---
title: "Vendor verification: how to verify vendor bank details before you pay"
description: "A practical guide to vendor verification for finance teams: how to confirm vendor bank-detail changes, run callbacks, and prevent vendor impersonation fraud."
url: https://realpayee.com/vendor-verification
canonical: https://realpayee.com/vendor-verification
date_published: 2026-10-05
date_modified: 2026-10-05
updated: 2026-10-05
author: "RealPayee"
site: RealPayee
---

# Vendor verification: how to verify vendor bank details before you pay

> **Vendor verification** is the process of confirming that a supplier is real and that the bank details you are about to pay actually belong to it. In practice it means checking new vendors at onboarding and, above all, confirming every bank-detail change **out-of-band** - calling a known contact on a number from your own vendor master file, never one from the request - before any payment is released.

_Updated 2026-10-05 · 9 min read_

## Key takeaways

- Most vendor payment fraud happens at the **change request**, not at onboarding: a criminal impersonates a real supplier and asks you to update its bank details.
- Verify every change using contact details you **already had on file** - never the phone number, email or link in the request itself.
- Bank account verification (micro-deposits, Early Warning, Plaid Identity Match) confirms the account belongs to the business; a callback confirms the **request came from the real person**. You need both.
- Hold the first payment to new details, require a **second approver**, and keep an audit record of who verified what, when and how.

## What is vendor verification?

Vendor verification is the set of checks a finance team runs to make sure that a supplier exists, that it is who it says it is, and that payments go to an account it controls. It happens at two moments in the vendor lifecycle:

- **Onboarding** - confirming the legal entity, tax ID (a TIN match against the W-9), address, sanctions status and initial bank details before the vendor is created in your ERP.
- **Maintenance** - confirming any later change to the vendor record, especially bank account, remit-to address and contact details. This is where most money is lost.

Onboarding checks are well understood and often automated. Change verification is where teams cut corners, because a change request usually looks like routine admin: a polite email from a familiar contact, on a familiar thread, with a letter on company letterhead attached.

## Why vendor bank-detail changes are the highest-risk moment

Business email compromise (BEC) remains the costliest form of business payment fraud. The FBI's Internet Crime Complaint Center (IC3) recorded roughly **$3.0 billion** in BEC losses across 24,768 complaints in 2025 - an average of about $123,000 per complaint - up from $2.77 billion across 21,442 complaints in 2024. In the AFP's 2025 payments fraud survey, **45% of organizations reported vendor imposter fraud**, up 11 points from the prior year.

The pattern is consistent. A fraudster gains access to a supplier's mailbox (or registers a lookalike domain), watches real invoice threads, then sends a request to “update our remittance details”. If AP updates the vendor master file, the next payment run sends real money for real invoices to a mule account. Nobody notices until the genuine vendor chases an unpaid invoice, often weeks later, when the funds are long gone.

### Red flags in a bank-detail change request

- The request arrives by email only, or asks you to reply to a different address than usual.
- The sender's domain is slightly different (an extra letter, a different top-level domain, a free email provider).
- Urgency: “please update before this week's payment run” or “our old account is frozen”.
- The new account is in a different country, a different bank, or a different legal name than the vendor.
- The change arrives together with an overdue-invoice reminder or a request to pay outstanding invoices immediately.
- The contact discourages a call (“I'm travelling, email is best”) or supplies a new phone number to call.
- The bank-change letter is a PDF with no signature you can match, or the formatting differs from earlier documents.

## How to verify vendor bank details: step by step

Use this procedure for every request to add or change a vendor's bank account, whatever the amount and however familiar the sender. Consistency is the control: fraudsters target the exceptions.

1. **Freeze the change.** Log the request, but do not edit the vendor master file yet. Any payment already scheduled to that vendor stays on the old details or is put on hold.
2. **Pull the contact from your own records.** Look up the vendor's phone number and a named contact from the vendor master file, the signed contract or a previous invoice you already trust - never from the email, letter or PDF that asked for the change.
3. **Call back and confirm the details.** Call the known contact, ask them to read the new routing and account number to you (do not read it to them), and ask why the account changed. Note the name, number dialed, date and time.
4. **Validate the account.** Run a bank account verification check - a micro-deposit, your bank's account-validation service, or your AP platform's built-in check - to confirm the account is open and owned by the vendor's legal entity.
5. **Get a second approval.** A second person, who did not take the call, reviews the evidence and approves the change in the ERP. The person who requested or entered the change cannot approve it.
6. **Notify the vendor through the old channel.** Send a confirmation to the vendor's previously known email address so the real vendor can object if it did not ask for the change.
7. **Watch the first payment.** Hold or limit the first payment to the new account, or confirm receipt with the vendor before larger payments follow.
8. **Keep the audit record.** Store the request, the callback notes, the validation result and both approvals with the vendor record so auditors and insurers can see exactly who verified what.

