Hello everyone and welcome to today’s webinar stop the switch best practices for verifying bank account ownership and preventing payment fraud. My name is Marc Brousseau, President of Brousseau & Associates. I’m pleased to be one of your co-presenters for today’s webinar. Today’s webinar is brought to you by vendor info. I have a few housekeeping notes to go over before we officially get started. To ensure call quality, everyone’s voice lines have been muted today.
We encourage you to ask questions throughout today’s webinar. To do so, simply use the Q & A tool on your screen to submit your questions to me. We’ll answer your questions at the conclusion of today’s webinar. And finally, an on-demand version of today’s webinar will be sent to all of you within the next few business days. We encourage you to share it with your peers and your coworkers.
I’m pleased today to be joined by Phil Binkow, CEO of VendorInfo. Phil has built his business around helping AP teams just like yours, get smarter about fraud prevention, supplier onboarding, and bank account verification. Together, Phil and I are gonna walk you through the challenges AP teams are facing and the smart steps you can take to outpace fraud and to stay compliant.
So what are we gonna cover today? Well, we’re gonna start with a look at the different types of fraud that are increasingly targeting AP departments and why the pace and the sophistication of these attacks is growing. We’ll dive into the limitations of phone calls, emails and spreadsheets when it comes to verifying bank account details and how fraudsters are exploiting these limitations.
We’ll walk you through four best practices that can dramatically reduce your fraud risk, including process standardization, independent verification, risk flagging, and yes, automation. And if you’re exploring automation, we’re gonna help you understand what to look for in a solution that helps fit your process and compliance needs. Phil will be along to show you how Vendor Info’s platform brings these practices to life in a streamlined, auditable workflow. And finally, we’ll save time at the end of this webinar to answer your questions live.
Well, if you’re an AP leader, I probably don’t have to tell you that AP teams are increasingly being targeted by fraudsters because they control the flow of money. And one of the most common scams that AP teams are facing these days? Well, it’s phony bank account change requests. Cyber criminals know that AP teams are processing large volumes of payments every day, and you’re often doing it under pressure. And that’s what fraudsters are exploiting.
More and more fraud attacks are based on impersonating supplier or maybe even a trusted co-worker and asking that payment information be updated. And once it is, well, the fraudster waits for a legitimate payment to be redirected and then they whisk it to some far away bank account where it’s often hard to recover. And these are real losses we’re talking about. The insurance often doesn’t cover fraud caused by process failure and and recovery is unlikely once those funds are transferred overseas.
Put it all together and we find that today’s fraud schemes are more sophisticated, more brazen, and harder and harder to detect. These attacks work because they blend into your everyday operations. Here is how they typically unfold. Fraudsters do their homework. They often use social engineering and other techniques to figure out the names of your vendors, their invoice history, and even payment cycles.
In many cases, hacking into a supplier’s email or maybe even the email of, say, your senior finance execs and being able to read their information or even insert themselves into the email string is very helpful. In many cases fraudsters may register look-alike domains or gain access to the real email accounts through that phishing scheme I was talking about to make their requests seem legitimate. And once that change is processed, once you have changed the bank account details, they don’t need to do anything else.
The companies still see fraud prevention as the responsibility of, say, IT or a cyber security department. But in most cases, accounts payable. Yeah, you are the real frontline when it comes to stopping fraud schemes like BEC attacks and phishing schemes. Most fraud starts with social engineering, not hacking. The attacker’s goal is to trick someone, not to break into your system and that means that even the best firewalls won’t help if your processes aren’t right.
The bottom line is finance teams, AP practitioners in many cases, are the last line of defense. You may be the only department that reviews the payment before it goes out and that makes you and your team the gatekeeper. In many cases, AP processes are also the top attack surface, if you will. That’s technical jargon for you’re a big bullseye. Manual approvals, inconsistent workflows, and limited audit trails. Well, they all give fraudsters a whole lot of room to operate, and that’s what we’ve got to fix.
