Transcript
Hello everyone, and welcome to today’s webinar, Best Practices and Bank Account Verification.
My name is Mark Brousseau, and I’m pleased to be one of your speakers for today’s webinar. Today’s webinar is brought to you by VendorInfo.
Finance and Administration functions are as cumbersome and risky as onboarding suppliers and managing changes to their account information. These days, things have become even riskier with the increased prevalence of payment fraud. In fact, the way that many organizations collect and manage bank account information is leaving us vulnerable to bad actors.
During today’s webinar, we’re going to talk about best practices and bank account verification. We’re going to show you a live demonstration of one solution that can help you mitigate your risks. To help me do that, I’m pleased today to be joined by Phil Binkow, chief executive officer of Financial Operations Networks, the owner of Vendor Info.
OK, today, fraud is top of mind for accounts payable and finance leaders. It’s the number one challenge that AP leaders identify in their departments these days. There’s no surprise Interpol, state Attorneys General, the FBI—a who’s who of people you never want knocking at your front door—are sounding the alarm. They’re saying that the way that AP departments are doing things these days is leaving them more vulnerable to fraud. And the fact is, the risk of fraud is growing.
Today, most organizations say that their risk of fraud is higher compared to just three years ago. One in five organizations believe that their organization is under significantly higher risk of fraud compared to just a few years ago.
What’s more, 40% of AP departments say they have experienced multiple attempted or actual instances of payment fraud. And as startling as that number is, what’s even scarier is that when you drill down into these numbers, you find that one quarter of the organizations that have experienced multiple attempts or actual instances of fraud have experienced 12 or more cases within just the past year.
What’s going on here, you might be wondering? Well, the fact is, corporate America’s increased reliance on emails to onboard suppliers, chasing down invoice approvals, and approving payments for initiation is leaving us more vulnerable to bad actors, and the bad guys know it. Compared to secure automated solutions, the fact is email is insecure. It doesn’t provide segregation of duties, it doesn’t provide chain of custody assurance, it doesn’t track the actions taken on a supplier onboarding file, an invoice, or even a payment. It doesn’t provide you with ready access to audit information. And there’s no stopping someone from intentionally or inadvertently deleting information ahead of your organization’s retention schedule.
The fact is, bad actors are seizing upon our reliance on fraud and they’re doing it in three significant ways. The first is a growth of business email compromise attacks. These are cases where scammers gain access to your vendors’ email and send spoof emails, or in some cases, create web domains that look awfully similar to a vendor’s legitimate web domain. Maybe an L has been replaced with an I. In our haste to process the transaction, we overlook that change to the domain.
In other cases, scammers might actually infiltrate the email of a trusted employee, in many cases, a senior finance executive. We’ve probably all received these emails from a CFO, urging us to quickly go ahead and make payment to this vendor. And, oh, by the way, here are the bank account details where you should direct this payment. In many cases, business email compromise starts with phishing schemes. These aren’t the unsophisticated attacks of yesteryear. This is where bad actors use social engineering to be able to infiltrate our firewalls and our systems.
In many cases, they’ll use malicious software that’s downloaded into links embedded within an email or maybe hidden within an attachment to an email. Unwittingly, we hit, click on the link or open the attachment, and now the scammer has access to our email. Some cases, they watch our details, collect information so they can strike when the time is right. In other cases, they go ahead and they just overtake our accounts. The fact is, business email compromise attacks are on the rise.
Nearly two thirds of organizations say BEC is now the primary source of fraud attacks in their organization, 76% of organizations say they’ve experienced BEC fraud. And one third of organizations have actually lost money because of email schemes such as BEC attacks. And artificial intelligence is making it even easier for bad actors to perpetrate BEC attacks. You’ve probably heard of Chat GPT and other AI-driven tools that make it easy for us to be able to collect information via the Web.
In some cases, our sons and daughters are using these tools to help with their coursework at school, but I digress. Well, there are also tools called worm GPG is one example. This is the evil twin brother of Chat GPG, if you will. And as you can see, by the example on your screen, these nefarious GPG tools make it easy for bad actors to write convincing emails. That trick you into changing bank account details to an account that they control. The fact is, forget what you thought you knew about bad actors, being unsophisticated or using brute force.
