Transcript
Hello everyone, and welcome to today’s webinar, “Beyond the Basics: Advanced Bank Account Verification Strategies for Accounts Payable Professionals”. My name’s Mark Brousseau, president of Brousseau and Associates. I’m pleased to be one of your presenters for today’s webinar. Today I’m joined by Phil Binkow, chief Executive Officer of VendorInfo, the sponsor of today’s webinar.
Hi, Phil, thanks for joining us.
Hi, Mark. Thanks.
It’s great to be here.
The risk of payment fraud is at an all-time high. There are lots of reasons for that, as we’ll discuss. But the fact is that one of the biggest vulnerabilities in many organizations is the way that we go about verifying bank account details and changes to bank account details. Today, high-tech conmen have set their sights on infiltrating our departments through these antiquated processes. It’s for that reason that more organizations are looking at automating the process, deploying automated bank account ownership verification solutions in many cases, integrated into their self-service supplier onboarding platforms.
During today’s webinar, we are going to discuss how automation improves bank account ownership verification. We’re going to share with you some key considerations when evaluating bank account verification solutions, and Phil is going to provide you with a live demonstration of one solution that can automate your bank account ownership verification. And of course, we’ll leave time for your questions at the conclusion of today’s presentation.
If it feels like your risk of payment fraud is higher, you’re not alone. Whether it’s account takeovers, business email compromise attacks, phishing schemes, or phony invoices, fraudsters have set their sights on accounts payable departments. One of the most difficult fraud schemes to counter these days is phony bank account change requests. Corporate America’s dependence on email to onboard suppliers, manage invoices, and chase down approvals on approved invoices has left us vulnerable. It’s created a soft underbelly that fraudsters are all too eager to exploit.
In many cases, these schemes work something like this: they target an organization, do some reconnaissance to try to figure out who they should be targeting, then use LinkedIn and other online sources, even reputable news publications, to do some social engineering to understand who the target organization does business with, who their accounts payable person is, and maybe even identify who that person is likely to be working with from an AR standpoint with their suppliers.
Next, they go about the process of what we call phishing or spoofing, sending some emails to try to gain access to a supplier or trusted coworker’s email system. We all know the drill. Maybe it’s an email out of the blue asking us to verify the credentials for our ERP or office platform. Maybe even worse yet, our bank portals. When we’re in a rush, we might be too eager to go ahead and plug that information in and cross this off our to-do list, never realizing that we’ve just given up our credentials to a bad guy or bad girl.
And this isn’t just us we have to worry about; it’s also our suppliers too. Some cases they gain access through malicious downloads or software embedded in malicious downloads or links. Once they’re inside an email system, then they have the ability to spoof the legitimate party. Well, now they submit a fraudulent request to change bank account details.
Perhaps you’ve received them. Urgent.
This needs to be done at once. Oftentimes, it comes from a CFO or other C-level executive, maybe even from a reputable supplier. Oftentimes the language is convincing. Remember, these fraudsters will have infiltrated your supplier’s email or even your coworker’s email, so they know the types of things you talk about, the language you use between one another, and they could be awfully convincing. Once you’ve made that change and initiated that payment, as soon as it hits the account, it seemingly is swept away to a far-off bank account. These schemes are hard to detect and, in many cases, even harder to recover from.
It’s for this reason that more and more organizations are integrating automated bank account ownership verification into their AP processes. I know a lot of you are probably using things like penny tests or emails or phone calls or maybe even requesting information from a requester, such as telling me the information on the last invoice that you submitted. But the problem with a lot of these outdated approaches to verifying bank account ownership is that they have holes.
Take those penny tests, for instance, one of the most popular ways to verify bank account ownership. Well, if your supplier’s been hacked and the bad actor has access to their email, guess what? They could go ahead and approve that penny test. I probably don’t have to tell you that email is going to be wide open for fraudsters as well. And now we’re seeing fraudsters using things like artificial intelligence to be able to mimic the voice of trusted parties such as suppliers or coworkers so that even phone verification isn’t foolproof. And let’s face it, it’s not even easy getting somebody on the phone these days.
