---
title: "QuickBooks Online Vendor Bank Change Controls (7-Step Framework)"
description: "QuickBooks Online vendor bank change controls: custom roles, Bill Pay roles, approval workflows, the audit log, payment review and an independent callback to the vendor."
url: https://realpayee.com/guides/quickbooks-online-vendor-bank-change-controls
canonical: https://realpayee.com/guides/quickbooks-online-vendor-bank-change-controls
date_published: 2026-10-06
date_modified: 2026-10-06
updated: 2026-10-06
author: "RealPayee"
site: RealPayee
---

# QuickBooks Online vendor bank change controls: a 7-step framework

> **QuickBooks Online gives you permissions, Bill Pay roles, bill approval workflows and an audit log, but no documented alert when a vendor's bank details change.** Limit vendor editing with custom roles (Advanced) or Bill Pay roles, keep editing apart from paying, verify every change by calling a known contact, review vendor edits in the audit log every week, and hold the first payment to new details.

_Updated 2026-10-06 · 6 min read_

## Key takeaways

- **Custom roles** (QuickBooks Online Advanced) set view, create, edit and delete rights on vendors.
- Bill Pay roles: **Bill Clerk** edits vendors but can't approve or pay; **Bill Payer** pays and can edit vendor details, so watch that combination.
- Bill approval workflows approve **bills**, not vendor bank-detail edits.
- The **audit log** shows vendor edits by user and date; review it on a schedule because Intuit documents no change alert.

## The short version

QuickBooks Online is built for small and mid-size teams, so the control relies more on process than on system enforcement. The permissions and audit log are good enough to make changes **traceable**. Making them **verified** needs a callback rule, a second person and a review of every vendor edit before the next payment run.

## QuickBooks Online vendor bank change control framework (7 steps)

1. **Limit who can edit vendors.** In QuickBooks Online Advanced you can build custom roles with action-level permissions on the Vendors list (view, create, edit, delete). Give edit rights to as few named people as possible. On plans without custom roles, keep the number of users with vendor access to a minimum.
2. **Choose Bill Pay roles that separate duties.** With QuickBooks Bill Pay Elite or QuickBooks Online Advanced, Intuit offers Bill Approver (can only approve bills), Bill Clerk (adds bills, marks bills as paid, adds and edits vendors; can't approve or pay) and Bill Payer (views and pays bills and edits vendor details). Note that Bill Payer combines paying with editing vendor details, so if you need strict separation, use a custom role in Advanced or add a compensating review.
3. **Turn on bill approval workflows.** Bill Pay Elite supports approval workflows triggered by bill amount, vendor, location or a combination, and bills not reviewed within 30 days are automatically denied. These workflows approve bills, not vendor bank-detail edits, so pair them with the change review below.
4. **Verify every bank-detail change out-of-band.** Hold the change, call the vendor on a number from your records that existed before the request, reach an authorized person and have them state the new details. Never use contact details from the request. The FBI advises using secondary channels to verify requests for changes in account information.
5. **Review the audit log for vendor changes.** QuickBooks Online's audit log (Settings > Audit log) records edits to customers, vendors and employees, with the date, the user, the type of change and the vendor involved. Admin access is required and it can't be turned off. Intuit's help does not describe an alert to other users when a vendor's bank details change, so schedule a weekly review of vendor edits against your evidence log.
6. **Review payments before release.** Before paying, compare the payment list with vendors edited since the last run. Apply a cooling-off period (for example 24 to 72 hours) before the first payment to new details, and confirm receipt of that first payment with the known contact.
7. **Keep the evidence with the vendor.** Attach the request, the number dialed and its source, who confirmed, the approver and the date to the vendor record or your ticket system. Auditors and insurers ask for it.

## Bill Pay roles at a glance

| Role | Can do | Can't do | Risk note |
| --- | --- | --- | --- |
| Bill Approver | Approve bills | Pay bills or any other bill or payment action | Good second-person role |
| Bill Clerk | Add bills, mark bills as paid, add and edit vendors | Approve or pay bills | Can change vendor details, so their edits need review |
| Bill Payer | View and pay bills, edit vendor details | Add bills or other bill actions | Combines paying with vendor edits: add a compensating review |

Roles available with QuickBooks Bill Pay Elite, and customizable in QuickBooks Online Advanced, per Intuit.

## What QuickBooks Online does natively, and what it leaves to you

| Control | Native in QuickBooks Online? | How |
| --- | --- | --- |
| Restrict who edits vendors | Yes (best in Advanced) | Custom roles with vendor action permissions; Bill Pay roles |
| Approval of bills | Yes (Bill Pay Elite) | Approval workflows by amount, vendor or location |
| Approval of vendor bank-detail changes | Not documented | Policy: second person approves after reviewing callback evidence |
| Audit trail | Yes | Audit log with user, date, event and vendor |
| Alert on vendor bank change | Not documented | Weekly audit log review, or a verification layer |
| Confirm the real vendor asked | No | Out-of-band callback to a known contact, or RealPayee |

## Where RealPayee fits

[RealPayee](https://realpayee.com/demo) sits on top of these QuickBooks Online controls. It watches for vendor bank-detail changes and payments above your threshold, holds them, and asks the vendor's **known contact** (enrolled before the request) or the real executive to confirm out-of-band by SMS, Slack or Microsoft Teams, with phone-bound approval or government ID plus live selfie. The evidence (who confirmed, how, when) is attached automatically. It does not move money, does not validate account ownership against bank data, and does not replace the permission and segregation-of-duties steps above.

Start with the free [callback verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) and the step-by-step [vendor bank account change procedure](https://realpayee.com/how-to-verify-a-vendor-bank-account-change). Other ERPs: [NetSuite](https://realpayee.com/guides/netsuite-vendor-bank-change-controls) and [Xero](https://realpayee.com/guides/xero-vendor-bank-change-controls).