> [!WARNING]
> **Never verify through the request**
> Replying to the email, calling the number in the signature or clicking a “confirm your details” link only reaches the fraudster. Out-of-band means a channel and contact details the requester could not have supplied.

### Sample callback script

1. “Hi, this is [your name] from [company] accounts payable. I'm calling the number we have on file for [vendor] to confirm a change to your payment details. Is this a good time?”
2. “We received a request on [date] to change your bank account. Did you or your team send it?” - If they did not, stop and escalate as attempted fraud.
3. “Please read me the new routing number and account number.” - Compare with the request. Do not read the numbers to them.
4. “What is the reason for the change, and what name is the new account held under?”
5. “Who else at your company can confirm this?” - For large vendors, confirm with a second contact from your records.
6. “Thank you. We'll send confirmation to the email address we have on file, and the change will take effect after internal approval.”

Record the date, time, number dialed, the person you spoke to and their answers. The full script, with exception handling, is in our free [vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy).

## Bank account verification methods compared

“Bank account verification” and “vendor verification” are often used interchangeably, but they answer different questions. Account verification asks: does this account exist, and does it belong to this business? Person verification asks: did the real vendor actually ask for this? A fraudster can open a real account in a plausible name, so the strongest programs layer both.

| Method | What it confirms | What it misses | Typical use |
| --- | --- | --- | --- |
| Callback to a known contact | The real vendor made the request | Weak if the number came from the request, or if the call is rushed or skipped | Every bank-detail change |
| Micro-deposits / penny test | The account is open and can receive funds | Who owns it; who asked for the change | Onboarding, AP platforms such as Bill.com |
| Account-ownership validation (e.g. Early Warning Verify Account, Plaid Identity Match) | The account is open and the owner name matches the vendor | Whether the request was legitimate; coverage gaps for some banks and foreign accounts | Onboarding and changes, often built into AP suites such as Ramp |
| Payee name check / Positive Pay | Checks or ACH items match what you issued | Wires and changes made upstream in the vendor master file | Bank-side, at payment time |
| Vendor portal with MFA | The change came from an authenticated vendor user | Compromised vendor accounts; vendors who do not use the portal | Larger AP teams |
| Person verification (phone-bound approval or ID + live selfie) | The real, known person approved this specific change | Account ownership - pair it with account validation | Bank changes and high-value wires |

## What to include in a vendor verification form

A vendor verification form standardizes what you collect and what you checked. Use one for every new vendor and every bank change, and keep the completed form with the vendor record:

- Vendor legal name, DBA, tax ID and the date the W-9 was received and TIN-matched.
- Requested change: old and new bank name, routing number, last four digits of the account number, account holder name.
- How the request arrived (email, portal, letter) and the sender's address.
- Callback evidence: contact name, number dialed and where it came from (vendor master, contract), date, time, outcome.
- Account validation result and method used.
- Preparer and approver names, with dates - two different people.
- First-payment confirmation: date and whether the vendor confirmed receipt.

## Vendor verification controls by risk level

Not every change needs the same effort, but no bank change should skip out-of-band confirmation. Scale the extra checks to the exposure:

| Situation | Minimum controls | Approval |
| --- | --- | --- |
| New vendor, low spend | TIN match, account validation, callback to contact from contract or website you independently found | AP manager |
| Bank change, any vendor | Freeze, callback to known contact, account validation, notice to old email | Preparer + second approver |
| Bank change, top-spend vendor or open invoices above your threshold | All of the above plus a second contact or person verification, and a hold on the first payment | Controller |
| Change requested together with urgent payment | Treat as suspected fraud until verified; no payment until callback completes | Controller or CFO |
| Foreign or newly opened account | Enhanced review of the reason for the change and account ownership | Controller |

## Common vendor verification mistakes

- **Calling the number in the email signature.** If the mailbox is compromised, so is the signature.
- **Reading the account number to the vendor.** A fraudster will happily say “yes, that's right”. Ask them to read it to you.
- **Verifying once, then trusting the thread.** A compromised thread can request a second change a month later.
- **Letting urgency override the procedure.** Every exception you make is the exception attackers are looking for.
- **No evidence.** If the callback is not documented, auditors and insurers will treat it as not done.
- **Treating account validation as the whole answer.** A mule account in a plausible name can pass an ownership check.

## Where RealPayee fits

Manual callbacks work when they are actually done, done well and written down - which is hard to guarantee at month-end. [RealPayee](https://realpayee.com) automates the person-verification step: a vendor bank-detail change in NetSuite, QuickBooks or Xero (or Bill.com or Ramp) triggers a hold, the vendor's known contact verifies out-of-band with a phone-bound approval or ID plus live selfie, and the change is released or blocked with an audit record attached. It complements the account-validation checks you may already use. See the [comparison of approaches](https://realpayee.com/compare).

