A vendor emailed asking me to send their payments to a new bank account — how do I verify that before I pay?
Source-verified · Reviewed 2026-09-13 · How we verify answers
- [United States · financial institutions (banks, credit unions, wealth managers and insurance companies)] Travelers lists, among practical steps financial institutions can take, treating requests to change payment instructions as high risk.
- [United States · financial institutions (banks, credit unions, wealth managers and insurance companies)] Travelers lists, among practical steps financial institutions can take, verifying changes using contact information already on file rather than contact information supplied in the request itself.
- [United States · businesses and individuals seeking to guard against BEC] Among the tips the IC3 gives for remaining on guard against BEC, it advises using secondary channels or two-factor authentication to verify requests for changes in account information with the intended recipient; the page does not state how the secondary channel or its contact details are to be obtained.
- [United States · financial institutions (banks, credit unions, wealth managers and insurance companies)] Travelers states that documented procedures help provide consistency across teams and channels, and that predetermined callback requirements, separation of duties and standardized escalation paths help reduce reliance on individual judgment under pressure.
What this page establishes
- The recognised control expectation for a vendor banking-detail change — Not established
- What the FBI's guidance says about this fraud and where to report it — Partly established
- What your bank or the payment network can attempt to get the money back — Partly established
- Where the banking details live in your accounting or bill-pay platform — Not established
- The bookkeeping behind an unpaid vendor balance — Not established
- Whether insurance responds to a loss like this — Not established
- Holding payments to that vendor while the change is pending — Not established
- Why changing where the money goes is a control event, not an admin update — Not established
- Verify through a channel you already had, not one the email gives you — Not established
- What the verification has to settle before the change is made — Not established
- What raises the level of scrutiny on a request — Not established
- Who approves the change — and why it cannot be the person who received the email — Not established
- What you write down about the change and the verification — Not established
- Payments already scheduled or in flight when the request arrives — Not established
- If the payment has already gone out: what to do first — Not established
- Who you notify, and what each notification needs to contain — Partly established
- Recording the payment and whether the vendor is still owed the money — Not established
- The standing procedure that applies to every such request — Not established
Verify through a channel you already had, not one the email gives you
Travelers lists, among practical steps financial institutions can take, verifying changes using contact information already on file rather than contact information supplied in the request itself. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: presented as a practical step institutions ‘can take’)
“Verify changes using contact information already on file rather than information provided in the request.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Practical steps financial institutions can take to reduce social engineering risk”, bullet 2. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers lists, among practical steps financial institutions can take, using out-of-band communication – confirming an unexpected request through a different trusted channel, given as an example calling a known phone number rather than replying to the email. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: presented as a practical step institutions ‘can take’; calling a known number is given as an example (‘such as’), not the only method)
“Use out-of-band communication by confirming unexpected requests through a different trusted channel, such as calling a known phone number instead of replying to an email.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Practical steps financial institutions can take to reduce social engineering risk”, bullet 4. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Among the tips the IC3 gives for remaining on guard against BEC, it advises using secondary channels or two-factor authentication to verify requests for changes in account information with the intended recipient; the page does not state how the secondary channel or its contact details are to be obtained. (jurisdiction: United States, entity_scope: businesses and individuals seeking to guard against BEC)
“Use secondary channels or two-factor authentication to verify requests for changes in account information with the intended recipient.”Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) — Business Email Compromise (BEC), ic3.gov public Crime Info page, no edition or version shown; snapshot retrieved 2026-09-09; Business Email Compromise (BEC) > Stay Protected (first bullet). Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that documented procedures help provide consistency across teams and channels, and that predetermined callback requirements, separation of duties and standardized escalation paths help reduce reliance on individual judgment under pressure. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: stated as measures that ‘help’, not as requirements)
“Documented procedures help provide consistency across teams and channels. Predetermined callback requirements, separation of duties and standardized escalation paths help reduce reliance on individual judgment under pressure.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “How a layered defense can help financial institutions protect themselves against social engineering”, sub-heading “Process – verification and consistency”, first paragraph. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard, primary regulator or government. Highest achieved: authoritative lender insurer or program documentation, primary regulator or government.