In many cases, they’re well funded, well financed, they have advanced technology, just as we do, and they’re very motivated to perpetrate fraud. The second email-based fraud scheme that’s more prevalent these days is account takeover. Here, again, this often starts with phishing schemes that give bad actors access to our email systems. Once the scammers obtain the credentials to our networked systems, well, now they’re able to access our AP systems, our bank accounts, our vendor management system, our ERP, even our email.
And once they have these credentials, well, now, the scammer can go ahead and initiate and approve bogus payments, misdirect payments, or even steal our banking details and use them at their leisure. Similarly, bad actors can also impersonate vendors. This, again, starts with phishing schemes. They watch your email to see vendors who are in the process of being onboarded into our systems. At just the right time, the scammer slips their bank details into the onboarding process, believing that we’re paying a new supplier and not the bad actor.
It’s not until 30 or 60 days later when we get that call from the legitimate suppliers saying, “Hey, where’s my payment” that we realize we’ve been tricked. And in many cases as well, scammers can go ahead and use phone numbers, emails, and names that are very similar, if not the same, as legitimate contacts for your vendors. This is why it’s imperative that we not validate vendor information using emails.
Whether it’s BEC attacks, account takeovers, or even vendor impersonation, the costs of these schemes add up fast. We also focus on the financial losses. The funds stolen from our accounts, and rightfully so. But, the fact is, fraud also costs us in administrative expenses, whether it’s legal, insurance, or all that staff time that it takes to remediate these problems.
But, fraud also has a big impact on our partners. In some cases, we make it difficult for vendors to do business with us. It’s become so onerous that they take their business elsewhere. In other cases, vendors might be impacted by false positives that inevitably show up from our processes, trying to identify fraudulent transactions, whether it’s fraud losses, administrative expenses, or partner impact, the cost is huge.
In fact, each year in the United States, businesses now lose $300 billion to fraudulent payments. That’s more money than is lost to bank robberies. Now, I know bank robberies are probably more exciting than payment fraud. But the fact is, we can’t afford either. And we’re unwittingly creating vulnerabilities in the way that we go about verifying bank account details for suppliers either during the onboarding process or after they’ve been onboarded and their details have changed.
That’s not my opinion. That’s the opinion of your peers. Those surveyed by Financial Operations Network believe that fraudulent bank account information is the greatest risk in vendor onboarding. The problem is, most of us rely on manual, or what I’d call semi-automated processes. For validating bank account details, in many cases, these processes are pretty outdated and not foolproof. Most organizations are using manual or semi-automated processes.
The fact is, we need to find a better way to validate bank account ownership, and it’s often not being done automatically. In many cases, we’re using email, phone calls, petty tests, and other approaches to ensure that the account that we’re changing is indeed legitimate. And this is the biggest weakness. When it comes to supplier onboarding and registration, too many manual processes, not enough internal controls, and an ability to override what few controls we have. Put it all together, and the common denominator is, well, manual processes or semi-automated processes.
We’ve got to find a better way to validate bank account ownership, and that’s where supplier onboarding comes in. Today, the risks of onboarding suppliers are only going to increase. A recent survey by Financial Operations Networks found that 91% of accounts payable and procurement professionals believe that their vendor onboarding risk is going to increase over the next several years. I’ll pause here to point out that there are few things that we can get, even 51% of people to agree on, but 91%? Well, that’s unheard of.
You know that the problem has got to be large, and it’s for this reason that more organizations are deploying so-called self-service supplier portals as part of their process for onboarding suppliers and managing changes to vendor information. Supplier portals automate the collection of data and documents from suppliers during onboarding, and on an ongoing basis, they automatically validate key points of data. They can verify information, whether it’s bank account ownership, or TIN details, or even comparing vendors’ information and individual information to watch lists.
And vendor portals provide us with visibility across the vendor onboarding and vendor information management process. Vendor portals obviously have a tremendous impact on the efficiency of vendor onboarding and information management, but where they really shine is when it comes to helping us avoid the risks of paying bad actors. You see, supplier portals provide clear operational visibility and transparency at every step along the vendor onboarding and information management process.
They ensure that your processes and procedures are always updated. There’s no judgment calls by somebody in the field who’s handling vendor information. The system automatically ensures that the correct data and documents are collected, that they’re validated, and verified correctly, and that everything is stored for auditing later.
