Supplier bank change controls that actually catch fraud
· Daniel Okoro
Payment diversion fraud thrives on weak supplier master data. An attacker who changes a bank account in the vendor file can intercept legitimate invoices without inventing a fake supplier.
Test your control with a recent sample of bank detail amendments. For each change, ask: who requested it, how was the request verified with the supplier using known contact details, who approved it, and who was blocked from both requesting and approving? If verification used only the email on the change request itself, the control is circular.
Document the verification method on the change record. Call-backs to a number already on file, or a portal confirmation from a known contact, leave a trail. Forwarded PDFs of invoices with new bank details do not.
Review access quarterly. Buyers who can edit supplier banking details while also approving invoices concentrate risk that no policy paragraph will offset.