Skip to article
HSJGlobal

Supplier payment-control workflow

Invoice Fraud in Indonesia: Verify Supplier Bank Detail Changes

A practical control sequence for finance teams that receive a new supplier bank account, amended invoice, or urgent payment instruction.

A supplier bank-detail change should be treated as a controlled master-data event, not as a routine request contained in an invoice email. A real supplier may change accounts, but a compromised mailbox, altered PDF, or impersonated contact can use the same language. The safe response is to freeze the change, verify it through a pre-existing independent channel, and release payment only after the supplier identity, contract, invoice, beneficiary, and approver records match.

This is especially important for Indonesian entities and foreign businesses paying Indonesian suppliers, agents, freight parties, or service providers. It does not prove that a particular message is fraudulent or replace bank and legal advice; it creates a repeatable way to distinguish a verified supplier instruction from an unverified payment diversion attempt.

Key takeaways

  • Never use the new email signature, phone number, or link in the change request as the only verification channel; those details may be part of the compromise.
  • A bank-detail change should require a known-contact callback, two-person review, matching legal name and account evidence, and a dated audit trail.
  • Verify the change separately from the invoice amount. A correct purchase order does not validate a new beneficiary account.
  • Keep a protected supplier-master record and restrict who can amend it; finance should not have to decide a commercial relationship from an urgent email.
  • If payment has already been sent, contact the bank immediately, preserve the evidence, and consider the appropriate official financial-scam reporting channel.

Treat a bank-detail change as a control event, not an invoice edit

The risk is commonly called business email compromise or payment-diversion fraud. OJK's business-email-compromise guide discusses changed beneficiary-account information, which is a reminder that a believable instruction can still require a different verification process. The practical control is simple: do not allow an invoice or email to overwrite the supplier master record by itself.

A supplier's name on the invoice, a purchase order reference, or a familiar product description may all be genuine while the beneficiary account is not. Verify the payee as a separate fact every time a bank detail changes. This is why a finance team needs a change-control workflow that can operate even when the procurement contact is travelling, the payment is urgent, or the sender appears to be senior.

The workflow applies to local and cross-border payments. The country label matters because the organisation should know its local reporting and banking routes, but the central proof is the same: a verified supplier representative confirms the exact account change through a known, independent contact channel.

Check the supplier change before payment

Bring the supplier master, contract, invoice, known contact, and beneficiary evidence into one approval step.

Match five payment records before the beneficiary changes

Use a five-record match rather than a single 'please confirm' email. The person entering supplier data should be able to show why each record supports the same payment destination and why any difference has been escalated. No one person should create, approve, and pay a changed supplier bank account without an independent check.

Record Required match Escalate when
Supplier master Legal entity, tax or registration details where used, authorised contacts, prior account The request comes from an unlisted domain or unknown contact.
Contract or purchase order Contracting supplier, scope, payment clause, currency and approved approver The invoice issuer or requested beneficiary differs without a documented reason.
Current invoice Invoice number, goods or service, amount, due date, legal seller and bank detail A corrected PDF is sent only by email or has unexplained changes beyond the account.
Independent confirmation Known phone number, known portal, or verified in-person contact The caller redirects you to the number in the suspicious message.
Payment approval log Reviewer, date, evidence reviewed, beneficiary added or amended The change is urgent, outside normal authority, or missing required evidence.

The resulting packet should be retained with the payment, not buried in a private mailbox. It gives audit, procurement, and management one clear answer to a later question: who changed the payee, what evidence was checked, and which person authorised the transfer?

Supplier bank-detail change verification grid A supplier request is matched to five records, verified through an independent callback, then approved or contained by separate roles. Supplier requests bank change Match supplier and contract data Independent callback Update master with evidence Separate approval and payment Mismatch: contain and bank contact
Each field must align before the master record and the payment approval are updated; an inconsistency routes the request to containment.

Use an independent callback that cannot be redirected by the request

The callback must use a number or portal that existed before the change request. Good sources include the supplier master, signed contract, known company switchboard, an approved vendor portal, or an existing relationship manager. Do not use a number in the new invoice, a reply-to address that changed with the email, or a link supplied by the sender.

  1. Ask the known contact to state the supplier's legal name, the exact old and new account details, the reason for change, and the date from which it applies.
  2. Ask for a confirmation using a channel the supplier controls independently from the original request, then compare it with the procurement and finance records.
  3. Record the name of the verifier, time of callback, channel used, data confirmed, and any discrepancy; do not record unnecessary identity or banking information beyond your policy need.
  4. Require a second authorised reviewer to decide whether the evidence supports updating the supplier master and releasing the current payment.
  5. Notify the relevant internal owner if the transaction or relationship has special contractual, tax, Customs, or regulatory implications.

For a related local-control perspective, bank-account scam signals for Indonesian companies explains why payment authority and account access should be governed, not assumed. It does not authenticate a particular supplier instruction.

If the supplier is an affiliate or a new Indonesian operating entity, keep supplier payment evidence separate from the company formation in Indonesia documentation. A valid incorporation record does not establish that a particular email or new bank account is authorised.

Test the independent callback process

Identify whether finance can verify a new payee without relying on the sender's email, phone number, or link.

Separate commercial authority from supplier-data entry

A resilient process separates three roles: the business owner confirms the commercial relationship, a finance or master-data owner verifies the payee change, and an authorised approver releases funds. The same individual can perform more than one role only under a documented exception with an additional compensating control. The purpose is to make a compromised mailbox or rushed request fail against another person's independent evidence.

Set thresholds in advance. For example, a new beneficiary, first payment to a supplier, payment above a set amount, bank change shortly before a due date, or payment to a different country can trigger enhanced review. Do not make the threshold a secret number; make it an explicit policy so staff do not invent exceptions under pressure.

The process should also stop a subtle failure: a supplier update is verified correctly, but the current invoice was separately altered. Reconcile invoice number, account, amount, tax treatment, purchase order, goods or services received, and payee as distinct fields. A verified supplier is not the same thing as a verified invoice.

Once a change is approved, record the effective date, the evidence location, and the payment population to which it applies. Tell the known supplier contact what has been confirmed without disclosing unnecessary bank data. That closes the loop and makes it harder for a later impostor to exploit uncertainty by claiming that a different account, currency, or last-minute invoice rule was also approved.

Contain a diverted payment as soon as the mismatch is discovered

If the payment is pending, contact the bank using the bank's official channels to ask whether the transfer can be stopped or recalled. Suspend further payments to the supplier master record, tell procurement and finance about the verified facts, preserve email headers and documents where available, and ask the real supplier to confirm whether its systems may have been compromised.

If funds have left the account, keep the payment confirmation, invoice versions, supplier master history, callback record, email trail, and internal approval log together. The official Indonesia Anti-Scam Centre describes a route for rapid financial-scam handling and states that it does not replace a police report. Use appropriate banking, legal, and reporting advice for the circumstances; speed matters, but recovery is not guaranteed.

Correct the process only after the event is contained. Review how the request passed initial checks, whether supplier contact data was compromised, which permissions allowed a payee change, and whether the team needs a new callback rule or dual-authorisation threshold. The post-incident fix should reduce the next diversion opportunity, not merely replace the lost account number.

Apply a supplier-bank-change release gate to every amended payee

Approve a changed bank account only when the supplier relationship, contract, invoice, beneficiary evidence, independent callback, and second-person approval align. This is the sensible path for a legitimate supplier change that can withstand an audit or later dispute.

Stop the transfer when the sender, legal supplier, invoice, account evidence, callback, or approval record cannot be reconciled. The priority is to contain the payment risk and document the mismatch, even if the business still needs to resolve a real supplier invoice through an established channel.

Strengthen the supplier-payment gate

Get a practical review of approvals, records, and business controls before a changed invoice becomes a diverted payment.

Frequently asked questions

Can an email from a known supplier address still be risky?

Yes. A known mailbox can be compromised or a reply path can be altered. Verify a bank change through a contact route that existed before the request.

What is the safest way to verify a new supplier bank account?

Use a known contact number, approved vendor portal, or other independent channel, then match the supplier, account, invoice, contract, and approval record before release.

Should finance change the supplier master record before the callback?

No. Keep the prior account active until the evidence and approval process are complete, subject to your policy and any urgent exception control.

Does a bank-detail letter on supplier letterhead prove the change?

No. It is evidence to assess, but it should be confirmed through an independent channel and reconciled with the contracting supplier and invoice.

What should we do after a diverted payment?

Contact the sending bank promptly, preserve all records, notify the real supplier through a known channel, and seek appropriate legal or official reporting support for the facts.

On this page
Chat with an Expert