Procurement
A Supplier Onboarding Checklist That Prevents Fraud
Most payment fraud doesn't break into a system. It asks politely, by email, for bank details to be changed — and the control that stops it is boring and cheap.
The expensive supplier frauds are rarely technical. Someone emails accounts payable claiming to be a known vendor with updated bank details, the change is made by a helpful person under time pressure, and the next payment run sends real money to a real account belonging to someone else.
Verify the entity before the first order
• Registered company name and number, checked against the public register.
• Tax registration, validated with the tax authority's own lookup.
• Registered address, compared with the address on the invoice template.
• Named contact with a domain email — not a free webmail account.
• Sanctions and debarment screening, recorded with the date checked.
Store the evidence, not just the tick. A screenshot with a timestamp is worth more in a later investigation than a checkbox with no provenance.
Treat bank details as a separate, higher control
This is the control that matters most and the one most often skipped. Bank details should never be accepted or amended on the strength of an email, however convincing the signature block.
• Call back on a phone number from your own records — never one in the request.
• Speak to a named finance contact you have dealt with before.
• Require a second approver for any change to existing details.
• Log who requested, who verified, who approved, and when.
Any bank-detail change arriving by email is unverified by definition. The callback is the verification.
Watch for the pressure tell
Fraudulent requests almost always carry urgency: a payment is overdue, a shipment is held, the finance director is travelling and unreachable. Legitimate suppliers can wait a day for a callback. Make that explicit in the policy so staff are not choosing between the rules and being helpful.
Close the back door
An onboarding process is worth nothing if a purchase can be made outside it. If the only way to pay a new supplier is through the vetted record, the checklist protects everything. If an expense claim or a corporate card can route around it, the checklist protects the part of spend that was never at risk.
Re-check the dormant records
A supplier record that has not been used in two years is an attractive target: it looks legitimate in the master data and nobody would notice activity resuming. Deactivate on a schedule and require re-verification to wake a record up. This is a one-line policy that removes a whole class of attack.
Callback on a number from your own records, never the one in the request. We were targeted last year and that single rule is the reason it failed. The email was otherwise flawless.
Making the policy explicit about urgency matters more than people think. Staff were choosing between following the rules and being helpful, and helpfulness was winning.
Deactivating dormant records closed a gap we hadn't considered. A record last used in 2021 looks completely legitimate in the master data and nobody would question activity resuming on it.