## How to verify a vendor bank-detail change

1. **Freeze the change** - Log the request, but do not edit the vendor master file yet. Any payment already scheduled to that vendor stays on the old details or is put on hold.
2. **Pull the contact from your own records** - Look up the vendor's phone number and a named contact from the vendor master file, the signed contract or a previous invoice you already trust - never from the email, letter or PDF that asked for the change.
3. **Call back and confirm the details** - Call the known contact, ask them to read the new routing and account number to you (do not read it to them), and ask why the account changed. Note the name, number dialed, date and time.
4. **Validate the account** - Run a bank account verification check - a micro-deposit, your bank's account-validation service, or your AP platform's built-in check - to confirm the account is open and owned by the vendor's legal entity.
5. **Get a second approval** - A second person, who did not take the call, reviews the evidence and approves the change in the ERP. The person who requested or entered the change cannot approve it.
6. **Notify the vendor through the old channel** - Send a confirmation to the vendor's previously known email address so the real vendor can object if it did not ask for the change.
7. **Watch the first payment** - Hold or limit the first payment to the new account, or confirm receipt with the vendor before larger payments follow.
8. **Keep the audit record** - Store the request, the callback notes, the validation result and both approvals with the vendor record so auditors and insurers can see exactly who verified what.

## Frequently asked questions

### What is vendor verification?

Vendor verification is confirming that a supplier is legitimate and that the bank account you pay belongs to it. It covers onboarding checks (legal entity, tax ID, sanctions, bank details) and, most importantly, out-of-band confirmation of any later change to bank or remittance details.

### How do I verify vendor bank details?

Freeze the change, call the vendor on a phone number from your own records (not from the request), ask them to read the new account details to you, validate the account with a micro-deposit or account-validation service, have a second person approve, and keep the evidence with the vendor record.

### Is a micro-deposit enough to verify a vendor's bank account?

No. A micro-deposit proves the account exists and can receive money; it does not prove who owns it or that the real vendor asked for the change. Pair it with a callback to a known contact or another form of person verification.

### What is a vendor verification form?

A standard form that records the vendor's details, the requested change, how it was verified (callback contact, number, time), the account-validation result and the preparer and approver. Our [policy template](https://realpayee.com/templates/vendor-bank-change-policy) includes the fields to capture.

### Who should approve vendor bank-detail changes?

Someone other than the person who received or entered the change. Many teams require AP manager approval for routine changes and controller approval for top vendors or when open invoices exceed a set threshold.

### How often should we re-verify existing vendors?

Re-verify whenever bank, remit-to or contact details change, and review dormant vendors before they are paid again. Many teams also run a periodic vendor master review to remove inactive vendors and spot unexpected changes.

## Sources

- [McDonald Hopkins - The sobering truth of the FBI's 2025 Internet Crime Complaint Center report](https://www.mcdonaldhopkins.com/insights/news/the-sobering-truth-of-the-fbis-2025-internet-crime-complaint-center-report)
- [Nacha - FBI's IC3 finds almost $8.5 billion lost to business email compromise in last three years](https://www.nacha.org/news/fbis-ic3-finds-almost-85-billion-lost-business-email-compromise-last-three-years)
- [AFP - Survey: 79 percent of organizations were victims of attempted or actual payments fraud in 2024](https://www.financialprofessionals.org/about/learn-more/press-releases/Details/survey-79-percent-of-organizations-were-victims-of-attempted-or-actual-payments-fraud-activity-in-2024)

## Related

- [Free vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) - A free, copy-ready vendor bank-detail change and callback verification policy template plus checklist for AP teams. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Vendor fraud: types, examples and how to prevent it](https://realpayee.com/vendor-fraud) - What vendor fraud is, the most common schemes (vendor impersonation, fake bank changes, fake invoices) and the controls that stop them. (markdown: https://realpayee.com/vendor-fraud.md)
- [Compare: manual callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare) - An honest comparison of approaches to stopping vendor-impersonation and fake payment requests. (markdown: https://realpayee.com/compare.md)
- [Payment fraud glossary](https://realpayee.com/glossary) - Plain-English definitions of payment fraud and verification terms: BEC, vendor impersonation, callback verification, positive pay and more. (markdown: https://realpayee.com/glossary.md)

---

**Facts:** RealPayee holds vendor bank-detail changes and high-value payment requests in NetSuite, QuickBooks, Xero, Bill.com, Ramp until the real person confirms via SMS, Slack, Microsoft Teams. It does not move money or hold funds. Pricing: Starter $250/mo, Growth From $750/mo, Enterprise Custom. Demo: https://realpayee.com/demo#book

**Further reading**
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Vendor fraud: types and controls](https://realpayee.com/vendor-fraud.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/vendor-verification · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
