Practical Guidance

Three questions to ask before approving changed payment details

A request to change supplier banking details can look completely legitimate. A consistent verification process matters more than how convincing the message appears.

Changes to supplier banking details are a recurring fraud risk because the request itself can be completely legitimate. Suppliers do change banks. Companies restructure. Accounts change.

That means the existence of a change request tells you very little. The useful question is how the change is verified.

Did the request arrive through the expected process?

Most established supplier relationships already have a normal communication route. A request arriving somewhere else is not automatically fraudulent. It does mean the change deserves independent verification.

Be especially careful when the message also provides a convincing explanation for why the usual process cannot be followed.

Am I verifying using information that came with the request?

This is an easy mistake. A request changes the account details and then helpfully provides a phone number to confirm them.

That is not independent verification. The request supplied both the claim and the method used to prove the claim.

Use contact information that existed before the request arrived.

Would the process still make sense if the message turned out to be fake?

Imagine reviewing the decision after money has already been sent. Would the steps taken still look reasonable? Was the supplier contacted independently? Was the normal approval process followed? Was an exception documented?

If the justification is mainly “It looked genuine”, the decision relied on appearance rather than verification.

Good process makes convincing fraud less important

The goal is not to become perfect at recognising fake messages. A sufficiently good impersonation may look completely normal.

A consistent verification process reduces the importance of how convincing the message is. That is why payment fraud is as much a process problem as an awareness problem.

Explore Security Awareness Training

Filed under payments, verification, supplier fraud

Written by

Teofilus Shaduka

Founder, Principia Works.

Teofilus works across open-source intelligence, cybersecurity awareness and digital exposure research.

About Principia Works

Start with the problem, not the service.

You do not need to know exactly what you need before contacting us.

Tell us what happened, what concerns you or what you are trying to understand.

We will tell you whether Principia Works is the right fit and what the next step would involve.