With a vendor on a supplier portal, you can always be sure that your processes will comply with your internal processes and procedures, as well as any guidelines for your industry. What’s more? A supplier portal can help reduce your vulnerability to cyber threats, such as BEC attacks, account takeovers, and even vendor impersonation. And the way they do that is through automated bank account verification.
The automated bank account verification tools built into supplier portals can automatically verify details, such as the account name, the address, bank account number, routing number, and tin details, can even ensure that a bank account is open. Vendors securely submit their bank account information online, and the supplier portal does the rest. This is a game changer when it comes to mitigating our risk of payment fraud. It ensures that we’re paying the right entity.
But don’t take my word for it. Here’s Phil to show you a live presentation of how Vendor Info’s bank account verification solution works.
Thank you so much, Mark, and thank you, everyone, for being here today. Uh, Mark, can you see my screen OK?
Looks great, Phil. OK, great, thank you. So what happens, as Mark was talking about, the manual bank account verifications? Typically, they involve a lot of phone calls, you know, even searches with search engines to try to find the right person. If that person is not in our vendor file, these can be really tedious and time-consuming and, in some cases, disruptive, not only to our own internal organizations but to the vendors’ operations as well.
The solution to that is to just automate the bank account information and verification. And there’s a couple of ways that the Vendor Info portal actually allows you to do that. One is, the vendor can come. You can have the vendor come to a screen where they enter their bank account information if it’s a change, for example. You can have them enter their current financial information.
The new financial information, other verifying data, you can have them upload canceled checks. You can have them upload a letter from the bank, and then they will sign the document, and then submit it. You can also enter that information internally through an authorized admin on your team, where the vendor would provide the information, and your folks would enter that bank account information either way.
What happens automatically is that information goes and is verified against the national database of bank accounts, and you end up getting a result within seconds. That shows what the status of that bank account is, and who the owner is, and if it actually matches what the vendor submitted.
So in this particular case, and these are all color-coded, green is good, yellow is not so good, red is terrible, but in this particular case, everything matched, the bank account matched, the routing number matched, and six other data points as well. Company name, the street address, the city, the state, the zip, and the tin, all matched everything is green. That’s good, that’s good.
But in some cases, they don’t match. And in this case, a demonstration with Crazy Jim’s Pizza, in this particular case, it is a valid bank account, just so you know it’s open. And by the way, when you know it’s open as a bank account, it eliminates the need for penny tests. But the problem in this particular example is the name actually matches, but the address and the zip code, and the taxpayer identification number, have alerts by them. This means that they don’t match with possibly a typo. Maybe, maybe not.
There’s an even bigger difference, though, and a warning with the city and the state. They don’t even come close to matching. So, what happens here is you’re able to see where there are problems. And some further due diligence would obviously occur with this account.
You can also, the system also keeps track of a Google Map, is to where Google Earth is, the picture of the location, and a picture of a map of where that location is. You’d be surprised to know how many fraudulent attempts go to very suspect and sketchy areas, vacant lots, for example. All of this is recorded. You can see who did what and when they did it.
You can go back and have audit trails for internal audits so they can see what’s happening. Now in addition to this, in addition to the bank account verification, the system can also, if you want, be a modular system. It can also do things like tin verifications, where the vendor can actually come in.
Let me just show you this. They can fill out a W-9 or W-8. They fill it out. And once that’s done, you can also review the verification of the tin. You can do this internally as well, by filling out the information. You can have the vendor fill it out, and then what happens is you end up seeing, and once again, green is good.
You’ll end up saying, “Hey, this is the right address, the tin actually matched or not on the Death master file.” In this particular case, OFAC and other sanctions lists are also being screened. If you’re in healthcare, HIPAA lists are being screened as well. There’s about 40 some odd verifications here. If there was a discrepancy, like, in this particular case, you’d see it in red.
And in this case, the tin did not match and the system has a way for you to recontact the vendor to have them resubmit the form. It could be a typo. The address was also suspect here as well. So, what this does is it offloads the manual work of verification bank account verification, to a system that does it automatically. And, if you want, you can have modules for other types of verifications too, such as tin sanctions list screening than in others as well.
Uh, Mark, I want to go ahead and turn it back to you with the contact information.
I know we’re starting to run out of time here and we’d be good to go ahead and certainly allow folks to have time to ask some questions and to see where they can contact us.
