woman sitting at desk working on computer

Webinar: Bank Account Verification Essentials for AP Professionals

Transcript

Hello everyone and welcome to today’s webinar, “Navigating the Risk Landscape: Bank Account Verification Essentials for Accounts Payable Professionals”. Today’s webinar is sponsored by VendorInfo. My name’s Mark Brousseau. I’m pleased to be one of your speakers for today’s presentation.

Today, I’m pleased to be joined by Phil Binkow, Chief Executive Officer at VendorInfo. Hey Phil, thanks so much for joining us. Hey, Mark. Thank you. It’s a pleasure to be here. Thank you for inviting me. If it feels like your organization’s risk of fraud is higher these days, well, you’re not alone. Today, AP leaders identify the risk of fraud as their number one concern.

There’s no question that the shift to remote and hybrid working has disrupted established policies and procedures for how it is that organizations onboard suppliers and manage bank account change requests. What’s more, fraudsters have new tools these days for making it easier for them to perpetrate their crimes and harder for you to detect and recover from them.

But there are steps that organizations can take to mitigate their risks, and that’s the focus of today’s webinar. We’re gonna talk about this rising risk of fraud. We’ll show you some strategies for mitigating your organization’s risks, and we’re gonna provide you with a live demonstration of one solution that can help your organization automate the verification of bank account ownership change requests.

So why is it that the risk of fraud feels higher these days? Well, there’s a number of factors that are driving this fear, and rightfully so. The first, of course, is corporate America’s dependence on email. The fact is, is that email wasn’t ever designed to manage sensitive information and it creates opportunities for fraudsters to exploit vulnerabilities in our digital channels. In many cases, it’s emails that are the entry point for bad actors to get inside our systems.

Once they’ve hacked a supplier or stakeholder in our organization, well now they can perpetrate crimes like phishing schemes. Other bad actors are using email for things like account takeovers to be able to collect the credentials either from malicious software that’s downloaded or clicked on in a link. That has brought rise to more sophisticated cybercriminal tactics. Phil and I are old enough to remember the day when we all thought that, well, if we only got rid of these paper checks, then we’d eliminate our risk of fraud. And while checks have indeed declined in volume, the fact is is that fraud is down at an all-time high. What none of us could have anticipated is that fraudsters would use electronic payments against us today. Sophisticated technologies such as artificial intelligence are enabling fraudsters to continuously evolve their tactics, many cases it feels like they’re one step ahead of us.

And for those of us who are dragging our feet on automating our AP departments, well, they are at least one step ahead of us. We also see that fraudsters are using data breaches and identity theft to be able to perpetrate more crimes today. Being hacked with a data breach does more than just create some near-term concerns. That information often finds its way into the dark web, and it can be used against us at opportune times for fraudsters. While many organizations have spent a lot of time fortifying the firewalls that reside around their organization, in many cases, there’s a soft underbelly. Our systems internally make it hard to detect that we’ve been hacked. And in many cases, fraudsters can use new technologies to infiltrate even the hardest of firewalls. Globalization and cross-border payments create additional challenges for securing our information.

Then there’s the fact that many of us have staff who simply don’t know the risks that they should be aware of. Many organizations take what I call a set-it-and-forget-it approach to training staff on fraud risks. You know the drill. We sit a new hire down and tell them about the things they should and shouldn’t do to protect data and tell them about the things to look out for, and then we send them on their way. Well, the fact is, is that fraud tactics are continuously evolving. It’s imperative that our team knows those telltale signs to look for. Because of the turnover in our departments, well, we can’t count on seasoned staff to catch things all the time. Now with our staff working remotely, well, we can’t swap notes, if you will, at the water cooler. Fraud is definitely higher these days.

What’s compounding the problem is that in many cases, the way that we go about managing vendor data creates even additional vulnerabilities. The fact is, is that today we have lots of vulnerabilities around vendor master data management. There’s changes to our business. There’s rules and regulations we have to be mindful of. There’s constantly changing internal processes. All the while our suppliers expect us to deliver an exceptional experience throughout the vendor onboarding and vendor master database management process. When you factor in those fraud schemes, well, it could be downright hard because the reality is most organizations are using what I’d call a manual or semi-automated approach to onboarding vendors and managing changes to their vendor information.

You know the drill. A stakeholder in your organization collects some forms or requests to onboard a supplier. In many cases, those forms are PDFs. Some of you still rely on paper. Many of you have packets for new suppliers that could be 13 pages long. When you finally get the information from a vendor, now you’ve gotta check through it, make sure you have all the information you need, probably pass the documents around to different people in your organization where that information is probably re-keyed and somehow verified. Hopefully, once you’ve got some verification on that, well, you’re gonna go ahead and email it some more to more approvers who are gonna take a look at the documents and then conduct some sort of review.

