Vendor Bank Account Change Control for Finance

Vendor Bank Account Change Control for Finance featured image
What’s in this article?

    Vendor bank changes should never move straight from an email request into a payment file.

    Quick answer

    A practical finance guide to verifying vendor bank account changes before payment, reducing payment redirection risk, and preserving approval evidence.

    Vendor bank account change control is the finance workflow that verifies, approves, records, and releases changes to supplier banking details before any payment uses the new account. It exists because a changed account number is not a simple vendor profile edit. It is a direct path to cash leaving the company.

    For accounts payable teams, the hard part is balancing speed and control. Real vendors do change banks. Contractors may need a different payout method. International suppliers may update IBANs, intermediary banks, or payment currencies. But payment redirection fraud often starts with a normal-looking message asking finance to update payment details before the next run.

    What’s in this article?

    • What vendor bank account change control should include
    • How to verify bank changes without relying on the request itself
    • A practical workflow finance teams can use across vendors, contractors, and suppliers
    • Common mistakes that create payment fraud and audit risk
    • Where Workhint fits when vendor changes span AP, procurement, operations, and finance leadership

    Why bank account changes need stronger control

    A vendor address change may cause confusion. A vendor bank change can redirect money. The FBI’s guidance on business email compromise warns that attackers often send messages that appear to come from known sources and recommends verifying payment procedure changes with the person making the request. For finance teams, that means the verification path cannot depend only on the email, phone number, or attachment supplied in the change request.

    ERP platforms treat this as a controlled workflow for a reason. Microsoft Learn describes vendor bank approval workflow in Dynamics 365 Finance as a way to evaluate and approve supplier bank data changes before they become active. Even if your team does not use that ERP, the operating principle is useful: proposed banking changes should sit in a pending state until the right checks are complete.

    Vendor Bank Account Change Control Workflow

    A strong control separates the person requesting the change, the person verifying the change, the person approving the change, and the payment run that eventually uses the new details.

    StepFinance actionEvidence to keep
    Change requestCapture the request in an approved channelRequester, vendor, old details, proposed new details, timestamp
    Vendor identity checkConfirm the request is tied to an approved supplierVendor master record, contract, tax form, authorized contact
    Independent verificationCall or verify through known contact details already on fileVerifier, date, method, verified contact source
    Bank validationCheck format, account ownership, currency, country, and payment rail requirementsValidation result, banking document, platform check
    ApprovalRoute to AP, vendor owner, procurement, or finance leadership by riskApprover, role, decision, comments
    Payment holdHold payments using the new account until approval is completeHold status, release date, payment batch reference
    Audit recordStore the full change history with the vendor recordBefore-and-after values, approval trail, supporting documents

    How to verify a vendor bank account change

    1. Start with an approved intake channel

    Do not accept bank changes as casual email instructions. Require vendors to submit updates through a vendor portal, secure form, ticket, or controlled AP inbox. The request should identify the vendor, authorized contact, payment method, old account status, new banking details, effective date, and reason for the change.

    2. Use trusted contact details already on file

    The safest callback is not the phone number in the email asking for the change. Use a phone number, portal identity, or authorized contact already stored in the vendor record. UNC Finance gives similar practical guidance for safely updating vendor banking information: verify changes by contacting the company through an independently sourced accounting, billing, or receivables contact.

    3. Apply maker-checker approval

    The person who enters the bank change should not be the only person who approves it. A maker-checker model gives AP one role for capturing the proposed change and another role for verification or approval. Higher-risk changes can add a vendor owner, procurement lead, controller, or CFO review.

    4. Put payments on hold until the change is approved

    A control is weak if payment can run before approval finishes. Any vendor with a pending bank account change should be excluded from payment batches that use the new details. For urgent payments, require a documented exception, senior approval, and confirmation through a trusted contact path.

    5. Preserve the full record

    Business records need to support what happened later, not just enable the transaction today. The IRS recordkeeping page points businesses toward keeping records that support tax and operational reporting. For vendor bank changes, that means storing the request, verification method, approval trail, documents, before-and-after values, payment hold, and release decision.

    Risk-based approval rules

    Not every change needs the same level of review. A practical policy should route by risk:

    • Existing domestic vendor changing a routine ACH account: AP verification plus controller approval.
    • International supplier changing IBAN, SWIFT, country, or currency: AP verification, procurement or vendor owner approval, and finance approval.
    • New contractor payment account during onboarding: identity check, tax documentation review, and payment-method validation.
    • Urgent request before a large payment run: automatic hold, independent callback, and senior finance approval.
    • Request from a new email domain, unusual contact, or changed remittance instruction: fraud review before any master data update.

    The policy should be strictest when money is about to move, when a vendor has high payment volume, when the payment is cross-border, or when the request changes both contact information and bank information at the same time.

    Common mistakes to avoid

    • Using email as proof. Email is the request channel, not verification evidence.
    • Skipping callbacks for familiar vendors. Long-standing suppliers are attractive targets because finance teams trust the relationship.
    • Changing vendor master data without a payment hold. A pending change should not be usable in a payment batch.
    • Approving changes without before-and-after history. Finance should know exactly what changed, who changed it, and who approved it.
    • Letting exceptions become routine. Urgent payments should have tighter review, not looser review.

    Where Workhint fits

    Workhint helps finance and operations teams turn vendor bank account change policies into live workflows. A team can define intake steps, vendor roles, required documents, verification tasks, approval thresholds, payment holds, exception routing, and audit records in one operating system. When supplier data changes touch AP, procurement, operations, contractors, and finance leadership, vendor management software helps keep the change controlled instead of scattered across inboxes and spreadsheets.

    Workhint does not replace bank validation, accounting judgment, or legal advice. It helps teams coordinate the work around the control so that no one has to guess whether a bank change is verified, approved, or safe to use.

    FAQ

    What is vendor bank account change control?

    It is the workflow finance uses to verify, approve, document, and release changes to supplier banking details before payments use the new account.

    Who should approve vendor bank changes?

    At minimum, someone separate from the person entering the change should approve it. Higher-risk changes should involve AP leadership, procurement, the vendor owner, or finance leadership.

    Should payments be held after a bank account change?

    Yes. Payments using the new account should stay on hold until verification and approval are complete. Urgent exceptions should be documented and approved by senior finance.

    What evidence should finance keep?

    Keep the original request, trusted-contact verification, bank validation result, approvals, before-and-after details, payment hold status, exception notes, and release decision.

    Conclusion

    Vendor bank account changes deserve more control than ordinary vendor updates because they affect where cash goes. The best workflow captures the request in one channel, verifies it through trusted contact details, validates the bank information, separates entry from approval, holds payment until complete, and preserves the record. Done well, the process protects vendor relationships and payment speed while reducing the chance that finance approves a clean-looking but fraudulent change.

    Comments

    Leave a Reply

    Your email address will not be published. Required fields are marked *


    The reCAPTCHA verification period has expired. Please reload the page.