sxsphinxstack

Skills / Advanced / Recover from a global treasury control failure

Advanced Money skill

Recover from a global treasury control failure

Recover from a global treasury control failure with independent containment, payment reconstruction, liquidity protection, obligation recovery, bank coordination, clean authority, and verified control restoration.

When to use

  • Use after credential theft, payment fraud, mandate corruption, duplicate release, bank-channel compromise, sanctions-control failure, cash-pool error, or material reconciliation breakdown.
  • Use when accounts, entities, currencies, banks, payment rails, hedges, debt, payroll, tax, suppliers, and customer funds interact.
  • Do not freeze protected customer or payroll funds without lawful authority and a human-impact plan.

Preconditions

  • Establish conflict-checked incident command with treasury, finance, security, legal, compliance, fraud, accounting, operations, and human-impact owners.
  • Create bank-verified out-of-band contacts, independent evidence storage, a controlled instruction register, and a single authority clock.
  • Define payment-stop, liquidity, disclosure, sanctions, insurer, regulator, and board authority by entity and jurisdiction.

Procedure

Run four linked workstreams: independent containment and human protection; account, instruction, and effect reconstruction; liquidity and obligation recovery; trust reestablishment.

  1. Open a global treasury control failure timeline with UTC time, entity, account, bank receipt, instruction state, decisions, and uncertainty.
  2. Protect payroll, customer money, critical services, taxes, debt covenants, safeguarded accounts, and sanctioned-person restrictions.
  3. Fence compromised channels, credentials, APIs, files, templates, devices, mandates, beneficiaries, approvers, robots, and bank sessions.
  4. Instruct every bank through verified contacts to hold or flag affected items while preserving accepted, pending, rejected, recalled, and settled states.
  5. Snapshot bank statements, intraday feeds, acknowledgements, payment files, API logs, approvals, ERP events, ledgers, cash positions, forecasts, mandates, and beneficiary changes.
  6. Assign stable IDs and one authority epoch to accounts, credentials, instructions, approvals, batches, bank events, ledger entries, beneficiaries, hedges, and liquidity decisions.
  7. Reconstruct account, mandate, credential, instruction, approval, bank, ledger, beneficiary, hedge, and liquidity reconciliation at item level.
  8. Treat bank acknowledgement and settlement as distinct; record each rail’s cutoff, cancellation, recall, return, finality, fees, and counterparty action.
  9. Maintain a partial-recovery state machine for every original instruction: amount and currency; frozen, recalled, returned, irreversibly settled, unrecovered, fee, and FX amounts; beneficiary action; protected obligation; accounting entries; and replacement instruction ID. Identify duplicate, altered, missing, unauthorized, misrouted, blocked, returned, delayed, or incorrectly booked effects without netting away evidence.
  10. Build a time-phased liquidity and obligation plan by legal entity, currency, restriction, value date, confidence, and protected priority.
  11. Recover funds through bank, beneficiary, insurer, correspondent, law-enforcement, and legal channels while recording authority and avoiding unsafe contact; require bank-verified state and dual approval before a replacement payment, write-off, or liquidity reallocation.
  12. Rebuild mandates, devices, identities, beneficiaries, templates, signing keys, integrations, and approvals from clean evidence with independent administration.
  13. Issue only new-epoch instructions with stable idempotency keys; reject stale files, callbacks, approvals, and retries across every channel.
  14. Reconcile bank, ledger, tax, hedge, debt, payroll, supplier, customer, and cash-forecast effects before reopening each payment class.
  15. Validate controls under insider, vendor, bank, API, file, time-zone, sanctions, outage, duplicate, recall, and degraded-manual scenarios.

Failure plan

  • Keep affected payment classes fenced and use approved alternate arrangements while authority, finality, liquidity, or legal status is uncertain.
  • Never roll back by replaying old files or restoring old credentials; create reconciled corrective entries and new-epoch instructions.
  • Escalate an inability to protect people, customer funds, statutory obligations, or critical liquidity immediately.

Worked example

A stolen treasury workstation adds a beneficiary, alters two payment files, releases a duplicate batch, disrupts sanctions screening, and leaves banks reporting inconsistent settlement while payroll and a debt payment approach.