What the verification has to settle before the change is made
The IC3 states that the BEC scam is frequently — not invariably — carried out when a subject compromises legitimate business e-mail accounts through social engineering or computer intrusion techniques, resulting in an unauthorized transfer of funds. (jurisdiction: United States, entity_scope: businesses and individuals performing a transfer of funds)
“The scam is frequently carried out when a subject compromises legitimate business e-mail accounts through social engineering or computer intrusion techniques resulting in an unauthorized transfer of funds.”Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) — Business Email Compromise (BEC), ic3.gov public Crime Info page, no edition or version shown; snapshot retrieved 2026-09-09; Business Email Compromise (BEC) > What is BEC?. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers describes business email compromise as involving impersonation of executives, employees, customers, vendors or trusted partners in order to request payments or sensitive information. (jurisdiction: United States, entity_scope: organizations of all sizes and across industries, conditions: described within a financial-institution context)
“Business email compromise involves impersonating executives, employees, customers, vendors or trusted partners to request payments or sensitive information.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “What social engineering schemes affect financial institutions?”, sub-heading “Business email compromise (BEC)”, first sentence. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers lists, among practical steps financial institutions can take, requiring the requester to supply complete verification information without the employee offering hints or supplying missing details. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: presented as a practical step institutions ‘can take’)
“Require the requester to provide complete verification information without offering hints or missing details.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Practical steps financial institutions can take to reduce social engineering risk”, bullet 5. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that, for financial institutions, the rise of AI-assisted impersonation reinforces the importance of consistent verification procedures rather than relying solely on how genuine a request appears. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies))
“For financial institutions, where transaction authority and identity verification are central to operations, this reinforces the importance of consistent verification procedures rather than relying solely on how “real” a request appears.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “How are AI and deepfakes used in social engineering fraud?”, final paragraph. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard, primary regulator or government. Highest achieved: primary regulator or government.
What raises the level of scrutiny on a request
The FTC identifies as a scammer tactic pretending to be someone the target trusts, impersonating a company or government agency the target knows, in order to get the target to pay. (jurisdiction: United States, entity_scope: Small businesses and non-profit organizations in the United States (and their staff) targeted by scams, effective_from: 2023-07)
“Scammers pretend to be someone you trust. They impersonate a company or government agency you know to get you to pay.”Federal Trade Commission — Scams and Your Small Business: A Guide for Business, 2023-07; Section "Scammers' Tactics", first listed tactic. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
The FTC identifies as a scammer tactic creating a sense of urgency, intimidation and fear, so that the target acts before having a chance to check out the scammer's claims. (jurisdiction: United States, entity_scope: Small businesses and non-profit organizations in the United States (and their staff) targeted by scams, effective_from: 2023-07)
“Scammers create a sense of urgency, intimidation, and fear. They want you to act before you have a chance to check out their claims.”Federal Trade Commission — Scams and Your Small Business: A Guide for Business, 2023-07; Section "Scammers' Tactics", second listed tactic. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
The FTC advises not trusting caller ID, because scammers often fake their phone numbers. (jurisdiction: United States, entity_scope: Small businesses and non-profit organizations in the United States (and their staff) targeted by scams, effective_from: 2023-07)
“Since scammers often fake their phone numbers, don’t trust caller ID.”Federal Trade Commission — Scams and Your Small Business: A Guide for Business, 2023-07; Section "Protect Your Business", sub-heading "Spot Tech-Related Scams". Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that voice cloning and deepfake technology can make it harder to rely on traditional cues – among them tone, familiarity or visual appearance – when assessing authenticity during phone or virtual interactions. (jurisdiction: United States, entity_scope: organizations of all sizes and across industries, conditions: cues listed as examples (‘such as’))
“Voice cloning and deepfake technology can make it harder to rely on traditional cues such as tone, familiarity or visual appearance when assessing authenticity during phone or virtual interactions.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “How are AI and deepfakes used in social engineering fraud?”, second paragraph. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers lists, among practical steps financial institutions can take, being cautious of urgency or pressure to bypass procedures. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: presented as a practical step institutions ‘can take’)
“Be cautious of urgency or pressure to bypass procedures.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Practical steps financial institutions can take to reduce social engineering risk”, bullet 3. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Why changing where the money goes is a control event, not an admin update
Travelers lists, among practical steps financial institutions can take, treating requests to change payment instructions as high risk. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: presented as a practical step institutions ‘can take’)
“Treat requests to change payment instructions as high risk.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Practical steps financial institutions can take to reduce social engineering risk”, bullet 1. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers describes fraudulent instruction schemes as involving impersonation of customers, authorized representatives or internal personnel to induce fund transfers, account changes or access approvals. (jurisdiction: United States, entity_scope: organizations of all sizes and across industries, conditions: described within a financial-institution context)
“Fraudulent instruction schemes involve impersonating customers, authorized representatives or internal personnel to induce fund transfers, account changes or access approvals.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “What social engineering schemes affect financial institutions?”, sub-heading “Fraudulent instructions and impersonation schemes”, first sentence. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard, primary regulator or government. Highest achieved: authoritative lender insurer or program documentation.
