Supplier Bank Account Change Scams: Verification Controls for Finance Teams
Supplier bank account change scams can expose businesses to significant financial losses, even when their finance teams follow established payment procedures. A fraudulent email may appear to come from a trusted supplier and request an update to existing banking details. If employees accept the request without independent verification, the next payment could go to a criminal instead of the intended recipient.
The FBI identifies fraudulent vendor payment instructions as one example of business email compromise (BEC). These scams can involve spoofed email addresses, compromised accounts and convincing messages that imitate legitimate business communications.
For this reason, supplier bank account change scams deserve specific attention from finance teams, accounts payable departments and business owners. This guide explains how these scams work, which warning signs employees should recognise and how companies can strengthen supplier verification and payment controls.
What Are Supplier Bank Account Change Scams?
Supplier bank account change scams occur when criminals attempt to redirect legitimate business payments by providing fraudulent banking information.
In many cases, the criminal impersonates an existing supplier and asks the customer to update the bank account recorded in its accounting system. The request may arrive by email, telephone or another communication channel.
For example, a company may receive an email stating that its supplier has changed banks. The message includes a new account number and asks the accounts payable team to use the updated details for all future invoices.
Because the supplier relationship already exists, the request may appear routine. However, the email could originate from a fraudulent address or a compromised mailbox.
The risk is not limited to unfamiliar suppliers. Criminals may exploit genuine business correspondence to make their messages appear more convincing.
According to the FBI’s guidance on business email compromise, criminals may impersonate vendors and manipulate payment instructions to divert funds.
Consequently, companies should treat every request to change supplier banking information as a separate verification event.
How Do Supplier Bank Account Change Scams Work?
Understanding the typical fraud process helps finance teams recognise suspicious requests before money leaves the business.
1. Criminals Identify a Supplier Relationship
Fraudsters may learn about a company’s suppliers, invoices, payment schedules and business contacts through publicly available information, social engineering or compromised email accounts.
With these details, they can create a message that fits an existing commercial relationship.
2. They Send a Convincing Change Request
The criminal sends a message claiming that the supplier has updated its banking arrangements.
The email may include a professional signature, a familiar invoice reference and language consistent with previous communications.
In some cases, the criminal may gain access to an actual email account and insert fraudulent instructions into a legitimate conversation.
3. Employees Update the Supplier Record
An accounts payable employee receives the request and changes the bank details in the accounting or payment system.
If the company does not require independent verification, the employee may rely entirely on the email and supporting documents.
4. The Company Releases the Payment
The next invoice payment goes to the fraudulent account instead of the genuine supplier.
The company may discover the problem only when the supplier reports an overdue invoice or the finance team investigates a payment discrepancy.
At this stage, recovering the money may be difficult. Therefore, preventing unauthorised changes before payment is released is essential.
Seven Warning Signs Finance Teams Should Recognise
A bank account change request does not automatically indicate fraud. Nevertheless, certain characteristics deserve additional scrutiny.
1. Unexpected Banking Changes
A supplier suddenly requests new bank details without a clear explanation or supporting verification.
Finance employees should follow the company’s verification procedure even when the request appears reasonable.
2. Urgent Payment Instructions
The sender insists that the details must be changed immediately to avoid delayed deliveries, penalties or disruption to business operations.
Pressure to act quickly can discourage employees from performing essential checks.
3. Slightly Different Email Addresses
A fraudulent sender may use a domain that resembles the supplier’s legitimate domain.
For example, a criminal might replace one character, add a word or use a different domain extension.
Employees should inspect the complete sender address rather than relying on the display name alone.
4. New Contact Details in the Same Request
A message requesting new bank details may also provide a new telephone number or contact person.
Using those newly supplied details to verify the request is risky because the same criminal may control both communication channels.
5. Inconsistent Beneficiary Information
The proposed bank account name does not match the supplier’s legal name or the beneficiary details already held by the company.
There may be legitimate explanations for differences, but finance staff should investigate them before approving the change.
6. Unusual Requests for Confidentiality
The sender asks the employee to keep the change private, bypass normal approval procedures or avoid contacting the usual supplier representative.
These instructions should trigger additional review.
7. Changes Made Outside Normal Procedures
A supplier record is changed without the required supporting evidence, authorisation or audit trail.
Even if the banking information is legitimate, bypassing established procedures weakens financial accountability and makes fraudulent changes harder to detect.
