01Open a controlled change request
Assign request ID, supplier entity, vendor record, requester, channel, received time, proposed effective date, currency and affected open invoices. Capture the existing approved beneficiary before changes. Place the relevant payment on hold according to policy. Do not update master data from a bank detail printed on an invoice or embedded in a reply thread alone.
02Review message and transaction red flags
Compare sender domain and reply-to, language, timing, urgency, secrecy, account country, beneficiary name and payment pattern with prior verified activity. Check whether an executive, new contact or unexpected intermediary is involved. FinCEN notes that a changed beneficiary account, near-copy email, unusual urgency and no prior payment history can be warning signals, but no single flag proves fraud.
03Verify through an independent channel
Contact the supplier through a phone number or route already validated in master data, contract records or an independently located official source—not the change request. Speak to an authorized person and document name, role, date and method. Ask them to state key request details. If the known contact cannot verify it, keep the hold and escalate; do not use continued email replies as a substitute.
04Review beneficiary evidence
Obtain documents required by policy and compare supplier legal name, beneficiary name, account jurisdiction, currency and bank information. Resolve third-party, factoring, agent or group-company beneficiaries through written commercial and legal authority. Treat a stamped letter, bank screenshot or PDF as supporting material, not conclusive identity proof; compromised accounts can send realistic files.
05Control master-data change
Separate request, verification, data entry and approval roles where practical. Use dual approval, least access, change reason, old/new values, timestamp and attachment log. Set an effective date and prevent retroactive replacement across already settled transactions. Notify accounts payable and procurement through an internal trusted channel and lock or archive obsolete beneficiary details.
06Review the first affected payment
Reconfirm supplier, invoice, currency, amount, beneficiary and change-request approval before release. Apply test payment, payment limit, delayed activation or additional bank verification only if policy and bank capability support it. A successful small transfer does not prove supplier ownership of the account. Monitor bank response, beneficiary mismatch, return and supplier acknowledgment.
07Respond to suspected diversion
Stop pending payments and notify authorized finance, security and legal owners. If money moved, contact the sending financial institution immediately to request its fraud response or recall process, preserve messages and logs, and report through required channels. Do not warn a possibly compromised mailbox before the response plan decides the channel. Review other recent master-data changes and payments.