A bank account number can be copied into an email in seconds. That does not tell you who controls the account, whether the payment request is genuine, or whether the payee matches the supplier structure you agreed to.
Before a first supplier payment, treat bank details as a verification task, not a box to tick at the bottom of a pro forma invoice. You need to connect the proposed payment recipient with the legal entity, contract, invoice, and order record. You also need a process for any change that arrives after those details were set up.
This is general sourcing information. It cannot confirm that a particular account is safe, owned by a stated company, or appropriate for your payment. If an order is material, the information conflicts, or you suspect a fraudulent request, pause the transaction and obtain support from your financial institution and qualified advisers.
Start with the entity map, not the account number
Do not begin by staring at the account number. Start with the order entities.
For a straightforward order, the manufacturer, contract seller, invoice issuer, and payment recipient may all be the same legal entity. In other cases, a trading company, export company, or group entity may be involved. That can be workable if the role of each company is clear and documented.
Before payment, create a simple record:
| Item | What to record | Why it matters |
|---|---|---|
| Supplier legal entity | Official company name and registration details | Identifies the company behind the order |
| Contract seller | Name shown on the contract or purchase order | Shows who accepts the commercial obligation |
| Invoice issuer | Entity named on the pro forma invoice | Connects the request to the document asking for payment |
| Proposed payee | Full beneficiary name and supplied bank details | Identifies the intended recipient of funds |
| Exporter or trading entity, if used | Legal name and stated role | Explains why another company may appear in the order path |
| Verification record | Date, person, channel, and result of the check | Creates an auditable decision trail |
If the names differ, do not assume that one of them is wrong. Ask the supplier to explain the relationship in writing. Then decide whether the explanation, documents, and risk of the order are sufficient for the next step.
Sourcing All’s guide to export rights and trading companies explains why the manufacturer, exporter, invoice issuer, and payment recipient may have different roles in a China order. That map should come first. Account verification checks whether the payment request still fits it.
Know why email-only verification is weak
Payment requests are a common target for business email compromise. The FBI describes scams in which messages appear to come from known sources and request changes to account information or payment procedures. It also notes that small changes in an email address, web address, or spelling can be used to make a fake message look legitimate. [1]
An email in an existing thread can look convincing. A familiar logo can look convincing. An attached invoice can look convincing. None of those details should be the only reason to change a payee or release money.
The question is not “Does this message look normal?” The question is “Have we confirmed this instruction through a separate, trusted route?”
Use a trusted callback or another independent channel
For a first payment or a change in bank details, verify the request using contact information you already trust. That may be a phone number in the signed contract, an approved supplier record, a previously confirmed company website, or a known account contact established before the payment request.
Do not use a phone number, link, or contact address supplied only in the new payment-change message. The FBI advises looking up the company’s phone number independently rather than using a number provided in a potentially suspicious request. It also recommends verifying changes in account number or payment procedures with the person making the request. [1]
CISA’s archived business-email-compromise alert gives the same practical control: confirm supplier payment-instruction changes by calling a number from a known supplier contact list, not a number contained in the electronic request. [2]
A callback does not prove account ownership. It gives you a second channel to detect a message sent from a compromised or spoofed email account. Record who confirmed the details, which known channel you used, and what was confirmed.
Separate first-time setup from a change request
A new supplier account and a change to an existing supplier account both need review. The change request deserves special attention because it may arrive when your team is trying to meet a payment deadline.
Use two short workflows.
First-time supplier payment
Before setting up the payee:
- Confirm the supplier’s legal entity and role in the order.
- Compare the contract seller, invoice issuer, and proposed payee.
- Collect the supplier’s payment instructions through an agreed business channel.
- Verify the instructions through a trusted, independent contact route.
- Record the verification result and hold the payment if any material item is unclear.
Change to existing bank details
Before updating the record:
- Treat every bank-detail change as a new verification event.
- Compare the new beneficiary name and details with the existing supplier record.
- Confirm the request through a trusted contact channel that did not come from the change message.
- Keep the old and new instructions, the reason given, and the verification record together.
- Require a second reviewer or escalation step when the change does not match the supplier entity map or the order is material.
