Verification Procedures
The bank details changed. Call the number you already have.
What Is Verification Procedures?
A long-standing supplier emails to say their bank has changed and asks you to update the payment record before the next run. The invoice number is real, the signature matches someone you have spoken to, and the only wrong details are the contact information and the account number. You'll work the procedure that catches it: open the procurement-vetted vendor directory, compare the verified phone, email, and banking history against what the email claims, and call the number on record to confirm.
What You'll Learn in Verification Procedures
- Treat banking-detail change requests as the highest-risk request type in accounts payable, with formal verification mandatory regardless of urgency or relationship history
- Use an authoritative vendor directory kept under separate control by Procurement as the only reliable source for verified contact and banking details
- Reject contact information supplied inside a suspicious request - phone numbers, reply-to addresses, and signature blocks in the message are part of the attack
- Compare an inbound request against a vendor's banking change history to detect fabricated stories like sudden bank acquisitions or routing rotations
- Place an out-of-band verification callback to the directory's verified number on a recorded line before any banking record is updated
- Require a formal change request flowing through Procurement before AP can act on a banking-detail change
- File a structured incident report capturing sender domain, spoofed phone, fraudulent account, and the verification steps taken so the SOC can hunt for parallel attempts
Verification Procedures — Training Steps
-
A Quiet Thursday Morning
It is Thursday morning at CypherPeak Technologies. You're Alice, an Accounts Payable Coordinator, and Friday's vendor payment run is your last big task before the weekend. Most of the work is routine: match invoices to purchase orders, queue payments, and double-check that any banking-detail changes have been formally approved through Procurement.
-
An Email From Cascade Heavy
An email arrives in your inbox marked urgent. The sender display name reads Marcus Webb - the senior account manager at Cascade Heavy Industries, one of your long-standing suppliers.
-
Reading the Request
The subject line reads URGENT: Banking Detail Update Before Friday's Cycle - INV-2026-3847 . Marcus's name is right. The invoice number is right. The amount and due date match Friday's run. But Marcus is asking you to redirect the payment to a brand-new bank account because his company's bank was supposedly just acquired.
-
CypherPeak's Verification Policy
Your AP playbook is clear. For any banking-detail change request, the verification procedure is non-optional: Look up the vendor in VendorVerify , the procurement-vetted authoritative directory. Use the verified phone number from VendorVerify - never a number from the request itself. Confirm the change with the vendor's named contact on a recorded line. Require a formal change request through Procurement before any account update. The point is simple: an attacker can spoof an email, a signature, even a reply-to. They cannot spoof the verified contact details that Procurement keeps under separate control.
-
Open VendorVerify
Open the browser and navigate to VendorVerify. The directory is hosted internally at vendor-verify.cypherpeak.com and is the only authoritative source for vendor contact and banking details at CypherPeak.
-
Sign In to VendorVerify
VendorVerify uses CypherPeak SSO, the same account that gates every internal portal. Use the saved credentials in your password manager.
-
Search for the Vendor
VendorVerify shows the directory dashboard. Search for the vendor named in the email so you can compare what the email claims with what Procurement has actually verified.
-
Open the Vendor Record
One verified result matches: Cascade Heavy Industries. Open the record to see the verified contact and banking details that Procurement keeps under separate control.
-
Compare the Verified Phone
The vendor record shows the contact details Procurement actually verified, with the date of verification. Compare those against what the email claims.
-
Compare the Banking History
Banking changes at CypherPeak are tracked formally. Procurement records every approved change with a timestamp and an approver. The history makes the email's story easy to falsify. VendorVerify and the email disagree on Marcus's contact details. You have to pick a channel to confirm the request with the real Marcus before doing anything else.
Security Framework Coverage
MITRE ATT&CK
- T1656 Impersonation
CIS Controls
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind