Impersonation policy template: what belongs in each section. Impersonation policy template: what belongs in each section
Photo by Privacy Scam Verification on card

Costs

Part of Impersonation runs both ways: protecting your name and your trust in others

Impersonation policy template: what belongs in each section

A working impersonation policy for a small team or group: the decisions it has to settle, a skeleton to adapt, and the drills that make it hold.

Most impersonation policies fail in the same way. They describe the problem, they assign a coordinator, and they say nothing about what an ordinary member does at nine in the evening when a message arrives claiming to be from someone senior.

A usable policy answers a small number of questions in advance so that nobody has to be brave in the moment. This is a skeleton for a club, a small business, a volunteer group, or a family that shares money decisions. Adapt it, and keep it short enough that somebody reads it.

What to take away

  • A policy earns its place by removing decisions from the moment of pressure, not by describing threats.
  • The two rules that do the work are a callback rule and a no-blame reporting rule.
  • Anything untested is a document rather than a policy, so write one drill into it.

What the policy has to settle

Six questions. If a draft does not answer these, it is not finished.

Checklist of six questions an impersonation policy must answer (Impersonation policy template: what belongs in each section)
If a draft does not answer these six questions, it is not finished. Image: Privacy Scam Verification
The question Why it has to be decided in advance
What channels are official Otherwise every new channel looks plausible
How a request for money or data is confirmed Because confirming in the moment favors the confident
Who can approve a payment, and how So an urgent instruction from a name has no route
What a member does when they suspect impersonation Reporting has to be easier than staying quiet
Who speaks publicly, and when To stop five contradictory statements
What happens after, and to whom So the person who reported is not the person punished

The skeleton

Adapt the wording. Keep the structure.

Steps showing how to confirm a request using the callback rule (Impersonation policy template: what belongs in each section)
The callback rule is the core of the skeleton: confirm off-channel, using details you already hold. Image: Privacy Scam Verification

Scope. This applies to anyone acting for the group: staff, volunteers, committee members, contractors. It covers our name being used on outsiders and outside names being used on us.

Official channels. Our official accounts and addresses are listed here, maintained by one named role. We announce a new channel from an existing one before using it. We never announce a channel from the new channel itself.

The callback rule. Any request involving money, credentials, personal data, or urgency is confirmed on a channel other than the one it arrived on, using contact details held by us rather than details supplied in the request. This applies regardless of who the request appears to come from, and seniority does not waive it. A person who cannot wait for a callback is not somebody we transact with.

Payment authority. Payments and changes to payment details follow the process below and no other route. Changes to a supplier's bank details are confirmed by callback to a number held on file before the change, never a number in the request. Nobody may approve their own exception.

Codes and credentials. No member ever shares a one-time code, a password, or a screen with anybody, including anybody claiming to be internal support. Our own support will never ask.

Reporting. Anybody who suspects impersonation reports to the named role immediately, and reports it whether or not they acted on it. Reports made in good faith carry no consequence, including when the person already sent money. This clause is the one that decides whether the policy works.

Response. The named role collects the evidence, reports to the platform, warns the people likely to be contacted, and issues one public statement. Members do not engage with the account.

Review. Reviewed twice a year and after any incident, by the named role, with the date recorded on the document.

Adapting it honestly

Three adjustments matter more than the wording.

Checklist of three adjustments for adapting the policy honestly (Impersonation policy template: what belongs in each section)
Wording matters less than naming people, setting a real threshold, and protecting the junior person. Image: Privacy Scam Verification

Name real people rather than titles, since a title with nobody in it is where policies die. Set the payment threshold at a number this group would genuinely feel, rather than a number copied from a larger organization.

And write the callback rule so it protects the junior person. Include the sentence that no member will ever face criticism for slowing a request down, and that anyone who applies pressure to skip the check is treated as a warning sign.

The reasoning behind putting recovery settings and account access ahead of the public response is in account security.

The drills worth running

Twenty minutes, twice a year, and they find more than the document does.

Steps for a twenty-minute impersonation policy drill (Impersonation policy template: what belongs in each section)
Twenty minutes, twice a year, and the drills find more than the document does. Image: Privacy Scam Verification

Ask three members to say from memory what they would do with an urgent payment message from the person in charge. Try to reach the named role using only the policy's contact details and see whether they still work.

Take one supplier and confirm the process for a change of bank details actually exists. Read the last incident and check whether the person who reported it would report it again.

The failure modes these expose are the ordinary ones described in impersonation risks: a channel nobody maintains, a role nobody fills, and a reporting route that costs somebody their standing.

After an incident

Write the record while it is fresh, and keep it factual.

Checklist of details to capture in an incident record (Impersonation policy template: what belongs in each section)
That record is what a bank, a platform, or an insurer will ask for. Image: Privacy Scam Verification

What arrived, on what channel, what was asked for, what happened, when it was noticed, who was told, and what was reported where, with reference numbers. That record is what a bank, a platform, or an insurer will ask for, and it is the material for the review.

Report it externally as well as internally. In the US, consumer fraud reports go to the Federal Trade Commission's reporting route, and internet-enabled crime reports go to the FBI's Internet Crime Complaint Center, which explains what a complaint can and cannot do. Where a payment moved, the provider comes first and the sequence is in reporting and recovery.

What to leave out

Short policies get read. Long ones get filed.

Comparison table of what to leave out of a policy and what to keep (Impersonation policy template: what belongs in each section)
Short policies get read; long ones get filed. Image: Privacy Scam Verification

Leave out descriptions of how attacks are constructed, which help nobody who has to follow the policy. Leave out a list of red flags, which ages badly and trains people to look for a style rather than to apply a rule: recognition belongs in training, and the pattern-level version of it sits in phishing scams.

Leave out any promise about how quickly a platform will act, because you do not control that. And leave out consequences for members who fell for something, unless you want the next incident reported a week late.

Common questions

Is a policy worth it for a group of five people?

Yes, at one page. The callback rule and the no-blame rule are the entire benefit, and both fit in two sentences.

Who should hold the named role?

Somebody who is usually reachable, not necessarily the most senior person. A role nobody can reach at nine in the evening produces the delay the policy exists to remove.

Should the policy be public?

The parts that tell outsiders how we contact them should be, since that is what makes a fake approach checkable. The internal thresholds should not be.

What if the impersonation targets our customers rather than us?

Warn them directly and quickly, on the channels they already use, and say plainly what you will never ask for. That warning does more than any takedown request.

How do we know the policy is working?

By the number of near misses reported, which should rise rather than fall. A group that reports nothing is not a group without approaches.

More in Costs

Latest from Planning Desk