Who approves the change — and why it cannot be the person who received the email
The article states that the core principle of segregation of duties is that no one person should be able to abuse the system on their own, and gives as an example that the person receiving cash should not also be the person who records how much was received, deposits the funds, or reconciles the bank account. It is stated as a principle and a cash-handling example, not as a rule about vendor banking-detail changes. (jurisdiction: United States (AICPA & CIMA / Journal of Accountancy professional publication addressed to CPAs; the article itself states no jurisdictional limit), entity_scope: organizations generally, as addressed to CPAs inside or advising an organization, conditions: magazine feature article presented as an overview for newer CPAs and a refresher for more experienced ones on the basics of internal controls; publisher note: item is from the archives, published 2023, provided for historical reference, and the content may be out of date; stated as one of several examples of preventive controls; the illustration given is cash receipts, not vendor payment-detail changes)
“Segregation of duties: The core principle of the segregation of duties is that no one person should be able to abuse the system on their own. For example, the person receiving cash should not be the same person who is responsible for recording how much was received, depositing those funds, or reconciling the bank account.”American Institute of CPAs / Association of International Certified Professional Accountants (Journal of Accountancy) — Preventing fraud with internal controls: A refresher, 2023-08-01; Section 'PREVENTIVE CONTROLS: PREVENTION IS BETTER THAN CURE', bulleted example 'Segregation of duties'. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
The article states that organizations should ideally employ the principle of least privilege, meaning users should only have the level of access required to do their required tasks and no more than that. (jurisdiction: United States (AICPA & CIMA / Journal of Accountancy professional publication addressed to CPAs; the article itself states no jurisdictional limit), entity_scope: organizations generally, as addressed to CPAs inside or advising an organization, conditions: magazine feature article presented as an overview for newer CPAs and a refresher for more experienced ones on the basics of internal controls; publisher note: item is from the archives, published 2023, provided for historical reference, and the content may be out of date; hedged as 'ideally')
“IT passwords and access controls: Ideally, organizations should employ the principle of least privilege, which means that users should only have the level of access required to do their required tasks and no more than that.”American Institute of CPAs / Association of International Certified Professional Accountants (Journal of Accountancy) — Preventing fraud with internal controls: A refresher, 2023-08-01; Section 'PREVENTIVE CONTROLS: PREVENTION IS BETTER THAN CURE', bulleted example 'IT passwords and access controls'. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: high quality professional secondary reference.
What you write down about the change and the verification
Travelers states that clear documentation of controls, verification procedures and employee training can play an important role both in preventing loss and in responding to a claim; it is stated as a contributing factor, not as a policy condition precedent. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: stated as ‘can play an important role’, not as a policy requirement)
“Clear documentation of controls, verification procedures and employee training can play an important role in both loss prevention and claim response.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Understanding social engineering coverage considerations”, second paragraph, second sentence. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
The standing procedure that applies to every such request
The FTC's recommended practice for verifying invoices and payments is to make procedures for approving purchases and invoices clear, to ask staff to check all invoices closely, and to pay attention (and have staff pay attention) to how someone asks to be paid. (jurisdiction: United States, entity_scope: Small businesses and non-profit organizations in the United States (and their staff) targeted by scams, effective_from: 2023-07)
“Make sure procedures are clear for approving purchases and invoices and ask your staff to check all invoices closely. Pay attention to how someone asks you to pay and tell your staff to do the same.”Federal Trade Commission — Scams and Your Small Business: A Guide for Business, 2023-07; Section "Protect Your Business", sub-heading "Verify Invoices and Payments". Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that consistent verification procedures, clear escalation paths and employee awareness are critical across organizations, and that social engineering ultimately succeeds or fails at human decision points whatever channel the request arrives by. (jurisdiction: United States, entity_scope: organizations of all sizes and across industries, conditions: channels listed openly (‘or another channel’))
“Consistent verification procedures, clear escalation paths and employee awareness are critical across organizations. While technology plays an important role, social engineering ultimately succeeds or fails at human decision points – regardless of whether the request arrives by email, phone call, text message or another channel.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “How do social engineering scams unfold?”, final paragraph. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
The article states that, for the first step of creating a new vendor, an organization can begin by documenting the process and asking itself questions such as those listed; the questions given are offered as examples ('questions like'), not as a closed list. (jurisdiction: United States (AICPA & CIMA / Journal of Accountancy professional publication addressed to CPAs; the article itself states no jurisdictional limit), entity_scope: organizations generally, as addressed to CPAs inside or advising an organization, conditions: magazine feature article presented as an overview for newer CPAs and a refresher for more experienced ones on the basics of internal controls; publisher note: item is from the archives, published 2023, provided for historical reference, and the content may be out of date; applies to creating a new vendor, which is the example the article works through; the article does not state a procedure for changing an existing vendor's banking details; list of questions is introduced as examples and is open)
“Looking at the first step of creating a new vendor, an organization can begin by documenting the process and ask themselves questions like:”American Institute of CPAs / Association of International Certified Professional Accountants (Journal of Accountancy) — Preventing fraud with internal controls: A refresher, 2023-08-01; Section 'ASSESSING RISK'. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard. Highest achieved: authoritative lender insurer or program documentation, primary regulator or government.