Indeed, Phil is. We’re going to answer the Q and A portion of this webinar, if you haven’t already asked a question for Phil, or if you’ve thought of another question for Phil, somebody might be calling you right now with questionnaires so eager to get their question answered.
If you’ve thought of another question for Phil, go ahead, use the Q and A tool on your screen to submit your question to me now. We’ll answer as many questions as time allows until we have several. Our first question, Well, it’s an easy one, is from John. John wants to know, “Is this being recorded so that we can get a copy of this?” Yes, John, I was remiss. We were automatically recording this webinar and we will send all of you the on-demand materials within the next several business days. We encourage you to share it with your co-workers and peers.
Our next question is from Vinita. Anita wants to know “Can you use an Oracle supplier portal and build APIs to do the bank verification?” Would you need to do that with the solution Phil? Yes, you can. In fact, this is a very friendly talk to everybody. And Vinita, just give us a shout out and call or email. We can certainly go through that with you as well.
Catherine wants to know “How does this handle the bank accounts that have been created specifically for… payments?” They are the account numbers being used on vendor invoices in place of their actual bank account numbers. It’s as long as the bank accounts are in the national database. It will actually screen them and show you what the status of those records really are.
Peggy wants to know, “How does this integrate with our ERP? What’s involved from an IT perspective?” Sure. So, it plays nice with all the ERP systems. There’s a number of ways to integrate with your ERP. We haven’t run into any difficulties actually with any and you know who the bigger ones are. You know, those are a matter of course, but, you know, there’s a lot of really small ones out there, too, that are highly specialized, for example, for law firms. And the system is able to handle all of those.
Durrani wants to know “Does the tool support global banking information or only the US?” The completely automated pace that’s totally automated is US-based. There are other ways to do this that aren’t quite as automatic all the time. For international, you know, we can use it, or globally, it depends on the country. Some countries are easier than others, so it’s not to be. It’s not as completely automated for what I just showed you for domestic, for international, but international can be done.
Catherine writes that her organization is currently using another solution, and it’s failing to identify small banks and credit unions. Does your solution have the same limitations? I’d have to say that’s a good question. And what I need to do is if you can just reach out to us and we can see where the problems are, you know, we can certainly address that and do a comparison and see if this will solve your problem.
We have a question here from Pat. Pat wants to know, “Tell me more about your OFAC screening. We mentioned that on this slide, how does that fit into this discussion?” Sure. Thanks. So, OFAC screening is also automated. The various sanctions lists such as OFAC, SDN, EU, UK, UN are all downloaded every night, and then those screens, the screen happens both at Vendor onboarding, but because those lists actually change from time to time and sometimes they can change daily, actually. You can actually run your vendor lists against the screen. The sanctions list screening list every single day if you wanted to.
That will be our final word, Phil. If folks want more information, they can contact you using the information now displayed on the screen as I write.
That is absolutely correct. Thank you all for being here, and I hope this was helpful. Oh, we have one more question that slipped in here. I’m sorry, Phil. Durrani writes, “If the match is not 100%, like in red on the demo, what would be the next step based on your experience with customers? What happens?”
If we’re talking about the bank account verification match, that was not 100%. There are various degrees, there are various degrees of, of accuracy, and accuracy isn’t the right word, but of matching. So, if it’s really, really small, some customers might overlook it, But if you have a number of yellow fields or a number of red fields, you would definitely want to do more due diligence.
That can involve getting back with the vendor, finding out if perhaps they made some typos, or maybe they used an incorrect address for part of the verification. If it’s an error in the tin matching, for example, what would happen if you’d reach out to the vendor and ask them to resubmit the form. You can do that right from the system. It’ll shoot the vendor a link to come back and do the form.
All of that is certainly recorded, and you have all the different versions that somebody filled out. There’s a whole body of work around the answer to your question, Durrani, so, be happy to go over that with you, and, uh, you know, probably take 10 or 15 minutes in a smaller demonstration.
That will be our final word, Phil. Thank you so much for an excellent presentation and for sharing your insights with us today. And thank you all for taking time out of your busy days to join us on behalf of Vendor Info and Financial Operations Network. This is Mark Brousseau, thanks so much for joining us.
Everyone, hope to speak with you all again soon.

