Skip to main content
Vendor Governance

Vendor Bank Detail Changes: Controls That Prevent Payment Fraud

In brief

Never verify a bank change using contact details supplied only in the request. Use an independently established contact and callback.

Direct answer: Verify a requested bank-detail change through an independently established contact, then require separate approval before changing the payment record. A familiar sender, convincing invoice or urgent deadline is not sufficient evidence that the new account belongs to the intended supplier.

Keep the payment record separate from the request

Open a change case against the existing vendor record. Retain the request and identify the legal entity, current approved beneficiary, proposed beneficiary and intended effective date. Mark the proposed details as unverified; do not overwrite the active account while the request is still being assessed.

Check whether a payment batch or invoice is already awaiting release. Notify the responsible finance contact that a change is under review so the request cannot bypass verification through an urgent one-off payment. Follow the organisation's approved payment-control procedure when deciding what must be held.

Verify through an independent channel

Use a contact route established before the change request, rather than a telephone number or link supplied in that request. Ask the authorised supplier contact to confirm the change and its business reason. If the established contact has also changed, resolve that identity question independently before treating a callback as verification.

FBI guidance on business email compromise recommends secondary-channel verification for changes in account information. This supports the verification principle; it is not a statement of a universal UAE banking procedure. See the IC3 business email compromise guidance.

Resolve beneficiary differences before approval

Compare the proposed beneficiary with the contracting supplier's legal identity and the evidence required by company policy. A different group company, collection agent or financing arrangement needs an explanation and the appropriate finance or legal review. Do not treat a similar trading name as proof that the accounts are interchangeable.

Record what was verified, by whom and through which channel. A bank letter or cancelled cheque may be part of the evidence package, but a document received through the same compromised channel should not replace independent confirmation. Keep contradictory information visible rather than selecting the most convenient document.

Use two distinct decisions

The person entering the change should not be its sole approver. Give the checker the old and new values, verification record and unresolved exceptions. Approval should identify the exact account and effective date, not merely acknowledge that an email was received.

Apply the approved change through the controlled vendor-master process. Record the version and verify that any downstream payment system received the intended value. A successful save in an intake form does not demonstrate that the payment record was updated correctly.

Test the controls against realistic failure cases

Test a genuine change, a changed callback number, a beneficiary-name mismatch, a duplicate request and a request received while the usual approver is absent. Confirm that missing evidence cannot silently become approval and that the backup approver can retrieve the same case history.

Track changes awaiting independent verification, rejected mismatches, unauthorised overrides and corrections after activation. Review these measures beside turnaround time. A faster process is not an improvement if it removes the check that would have detected a substituted account.

Respond promptly to suspected compromise

If a suspicious change has already affected a payment, involve the organisation's finance and incident-response owners promptly and contact the relevant bank through an established channel. Preserve the request, approval and transaction records. Follow the applicable reporting process with qualified advice; this guide cannot determine recovery or reporting obligations for a particular incident.

How Vendoreye supports this workflow

Vendoreye can coordinate structured intake, tenant-controlled categories, document requirements, evidence review, assessment, remediation, approval, lifecycle status and audit history. Tenant-scoped APIs can expose governed vendor information to ERP and procurement systems. Vendoreye does not replace the customer's responsibility for legal interpretation, policy, source verification or final decisions. Continue with the related implementation resource.

Sources and editorial basis

  1. ISO 31000 risk management overview

These sources establish the official or recognised framework used in this article. Vendoreye's workflow recommendations are identified as implementation guidance rather than statements of universal law.

General information only, not legal advice. Requirements vary by entity, sector, jurisdiction and contract. Official sources and links last reviewed 13 August 2026.

References and further reading

  1. ISO 31000 risk management overview — ISO 31000 risk management overview
  2. OECD public procurement — OECD
  3. Open Contracting Data Standard — Open Contracting Partnership

These references provide background and further reading. Last recorded editorial review: 2026-08-13. Verify current requirements with the relevant authority.

Vendor GovernanceVendor OnboardingProcurement Governance