How to Prevent Supplier Bank Account Change Scams
The most effective response combines independent verification, controlled access to supplier records and clear payment authorisation procedures.
1. Verify Changes Through an Independent Channel
Never rely solely on the email requesting the change.
Instead, contact the supplier using a telephone number or contact method already held in your approved supplier records. Do not use the telephone number or verification link supplied in the suspicious message.
Ask an authorised supplier representative to confirm the requested change and document the outcome.
The FBI’s business email compromise guidance recommends independently verifying changes to account information and payment procedures.
For higher-risk changes, consider requiring a second independent verification step.
2. Separate Supplier Record Changes From Payment Approval
The employee who updates supplier banking information should not automatically have unrestricted authority to approve and release payments.
Where practical, assign different responsibilities to different employees:
- One employee receives and documents the change request.
- Another employee verifies the request independently.
- An authorised reviewer approves the supplier record update.
- A separate payment approver authorises the transaction.
This segregation of duties reduces the risk that one person can introduce and execute an unauthorised change without detection.
Smaller businesses with limited staff can introduce compensating controls, such as independent owner review and documented secondary approval.
3. Establish a Formal Supplier Verification Policy
A written policy should explain how employees handle requests to change supplier banking details.
At a minimum, it should specify:
- Which documents or records are required.
- Who may verify a banking change.
- Which independent contact methods are acceptable.
- Who approves the supplier master data update.
- How verification evidence must be retained.
- How urgent or unusual requests are escalated.
Additionally, the policy should apply consistently across email, telephone and other communication channels.
A documented procedure helps employees make consistent decisions instead of relying on informal judgement.
4. Restrict Access to Supplier Master Data
Supplier master data includes information such as legal names, addresses, contact details, payment terms and bank account information.
Businesses should limit access to employees who genuinely need to maintain these records.
Where the accounting system supports it, configure role-based permissions, approval workflows and alerts for changes to sensitive supplier information.
The system should also maintain an audit trail showing who requested, changed and approved the banking information.
Regular access reviews can help identify unnecessary permissions and reduce the opportunity for unauthorised changes.
5. Introduce Additional Controls for High-Risk Payments
Not every payment requires the same level of review. However, businesses should apply additional checks when a request involves a new beneficiary, an unexpected bank account change or an unusually large payment.
Depending on the company’s risk assessment, additional measures may include:
- Secondary approval by a finance manager.
- Independent confirmation of beneficiary information.
- A review of recent supplier master data changes before payment runs.
- Additional checks for first payments to updated bank accounts.
- A temporary hold while discrepancies are investigated.
These controls should fit the organisation’s payment volume, staffing structure and financial risk exposure.
6. Monitor Changes and Review Exceptions
Preventive controls should be supported by regular monitoring.
Finance teams can review reports showing recent supplier banking changes, unusual payment destinations, repeated failed verification attempts and payments made shortly after a master data update.
They should also investigate duplicate supplier records and unexplained changes in beneficiary information.
Furthermore, management should review recurring exceptions to determine whether employees need additional training or the approval process requires improvement.
7. Train Employees to Recognise Social Engineering
Employees responsible for supplier communication and payment processing should understand how impersonation attempts work.
Training should include examples of suspicious email addresses, urgent payment requests, unexpected changes to banking details and attempts to bypass normal procedures.
Employees should also know how to report suspicious messages without fear of being blamed for raising a concern.
For additional guidance, businesses can consult the FBI’s business email compromise resources and the Internet Crime Complaint Center’s BEC guidance.
A Practical Supplier Bank Account Verification Workflow
A consistent workflow helps businesses prevent unauthorised changes while maintaining efficient supplier relationships.
Step 1: Record the Request
Log the date, supplier name, requested change, sender details and supporting documents. Do not update the approved supplier record at this stage.
Step 2: Check the Existing Supplier Record
Compare the request with the company’s approved contact information, legal entity details and previous banking records.
Identify inconsistencies that require clarification.
Step 3: Verify Independently
Contact an authorised supplier representative using previously verified contact details.
Confirm the new bank information and record the verification method, date and person contacted.
Step 4: Obtain Internal Approval
Send the verified request to an authorised reviewer who is separate from the employee making the change, where practical.
The reviewer should confirm that the required checks have been completed.
Step 5: Update and Document the Record
Only after approval should the authorised employee update the supplier master data.
