woman sitting at desk working on computer

Webinar: A Comprehensive Guide to Bank Account Verification

Transcript

Hello everyone, and welcome to today’s webinar, “Mitigate Your Risk: A Comprehensive Guide to Bank Account Verification Best Practices.” My name is Mark Brousseau, president of Brousseau and Associates. I’m pleased to be one of your co-presenters for today’s webinar.

Today’s webinar is sponsored by VendorInfo.

If your risk of payment fraud feels higher these days, well, you’re not alone. A recent study by the Association for Financial Professionals found that more than two-thirds of all organizations have experienced attempted or actual payment fraud within the past year. Fraudsters are becoming more brazen, and today it’s harder to detect and even harder to recover from the fraud schemes that they’re using.

During today’s webinar, we are going to show you how the way your organization verifies bank account change requests could be leaving your organization vulnerable to this payment fraud. Most importantly, we are going to provide you with a strategy for mitigating your risk of fraud. We’re also going to provide you with a demonstration of one solution that can automate the process of verifying bank account details.

To help me do all that, I’m pleased today to be joined by Phil Binkow, the Chief Executive Officer for VendorInfo. Hey, Phil, how are you today?

Doing great, Mark. Thank you so much. It’s a pleasure to be here.

Likewise. So today we’re going to talk about the risks of traditional approaches to verifying bank account ownership. We’ll discuss how automated bank account verification reduces your fraud risk, and we’re going to share with you best practices for verifying the ownership of bank accounts. Phil is going to provide you with a demonstration of VendorInfo’s solution for automating bank account ownership verification.

As I said, these days, businesses can be excused for feeling like they’re under siege by bad actors. Interpol, the FBI, and state attorneys general are all sounding the alarm. They’re saying that the way accounts payable departments are doing things these days are increasing our risk of fraud.

The move to remote and hybrid work environments disrupted long-established policies and procedures for the way that we go about approving invoices and managing requested changes to bank account details. And in many cases, organizations are feeling the pain. They’re feeling that their risk of fraud is higher, and the numbers bear this out. It’s not just paper checks that are responsible for fraud these days. Unfortunately, we’ve also seen a huge spike in fraud related to digital payments, and a lot of that fraud comes from email.

Yes, I said email. I know that when we were forced out of our offices at the start of the pandemic, email was an appropriate workaround. After all, we couldn’t be in the office to receive our paper and to be able to cut checks and physically approve invoices. The problem is that email is a workaround that I’d argue is no longer working.

Email isn’t secure. It doesn’t assure chain of custody. It doesn’t enforce separation of duties. It doesn’t log the actions taken on a document. It doesn’t provide us with visibility into where things stand in the process. It doesn’t provide systematic workflows. It doesn’t stop someone from deleting an important document ahead of our organization’s retention schedules. But most importantly, what email does is it throws the barn door wide open to bad actors across the globe who are keen on ripping us off.

They’re exploiting corporate America’s dependence on email with sophisticated phishing schemes designed to trick us into clicking on malicious links, opening malicious attachments, or inadvertently giving up our credentials for our systems. Then once inside our email networks or even inside our own systems, well now they have carte blanche to rip us off.

And the problem is there are lots of different phishing methods designed to get at our sensitive information. These aren’t the broad buckshot hopeful approaches of yesteryear. No, these are targeted approaches. Email phishing designed to trick us into opening an attachment or clicking on a link. Spear phishing, very targeted scams that use social engineering, perhaps data about us on LinkedIn or other social media sources to tailor the phishing scheme. So it seems like this person is a trusted resource. Whaling. This is when the con men go after senior executives in our organizations.

We’ve all received those phony emails from CFOs and other high-ranking executives urgently asking us to change bank account details for a particular supplier. Those came from whaling attacks.

But then there’s also “vishing”.

This is using fraudulent telephone conversations to impersonate legitimate executives and suppliers.

“Smishing”. The same concept, only this time with text schemes. We also see invoice phishing becoming more common, where fraudsters are submitting phony invoices that appear to be from legitimate suppliers, but are really their own.

We’re also seeing much more cross-site scripting where a fraudster directs us to a site that appears to be legitimate but really has a link in there that they control. Put it all together, and it’s no wonder that organizations are suffering more electronic payment fraud these days.

