Vendor Bank Detail Verification & Smart Auto-Fill
Vendor bank detail verification ensures payment data comes from exactly one place — the verified vendor master file — auto-filled onto every request as read-only data, with any change confirmed through a second channel before it takes effect.
Payment diversion is the most common vendor fraud, and it works by editing the destination: the bank details on an invoice, or a "we've changed our account" email. Verification defeats it by making the destination un-editable at the point of payment. The fraud-scheme context: How to Prevent Vendor Fraud; the onboarding step: the vendor approval gate.
The verification chain, end to end
- At onboarding — bank details confirmed by callback on an independently sourced number before the vendor enters the master file
- In storage — verified details held in the master file, encrypted at rest
- At request — a user selects the vendor; account name, IBAN, and SWIFT auto-fill, read-only. No typing, no pasting, no editing
- On change — any request to update a vendor's bank details routes through verification again: second-channel confirmation before the master file accepts the change
How the fraud actually works — and where it dies
| The scheme | How it attacks | Where verification stops it |
|---|---|---|
| Edited invoice | Fraudster changes the IBAN on the invoice document | Payment data never comes from the invoice — auto-fill from the master only |
| "We changed our bank" email | Compromised or spoofed vendor email requests a detail update | Changes require second-channel confirmation before taking effect |
| Imposter vendor | A fake supplier submits genuine-looking banking | The onboarding callback fails — the number belongs to the real company |
Smart auto-fill: the user experience of the control
Controls fail when they're annoying, so this one is invisible: the requester types a vendor name, selects it, and the bank details appear — populated, grayed out, done. The user can't mistype an IBAN because the user never types an IBAN. The control and the convenience are the same feature. Product mechanics: Vendor Master Data & Smart Auto-Fill.
Frequently Asked Questions
How do you verify vendor bank details?
Confirm by callback at onboarding against an independently sourced number, store in the verified master, auto-fill read-only on requests, and re-verify any change through a second channel.
What is bank detail diversion fraud?
A scheme where the payment destination is edited — via invoice tampering or a fake change request — so legitimate payments route to a fraudster's account. The most common vendor fraud; beaten by verified, pull-only payment data.
Should payment details ever be typed from an invoice?
No. The invoice is the document asking for money — the least trustworthy source for the destination. Payment data comes from your verified records, and changes are verified, not trusted.
Approvdit auto-fills verified bank details on every request — read-only, encrypted at rest, changes gated behind second-channel verification. Book a live demo to see auto-fill stopping the fraud vector.