Changed Bank Details? A Checklist for Accounting Teams
An email arrives during a busy payment run. It appears to come from a familiar supplier and asks the team to use a new bank account. The invoice looks normal, the amount is expected and the sender wants it paid today.
That is a useful situation to rehearse before it happens. Accounting teams need a process that works when the message looks convincing, not only when it contains obvious spelling errors.
Business email compromise can involve impersonation or a real mailbox that an attacker has accessed. The Australian Cyber Security Centre's explanation includes requests to change bank details among the warning signs. A familiar email thread is therefore a reason to investigate the request carefully, not sufficient proof that it is valid.
Separate the request from the approval
Treat a bank-detail change as a change to controlled supplier information. Do not let the person preparing a payment silently edit the account and approve the transfer in one step.
For a small firm, the process can be simple. One person records the request, another authorised person verifies it, and the payment approver checks that the verification is complete. If your practice only prepares files for a client, agree who at the client organisation owns the final approval.
Give staff a clear holding action: pause the affected payment and mark the change as unverified. An incomplete check should remain visible instead of disappearing into an inbox.
Do not grant broad access to full bank details just to make the process easier. Keep the request and approval evidence in the approved system with access limited to the people who need it.
Verify through a contact you already trust
Contact the supplier through an independently established channel. Use a number already held in approved records, not the number supplied in the change request or its attachment. If your existing records are uncertain, establish a trusted contact before proceeding.
Do not use an incoming call alone as verification. Have your team initiate the contact through the established channel and follow the firm's agreed identity checks. Avoid relying only on a recognisable voice or knowledge of the invoice.
Record the date, the person who completed the check, the verified contact and the approval outcome. The record should show how the change was verified without collecting unnecessary personal information.
For example, a fictional supplier named Harbour Office Supplies requests a new account. Your team pauses that supplier's payment, contacts the known accounts manager using the stored number, and asks an authorised colleague to review the outcome. The example is a rehearsal, not an actual client incident.
Practise the awkward cases
A procedure is easier to follow when staff have rehearsed the exceptions. Discuss what happens if the usual contact is on leave, the request comes from a partner, or the payment deadline is close.
Make it acceptable to delay a payment that cannot be verified. Name an escalation contact and a backup. Include supplier changes received through a portal or telephone call, not just email.
Supporting technical checks matter too. Ask your IT provider to review mailbox access, forwarding rules and sign-in protection. Our guide to multi-factor authentication explains the starting point. These controls support the payment process; they do not prove that an invoice is genuine.
Know who to call if money has moved
If a suspect payment has already been made, contact the financial institution immediately using its official contact details. Preserve the messages and payment references, and involve your IT provider. Follow the ACSC's business email compromise recovery guidance. Prompt action can help, but recovery of funds is not guaranteed.
Use one short team exercise this month to test who pauses, who verifies and who approves a changed account. If the technical controls or responsibilities are unclear, contact SuperStack IT to discuss the gaps before the next urgent request.