← All insights

Practical checklist or tool

The Payment-Change Verification Worksheet for a Small Office

A printable, role-based worksheet for stopping fraudulent vendor, payroll, wire, and bank-account changes before money leaves the business.

Central Florida construction accounting team independently verifying a payment-change request

Use this worksheet before approving a changed payment instruction

Business email compromise often succeeds because a legitimate business process is changed quickly. A vendor appears to update bank details. An executive requests an urgent transfer. An employee asks payroll to change direct-deposit information. A customer or closing party sends new instructions that seem to fit an existing conversation.

The FBI advises businesses to verify payment and purchase requests through a separate channel and to verify any change in account number or payment procedure with the person making the request. The Internet Crime Complaint Center similarly recommends secondary channels or two-factor verification for account-information changes.

Source: https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise

Source: https://www.ic3.gov/CrimeInfo/BEC

Use the worksheet for any of the following:

  • A new bank account or routing number.
  • A change to a vendor’s payment address.
  • A request to send money earlier than usual.
  • A request to bypass normal approval.
  • A change to employee direct-deposit information.
  • A request involving gift cards, cryptocurrency, wire transfers, or unusual secrecy.
  • A payment request that arrives after an email account, phone number, or communication platform changes.

Section 1: Record the request

Complete this section before approving, forwarding, or deleting the message.

  • Date and time received: ______________________________
  • Person who received the request: _____________________
  • Requestor’s claimed name and role: ____________________
  • Email address, phone number, or account used: __________
  • Vendor, employee, customer, or transaction involved: ___
  • Amount and payment method: __________________________
  • Requested completion date: ___________________________
  • What changed from the normal process? _________________

Attach the original message, invoice, attachment, and relevant conversation. If the message was received by email, preserve the full message and headers when possible. Do not rely only on a screenshot.

Section 2: Mark the warning signs

Check every item that applies.

  • [ ] The request creates urgency or threatens a consequence for delay.
  • [ ] The request changes bank details, payment location, payroll information, or a known contact method.
  • [ ] The sender asks for secrecy or says normal approval is unnecessary.
  • [ ] The sender cannot be reached through the usual phone or video channel.
  • [ ] The email address contains a slight spelling or domain variation.
  • [ ] The reply address differs from the visible sender address.
  • [ ] The request arrives near a closing, payroll run, holiday, travel period, or executive absence.
  • [ ] The request asks for gift cards, cryptocurrency, a wire, or another difficult-to-reverse payment.
  • [ ] The request includes a new attachment or link that was not expected.
  • [ ] The request conflicts with a contract, purchase order, invoice history, or established practice.

One warning sign does not prove fraud. Multiple signs should trigger a pause and independent verification.

Section 3: Verify outside the message

Do not use the phone number, link, or contact information included in the suspicious request. Use information already held in the vendor record, contract, accounting system, employee file, or a previously verified conversation.

  • Independent contact method used: ______________________
  • Contact source: ______________________________________
  • Person reached and role: ______________________________
  • Date and time of verification: _________________________
  • What was confirmed? __________________________________
  • Did the person confirm the exact account and amount? ____

For an executive or owner request, speak directly with that person or use a pre-established internal verification method. For a vendor request, call a known number from the vendor record. For payroll changes, require confirmation through the organization’s established employee process rather than relying on email alone.

The FTC recommends that small businesses use email authentication tools such as SPF, DKIM, and DMARC to make it harder for criminals to spoof a company’s domain. These controls can reduce spoofing risk, but they do not eliminate compromised accounts or social engineering. A real account may still be abused.

Source: https://www.ftc.gov/business-guidance/small-businesses/cybersecurity

Section 4: Require a second approval

A second reviewer should independently examine the request and verification record. The reviewer should not simply approve because the first employee says the request was confirmed.

  • First reviewer: ______________________________________
  • Second reviewer: _____________________________________
  • Verification evidence reviewed: _______________________
  • Approved, rejected, or escalated: ______________________
  • Reason: _____________________________________________

For higher-risk payments, establish a dollar threshold requiring owner approval or two-person authorization. If the office is too small for two employees, use an owner, external accountant, bank contact, or other pre-arranged independent reviewer. Document the exception when a second reviewer is unavailable.

Section 5: If the request appears fraudulent

Do not reply to the suspicious sender with internal details. Do not click links or open unexpected attachments. Notify the office’s designated incident contact and preserve evidence.

If money has already moved:

  • Contact the financial institution immediately.
  • Ask whether a recall, hold, or other recovery action is available.
  • Preserve payment records and communications.
  • Report the incident to IC3 at https://www.ic3.gov.
  • Consider reporting the matter to the Florida Department of Law Enforcement Cybercrime Office at https://www.fdle.state.fl.us/FCO.
  • Contact counsel and the cyber-insurance carrier according to the policy and response plan.

The time-sensitive financial steps should not wait for a complete investigation. The office can correct or supplement a report as more facts become available.

Section 6: Turn the worksheet into policy

After using the worksheet, improve the underlying process.

  • Keep vendor bank information in a controlled record.
  • Prohibit payment changes based solely on email.
  • Require independent voice verification for new or changed payment instructions.
  • Use two-person approval for higher-risk payments.
  • Review mailbox forwarding rules and MFA alerts when an account compromise is suspected.
  • Train staff with examples that match the office’s actual vendors and workflows.
  • Test the procedure during a short tabletop exercise.

What this tool can and cannot prove

The worksheet can show that the office paused, verified, documented, and approved a payment decision. It cannot prove that a caller or email account was genuine unless the verification method was independent and trustworthy. It also does not replace bank controls, accounting segregation of duties, legal advice, insurance requirements, or technical investigation.

Review the worksheet monthly for the first quarter, then at least annually or after a significant fraud attempt. The strongest process is one employees can use under pressure. A clear pause rule, an independent contact method, and a second review can turn a convincing payment request into a documented question instead of an irreversible loss.

Sources