Let’s look at why those old school verification methods for bank account ownership verification, just don’t cut it anymore. And it all starts with the fact that today’s scammers can use voice cloning and number spoofing tools that make calls look and sound legitimate. This is where you hear a lot about artificial intelligence these days. Some AI tools can take snippets of someone’s voice, such as mine, and turn it into a conversation that sounds like I actually meant to say that.
In fact, AI has become so sophisticated that one CEO of an AI company predicted just last week that soon the technology will be able to create videos of individuals that are nearly indistinguishable from the real live video of a person. Today’s scammers are using these technologies to their advantage. What’s more, we’re also seeing that many of us are relying on emails. Yeah, I know they were a good workaround during COVID. And now that we’re working at home, at least part of the time, the fact is, is in many cases, we still rely on those emails. But the problem is, if a vendor’s email is compromised, even a real-looking reply could be fraudulent. Even one of those penny tests that so many of us do could be responded to by the fraudster.
And then, of course, here’s a sad reality. In many cases, corners can be cut. Even if your department had the best processes in place for manually verifying bank account ownership, the fact is there’s no stopping someone from cutting a corner or having an oversight. When your team’s busy or they’re understaffed, the reality is that steps are probably going to get skipped and fraudsters know exactly when to strike. It only takes one mistake to cause a major financial loss and irreparable damage to your company’s reputation.
Here’s a scenario that plays out far too often in accounts payable departments. A change request is processed without verification. Maybe it came from a known contact. Maybe it was a supplier you’ve been doing business with for years or maybe it came from your CFO. Maybe your team was short staffed, who knows? But regardless of how it was processed, there was no independent verification, and that led to the fraud loss.
In other cases, AP might receive a legitimate looking email from a known supplier. The logo looks right, the email signature checks out, it even references a real invoice, but it’s not your supplier, it’s a fraudster. In some cases, you’re going to have big dollar losses, such as, say, an $840,000 payment that’s wired to a fraudster’s offshore account. By the time the error is caught, the money is long gone. The bank can’t claw it back, insurance might not cover it, and you are left holding the bag. And that’s a situation none of us want, but this is exactly what could go wrong when you rely on manual or semi-automated bank account verification processes.
And international payment fraud is even harder to detect and just as hard to reverse. And there’s a reason for that. Fraudsters love these targets. Languages and time zones create delays, and we all know that the longer it takes to verify something, that’s the bigger the window that the fraudster has to strike. Verifying account details with an overseas vendor, that could take days in many cases due to language barriers or scheduling issues.
Domestic verification systems also don’t always work so well when it comes to banks and that leaves your teams back to square one manual verification there’s also no single rule book for global account validation as Phil is going to show you a little later countries might have a database for verifying bank account ownership and they might not and there might be different processes this lack of uniformity well that creates confusion and confusion creates opportunities, you guessed it, for fraud.
The problem is, is that manual checks simply can’t keep up in today’s increasingly sophisticated, increasingly complex fraud environment. Manual processes that might have worked in the past simply aren’t built for today’s risks. Without documented steps, it’s hard to prove who approved a change or whether it was even verified in the first place. When your team is flooded with invoices and vendor requests, it’s easy for things to get missed or lost in the shuffle of our busy days. Even your best people are going to make requests or make mistakes when relying on emails or calls or spreadsheets. And fraudsters know this. They wait for that one moment of distraction to strike.
Four Best Practices for Bank Account Verification
A standardized process is one of your strongest defenses against fraud. We’re going to share four best practices, but make no mistake about it. Standardization is the ground floor for improving your fraud posture. What you want to do is you want to require vendors to submit change requests via a secure portal or a ticketing system, not email. Email is a fraudster’s tool of choice when it comes to perpetrating their crimes.
You also want to set rules for what must be submitted, such as, say, avoided check or a government-issued ID or maybe even a bank letter. You also want to define clear ownership and workflows for approval. You want to know who’s responsible for what. You want to automate that routing and logging so there’s no chance that anything falls through the cracks. This is your first step toward mitigating your risk of falling victim to phony bank account change requests.