This technology does a lot to help streamline the process and mitigate our risks. It verifies information in real time and provides us with notification and alerts of suspicious or potentially fraudulent transactions. It does it in a way that’s user-friendly, so it’s really easy to use these solutions, and they allow us to add some custom workflows so that when it detects something that doesn’t seem quite right, well, we could set the rules on who it is that responds to it. All along the way, you’re going to get complete audit tracking, so you can see all the information that was collected and all the actions taken on a transaction, and there’s complete reporting on the backend.
Put it all together, and this significantly mitigates our risk of fraud. It does it in a way that’s fast and efficient. It provides us with better data accuracy than trying to collect information via email or phone calls, or in some cases even faxes. What’s more, those workflows we discussed will ensure that you have consistent and standardized processes. There’s no room for corner cutting when you have digital workflows. These solutions are adaptable. Remember, the fraudsters these days are sophisticated. These are not just fly-by-night organizations. In many cases, their business is to rip you off. And so they’re constantly evolving their tactics. The good news with an automated solution, like what I’m describing, is it can adapt with the new schemes. Finally, these solutions are scalable. There’s no need to hire additional staff. As your business grows, the technology does the heavy lifting; it does the work for you.
But that doesn’t mean that every bank account ownership verification solution is created equal. There are a couple of key considerations you need to keep in mind when you’re evaluating this technology to ensure that the one you choose will help mitigate your risks.
The first consideration is which accounts the technology covers. You need to be sure that the prospective bank account verification solution works with the types of banks that your suppliers are probably doing business with. So is it just domestic? Or if you’re a global business, will those solutions support those bank accounts as well? To be quite honest, verifying global bank account ownership is a lot trickier in some cases than domestic, so this is something you want to make sure that you get right.
The second consideration is how easy the solution is to use. You want to ask a prospective vendor, how is the vendor bank data collected and what vendor bank data is collected? How hard is it for me to review the information? Is it intuitive? Will things be presented in a plain way that I can make informed and speedy decisions? What information am I getting back from the solution? Will this provide me with all of the details I need to make that good decision? You also want to make sure that the solution is tracking all verifications. We don’t want any second-guessing at the back end of this. Remember, frauds are very sophisticated and they’re counting on things slipping through the cracks. You want to make sure you have auditing of all the information that is checked.
Third, you want to understand how the bank account verification solution matches information in bank account fields. It’s one thing to say, yeah, these bank accounts match or this bank account’s open. But you want to make sure that all the information lines up so you can be confident that this is a legitimate bank account. So look for a solution that can match routing numbers and account numbers. You certainly want to make sure that the name on the account matches the name of your supplier; that should be a red flag. You also want to make sure that the address on the account matches the address of your supplier.
For instance, if your supplier’s based in Texas, you want to make darn well sure that this solution is going to flag a bank account that’s located in Eastern Europe. You also want to understand whether any of the bank account information is old, whether that bank account is still open, and whether there’s any invoice information that’s available. You want to be able to match all this information to give you the highest level of assurance that the bank account is legitimate.
Next, you need to understand exactly how the solution is configured. By that, I mean you want to understand how it’s deployed in your organization. Is this an automated standalone solution, or is it an automated solution that can integrate into, say, a self-service supplier portal, which is already providing you with workflows for onboarding suppliers? Or is the solution integrated into your accounts payable solution? Or is this a standalone manual process, which is probably the last thing your organization needs? Be sure to ask these questions upfront. You also want to make sure that if you need the solution to integrate with any downstream systems, such as your ERP, that you ask those questions upfront, not after you’ve signed the contract.
The fifth consideration is the glass-half-empty kind of things. What happens when something turns up that’s not so good? How are those not-found results handled? What level of detail is provided? What if some of the information matches, but some doesn’t? Some solutions provide you with what I call a stoplight. Green means all clear, go. Yellow means some of the information’s right, but some doesn’t line up; somebody should take a look at this. Red means we’re pretty certain that this is not a legitimate account. You want to be able to configure your workflows or business rules for viewing those results that require review. You want to make sure that’s easy for your staff to do so that you’re not always dependent on going back to the vendor and paying professional services charges to reconfigure those workflows. This is an important consideration when evaluating solutions.