The problem is that the way most organizations go about verifying banking account changes is making things riskier. For many organizations today, most are using a mostly manual or semi-automated approach to verifying bank account change requests. When we’re relying on email and never sure who’s on the other side of that email, well that puts our company at great jeopardy of being the victim of payment fraud.

And these fraud losses can add up fast. We tend to focus on the financial losses associated with payment fraud. In other words, the money that’s lost from our accounts. But the fact is that’s only the tip of the proverbial iceberg. We also have chargeback costs. There’s the legal fees associated with recovering from a fraud scheme. There might be insurance costs. There’s, of course, the time that our staff must spend remediating and researching the situation. And then there’s the impact on our partners. In many cases, we require our vendors to jump through hoops in order to do business with us because we’re so fearful of being ripped off. In many cases, we delay payments to suppliers, legitimate payments to legitimate suppliers because the antiquated approaches we have for verifying systems turn up false positives. Put it all together, the fraud losses, the administrative expenses, and the partner impact, and only then can you get the total cost of fraud. It’s no wonder that businesses are losing billions of dollars every year to fraud losses.

In fact, businesses in the United States are now losing more money to payment fraud each year than to bank robberies. I know what you’re thinking. Bank robberies are far more exciting than payment fraud, but neither of ’em is something we want any part of.

Think about the way that your organization is probably going about verifying bank account changes. Perhaps you use the so-called petty test where you deposit a small amount of money into an account to make sure it’s there. It tells us if the account is open, but does it necessarily tell us much more? Maybe you call or maybe you even email (don’t do that) a supplier to make sure that the bank account change request is legit. Hopefully you have the contact information on file for the trusted source. If not, then you’re really flying blind. Perhaps you call or you email the internal stakeholder or sponsor for the supplier to ask them to help you verify the information, to help verify that this is a legitimate supplier. Maybe you ask the supplier to provide a bank letter or void a check. Maybe you go ahead and you match the bank that the money is being asked to be directed to, to the country in which the supplier is based. If there’s a mismatch, that of course is a red flag. Perhaps you ask your suppliers to provide you with the details of their previous bank account or maybe the details of the last invoice for which you paid them. Maybe you call or you email the bank involved in the change request to see what they’ll tell you about the legitimacy of the request.

While all of these have some value to helping you ensure that the bank account change request is legit, the fact is almost all of ’em fall short in some very important ways. And that’s not my opinion, that’s your opinion. When recently asked what they see as the greatest risk in vendor onboarding, accounts payable, and procurement professionals identified fraudulent bank account information as their biggest risk, and it wasn’t even close for second place.

The fact is, we know that the way we’re verifying this information is risky. The question is, what do we do about it? After all, these traditional bank account verification approaches take a lot of time. You’ve got to collect this information, you’ve got to track down the right person to call or email. It’s really hard to scale these manual processes. So as our business grows, who has the time to do all this checking? Of course, these traditional bank account verification approaches are vulnerable to social engineering. There’s a lot of information about us and our businesses online, and it’s easy to use that information against us.

I spoke at an Institute of Finance and Management conference two years ago, and a woman in attendance came up to me after the session and she told me of an exercise she did at her kitchen table. Just a few weeks before, her business had been recently burned by a fraudulent bank account change request. She was curious how hard it was to create one of these phony letters. So she challenged her high school son to go off and see if he could create a letter that could potentially dupe her. She told her about a couple of suppliers her company did business with, and she told me that within the hour her son exuberantly came back and showed her a letter he had created, complete with the logo of the supplier, a name of the actual trusted resource at that supplier (it was the AR person), and a letter that read like it wasn’t written by a high schooler but by an actual person who might be in AR. This is when she realized just how big the risk was to her organization and those of her peers.

The thing is, traditional bank account verification is largely ineffective against these types of social engineering and phishing exercises, and it’s hard to adapt them as new schemes come out. In many cases, we built these traditional bank account verification approaches to address our paper-based world, and we know that today much more of our business is being conducted via PDFs or electronically.

It’s also hard to be able to access the information we need for these approaches. There’s little real-time verification involved. It all takes a lot of time and put it all together, it’s expensive and also ineffective. When we talk to AP and procurement professionals about what they are trying to automate in their department, well, it’s bank account verification that stands apart. And again, it’s not close.

