives twenty screenshots produced by the client's administrator. They are testing a control using evidence generated
Who let the vendor in? Per-session authorization for medical device service access
Infusion pumps and imaging consoles are serviced remotely through shared manufacturer accounts and standing VPN paths. When a device misbehaves after a service session, t
The secure software development attestation and the human who signed it
Federal software producers attest to secure development practices. An executive signs for engineering practices spanning potentially thousands of repositories, on evidenc
Construction draws: large, repeated, and authorised by PDF
A construction loan pays out in instalments against signed forms circulated by email. The forms are PDFs, the amounts are six figures, and the process repeats monthly for
The email warning banner as a legal defence
Title agencies put a red warning about wire fraud at the bottom of every email. Whether that discharges a professional's duty of care is a question courts are answer
The interview proves someone can interview
A video interview establishes that a person appeared and answered questions. Real-time face replacement means it does not establish which person, and nothing connects the
Source code exfiltration by people who are supposed to have it
Data loss prevention looks for sensitive content leaving. A contractor cloning a repository they were granted access to produces traffic that is indistinguishable from wo
Rotating signing keys without breaking verification
Key rotation causes outages when verifiers reject signatures made with a key they have not yet seen. The fix is an overlap window and a discipline about what gets retired
What brokers can actually negotiate on impersonation risk
A broker's leverage comes from what they can show an underwriter. On deepfake-enabled fraud there is little to show, which is why sub-limits have not moved.
Your cyber limit is not your wire fraud limit
A large cyber tower can carry a small sub-limit for the loss type most likely to occur. Treasury discovers this at claim time rather than at renewal.
Software warranties require a defect you can define
Vendors are starting to back security claims with money. A warranty only works if what counts as a failure can be determined without a dispute.
Address poisoning works because humans check the ends
Nobody reads a forty-character address. They check the first four and the last four, which is exactly the check an attacker can defeat by brute force.
Read-back is not evidence: verbal orders in an era of synthetic voice
Read-back verifies transcription accuracy, not speaker identity. Retrospective countersignature verifies neither. With voice cloning now commodity tooling, the verbal ord
Workload identity federation: removing the secret without removing the question
Federation is a genuine improvement — no static secret to leak. The trust policy that decides which repository or branch may assume a powerful role is a configuration fil
Auto-execute modes remove the only gate that was working
Agentic development tools offer a setting that runs commands without asking. Developers enable it because the prompts are tedious. The prompts were the control.
Replacing approval screenshots with something an auditor can check
Screenshots of chat approvals are the most common change-control evidence in software companies and among the weakest. They are also entirely avoidable.
Adverse action under algorithmic discrimination law
State AI acts require deployers to explain adverse decisions and demonstrate they guarded against discriminatory outcomes. Both obligations attach to individual decisions
Sign-all and the ambient scribe: what the clinician actually attested
Ambient documentation tools generate notes a physician signs. Bulk signing existed before AI and was already a problem; automated generation makes the volume larger and t
Consumer protection liability when the bot makes the promise
Consumer protection law holds a business responsible for representations made on its behalf. Nothing in that framework requires the representation to have come from a per
Sectoral AI regulation: one control, several regulators
A regime that empowers existing sector regulators rather than passing a single AI statute produces overlapping expectations. The practical response is to find the control
Evidencing human oversight for an AI management system audit
Management system certification is an evidence exercise. The oversight clauses are where organisations most often present intent and get asked for operation.
Why CAPTCHA is finished as a human test
The premise was a task humans find easy and machines find hard. Vision models now solve visual puzzles more accurately and faster than people do.
Two-person control that software cannot prove
Two-person control is a physical concept: two keys, two humans, two locks. Digitised into a workflow with two approver fields, its independence is asserted by procedure r
Recycled numbers: the account recovery collision nobody owns
A phone number is treated as a durable identifier by thousands of relying parties and as a leased resource by carriers. When a number is reassigned, every account still b
One human, one offer: promotion integrity without surveillance
One-per-person offers are enforced by fingerprinting, IP analysis and payment matching. All three are degrading, all three produce false positives against real customers,
Emergency services location: tiering account attributes by physical harm
A registered emergency location determines where armed responders are dispatched. It is changed through a self-service portal with the same authorisation strength as a ma
Public records requests and redaction authority: who decided this could be released?
Agencies are adopting automated and AI-assisted redaction to manage backlogs, shifting review from page-by-page human work to exception handling. An improper release cann
Secondaries and SPVs: transfer consent in a market built on PDFs
Transfer of an LP interest requires GP consent and a chain of authority documents across entities. Every artefact is a PDF, and verification is a law firm reading them.