How to teach staff to verify supplier bank detail changes

Teach staff to verify supplier bank detail changes in 2026: a call-back rule, three drills, and a 30-day plan that stops invoice fraud wires.

Supplier bank-detail change requests are one of the highest-value social engineering paths into accounts payable, and teaching staff to verify them is still the control that stops the wire after filters fail.

Key takeaways

Why this matters

Attackers do not need malware when a polite email from a compromised supplier inbox can re-point the next invoice. The message looks routine. The invoice number matches. Only the BSB and account digits changed.

In 2026, organisations that train the whole company on generic phishing still lose on bank-detail scams because the people who edit vendor masters never practised a call-back. Pair security awareness training with a non-negotiable verification rule and you finally have a behaviour you can score.

Verizon’s 2026 Data Breach Investigations Report found the human element involved in 62% of breaches. Bank-detail fraud is that human element with a payment attachment.

What you will need

The steps

1. Freeze the policy before you train anyone

Write one rule in plain language: no supplier bank detail is saved, edited, or paid against until a verbal call-back is logged against a phone number that already exists in the vendor master or procurement file — never against a number in the email or attachment. Have the CFO sign it. Put it on one page on the intranet.

Training without the rule is optional advice. With the rule, training has a pass/fail.

Expected outcome: a signed one-pager dated in 2026 that AP can quote when pressured.

Common mistake: allowing “known supplier” exceptions. Compromised real Outdoor-supplier mailboxes are the whole attack.

2. Map every person who can edit or pay against vendor banks

Export roles with vendor-create, vendor-edit, or payment-release rights. That list — often 10–40 people — is your primary cohort. Broader staff get a lighter awareness later.

Expected outcome: a named roster, not an all-staff blast list.

Common mistake: training sales and skip-level managers at the same depth as AP, which wastes seats and dilutes the drill.

3. Teach the 90-second call-back script

Run a 10-minute lesson covering three patterns only: (1) PDF invoice with new bank details in the footer, (2) email “from” a known AP contact at the supplier asking to update details before Friday’s payment run, (3) lookalike domain that swaps one letter. End by making each person speak the call-back script once out loud.

Cyber Aware short story-led modules work here: one pattern, one quiz, same day.

Expected outcome: 100% of the cohort completes within five business days.

Common mistake: a 40-minute annual fraud video with no spoken practice of the call.

4. Run three bank-change simulations across 30 days

Space sends seven to ten days apart:

  1. Days 3–5: soft invoice with a subtle domain lookalike and a new account number in the remittance block.
  2. Days 12–15: mid-morning email during a real payment-run window, spoofing a supplier AP contact, asking for a “temporary” bank update.
  3. Days 22–25: urgent change tied to a real internal project name drawn from public information only, with a tight two-hour deadline.

Fail → automatic short remediation. Report → short congratulations so the habit sticks.

Expected outcome: click rate falls across three sends; report rate clears 20% by send three.

Common mistake: one ultra-hard send on day one that tanks trust and teaches nothing about the rule.

5. Sample live bank-change tickets every month

After each simulation week, pull five real vendor bank edits or change tickets and check the call-back log. Pair that with simulation report rate in a simple human risk reporting view so QBRs show behaviour, not vanity completion.

Expected outcome: a one-page monthly scorecard: training done, sims reported, live call-backs logged.

Common mistake: celebrating 98% course completion while the call-back log is empty.

6. Close with dual control and a 60-day re-test

Where one person still both edits and releases payment against a new bank, add dual approval above a fixed dollar threshold. Brief managers on who needed remediation. Re-run the hardest template at day 60 on the same cohort.

Expected outcome: one permanent workflow fix plus a dated re-test on the 2026 calendar.

Common mistake: stopping at the certificate folder and never touching vendor-master permissions.

Troubleshooting

AP says call-backs slow month-end. Time five real call-backs. Most clear in under three minutes. Compare that to one redirected wire.

Suppliers refuse phone verification. Your policy still holds. Offer a known-number call initiated by you; never accept a number the supplier just emailed.

Click rates stay flat. Templates are too similar or too obviously fake. Align send three to a real AP calendar day and a real supplier naming pattern.

IT quarantines simulation mail. Whitelist sending domains and IPs before campaign one.

Shared AP mailboxes blur who clicked. Assign simulations to named users, not only the shared inbox alias.

No historical baseline. Treat send one as baseline even if the click rate looks ugly. 20–35% on a first bank-change lure is common in 2026.

Tools and resources

What to do next

Once money-movers clear report-rate and call-back targets, fold a light monthly bank-change template into your standing simulation cadence and extend a shorter module to anyone who forwards invoices. Do not jump from a 20-person AP cohort to a full-company send in one go.

FAQ

How do you teach staff to verify supplier bank detail changes in 2026? Publish a verbal call-back rule, train only people who edit or pay vendors, run three escalating bank-change simulations in 30 days, and sample live call-backs monthly.

Is an email confirmation from the supplier enough? No. Confirm on a phone number already stored in your vendor master. Numbers inside the requesting email are part of the scam.

Who needs this training first? AP clerks, finance controllers, payroll if they share vendor files, and anyone with rights to create or edit supplier bank fields.

How often should bank-change simulations run? Three sends in the first 30 days, then at least quarterly inside the wider phishing programme.

What if the supplier’s only contact is the person who emailed? Use a second channel already on file — main switchboard, portal, or procurement record — not the signature block on the suspect message.

Does this replace email security? No. Filters still miss compromised-supplier threads. The call-back is the last control before money moves.

What report rate should we hit by day 30? Above 20% on the third simulation, with click rate trending down and live call-backs logged on real tickets.

Can a small AP team run this without a security department? Yes. One signed rule, three templates, short lessons, and a shared log are enough to start in 2026.

One last thing

The programme fails quietly when certificates stack up and nobody checks whether a human voice confirmed the last five bank edits. Put those five live tickets next to the simulation score every month. That single habit is what separates a compliance folder from a control that actually stops redirected payments in 2026.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.