A supplier sends an urgent message: its bank account has changed, the shipment is ready, and payment must be released before the day ends. The email looks legitimate. The contact name is familiar. For an import-export business or procurement team, this is exactly the moment when disciplined controls prevent supplier payment fraud.
Supplier payment fraud is not limited to fake companies. It also includes criminals impersonating real suppliers, compromised email accounts, altered invoices, and intermediaries who redirect funds to accounts unrelated to the contracted business. Once an international transfer is sent, recovery can be difficult, slow, and uncertain. The practical objective is not to eliminate every commercial risk. It is to make sure no single urgent email, unverified document, or employee can move money without evidence and review.
Why supplier payment fraud succeeds
Most fraud attempts exploit a gap between commercial urgency and verification discipline. A buyer may have already completed basic onboarding months earlier, so the supplier is treated as trusted. The fraudster then waits for a busy period, copies the supplier’s email style, and requests a change to bank details or payment instructions.
Other schemes begin before onboarding. A fraudster may present a convincing website, company registration certificate, product catalog, and trade references. The entity might be recently formed, inactive, misrepresenting its ownership, or using a name confusingly similar to a legitimate manufacturer. The buyer sees a low price and a tight delivery window, then sends a deposit before verifying who controls the company and whether it can actually fulfill the order.
Neither risk is solved by asking for more paperwork alone. Documents can be forged, outdated, or supplied by the wrong party. Effective controls compare information across independent sources and require confirmation through a communication channel that the payment change request cannot control.
Prevent supplier payment fraud at onboarding
The safest payment control starts before the first purchase order. Treat a new supplier as a business relationship that must be verified, not merely a vendor record that needs to be created.
Confirm the legal entity behind the sales contact
Start with the supplier’s full legal name, registration number, jurisdiction, registered address, and active status. These details should match the contract, invoice, website disclosures, and bank-account beneficiary name as closely as possible. A trading name can be legitimate, but it should not obscure which legal entity is asking to be paid.
Check who owns and controls the company where legally accessible information is available. Ownership matters because payment fraud, sanctions exposure, conflicts of interest, and hidden related-party arrangements often sit behind an otherwise ordinary company profile. If a representative refuses to identify the contracting entity or provides inconsistent information, pause the transaction until the discrepancy is resolved.
For higher-value orders, assess the company’s operating footprint. Consider whether its age, stated business activity, market presence, regulatory history, public records, and apparent capacity align with the proposed deal. A company claiming to supply large volumes of regulated goods with no credible operating history deserves closer scrutiny, even if its registration is valid.
Verify the bank account independently
The bank account is a separate verification question. A legitimate supplier can still have a compromised mailbox, while a valid company registration does not prove that a particular account belongs to that company.
Obtain bank details through a formal onboarding process, not solely from an invoice. Confirm the beneficiary name, account number, bank location, and currency requirements against the contracting entity. Where the beneficiary is a parent company, finance company, or affiliate, request a clear written explanation and supporting authorization. Payment to an unrelated third party should be treated as an exception requiring senior approval.
Then confirm the details using a known, independently sourced phone number or established contact channel. Do not use the phone number embedded in the email requesting the change. This control may feel slow when a shipment is waiting, but a short verification call is far less costly than a misdirected transfer.
Build controls around payment changes
A supplier bank-detail change should never be treated as routine administration. It is one of the most common points of attack because it relies on staff believing an instruction that appears to come from a known supplier.
Create a written change process that applies to every supplier, regardless of relationship length. The request should be logged, reviewed by someone outside the purchasing conversation, and independently verified before the vendor master record is amended. The person who enters the new bank details should not be the only person authorized to approve payment to them.
Your process should require four pieces of evidence:
- A formal request from an authorized supplier contact, with the reason for the change.
- Independent confirmation by phone or another pre-established channel.
- A comparison of the new beneficiary details with the supplier’s legal entity and prior records.
- Approval by finance and, for material amounts or exceptions, a senior decision-maker.
A short holding period can add another useful layer. If a bank change is verified today, schedule the first payment to the revised account after a defined review window unless a documented business emergency justifies an exception. This gives teams time to spot contradictions, especially when multiple urgent requests arrive at once.
Separate commercial approval from payment release
Payment fraud becomes easier when one employee can select the supplier, approve the invoice, change banking details, and release the transfer. Small businesses may not have large finance departments, but they can still separate the most sensitive actions.
Procurement should confirm that goods or services were ordered and received according to the contract. Finance should validate the invoice, supplier record, tax treatment, and bank details. A manager or designated approver should authorize material payments based on thresholds that reflect the business’s cash exposure. For example, a low-value recurring local purchase may follow a lighter process, while a first deposit to an overseas supplier should receive enhanced review.
Do not let speed erase those distinctions. A legitimate supplier can usually tolerate a documented verification step, particularly when it is presented as standard policy. A fraudster is more likely to press for secrecy, bypass established contacts, or insist that controls must be ignored because the opportunity will disappear.
Watch for signals that require escalation
No individual warning sign proves fraud. A supplier may have a new bank account after changing banks, a different email address after an IT migration, or a third-party payment arrangement for legitimate commercial reasons. Risk rises when several inconsistencies appear together.
Escalate the transaction when an email domain is slightly different from the usual address, a payment request arrives outside normal process, an invoice has altered formatting, or the beneficiary name does not match the supplier. Other material signals include a request to pay a personal account, an unexplained change in country or currency, pressure to make payment before verification, and a refusal to provide company or ownership information.
Keep a record of each discrepancy and the evidence used to close it. This protects the business if a transaction is questioned later and helps identify patterns across suppliers. It also turns fraud prevention into an operational discipline rather than an informal judgment call.
Use due diligence proportionate to the exposure
Not every vendor needs the same level of review. A small purchase of noncritical office supplies is different from a six-figure advance payment for commodities, electronics, machinery, or regulated goods. The right question is whether the level of verification matches the financial, operational, and compliance consequence if the counterparty is not what it claims to be.
For high-value, cross-border, first-time, or strategically important suppliers, independent due diligence provides a clearer basis for approval. A source-cited review can verify company identity, assess ownership and public-record risk, identify regulatory concerns, and highlight fraud indicators before money or contractual commitments are released. Services such as SDDCheck are designed to turn fragmented checks into a documented decision record for teams under time pressure.
Verification should also continue after onboarding. Review key suppliers when ownership changes, contracts renew, payment behavior shifts, or the business expands into new jurisdictions. A supplier that was acceptable two years ago may no longer present the same risk profile.
The best control is one your team will use when the pressure is real. Give employees a clear rule: no new supplier, changed bank account, or unusual payment instruction is too urgent to verify independently. That rule protects cash, preserves supply continuity, and gives decision-makers a defensible reason to stop a payment until the facts are clear.