The second best practice for verifying bank account ownership is to trust, but verify independently. When you rely on supplier provided information, that’s a recipe for risk. So what you want to do is you want to use third-party sources or automated tools. These can confirm bank account ownership against real-time databases, not just static files. You also want to make sure that you never rely solely on supplier-provided information. Even legitimate suppliers make mistakes. Even your most trusted supplier can be hacked. and fraudsters are banking on you, accepting what’s been handed to you. So you always wanna verify all of the information you receive every time.
And you also want to confirm account matches the supplier’s legal entity, not just the DBA or the trade name. You wanna match to the tax ID and legal name to ensure true ownership to mitigate your risk.
The next step to mitigating your risk of falling victim to phony bank account change requests is to make sure you flag high-risk changes. Not all changes are created equal. Some warrant closer scrutiny, such as changes to high dollar or high-frequency suppliers. These payments are more attractive to fraudsters and certainly more damaging if misrouted. You might also want to flag changes involving international banks. The added complexity and the reduced visibility make these inherently higher risk. And you want to flag changes submitted outside your standard protocols. Anything arriving via email or bypassing your normal system, that should trigger a red flag, particularly if you currently have a supplier portal.
And the fourth best practice for mitigating your risk of falling victim to phony bank account change requests is to automate your verification process. Manual checks are inconsistent, they’re inefficient, but automation changes the game. It eliminates the opportunity for human error. Automated systems never skip steps and they never forget to log actions. They work the same every single time.
Automated systems also reduce the time spent on manual checks. They free up your team to focus on strategic tasks while the system handles repetitive risk-prone steps. And that time that your staff has from being freed up from mundane tasks, that’s time they could also spend focusing on those not so sure verification steps. the system sees a flag and wants you to take a closer look. Now you have the time to do that.
Automation also allows you to maintain audit trails and compliance logs. Every verification is documented, it’s timestamped, and it’s accessible for audit and reporting. There’s no more guesswork about who did what or when.
Choosing the Right Automated Solution
The thing is though, Not all automated solutions are created equal. Choosing the right verification solution is critical to your success. So here’s what I want you to prioritize when it comes to looking for an automated bank account ownership solution.
The first, make sure it seamlessly integrates with your existing systems, whether that’s your ERP, your supplier portal, your banking platforms, make sure it has the ability to connect to those. I also want you to make sure it supports both domestic as well as international bank accounts. Remember folks, fraud isn’t limited to any one region. You need global capabilities and even small businesses do business with global suppliers, at least from time to time.
You also want to make sure the solution provides you with real time ownership validation, not batch files, not static lookups. You want live confirmation tied to the current banking networks whenever possible. You also wanna make sure that it has built-in alerts and escalation procedures. When something looks off, when we’re not quite sure about something, your team should be notified automatically with clear next steps and workflows that are pre-configured so you’re sure the right people are always reviewing suspect transactions.
And finally, you want to make sure a solution has full audit and compliance documentation. The system should log every action and it should provide you with a full paper trail for auditors and for stakeholders.
The Difference Between Manual and Automated Processes
So what does a secure verification environment look like? Well, here’s the difference between doing things the old way and doing it the right way. In the old way, you had manual error-prone tasks. In an automated environment, you replace those emails and calls with a consistent automated process.
In a manual environment, we don’t have complete visibility. In an automated environment, real-time alerts allow you to see immediately when something fails a validation or doesn’t meet your policies. We know that manual tasks have no audit trails, but in an automated environment you get full documentation. You know exactly who did what and when, and that’s ideal for compliance and reporting and accountability.
And finally, without automation, you are at high risk. But in an automated environment, Things are controlled, they’re secured. When your workflow is automated, your risk goes down and your confidence goes up.
Summary
So to wrap up, here’s what we want to leave you with today. Pavement fraud is evolving and it’s also accelerating. Attacks are more frequent, they’re more targeted, they’re more brazen, and they’re more costly. And the reality is, is manual processes simply can’t keep up. Emails and spreadsheets and phone calls and even penny tests in many cases simply don’t offer enough protection anymore. You need more.
