Nirmion
HelpLog in Find a tool

Business Operations · THE NO-PANIC PLAN

Verify a vendor bank-detail change before paying

A genuine vendor email thread can be compromised, and a polished invoice with a new account number is not proof that the supplier changed banks. The FBI advises verifying changed account or payment procedures with the known contact, using a number found independently rather than one supplied in the request. This workflow helps a business prevent payment diversion and respond quickly if money was sent to the wrong account. It does not replace the bank's fraud process, the organization's payment policy or law-enforcement instructions.

MISSION Give a U.S. business accounts-payable team a documented control for pausing, independently verifying, approving and safely recording a supplier payment-detail change.

Independently verify every requested change before updating payee data

THE REAL-WORLD BIT

What happens outside this browser tab?

Freeze the pending payee change; compare the request with existing vendor records and look for fraud signals; independently call a previously verified contact using a known number; obtain separate approval and securely update the vendor master; validate the next payment and rapidly escalate suspected fraud.

YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES

One step at a time.

Follow the order below. If a step names a Nirmion tool, its link is right there with it.

  1. 01

    Pause the payee change and protect the payment queue

    When a supplier requests a new bank account, routing number, payment address or payment method, do not edit the vendor master or release a payment based only on email, an attachment, caller ID or a reply in the same thread. Put the change and any imminent transfer into a documented hold state, notify the designated accounts-payable approver, and preserve the original message and invoice headers according to company policy. Urgency, secrecy, a changed email domain, new phone number, altered invoice or request to bypass normal approval is a reason to slow down. Use the established vendor record and ordinary callback procedure, not contact details included in the change request. Avoid opening unexpected links or attachments while validating the request.

  2. 02

    Compare the request with the trusted vendor record

    Check the legal supplier name, vendor ID, tax and contract records, current approved remittance details, invoice number, known billing contacts and prior change history. Compare the sender's full email address and domain carefully, but treat a matching address as only one signal because a legitimate mailbox can be compromised. The FBI describes BEC scams that imitate vendors with changed payment details and recommends confirming account-number or payment-procedure changes with the requesting person. Document what changed, when it was requested, who submitted it, and whether the request followed the vendor's usual channel; do not copy sensitive bank details into broadly visible notes or share them outside the payment team.

  3. 03

    Verify with the supplier over a separately sourced channel

    Call the vendor contact using the phone number already stored in the approved vendor master or another independently verified source established before the request. Ask the supplier to confirm that it requested the change, the effective date and whether pending invoices should use old or new instructions; do not read the entire new account number aloud to an unverified caller. If the known contact cannot be reached, stop and use the organization's vendor-verification escalation path. IC3 specifically recommends secondary channels or two-factor verification for account-information changes. Record the date, number/source used, person reached, confirmation details and verifier; a callback to a phone number provided in the suspicious message is not independent verification.

  4. 04

    Require separate approval and update the payee record securely

    After independent verification, route the change to an approver who did not enter it, and apply any dual-control threshold for high-value or urgent payments. Validate that the change is consistent with the contract and supplier documentation without collecting more banking information than the organization's controlled process requires. Enter new details only in the restricted vendor-master system; retain the old value, new value, approver, verifier, timestamp and change ticket in the authorized audit trail. Notify the supplier through its known contact that the update is complete, without sending full bank details in plain email. Separate creation, approval and payment release where staffing permits, and escalate exceptions rather than waiving controls under deadline pressure.

  5. 05

    Validate the first payment and act quickly if diversion is suspected

    Before the first payment using the new details, re-check the approved vendor record and transaction against the change ticket; for a high-risk transfer, use an additional confirmation step defined by finance policy. The Vendor Payment Tracker (tool 34232) can organize the payment amount, due date and status after the change is approved, but it does not verify account ownership or transmit funds. Reconcile the payment confirmation and retain the approval evidence. If funds may have been sent to a fraudulent account, contact your financial institution immediately and ask about a recall or hold, alert internal finance/security leadership, preserve messages and logs, and report the incident to the FBI's IC3 as appropriate. Do not wait for routine month-end reconciliation to raise a suspected payment diversion.

THE HELPER CREW

Tools for the fiddly bits.

These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.

RECEIPTS, PLEASE

Sources & review notes

Each source is linked to the steps it supports. Open it to check its scope and current guidance.

Source checked 2026-10-06