A supplier payment request can look normal because it arrives in an existing email thread, uses a familiar logo, and names an order that is already in production. That does not prove the bank details are correct. A changed beneficiary name, account number, payment procedure, or invoice attachment can create a high-impact error if the buyer’s team treats email as the only source of truth.
A China supplier bank detail verification process creates a controlled path for payment instructions and changes. It identifies the approved vendor record, sends new requests through one intake channel, verifies the request through a known contact method, compares the legal entity and invoice details against the order, requires authorized approval, and retains the evidence with the payment record.
This is general anti-fraud and sourcing-process guidance. It does not tell a buyer where to send funds, how to validate an account, how to handle tax or sanctions, or whether to make a payment. The buyer’s authorized finance, banking, legal, tax, and compliance teams must make those decisions.
A payment change is not routine data entry. It is a request to change a controlled vendor record.
Keep a controlled supplier payment baseline
Before any payment is due, record the supplier’s approved legal name, registered address where relevant, known finance contacts, approved payment method, beneficiary information, invoice format, and order reference requirements. Limit who can edit the record and preserve a history of every change.
| Vendor-record field | Why it matters |
|---|---|
| Legal supplier name | Helps compare contracts, invoices, and change requests |
| Known finance contact | Provides a trusted contact path independent of a new email |
| Approved payment method | Distinguishes a normal procedure from an unplanned change |
| Beneficiary data record | Provides the baseline for a proposed change review |
| Invoice requirements | Defines PO, product, quantity, currency, and commercial-data checks |
| Change history | Shows what changed, when, why, and who approved it |
| Approval owner | Identifies the authorized finance role for release decisions |
Do not store sensitive payment data in uncontrolled chat histories or casual spreadsheets. Use the company’s approved finance or vendor-management system, limit access, and follow internal security policy. The sourcing team can support identity and order checks without assuming responsibility for authorizing a bank transfer.
Treat every change request as a new control event
A request can involve an obvious new account number or a subtle wording change such as a new intermediary, revised remittance instruction, changed beneficiary spelling, or request to use a different entity. Route all such requests through the same review process, even if the supplier says the change is urgent.
| Request type | Initial control action |
|---|---|
| New supplier payment instruction | Create a vendor-onboarding review, not an email-only record |
| Bank or account-number change | Freeze edit and start independent verification |
| Beneficiary-name change | Compare with legal entity and contract records; escalate for authorized review |
| Revised payment procedure | Confirm through a known contact and update only after approval |
| New invoice attachment | Check source, order reference, amount, and change indicators |
| Urgent payment request | Apply the same controls and flag urgency as a risk signal |
The FBI describes business email compromise scams that can impersonate known vendors and send invoice-related requests.1 It advises verifying changes in account number or payment procedures with the person making the request and independently looking up contact information rather than using a number provided in the suspicious message.1
Verify through an established contact path
Independent verification is strongest when the buyer uses contact information already on file or obtained from a trusted, separate source. Do not simply reply to the received email, click the phone number in its signature, or call a number added in the change request. A compromised mailbox can make all of those routes appear normal.
| Verification step | Practical buyer action |
|---|---|
| Select contact channel | Use a known phone number, company directory, prior approved contact, or other authorized channel |
| Authenticate the contact | Confirm the person’s role and ask them to verify the request through the company’s approved process |
| Read back only necessary data | Follow internal policy for handling sensitive information; do not expose unnecessary details |
| Confirm scope | Ask whether the request is permanent, order-specific, or a response to a known issue |
| Record result | Log date, person, channel, reference, outcome, and reviewer |
| Escalate mismatch | Stop the change and send it to the authorized fraud or finance owner |
The purpose is not to interrogate a supplier’s staff. It is to confirm that the supplier itself initiated the request and that an authorized company contact stands behind it. Use a second verifier for material changes under the buyer’s internal policy.
Compare the payment request with the transaction file
A legitimate vendor contact does not remove the need to check the commercial request. Compare the pro forma invoice, commercial invoice, purchase order, product scope, quantity, currency, payment terms, and any approved change notice. An incorrect invoice may result from a simple administrative mistake, a supplier dispute, or a fraudulent message. The buyer should not decide which one without evidence.
| Comparison point | Buyer question |
|---|---|
| Supplier entity | Does the invoice entity match the approved supplier record and contract context? |
| Purchase order | Does the invoice cite the correct PO, product scope, and approved revision? |
| Quantity and price | Do values match agreed commercial records or an approved change? |
| Currency | Is the invoiced currency the one agreed for the transaction? |
| Payment terms | Does the request align with the agreed milestone or condition? |
| Beneficiary instruction | Has the authorized review confirmed the requested payment data? |
| Supporting documents | Are packing, inspection, or shipment conditions present if the milestone requires them? |
A buyer should distinguish supplier identity verification from payment approval. Both matter, but they can have different owners. Finance may approve payment only after sourcing or quality confirms that an agreed production, inspection, or shipping milestone has occurred.
Use a dual-review and change-hold rule
A single person should not receive a change request, verify it, alter the vendor record, and approve payment without an independent check. Define separation of duties that fits the organization’s size. A small buyer may use a finance owner and company director. A larger organization may separate procurement, vendor master data, accounts payable, and payment release.
| Control stage | Example responsible role |
|---|---|
| Receive and flag request | Accounts payable or vendor-management intake owner |
| Verify supplier identity | Sourcing owner using established supplier contact |
| Review commercial match | Procurement or order owner |
| Update vendor record | Authorized finance or master-data owner |
| Approve change | Second authorized reviewer |
| Approve payment | Authorized payment approver under company policy |
| Archive evidence | Finance record owner |
Place a change hold on payment instructions until verification and approvals are complete. This does not mean ignoring a supplier or missing a payment by default. It means the team communicates that it is following a standard verification process and provides the internal escalation path if a time-sensitive decision is needed.