Organizations recognize that in order to mitigate their risk and to improve the efficiency of their department, they’ve got to find a better way to verify bank account change requests. That’s why more and more organizations are deploying online self-service supplier portals that have automated bank account ownership verification capabilities built in.

A self-service portal allows a supplier a place to go to provide information that their buyer needs to verify their information that they’re a payable supplier. This, of course, would be things like contact details and bank account details and TIN numbers and even tax forms and such. Well, what’s happened is that leading portal suppliers have extended the capabilities of those portals to provide some backend verification and validation capabilities. One of those is the ability to automatically verify bank account ownership. It can verify that the account name matches the one that the bank has on record for that account. It could verify the address, the bank account number, the routing number, and even the TIN number. Put it all together, this provides organizations with some pretty awesome capabilities.

First of all, it’s a real-time verification of the information that you’ve been provided by the individual, and you get immediate notification and alerts of information that doesn’t quite match. You’re able, through a user-friendly interface, to immediately be able to see what information needs additional review. You can establish custom verification workflows, so when there is a mismatch of information, you can decide who reviews that information and also the steps that they should take.

What’s more, all the information that’s collected through these automated bank account verification solutions is collected over time, so it can be audited by anyone. You can also have comprehensive reporting, so there’s never any guesswork about who made what decision. This provides you with tremendous accountability.

What does this mean to an organization like yours? Well, it means that you can finally turn the tables on the fraudsters. You can use sophisticated technology just as they are, only this time it’s to stop ’em in their tracks. Of course, bank account verification can help you mitigate your risk of falling victim to payment fraud. The process is fast and efficient, so it’s no longer a burden on your staff. There’s no longer the chance that an overworked employee will cut a corner or overlook something just because they’ve been burning the midnight oil on their so-called day job. The information is going to be accurate. The technology has a high level of accuracy. It allows you to have consistent and standardized processes so there’s no more human judgment involved. All of the data goes through the same processes based on your rules.

What’s more, automated bank account verification solutions are easily adaptable to whatever schemes the bad guys cook up. You better believe they’re thinking of ’em right now. And what’s more, these solutions are scalable. As your business grows and as you onboard more suppliers and manage their data, you’re going to be able to easily scale your operations without the need to hire additional staff or to push things to the back burner.

There are some best practices that organizations should be taking to help ensure that their bank account change requests are handled in the appropriate manner. The first is, of course, stay informed about the types of scams that the con men are using against our organizations. And there are lots of them, and they’re changing all the time. You also want to make sure your employees know about these scams. Make sure they know what to look for. This isn’t a set-it-and-forget-it kind of thing. You need to make sure you’re regularly letting your employees know about scams and the steps they should be taking.

You also want to periodically conduct security reviews, test your staff to make sure they’re doing the right things. Are they clicking on those links? Are they opening those attachments? Are they verifying these email addresses before they start engaging in conversation? There are ways to do that. You also want to make sure that you’re regularly updating your procedures. This is not one of those things that you create a policy and you put it away somewhere on a shelf never to be seen again. The fact is, you want to make sure that you are adapting to the fraud schemes that bad guys are using.

You also want to make sure that you’re directly communicating with your suppliers. They’ve got skin in the game too. You’ve got to make sure that they’re doing the right things on their end to help prevent being hacked and so their emails aren’t being infiltrated and generating these phony emails in the first place. You also want to make sure you verify changes through multiple channels. There’s no magic bullet here. You want to use as many tools as possible to make sure bank account ownership is legit. You want to be vigilant. You want to make sure that you use technology to help you identify anomalies. Is there an invoice amount that’s out of range? Have you suddenly started receiving invoices more frequently from a particular supplier? Have you now received an invoice for a supplier whose address has recently changed, or bank account details have recently changed? If so, these are all indications that you might want to take a closer look at what’s going on with the supplier’s account.

And finally, you must automate. We can’t rely on manual processes. The risks are too high for our organization, and you better believe that the fraudsters are already availing themselves of the types of technologies we’re talking about here today. So you want to level the playing field.

But you don’t want to take my word for any of this. Here’s Phil to show you how one solution, one from VendorInfo, can help your organization mitigate its risk of fraud.

Mark, thank you very much. Appreciate that. And thank you. Hi, everybody. It’s good to be here today. Mark, can you see my screen? Can everyone see my screen?

We can. You might want to make it full-sized.

