---
title: "Xero Vendor Bank Change Controls and the Notification Gap"
description: "Xero supplier bank change controls: the bank account admin permission, the notification gap (only the editor is emailed), the Assurance dashboard, alert apps, payment review and callbacks."
url: https://realpayee.com/guides/xero-vendor-bank-change-controls
canonical: https://realpayee.com/guides/xero-vendor-bank-change-controls
date_published: 2026-10-06
date_modified: 2026-10-06
updated: 2026-10-06
author: "RealPayee"
site: RealPayee
---

# Xero vendor bank change controls: closing the notification gap

> **In Xero, limit the bank account admin permission, then close the notification gap.** Xero emails a confirmation when a contact's bank details change, but users report it reaches only the person who made the change, and Xero said on September 29, 2026 that letting organisations choose recipients isn't on the roadmap yet. Review the Assurance dashboard on a schedule or use an alert app, verify every change by calling a known contact, and hold the first payment.

_Updated 2026-10-06 · 6 min read_

## Key takeaways

- Only users with **bank account admin** can add or edit a contact's bank details. Keep that list short.
- Xero's change email goes to **the user who made the change**, per users on Xero's Product Ideas forum; choosing other recipients is **not on the roadmap yet** (Xero, Sep 29, 2026).
- The **Assurance dashboard** (adviser role) lists contacts with edited or identical bank details, with the user and date.
- Third-party apps such as **VendorAlert** alert the people you choose. None of these confirm the real supplier asked.

## The short version

Xero's permission model is simple and effective: one permission controls who can change supplier bank details. The weak point is visibility. If the only person told about a change is the person who made it, a fraudster who tricks that person (or an insider) meets no second pair of eyes. Every Xero control set should answer one question: **who other than the editor sees each bank change before money moves?**

## Xero supplier bank change control framework (7 steps)

1. **Restrict the bank account admin permission.** In Xero, only users with the **bank account admin** permission can add or edit a contact's bank account details. It can be added to the standard, adviser, invoice only (purchases) and invoice only (approve & pay) roles by a user with manage users permission. Give it to as few people as possible.
2. **Close the notification gap.** Xero sends an email when a contact's bank account details change, but users on Xero's Product Ideas forum report it goes only to the user who made the change. The idea to let organisations choose who is notified has 261 votes, and in its September 29, 2026 response Xero said the work "isn't directly on the roadmap just yet". Until that changes, someone other than the editor must see every change: a scheduled review or an alert app.
3. **Review changes on the Assurance dashboard.** Users with the adviser role can open the Assurance dashboard, whose Contacts tab lists contacts whose bank account details were edited (number of edits, date last edited and the user) and contacts that share identical bank details. The History and notes report shows changes with the date and the user who made them.
4. **Verify every change out-of-band.** Hold the change, call the supplier on a number from your records that existed before the request, reach an authorized person and have them state the new details. Never use contact details from the request.
5. **Separate editing from approving and paying.** The person with bank account admin should not be the person who approves or pays bills to that supplier. If one person does both in a small team, add an owner or adviser review of every bank-detail change before the next payment.
6. **Review the payment batch and hold first payments.** Before paying, check the batch against suppliers whose bank details changed since the last run. Apply a cooling-off period (for example 24 to 72 hours) and confirm receipt of the first payment with the known contact.
7. **Keep the evidence.** Record the request, the number dialed and its source, who confirmed, who approved and when, and keep it with the contact or in your ticket system.

## The notification gap, in detail

| Question | What we found (checked October 6, 2026) |
| --- | --- |
| Does Xero send an email when a contact's bank details change? | Yes, an email to check the change is valid |
| Who receives it? | The user who made the change, per users on Xero's Product Ideas forum |
| Can you choose other recipients? | Not natively. The idea "Set which users to receive Bank account change notification" has 261 votes |
| Is it planned? | Xero (Sep 29, 2026): "this work isn't directly on the roadmap just yet", but the idea is "on our radar" |
| Native workaround | Assurance dashboard (adviser role) and History and notes report, reviewed on a schedule |
| Third-party option | Alert apps on the Xero App Store, for example VendorAlert |

**VendorAlert**, listed on the Xero App Store, says it alerts "the people you choose, not only the person who made the edit", connects with read-only access, checks about every six hours, on manual sync and when Xero sends contact updates, and keeps an exportable audit trail. We have not tested it; check its current listing before relying on it.

> [!WARNING]
> **An alert is not verification**
> An alert tells a second person that bank details changed. It does not tell them whether the real supplier asked. The callback to a known contact is still the step that stops the fraud.

## Where RealPayee fits

[RealPayee](https://realpayee.com/demo) sits on top of these Xero controls. It watches for vendor bank-detail changes and payments above your threshold, holds them, and asks the vendor's **known contact** (enrolled before the request) or the real executive to confirm out-of-band by SMS, Slack or Microsoft Teams, with phone-bound approval or government ID plus live selfie. The evidence (who confirmed, how, when) is attached automatically. It does not move money, does not validate account ownership against bank data, and does not replace the permission and segregation-of-duties steps above.

Put the rules in writing with the free [callback verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) and follow the [step-by-step verification procedure](https://realpayee.com/how-to-verify-a-vendor-bank-account-change). Other ERPs: [NetSuite](https://realpayee.com/guides/netsuite-vendor-bank-change-controls) and [QuickBooks Online](https://realpayee.com/guides/quickbooks-online-vendor-bank-change-controls).