Retain the supporting documents, verification evidence and approval history in accordance with the company’s recordkeeping policy.
Step 6: Apply Payment Controls
Before releasing the next payment, check whether the transaction requires additional review under the company’s payment policy.
Any mismatch or unexplained change should be investigated before payment proceeds.
What Should a Business Do If It Discovers a Fraudulent Payment?
Even a well-designed control framework cannot eliminate every risk. Businesses should therefore prepare a clear incident response procedure.
If a payment has already been sent to a fraudulent account, the finance team should:
- Contact the sending bank or payment provider immediately and request assistance with recalling or stopping the transfer.
- Notify the company’s finance leadership and relevant internal security or compliance personnel.
- Preserve the suspicious emails, payment records, supplier communications and other relevant evidence.
- Contact the genuine supplier through previously verified contact details.
- Report the incident to the appropriate law enforcement or cybercrime reporting authority.
- Review how the fraudulent request passed through the company’s controls and implement corrective measures.
The FBI’s official guidance on business email compromise recommends contacting the financial institution promptly when a fraudulent transfer is discovered. In the United States, affected businesses can also consult the IC3 reporting guidance.
Businesses operating in other countries should contact their relevant financial institutions and local authorities. Recovery is not guaranteed, so rapid escalation is important.
How Supplier Verification Supports Stronger Financial Controls
Supplier bank account verification is one part of a broader financial control framework. It works best when connected to accounts payable procedures, supplier onboarding, payment approvals and accounting recordkeeping.
For example, a company may have a strong invoice approval process but still face fraud if employees can change supplier bank details without independent review.
Similarly, maintaining accurate accounting records is not enough if the business cannot establish who authorised a payment or why supplier information changed.
Companies should therefore review the entire process, from supplier onboarding and master data maintenance to invoice approval, payment execution and reconciliation.
For businesses operating across several entities or countries, documented responsibilities and consistent verification principles can improve accountability. Local banking arrangements and applicable legal requirements should still be considered when designing the process.
How uSafe Can Support Your Finance Operations
Effective supplier payment controls require reliable accounting records, clear documentation and consistent financial procedures.
uSafe provides accounting, tax, payroll and corporate secretarial services to support businesses with their financial and administrative requirements.
Depending on your business needs, professional support may help improve record organisation, strengthen accounting workflows and identify opportunities to make financial procedures more consistent.
Explore our services:
- Accounting Services — support for accounting records and financial processes.
- Tax Services — assistance with tax-related business requirements.
- Payroll Services — support for payroll administration and related processes.
- Corporate Secretarial Services — support with corporate administration and statutory obligations.
If your business wants to improve supplier verification or review its accounts payable procedures, contact uSafe to discuss your accounting and business support requirements.
Frequently Asked Questions
What is a supplier bank account change scam?
It is a form of payment fraud in which a criminal attempts to redirect a legitimate business payment by submitting false or unauthorised supplier banking information.
How can a company verify a supplier bank account change?
Contact an authorised supplier representative through a previously verified communication channel. Confirm the requested details independently, document the verification and obtain internal approval before updating the supplier record.
Is email confirmation enough to approve new supplier bank details?
Email alone is generally insufficient for a sensitive banking change. Businesses should use an independent verification channel and follow their documented approval policy.
Who should approve supplier bank account changes?
Ideally, the employee requesting or entering the change should not be the sole person verifying and approving it. A separate authorised reviewer provides an additional layer of control.
What should a company do after sending money to a fraudulent account?
Contact the sending bank or payment provider immediately, request assistance with recovering the funds, notify internal management, preserve evidence and report the incident to the relevant authorities.
Can accounting software prevent supplier payment fraud?
Accounting software can support access restrictions, approval workflows, change logs and exception reports. However, the effectiveness of these features depends on proper configuration, independent verification and consistent employee compliance.
Conclusion
Supplier bank account change scams exploit trust, familiar business relationships and gaps in payment procedures. A convincing message can lead to a significant loss when employees update supplier records without verifying the request independently.
Businesses can reduce this risk by establishing formal verification procedures, separating supplier record maintenance from payment approval, restricting access to sensitive information and monitoring unusual changes.
Ultimately, effective financial controls combine appropriate technology with documented responsibilities and human oversight.
Need help reviewing your accounting and financial procedures? Contact uSafe to discuss accounting and business support services tailored to your company’s needs.