Okay. Alrighty. Let me just move this over a little bit. I think that’s about as full size as it’s gonna. Okay, so thank you everyone. However, if you’d like slides of this demonstration, when we’re done here, you’ll get my email address, and we can send you screenshots of everything in the overview.

For bank account validation, there are a couple of things that happen. Number one is instead of sending emails back and forth with information or talking to the folks over the phone, what can happen is your vendors can go to a portal that’s branded to look just like you. Here are some examples. Casio’s USA looks like this. Asics, this is the log-on page for them. Fox looks more like this. Milliken’s log-on page. Adobe’s is a little fancier. Coca-Cola, of course, is pretty clear as well. So the vendor comes and they can go right to a banking form, and then they can fill in. Of course, they would log on, and they would fill in the information that you want them to submit, basically, their company name. You can have, if it’s a bank change, you can have them add their current banking information, the new banking information. They would fill that in, they’d sign this and submit it. You can also have them upload a voided check or a letter from a bank or any other corroborating information. Then they click submit after they sign this, and instantly that information gets verified.

I will show you what a verification looks like. I’ll show you a good one, and I’ll show you one that’s maybe not so good. A good verification is green. Suspect ones are yellow, and bad ones are red. This is one—there are eight points that get validated. The routing number and the account number, but also the company name, the street address, the city, the state, the zip, and the taxpayer identification number. If all those are perfect matches, they come up in green and say valid match. But if they’re not, then with this demonstration example for Crazy Jim’s Pizza here, what that would look like is this. What you can see is that this is an actual account because the account is valid and Crazy Jim’s matches the name on the account, but the street address is suspect. The zip code is suspect, the TIN is suspect, and the city and the state are even more out of alignment. The difference here between an alert that’s in yellow and a warning is a difference in degree. So an alert might be, it’s not a perfect match, but there is some matching here that’s going on. Perhaps the problem is a typo of some sort, but a warning is pretty much out of kilter. When this happens, you can have other ways, of course, to go back and validate that account. Your folks can review that information. You can see the documents that got submitted, and as they are reviewed, they can be approved by one or more levels, one or more paths. Then that information can be uploaded into your vendor master file if everything’s okay. If there was an error on it, something that was not correct, this little email icon here can go back to the supplier, and you can send them a note that says, you know, please fix that information, whatever it happened to be.

There’s more as well. Not only will this validate your bank account, but you can also validate your vendor’s identity by having them fill out other important forms on the site as well. For example, they can fill out a W-9 and they can sign it. Once they do that and submit it, then that’s going to get verified too. The TIN’s going to get verified, the address is going to get verified. I’ll show you a list of most of the things that are getting verified here. You can also have them fill out their W-8s online if it’s an international supplier. There’s a little wizard here that guides the supplier to the right W-8. It’s pretty cool, so they don’t have to guess at which W-8 to use. The wizard also walks them through the W-8. This happened to be a BEN-E. You can have them fill out your own vendor information form, and they can fill that out. Whatever information you’re requesting can be on the form. They sign it and submit it. When the W-9 is submitted, you get an even greater group of verifications, and I’ll show you what that looks like.

In this particular case, we can see that the TIN was matched correctly. This happens to be our company, Financial Operations Networks. It’s not on the Death Master File. There was a complete address, as Mark was talking about earlier. It’s not on any sanctions lists: OFAC, UK, UN, EU, others. It’s not on, particularly if you’re in healthcare, it’s not on any of the OIG lists, whoever this company is, or if it’s an individual. There’s about 40-50 verifications here that are actually being checked. Once again, green is good.

On the other hand, if there was a problem, like here for John Smith, in this particular case, there was an error with the TIN, and the address is suspect too. So once again, when everything else was okay, but once again, when that occurs, you can click on the envelope icon, and that will bring up an email. It says, whatever the problem is, please verify your TIN, please verify your address. There seems to be a discrepancy. When they click on this link, it takes them right back to the form. As Mark was discussing earlier, everything that anybody does is totally tracked: who did what, who filled out what, who reviewed which item, when they did it, what steps they took. Once this is all approved, then it can be uploaded into your vendor master file.

What happens here is not only are you getting the ability to verify bank account ownership, but it also goes a step deeper and allows you to get information to know your supplier and do background checks on them so that when you get this information, it’s not problematic, and it is in spec. Importantly, it goes into your vendor master file, and it’s accurate. A clean vendor master file starts with clean data going into the vendor master file.