All the while you’ve got to find ways to collect this information. In many cases, the same information is re-keyed multiple times. In some cases, that information is emailed multiple times. Finally, once we have an approved vendor, now we go about the process of re-keying that information again into our ERP so we could create the supplier record. It sounds exhausting, and it is. It takes many days, in some cases, weeks, and lots of stakeholders in many organizations. All along the while, you’ve got to be mindful of lots of issues. Is this vendor already in ERP? Is this a vendor we can actually do business with? Has somebody reviewed these documents? Well, wait a second. Where is this document? Oh, hold on a second. You’re asking me to submit this document again? I already sent it to you a couple of weeks ago. Don’t you remember? And of course, vendors get frustrated. Why is this taking so long? Why can’t I just get on with the task of doing business with your company?

This is exhausting for everyone involved. Vendor data management these days really falls short in lots of ways. It’s too reliant on PDFs and emails. It requires too much manual keying. There’s not enough standardization. It’s too easy for folks to cut corners or to use personal discretion. No matter what our company’s policies are, we can never be sure what we’ve already received or where things stand in the process. It’s hard to adapt these rigid manual and semi-automated processes to our changing business environment. Each time our business grows, we’re probably gonna need more people to manage vendor onboarding and changes to vendor information. That labor is hard to find these days.

What’s more is that complicating all of this, we can never be too sure who it is that’s sending us the information about a bank account change request. You’ve read the headlines these days. Business email compromise is the fastest growing of payment fraud. In fact, these days, businesses in the United States lose more money to business email compromise attacks than to bank robberies. I know bank robberies are far more interesting than BEC attacks, but these are the stats I’ve given. You also find that today we see more cases of account takeovers and phishing schemes. This has created lots of opportunities for fraudsters to perpetrate phony bank account change requests. It often starts with targeting an organization, doing what I’ll call reconnaissance. They identify a business that they wanna go ahead and rip off, and then they conduct some sort of social engineering.

Who is it that’s the AP person at that company? Who does that company do business with? Who’s the AR person at that company? Can I determine what bank these organizations are doing business with? Then for filling in any gaps, this is where those emails come in. They’ll do phishing schemes to try and collect information to hack into a supplier or stakeholder’s email where they’re able to glean any information they weren’t able to find through the web or the dark web. Once they have all the information they need to perpetrate a scheme, now they submit a fraudulent bank account change request. In many cases, it’s hard to discern these from legitimate bank account change requests. Once we’ve been tricked, that money ends up in the wrong hands and it’s quickly swept away, typically to a far-off bank where it’s hard to recover.

The fact is, is that lots of people in the process are increasing our risk. Think about it for a moment. We’ve got your staff, the person who initiated the relationship from your organization. You have your AP team, your procurement team, and then all those approvers of the person who’s being onboarded. All those people are a point of potential failure in this process. All it takes is for one person to cut a corner or to skip a step because they don’t believe it’s their job or they’re too busy doing what they deem as their full-time job. Now we’ve let in a bad guy, something slipped through the cracks. In many cases, this has tremendous financial and reputational consequences to our organizations.

Many organizations recognize these risks, and it’s for that reason that they’re implementing these so-called self-service online vendor portals. These are end-to-end solutions that help us better manage our vendor information, whether that’s from vendor onboarding or through vendor master database management. These portals allow us to automate the collection and management of vendor information, whether it’s a first-time vendor or it’s an existing vendor. Configurable digital approval workflows eliminate the email paper chase. These rules automatically route information to predefined individuals based on rules that we’ve set up. There’s self-service inquiries so that we’re able to see at any time the real-time status of a document or a supplier, and our suppliers are able to see where they stand in the process.

What’s more, you’re able to upload invoices and other documents into the portal so that all the information is in one place. There’s a single source of truth, if you will, and in the back end, these portals integrate seamlessly into our ERP. There’s less re-keying of information and everything is synchronized in real-time. But what might be the most compelling benefit of a self-service online portal is its ability to automatically validate and verify the information supplied by a vendor. Whether it’s TIN matching or OFAC checking or sanction screening, a portal can automatically check internal and external databases to validate the authenticity of the information, the vendor, and even the individuals associated with them.