The recognised control expectation for a vendor banking-detail change
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard. Highest achieved: authoritative lender insurer or program documentation, high quality professional secondary reference, primary regulator or government.
What the FBI's guidance says about this fraud and where to report it
The IC3 directs a BEC victim to file a detailed complaint with www.ic3.gov, which is the reporting channel the FBI's Internet Crime Complaint Center gives for this class of fraud. (jurisdiction: United States, entity_scope: victims of a BEC incident)
“File a detailed complaint with www.ic3.gov.”Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) — Business Email Compromise (BEC), ic3.gov public Crime Info page, no edition or version shown; snapshot retrieved 2026-09-09; Business Email Compromise (BEC) > What To Do In Case Of A BEC Incident > File a Complaint. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
The IC3 states it is vital that the complaint contain all required data in the provided fields, including banking information; banking information is given as included in, not as the whole of, the required data. (jurisdiction: United States, entity_scope: persons filing a BEC complaint with the IC3)
“It is vital the complaint contain all required data in provided fields, including banking information.”Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) — Business Email Compromise (BEC), ic3.gov public Crime Info page, no edition or version shown; snapshot retrieved 2026-09-09; Business Email Compromise (BEC) > What To Do In Case Of A BEC Incident > File a Complaint. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Partly established. Established: the government or law-enforcement guidance available to a US business on payment-diversion and business-email-compromise fraud (S03, S05, S19, S22, S23); the verification practice that guidance recommends (S03, S19); the channel for reporting an incident (S22, S39). Missing: what such a fraud obtains from a change of vendor banking details; the classes of indicator the guidance identifies as raising scrutiny on a request; what a report to that channel is expected to contain.
Payments already scheduled or in flight when the request arrives
QuickBooks Bill Pay allows an ACH bill payment to be cancelled while it is in Scheduled or Processed status, provided the cancellation is made before 5 pm on the day the payment is set to be credited to the vendor. (jurisdiction: United States, entity_scope: QuickBooks Bill Pay users paying bills in QuickBooks, platform: QuickBooks Bill Pay (QuickBooks Online), platform_edition: United States (en-US) QuickBooks support article, updated 8/26/2026, conditions: payment method is ACH; payment status is Scheduled or Processed; cancellation made before 5 pm on the day the payment is set to be credited to the vendor)
“You can cancel an ACH bill payment if it’s in Scheduled or Processed status before 5 pm on the day it’s set to be credited to the vendor.”Intuit Inc. — Cancel or void a scheduled bill payment, 2026-08-26; Article body, introductory paragraph under the title “Cancel or void a scheduled bill payment” (pinned text line 44). Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
QuickBooks Bill Pay allows a check payment to be voided while it is in Shipped status. (jurisdiction: United States, entity_scope: QuickBooks Bill Pay users paying bills in QuickBooks, platform: QuickBooks Bill Pay (QuickBooks Online), platform_edition: United States (en-US) QuickBooks support article, updated 8/26/2026, conditions: payment method is check; payment status is Shipped)
“You can also void a check payment if it’s in Shipped status.”Intuit Inc. — Cancel or void a scheduled bill payment, 2026-08-26; Article body, introductory paragraph under the title “Cancel or void a scheduled bill payment” (pinned text line 44). Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
A check that has already shipped but has not yet been credited to the vendor can be voided by submitting a request in-product (Expenses > Bill payments > View details > Request to void check > Request to void), after which a confirmation screen shows the request is in process. (jurisdiction: United States, entity_scope: QuickBooks Bill Pay users paying bills in QuickBooks, platform: QuickBooks Bill Pay (QuickBooks Online), platform_edition: United States (en-US) QuickBooks support article, updated 8/26/2026, conditions: payment method is check; check has shipped; check has not yet been credited to the vendor)
“To void a check that has already shipped but has not yet been credited to the vendor: Select Expenses , then Bill payments ( Take me there ). Choose the bill payment from the list, then select View details . Select Request to void check . Select Request to void . You’ll see a confirmation screen that the request is in process.”Intuit Inc. — Cancel or void a scheduled bill payment, 2026-08-26; Section “To void a check that has already shipped but has not yet been credited to the vendor:” and its numbered steps (pinned text lines 55–59). Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
OCC consumer guidance says the account holder should ask the bank to take steps to prevent further loss of funds; it gives closing the account and stopping any pending transfers as examples ("such as"), not as a closed list. (jurisdiction: United States, entity_scope: consumers of banks, which the page states generally means national banks, federal savings associations, and federal branches or agencies of foreign banking organizations regulated by the OCC, conditions: a fraudulent wire transfer has been sent)
“Request that the bank take steps, such as closing the account or stopping any pending transfers, to prevent further loss of funds.”Office of the Comptroller of the Currency (HelpWithMyBank.gov) — What should I do if a wire transfer is fraudulent?, 2024-04; Help Topics > Fraud & Scams > Scams > Wire Transfer Scams, answer body under the heading "What should I do if a wire transfer is fraudulent?", first paragraph (TEXT.txt line 35). Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: official platform documentation.
