What this is
What is supplier bank detail verification?
What is supplier bank detail verification?
It is the control confirming a supplier's bank account belongs to that supplier before money is sent to it. The confirming step is a voice call to a number obtained from a source independent of the request. Everything else, including two-person approval and retention of the previous details, exists to stop that call being bypassed under pressure.
What is payment redirection fraud?
Payment redirection, often called mandate fraud or business email compromise, is an instruction to change a supplier's bank details that appears to come from the supplier and usually comes from a compromised or imitated mailbox. There is no intrusion to detect. The loss is authorised by your own staff, which is why recovery is rare and the control must be procedural.
What makes a phone number independently obtained?
It came from somewhere the requester could not control: your master record predating the request, a signed contract, a purchase order, or published details reached without following a link in the request. A number in the signature block, on the attached letterhead, or offered in a follow-up is not independent, however plausible.
Scope
When is a supplier bank detail verification required?
This record covers one question: are these banking details genuinely the supplier's. It runs at setup and again on every change, however small. It does not assess the supplier as a counterparty and does not stand in for the wider onboarding sequence.
Use this template when
- A new supplier's payment details are entered into the finance system for the first time
- A change to bank details, account name or payment reference is requested through any channel
- Periodic reverification of a high-value or high-frequency supplier's details falls due
- The supplier notifies a bank, merger or entity change affecting where payment lands
- A payment bounces or is returned, or a supplier queries non-receipt of funds already sent
Do not use it for
- Supplier Master Data Setup, which applies the verified details to the finance system and is deliberately done by a different person after this record clears.
- Supplier Due Diligence and Screening, which assesses ownership, solvency and integrity of the party rather than the authenticity of a payment instruction.
- Supplier Change Notification, which handles commercial changes such as site, contact or capability rather than banking.
- Contractor Rate and Invoice Verification, which checks the amount is right, where this record checks the destination is right.
- Supplier Onboarding Checklist, which sequences onboarding and references this verification rather than performing it.
Compliance mapping
Which ISO 27001 cl.8.2 requirements does this satisfy?
ISO/IEC 27001 treats supplier relationships and information transfer as controlled activities whose risks must be assessed and treated. The mapping below ties those obligations, and the segregation expectation in ISO 37001, to the sections carrying the evidence.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO/IEC 27001:2022 cl.8.2 | Risk assessment performed at planned intervals and when significant changes are proposed | Red flags checked |
| ISO/IEC 27001:2022 Annex A 5.14 | Rules and procedures for information transfer, including verification of the channel used | Independent verification |
| ISO/IEC 27001:2022 Annex A 5.19 | Processes to manage information security risks in the use of supplier products and services | Controls |
| ISO/IEC 27001:2022 Annex A 5.24 | Planning and preparation for managing incidents, including reporting routes | Outcome |
| ISO/IEC 27001:2022 Annex A 6.3 | Awareness, education and training appropriate to role, kept current with the threats faced | Controls |
| ISO 37001:2016 cl.8.3 | Financial controls including segregation of duties and dual authorisation over payments | Controls |
What it does not cover
- Phone Number Obtained Independently marked Yes on a number from the request's signature block, which records the fraudster's own contact detail as an independent source and inverts the control.
- Verifier Independent Of The Requester marked N/A because the team is small, which turns a segregation requirement into a resourcing observation and leaves one person able to originate and confirm a payment change.
- Details Read Back And Confirmed marked Yes after the supplier read them to you, which reverses the direction of the check and lets a caller with a partly correct account be corrected by you.
- A verification recorded after the change was applied, which documents the control rather than operating it and leaves the exposure window uncontrolled.
- Suspected Fraud Attempt marked No on a request that failed several red flag items, which suppresses the pattern data identifying a campaign against several of your suppliers at once.
Global
Supplier Bank Detail Verification requirements by country
Liability for a misdirected payment turns on whether a reasonable verification procedure was in place and followed. Three regimes shape that question differently, and all now assume a callback or equivalent name check as baseline.
Payment Services Regulations 2017 and the Payment Systems Regulator's APP reimbursement requirement
Mandatory reimbursement of in-scope authorised push payment fraud victims, subject to a consumer standard of caution
Protection is centred on consumers and micro-enterprises, so most business payments fall outside it. Confirmation of Payee gives a name match, not an authenticity check, so the independently obtained call remains the operative control for payables.
Regulation (EU) 2024/886 on instant credit transfers in euro
Payment service providers must offer verification of payee, matching account identifier to payee name before the payment is confirmed
Name mismatch becomes visible at the point of payment, which raises the value of Account Name Matches The Trading Name and Account Name Differs From The Supplier Name. It cannot detect a genuine account opened in a similar name, so the callback is not displaced.
Uniform Commercial Code Article 4A, ss.4A-202 and 4A-203
Loss from an unauthorised or misdescribed funds transfer allocates by whether a commercially reasonable security procedure was agreed and followed
A documented, consistently operated callback procedure is the evidence deciding where the loss sits. Records showing it existed but was skipped under time pressure are worse than no procedure at all in that argument.
