What it means
A vendor emails new bank details and asks that the next invoice be paid there; if the message is mistaken or fraudulent, the payment may be difficult to recover, so change control treats the bank-field update as a high-risk decision. Start with the existing vendor record, confirming the legal supplier, account owner, contract and current payment setup, and do not create a nearly identical supplier just to process a change quickly.
Preserve the request by recording the observed sender, date, proposed details and attached document without accepting its identity claims, since an invoice footer or email signature is not independent proof. Verify through a trusted route by using a contact method already held and independently established, not the new phone number in the request, and check who at the supplier is authorised to confirm banking changes.
The NSW Independent Commission Against Corruption recommends independent verification of vendor bank-account details in accounts management controls, and an ACFE case discussion shows why change requests can be exploited. Check document authenticity too, because a letter on letterhead can be forged and may support the process but should not replace independent contact and authorised approval.
Separate roles, so the person verifying should not alone enter and approve the new account if the business can reasonably divide these duties, while a small firm can use owner review and a later bank reconciliation as compensating checks. Consider dual approval, where one person verifies the supplier through a known channel and another approves the master-data change, with the exact design fitting company size and payment risk.
Compare account-holder information where available, since a mismatch between vendor legal name and beneficiary needs investigation, and the exact verification options vary by bank and country. Review related open invoices and decide whether the change applies to all future payments or a named invoice only, because a temporary payment instruction should not silently become permanent master data.
Set an effective date, since a payment already released may still use old details, and confirm which payment batch can safely use the approved new account. Avoid urgency as a substitute for proof: a supplier deadline may be real but it does not make an unverified bank change safer, so escalate timing conflicts to the proper approver and put affected payments on hold, because a valid invoice can wait for verified destination details under the company's terms and an untrusted account should never be paid to clear an overdue queue.
Control system access by restricting who can edit bank details and logging the old and new values with timestamps, noting that some systems mask digits, so retain enough verified comparison data under secure access. Check for recent parallel edits, since a vendor change combined with a new email address or unfamiliar phone number is more complex than one isolated field, and confirm each changed detail separately.
Watch for callback failure as well, because a voicemail or unanswered call is not supplier confirmation, so keep the change pending until the authorised contact is actually reached. An illustrative verification completion rate is 18 bank-change requests independently confirmed before activation out of 20 requests received, or 90%, and the other two are pending or rejected; the metric does not prove the confirmed details were ultimately correct.
Maintain an audit trail linking the request, independent confirmation, approvals, system update and first payment check, and check the first payment against the approved account in the payment file and bank confirmation, since a correctly updated master record can still be overridden in a payment batch. Train staff on impersonation, because a genuine-looking forwarded thread can be compromised, and for owners the control is about where money lands: the new bank account becomes usable only after independent identity and authority checks, proper approval and payment readback.
In practice
Real-world examples.
Example
Accounts payable at a fictional manufacturer calls an established supplier contact, taken from the original contract, to verify a bank-change letter. The contact confirms the change and names the person who authorised it. Only then does a second employee approve the update in the vendor record.
Example
A fictional wholesaler has a pending invoice that remains on hold until the new beneficiary is confirmed. The supplier complains about the delay, but the buyer explains that payment terms allow time for verification. The invoice is paid on the verified account within the agreed terms.
Example
A reviewer at a fictional retailer checks the first payment file against the approved account after a change. The payment batch had picked up an old account from a saved template. The reviewer stops the batch and corrects the template before any money is sent.
Formula
Calculation
Illustrative pre-activation verification rate = independently confirmed changes / bank-change requests x 100. Eighteen of 20 = 18 / 20 x 100 = 90%; pending requests are not approved.
Worked follow-up: of the two requests not confirmed, one is rejected after the supplier denies sending it and one is pending a callback. Neither is activated, so the payment file still uses the old, verified accounts for both suppliers until the check is complete.Case study
Seen in the real world.
This entirely fictional example follows Elm Fabrication. A message with a supplier logo requested a new payment account for an urgent invoice. The address was unfamiliar, so accounts payable used its existing contact record rather than the number on the message.
The established supplier contact did not recognise the request. Elm kept the payment on hold and documented the discrepancy. The story does not identify the message sender or prove intent.
Watch out
Common mistakes.
- Trusting the phone number on the change request as independent verification.
- Letting one unreviewed person change vendor banking and release payment.
- Assuming a correct master-data update guarantees the payment file used that account.
Questions
People also ask.
Why verify through a separate route?
The request itself can contain false contact details or come from a compromised mailbox.
Should an urgent invoice bypass checks?
No. Escalate the timing, but verify the destination before payment.
What should be saved?
The request, independent confirmation, approvals, update history and first-payment check.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%