---
title: "How to Verify a Vendor Bank Account Change (7 Steps)"
description: "How to verify a vendor bank account change, step by step: 7 rules, an evidence checklist, red flags, and where to lock down bank details in NetSuite, QuickBooks Online and Xero."
url: https://realpayee.com/how-to-verify-a-vendor-bank-account-change
canonical: https://realpayee.com/how-to-verify-a-vendor-bank-account-change
date_published: 2026-10-06
date_modified: 2026-10-06
updated: 2026-10-06
author: "RealPayee"
site: RealPayee
---

# How to verify a vendor bank account change (step by step)

> To verify a vendor bank account change, **hold the change**, call the vendor on a **number you already had on file** (never one from the request), reach an **authorized person** and have them **state the new details** to you. Then validate the account, send notice to the vendor's known email, get a **second approver**, apply a **waiting period** and keep an evidence log before any payment goes to the new account.

_Updated 2026-10-06 · 8 min read_

## Key takeaways

- The core rule: **never verify a change using contact details from the request itself**, and treat recently changed contact details as unverified too.
- Ask the vendor to **state** the account details; reading them out and hearing "yes" proves nothing.
- A familiar voice is not proof. **Verify the person, not the channel.**
- Lock down who can edit vendor bank details in **NetSuite, QuickBooks Online or Xero**, and keep the person who edits apart from the person who pays.

## How to verify a vendor bank account change in 7 steps

1. **Hold the change.** Log the request (date, channel, sender, a copy of the message) but do not edit the vendor master file. Put any scheduled payment that would use the new details on hold.
2. **Use the contact already on file.** Take the phone number and named contact from records that existed before the request: the vendor master file, the signed contract or onboarding documents. Never use a phone number, email, link or QR code from the request. If the vendor's contact details also changed recently, verify that change first.
3. **Reach an authorized person.** Call and speak to the person at the vendor who is authorized to change payment instructions, not whoever answers the main line. An inbound call from the vendor is not a callback.
4. **Have them state the details.** Ask them to read the new bank name, routing number, account number and account holder name to you, and the reason for the change. Do not read the details out and ask them to confirm.
5. **Validate the account and use a second channel.** Check the account with your bank's or AP platform's account validation where available, and send a notice of the change to the vendor's previously known email address so the real vendor can object.
6. **Dual approval and a waiting period.** A second person who did not take the call approves the edit in the ERP. The change takes effect after a set waiting period, and the first payment to the new account is held or limited until the vendor confirms receipt.
7. **Log the evidence.** File the request, the number dialed and its source, who confirmed and what they stated, the validation result, the second-channel notice and both approvals with the vendor record.

> [!WARNING]
> **The number on file can be compromised too**
> If an attacker controls a vendor's mailbox, they may first send "new contact details" and only later the bank change, so a callback rings them. Contact-detail changes need the same verification as bank changes. See [is a callback enough?](https://realpayee.com/answers/is-a-callback-enough-to-stop-vendor-fraud)

## Evidence checklist

Keep this with the vendor record for every change. Auditors and cyber insurers ask for exactly these items.

- ☐ Copy of the original request, with date, channel and sender
- ☐ Confirmation that the vendor record was not edited before verification
- ☐ Number dialed and where it came from (vendor master, contract, onboarding form)
- ☐ Name and title of the authorized person reached, date and time
- ☐ Details as stated by the vendor, and that they match the request
- ☐ Account validation method and result
- ☐ Notice sent to the previously known vendor email address
- ☐ Approver name and date (not the person who made the call)
- ☐ Waiting period end date and first-payment receipt confirmation

## Red flags that should stop the change

- Urgency, or a request to pay overdue invoices to the new account right away.
- A request to keep the change quiet, or to avoid calling.
- A new phone number or contact supplied "for verification".
- Sender domain or reply-to address that differs slightly from the vendor's usual one.
- Account holder name that differs from the vendor's legal name, or a new bank in a different country.
- Contact details changed shortly before the bank details.
- The known contact is suddenly unreachable, or a different person insists on confirming.

## Where vendor bank details live in your ERP (and who can edit them)

Verification only works if nobody can quietly change the details afterwards. Restrict editing of vendor bank details to a small group, keep that group separate from the people who release payments, and review changes on a schedule. Menu names change between versions, so confirm against your own account. Full control frameworks: [NetSuite](https://realpayee.com/guides/netsuite-vendor-bank-change-controls), [QuickBooks Online](https://realpayee.com/guides/quickbooks-online-vendor-bank-change-controls) and [Xero](https://realpayee.com/guides/xero-vendor-bank-change-controls).

### NetSuite

- With the Electronic Bank Payments SuiteApp, a vendor's bank accounts are stored as **entity bank details** on the **Bank Payment Details** subtab of the vendor record (Lists > Relationships > Vendors).
- Access to entity bank details is set through role permissions. Give edit access only to a small, named role and view access to everyone else who needs it.
- Review changes to entity bank details regularly, for example with a saved search, and compare them with your evidence log.

### QuickBooks Online

- Vendor payment details for online bill pay sit with the vendor in QuickBooks.
- In **QuickBooks Online Advanced** you can build custom roles where modifying vendors and paying bills are separate permissions. With QuickBooks Bill Pay Elite or Advanced, standard roles such as **Bill clerk** (adds and edits vendors) and **Bill payer** (pays bills and edits vendor details) and bill approval workflows are available.
- Do not give the same user both vendor editing and payment rights. On plans without custom roles, keep the number of users who can edit vendors to a minimum and review the audit log.