The sixth consideration when evaluating bank account ownership solutions is to understand what other verifications are available. While the focus of today’s webinar is on fraud, the fact is there’s lots of other risks as well. You want to make sure you are striving to have a holistic approach to streamlining your supplier onboarding and vendor master data management. So you probably want to ask prospective vendors, how do you handle things like TIN matching or OFAC checking or sanction screening or validations of other information that might be in the vendor file? If you can find a solution that offers these capabilities in a modular approach, you will be able to really provide a solution that will deliver optimum benefits to your organization, not just reduce your hands of fraud risk but also help ease your compliance burden as well as your operational strain.
But don’t take my word for it. Phil wants to show you a demonstration of one solution that can help you mitigate your risks of fraud. This is a bank account ownership verification solution built into VendorInfo’s self-service portal. Phil?
Thank you so much, Mark. Is my screen okay for everybody to see? Yeah, you might want to go ahead and blow it up, Phil. Okay, hold on. Let me move it to another place. Is that better? No, we’re seeing you and your lovely wife, Nancy. Oh my goodness. Okay. But you’re scoring points with all the attendees by showing your wife. Yes. I’m hopefully I’m scoring points with you. There we go, Phil. It was there. Hold on. Oops. Hold on, Mark. You’re fine. Here we go. Perfect, Phil. Oh, almost perfect. There we go.
All right. Thank you everyone, and I apologize for that brief technical delay here. Let me just bring this up a little bit. There we go. There’s a couple of ways that you can configure this really great bank account verification tool. It can be three ways really. One is vendor-facing, another is internal-facing, or you can have it both vendor and internal-facing. If it were just internal-facing, your staff could enter the bank account information, the type, the routing number, the account number, and in the interest of time, I’m showing you the domestic version, but this also does international as well. You would have the type, whether it’s commercial or individual, the appropriate information that needs to be entered would be highlighted. It would be entered, and then it would be submitted.
If it was vendor-facing, you can do a few more things. For example, if it is a bank account change, you can have the vendor put in not only the new bank account information but the current information as well. Another cool thing here is you can do a little vetting of the person filling out the form by asking them to add some information such as a current invoice number, a current invoice amount, or a current invoice date to help validate that they actually are the right person. They would fill out the information here, and then they would sign this and submit it. You can also have them upload documents such as voided checks or bank letters as well for additional verification.
Once they click on the submit button, a cool thing happens. It’s automatically verified in real-time. This happens to be one of our accounts. I’ll show you Financial Operations Networks, and everything came out okay here. We’ll click this and see that green is good. Yellow would be not so good, and red would be really not bad. Not only does it show either red, yellow, or green, but it also shows where a problem might lie. There are eight validation points here on the domestic side. Wells Fargo is the bank, and that’s the routing number and the account number. What this means is that this is actually a valid account. It’s an open account at Wells Fargo. If you were doing a penny test, for example, if you’re doing those today or prenote, then this eliminates the need to do that just to make sure that the bank account is valid.
In addition, the system also validates the company name that the bank has on file or the individual name if it’s an individual account such as maybe an independent contractor, the street address, the city, the state, the zip code, and the TIN, and in this case, everything matches. This one looks good. If there was an issue, like here with Crazy Jim’s Pizza, which shows up yellow, then some remedial action can be taken. For example, in this particular demonstration example, it’s a valid account. The routing number and the account number actually match, and the name actually matches Crazy Jim’s Pizza. But there are discrepancies on the address, the street address that is, the zip, and the TIN. Those are called alerts. The system calls those alerts. On the city and state, there are warnings. The alerts are in yellow and the warnings are in red. The difference between the alerts and the warnings is a matter of degrees. An alert might be one or two characters off, perhaps a typo. The warnings indicate there are many more characters off; there’s something wrong here. You would definitely want to take a closer look at this particular request to change or add a bank account.