## QuickBooks Online vendor bank change controls

1. **Limit who can edit vendors** - In QuickBooks Online Advanced you can build custom roles with action-level permissions on the Vendors list (view, create, edit, delete). Give edit rights to as few named people as possible. On plans without custom roles, keep the number of users with vendor access to a minimum.
2. **Choose Bill Pay roles that separate duties** - With QuickBooks Bill Pay Elite or QuickBooks Online Advanced, Intuit offers Bill Approver (can only approve bills), Bill Clerk (adds bills, marks bills as paid, adds and edits vendors; can't approve or pay) and Bill Payer (views and pays bills and edits vendor details). Note that Bill Payer combines paying with editing vendor details, so if you need strict separation, use a custom role in Advanced or add a compensating review.
3. **Turn on bill approval workflows** - Bill Pay Elite supports approval workflows triggered by bill amount, vendor, location or a combination, and bills not reviewed within 30 days are automatically denied. These workflows approve bills, not vendor bank-detail edits, so pair them with the change review below.
4. **Verify every bank-detail change out-of-band** - Hold the change, call the vendor on a number from your records that existed before the request, reach an authorized person and have them state the new details. Never use contact details from the request. The FBI advises using secondary channels to verify requests for changes in account information.
5. **Review the audit log for vendor changes** - QuickBooks Online's audit log (Settings > Audit log) records edits to customers, vendors and employees, with the date, the user, the type of change and the vendor involved. Admin access is required and it can't be turned off. Intuit's help does not describe an alert to other users when a vendor's bank details change, so schedule a weekly review of vendor edits against your evidence log.
6. **Review payments before release** - Before paying, compare the payment list with vendors edited since the last run. Apply a cooling-off period (for example 24 to 72 hours) before the first payment to new details, and confirm receipt of that first payment with the known contact.
7. **Keep the evidence with the vendor** - Attach the request, the number dialed and its source, who confirmed, the approver and the date to the vendor record or your ticket system. Auditors and insurers ask for it.

## Frequently asked questions

### Can I stop employees from editing vendor bank details in QuickBooks Online?

In QuickBooks Online Advanced, use custom roles to give vendor edit rights to only a few people. With Bill Pay Elite, choose roles carefully: Bill Clerk and Bill Payer can both edit vendor details, Bill Approver cannot.

### Does QuickBooks Online notify me when a vendor's bank account changes?

Intuit's help documentation does not describe such an alert. Use the audit log, which records vendor edits with the user and date, and review it on a schedule.

### Where is the audit log in QuickBooks Online?

Go to Settings and select Audit log. You need admin access, and the audit log can't be turned off.

### Do QuickBooks approval workflows cover bank-detail changes?

Bill Pay Elite approval workflows are triggered by bills (amount, vendor, location), not by vendor record edits. Bank-detail changes need their own review and callback.

## Sources

- [QuickBooks: Set up roles and permissions for paying bills](https://quickbooks.intuit.com/learn-support/en-us/help-article/manage-workflows/set-roles-permissions-paying-bills-quickbooks-bill/L0Z0K2aXV_US_en_US)
- [QuickBooks: Add and manage custom roles in QuickBooks Online Advanced](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US)
- [QuickBooks: Use the audit log in QuickBooks Online](https://quickbooks.intuit.com/learn-support/en-us/help-article/audit-log/use-audit-log-quickbooks-online/L2WoVnW6I_US_en_US)
- [FBI IC3 PSA: Business Email Compromise: The $55 Billion Scam (Sep 11, 2024)](https://www.ic3.gov/PSA/2024/PSA240911)
- [J.P. Morgan: When callbacks go wrong (Feb 27, 2026)](https://www.jpmorgan.com/insights/cybersecurity/business-email-compromise/when-callbacks-go-wrong)

## Related

- [How to Verify a Vendor Bank Account Change (7 Steps)](https://realpayee.com/how-to-verify-a-vendor-bank-account-change) - How to verify a vendor bank account change, step by step: 7 rules, an evidence checklist, red flags, and where to lock down bank details in NetSuite, QuickBooks Online and Xero. (markdown: https://realpayee.com/how-to-verify-a-vendor-bank-account-change.md)
- [Callback Verification Policy Template (Free SOP for Vendor Bank Changes)](https://realpayee.com/templates/vendor-bank-change-policy) - Free callback verification policy template for vendor bank account changes: a full SOP with RACI, independent contact rule, callback script, evidence log and checklist. Download as Markdown or text. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)
- [NetSuite Vendor Bank Change Controls (7-Step Framework)](https://realpayee.com/guides/netsuite-vendor-bank-change-controls) - NetSuite vendor bank change controls: who can edit entity bank details, Payment Automation approval routing, system notes, saved search alerts, segregation of duties and an independent callback. (markdown: https://realpayee.com/guides/netsuite-vendor-bank-change-controls.md)
- [Xero Vendor Bank Change Controls and the Notification Gap](https://realpayee.com/guides/xero-vendor-bank-change-controls) - Xero supplier bank change controls: the bank account admin permission, the notification gap (only the editor is emailed), the Assurance dashboard, alert apps, payment review and callbacks. (markdown: https://realpayee.com/guides/xero-vendor-bank-change-controls.md)
- [Book a RealPayee demo](https://realpayee.com/demo) - Book a demo of RealPayee: see vendor bank-change and high-value wire verification on your NetSuite, QuickBooks or Xero payment flow. (markdown: https://realpayee.com/demo.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/guides/quickbooks-online-vendor-bank-change-controls · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
