Most contractors with an accounts payable team already have a rule that bank changes must be verified by phone. The rule exists on paper. What matters is whether a busy person, on a Friday afternoon, with a superintendent asking about a vendor's payment, actually follows it. Habits beat policy, and habits are built through design, practice, and support from leadership.
This post offers practical ways to help accounts payable staff pause when it counts.
Why people skip verification
Understanding the reasons helps address them.
- Time pressure. Vendors and project teams want payments quickly.
- Social pressure. A call-back can feel like accusing a vendor.
- Authority. A message that appears to come from an executive is hard to question.
- Unclear procedure. If staff are unsure of the steps, they improvise.
- Fear of blame. Employees worry about being punished for delaying a legitimate payment.
Fraudsters exploit all of these. They create urgency, claim authority, and rely on politeness.
Make the rule specific
Replace vague guidance with a clear trigger and clear steps.
Trigger: Any request to add a vendor, change bank details, change a remittance address, or send a one-off wire.
Steps:
- Do not reply to the request or use the contact details in it.
- Find a phone number from your records, such as a previous contract or your accounting system.
- Call and speak with a known contact.
- Confirm the details aloud, including the last four digits of the account.
- Record who you spoke with, when, and what was confirmed.
- Have a second person approve the change.
Give staff a script
Many people hesitate because they do not know what to say. Provide wording like this:
- "We process banking changes the same way for every vendor. I need to confirm this with you by phone before we can update it."
- "Our policy requires a second approval, which usually takes one business day."
- "This is routine and protects both of us."
Scripts make it easier to be polite and firm.
Give staff authority to say no
Leaders should state clearly, and repeat often, that delaying a payment for verification is always acceptable. Be explicit: if an executive or project manager asks to skip the process, the AP team should escalate rather than comply. Make sure executives do not use their authority to override controls, since that sets a dangerous precedent.
Practice with realistic exercises
Training once a year is rarely enough. Run short, regular drills.
- Prepare a hypothetical email that looks like a vendor requesting a bank change.
- Ask staff to walk through what they would do.
- Discuss which red flags appeared and which steps they would take.
- Rotate scenarios: a CEO request, a rushed subcontractor, a payment portal link, a fake invoice from a real supplier.
Keep sessions brief, fifteen minutes is enough, and keep them blame-free.
Build friction into the system
Do not rely on memory alone. Use tools that support the habit.
- Require a verification note in the accounting system before a bank change can be saved.
- Use approval workflows so changes cannot be completed by one person.
- Add banners to external emails to remind staff to be careful.
- Keep a vendor contact list with verified phone numbers in a protected location.
- Set payment holds after bank detail changes, such as a short delay before the first payment to the new account.
Celebrate catches
When someone stops a suspicious request, recognize it. Thank them in a team meeting, describe what they did right without naming the vendor if privacy matters, and use it as a case for training. Positive reinforcement helps more than warnings.
Review near misses
Not every problem results in loss. Track attempts and near misses, including requests that raised concerns and were later confirmed legitimate. Ask what slowed down the process and adjust. If the call-back steps are too cumbersome, people will find shortcuts.
Consider a hypothetical week
A hypothetical AP clerk receives a request on Friday at 4:30 p.m. to update a concrete supplier's account before a large payment run. The clerk follows the script, calls the number on file, and learns the supplier made no such request. Because the policy was clear and the manager supported delays, the clerk felt comfortable doing so. That is the outcome good design should produce.
Where Ironfield Cyber helps
Ironfield Cyber helps contractors combine finance procedures with technical protections such as email filtering, MFA, and mailbox monitoring. We can also help build short training sessions for AP and project teams so verification becomes habit rather than policy.