Vendor Bank Detail Change Verification Checklist Template

The email comes from your supplier’s real mailbox, quotes a real invoice and asks you to pay a new account. That is what mandate fraud looks like, and one unchecked change can send a whole payment run to a criminal.

Changing a supplier’s bank details is the single most valuable edit anyone can make to your vendor master, and it is usually made by one person working from one email. This free checklist gives AP leads, controllers and finance managers a control that runs every time a supplier asks to be paid somewhere new. It logs the request whatever the channel, holds payments, verifies the change by calling a contact you already know on a number you already hold, checks the account name where the payment system allows it, and puts a second person and an approval between the request and the vendor master. The first payment to the new account is then held and confirmed. A payee name check phase appears only for UK and eurozone accounts, and an enhanced checks phase only when the request shows a red flag.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Why a Bank Detail Change Needs Its Own Control

Business email compromise, called mandate fraud or invoice redirection fraud in the UK, rarely involves a fake supplier. The criminal either takes over a genuine supplier mailbox or registers a lookalike domain, waits for a real invoice, then asks for the money to go to an account they control. Your team pays a real invoice to a real supplier name. Only the account number is wrong, and the supplier finds out when it chases you for payment weeks later.

The losses are large. The FBI’s IC3 2025 Internet Crime Report recorded almost $3.05 billion of business email compromise losses reported by US victims in 2025, the second-largest category after investment fraud. In the UK, UK Finance’s Annual Fraud Report 2026 put invoice and mandate scam losses at £41.3 million in 2025, £28 million of it on business and other non-personal accounts. Both figures count only what victims reported.

Onboarding checks do not cover this, because the supplier was verified when it was set up. The risk arrives later, as a change to a record everyone already trusts. That is why this checklist sits between your onboarding process and your payment run.

Once, at set-up

Vendor onboarding

Every change request

This checklist

  • Request logged and payments held
  • Independent call-back to a known contact
  • Second-person review and approval
  • First payment held and confirmed
Every payment run

Accounts payable

What the Bank Detail Change Checklist Covers

Six phases run from the moment a request arrives to the supplier confirming it received the first payment. Phase 3 appears only for UK and eurozone accounts, and Phase 4 only when the request shows a red flag.

Intake

Phase 1: Log the Request & Hold Payments

Owned by whoever receives the request. Nothing in the request itself is trusted from this point on.

  • Log the request whatever the channel — email, letter, phone call, supplier portal or a note on an invoice all start this checklist
  • Attach the original request with full email headers — the sender address, reply-to address and domain are evidence
  • Flag the vendor so no payment run includes it — until Phase 5 is approved, nothing is paid to the old or new details without the controller’s sign-off
  • Do not reply, call or click anything in the request — every contact detail in it belongs to whoever sent it
  • Name the handler, verifier and master-data editor — three different people, none of whom can approve their own step
  • Answer the scope questions — where the new account is held, and whether the request shows any red flag from the policy list
Call-Back

Phase 2: Verify Independently

Owned by the verifier, who did not receive the request.

  • Find the supplier’s phone number from an independent source — the vendor record as it stood before the request, the signed contract or the supplier’s website typed in by hand, never the request or the invoice attached to it
  • Call a contact you have dealt with before and confirm the change — ask them to read the new account details to you rather than reading them out yourself
  • Ask why the account changed and from which date — a genuine supplier can name the reason, such as a new bank or a change of entity
  • Confirm the account holder name matches the supplier’s legal entity — a personal name or a different company is a red flag
  • Record who you spoke to, the number dialled and the time — a call note is the evidence the control ran
  • Attach supporting documents, such as a bank letter — useful, but never a substitute for the call, because documents are easy to forge
UK & Eurozone

Phase 3: Payee Name Check

Shown only when the new account is held in the UK or the eurozone, where a name check is available.

  • Run a Confirmation of Payee check through your bank — by setting up the payee in online banking, or through a bulk name-check service if your bank offers one
  • For a euro account, record the Verification of Payee result — eurozone payment providers have had to offer it since 9 October 2025
  • Record the result: match, close match, no match or check not possible — attach a screenshot
  • Close match: confirm the exact account name with the known contact — using the number from Phase 2
  • No match: stop and escalate to the controller — and complete Phase 4 whatever the scope answer
If Red Flags

Phase 4: Enhanced Checks

Shown only when the request shows a red flag. Owned by the controller or finance manager.

  • Call a second known contact at the supplier — such as its finance director, on an independently sourced number
  • Compare the request’s email domain with the domain on file — swapped characters, added hyphens or a different ending
  • Ask IT to review the email and your own mailboxes — forwarding rules or unusual sign-ins mean the compromise may be on your side
  • Warn the supplier through the verified contact if its mailbox looks compromised — so it can alert its other customers
  • Reject the change if fraud is suspected and report it — to your bank, and to the FBI’s IC3 in the US or Report Fraud in the UK
Approval

Phase 5: Approve & Update the Vendor Master

  • Second-person review of the evidence — by someone who neither received the request nor will edit the record
  • Controller approval of the change — required before anyone edits the vendor master
  • Update the bank details exactly as verified — the master-data editor enters the approval reference in the change note
  • Compare the saved record with the call note — character by character, by someone other than the editor
  • Send a confirmation to the supplier’s known contact on file — so a genuine supplier that never asked for the change can object before money moves
First Payment

Phase 6: Hold, Pay & Confirm

  • Hold the first payment until your cooling-off period ends — the number of working days your policy sets
  • Remove the payment-run flag and release the first payment — released by someone other than the master-data editor
  • Ask the known contact to confirm receipt — within the days your policy sets, and attach the reply
  • Treat any reminder for an invoice you have paid as an alarm — it is often the first sign the money went elsewhere
  • If a payment went astray, call your bank at once and ask for a recall — then report it as in Phase 4, because speed decides whether funds can be frozen
  • Close the checklist with the evidence attached — it feeds the monthly review of vendor master changes

Red Flags in a Bank Detail Change Request

Any one of these answers Yes to the red flag question in Phase 1. A well-run fraud may show none of them, which is why the call-back in Phase 2 runs on every request.