Now’s the time to automate and secure your verification workflow. You want to take action so you can reduce your risk, speed your onboarding process, and provide everyone in your organization with greater peace of mind.
VendorInfo Platform Demonstration
So how do we do this? Well, now that we’ve covered the principles, let’s show you what they look like in action. Phil is gonna walk you through how VendorInfo’s verification portal works and how it can help you mitigate your risk of fraud.
Hey, Mark, thank you very much, and thank you, everyone, for coming and your interest in verifying bank account automation. It’s a pleasure to have you here today. The VendorInfo application allows you to do several things. One is to verify not just bank account ownership, but also other important data, such as taxpayer identification number, addresses, whether folks are on sanctions lists, and so on.
And it’s modular, so you’re able to actually do this as an AP, as internally, or you can actually have this vendor facing and allow your vendors to enter the information and submit it and have it automated automatically as well. I’ll you a couple examples of each one.
One is if you wanted to verify a bank account, what would happen here is you’d come, your folks would come to a screen, and this can work for both domestic and international accounts. They’d enter the type of account, the routing number if it’s international, I’ll show you in a second, international information shows up, the account address, the city, the state, the zip, and then it would be submitted.
You can also have a form that would look like this. It would allow you to enter either US information or non-US information, and then it would ask for the appropriate information and then also bring up the appropriate information for that country and also in the language of that country as well.
Once that information is entered, what you’re able to do is take a look at it. If the bank account information is in a database, like in the United States, it is in many overseas countries, There’s also databases. When that happens, depending on the database, that information can come back immediately. And it certainly does for US.
So this is an example. This is our company, Financial Operations Networks. The information was entered, and it’s verified. And it’s verified according to a color code of green, yellow, and red. Green is good. red is stop and yellow is caution and what you can see is there’s a nine point check here a nine point verification process that looks at the routing number and the account number make sure that it’s a valid account but also checks the company name the street address the city the state the zip and the tin and this these verifications are are done against what the bank actually on file.
There’s also a picture and a map of the facility so you can see what’s actually, you can see that’s where that business is located and what it happens to look like. So this is an example of a good match.
In some cases all the data doesn’t match or none of it matches and in this this is a case with Crazy Jim’s Pizza that I’ll show you now with Crazy Jim’s, it’s yellow. And the reason it’s yellow is while it is a bank account that’s a valid bank account, and the name Crazy Jim’s actually matches. But the street address and the zip and the TIN have mismatches, they’re alerts. So they’re not great mismatches, but there are three of them. But the city and state don’t match really at all. and there’s warnings by them.
So this gives your folks a head up that either this is an invalid account or certainly an invalid account for that vendor or further investigation is needed. And we actually have a service that can do that further due diligence for you. And certainly we can talk to you about that and how it works if you’d like to do a deeper dive.
So, what I’ve shown you so far, it’s a bank account validation that happens internally. Your folks enter the information. The same thing can happen with looking at other areas that you’d like to validate for the bank, such as taxpayer identification numbers, addresses, whether they’re on any sanctions lists, whether they’re on any government lists, cybercrime lists, white collar crime lists, all of that is here in the system and it all comes up green.
Once again, this is us. But let’s just say there was an error in the TIN like there is with this particular example. It’s flagged red. And what this is showing is that the TIN actually is incorrect. and this is matched against the IRS database, and it’s come back and it’s not found.
You’re able within the system to email the supplier, whoops, let me just pull this over here. You’re actually able to email your supplier a note that says, hey, it looks like this information is invalid, please click on the link, and that can bring them back to a place where they can actually correct the information themselves.
You can also have the suppliers enter this information themselves. You would send the suppliers an invitation to come to the site, they’d come to the site, they’d register, everything’s secure, it’s multi-factor authenticated. By doing this, you actually eliminate emails that are going back and forth and eliminate an awful lot of paper-chasing that sometimes happens when trying to collect the information that you need from a vendor. But the vendor could enter all of the information you want. The system would accommodate your forms and your information requirements. You can have them fill out W-9s or W-8s.