How to complete it
How to complete a supplier bank detail verification, step by step
Almost every item is a yes or no. The record's defensibility rests on four judgements made before the first box is ticked.
Record the source of the number, not merely that it was independent. A contract predating the request, a master data record with an audit trail, or a directory entry retrieved without following any link are defensible; recollection is not. Where the only number you hold was supplied recently, treat the change as unverified and escalate.
Three roles appear here: Requested By, Verified By, and whoever later applies the change in master data. The template scores the first two separations directly. In small teams these collapse, and the right response is to name an approver outside finance rather than mark N/A. A control recorded as inapplicable is a control removed.
Genuine suppliers do send urgent requests from unusual addresses during a migration. The Red flags checked items are not a verdict; they are the context justifying proportionate escalation and later explaining the decision. Record them truthfully even where the change was legitimate: the value is the pattern across records, not the answer in any one.
First Payment After Change Monitored is the last line of defence and the one most often marked Yes with no mechanism behind it. Decide who checks the payment cleared to the expected beneficiary, and by when, and keep Old Details Retained For Audit populated so a reversal has somewhere to go. Fraud found within hours is sometimes recoverable; at month end it is not.
What auditors find
Most common supplier bank detail verification findings
These findings recur across finance functions, and each is visible on the face of the completed record.
| Finding | Clause | What fixes it |
|---|---|---|
| Verification recorded, but the number used was the one on the request | ISO/IEC 27001:2022 Annex A 5.14 | Require the source of the number to be recorded, and make a No on Not The Number On The Request block the change rather than merely reduce the score. |
| The same person appears as Requested By and Verified By | ISO 37001:2016 cl.8.3 | Enforce the separation in routing rather than policy, and where headcount prevents it, route the second approval to a named manager outside finance. |
| Change applied to the finance system before Verification Outcome recorded | ISO/IEC 27001:2022 cl.8.1 | Make Master Data Record ID unobtainable until the verification is complete, so the sequence is enforced by the system rather than by discipline. |
| Suspected fraud attempts handled informally, with no Case ID raised | ISO/IEC 27001:2022 Annex A 5.24 | Treat every rejected change as a reportable incident with an owner and case reference, and review them together so a campaign across suppliers becomes visible. |
| Finance Team Trained On This Fraud answered Yes on induction training years earlier | ISO/IEC 27001:2022 Annex A 6.3 | Date the training and refresh it against current tactics, including synthesised voice, which defeats a callback that only checks somebody answered. |
| Old details overwritten in master data, leaving no record of the prior account | ISO/IEC 27001:2022 Annex A 5.19 | Retain superseded details with effective dates, so a disputed or reversed payment can be traced and the change history reviewed. |
Case in point
Case in point: the migration that made the fraud plausible
A supplier genuinely announces an ERP migration and warns that remittance details will change. Two weeks later a request arrives from a compromised mailbox at that supplier, referencing the migration, attaching a real outstanding invoice, giving a new account. The story is not merely plausible, it is true in every part but the account number. Finance calls the number in the request, reaches the sender, and marks the verification complete.
The error is visible in the record afterwards: Phone Number Obtained Independently marked Yes, Not The Number On The Request marked No, the two contradicting each other on one row. Two payment runs land in the fraudster's account before the supplier chases. Had the second item been treated as blocking rather than merely scored, the call would have gone to the contract number and cost ten minutes.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- LOG-043
- Archetype
- Record
- Record ID
- BANK-2026-000
- Scoring
- Verified independently
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 27001 cl.8.2
- Links
- Feeds Master Data Setup
- Tags
- Supplier, Finance, Fraud
- Sections
- 5
- Fields
- 53
- Follow up fields
- 4
- Repeating sections
- 0
- Links out
- 4
Header
16 fieldsVerification ID*
Auto sequence. Format BANK-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Supplier Name*
Vendor ID
Links to FDN-005 Vendor ID
Trigger*
New supplier setup, change request, or periodic reverification.
Requested By*
Verified By*
Verifier Independent Of The Requester*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Request Arrived By*
Email, letter, portal, phone or in person. Email is the highest risk.
Account Name Provided
Account Name Matches The Trading Name*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
One Call To A Number You Looked Up Yourself
Payment redirection fraud arrives as a convincing email from a real supplier contact asking to update bank details. It is defeated by calling a number you obtained independently, never the one on the request.
Independent verification
6 fieldsPhone Number Obtained Independently*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Not The Number On The Request*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Called A Known Contact Rather Than A New One*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Spoke To A Person Rather Than Left A Message*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Details Read Back And Confirmed*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Verification Recorded With Date And Name*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Red flags checked
6 fieldsUrgency Applied By The Requester*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Request Came Outside Normal Channels*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Email Domain Slightly Different*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Account In A Different Country*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Account Name Differs From The Supplier Name*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Previous Change Requested Recently*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Controls
6 fieldsTwo Person Approval Applied*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Change Made By Somebody Other Than The Verifier*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Old Details Retained For Audit*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Supplier Notified Of The Change By A Separate Channel*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
First Payment After Change Monitored*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Finance Team Trained On This Fraud*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Outcome
19 fieldsVerification Outcome*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Change Applied*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Applied On
Suspected Fraud Attempt*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Case ID
Thread key
Master Data Record ID
Links to LOG-044 Record ID
Items Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Finance*
Signature*
Finance Manager*
Second Signature*
LOG-043 · record IDs look like BANK-2026-000 · Feeds Master Data Setup
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The control fails under time pressure, and pressure is what the fraud manufactures. What slips is the sequencing, the second pair of eyes and the follow-up on the first payment.