## Xero supplier bank change controls

1. **Restrict the bank account admin permission** - In Xero, only users with the **bank account admin** permission can add or edit a contact's bank account details. It can be added to the standard, adviser, invoice only (purchases) and invoice only (approve & pay) roles by a user with manage users permission. Give it to as few people as possible.
2. **Close the notification gap** - Xero sends an email when a contact's bank account details change, but users on Xero's Product Ideas forum report it goes only to the user who made the change. The idea to let organisations choose who is notified has 261 votes, and in its September 29, 2026 response Xero said the work "isn't directly on the roadmap just yet". Until that changes, someone other than the editor must see every change: a scheduled review or an alert app.
3. **Review changes on the Assurance dashboard** - Users with the adviser role can open the Assurance dashboard, whose Contacts tab lists contacts whose bank account details were edited (number of edits, date last edited and the user) and contacts that share identical bank details. The History and notes report shows changes with the date and the user who made them.
4. **Verify every change out-of-band** - Hold the change, call the supplier on a number from your records that existed before the request, reach an authorized person and have them state the new details. Never use contact details from the request.
5. **Separate editing from approving and paying** - The person with bank account admin should not be the person who approves or pays bills to that supplier. If one person does both in a small team, add an owner or adviser review of every bank-detail change before the next payment.
6. **Review the payment batch and hold first payments** - Before paying, check the batch against suppliers whose bank details changed since the last run. Apply a cooling-off period (for example 24 to 72 hours) and confirm receipt of the first payment with the known contact.
7. **Keep the evidence** - Record the request, the number dialed and its source, who confirmed, who approved and when, and keep it with the contact or in your ticket system.

## Frequently asked questions

### Who gets notified when supplier bank details change in Xero?

Xero sends an email to check the change is valid. Users on Xero's Product Ideas forum report that it goes only to the user who made the change, and choosing other recipients is not currently available.

### Is Xero adding notifications to other users?

In a September 29, 2026 response to the product idea, Xero said the work "isn't directly on the roadmap just yet" but is "on our radar". Check the idea page for updates.

### Who can change a contact's bank details in Xero?

Only users with the bank account admin permission. It can be added to the standard, adviser, invoice only (purchases) and invoice only (approve & pay) roles by a user with manage users permission.

### How do I see which supplier bank details were changed in Xero?

Users with the adviser role can use the Contacts tab of the Assurance dashboard, which lists contacts with edited bank details, the number of edits, the date last edited and the user. The History and notes report also shows changes by date and user.

### Does an alert app like VendorAlert stop the fraud?

It closes the visibility gap by telling the people you choose about a change. You still need to verify the change with the supplier's known contact before paying.

## Sources

- [Xero Central: Give users the bank account admin permission](https://central.xero.com/s/article/Give-Contact-Bank-Account-Admin-permission-to-a-user)
- [Xero Product Ideas: Email Settings - Set which users to receive Bank account change notification (Xero response Sep 29, 2026)](https://productideas.xero.com/forums/967121-users-setup/suggestions/44961091-email-settings-set-which-users-to-receive-bank-a)
- [Xero Central: The Assurance dashboard explained](https://central.xero.com/0/article/Assurance-dashboard-explanation)
- [Xero Central: History and notes report](https://central.xero.com/0/article/View-a-history-and-notes-summary-for-transactions-and-user-activity)
- [Xero App Store: VendorAlert](https://apps.xero.com/nz/app/vendoralert)
- [FBI IC3 PSA: Business Email Compromise: The $55 Billion Scam (Sep 11, 2024)](https://www.ic3.gov/PSA/2024/PSA240911)

## Related

- [How to Verify a Vendor Bank Account Change (7 Steps)](https://realpayee.com/how-to-verify-a-vendor-bank-account-change) - How to verify a vendor bank account change, step by step: 7 rules, an evidence checklist, red flags, and where to lock down bank details in NetSuite, QuickBooks Online and Xero. (markdown: https://realpayee.com/how-to-verify-a-vendor-bank-account-change.md)
- [Callback Verification Policy Template (Free SOP for Vendor Bank Changes)](https://realpayee.com/templates/vendor-bank-change-policy) - Free callback verification policy template for vendor bank account changes: a full SOP with RACI, independent contact rule, callback script, evidence log and checklist. Download as Markdown or text. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)
- [NetSuite Vendor Bank Change Controls (7-Step Framework)](https://realpayee.com/guides/netsuite-vendor-bank-change-controls) - NetSuite vendor bank change controls: who can edit entity bank details, Payment Automation approval routing, system notes, saved search alerts, segregation of duties and an independent callback. (markdown: https://realpayee.com/guides/netsuite-vendor-bank-change-controls.md)
- [QuickBooks Online Vendor Bank Change Controls (7-Step Framework)](https://realpayee.com/guides/quickbooks-online-vendor-bank-change-controls) - QuickBooks Online vendor bank change controls: custom roles, Bill Pay roles, approval workflows, the audit log, payment review and an independent callback to the vendor. (markdown: https://realpayee.com/guides/quickbooks-online-vendor-bank-change-controls.md)
- [Book a RealPayee demo](https://realpayee.com/demo) - Book a demo of RealPayee: see vendor bank-change and high-value wire verification on your NetSuite, QuickBooks or Xero payment flow. (markdown: https://realpayee.com/demo.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/guides/xero-vendor-bank-change-controls · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
