The Verification Gap: Why DAF Disbursements Are Exposed
A void cheque proves an account exists, not that it belongs to the charity. Why charitable disbursement controls are failing, and what actually closes the gap.
Jeff Golby
CEO & Co-Founder, WellFunded

Key Takeaways
- Every common method (a void cheque, a video call, a mailed cheque, an emailed form, a secure upload link) confirms that an account exists or that data moved safely. None confirms the account belongs to the charity.
- That gap is where fraud enters, and the liability lands on the DAF and on the administrator personally.
- Real verification means ownership, regulated, and current. It confirms the account against the charity's own bank, keeps it current as details change, and syncs the charity's CRA standing monthly.
- WellFunded never holds your funds, and your team never collects or stores banking data, so adopting verified disbursement removes a liability you already carry rather than adding one.

The methods the charitable sector uses to confirm where a payment is going were built for a world where forging a document was hard, impersonating a person was harder, and a cheque was considered reliable. That world is gone. The true cost of fraud last year for Canadians was believed to exceed $6 billion. AI is making fraud cheaper and faster to run. Charities and DAFs need to do better.
Your disbursement process likely looks something like this:
- A donor recommends a grant to a charity you don't yet have on file, so you ask the charity for a void cheque. They send a scan, by email or, at best, through a secure link.
- You jump on a Zoom call with the sender to confirm the cheque is real, usually a quick hello and asking them to read out the cheque number.
- An administrator keys the numbers into a spreadsheet or a tool that generates the payment file when it is time to disburse.
Almost every time, the money lands where it should, and nobody thinks about it again. The process feels routine, and routine feels safe.
It only takes one conversation with a DAF that's been defrauded to see that routine and safe aren't the same thing. What remains is a set of habits that confirm the wrong thing, carry real liability, and put a foundation's name one bad transfer away from a story it doesn't want to be in.
The distinction that matters
At the centre of charitable disbursement, most DAFs can't answer one question: how do they prove the account number actually belongs to the charity, and that it's accurate on the day the money goes out?
A bank account can be real and still belong to the wrong person. A void cheque only confirms that someone can produce a void cheque, real or real-looking. Banking details can arrive safely and still be wrong.
What verification should mean
Before taking the methods apart, it helps to name the standard they should be measured against. Real verification of a charitable payment has three properties:
- Ownership, not existence. It confirms the account belongs to the registered charity, not merely that the account is real.
- Regulated, not self-attested. The confirmation comes from a regulated financial process, not from a document the recipient supplied about themselves.
- Current, not stale. It reflects where the charity banks today, not where they banked the last time anyone checked, and it is kept current as the charity's details change rather than trusted indefinitely.
Hold each common method against those three, and the picture gets clear quickly.
What checking a charity's standing should mean
A bank account is only half the question. The other half is whether the recipient is still a registered charity at all.
Registered status isn't permanent. The CRA revokes registrations, sometimes for non-filing, sometimes for cause, sometimes at a charity's own request. A grant sent to an organization that has lost its status is a compliance problem, not just an administrative one.
The standard here is timeliness. The CRA sends registration updates to select partners, including WellFunded, monthly. Most current processes never check this at all, and an annual review, while better than nothing, is still too slow.
What data storage should mean
Start with how the data moves. Sending banking details by email leaves you wide open before they're even stored. A monitored or compromised inbox lets an attacker read the details in transit, and a spoofed sender can slip false ones in. This is the territory of business email compromise, one of the costliest attacks aimed at organizations today, and it's a serious liability on its own. And that's only the transmission.
Holding the data afterward is a standing responsibility, and it's where a surprising amount of quiet risk builds up.
Banking details collected on void cheques and kept in shared drives, spreadsheets, and email folders are sensitive financial records sitting on systems never built to protect them. Every person with a login is another point of exposure. Every copy is another place the data can leak or be misused.
The standard is that this data should live in secure, encrypted infrastructure with Canadian data residency, visible to as few people as possible, and held in one controlled system rather than scattered across the funder's own drives, inboxes, and spreadsheets. The safest banking data is the kind you're not storing yourself.
Does a void cheque verify ownership?
No. A void cheque proves an account exists and that a name has been printed on a piece of paper. It proves nothing about who owns the account.
- A successfully processed void cheque tells you the account was real at some point. It doesn't tell you it's the right one. The name on the cheque and the owner of the account are simply assumed to match, and that assumption is the entire security model.
