A Vendor Changes Its Bank Details, Who Should Verify and Approve the Update Before Payment?

Finance employee checking vendor bank details by phone.

A vendor sends an email saying that its bank account has changed. The next invoice is due in three days, and the message includes new routing and account numbers. Accounts payable updates the record, the invoice reaches its normal approval stage, and the money goes out.

That sequence looks routine, which is exactly why bank-detail changes deserve their own control. Criminals involved in business email compromise regularly impersonate suppliers or gain access to legitimate email accounts, then replace genuine payment instructions with accounts they control.

Online scams can take many forms, from compromised business communications to seemingly legitimate job arrangements, as this account of an internet nanny scam shows.

A safer process separates three decisions. Someone verifies that the request really came from the vendor, someone with appropriate authority approves the master-data change, and the payment team confirms that the account being paid has passed those checks.

A Bank Detail Change Is a Payment-Control Event

Changing a vendor name, mailing address or contact person may be ordinary master-data maintenance. Replacing the bank account changes where company money will be sent, so the update deserves a higher level of scrutiny.

The invoice itself may be completely genuine. A fraudster only needs to alter the destination of the payment. The FBI specifically warns businesses to verify changes in vendor payment information through a known contact rather than relying on the phone number or other details supplied in the suspicious message.

The control should therefore begin before anyone edits the vendor record. The request enters a defined workflow, receives independent verification, moves to an authorized approver and leaves a record showing who completed each step.

Companies rebuilding that process sometimes replace email chains and spreadsheets with a dedicated workflow system. Teams comparing workflow software should also review https://altaflow.com/kissflow-alternatives.

Who Should Verify the New Bank Details?

Employee confirming vendor banking information by phone.
Independent verification should use contact details already on file, not information supplied in the bank-change request.

The verification step usually belongs to accounts payable, vendor master data or another finance employee who is not relying solely on the incoming request.

The verifier should contact the vendor through information the company already trusts. That could mean calling a telephone number stored in the existing vendor record, speaking with a known account manager or using a previously established supplier portal.

The important point is where the contact information comes from. A telephone number printed on the new bank-change form proves very little if the form itself is fraudulent.

The FBI recommends independently looking up or using known contact information and directly confirming changes in account numbers or payment procedures.

What the Verifier Should Confirm

A verification call should establish more than the fact that somebody at the vendor answered the phone. Finance should confirm the legal vendor name, the requested bank change, the effective date and enough banking information to match the submitted request.

  • The vendor actually requested the change
  • The new beneficiary name is correct
  • The bank and account information match the request
  • The effective date is correct
  • The employee confirming the change has authority to discuss payment details

The verification result should then be recorded in the vendor file or workflow. A note such as “confirmed by phone” is less useful than a record showing the date, employee, vendor contact and method used.

Who Should Approve the Update?

Verification and approval serve different purposes. The verifier establishes that the request is genuine. The approver decides that the company has enough evidence to change the payment destination in its system.

For many organizations, the approver is an accounts payable manager, controller, finance manager or another employee with formal vendor-master authority. Larger businesses may set approval levels according to payment value, vendor risk or the type of change requested.

The employee entering the new account should not automatically approve the same change. Separating those actions reduces the chance that one compromised account, mistake or dishonest employee can redirect payments without another person reviewing the evidence.

The Business Owner Can Confirm the Relationship

The department that works with the supplier also has a useful role. A procurement manager, project owner or department head can confirm that the supplier relationship is active and that the request is consistent with recent communication.

That person should not replace independent financial verification. A manager may recognize the vendor name and invoice but still have no way to know if an email account has been compromised.

Two employees checking supplier details on a tablet.
A business owner can confirm that the supplier relationship is active, but financial details still need independent verification.

Who Should Release the First Payment to the New Account?

Approval of the bank change should not make the next payment invisible to the payment team. The first payment after a bank-detail update deserves an additional check because it is the point where an incorrect change becomes an actual financial loss.

The payment processor or treasury employee can confirm that the destination account matches the approved vendor record and that all required verification and approval steps are complete.

Some companies also flag the first payment after an account change for manual review. Higher-value payments may require an additional treasury or finance approval under the company’s normal authorization limits.

Controls become especially important when a bank change arrives shortly before a large payment. Urgency should increase scrutiny rather than shorten the process.

A Clear Approval Chain for Vendor Bank Changes

A practical workflow does not need ten signatures. It needs enough separation to stop one email from becoming a payment instruction.

  1. Request received. Finance records the requested bank change without updating the active payment account.
  2. Independent verification. An authorized employee contacts the vendor through information already held by the company.
  3. Change approved. A separate finance approver reviews the request and verification record.
  4. Vendor record updated. An authorized employee enters the approved banking information.
  5. First payment reviewed. The payment team checks that the account matches the approved change before releasing funds.

The exact job titles will differ between a small company and a multinational business. The important control is separation between requesting, verifying, approving and paying wherever staffing allows it.

Infographic showing vendor bank change verification and approval workflow.
Separating verification, approval, record updates and payment review reduces the risk of fraudulent bank-detail changes.

Red Flags That Should Stop the Update

Some bank changes deserve immediate escalation before anyone edits the vendor master record.

  • The vendor suddenly asks for payment to a different country
  • The beneficiary name does not match the supplier
  • The request arrives from a slightly altered email domain
  • The sender insists that the change is urgent or confidential
  • The vendor refuses telephone or other direct confirmation
  • The new bank details appear only on an invoice
  • The sender provides a new telephone number and asks finance to use only that number
  • The change appears immediately before a large or unusual payment

None of those signs proves fraud on its own. Each one gives finance a reason to stop the update and complete an independent check before money moves.

Email Approval Alone Is Not Enough

An approval email from a manager may appear to add another control, but it remains weak if the original problem is a compromised mailbox.

A fraudster with access to a vendor email account can participate in an existing conversation, copy normal writing patterns and wait for an invoice that is genuinely due. Attackers may also impersonate an internal executive or finance employee.

Independent verification breaks that chain because the company switches to a communication channel and contact source that the attacker did not provide.

Workflow history also helps. Finance should be able to see the original request, verification record, approval, date of the account change and identity of the employee who made it.

What If the Payment Has Already Been Sent?

Employee contacting the bank after a questionable vendor payment.
When a fraudulent payment is suspected, contacting the bank immediately can improve the chance of stopping or recalling the transfer.

Speed matters once a company discovers that money may have gone to a fraudulent account. The bank or payment provider should be contacted immediately so it can attempt to stop, recall or trace the transaction.

Businesses in the United States can also report business email compromise to the FBI’s Internet Crime Complaint Center. Internal security, finance and legal teams should preserve the relevant emails, payment records, account information and system logs rather than deleting suspicious messages.

The incident should also trigger a review of other pending payments. An attacker who successfully changes one vendor account may have access to additional email conversations or finance information.

The Bottom Line

A new vendor bank account should never move directly from an email into the payment system. One employee should verify the request through an existing trusted contact, an authorized finance employee should approve the change, and the payment team should confirm that the first transfer matches the approved record.

The process adds a few minutes or, for larger organizations, an extra approval step. That small delay is far easier to deal with than discovering that a legitimate invoice was paid to somebody else’s bank account.