Treadstone Associates
Article · 12 min read

Freight fraud prevention for brokers

The controls that stop freight fraud are dull and cheap. The test is whether they survive a busy Friday afternoon.

Treadstone Associates · Updated 2026

Key takeaways

  • • Verify carrier identity in the issuing province’s register, not on the documents you were sent.
  • • Verify every change of banking details by calling a number held on file from before the request — with no exception for urgency.
  • • Separate duties even in a three-person team: onboarding, banking changes and payment approval should not sit with one person.
  • • If personal information is compromised, PIPEDA requires reporting breaches posing a real risk of significant harm, notifying individuals and keeping records of all breaches.

The short answer

The controls that actually stop freight fraud at a small brokerage are dull and cheap: verify identity at the regulator rather than on the documents you were sent, verify any change of payment details by calling a number you already held, restrict who can change a carrier record or release a load, keep an audit trail of who did what, and know in advance what you do in the first hour after something goes wrong.

Nothing on that list requires a large budget. What it requires is that the rules survive contact with a busy Friday afternoon, which is the only real test any of them face.

Control 1 — identity, verified at source

Fraud in freight is usually identity fraud: someone presents as a legitimate carrier. The counter is to verify with the issuing authority instead of the sender. Ontario publishes a free carrier safety rating enquiry and a carrier search by name, plus lists of excellent and of unsatisfactory or cancelled carriers, with a CVOR abstract available online for a fee. Alberta publishes safety fitness certificate and operating status information.

Underneath the provincial registers is a single national requirement: no person or body shall operate an extra-provincial motor carrier undertaking except under a safety fitness certificate issued by a provincial authority, valid throughout Canada. If a purported carrier cannot be located in the register of the province it claims to be plated in, stop there. The sequence is set out in the carrier vetting checklist.

Control 2 — payment changes, verified out of band

The highest-value single control in a brokerage is a rule about banking details. Any change — new account, new factoring company, new remittance address — is verified by telephoning a number already on file from before the request arrived, never a number in the message itself, and the verification is recorded with the date, the number called and the person spoken to.

The reasoning is the same one that governs high-value transfers in other professions; see why payment instructions are verified by phone before large sums move. Make it a rule with no exception for urgency, because urgency is the pressure the fraud depends on.

Control 3 — separation of duties, even with three people

Small teams assume separation of duties is for large ones. It is not; it just looks different. The workable minimum is that the person who onboards a carrier is not the only person who can change its banking details, and the person who books a load is not the only person who can approve payment on it. Where the team is genuinely two people, use a second-look rule for changes above a threshold you set in advance.

Whatever your system is, make sure it records who changed what and when. An audit trail is the difference between knowing what happened and guessing.

Control 4 — document and handover integrity

Seals, driver identity at pickup and delivery, and a proof of delivery that names the person who signed. Ask shippers to record the carrier name from the tractor door on the bill of lading — it costs nothing and it is the control that catches the pattern described in how to spot double brokering.

Where the freight is regulated, the documentation is also a control in its own right. Dangerous goods shipping documents must carry the consignor’s Canadian place of business, the date the document was prepared or first given to a carrier, and each dangerous good described in the prescribed order beginning with the UN number and shipping name. Food moving between provinces requires traceability documents recording the common name, a lot code or other unique identifier, who the food was provided to and when, and who provided it and when. Records like these make a substitution visible.

Control 5 — your data, and the obligation if it leaks

A brokerage holds driver names, licence details, carrier banking information and customer contacts. If that is compromised, obligations follow. The Office of the Privacy Commissioner sets out that organisations subject to PIPEDA must report to the Privacy Commissioner breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals, notify affected individuals, and keep records of all breaches.

The practical implication is that your incident plan needs a privacy limb, not only a money limb. Knowing in advance who assesses whether the threshold is met is worth more than a policy nobody has read.

Control 6 — the first hour after it happens

Write the sequence down before you need it. Freeze outbound payments on the affected file. Preserve everything — messages, documents, system logs — before anyone tidies. Tell your customer rather than waiting for the claim. Notify your insurer and get advice before paying anyone, because paying the wrong party is how a single loss becomes two. Report it: the Canadian Anti-Fraud Centre collects information on fraud and identity theft and provides information on current frauds affecting Canadians.

If personal information is involved, run the privacy assessment in parallel rather than afterwards, using the Privacy Commissioner’s guidance on mandatory breach reporting.

Worked example: a Friday afternoon banking change

At 4:40 p.m. on a Friday, a brokerage received an email from a long-standing carrier’s usual address, attaching a notice on letterhead that it had moved to a new factoring company, with new remittance details and a request to apply them to three invoices due that day.

The rule in place was that any banking change is verified by calling the number held on file from before the request. The number was called; the carrier’s owner had not sent it. The email account had been compromised, and the letterhead was genuine because it had been taken from the account.

Two details made the control work. The number was in the carrier file rather than in the email, and the rule had no urgency exception — which mattered, because the request was engineered to arrive when checking felt expensive. The brokerage added a third element afterwards: banking details can only be changed by a second person, and the change is logged.

Where automation helps, and where it must not decide

Automation earns its place on the monitoring side. Watching for a change in a carrier’s banking details, flagging when an invoice arrives from an entity that does not match the booked carrier, comparing the legal names across the documents in a file, raising an alert when a certificate or clearance lapses, and assembling the evidence pack when something is disputed. These are matching, extraction and alerting tasks, and doing them consistently is most of the value.

What a tool must not do is approve. Releasing a load, accepting a carrier, and authorising a payment are decisions with money and liability attached, and they belong to a named person who signs. Keep the boundary explicit in the procedure, so that an alert is a prompt to check rather than a step that clears itself.

Common questions

What is the single most effective control?

The out-of-band verification of payment changes, with no exception for urgency. It is the control that most directly defeats the highest-value attack.

Where do we report freight fraud in Canada?

To the police of jurisdiction, and to the Canadian Anti-Fraud Centre, which collects information on fraud and identity theft. Report even when the money is not recovered, because the reporting is what makes patterns visible.

Do we have privacy obligations if our system is breached?

If personal information is involved and you are subject to PIPEDA, yes: report breaches that pose a real risk of significant harm, notify affected individuals, and keep records of all breaches.

How long should we keep the evidence?

At least as long as your ordinary records, which under the Income Tax Act is six years from the end of the last taxation year to which they relate and under the GST/HST rules six years after the end of the year to which they relate. Disputes about a load routinely surface long after the freight has been delivered.

Put the boring controls in before you need them.

A 30-minute call is enough to see what can be monitored automatically.