Verify changes before money moves
A request to change supplier bank details can look routine, especially when it appears in an existing email conversation. Stratiis helps Scottish organisations make payment changes easier to check: clear ownership, an independent verification route, practical staff guidance and a response plan when something does not look right.
What is payment change fraud?
Payment change fraud is an attempt to redirect a legitimate payment by substituting a criminal's bank details or inventing an urgent transfer. An attacker may impersonate a supplier, colleague or senior leader, or use a compromised email account. It is often called payment diversion fraud or business email compromise. The safe decision depends on independently confirming the change and following the organisation's approval process.
Make an independent check part of the process
A good control still works when the message looks familiar or arrives at a busy time.
Trusted details
Staff use contact information already held by the business.
Clear approval
The right people review and authorise the change.
Visible evidence
Checks and decisions can be recorded for later review.
Prompt escalation
Suspected fraud reaches the bank and response team quickly.
What should a payment change process include?
Define the route from a request to an approved change before relying on a message or document.
| Area | Question to answer | Useful output |
|---|---|---|
| Request | Who may ask for a new payee or a change to existing bank details? | Recognised intake route. |
| Trusted contact | Which number or contact record was held before the change request arrived? | Independent verification method. |
| Approval | Who can authorise the change, and when is a second check needed? | Decision rights and separation of duties. |
| Evidence | How are the request, check, approval and effective date recorded? | Reviewable change record. |
| System access | Who can edit supplier records and release payments? | Limited permissions and activity review. |
| Exceptions | What happens if the contact cannot be reached or the request is urgent? | Hold and escalation route. |
| Response | Who contacts the bank and investigates if a payment may be misdirected? | Named response owners. |
Do not use the phone number, reply address or link supplied in the message being checked as the only proof. A convincing email thread can still be compromised.
Which payment requests need a deliberate pause?
Apply the agreed checks to changes and exceptions, even when the sender is known.
New bank details
Confirm the change with the supplier using a trusted contact record before updating payment data.
Urgent transfer requests
Follow the normal authority and verification route when a request asks you to bypass it.
Invoice corrections
Compare changed remittance details with the approved supplier record and query differences.
Executive instructions
Independently check an unusual payment request that appears to come from a senior colleague.
Existing email threads
A familiar conversation is not enough; use a separate, established channel to verify the change.
New payees
Confirm the business purpose, payee identity and approval before the first transfer.
Turn a policy into a workable payment check
Test the path with a realistic supplier change and a request that cannot be verified straight away.
Map
Follow how payee details are requested, edited, approved and paid today.
Agree
Set trusted contact, approval, evidence and exception rules with finance owners.
Practise
Give staff examples of impersonation and rehearse a separate verification call.
Review
Check that the process is followed and update gaps after reports or near misses.
Phishing and Impersonation covers the wider pattern of deceptive requests across channels.
Keep payment authority with the right people
Technology can support checks, but business owners must define who can change and approve a payment.
What Stratiis can help plan
A review of the email and account risks around payment requests.
Staff guidance for impersonation and reporting.
Access and activity checks for relevant systems.
A technical escalation route if an account may be compromised.
What your team owns
Supplier and payee verification standards.
Approval levels and separation of duties.
Trusted contact records and evidence of checks.
Bank contact and decisions when a transfer is in doubt.
What should happen when fraud is suspected?
Act promptly and use official channels. The exact response depends on whether details were changed or funds have moved.
| Situation | Immediate action | Owner to involve |
|---|---|---|
| Unverified request | Hold the change and contact the supplier or colleague through a known route. | Finance approver. |
| Supplier record changed | Stop pending payments, preserve the change record and investigate how it was authorised. | Finance and IT response. |
| Payment sent | Contact the bank immediately through its official number or website and report internally. | Finance lead, bank and IT response. |
| Account may be compromised | Escalate the suspected access issue and follow the account incident process. | IT or security response. |
| Evidence and follow-up | Record the timeline, affected transactions and decisions for investigation. | Incident owner. |
The NCSC's business payment fraud guidance also advises prompt internal reporting and direct contact with the bank. No recovery outcome can be assumed.
Reduce reliance on one person's judgement
Use layered controls around the request, the account and the payment workflow.
Email security
Review filtering, domain protection and suspicious message reporting.
Account security
Use MFA and appropriate access for mail and financial systems.
Change controls
Limit who can edit payees and review unusual changes.
Response readiness
Keep trusted bank details and escalation contacts available.
Monitoring and Response helps connect suspicious account activity with a clear investigation route.
Connect payment checks to wider security work
Payment diversion is a business process risk as well as a cybersecurity concern.
Payment change verification FAQs
Practical answers for teams handling supplier and payment instructions.
How should a business verify a change of bank details?
Contact the supplier through a number or route already trusted by the business, confirm the change with an authorised contact and follow the approval process before editing the payee record.
Is a reply in the same email thread enough?
No. A mailbox or conversation may be compromised. Use a separate contact method based on a record held before the request.
What if the request appears to come from the managing director?
Apply the same payment authority and independent verification rules. Seniority or urgency should not remove the check.
Who should approve supplier payment changes?
Your organisation should name the roles, approval levels and evidence required. For higher-risk changes, an independent second check may be appropriate.
What if the supplier cannot be reached?
Hold the change or payment and use the agreed escalation route. An inability to verify is a reason to pause, not to use the contact details in the suspicious request.
What if payment has already been sent to the wrong account?
Notify the finance lead and response team immediately, then contact the bank directly using official details. Provide the transaction information requested by the bank and preserve relevant evidence.
Can cybersecurity tools prevent every fraudulent payment?
No. Email and identity controls can reduce exposure, but a reliable payment workflow still needs independent verification, approval and reporting.
How can we tell whether the process is working?
Review whether checks are recorded, exceptions are escalated, suspicious requests are reported and payee changes match the approved process. Use near misses to refine the controls.
Make payment changes easier to verify
Tell us how your team receives and approves changes. We can help align staff guidance, account controls and a clear response route with your finance process.