Holding payments to that vendor while the change is pending
Not established from an authoritative source.
Where the banking details live in your accounting or bill-pay platform
A vendor’s payment info is viewed by selecting that vendor in the Vendors list, i.e. the payment info sits in the individual vendor’s record. (jurisdiction: US, entity_scope: QuickBooks Online subscribers in the United States using QuickBooks Bill Pay, platform: QuickBooks Online (US) — QuickBooks Bill Pay, platform_edition: US English (en-US) help article, Updated 8/26/2026 12:54)
“Select a vendor to view their payment info.”Intuit Inc. — View or edit your vendor's payment info, 2026-08-26; Section “View and update the payment info for your vendors”, step 2. Verified 2026-09-09.
For such a payable Business Network vendor, the vendor is to be contacted to update their ACH payment info in the vendor’s own QuickBooks first, after which the payment can be completed. (jurisdiction: US, entity_scope: QuickBooks Online subscribers in the United States using QuickBooks Bill Pay, platform: QuickBooks Online (US) — QuickBooks Bill Pay, platform_edition: US English (en-US) help article, Updated 8/26/2026 12:54, conditions: vendor is a payable member of the QuickBooks Business Network; the paying business is connected with that vendor on the network; concerns ACH payment info)
“Contact your vendor to update their ACH payment info in their QuickBooks first. Then you can complete the payment.”Intuit Inc. — View or edit your vendor's payment info, 2026-08-26; Section “View and update the payment info for your vendors”, note following step 3. Verified 2026-09-09.
Not established from an authoritative source.
If the payment has already gone out: what to do first
In case of a BEC incident the IC3 directs the victim to contact the originating financial institution as soon as the fraud is recognized, in order to request a recall or reversal as well as a Hold Harmless Letter or Letter of Indemnity. (jurisdiction: United States, entity_scope: victims of a BEC incident, conditions: fraud has been recognized)
“Contact the originating Financial Institution as soon as fraud is recognized to request a recall or reversal as well as a Hold Harmless Letter or Letter of Indemnity.”Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) — Business Email Compromise (BEC), ic3.gov public Crime Info page, no edition or version shown; snapshot retrieved 2026-09-09; Business Email Compromise (BEC) > What To Do In Case Of A BEC Incident > Contact Your Bank. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
The IC3 states that requesting a recall and obtaining a Hold Harmless Letter or indemnification documents as quickly as possible may reduce or eliminate the victim's financial losses — a possible, not a guaranteed, outcome. (jurisdiction: United States, entity_scope: victims of a BEC incident, conditions: action taken as quickly as possible)
“Requesting a recall and obtaining a Hold Harmless Letter/Indemnification documents as quickly as possible may reduce or eliminate your financial losses.”Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) — Business Email Compromise (BEC), ic3.gov public Crime Info page, no edition or version shown; snapshot retrieved 2026-09-09; Business Email Compromise (BEC) > What To Do In Case Of A BEC Incident > Contact Your Bank. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
OCC consumer guidance says that a person whose wire transfer is fraudulent should contact their own bank and also the bank that may have received the funds. (jurisdiction: United States, entity_scope: consumers of banks, which the page states generally means national banks, federal savings associations, and federal branches or agencies of foreign banking organizations regulated by the OCC, conditions: a wire transfer that is fraudulent)
“Contact your bank and the bank that may have received your funds.”Office of the Comptroller of the Currency (HelpWithMyBank.gov) — What should I do if a wire transfer is fraudulent?, 2024-04; Help Topics > Fraud & Scams > Scams > Wire Transfer Scams, answer body under the heading "What should I do if a wire transfer is fraudulent?", first paragraph (TEXT.txt line 35). Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
OCC consumer guidance says that a person whose wire transfer is fraudulent should request a recall on the wire transfer that left their account; the request is made by the account holder to the bank. The page states no deadline for the request. (jurisdiction: United States, entity_scope: consumers of banks, which the page states generally means national banks, federal savings associations, and federal branches or agencies of foreign banking organizations regulated by the OCC, conditions: a fraudulent wire transfer has already left the account holder's account)
“Request a recall on the wire transfer that left your account.”Office of the Comptroller of the Currency (HelpWithMyBank.gov) — What should I do if a wire transfer is fraudulent?, 2024-04; Help Topics > Fraud & Scams > Scams > Wire Transfer Scams, answer body under the heading "What should I do if a wire transfer is fraudulent?", first paragraph (TEXT.txt line 35). Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
An Originator or ODFI must transmit a Reversal in such time that it is made available to the RDFI within 5 banking days following the Settlement Date of the Erroneous Entry, and Nacha states the new rules do not change that timing. (jurisdiction: United States - the Nacha ACH Network, entity_scope: Originators and ODFIs originating Reversing Entries, platform: ACH Network (Nacha Operating Rules), platform_edition: Nacha Operating Rules as amended by the 2021 Reversals rule change, conditions: the 5-banking-day window runs from the Settlement Date of the Erroneous Entry; the document states this timing pre-dates and is unchanged by the 2021 rule changes)
