Knowella

Supplier Bank Detail Verification

The recurring failure is not that finance skips the callback. It is that finance calls the number printed on the request. The email looks genuine, the contact is one they have dealt with for years, the invoice is real, and only the account has changed. Verification carried out inside the fraudster's own channel confirms the fraud and produces a record saying it was verified.

KnowLogisticsRecordLOG-043Pinned in navigation53 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27001 cl.8.2
Workspace
KnowLogistics
Form type
Record
Review trigger
New supplier setup, any change request, or periodic reverification
Completed by
Finance, never the person who received the request

The short version

  • The control is not the callback. It is the independence of the number, which is why Phone Number Obtained Independently and Not The Number On The Request are scored as two items, not one.
  • Verification and application must be different people. Verifier Independent Of The Requester and Change Made By Somebody Other Than The Verifier are the segregation controls, and a record failing these has verified nothing.
  • Urgency is data, not noise. Red flags checked records pressure, off-channel arrival and near-miss domains because those patterns are the signature of the fraud, and belong in the record whether or not the change was legitimate.
  • A rejected change is a successful outcome. Suspected Fraud Attempt with a Case ID is the record doing its job, and organisations that never log one are failing to log rather than never being targeted.

What this is

What is supplier bank detail verification?

What is supplier bank detail verification?

It is the control confirming a supplier's bank account belongs to that supplier before money is sent to it. The confirming step is a voice call to a number obtained from a source independent of the request. Everything else, including two-person approval and retention of the previous details, exists to stop that call being bypassed under pressure.

What is payment redirection fraud?

Payment redirection, often called mandate fraud or business email compromise, is an instruction to change a supplier's bank details that appears to come from the supplier and usually comes from a compromised or imitated mailbox. There is no intrusion to detect. The loss is authorised by your own staff, which is why recovery is rare and the control must be procedural.

What makes a phone number independently obtained?

It came from somewhere the requester could not control: your master record predating the request, a signed contract, a purchase order, or published details reached without following a link in the request. A number in the signature block, on the attached letterhead, or offered in a follow-up is not independent, however plausible.

Scope

When is a supplier bank detail verification required?

This record covers one question: are these banking details genuinely the supplier's. It runs at setup and again on every change, however small. It does not assess the supplier as a counterparty and does not stand in for the wider onboarding sequence.

Use this template when

  • A new supplier's payment details are entered into the finance system for the first time
  • A change to bank details, account name or payment reference is requested through any channel
  • Periodic reverification of a high-value or high-frequency supplier's details falls due
  • The supplier notifies a bank, merger or entity change affecting where payment lands
  • A payment bounces or is returned, or a supplier queries non-receipt of funds already sent

Do not use it for

  • Supplier Master Data Setup, which applies the verified details to the finance system and is deliberately done by a different person after this record clears.
  • Supplier Due Diligence and Screening, which assesses ownership, solvency and integrity of the party rather than the authenticity of a payment instruction.
  • Supplier Change Notification, which handles commercial changes such as site, contact or capability rather than banking.
  • Contractor Rate and Invoice Verification, which checks the amount is right, where this record checks the destination is right.
  • Supplier Onboarding Checklist, which sequences onboarding and references this verification rather than performing it.

Compliance mapping

Which ISO 27001 cl.8.2 requirements does this satisfy?

ISO/IEC 27001 treats supplier relationships and information transfer as controlled activities whose risks must be assessed and treated. The mapping below ties those obligations, and the segregation expectation in ISO 37001, to the sections carrying the evidence.

