Most conversations about payment fraud focus on the moment money leaves. Just as important is the moment a vendor is created. If a fraudulent payee gets into your accounting system, every later control has to catch it again and again. If the vendor setup process is strong, many fraud attempts never get far.
This post describes a practical vendor onboarding process for contractors and energy services firms, one that a small accounting team can follow without special software.
Why onboarding matters
Contractors deal with a constantly changing set of suppliers, subcontractors, equipment rental companies, and material yards. Jobs start quickly, and pressure to pay a new sub so crews can keep working is real. Fraudsters count on that pressure. They may pose as a new supplier, submit a convincing form, or use a stolen identity of a real company.
Strong onboarding makes it harder for those attempts to look routine.
Build a standard vendor packet
Require the same information from every new vendor before the first payment.
- A completed W-9 and company legal name
- A business address that can be independently confirmed
- A named contact person with a direct phone number
- Certificates of insurance, where applicable
- Bank details submitted on a company form, not in an email body
- Signed acknowledgement of your payment policy
Make it clear that payment will not be released until the packet is complete. A fixed rule is easier to defend than a judgment call made under time pressure.
Verify independently
Collecting information is not the same as verifying it. At least two checks should use sources you found yourself.
- Call back. Look up the company's phone number from a source other than the form, such as a prior contract, a public directory, or the person who referred them, and confirm the details verbally.
- Confirm the business exists. Check state business records for registration and confirm the name matches the W-9.
- Match the bank account name. Where your bank supports account validation, confirm the account name matches the vendor's legal name.
- Ask who referred them. A new vendor should usually be connected to someone inside your company. Confirm with that person.
Red flags at setup
- Urgent requests to skip the usual paperwork
- Bank accounts in a name that does not match the vendor
- A free email address for a company that claims to be established
- A mailing address that is a residence or a mail drop with no explanation
- Pressure to pay the first invoice immediately
Separate duties
The person who creates a vendor should not be the person who approves payments to that vendor. In a small office, that might mean the office manager enters vendors while the controller reviews a weekly report of new vendors and changed bank details.
If your accounting software offers workflow approvals for vendor changes, turn them on. If not, use a manual report and a signature.
Hold the first payment
Consider a hypothetical rule: no first payment goes out within two business days of vendor creation, unless the controller approves an exception in writing. That short delay gives time for verification and for a mistaken or fraudulent setup to be noticed. Pair it with a simple emergency process so field crews are not left stranded when a supplier is genuinely needed.
Review the vendor list periodically
Fraud sometimes enters through dormant vendors. Twice a year, run a report of vendors with no activity and mark them inactive. Look at duplicates, vendors with shared bank accounts, and vendors whose address matches an employee's. Those patterns deserve a closer look.
Train the people who handle setup
The clerk who gets a vendor packet at 4:45 on a Friday is the person fraudsters are hoping to reach. Give that person:
- A written checklist
- A named person to call with questions
- Authority to say no or delay without fear of blame
- A short refresher each year, with real examples of how fake vendor requests look
Document everything
Keep the vendor packet, the verification notes, and the name of the person who verified in one place. If a payment is questioned later, you will have a clear record. That record is also useful for insurers and auditors who ask about financial controls.
Where Ironfield Cyber helps
Ironfield Cyber helps contractors and energy companies pair strong finance procedures with technical protections, such as email security and MFA that prevent attackers from impersonating vendors in the first place. If you would like a second opinion on your vendor setup and payment controls, we are glad to review them with your accounting team.