“No. The new rules do not impact the timing for the initiation of a Reversal. An Originator or ODFI must still transmit a Reversal in such time that it is made available to the RDFI within 5 banking days following the Settlement Date of the Erroneous Entry.”Nacha (National Automated Clearing House Association) — ACH Network Rules: Reversals and Enforcement, Nacha 'New Rules' page for Reversals and Enforcement; Rule Status shown as 'Archived Rule Changes'; stated Effective Date June 30, 2021 (Enforcement rule January 1, 2021); page carries a 2026 Nacha copyright; exact edition not confirmable (host returned HTTP 403 to the harness on 2026-09-09); FAQs Section > REVERSALS > 'Do the upcoming rule changes to Reversals provide additional time for an Originator or ODFI to initiate a Reversing Entry?'. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that delayed detection compounds the damage, that fraudulent requests are often structured to align with normal business activity so irregularities may not surface until funds have settled or a customer raises a concern, and that in business email compromise scenarios even brief delays in recognition can significantly affect recovery options. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies))
“Delayed detection compounds the damage. Fraudulent requests are often structured to align with normal business activity, so irregularities may not surface until after funds have settled or a customer raises a concern. In business email compromise scenarios, even brief delays in recognition can significantly affect recovery options.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Why do social engineering losses escalate so quickly?”, second paragraph. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Required authority: authoritative lender insurer or program documentation, primary regulator or government. Highest achieved: authoritative lender insurer or program documentation, official platform documentation, primary regulator or government.
What your bank or the payment network can attempt to get the money back
Alongside the existing reasons for originating a Reversing Entry that the document identifies - duplicate entry, incorrect receiver, incorrect dollar amount, or certain PPD credits related to termination/separation from employment - an Originator or ODFI may now also initiate a Reversal when it has transmitted a debit Entry ordering payment on a date earlier than intended, or a credit Entry ordering payment on a date later than intended. (jurisdiction: United States - the Nacha ACH Network, entity_scope: Originators and ODFIs originating Reversing Entries, platform: ACH Network (Nacha Operating Rules), platform_edition: Nacha Operating Rules as amended by the 2021 Reversals rule change, effective_from: 2021-06-30, conditions: reasons as listed by this page; the page summarises rather than reproduces the Operating Rules text)
“In addition to existing reasons for the origination of a Reversing Entry (i.e., duplicate entry, incorrect receiver, incorrect dollar amount, or certain PPD credits related to termination/separation from employment), an Originator or ODFI may now also initiate a Reversal when it has transmitted a debit Entry that orders payment on a date earlier than intended, or when it has transmitted a credit Entry that orders payment on a date later than intended.”Nacha (National Automated Clearing House Association) — ACH Network Rules: Reversals and Enforcement, Nacha 'New Rules' page for Reversals and Enforcement; Rule Status shown as 'Archived Rule Changes'; stated Effective Date June 30, 2021 (Enforcement rule January 1, 2021); page carries a 2026 Nacha copyright; exact edition not confirmable (host returned HTTP 403 to the harness on 2026-09-09); FAQs Section > REVERSALS > 'The new rule expands the permissible reasons that an Originator or ODFI may initiate a Reversing Entry. What has changed?'. Verified 2026-09-09.
Partly established. Established: how the account holder requests it (S27, S32). Missing: what a US bank or payment provider can attempt once a payment has been sent to a fraudulent account; how the available options depend on the payment method used; which of those options are time-critical; how quickly each time-critical option must be requested to remain available.
Who you notify, and what each notification needs to contain
The FTC directs a business that spots a scam to report it to ReportFraud.ftc.gov, and states that the report can help stop the scam. (jurisdiction: United States, entity_scope: Small businesses and non-profit organizations in the United States (and their staff) targeted by scams, effective_from: 2023-07)
“If you spot a scam, report it to ReportFraud.ftc.gov . Your report can help stop the scam.”Federal Trade Commission — Scams and Your Small Business: A Guide for Business, 2023-07; Section "Report". Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that engaging an experienced insurance professional can help an institution evaluate how its coverage aligns with evolving fraud risks. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies))
“Engaging with an experienced insurance professional can help institutions evaluate how their coverage aligns with evolving fraud risks.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Understanding social engineering coverage considerations”, third paragraph. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Partly established. Established: notification of the bank or payment provider (S32); notification of the reporting channel for this class of fraud (S22, S39). Missing: notification of the vendor through the verified channel; notification of any insurer; what each notification needs to contain.