What’s more, self-service portals can also help us mitigate our risk of payment fraud by offering bank account ownership verification. These components in leading supplier portals automatically verify that the account name, the name on a bank account matches the name of the supplier, who we’ve been led to believe is requesting that bank account change. It can also verify the address of that bank account so we can be sure that the account resides here in the United States and where the vendor is, and not in some far-off country. Information such as the bank account number as well as the routing number can also be verified, and even TIN details can be verified. We can also be sure that the account is open, that there’s no holds or any other actions against the account.

Then the solution will tell us how much of the information is verified. It’s almost like a streetlight. Green means everything matches. This looks to be in order. Yellow means, well, the information didn’t quite match. Somebody probably ought to take a look at this. Red means we’ve seen some discrepancies and somebody absolutely needs to take a look at this. Much more effective than penny tests or email verifications or even phone calls, bank account ownership verification solutions provide us insights in real-time into who it is that owns a bank account. That information is automatically captured so we have an audit trail to show all the responses that we received, put it together versus some of the antiquated ways that we verify bank account details. Well, there’s no competition between bank account ownership verification and those solutions.

It provides a much more secure platform for managing vendor information. All the information is securely transmitted, so we have better data integrity compared to emails. Granular access controls and user permissions ensure that there’s only the people who should be accessing information or viewing email communications and attachments are able to do so. Detailed audit logs of user activities and interactions, and even the results of bank account ownership verification are all logged. There’s plenty of tracking of all exchanges and all actions. Supplier portals also provide a dedicated platform for vendor data management. This way you can be sure that everything is in one central location. With built-in collaboration tools and a supplier portal provides secure login credentials and bank account verification, which helps fight back against the rising tide of payment fraud.

It helps us push back against phishing attacks and spoofed emails. Put it all together, a supplier portal with built-in bank account ownership verification means that you’re gonna have fewer manual processes, less paper to handle, less email shuffling, less re-keying of data. You’re also gonna have faster cycle times. Information is routed systematically, digitally based on automatic business rules so there’s no tracking down an approver and having something sit in the bottom of their jam-packed email box. Reviewers are alerted of documents awaiting their action. There’s complete tracking control, so you can see where everything stands in the process.

The solution can be easily scaled and adaptable to your changing business needs. Suppliers are going to have a better experience. They won’t be resubmitting the same document multiple times. They won’t have to wait around and wonder where things stand in the process. In many cases, they’re gonna be able to start doing business with your organization much, much sooner.

But most importantly, for today’s conversation, a self-service supplier portal can help reduce your fraud and compliance risk through built-in bank account ownership verification. But don’t take my word for it. Now, Phil is gonna give you a demonstration of one solution that allows you to automate the verification of bank account details. Phil.

Thank you, Mark. My pleasure. Can you see my screen okay? Looks great, Phil. Okay, thanks. So, it’s great to be here and thank you all for joining us on this webinar today about automating your bank account verification, uh, bank account ownership verification. You’re looking at a screen that the vendor that you can have your vendor go to, it would be branded according to your company. The vendor can fill out information actually about their bank account. You can have this vendor-facing, like you’re seeing right now, or I’m gonna show you in a minute. You could have it not vendor-facing, and y’all can enter the information yourselves for this kind of verification.

The vendor would key in their current financial information, if it’s a bank account change request, the vendor would enter their current information. You can have them enter a voided check or a bank letter or both. Then they’d enter the new information for their new account. Then they can also enter further corroborating information such as their vendor number or a current invoice number and an invoice amount or an invoice date. All of these things would work together to help you validate that the request to change a bank account is actually legitimate.

If it was an international bank, then this is pretty cool. If you’re doing business with international banks, you can check, or the vendor would check that it’s a non-US bank. Based on the country and the region and the type of payments that it’s going to be, specific screens would show up requesting the information, the banking information for that specific country. In any event, the vendor would sign the information. If this was vendor-facing, if it was not vendor-facing, then your staff would enter the information on an abbreviated form and they would enter that here and then they would submit it.

What happens is after that information is submitted, it’s immediately verified for domestic accounts. It can be immediately verified for international accounts, sometimes the international may take a little bit longer, and you would see information that looks like this. This is an actual result for our company, Financial Operations Networks. This bank icon is green, showing that it went through the review process and everything came as it was expected to. When I click on that, I actually can get the details.

There’s an eight-point account and ownership matching process. One is the routing number and the account number. This shows that this actually is a valid account that’s open. This eliminates the need to do a penny test or a prenot. It also matches on information that the bank has on file for the organization name or if it’s an independent contractor, the individual name, the street address, the city, the state, the zip, and the taxpayer identification number with which that supplier opened their account with the bank. Everything is green, it’s looking pretty good.