- It's also no longer difficult to fake with AI. The cheque at the top of this page took seconds to make. The organization on it doesn't exist, and the numbers are invalid, but to anyone reviewing a batch of disbursements it would pass without a second look.
This isn't theoretical. In Richmond, British Columbia, the Regional Animal Protection Society (RAPS) was targeted with a sophisticated fraud built around a counterfeit instrument, and at least two other BC animal sanctuaries were hit by the same scheme. Hamilton Community Foundation went public with a fraud of its own, and we know of others who have absorbed losses privately. The sector's systems aren't built to catch this.
Against the standard:
- Existence, not ownership
- Self-attested, not regulated
- A single moment, after which it quietly goes stale
A void cheque proves an account exists. It says nothing about who owns it.
Is it safe to confirm banking details over a video call?
No, for two reasons.
- The first is that a call can't confirm this is the right person at the charity, or that they're still the right person the next time you need to verify. People change roles, they change in trustworthiness, and they leave.
- The second is that AI-generated deepfakes on a video call are now cheap and easy to produce.
For a long time, seeing and hearing a person felt like proof. If the executive director got on a call and confirmed the account, that was good enough. That era ended in public.
A finance worker at a multinational firm paid out roughly $25 million after joining a video call with what he believed were several colleagues, including the company's chief financial officer. Every person on the call was an AI deepfake. He had initially suspected a phishing email and grown cautious, then set the caution aside because the people on the screen looked and sounded exactly like the colleagues he knew.
If a multinational with real financial controls can lose that much because a video call looked convincing, then confirming a charity's banking details over Zoom is resting on the precise thing fraud has now learned to fake.
A genuine call only confirms that a person said something.
A video call confirms a face. Faces can now be faked.
Why don't mailed cheques solve this?
The mail itself is no longer something to count on. And even when a cheque does arrive, it trades one set of risks for another and still never verifies the destination.
A mailed cheque can be intercepted, altered, lost, or deposited into the wrong account. There's no real-time audit trail and no confirmation of receipt until the charity calls to say thank you, or doesn't. Mail is unreliable often enough that delay is a normal outcome, not an edge case.
It's also expensive on both sides:
- The funder pays for printing, postage, tracking, reconciliation, and staff time.
- The charity waits weeks for funds to clear, then spends its own staff time to deposit and reconcile. For a lean charity operating remotely, simply getting a cheque to a branch is a bottleneck.
Most of all, a cheque doesn't verify that the destination belongs to the charity. It just moves that unanswered question into an envelope.
A cheque moves money without ever confirming where it lands.
A secure upload link fixes this, doesn't it?
This is the one that fools almost everyone, because it's half right.
A secure link does fix the transport problem. The banking details travel through an encrypted channel instead of an email attachment, so they can't be intercepted in transit. That's a real improvement, and it's where many well-intentioned organizations stop, believing they have solved verification.
They haven't. The channel is secure. The claim inside it is still unverified. A charity, or someone posing as one, uploads banking details through the encrypted link. The system confirms the upload was secure. It confirms nothing about whether the account belongs to the registered charity.
A secure link protects the envelope, not the truth inside it.
The person caught in the middle
Perhaps most troubling, there's a human being inside this process, and the current model puts them in an indefensible position.
To collect void cheques, key in banking details, and build payment files, an administrator needs access to all of it: account numbers, transit numbers, the funds in motion. That access makes them the system's single point of trust. If they ever chose to act dishonestly, they could. And if anything ever goes wrong, whether they touched it or not, they're the first person asked to explain. That's an enormous amount of liability to rest on one person's integrity, and it's unfair to them.
Sign-offs don't fix this. A second signature on a disbursement approves a dollar amount and a charity name. It doesn't confirm the bank account behind that name belongs to the charity. Unless a board member is personally checking account and transit numbers against a verified source, an approval controls how much leaves and to whom on paper. Where the money actually lands is a separate question. The amount and the name can be exactly right and the account still wrong.
The deeper problem runs through this entire piece. The system trusts a person where it should verify a fact.
What actually closes the gap
Verification that clears all three bars looks different from any of the above. It doesn't rely on a document, a face, or a channel. It confirms the account itself. Here's what that takes, and how WellPay does it:
- Ownership, verified at the source. Account ownership is confirmed through Instant Bank Verification, an open banking process that checks the account directly with the charity's own bank.
