Back to Explore
🕵️

Supplier Risk

Vendor Banking-Detail Changes

Monitors changes to supplier banking details, a leading indicator of payment-diversion fraud.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why banking changes are a fraud frontier

Business email compromise and payment-diversion fraud almost always begin with a change to a supplier's banking details, redirecting legitimate payments to a fraudster's account. Controls over banking changes are a core requirement of the CSD regime and a recurring AGSA and forensic focus. AuditPro Core monitors every change to supplier banking details so each is verified independently before the next payment leaves.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Banking Changes

419

this year

Change Then Pay < 48h

37

▲ 9

Unverified Changes

62

no callback

Reverted Changes

14

fraud suspected

Banking Changes per Month

High-Risk Banking Changes

VendorChanged ByPay GapNext Pay (R'000)
Vendor 0612User 0916 hours3820
Vendor 0944User 1441 day2910
Vendor 1288User 09111 hours2140
Vendor 1577User 2032 days1680
Vendor 1809User 0914 hours1230

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Banking change as a leading indicator

Most payment-diversion schemes turn on a single altered bank account. Treating any banking change as high-risk catches the fraud before funds move, not after.

Independent verification

A change must be confirmed through a channel independent of the request, such as a known contact or CSD validation, never the contact details supplied with the change itself.

Change-then-pay sequencing

A banking change immediately followed by a payment is the highest-risk pattern, because it is exactly the sequence a diversion fraud produces.

Segregation over the master file

The person who can edit banking details should not be able to approve payments. Concentrating both powers in one user is the control weakness fraud exploits.

How AuditPro Core Bridges the Gap

  • Continuous monitoring: AuditPro Core logs every banking-detail change with who, when and the before-and-after values.
  • Exception workflow: Changes followed by near-term payments raise verification cases that can hold the payment.
  • Reconciliation: New banking is reconciled against CSD-validated accounts.
  • Traceability to source: Each change links to the requesting user, supporting evidence and subsequent payments.

Key Takeaways

  • Most payment diversion begins with a banking-detail change.
  • Verify every change through an independent, out-of-band channel.
  • Treat change-then-pay sequences as the highest-risk pattern.
  • Separate the power to edit banking from the power to approve payments.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.