Red flag Why it matters What the checklist does
Urgency or secrecyPressure to pay today, or not to call, is designed to stop the checkNo change is made before Phase 5, however urgent
New account in a different countryA UK or US supplier suddenly banking abroad is a classic redirection patternPhase 4 and a second contact
Account name is a person or another companyFunds are usually sent to a mule account and moved on quicklyName confirmed on the call and, where available, by a name check
Lookalike or changed email domainA domain one character off is cheap to register and hard to spotDomain compared with the one on file
Change just before a large paymentCriminals time requests to the invoices they have seen in a compromised mailboxPayment hold from Phase 1 until confirmation
New contact or changed signature detailsThe person you know may not be the person writingCall-back only to a contact you have dealt with before

In the UK, most companies carry the loss themselves. The Payment Systems Regulator’s reimbursement requirement, in force since 7 October 2024, makes payment firms reimburse authorised push payment scams over Faster Payments up to £85,000 per claim, and the Bank of England applies the same limit to CHAPS. It protects consumers, micro-enterprises (fewer than 10 staff and turnover or balance sheet total of no more than €2 million) and charities with annual income under £1 million. Claims must be made within 13 months, and international payments are excluded. A PSR-commissioned evaluation published in July 2026 found in-scope losses had fallen, and the government has announced that the PSR’s functions will move to the FCA. Confirmation of Payee helps, but a match only confirms the name on the account, not that your supplier asked for the change.

In the US, there is no reimbursement scheme for business wire fraud. A BEC payment is usually one your own staff authorised, so the protections in UCC Article 4A for unauthorised payment orders rarely help, and section 4A-207 lets the beneficiary’s bank rely on the account number unless it actually knows the name and number belong to different people. The Fourth Circuit applied that rule against a BEC victim in Studco v. 1st Advantage in 2025. Since Nacha’s Phase 2 fraud monitoring rules took effect in June 2026, every non-consumer ACH originator needs risk-based processes to identify payments induced by false pretenses, which include vendor impersonation, and must review them at least annually. A documented checklist like this one can form part of that process. Report a misdirected payment to your bank and to IC3 straight away: the FBI’s Recovery Asset Team works with banks to freeze funds, and the chance of recovery falls quickly.

Why Run Bank Detail Changes in CheckFlow?

1

The approval cannot be skipped

The controller’s approval task halts the checklist until it is answered Approved or Not approved, so the vendor master edit and the first payment cannot be ticked off before the change is signed off.

2

Segregation you can see

The handler, verifier, editor and approver are separate Members fields, and every task is assigned from them. A vendor data set gives a live dropdown of suppliers, so each request is tied to the right record.

3

Evidence for every change

The original email, the call note, the name check screenshot and the supplier’s confirmation sit on the tasks that produced them. The timestamped activity trail exports for auditors, and analytics show requests stuck in verification.

This control protects details captured at set-up. Our vendor onboarding guide and vendor onboarding software cover the first capture, the Accounts Payable Process Checklist runs the payment cycle that follows, and the Segregation of Duties Review Checklist tests that the people in this checklist really are separate.

CheckFlow is not a payments system, a bank or an account validation service, and it does not check account names. It runs the workflow around your bank’s name check and your accounting system: who received the request, who called whom, who approved and when. For the monthly review, a recurring checklist compares your accounting system’s change log with the completed checklists, and any change without one is investigated.

Frequently Asked Questions

How do you verify a change to a supplier’s bank details?

+

Call a contact you have dealt with before, on a phone number you already held before the request arrived, and ask them to confirm the new details. Never use contact details from the request. Then have a second person review the evidence, get approval before editing the vendor record, and confirm receipt of the first payment with the same known contact.

What is mandate fraud?

+

Mandate fraud, also called invoice redirection fraud, is when a criminal poses as a supplier and persuades you to change the bank account you pay it into. It is a form of business email compromise aimed at accounts payable teams. The supplier and invoices are real; only the account belongs to the fraudster.

Is a letter on the supplier’s headed paper enough to change bank details?

+

No. Letterheads, bank letters and signed forms are easy to forge, and an email from the supplier’s real address proves nothing if its mailbox has been taken over. Treat documents as supporting evidence, and make the independent call-back the control. A small test payment does not help either: it proves the account works, not who owns it.

Will our bank refund us if we pay a fraudster?

+

Usually not, for most companies. In the UK, mandatory reimbursement for authorised push payment scams covers consumers, micro-enterprises and small charities, up to £85,000 per claim; larger businesses depend on what can be recovered from the receiving account. In the US there is no equivalent scheme, and the law generally leaves the loss with the business that authorised the payment. Check whether your crime or cyber insurance covers social engineering fraud.

What should we do if we have already paid the wrong account?

+

Call your bank’s fraud line immediately and ask it to recall the payment and contact the receiving bank. Then report it: to IC3 at ic3.gov in the US, or to Report Fraud, which replaced Action Fraud in December 2025, in the UK. Preserve the emails and headers, check your own mailboxes for compromise, and tell the genuine supplier through its known contact.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Verify Every Bank Detail Change Before a Single Payment Moves

Free trial — no credit card required.