Required authority: authoritative lender insurer or program documentation, primary regulator or government. Highest achieved: primary regulator or government.
Whether insurance responds to a loss like this
Travelers states that social engineering fraud can raise complex coverage considerations depending on the facts of a loss, and that financial institutions should review how their crime policies, financial institution bond or related policies respond to fraudulent instructions, impersonation schemes and funds transfer exposures; it does not state that any such policy does respond. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: depending on the facts of a loss; policy classes named non-exhaustively (‘or related policies’))
“Social engineering fraud can trigger complex coverage considerations depending on the facts of a loss. Financial institutions should review how their crime, financial institution bond or related policies respond to fraudulent instructions, impersonation schemes and funds transfer exposures.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Understanding social engineering coverage considerations”, first paragraph. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that coverage language, definitions and conditions vary; the article itself sets out no policy terms. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies))
“Coverage language, definitions and conditions vary.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “Understanding social engineering coverage considerations”, second paragraph, first sentence. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Travelers states that social engineering coverage can help address financial loss, while reducing exposure ultimately depends on how the organization’s safeguards work together. (jurisdiction: United States, entity_scope: financial institutions (banks, credit unions, wealth managers and insurance companies), conditions: no coverage terms, triggers or conditions stated)
“While social engineering coverage can help address financial loss, reducing exposure ultimately depends on how these safeguards work together across the organization.”The Travelers Indemnity Company — How to Protect Against Social Engineering Fraud and Scams, Web article, no edition or version stated; ©2026 The Travelers Indemnity Company; cites the FBI/IC3 2024 Internet Crime Report and the OCC Semiannual Risk Perspective Spring 2025; Section “How a layered defense can help financial institutions protect themselves against social engineering”, opening paragraph, second sentence. Verified 2026-09-09. Flagged for professional review — a bookkeeper or accountant should confirm this applies to your situation.
Not established from an authoritative source.
Recording the payment and whether the vendor is still owed the money
Payment of an account payable is recorded as a debit to Accounts Payable and a credit to Cash. (jurisdiction: United States, entity_scope: companies paying recorded accounts payable, accounting_basis: accrual method of accounting, conditions: the explanation states it assumes throughout that the companies follow the accrual method of accounting)
“When an account payable is paid, Accounts Payable will be debited and Cash will be credited.”AccountingCoach, LLC (Harold Averkamp, CPA, MBA) — Accounts Payable: In-Depth Explanation with Examples, not stated on the page; snapshot retrieved 2026-09-09, footer copyright year 2026; Introduction. Verified 2026-09-09.
The credit balance in Accounts Payable should equal the amount of vendor invoices that have been recorded but not yet paid. (jurisdiction: United States, entity_scope: companies maintaining an Accounts Payable account, accounting_basis: accrual method of accounting, conditions: the explanation states it assumes throughout that the companies follow the accrual method of accounting)
“Therefore, the credit balance in Accounts Payable should be equal to the amount of vendor invoices that have been recorded but have not yet been paid.”AccountingCoach, LLC (Harold Averkamp, CPA, MBA) — Accounts Payable: In-Depth Explanation with Examples, not stated on the page; snapshot retrieved 2026-09-09, footer copyright year 2026; Introduction. Verified 2026-09-09.
Under the accrual method, a company's financial statements must report all expenses and liabilities that are probable and can be measured, even where the vendors' invoices have not yet been received or fully processed. (jurisdiction: United States, entity_scope: companies preparing financial statements, accounting_basis: accrual method of accounting)
“Note: Under the accrual method of accounting, a company’s financial statements must report all expenses and liabilities that are probable and can be measured even if the vendors’ invoices have not yet been received or fully processed.”AccountingCoach, LLC (Harold Averkamp, CPA, MBA) — Accounts Payable: In-Depth Explanation with Examples, not stated on the page; snapshot retrieved 2026-09-09, footer copyright year 2026; Accruing Expenses and Liabilities — closing Note. Verified 2026-09-09.
Where the existing general ledger accounts are not sufficient, new accounts should be added, because meaningful financial reporting of transactions should not be limited to a preconceived list of accounts. (jurisdiction: United States, entity_scope: companies maintaining a chart of accounts)
“When the existing accounts are not sufficient, new accounts should be added. In other words, meaningful financial reporting of transactions should not be limited to a preconceived list of accounts.”AccountingCoach, LLC (Harold Averkamp, CPA, MBA) — Accounts Payable: In-Depth Explanation with Examples, not stated on the page; snapshot retrieved 2026-09-09, footer copyright year 2026; Adding General Ledger Accounts. Verified 2026-09-09.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard. Highest achieved: high quality professional secondary reference.
