Verification Procedures

Verification Procedures

The bank details changed. Call the number you already have.

What Is Verification Procedures?

A long-standing supplier emails to say their bank has changed and asks you to update the payment record before the next run. The invoice number is real, the signature matches someone you have spoken to, and the only wrong details are the contact information and the account number. You'll work the procedure that catches it: open the procurement-vetted vendor directory, compare the verified phone, email, and banking history against what the email claims, and call the number on record to confirm.

What You'll Learn in Verification Procedures

Verification Procedures — Training Steps

  1. A Quiet Thursday Morning

    It is Thursday morning at CypherPeak Technologies. You're Alice, an Accounts Payable Coordinator, and Friday's vendor payment run is your last big task before the weekend. Most of the work is routine: match invoices to purchase orders, queue payments, and double-check that any banking-detail changes have been formally approved through Procurement.

  2. An Email From Cascade Heavy

    An email arrives in your inbox marked urgent. The sender display name reads Marcus Webb - the senior account manager at Cascade Heavy Industries, one of your long-standing suppliers.

  3. Reading the Request

    The subject line reads URGENT: Banking Detail Update Before Friday's Cycle - INV-2026-3847 . Marcus's name is right. The invoice number is right. The amount and due date match Friday's run. But Marcus is asking you to redirect the payment to a brand-new bank account because his company's bank was supposedly just acquired.

  4. CypherPeak's Verification Policy

    Your AP playbook is clear. For any banking-detail change request, the verification procedure is non-optional: Look up the vendor in VendorVerify , the procurement-vetted authoritative directory. Use the verified phone number from VendorVerify - never a number from the request itself. Confirm the change with the vendor's named contact on a recorded line. Require a formal change request through Procurement before any account update. The point is simple: an attacker can spoof an email, a signature, even a reply-to. They cannot spoof the verified contact details that Procurement keeps under separate control.

  5. Open VendorVerify

    Open the browser and navigate to VendorVerify. The directory is hosted internally at vendor-verify.cypherpeak.com and is the only authoritative source for vendor contact and banking details at CypherPeak.

  6. Sign In to VendorVerify

    VendorVerify uses CypherPeak SSO, the same account that gates every internal portal. Use the saved credentials in your password manager.

  7. Search for the Vendor

    VendorVerify shows the directory dashboard. Search for the vendor named in the email so you can compare what the email claims with what Procurement has actually verified.

  8. Open the Vendor Record

    One verified result matches: Cascade Heavy Industries. Open the record to see the verified contact and banking details that Procurement keeps under separate control.

  9. Compare the Verified Phone

    The vendor record shows the contact details Procurement actually verified, with the date of verification. Compare those against what the email claims.

  10. Compare the Banking History

    Banking changes at CypherPeak are tracked formally. Procurement records every approved change with a timestamp and an approver. The history makes the email's story easy to falsify. VendorVerify and the email disagree on Marcus's contact details. You have to pick a channel to confirm the request with the real Marcus before doing anything else.

Security Framework Coverage

MITRE ATT&CK

  • T1656 Impersonation

CIS Controls

  • CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind