BUSINESS PAYMENT VERIFICATION · MODULE 24

Verify the payment before you approve the change.

Payment fraud often begins with a detail that looks small: a new bank account, changed wallet address, revised invoice, new payment link or urgent request from someone who appears familiar. This guide helps you verify the changed detail independently before money leaves the organization.

Use this sequence: PAUSE → IDENTIFY → VERIFY → CONFIRM → APPROVE → RECORD.

A familiar supplier, colleague, executive or conversation does not make a changed payment instruction automatically trustworthy. Treat the change as a new claim that needs fresh verification.

The safest verification channel is one that existed before the suspicious or changed instruction. For example, a phone number in your business records, an established supplier contact or an independently verified official account.

What should never be used as proof by itself?
A logo, familiar name, email thread, forwarded message, payment screenshot, QR code, invoice attachment, caller ID or urgent instruction can be useful context, but none of these proves that the changed payment details are legitimate. Verify the underlying beneficiary, purpose, amount and authorization through an independent source.
What should I never share to verify a payment?
Never disclose passwords, OTPs, PINs, recovery codes, recovery phrases, private keys or other authentication secrets to a supplier, customer, colleague, executive or supposed bank/support agent as a condition for verifying a payment.
01 · STRUCTURED VERIFICATION

Work through the payment-change checks.

Use these checks for bank transfers, supplier payments, executive requests, invoices, cryptocurrency payments and other consequential business transactions.

Identify exactly what changed

Before approving a business payment, write down the beneficiary, account or wallet, amount, purpose, invoice or reference and the specific detail that changed. A small change can create a completely different payment instruction.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 01

Pause the payment until the change is verified

Do not approve a consequential payment simply because the request looks familiar or urgent. Put the payment on hold while the changed detail is independently confirmed.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 02

Verify the beneficiary independently

Use contact information already stored in your business records, an established supplier relationship or another trusted channel. Do not use the phone number, email address or link supplied in the change request as the only proof.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 03

Verify the purpose and invoice

Confirm what the payment is for, which invoice or purchase order it relates to and whether the amount is consistent with the underlying business transaction. A legitimate beneficiary can still be attached to an incorrect invoice or request.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 04

Verify the amount

Compare the requested amount with the approved invoice, contract, purchase order or other authoritative business record. Treat an unexpected increase, duplicate payment or changed currency as a reason to stop and investigate.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 05

Verify unusual urgency or authority

Pressure such as 'pay now', 'keep this confidential' or 'the CEO approved it' should not replace normal approval controls. Follow the organization's established authorization process even when the requester appears senior.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 06

Verify changed bank details through a known channel

When a supplier says its bank account has changed, confirm the change with a contact method that existed before the request. Where appropriate, require a second person or established approval workflow to review the change.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 07

Verify crypto addresses and networks separately

For cryptocurrency payments, verify the destination address, asset and network independently. A new wallet address sent in an email, WhatsApp message or invoice should be treated as a new instruction, not an automatic continuation of the old payment.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 08

Verify QR codes and payment links

A QR code or payment link can direct funds to a destination you did not intend. Open the payment or wallet interface yourself where possible and inspect the beneficiary and amount before authorizing.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 09

Do not use screenshots as payment confirmation

A screenshot can be edited, reused or taken before a transaction is actually completed. Confirm payment status through the business's own bank, payment account or other authoritative transaction record.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 10

Record verified changes

Once a legitimate change has been confirmed, record who verified it, when it was verified, how it was verified and which account or beneficiary was confirmed. This creates an auditable trail and reduces repeated uncertainty.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 11

Know what to do when the details do not match

If the supplier, beneficiary, amount, account, wallet address or approval trail cannot be confirmed, do not improvise. Escalate through the organization's established finance, management, bank or security process.

Why does this matter?
The goal is to prevent a changed instruction from silently becoming an unauthorized payment. Verification should be independent of the message that introduced the change.
CHECK 12
02 · REAL-WORLD EXAMPLES

Recognize payment-change traps in context.

These examples cover common business payment situations without requiring you to disclose real account numbers or payment secrets.

The Supplier Bank-Account Change

Situation: A regular supplier emails that its bank account has changed and asks the business to use the new account for today's invoice.

Safer verification: Pause the payment and call the supplier using a phone number already stored in the business records. Confirm the new account and document who confirmed it before approval.

The Urgent CEO Payment

Situation: A message that appears to come from the CEO asks finance to pay a new beneficiary immediately and says the request must remain confidential.

Safer verification: Do not rely on the message or title. Follow the normal payment-approval process and independently confirm the request with the executive or an established approval channel.

The Changed Invoice

Situation: A supplier sends a revised invoice with a different bank account and a higher amount than the earlier invoice.

Safer verification: Verify both changes separately against the supplier and the underlying purchase order or contract. Do not treat the revised document as proof of its own changes.

The New Crypto Wallet Address

Situation: A contractor says its usual crypto wallet is unavailable and sends a replacement address through WhatsApp.

Safer verification: Treat the address as a new payment instruction. Confirm the address, asset and network through a previously trusted contact route before sending.

The QR Code on an Invoice

Situation: A new invoice contains a QR code for payment, but the business has never used QR payment with this supplier before.

Safer verification: Do not scan and approve automatically. Verify the invoice and beneficiary independently, then inspect the final payment details before authorizing.

The Payment Link

Situation: A vendor sends a link saying payment must be completed today or the service will be suspended.

Safer verification: Do not use the link as the verification channel. Open the vendor's official website or account directly and confirm the invoice, payment status and beneficiary.

The Payment Screenshot

Situation: A customer sends a screenshot claiming a transfer has already been made and asks the business to release goods.

Safer verification: Check the business's own bank or payment account and transaction record. A screenshot supplied by the payer is not authoritative confirmation that funds arrived.

The 'Test Payment' Request

Situation: Someone says the business should send a small test payment to confirm that a newly supplied account works.

Safer verification: Do not use a test payment to bypass verification. First establish who controls the destination and why the change is legitimate through an independent channel.

The Duplicate Payment Request

Situation: A supplier says its earlier invoice payment failed and asks the business to send the same amount again to a different account.

Safer verification: Check the actual bank transaction record before sending anything else. Confirm whether the first payment settled, failed or is pending, then verify any new destination independently.

The Last-Minute Beneficiary Change

Situation: Minutes before a scheduled transfer, a message says the beneficiary account has changed because the old account is 'under review'.

Safer verification: Stop the transfer and use the previously known contact route to verify the change. Do not let the deadline override the organization's payment controls.

The Confidential Payment Instruction

Situation: A senior-looking message says the payment is part of a sensitive business matter and normal approval should be skipped.

Safer verification: Keep the normal approval process. Confidentiality does not remove the need to verify the beneficiary, purpose, amount and authorization.

The Familiar Supplier, New Contact

Situation: The request comes from a familiar supplier name, but the sender address and phone number are different from the contacts stored by the business.

Safer verification: Treat the new contact as unverified. Contact the supplier through an existing trusted channel before accepting any payment or account change.

The Payment Change Test

Before approving a changed payment instruction, ask:

  1. WHAT exactly changed: beneficiary, account, wallet, amount, invoice, payment link or approval instruction?
  2. WHO requested or approved the change?
  3. WHY is the change necessary, and does it match the underlying business transaction?
  4. WHERE did the new payment details come from?
  5. HOW did we independently verify the change?
  6. IS the beneficiary or destination confirmed through a previously trusted channel?
  7. DO the amount, currency and invoice match authoritative business records?
  8. HAS the required second-person or management approval been completed?
  9. ARE we relying on a screenshot, forwarded message, QR code or changed contact as proof?
  10. CAN we explain and record who verified the payment details before approval?

If one important answer cannot be established, pause the payment and escalate through the organization's established process.

03 · WHEN SOMETHING DOES NOT MATCH

Stop without creating a second problem.

A mismatch is a reason to pause and verify, not a reason to send a small payment, click a recovery link or bypass approval controls.

Hold the payment

Do not approve or release funds while a critical detail remains unexplained.

Use the established contact

Contact the supplier, customer or executive using a previously trusted phone number, address book entry or established business channel.

Check authoritative records

Review the actual bank, payment, accounting or transaction record rather than relying on screenshots or forwarded confirmations.

Escalate

Use the organization's finance, management, bank or security escalation process when the change cannot be independently established.

Preserve useful evidence

Keep relevant messages, invoices, transaction references and timestamps where safe to do so. Do not repeatedly engage with a suspicious sender just to collect more evidence.

Watch for recovery fraud

If money has already been sent, be cautious of anyone who promises to recover it for an upfront fee or asks for credentials or authentication codes.
IF THE PAYMENT MAY ALREADY BE COMPROMISED

Move from verification to incident response.

If a payment was sent to the wrong beneficiary, an account was compromised or someone may have gained unauthorized access, stop further risky activity, preserve useful information and use the affected provider's official security or fraud-reporting process.

Open First Response Guidance →
VERIFY BEFORE YOU TRUST.

A changed payment detail is a new claim. Verify it independently before the money moves.

Return to Module 24 →