Do not let “we have paid this supplier before” replace the verification step. A genuine supplier can have a compromised email account. A change can also be legitimate. The control is there to distinguish a documented change from an unverified instruction.
Compare the right details
The exact format of payment information varies by country and bank. Your internal process should focus on whether the payment details and order documents tell a consistent story.
Compare the details shown in the payment request with the supplier record:
- Legal beneficiary name;
- Supplier legal entity and contract seller;
- Invoice issuer and invoice number;
- Bank name and location, where stated;
- Account, IBAN, or other payment identifier supplied for the transaction;
- Currency and payment terms agreed in the order;
- Reason for any mismatch, new entity, or account update.
A matching beneficiary name is useful evidence. It is not a complete fraud check. A different beneficiary name is not automatic proof of wrongdoing. It is a reason to stop, document the difference, and obtain a clear explanation before you proceed.
For the earlier legal-entity review, use How to Read a Chinese Business License Before You Pay a Deposit. For the full first-order decision process, see the supplier verification checklist before your first order.
Build a small payment-change control
A simple control can prevent a last-minute request from becoming a rushed decision. Define who can request a bank-detail change, who may verify it, who can approve an update, and where the evidence is stored.
CISA’s archived alert recommends limiting the number of people able to approve or conduct transfers, using an out-of-band check for apparently legitimate requests, and requiring dual approval for higher-risk cases such as new partners or new bank-account numbers. [2] Use those as process-design principles, then adapt the controls to the size of your team and the risk of the order.
| Control | Practical version for a sourcing team |
|---|---|
| Separate request from verification | The person receiving the invoice does not treat their own email exchange as final verification. |
| Use an independent contact route | Confirm through an existing approved number or contact, not new details in the message. |
| Record the decision | Save the change request, supporting documents, callback result, date, and reviewer. |
| Add a second check when risk is higher | Require a second person to review a new payee, changed account, large order, or entity mismatch. |
| Hold unclear requests | Do not release funds until the mismatch is explained and recorded. |
The purpose is not to create bureaucracy for its own sake. It is to make sure urgency does not remove the one check that would have caught an inconsistent instruction.
Watch for signals that need a pause
A single warning sign is not a verdict. It is a reason to verify more carefully. Pause when you see situations such as:
- A request to change bank details after the invoice or payment terms were already agreed;
- A sender address that is close to, but not the same as, the supplier’s known address;
- A request that demands urgent payment or discourages a callback;
- A payee name that does not match the contract seller or invoice issuer and has no written explanation;
- A new bank account provided only in an email attachment or chat message;
- A supplier contact who will not confirm the request through the established channel;
- Different people at the supplier giving incompatible explanations of who should receive payment.
The FBI specifically advises caution when the requester pressures you to act quickly and advises examining the email address, URL, and spelling in correspondence. [1]
Understand what verification can and cannot do
A documented callback, matching records, and a second review can reduce the chance of acting on an unverified instruction. They do not guarantee that the bank account is owned by the supplier, that the supplier will perform the order, or that the transaction meets every legal, financial, banking, customs, or contractual requirement.
Keep payment verification connected to the rest of the order controls: legal-entity review, product specification, quote comparison, sample approval, contract terms, quality plan, inspection, and shipping documents. A clean payment record cannot repair a weak product brief. A good sample cannot explain an unexplained payee change.
If you suspect a fraudulent request
Do not reply only within the suspicious email thread. Use a known contact method to verify the request, hold the payment or account change while it is reviewed, and follow your organization’s incident process.
If money has already been sent and you believe the instruction may have been fraudulent, contact your financial institution immediately. The FBI also directs victims of business email compromise to report the incident through its Internet Crime Complaint Center. [1] Your bank and appropriate legal, financial, or cybersecurity professionals can advise on the specific next steps for your situation.
The practical rule
Before sending money, make the payee make sense in the order file. Match the entity record, contract, invoice, and payment request. Confirm changes through a channel you already trust. Write down what you checked. Then hold the transaction when the story does not line up.
That does not make every payment risk disappear. It gives you a repeatable control that is stronger than trusting the latest email.
References
[1] FBI, “Business Email Compromise”
[2] CISA, “Business Email Compromise Continues to Swindle and Defraud U.S. Businesses” (archived guidance)