Preserve the right evidence without oversharing data
Retain the records that explain why the organization accepted or rejected a change: the original request, known contact used, verification date, reviewer, commercial comparison, approvals, and final vendor-record update. Limit sensitive data access and use secure systems rather than including full details in broad email distribution.
| Evidence item | Why retain it |
|---|---|
| Original request | Shows what was received and when |
| Independent confirmation record | Shows the channel and authorized contact used |
| PO and invoice comparison | Connects payment request to underlying transaction |
| Approval record | Identifies decision owners and timing |
| Change log | Shows exactly what vendor data was updated |
| Exception record | Documents why a normal step was varied or escalated |
| Incident record | Preserves facts if a request appears compromised |
The evidence should be available to the people responsible for later reconciliation, supplier follow-up, audit, or incident response. It should not become an unnecessary collection of bank details in unsecured files.
Handle suspicious requests as an incident, not a supplier dispute
Warning signs can include a new email domain, slight spelling differences, a request to bypass procedure, unexplained urgency, changes that conflict with known supplier information, or an instruction to keep the request confidential. None alone proves fraud. Together, they justify a controlled pause and escalation.
| Warning signal | Immediate response |
|---|---|
| New or altered email address | Do not rely on the message; verify through a known channel |
| Account or procedure change | Hold the vendor-master update until approval is complete |
| Pressure to pay immediately | Follow the same verification process and alert an authorized owner |
| Mismatch with invoice or PO | Stop the request and reconcile commercial data |
| Supplier denies the request | Preserve evidence and notify internal fraud or security owner |
| Payment may already have been sent | Contact the organization’s authorized finance and bank-response contacts immediately |
The FBI advises people who believe they are victims of BEC to contact their financial institution immediately and report the crime through the Internet Crime Complaint Center.1 Follow the buyer organization’s incident-response process and obtain appropriate legal or financial guidance. Do not ask a factory contact to investigate a suspected compromise through the same questionable email thread.
Communicate the process before a change is needed
Tell suppliers during onboarding that payment details and beneficiary changes require independent verification and may need dual approval. Provide one legitimate route for submitting a request, a minimum lead time, and the information needed for review. A clear process protects honest supplier staff as well as the buyer.
| Supplier communication item | Why it helps |
|---|---|
| Official request channel | Reduces use of informal chat or unexpected email threads |
| Required change form or data | Makes it easier to identify missing information |
| Verification expectation | Prepares supplier contacts for a known-channel confirmation |
| Lead time | Reduces urgent requests that bypass review |
| Authorized contacts | Helps both sides know who may request and confirm changes |
| Escalation contact | Provides a route when timing or language creates difficulty |
Do not promise that a change will be accepted once a form is submitted. The supplier should understand that the buyer will make the change only after its internal review and authorized approval.
Use a controlled change intake form
A supplier should not need to guess how to submit a payment-data change. Give it a short form or secured request route that captures the requesting entity, authorized contact, reason, effective date, related purchase orders, and supporting documents. The form begins review. It does not itself authorize a vendor-record or payment change.
| Intake field | Review purpose |
|---|---|
| Supplier legal entity | Connects request to the approved vendor record |
| Requesting contact | Identifies the person who must be independently confirmed |
| Change type | Routes bank, beneficiary, or procedure changes to the right control |
| Effective scope | Distinguishes an order-specific issue from a permanent record change |
| Related PO or invoice | Enables commercial reconciliation |
| Submitted date | Supports lead-time and audit tracking |
| Internal status | Shows pending, verified, approved, rejected, or escalated |
This format lets finance and sourcing teams see what is still missing before a payment deadline creates pressure to bypass the process.
Frequently asked questions
Why should a buyer verify a China supplier bank-detail change outside the email thread?
A compromised or spoofed email thread can look familiar. Using a known contact path gives the buyer a separate way to confirm whether the supplier truly requested the change.
Who should approve a supplier payment-instruction change?
The buyer should follow its internal authorization policy. A sound process separates supplier identity confirmation, vendor-record editing, commercial review, and payment approval where possible.
What information should the sourcing team check?
The sourcing team can confirm the supplier relationship, known contact, purchase order, product scope, and whether a commercial change was approved. Authorized finance staff should control sensitive vendor data and payment release.
What should happen if the supplier says it did not request the change?
Stop the change, preserve the message and verification record, notify authorized fraud, finance, or security owners, and use the organization’s incident-response process. If payment has been sent, contact authorized banking and finance contacts immediately.
Make payment changes traceable and independently checked
A China supplier bank detail verification process gives buyers a repeatable way to handle new payment instructions and changes without treating every request as an emergency. It combines a controlled vendor record, independent supplier confirmation, transaction comparison, dual review, secure evidence, and prompt escalation when something does not match.
Before the next payment milestone, document the company’s approved supplier-change workflow and give China suppliers one official submission route. Supplier Ally can help buyers coordinate supplier contact verification, purchase-order and invoice reconciliation, and sourcing-side evidence while authorized finance teams retain payment decision control.