ClauseRequirementWhere it lands
ISO/IEC 27001:2022 cl.8.2Risk assessment performed at planned intervals and when significant changes are proposedRed flags checked
ISO/IEC 27001:2022 Annex A 5.14Rules and procedures for information transfer, including verification of the channel usedIndependent verification
ISO/IEC 27001:2022 Annex A 5.19Processes to manage information security risks in the use of supplier products and servicesControls
ISO/IEC 27001:2022 Annex A 5.24Planning and preparation for managing incidents, including reporting routesOutcome
ISO/IEC 27001:2022 Annex A 6.3Awareness, education and training appropriate to role, kept current with the threats facedControls
ISO 37001:2016 cl.8.3Financial controls including segregation of duties and dual authorisation over paymentsControls

What it does not cover

  • Phone Number Obtained Independently marked Yes on a number from the request's signature block, which records the fraudster's own contact detail as an independent source and inverts the control.
  • Verifier Independent Of The Requester marked N/A because the team is small, which turns a segregation requirement into a resourcing observation and leaves one person able to originate and confirm a payment change.
  • Details Read Back And Confirmed marked Yes after the supplier read them to you, which reverses the direction of the check and lets a caller with a partly correct account be corrected by you.
  • A verification recorded after the change was applied, which documents the control rather than operating it and leaves the exposure window uncontrolled.
  • Suspected Fraud Attempt marked No on a request that failed several red flag items, which suppresses the pattern data identifying a campaign against several of your suppliers at once.

Global

Supplier Bank Detail Verification requirements by country

Liability for a misdirected payment turns on whether a reasonable verification procedure was in place and followed. Three regimes shape that question differently, and all now assume a callback or equivalent name check as baseline.

United Kingdom

Payment Services Regulations 2017 and the Payment Systems Regulator's APP reimbursement requirement

Mandatory reimbursement of in-scope authorised push payment fraud victims, subject to a consumer standard of caution

Protection is centred on consumers and micro-enterprises, so most business payments fall outside it. Confirmation of Payee gives a name match, not an authenticity check, so the independently obtained call remains the operative control for payables.

European Union

Regulation (EU) 2024/886 on instant credit transfers in euro

Payment service providers must offer verification of payee, matching account identifier to payee name before the payment is confirmed

Name mismatch becomes visible at the point of payment, which raises the value of Account Name Matches The Trading Name and Account Name Differs From The Supplier Name. It cannot detect a genuine account opened in a similar name, so the callback is not displaced.

United States

Uniform Commercial Code Article 4A, ss.4A-202 and 4A-203

Loss from an unauthorised or misdescribed funds transfer allocates by whether a commercially reasonable security procedure was agreed and followed

A documented, consistently operated callback procedure is the evidence deciding where the loss sits. Records showing it existed but was skipped under time pressure are worse than no procedure at all in that argument.

How to complete it

How to complete a supplier bank detail verification, step by step

Almost every item is a yes or no. The record's defensibility rests on four judgements made before the first box is ticked.

Where the number came from, and whether you can still prove it

Record the source of the number, not merely that it was independent. A contract predating the request, a master data record with an audit trail, or a directory entry retrieved without following any link are defensible; recollection is not. Where the only number you hold was supplied recently, treat the change as unverified and escalate.

Whether the independence between the three roles is real

Three roles appear here: Requested By, Verified By, and whoever later applies the change in master data. The template scores the first two separations directly. In small teams these collapse, and the right response is to name an approver outside finance rather than mark N/A. A control recorded as inapplicable is a control removed.

How you treat red flags on a legitimate change

Genuine suppliers do send urgent requests from unusual addresses during a migration. The Red flags checked items are not a verdict; they are the context justifying proportionate escalation and later explaining the decision. Record them truthfully even where the change was legitimate: the value is the pattern across records, not the answer in any one.

What happens to the first payment after the change

First Payment After Change Monitored is the last line of defence and the one most often marked Yes with no mechanism behind it. Decide who checks the payment cleared to the expected beneficiary, and by when, and keep Old Details Retained For Audit populated so a reversal has somewhere to go. Fraud found within hours is sometimes recoverable; at month end it is not.

What auditors find

Most common supplier bank detail verification findings

These findings recur across finance functions, and each is visible on the face of the completed record.

