Vendor management · Troubleshooting · intermediate

A contractor changed bank details. What should you verify?

Separate a legitimate invoice from a new payment destination with a callback record, approval check, and release decision.
By Aptoria editorial team · 7 min read · Updated 2026-09-06 · Last reviewed 2026-09-06
Technical content review: Codex technical editorial review. Reviewed distinct intent, original decision artifacts, fictional examples, operational boundaries, and the limited claims supported by primary sources. No human, legal, tax, building-safety, or banking approval is claimed.
This is a technical review, not independent human or professional review.
What to do now
Hold use of the new payment destination and verify the request through an independently established contact channel, not the number or link supplied in the change message. Record who confirmed the change, which instructions they confirmed, and who authorized the update. Recheck the actual payment destination before release; a valid invoice does not validate new bank instructions.

Work through the problem

From evidence to a recorded decision
01
Identify the affected payment
Preserve the request and locate queued transactions before using the new destination.
02
Verify independently
Use a separately established contact route and confirm identity, authority, and the specific change.
03
Authorize the version
Record the instruction version, verification evidence, and authorized updater or approver.
04
Compare before release
Check the actual pending payment against the approved amount and destination.
05
Reconcile or escalate
Retain the provider outcome; if a suspicious transfer occurred, contact the institution and incident owner promptly.

Key takeaways

  • An existing email thread and a matching invoice are not independent confirmation of changed payment instructions.
  • Approval to pay for work and approval to change the payment destination are different decisions.
  • A destination edit must be checked against queued payments and the final payment instruction, not just the vendor profile.

Pause the changed instruction, preserve the request

Save the change message and its attachments in the restricted vendor record. Identify the vendor, invoice, requested destination version, affected payment run, and any pending transaction. Tell the internal payment owner that destination verification is incomplete. Do not delete the message or overwrite the old instruction before the review can compare them.
A hold here is an internal control on using unverified instructions, not a conclusion about when money is contractually due. Resolve any timing or contractual question through the responsible person. Do not assume that the old destination is still usable; the legitimate contractor may really have closed or restricted that account.

Check where the confirmation channel came from

The FBI recommends independently checking a company’s phone number and verifying changes to account numbers or payment procedures. Its business-email-compromise guidance also explains that attackers can exploit legitimate correspondence. Replying to the same thread therefore does not provide an independent check.
Use an established vendor contact record whose provenance predates the request, or independently obtain an appropriate company contact. Confirm you are speaking with a person authorized to handle the vendor’s payment instructions. A familiar voice, caller ID, or a successful call by itself does not document that authority.
For context, the FBI’s 2025 IC3 Annual Report, released April 6, 2026, records US$3,046,598,558 (about US$3.05 billion) in Business Email Compromise complaint losses on page 8. This covers BEC reports across IC3’s reporting population, not landlord-specific losses or total real-world incidence. Appendix C notes that complaint data can change and duplicates can occur. The figure gives context for verifying payment changes; it does not estimate whether this request is fraudulent or how effective this checklist is.
Contact provenance decision table
Confirmation routeWhat it establishesReview decision
Number in the bank-change emailOnly that the requester supplied a numberDo not treat as independent verification
Reply in the existing email threadA response inside the same channelKeep destination verification open
Established contact record, unchanged before the requestA separately recorded route to the vendorVerify identity, authority, and exact change
New company contact obtained independentlyA separate contact leadEstablish role and authority before relying on confirmation
No reliable independent contact availableVerification remains incompleteEscalate; do not guess a destination

Keep a small instruction-change packet

The working packet should reference the restricted payment instruction rather than copying full account information into team chat or an owner report. Record a stable version or secure record ID, the contact route’s provenance, confirmation time, verifier, authorizer, and affected pending payments. Use masked identifiers only where they distinguish records adequately; masking is not proof that the destination is correct.
Ask the authorized contact to confirm that the requested change is genuine and which instruction version it concerns using your approved secure process. Do not request an online-banking password, one-time login code, or unnecessary identity documents. If your payment provider supplies destination-verification controls, record their actual scope rather than assuming they establish every fact about authority.
Separate the approvals before releasing payment
DecisionEvidence to retainWhat it does not prove
Invoice approvedScope, completion evidence, amount, invoice IDThat a new destination belongs to the vendor
Change independently confirmedContact provenance, identity/role, instruction version, timeThat the internal updater has payment authority
Destination update authorizedNamed approver and exact approved versionThat already queued payments use that version
Payment ready to releaseFinal destination and amount compared with approvalThat the provider has settled the transfer
Outcome reconciledProvider result and matching internal recordThat future changes can skip verification

Make the control workable for a small team

Where the team has separate people available, distinguish verification, authorization, and payment release in the record. Where one landlord fills several roles, say so honestly and still record the independent contact evidence and the final instruction comparison. A second checkbox completed by the same person is not independent review.
Set a clear backup contact for an absent payment owner. Urgency should change the escalation path, not turn an unverified message into authority. Keep vendor-facing communication factual: “We are confirming the changed payment instructions through our established process.” There is no need to accuse the contractor of fraud while facts remain uncertain.

Operational checklist

Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
0 of 8 marked

Edge cases

  • The contractor changed both email and phone details: verification is incomplete until an independent route is established.
  • A payment run was created before the vendor profile changed: inspect the instruction in the run itself.
  • The legitimate contractor confirms that the old account is closed but new details remain unverified: escalate the unresolved payment method rather than reverting automatically.
  • A bank change concerns a different legal vendor entity: route it for appropriate vendor-identity and authority review rather than treating it as a simple profile edit.

Questions that come up

Does a matching invoice validate the new bank account?

No. The invoice may validate the work and amount, but it does not independently validate a changed payment destination. Verify the destination through an established channel.

Can the team keep paying the old account while checking?

Do not assume the old destination remains valid. Hold or route the payment under the organization’s approved process while the responsible reviewer resolves timing and destination.

What if a payment was already released?

Preserve the instruction and payment evidence, promptly contact the relevant financial institution or provider, use the incident process, and reconcile the actual outcome. Do not promise recovery.

Sources and references

Follow each source to check the underlying claim. Access checks and professional review are different steps.
1. Primary source · Federal Bureau of Investigation
Business Email Compromise
Independently verify changes to payment instructions; familiar correspondence can be compromised. For suspected BEC, promptly contact the financial institution and report through IC3. No recovery guarantee or mandatory payment-hold period is stated here.
Source checked 2026-09-06
Automated source-access check: 2026-09-06.
2. Primary source · Federal Bureau of Investigation, Internet Crime Complaint Center
2025 IC3 Annual Report — BEC complaint losses, page 8; data notes, page 62
Page 8 reports US$3,046,598,558 in 2025 Business Email Compromise complaint losses across the IC3 reporting population. Appendix C, page 62, explains variable complaint data, possible duplicates, loss deduplication, and conversion of foreign currencies to U.S. dollars when possible. Not landlord-specific incidence or a measure of checklist efficacy.
Published 2026-04-06 · Source checked 2026-09-06
Automated source-access check: 2026-09-06.

Revision history

2026-09-06
Initial original operational workflow and fictional examples, with explicit AI-assisted technical review and narrowly scoped primary references.
Report a correction to this resource