You can also embed a substitute W-9 on the form if you prefer to go down that route. Of course, the vendor can then enter their bank account information, domestic and, excuse me, domestic and international. You can have places for collecting vendor diversity information, ESG information, you can actually allow the vendor to review documents that you have like your code of conduct and they can they can sign that or check off on that.
The vendor then goes and signs this and submits it and in virtually real-time all the verifications are done if it’s domestic, some international bank verifications can be done in real time, but some due to the different natures of different databases and countries that don’t have databases might actually take a little longer to get a return, but it’s all done for you and the system handles it automatically.
Then you’re able to go back to your dashboard and see the status of everything. Your folks are able to look at the forms that were submitted. They’re able to look at the verifications that occurred. And they’re able to actually process this according to your workflow for reviewing and approving information. And then what happens is all that information can be exported back for upload into your ERP system.
And what’s cool about this is that this can function because it’s modular, it can function as an entire vendor onboarding and verification application, but you can also use it modularly, so some folks actually use it just for the bank account verification or just for the TIN and sanctions and other verifications as well, but it streamlines what folks are doing today, it takes an awful lot of tedious manual work that is often, excuse me, that often just takes so much time and really free your folks up to do other things that you may want them to do that have higher value.
Q&A Session
Mark, I think this might actually be a good time to just ask folks if they have some questions, provide them with some contact details, and go from there. Let’s do it. We’re going to dive into the Q &A portion of this webinar. If you haven’t already submitted your question for Phil, or if you’ve thought of another question for Phil, go ahead, use the Q &A tool on your screen to submit your question to me now. We’ll answer as many questions as time allows.
Our first question up, Phil, is from Eugenia. Eugenia, they write, is the database larger in the United States? does the company have the ability to validate banking information in Asia, Europe, and Canada?
Sure. Great, great question. So the database in the United States is the largest country-based bank account database in the world. So it’s huge. But in 25, 30 countries also have databases as well. They don’t all work the same. None, in fact, very few of them work the same, and that, but it does allow you to verify bank accounts in those databases, but we also have a methodology to validate bank accounts in other countries where there is no database as well, or if it’s in a country where there actually is a database, but not all banks participate in the database, those can be as well, Eugenia. And I think that answers Esther’s question as well.
Thank you, Esther, for submitting your question. A follow-up question from Eugenia. If the bank account is green or matched or validated and it turns out to still be a fraud, who takes responsibility?
Yeah, that’s a really good question. So we have, we do have insurance against that, so you’ll be happy to go into the with you if you’d like to do a deeper dive.
Susan wants to know what’s involved in integrating this with her ERP. Great question Susan. So what happens is this data, once it’s entered and once it’s validated and once it’s approved, can actually be exported into a file that can be uploaded into your ERP.
Roger wants know more about your TIN matching capabilities. Sure, thanks Roger. So TINs are matched against the IRS database and once again those are instantaneous as well and while that’s happening the system is also screening against various sanctions lists OFAC, EU, UN, UK for example.
Yeah, Tomas had a question about that, wanted to know what sanctioned screening capabilities were built into the solution. Yeah, pretty much, you know, pretty much everything worldwide is built into the system and into the process.
Phil, a couple of our attendees are asking how fast you get a result from the solution. When the bank account is in a, for non-bank account information such as TINs and sanctions screening and others, that all comes back instantaneously. For U.S. domestic bank account information verifications, that comes back immediately, real-time. in for foreign countries, depending on the database and how the database works, it can come back immediately or it might could take a day or two.
Phil, what would somebody do if they wanted to take a deeper dive into the solution? Yeah, just reach out, shoot us an email at VendorInfo.com or feel free to email me or call me directly at the email and telephone number that you’re looking at right now. Be happy to take you on a deeper dive, answer your questions, and certainly see if there’s a way to help you incorporate those four best practices that Mark was talking about a little bit earlier.
And that will be our final word. Phil, thank you so much for an excellent presentation and for sharing your insights with today. And thank all of you for taking time on your busy days to join us. On behalf of Phil and VendorInfo, this is Mark Brousseau. Thanks everyone. I hope to speak with you all again soon.

