MINJIBuyer resourcesAsk on WhatsApp

Beneficiary change verification

Supplier bank account change verification checklist

A convincing email thread can still carry fraudulent payment instructions. Supplier bank changes need independent identity verification, controlled master data and payment review before money moves.

Direct answer

The short version

Verify a supplier bank account change by pausing payment and opening a numbered change request instead of editing the beneficiary from an email or invoice. Record the supplier legal entity, current approved bank record, proposed beneficiary name, country, currency, effective date, requester, channel and affected invoices. Examine sender domain, reply-to, wording, urgency, changed communication pattern and unexpected geography, but do not treat a familiar-looking thread as proof. The FBI specifically advises verifying account or payment-procedure changes with the person making the request and calling through a number found independently, not the number in the message. Use a previously validated supplier contact or independently sourced official route for callback, and ask the authorized contact to confirm the request and key details. Do not send the entire proposed account first and invite a yes answer. Require appropriate supplier documentation and check beneficiary name, bank and currency consistency without promising that document appearance proves legitimacy. Separate requester, verifier, master-data editor and payment approver where practical; use dual approval and an audit trail. Notify relevant users of the effective date, block old or unverified details and revalidate open invoices. Apply risk-based first-payment review or test only under finance and banking policy. Monitor returned payment, beneficiary mismatch or urgent follow-up. If fraud is suspected after transfer, contact the financial institution immediately and follow authorized incident and reporting procedures.

Use this before requesting a quotation

Prevent an authentic-looking request from redirecting supplier payments

01

Open a controlled change request

Assign request ID, supplier entity, vendor record, requester, channel, received time, proposed effective date, currency and affected open invoices. Capture the existing approved beneficiary before changes. Place the relevant payment on hold according to policy. Do not update master data from a bank detail printed on an invoice or embedded in a reply thread alone.

02

Review message and transaction red flags

Compare sender domain and reply-to, language, timing, urgency, secrecy, account country, beneficiary name and payment pattern with prior verified activity. Check whether an executive, new contact or unexpected intermediary is involved. FinCEN notes that a changed beneficiary account, near-copy email, unusual urgency and no prior payment history can be warning signals, but no single flag proves fraud.

03

Verify through an independent channel

Contact the supplier through a phone number or route already validated in master data, contract records or an independently located official source—not the change request. Speak to an authorized person and document name, role, date and method. Ask them to state key request details. If the known contact cannot verify it, keep the hold and escalate; do not use continued email replies as a substitute.

04

Review beneficiary evidence

Obtain documents required by policy and compare supplier legal name, beneficiary name, account jurisdiction, currency and bank information. Resolve third-party, factoring, agent or group-company beneficiaries through written commercial and legal authority. Treat a stamped letter, bank screenshot or PDF as supporting material, not conclusive identity proof; compromised accounts can send realistic files.

05

Control master-data change

Separate request, verification, data entry and approval roles where practical. Use dual approval, least access, change reason, old/new values, timestamp and attachment log. Set an effective date and prevent retroactive replacement across already settled transactions. Notify accounts payable and procurement through an internal trusted channel and lock or archive obsolete beneficiary details.

06

Review the first affected payment

Reconfirm supplier, invoice, currency, amount, beneficiary and change-request approval before release. Apply test payment, payment limit, delayed activation or additional bank verification only if policy and bank capability support it. A successful small transfer does not prove supplier ownership of the account. Monitor bank response, beneficiary mismatch, return and supplier acknowledgment.

07

Respond to suspected diversion

Stop pending payments and notify authorized finance, security and legal owners. If money moved, contact the sending financial institution immediately to request its fraud response or recall process, preserve messages and logs, and report through required channels. Do not warn a possibly compromised mailbox before the response plan decides the channel. Review other recent master-data changes and payments.

Reusable buyer brief

Supplier bank account change verification record

Change request ID, supplier entity/vendor record and date:
Requester name/role, channel, sender domain and reply-to:
Current beneficiary record and proposed effective date:
Proposed beneficiary name, bank country and currencies:
Affected invoices/payments and payment-hold reference:
Urgency, new contact, domain, geography and pattern red flags:
Independent contact source, callback route, person and role:
Supplier-stated change details and verification outcome:
Required document, name/authority check and open concern:
Requester, verifier, editor, approvers and segregation record:
First-payment review, bank response and supplier acknowledgment:
Incident/recall action, monitoring, review date and closure:

Fill only the details relevant to your request

Before you send the request

Questions buyers often ask

Should a supplier bank change be accepted by email

No email thread alone should be treated as sufficient verification. Use the organization’s approved independent callback and master-data controls before updating or paying.

Which phone number should be used to verify a bank change

Use a number already validated or independently obtained from an official source, not a number supplied in the account-change message or attachment.

Does a bank letter prove the new account is safe

It may support the review but is not conclusive by appearance alone. Confirm the supplier identity and authority independently and apply controlled approval and payment checks.

What should happen if payment was sent to a fraudulent account

Contact the financial institution immediately, request its fraud or recall process, preserve evidence and follow authorized incident, legal and reporting procedures as quickly as possible.

Keep the request specific

This control reduces risk but cannot guarantee recovery

Banking, privacy, sanctions, fraud reporting, evidence and recovery duties vary by jurisdiction and institution. FBI and FinCEN guidance is U.S. public-source context and does not replace the buyer’s bank, legal, cybersecurity or law-enforcement instructions. Never place complete bank credentials in an openly shared template.

Send this checklist on WhatsApp

Editorial method

How this guide was prepared

MINJI treats beneficiary changes as high-risk identity, communication, master-data and payment events. FBI and FinCEN directly document supplier-impersonation and changed-account fraud; NIST supports separated duties and controlled access.

Ready with the key details

Discuss a wholesale request

Send the product reference, estimated quantity and destination so the conversation starts with useful context.

Continue on WhatsApp