The bookkeeping behind an unpaid vendor balance
When a vendor invoice is recorded, Accounts Payable is credited and, as double-entry accounting requires, at least one other account must be debited. (jurisdiction: United States, entity_scope: companies recording vendor invoices under double-entry accounting, accounting_basis: accrual method of accounting, conditions: the explanation states it assumes throughout that the companies follow the accrual method of accounting)
“Hence, when a vendor invoice is recorded, Accounts Payable will be credited and another account must be debited (as required by double-entry accounting).”AccountingCoach, LLC (Harold Averkamp, CPA, MBA) — Accounts Payable: In-Depth Explanation with Examples, not stated on the page; snapshot retrieved 2026-09-09, footer copyright year 2026; Introduction. Verified 2026-09-09.
See Payment of an account payable is recorded as a debit to Accounts Payable and a credit to Cash.
Under the accrual method, a company receiving goods or services on credit must report the liability no later than the date the goods or services were received. (jurisdiction: United States, entity_scope: companies receiving goods or services on credit, accounting_basis: accrual method of accounting)
“Under the accrual method of accounting , the company receiving goods or services on credit must report the liability no later than the date they were received.”AccountingCoach, LLC (Harold Averkamp, CPA, MBA) — Accounts Payable: In-Depth Explanation with Examples, not stated on the page; snapshot retrieved 2026-09-09, footer copyright year 2026; Introduction. Verified 2026-09-09.
Not established from an authoritative source.
Required authority: authoritative professional or accounting standard. Highest achieved: high quality professional secondary reference.
Not yet fully established from an authoritative source
- Establish the recognised control expectation for changing a vendor's banking details, including verification through a channel independent of the request and separation between the person verifying, the person approving and the person paying. Establish also what the verification must settle - the requester's identity, their authority to change payment details, and whether the request came from a compromised mailbox - that the approver is neither the recipient of the request nor the person releasing payment, and what the business records of the request, its verification and its approval. (not established; below the required authority class)
- Establish the government or law-enforcement guidance available to a US business on payment-diversion and business-email-compromise fraud, including the recommended verification practice and the channel for reporting an incident. Establish also what such a fraud obtains from a change of vendor banking details, the classes of indicator the guidance identifies as raising scrutiny on a request, and what a report to that channel is expected to contain. (partly established)
- Establish what a US bank or payment provider can attempt once a payment has been sent to a fraudulent account, how the account holder requests it, and how the available options depend on the payment method used. Establish also which of those options are time-critical and how quickly each must be requested to remain available. (partly established)
- Establish how mainstream accounting and payment platforms store vendor banking details, what they record when those details change, and whether a change can be restricted or made to require approval. Establish also whether payments already scheduled or in flight can be held or cancelled before release while a change is verified. (not established)
- Establish the accounting treatment of a payment sent to a fraudulent recipient, including whether the underlying vendor obligation remains outstanding and how the loss and any recovery are recorded. (not established; below the required authority class)
- Establish whether classes of business insurance respond to a loss of this kind, and what a policy of such a class requires the insured to have done beforehand and to report on discovery. (not established)
- Establish the control expectation for payments already scheduled or in flight to a vendor whose banking details are the subject of a pending change request, including whether payments to that vendor are held until the verification and the approval are complete. (not established)
- Establish why a banking-detail change is the highest-value change anyone can make to the vendor file, and therefore why it is handled as a control event rather than as an administrative update. (not established; below the required authority class)
- Establish the independent-channel principle explicitly, including that contact details must predate the request and must not be taken from it or from anything attached to it. (not established; below the required authority class)
- Establish the three things verification must actually settle - identity, authority to change payment details, and whether the vendor's own mailbox is compromised - and why confirming only the first is insufficient. (not established; below the required authority class)
- Establish the classes of indicator that raise scrutiny, framed so they do not degrade into a checklist of surface details an attacker can trivially satisfy. (not established)
- Establish who may approve the change and why the approver must be someone other than the person who received the request and the person who releases the payment. (not established; below the required authority class)
- Establish what is recorded about the change and its verification, and where in the vendor file or payment system that record is kept. (not established)
- Establish the handling of payments already scheduled or in flight at the moment the request arrives, including whether they are held while verification completes. (not established; below the required authority class)
- Establish the actions available once a payment has already been sent, ordered by time-criticality, and state how the available options depend on the method by which the payment was made. (not established; below the required authority class)
- Establish who must be notified - the vendor through the verified channel, the bank or payment provider, the reporting channel for this class of fraud, and any insurer - and what each notification needs to contain. (partly established; below the required authority class)
- Establish how the diverted payment and any recovery are recorded, and whether the obligation to the vendor remains outstanding after the money has left the business. (not established; below the required authority class)
- Establish the standing change procedure that applies to every banking-detail request regardless of source, so that the control does not depend on someone being suspicious on the day. (not established; below the required authority class)
Reference date 2026-09-07. Statements are quoted verbatim from their sources; scope and verification dates are shown on each.