Additional verifications, as Mark mentioned, can also be undertaken. For example, you can have the vendor fill out a W-9 on the application or even a substitute W-9 and collect other vendor information as well. The vendor can sign this here and submit it. When they do that, we can go back to our review and see exactly what happened here. In this particular case, a TIN match was performed, an address match was performed, and like on the banking verifications, green is good. Everything here matches. This happens to be us as well. Everything here matches. We’re not on the death master file because that’s a list that was checked as well. The address matches, and we’re not on any sanctions lists such as OFAC, UN, EU, or UK, or any of the sanctions violator lists. There are foreign financial and corruption lists that are checked as well. All of those are checked automatically in real-time.
If there was a glitch, like there is here with John Smith, it’s a little red circle with an arrow, with a check mark in it. In this particular case, the TIN did not match, and the address was suspect. Everything else looked pretty good. But here, it might be a typo. What you can do here is actually use the system to click on the little envelope icon. An email comes up and it automatically goes back to the individual, asking them to fill out the form again. The system keeps track of all changes and attempts, recording who did it, when they did it, and what they did. Your audit folks will have a complete audit trail of everything that anybody ever did within the system.
To summarize, what we’re looking at is a way to have either an outward-facing tool for your vendors to submit information or an inward-facing tool for your team to do it, or both. The bank account information is verified. You can also verify other information. You can include questions such as invoice numbers and invoice amounts, have them upload additional data such as voided checks or letters from the bank to ensure you’re actually paying the right person. The identity of the person who’s submitting the bank account is verified automatically. Once all of that is done, you can take this and all the information and upload it directly into your ERP system to save you the data entry activities as well.
Mark, I think that gives us a pretty good high level and somewhat detailed look at this. If folks would like to contact us or if they have some questions right now, we’d be happy to take those.
That brings us to the Q&A portion of this webinar. If you haven’t already submitted your question for Phil, or if you’ve thought of another question for Phil, go ahead. Use the Q&A tool on your screen to submit your question to me now. We’ll answer as many questions as time allows.
Phil, our first question up is from Anthony. He is wondering, so how do you do all these checks? Sure. Great question, Anthony. The checks use various databases. For bank account verifications, we’re using Early Warning System. We’re using other sources globally to verify the bank account. For IRS TIN matching, we’re actually going to the IRS site. The address uses the Post Office site. The death master file uses the IRS site. For sanctions checking, the system is using downloads every day from the various governmental agencies that issue the sanctions, such as EU, UN, UK, and the Treasury Department in the United States for OFAC.
Verina wants to know, are there industry-specific validations that can occur? That’s a really good question. The answer is yes, and it depends on the industry. For example, with healthcare, looking at the OIG list is really important, and it’s true for non-healthcare companies also that have government contracts. The OIG list is a list of companies that the government wants you to not do business with, so the system can check that as well. There are other industry specifics. We can certainly talk about yours if you’d like and show you how that’s done.
Ron wants to know, what is the level of IT involvement required to integrate this platform into our ERP? It’s minimal. There are a number of ways to integrate it. We just want to talk with you and your IT team, but usually, our customers are telling us that it’s just not a big deal at all.
Another attendee wants to know, does this support global bank accounts? It does. It does support a bank account pretty much anywhere in the world. Another attendee wants to know, has this been integrated with Coupa before? Yes, we can give you examples of that as well.
Phil, what other advice would you give to folks who are considering automating their bank account verification? Which recommendation do you think stands out as being the most important, Phil? I think getting a system that is easy for your team and the vendors to work with is really key. Having one that minimizes the amount of effort that your team would need to put into it, whether it’s IT getting it set up, which is minimal, or the actual day-to-day use, I think that’s critical as well.
Certainly, do it. I think automating this is a way better way to go. It gets you ahead of the curve. It really eliminates a lot, and it’s trackable for one thing, and it eliminates a lot of manual work for both you and your vendors. I think integration with your systems is important as well. There are a number of criteria. The number one is to do it. These bad guys are just getting better at applying their trade, and this is just another way of implementing a tool that helps you stay ahead of them and ward off any problems that could arise.
That will be our final word. If you’d like more information on VendorInfo or a demonstration of the solution Phil showed you today for your team, I invite you to contact Phil at the information now displayed on your screen. On behalf of VendorInfo, this is Mark Brousseau. Thanks so much, everyone, for joining us today. Hope to speak with you all again soon. Thanks, Mark.