FindingClauseWhat fixes it
Verification recorded, but the number used was the one on the requestISO/IEC 27001:2022 Annex A 5.14Require the source of the number to be recorded, and make a No on Not The Number On The Request block the change rather than merely reduce the score.
The same person appears as Requested By and Verified ByISO 37001:2016 cl.8.3Enforce the separation in routing rather than policy, and where headcount prevents it, route the second approval to a named manager outside finance.
Change applied to the finance system before Verification Outcome recordedISO/IEC 27001:2022 cl.8.1Make Master Data Record ID unobtainable until the verification is complete, so the sequence is enforced by the system rather than by discipline.
Suspected fraud attempts handled informally, with no Case ID raisedISO/IEC 27001:2022 Annex A 5.24Treat every rejected change as a reportable incident with an owner and case reference, and review them together so a campaign across suppliers becomes visible.
Finance Team Trained On This Fraud answered Yes on induction training years earlierISO/IEC 27001:2022 Annex A 6.3Date the training and refresh it against current tactics, including synthesised voice, which defeats a callback that only checks somebody answered.
Old details overwritten in master data, leaving no record of the prior accountISO/IEC 27001:2022 Annex A 5.19Retain superseded details with effective dates, so a disputed or reversed payment can be traced and the change history reviewed.

Case in point

Case in point: the migration that made the fraud plausible

A supplier genuinely announces an ERP migration and warns that remittance details will change. Two weeks later a request arrives from a compromised mailbox at that supplier, referencing the migration, attaching a real outstanding invoice, giving a new account. The story is not merely plausible, it is true in every part but the account number. Finance calls the number in the request, reaches the sender, and marks the verification complete.

The error is visible in the record afterwards: Phone Number Obtained Independently marked Yes, Not The Number On The Request marked No, the two contradicting each other on one row. Two payment runs land in the fraudster's account before the supplier chases. Had the second item been treated as blocking rather than merely scored, the call would have gone to the contract number and cost ten minutes.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

53fields
5 sections
Reference
LOG-043
Archetype
Record
Record ID
BANK-2026-000
Scoring
Verified independently
Direction
High is good
Singleton
Yes
Basis
ISO 27001 cl.8.2
Links
Feeds Master Data Setup
Tags
Supplier, Finance, Fraud
Sections
5
Fields
53
Follow up fields
4
Repeating sections
0
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

16 fields
Text

Verification ID*

Generated on save

Auto sequence. Format BANK-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Supplier Name*

Text

Vendor ID

OptionalLinked

Links to FDN-005 Vendor ID

Single Choice

Trigger*

New supplier setup, change request, or periodic reverification.

New supplier setupChange requestPeriodic reverification
Users

Requested By*

Users

Verified By*

Single Choice

Verifier Independent Of The Requester*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Request Arrived By*

Email, letter, portal, phone or in person. Email is the highest risk.

EmailLetterSupplier portalPhoneIn person
Text

Account Name Provided

Optional
Single Choice

Account Name Matches The Trading Name*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Info

One Call To A Number You Looked Up Yourself

Payment redirection fraud arrives as a convincing email from a real supplier contact asking to update bank details. It is defeated by calling a number you obtained independently, never the one on the request.

Independent verification

6 fields
Single Choice

Phone Number Obtained Independently*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Not The Number On The Request*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Called A Known Contact Rather Than A New One*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Spoke To A Person Rather Than Left A Message*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Details Read Back And Confirmed*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Verification Recorded With Date And Name*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator

Red flags checked

6 fields
Single Choice

Urgency Applied By The Requester*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Request Came Outside Normal Channels*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Email Domain Slightly Different*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Account In A Different Country*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Account Name Differs From The Supplier Name*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Previous Change Requested Recently*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator

Controls

6 fields
Single Choice

Two Person Approval Applied*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Change Made By Somebody Other Than The Verifier*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Old Details Retained For Audit*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Supplier Notified Of The Change By A Separate Channel*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

