Blog

Vendor Bank-Detail Changes: A Verification Checklist

A practical workflow for verifying vendor bank-detail changes, protecting trusted contacts, documenting approval, and escalating suspected payment fraud.

When a vendor asks you to change its bank details, pause the change and verify it through a contact route established independently of the request. Have an authorized person confirm the exact change, record the verification, and require a separate approval before the new instructions can be used. A familiar email thread is not enough.

For business owners, IT directors, and MSPs supporting accounts-payable teams, the goal is to make this decision repeatable. Email security can reduce exposure to fraudulent messages; a controlled verification process determines whether a requested payment destination is authorized.

Why a convincing email is insufficient evidence

Business email compromise can involve an actual business mailbox taken over by an attacker, as the FBI/IC3 explains in its BEC advisory. Recognizable names, prior correspondence, and a realistic business reason therefore cannot establish that a bank-detail change is genuine.

A recent case illustrates the problem. In an August 28, 2026 sentencing announcement, the Justice Department described spoofed domains and compromised email accounts used to send false confirmations of fraudulent requests. The underlying conduct occurred between June and August 2020. Our practical takeaway is to establish verification outside the message chain that requested the change.

Build a verification workflow with a clear stopping point

The workflow below is a recommended operating design for finance and IT teams to adapt together. It turns the FBI/IC3 recommendation to verify account changes through a secondary channel into defined actions and evidence.

  1. Place the change on hold. Record the request without updating the approved vendor record or releasing a payment using the new details. Give staff an explicit route to pause the process when verification is incomplete, including when a deadline or senior executive creates pressure.
  2. Retrieve an independently established contact. Use the vendor contact recorded during a previously verified onboarding process or an existing trusted relationship. Do not use a phone number, portal link, or replacement contact supplied only in the change request. The FBI/IC3 advises using previously known phone numbers when verifying a transfer request.
  3. Initiate the confirmation yourself. Reach the authorized vendor contact through that established route and confirm whether the change was requested, what details are changing, and when it should take effect. An incoming call or a reply in the same email thread does not establish an independent route. If the contact cannot be reached, keep the change pending.
  4. Record the evidence and obtain a second approval. Capture who verified the request, whom they reached, the source of the contact details, the time, the result, and the reference to the proposed change. A separate authorized reviewer should inspect that evidence and the exact destination change before approving it.
  5. Apply and check the approved change. Restrict vendor-record editing to designated roles. After an approved edit, have the reviewer check that the saved details match the independently confirmed instructions. Preserve the audit trail and the normal payment-approval process.

The stopping rule should be simple: an unresolved discrepancy, an unverified contact, or missing approval keeps the change on hold. Define who can resolve each condition so employees are not left improvising under pressure.

Protect the contact record as well as the payment record

A callback process depends on the trustworthiness of the contact it uses. If the same unverified message can replace both a vendor's phone number and its bank account, calling the newly entered number adds little assurance.

Treat changes to authorized contacts as controlled changes too. Keep a record of how the original contact was established, limit who can edit it, and review contact changes that arrive alongside new payment instructions. For a new vendor or an unavailable former contact, use a documented onboarding or revalidation process before accepting the request.

Do not substitute voice familiarity for that process. The FBI/IC3's February 16, 2022 advisory describes BEC schemes using virtual meetings and fabricated audio. This supports a practical distinction: initiate contact through an established route and complete the approval checks, even when a voice or meeting invitation seems familiar.

Give each team a specific responsibility

Suggested responsibilities for vendor bank-detail changes
OwnerDecision or actionEvidence to retain
Accounts payableHold the request and verify it with the authorized vendor contact.Request reference, trusted contact source, confirmation time, and outcome.
Finance approverReview the independent verification and approve or reject the exact change.Reviewer identity, decision, and reference to the approved record.
IT or the MSPSupport access restrictions, reporting channels, and the audit records available in the systems it manages.Agreed system scope, responsible administrator, and logging or access gaps.
Security responderInvestigate suspected impersonation or account compromise and coordinate containment.Original message, relevant timestamps, case reference, and documented response actions.

Keep full banking details in the approved restricted system. Routine tickets should reference that record or use masked details where practical. The audit trail needs to show what was approved without scattering sensitive information across inboxes and support queues.

For MSPs, settle the boundary with the customer: who approves financial changes, who manages the relevant application, who receives suspicious-message reports, and what support is available outside business hours. Technical support access should not silently become authority to approve a payment destination.

Test the process with realistic exceptions

Run a short, authorized tabletop using fictitious details and no real transaction. Present these situations to the people who actually handle vendor records:

  • A known vendor requests an urgent change in an existing email conversation.
  • The request supplies a new phone number and says the usual contact has left.
  • An executive asks staff to skip verification because a deadline is approaching.
  • The normal verifier is absent and the backup approver cannot find the contact record.

Ask participants to show where they would place the hold, find the trusted contact, document confirmation, and obtain approval. Use missing records or unclear authority to improve the workflow. The useful result is a process people can execute during an ordinary busy workday.

If a fraudulent payment may already have been sent

Contact the originating financial institution immediately through a trusted route and ask about a recall and its required documentation. File a complaint with FBI IC3 promptly. FBI/IC3 guidance emphasizes rapid contact with the bank; recovery is not guaranteed.

In parallel, alert the finance lead and security responder, stop further use of the disputed instructions, and preserve the original messages and transaction records. Have the security team assess possible account compromise. A bank-detail correction alone does not resolve unauthorized mailbox access.

Connect email protection to the approval process

Network Box USA's Managed Cloud Email Security includes filtering for phishing, malicious content, spoofing, and impersonation risks. Its Security Awareness Training addresses social engineering, reporting, and payment-change fraud. Finance still owns verification of the vendor's instructions and approval of the change.

Bring your current vendor-change procedure to a Network Box USA email-security review to discuss how filtering, employee reporting, and awareness training can support that workflow.