Ties the verification to the vendor register and master data record, so no change can be applied against a supplier with no completed, in-date verification behind it.
Routes rejected changes into the incident register with a case reference, and reviews red flag patterns so a campaign against several suppliers is seen as one event.
Holds the sequence as scheduled work: verification before application, application by a different person, and the first payment checked against the expected beneficiary.

Flags records where independence items contradict each other, where requester and verifier are one person, and where a change was applied ahead of its verification, holding every write for approval.
This template lives in KnowLogistics — supply chain execution. Inbound, outbound, inventory, yard, claims, supplier lifecycle and customs.
Glossary
Supplier Bank Detail Verification definitions and key terms
- Payment redirection
- An authorised payment sent to a fraudster's account after a convincing instruction to change a genuine supplier's banking details.
- Business email compromise
- Unauthorised access to, or imitation of, a legitimate mailbox used to issue instructions appearing to come from a trusted party.
- Callback verification
- Confirmation of a payment instruction by voice call to a number from a source predating and independent of the instruction itself.
- Segregation of duties
- The requirement that origination, verification and application of a change are done by different people, so no one person can complete a payment diversion.
- Verification of payee
- A bank service checking whether the account name given matches the account holder's registered name, catching mistyping and crude impersonation but not an account opened in a similar name.
FAQ
Frequently asked questions about supplier bank detail verification
Is an email confirmation from a second contact enough?+
No. If the mailbox or domain is compromised, a second email is the same channel and often the same attacker. The control requires a different medium: a voice call to an independently sourced number.
What if the supplier will not take a call?+
Then the change does not proceed. A supplier that has genuinely changed accounts has every reason to confirm it, and a refusal to speak is itself a red flag worth recording. Keep paying the old, verified account until a call happens.
Does Confirmation of Payee remove the need for this record?+
No. Name matching catches errors and crude impersonation. It misses an account genuinely opened in a name close to the supplier's, and says nothing about whether the instruction was authentic.
Should we reverify details that have not changed?+
For high-value or high-frequency suppliers, yes, on a defined cycle, which is why Periodic reverification is a Trigger option. Details can be altered by an insider or an earlier unverified change, and only a cycle finds that.
Can deepfaked voice defeat the callback?+
It defeats a callback that only checks somebody answered. It cannot defeat one placed to a number the attacker does not control, because the call reaches the real supplier whoever the attacker can imitate. Independence of the number, not recognition of the voice, carries the control.
Who should hold the record once complete?+
Finance, with the second signature from the finance manager, and a link to the master data record that applied the change. The pairing proves verification preceded application rather than followed it.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Supplier Onboarding and Lifecycle
Conflict of Interest Declaration
Records a declared interest that could affect a business decision, and how it will be managed
Vendor and Contractor Register
Holds every supplier, contractor and service provider you work with, including their status and approval level
Supplier Onboarding Checklist
Takes a new supplier from selected to able to trade, covering banking, insurance, terms, technical approval and system setup
Supplier Sourcing Request
Starts the process of finding a new supplier, stating what is needed, why the existing suppliers cannot provide it and what the selection criteria will be
Supplier Due Diligence and Screening
Screens a prospective supplier for financial standing, ownership, sanctions exposure, litigation and adverse media before commercial discussions go far
Supplier Master Data Setup
Creates the supplier record in the systems that will use it, covering codes, terms, tax status, addresses and approval scope
More in Supplier Lifecycle
Supplier Onboarding Checklist
Takes a new supplier from selected to able to trade, covering banking, insurance, terms, technical approval and system setup
Supplier Sourcing Request
Starts the process of finding a new supplier, stating what is needed, why the existing suppliers cannot provide it and what the selection criteria will be
Supplier Due Diligence and Screening
Screens a prospective supplier for financial standing, ownership, sanctions exposure, litigation and adverse media before commercial discussions go far
Supplier Master Data Setup
Creates the supplier record in the systems that will use it, covering codes, terms, tax status, addresses and approval scope
Supplier First Delivery Review
Reviews the first delivery from a new supplier against everything that was promised during approval
Supplier Change Notification
Records a change a supplier has told you about, or one you have discovered, covering manufacturing site, formulation, ownership, subcontracting or certification

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO/IEC 27001:2022, cl.8.2 and Annex A controls 5.14, 5.19, 5.24 and 6.3
- ISO 37001:2016, cl.8.3, Financial controls
- Payment Services Regulations 2017 (UK) and the PSR APP reimbursement requirement
- Regulation (EU) 2024/886 on instant credit transfers in euro
- Uniform Commercial Code Article 4A, ss.4A-202 and 4A-203
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.