Sometimes they’re not all green. In this particular case with Crazy Jim’s Pizza, this is a demonstration example. We can see that it actually is a valid account and it’s opened and it actually is opened under the name of Crazy Jim’s Pizza. But as you can see by the little alert and warning icons here, the street address is an alert. The zip code isn’t quite right, and the TIN isn’t quite right. The difference between an alert and a warning is a matter of degree. Perhaps for these alerts, there were typos as Mark mentioned earlier. But as you can see with the city and the state, these are warnings. This is different. This would definitely require some further investigation on your staff’s part.

You can also have the vendor fill out further information on their vendor onboarding form. Let me just show you this. This can be as extensive as you want. You can have them fill out W-9s or even substitute W-9s. In this particular case, it’s a substitute W-9. But over here we can have them fill out a government form W-9 if you like. They fill out their address. You can have the bank account information as part of their onboarding form, the terms, any information that you like. When they sign this and submit it, then you get back a lot more information about the identity of that vendor as well.

For example, here, let me just show you here. This is us again, and you can see all the verifications that have been performed. There’s a TIN verification, there’s a verification for sanctions lists such as OFAC, the UK, EU, UN. Street is verified. The Department of the Treasury lists are also verified. Health and Human Resources lists from the Inspector General are verified. If you’re in healthcare, I know this is important to you. It also checks various lists for cyber crimes, FBI lists, CIA lists, FACT lists and so on.

If there were problems, then they would show up in red. For example, with John Smith, we see that this is flagged red and the TIN didn’t match, and that’s a problem, and the address was suspect. You can right from the system actually link an email back to the supplier and say, “Hey, you know, please reverify your TIN and your address, your form seems to have the following discrepancies.” They can click on the link and the link actually brings them right back to the same form that allows them to redo the information that looks like it was a problem.

The other thing that you can do, which is pretty cool, is the system can also give you a Google map of the organization and show you where it’s located and actually show you a picture from Google Earth. The purpose of this is not just to verify, and it’s a modular system. You could just verify the bank ownership information, but you can also get other information for that organization that helps you further validate the information as well. All of this can go into a workflow for your staff’s review and approval. They can look at everything.

Let me just show you here. You can have them look at the forms. For example, this was a W-9 form. You can have them look at the banking forms that were filled out. They can approve it if you have multi-level approvals or multi-path and multi-level approvals. The system will handle that. Once everything is approved, it can actually get uploaded right into your vendor master file. Mark, I think we maybe have some time for questions this afternoon, but in a nutshell, at a high level, this is what the system does.

It really reduces the amount of time your staff spends on this. It also provides an automated way with audit trails to make sure that the procedures and the processes for verifying the bank account ownership and any other information that you want verified are followed. Mark, should we open this up for questions and maybe give the folks some contact information?

Indeed, we should. This brings us to the Q&A portion of this webinar. If you haven’t already submitted your question for Phil, or if you’ve thought of another question for Phil, go ahead. Use the Q&A tool on your screen to submit your question to me. Now we’ll answer as many questions as time allows. Phil, one of our attendees is wondering what’s involved with integrating this solution with their ERP?

Yeah, it’s a good question. I’d say roughly 40% of our customers are on Oracle, Oracle-related systems. Another 40% are on SAP and SAP-related systems. The other 20% are involved or certainly related to a host of others as well. Whether it’s Microsoft Dynamics or Lawson or any of the Infor products, specialized law firm products. It really is ERP agnostic. Another attendee is wondering how long it takes to get a response back from your bank account ownership solution.

The responses are immediate. All of this is real-time. With regard to international bank account ownership verifications, the response might be immediate, but in some cases, it might take a little bit longer to actually get the verification done. I’d say, depending on the percentage of internationals that international bank accounts, 90-95% are right then and there. Another attendee wants to know more about why this is a better solution to penny tests, which is apparently what they’re using.

Penny tests are good. They work, but you actually have to make the penny test and then you have to get verification of the penny test as well. This verifies that it’s truly a bank account that’s actually opened, and there really isn’t anything necessary for your staff to do. How can somebody find out more information? Phil.

You know, just give me a call or an email. My email address is on the screen or just info@vendorinfo.com. Be happy to talk with you and give you maybe a little bit of a deeper dive if you’d like into the application and how it works. That will be our final word. Phil, thanks so much for an excellent presentation and for sharing your insights with us today. Thank you, and thank all of you for taking time out of your busy days to join us. On behalf of VendorInfo, this is Mark Brousseau. Thanks so much for joining us, everyone. Hope to speak with you all again soon.

Share This Post