Mark, let me just ask—oh, there is one other thing here. If you want, you can also do one-offs. So the vendor doesn’t have to fill out the form. If you have a one-off, you can do a bank account verification on one-offs as well. You can also do one-offs on TIN verifications as well. It just gives your admin team a little more flexibility to get the job done and to get it done really quickly in an automated way. It gives you an answer immediately.

I think at this time it might be good if we open up the floor to some questions.

Let’s do that indeed. If you haven’t already submitted your question or if you’ve thought of another question for Phil, go ahead, use the questions tool on your screen to submit your question to me. We’ll answer as many questions as time allows.

Our first question up, well, it’s from Holly. She writes, will we receive recordings or handouts from this webinar? And Holly, yes, you will. In the next few days, we will send you the recording from this webinar.

Our next question up is from another attendee. They write, hello, is your software matching the company name to the bank account information, or is the bank account verification just stating that an account is in good standing?

Great question. First of all, it’s demonstrating that it is in fact an account that’s open. But it’s also telling you that the ownership on it is matching the ownership of that account with the information that the vendor put in. So it is verifying the bank account ownership as well as whether or not that account actually exists and is open.

That question was from Mark, no relation. I apologize, Mark, for not having that. You said your name at the beginning.

Our next question up is from William. William writes, what is the information being validated against?

The information is being validated against information that the bank has on file for who owns that bank and what the address and the TIN are. There are eight different data points: the bank account, the bank account name, the street address, the city, the state, the zip, the TIN, the routing number, and the account number for the TIN. The OFAC and other verifications obviously would not match against the bank account because that’s a different database. TINs are verified against the IRS database, directly with the IRS. OFAC sanctions lists are validated against the various sanctioning entities themselves.

Jenny wants to know, is this a standalone platform or do you offer integrations with different ERPs?

It can be either. The system is modular, so different components of the system can be implemented. Some people just want to do bank account verifications, others want to do bank account verifications and TINs. They can stand alone, or they can also take the approved information and integrate it with your ERP and upload it right into your vendor file.

Lewis wants to know, will this work outside the US, for example, for accounts in Latin America and the Caribbean Islands?

Absolutely, it doesn’t matter. We have customers who have operations all over the world. Your location will not matter.

Lisa writes, we do not have an ERP and a system without API interface connectivity. Can we have tools to just handle one-offs?

Yes, indeed. The modularity of the system really lends itself to that. You really don’t have to boil the ocean if that’s not what you need. If what you need is to do the one-offs, you can get that functionality very easily.

That brings us to a question from Mark. He wants to know, is it possible to do just one-off verifications and not run our vendor management through VendorInfo first?

Yes, it absolutely is.

Anna wants to know, if a fraudster opened an account with the same company name and uses information from the company website, how would that information be validated to avoid payment to a fraudulent account?

That’s a really good question. Banks are highly regulated and extremely sensitive to this particular issue. For banks, KYC (Know Your Customer) protocols and policies and procedures are just huge. To open up a business bank account, it’s not like it was 15-20 years ago. You really have to provide documentation from your Secretary of State as to who you are. You have to provide letters, corporate resolutions, they require all kinds of information. And, of course, it’s matching. The TIN, everything is being matched against what the bank has on file for that particular vendor: address, TIN, city, state, their name. The bank has some responsibility to make sure that the customers are who they say they are, and they take that very seriously.

Melissa wants to know whether your platform can verify tax numbers for vendors located in Canada.

In some cases it can, but there are some limitations on that. Just send me an email and I’ll be able to provide you with that information as well.

One last question, this one’s from Mark. He wants to know, so how do we sign up to chat about the cost?

The costs are based on what the scope of work is and the number of verifications that you do, and a number of other factors. But if you call me at the number on your screen or shoot me an email at pbinkow@vendorinfo.com, we can have a quick chat and get an understanding and give you an idea of what is involved here.

That will be our final word. Hey, Phil, thank you so much for an excellent demonstration and for sharing your insights with us today. And thank all of you for taking time out of your busy days to join us. On behalf of VendorInfo, this is Mark Brousseau. Thanks so much for joining us. Hope to speak with you all again soon.

Share This Post