First Payment After Change Monitored*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Finance Team Trained On This Fraud*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator

Outcome

19 fields
Single Choice

Verification Outcome*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Change Applied*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Date & Time

Applied On

Optional
Single Choice

Suspected Fraud Attempt*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Text

Case ID

OptionalThread keyShows if Suspected Fraud Attempt equals Yes

Thread key

Text

Master Data Record ID

OptionalLinked

Links to LOG-044 Record ID

Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Finance*

Signature

Signature*

Users

Finance Manager*

Signature

Second Signature*

LOG-043 · record IDs look like BANK-2026-000 · Feeds Master Data Setup

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The control fails under time pressure, and pressure is what the fraud manufactures. What slips is the sequencing, the second pair of eyes and the follow-up on the first payment.

KnowLogistics

Ties the verification to the vendor register and master data record, so no change can be applied against a supplier with no completed, in-date verification behind it.

KnowComply

Routes rejected changes into the incident register with a case reference, and reviews red flag patterns so a campaign against several suppliers is seen as one event.

KnowOps

Holds the sequence as scheduled work: verification before application, application by a different person, and the first payment checked against the expected beneficiary.

Ella
Ella

Flags records where independence items contradict each other, where requester and verifier are one person, and where a change was applied ahead of its verification, holding every write for approval.

This template lives in KnowLogistics — supply chain execution. Inbound, outbound, inventory, yard, claims, supplier lifecycle and customs.

Glossary

Supplier Bank Detail Verification definitions and key terms

Payment redirection
An authorised payment sent to a fraudster's account after a convincing instruction to change a genuine supplier's banking details.
Business email compromise
Unauthorised access to, or imitation of, a legitimate mailbox used to issue instructions appearing to come from a trusted party.
Callback verification
Confirmation of a payment instruction by voice call to a number from a source predating and independent of the instruction itself.
Segregation of duties
The requirement that origination, verification and application of a change are done by different people, so no one person can complete a payment diversion.
Verification of payee
A bank service checking whether the account name given matches the account holder's registered name, catching mistyping and crude impersonation but not an account opened in a similar name.

FAQ

Frequently asked questions about supplier bank detail verification

Is an email confirmation from a second contact enough?+

No. If the mailbox or domain is compromised, a second email is the same channel and often the same attacker. The control requires a different medium: a voice call to an independently sourced number.

What if the supplier will not take a call?+

Then the change does not proceed. A supplier that has genuinely changed accounts has every reason to confirm it, and a refusal to speak is itself a red flag worth recording. Keep paying the old, verified account until a call happens.

Does Confirmation of Payee remove the need for this record?+

No. Name matching catches errors and crude impersonation. It misses an account genuinely opened in a name close to the supplier's, and says nothing about whether the instruction was authentic.

Should we reverify details that have not changed?+

For high-value or high-frequency suppliers, yes, on a defined cycle, which is why Periodic reverification is a Trigger option. Details can be altered by an insider or an earlier unverified change, and only a cycle finds that.

Can deepfaked voice defeat the callback?+

It defeats a callback that only checks somebody answered. It cannot defeat one placed to a number the attacker does not control, because the call reaches the real supplier whoever the attacker can imitate. Independence of the number, not recognition of the voice, carries the control.

Who should hold the record once complete?+

Finance, with the second signature from the finance manager, and a link to the master data record that applied the change. The pairing proves verification preceded application rather than followed it.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO/IEC 27001:2022, cl.8.2 and Annex A controls 5.14, 5.19, 5.24 and 6.3
  • ISO 37001:2016, cl.8.3, Financial controls
  • Payment Services Regulations 2017 (UK) and the PSR APP reimbursement requirement
  • Regulation (EU) 2024/886 on instant credit transfers in euro
  • Uniform Commercial Code Article 4A, ss.4A-202 and 4A-203

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.