- Kept current. Ownership is re-verified whenever a charity's banking details change, and CRA standing is synced monthly, so the data can't quietly go stale between one grant and the next.
- Location-aware. The system can flag where banking information is entered, so an update arriving from outside the charity's expected area is caught rather than trusted.
- Held to banking standards. Data is encrypted at rest and in transit, with Canadian data residency.
- Synced with the CRA. Registration status is re-checked against CRA records monthly, so a charity that has lost its standing is caught before funds move. No void cheque, call, or upload link ever checked this at all.
- Shared across the network. Verified banking data moves securely from one DAF to the next, so the network reinforces itself and the same charity isn't re-verified from scratch by every funder.
Because no one on your team is collecting or storing banking data, no one person is left holding the access, or the blame.
Ownership, regulated, current. That's the standard, and WellPay is built to meet it.
The time you get back
Risk is the reason to move. Time is the reason you'll be glad you did.
Look again at the process at the top of this piece: chasing a void cheque, scheduling a call to read out a cheque number, keying digits into a spreadsheet, building the payment file, then chasing the rejects when a transfer fails. Every step is manual, and every step repeats for every charity, every disbursement.
Verified-once-and-shared banking data removes most of that work:
- No collecting or storing void cheques
- No confirmation calls to read account numbers aloud
- No hand-keying, and far fewer failed transfers to chase
- Payment files generated, not assembled by hand
For a team disbursing at volume, that's not a marginal saving. It's hours back every cycle, and a real reduction in cost, redirected from data entry to the work donors actually want funded.
"You want us to trust a startup with our money and our charities' data"
No. The opposite.
The most reasonable objection a risk owner can raise is that adopting a new system means handing a young company control of the foundation's funds and a database of charity banking details. If that were the architecture, the objection would be correct.
WellFunded never touches the funds, and never sees your banking credentials.
Funds move on your own bank's regulated EFT rail. Authorization and fund movement are kept separate, so the system that approves a payment is never the system that moves the money. The verified banking data is held once, encrypted, with Canadian data residency, visible to very few people, rather than scattered across your drives, inboxes, and spreadsheets. Account ownership is confirmed through the charity's own bank, so the credentials that prove it never reach WellFunded at all. WellFunded is the intelligence layer: it makes the disbursement correct, keeps the authorization record, and runs the network that lets verified data move between funders. It's never in the flow of funds.
This inverts the risk conversation. Today, a DAF that collects void cheques and stores them on its own drives is itself a holder of sensitive banking data, a custody and fraud liability sitting on its own books. Adopting verified disbursement doesn't add that risk. It removes one you're already carrying.
Why this matters now
These methods were defensible when forging a document was hard, impersonating a person was harder, and an auditor was unlikely to ask how you confirm a destination account. All three conditions have changed.
Documents are trivial to generate. Faces and voices can be faked convincingly and at scale. And boards and auditors are starting to ask the question the old methods can't answer well: how do you actually know the money went where it was meant to go?
The cost of getting this wrong isn't only the lost grant. It's the donor who entrusted the foundation with their giving, the board that has to explain what happened, and a sector reputation that is easier to damage than to rebuild. The verification gap is quiet right up until the moment it isn't.
A standard worth setting, together
A small group of Canadian donor advised funds are setting this standard now, as founding partners, rather than waiting for a fraud event to force the conversation. The network effect is the point. Verify a charity once, and every funder on the network benefits from that verification.
We're building the founding cohort deliberately and keeping it small while we get it right. If you want to see how verified disbursement would hold up against your own process, book 30 minutes and bring your current workflow. We'll walk through where the gaps are, whether or not you end up on the network.
*This is part of WellFunded's series on charitable disbursement infrastructure in Canada. Read more on how charitable dollars actually reach charities and the real cost of DIY disbursements.*
Keep reading

How Charitable Dollars Actually Reach Charities
Canada's payment infrastructure moves $411B daily. Charitable disbursements still rely on void cheques and manual batch files.

The Real Cost of DIY Charitable Disbursements
Fraud, stale data, broken trust, and absurd fees — the hidden cost of every organization building its own disbursement process.

Shared Infrastructure for Charitable Disbursements
What charitable disbursement infrastructure should look like: verified, shared, zero-fee, and built for major giving.
Ready to modernize your philanthropy?
See how WellFunded can help your organization make better funding decisions.