### Xero

- A supplier's bank account is stored on the contact record.
- Only users with the **bank account admin** permission can add or edit bank account details for a contact. It can be added to standard, adviser, invoice only (purchases) and invoice only (approve & pay) roles, by a user with manage users permission.
- Grant it to as few people as possible and review contact bank detail changes regularly.

[RealPayee](https://realpayee.com/demo) watches for vendor bank-detail changes in NetSuite, QuickBooks, Xero, Bill.com and Ramp, holds them, and releases them only after the vendor's known contact confirms out-of-band, with the evidence log filled in automatically.

## Verify the person, not the channel

Each step above protects against a channel being faked: a spoofed email, a number in the request, a cloned voice. The underlying question is whether the real, authorized person at the vendor asked for this exact change. Write the rules into a policy with our free [callback verification policy template](https://realpayee.com/templates/vendor-bank-change-policy), and compare tools in [best vendor verification software for mid-size companies](https://realpayee.com/best-vendor-verification-software).

## How to verify a vendor bank account change

1. **Hold the change** - Log the request (date, channel, sender, a copy of the message) but do not edit the vendor master file. Put any scheduled payment that would use the new details on hold.
2. **Use the contact already on file** - Take the phone number and named contact from records that existed before the request: the vendor master file, the signed contract or onboarding documents. Never use a phone number, email, link or QR code from the request. If the vendor's contact details also changed recently, verify that change first.
3. **Reach an authorized person** - Call and speak to the person at the vendor who is authorized to change payment instructions, not whoever answers the main line. An inbound call from the vendor is not a callback.
4. **Have them state the details** - Ask them to read the new bank name, routing number, account number and account holder name to you, and the reason for the change. Do not read the details out and ask them to confirm.
5. **Validate the account and use a second channel** - Check the account with your bank's or AP platform's account validation where available, and send a notice of the change to the vendor's previously known email address so the real vendor can object.
6. **Dual approval and a waiting period** - A second person who did not take the call approves the edit in the ERP. The change takes effect after a set waiting period, and the first payment to the new account is held or limited until the vendor confirms receipt.
7. **Log the evidence** - File the request, the number dialed and its source, who confirmed and what they stated, the validation result, the second-channel notice and both approvals with the vendor record.

## Frequently asked questions

### Is an email confirmation from the vendor enough?

No. If the vendor's mailbox is compromised, the attacker can reply to your confirmation email. Confirm on a separate channel with a contact you already had.

### What if the vendor contact on file has left?

Verify the new contact through a second known person at the vendor, such as their finance lead or account manager, using details you already hold, before accepting them as the new contact.

### Should I send a test payment to the new account?

A small test payment proves the account works, not that the real vendor asked for it. Use it only in addition to the callback, and confirm receipt with the known contact.

### Do I need to verify every change, even small vendors?

Yes. Small vendors are often easier to impersonate and their payments still add up. Apply the same rule to every bank-detail change.

### How long should the waiting period be?

Long enough for the real vendor to see the notice and object, often one to two business days. Set it in your written policy so nobody shortens it under pressure.

## Sources

- [Oracle NetSuite help: Setting up primary bank for customer and vendor accounts (Bank Payment Details subtab)](https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_157974753932.html)
- [QuickBooks: Set up roles and permissions for paying bills](https://quickbooks.intuit.com/learn-support/en-us/help-article/manage-workflows/set-roles-permissions-paying-bills-quickbooks-bill/L0Z0K2aXV_US_en_US)
- [Xero Central: Give users the bank account admin permission](https://central.xero.com/s/article/Give-Contact-Bank-Account-Admin-permission-to-a-user)
- [J.P. Morgan: When callbacks go wrong (Feb 27, 2026)](https://www.jpmorgan.com/insights/cybersecurity/business-email-compromise/when-callbacks-go-wrong)

## Related

- [/answers/is-a-callback-enough-to-stop-vendor-fraud](https://realpayee.com/answers/is-a-callback-enough-to-stop-vendor-fraud) (markdown: https://realpayee.com/answers/is-a-callback-enough-to-stop-vendor-fraud.md)
- [Callback Verification Policy Template (Free SOP for Vendor Bank Changes)](https://realpayee.com/templates/vendor-bank-change-policy) - Free callback verification policy template for vendor bank account changes: a full SOP with RACI, independent contact rule, callback script, evidence log and checklist. Download as Markdown or text. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Vendor verification: how to verify vendor bank details before you pay](https://realpayee.com/vendor-verification) - A practical guide to vendor verification for finance teams: how to confirm vendor bank-detail changes, run callbacks, and prevent vendor impersonation fraud. (markdown: https://realpayee.com/vendor-verification.md)
- [Best Vendor Verification Software for Mid-Size Companies (2026)](https://realpayee.com/best-vendor-verification-software) - Vendor verification software for mid-size finance teams, compared: RealPayee, Trustpair, Eftsure, nsKnox, Trustmi, PaymentWorks, Sis ID, BILL, Ramp and more. Integrations, US vs global, watch-outs. (markdown: https://realpayee.com/best-vendor-verification-software.md)
- [Book a RealPayee demo](https://realpayee.com/demo) - Book a demo of RealPayee: see vendor bank-change and high-value wire verification on your NetSuite, QuickBooks or Xero payment flow. (markdown: https://realpayee.com/demo.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/how-to-verify-a-vendor-bank-account-change · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
