Topic
Vendor risk
Vendor payment risk is the chance that a supplier's bank details are changed, impersonated or compromised, sending a legitimate payment to a criminal.
Our vendor risk research covers onboarding, bank detail changes, impersonation of suppliers and the checks that confirm a vendor's account before the first and every changed payment.
Start here
All vendor risk research (3)
- You cleared the file. You did not prove the payee. Now what?
The release record needs to show entitlement, account verification, exceptions, and source evidence as they stood before funds left.
August 11, 2026
- Payment vendor acquisition controls still trust outdated tools.
A fraud platform can survive the deal while the alert labels, IDs, and evidence trail no longer prove the release.
August 11, 2026
- You approved the vendor. The bank account came with it
The risk sits inside the short onboarding window, when vendor identity and account ownership are accepted together.
May 28, 2026
Key terms
- Vendor impersonation fraud
Vendor impersonation fraud is an attack in which a criminal poses as an existing supplier and submits new banking details so that legitimate invoice payments are redirected to an account they control.
- Vendor master data
Vendor master data is the stored record of each supplier, including legal name, tax identifier, contacts, and remittance bank details, that a payment system reads when it pays an invoice.
- Bank account validation
Bank account validation is the process of confirming that a bank account exists, is open, and belongs to the party expected to own it, before that account is used to receive funds.
- Callback verification
Callback verification is the control of confirming a payment instruction or a bank detail change by telephoning the counterparty on a number already held on file, never a number supplied in the request itself.
Questions
When should vendor bank details be verified?
At onboarding and again whenever bank details change, using contact information already on file rather than details supplied in the change request.