Criminals love simple wins. One of the easiest: change where your money goes, then get a transfer approved before anyone notices. Locking how payees and payment instructions are created or modified is one of the most effective ways to stop wire, ACH, and bill‑pay fraud—and it’s just as relevant for individuals as it is for small businesses and nonprofits. This guide explains three practical controls you can ask your bank to enable (and how to implement them yourself): approval delays, dual control, and out‑of‑band checks.
Why payee changes are a prime target
Fraudsters often don’t need to break encryption or guess your password. Instead, they:
- Trick someone via phishing or business email compromise (BEC) to send money to a “new” account.
- Use stolen credentials to add or edit a payee, then quickly request a wire or ACH.
- Exploit weak internal processes—like a single person both adding and approving a new payee.
The risk spikes when a payee’s name, account number, or routing details are newly added or recently changed. Tightening controls around those events shuts down a major path to loss and identity abuse.
The three controls that stop most payment redirection fraud
Here’s what to ask for and implement, in plain language.
1) Approval delays for new or changed payees
What it is: A built‑in cooling‑off period (for example, 24–72 hours) before you can send money to a new payee or to an existing payee whose account details were modified.
Why it works: Criminals rely on speed. A delay gives you time to notice suspicious activity, receive alerts, and contact your bank before funds go out.
How to enable:
- Ask your bank for “new payee lock,” “beneficiary hold,” or “cool‑down for edited beneficiaries.” Many business online banking platforms can set policy‑based holds separately for wires, ACH, and bill pay.
- Choose different delays by payment type (e.g., 72 hours for wires, 24 hours for bill pay). Wires are riskier and usually irreversible.
- Require alerts whenever a payee is added or edited. Configure push/email/SMS so at least two team members see them.
Tips for individuals: If your bank doesn’t offer this, create a manual delay: don’t send to a new payee the same day you add it and verify out‑of‑band first (details below).
2) Dual control (two‑person integrity)
What it is: One person enters or changes payee details; a second, different person must approve the change before any payment can be sent to that payee.
Why it works: It eliminates single‑point failure. Even if one account is compromised or an employee is tricked, a second person must confirm.
How to enable:
- Ask your bank to set “dual administration” or “dual authorization” on: adding payees, editing payee details, releasing wires, and establishing ACH templates.
- Use named users with least privilege: one “Creator” role, one “Approver” role. Never share logins or tokens.
- Require separate authentication factors for the approver (e.g., a hardware token or app prompt) and log every decision.
Small organization workaround: If you’re a team of one, designate a trusted board member, accountant, or co‑owner as the approver with read‑only plus approve‑change rights. If that’s not possible, require your bank’s call‑back verification to a known number you control.
3) Out‑of‑band verification
What it is: Verifying payee change requests using a separate, trusted channel—not email or the messaging channel where the request arrived.
Why it works: If an attacker controls an email thread or has compromised a supplier mailbox, they can forge “new bank details.” A separate channel breaks that control.
How to do it:
- Build a “trusted contact registry” for vendors and payees: verified phone numbers you obtained independently (e.g., from a contract or the vendor’s official website), not from an email signature.
- Before sending to a new or changed account, call the registry number and read back the account changes. Require a named contact to confirm.
- If you can’t reach the contact, pause. No exception payments when verification fails.
What to request from your bank, step by step
- Secure your user access first. Turn on strong authentication for all online banking users. Remove old users, enforce unique logins, and prohibit password reuse.
- Enable alerts. Ask for real‑time notifications for: new payees added, payee edits, new wire/ACH templates, changes to daily limits, and profile or device changes.
- Set approval delays. Apply holds on payments to new or edited beneficiaries. Ask to make the delay irreversible by regular users (admin only).
- Turn on dual control. Separate duties for: adding payees, approving payees, releasing wires, approving ACH batches, and changing limits.
- Require call‑back verification for high‑risk actions. Instruct the bank to call a pre‑registered number—not a number provided in a change request—to confirm beneficiary changes and first‑time payments over a threshold you choose.
- Template discipline. Use payment templates for recurring vendors. Changes to templates should trigger dual control plus the delay.
- Whitelist with caution. If your bank offers whitelisting of trusted beneficiaries, apply it only after out‑of‑band verification and maintain a quarterly review.
Internal process: your anti‑fraud checklist
- Change requests policy: No bank details are accepted over email without a verified call‑back. Train staff to treat “urgent” or “secret” requests as red flags.
- Document the workflow: Write a one‑page SOP: who creates, who approves, what to check, and where to log verifications.
- Keep a verification log: Record date, time, person called, phone number dialed, and confirmation phrase for every new or changed payee.
- Limit authorities: Cap payment limits and require second approval above modest thresholds (e.g., $2,500 for ACH, $5,000 for wires) even for established payees.
- Quarterly reviews: Audit the payee list, templates, user access, and alert settings. Remove dormant payees and old users.
Common attack patterns and how these controls block them
Business email compromise (BEC) with “updated banking details”
Typical play: An attacker impersonates a vendor and requests payment to a new account. They insert themselves into a real thread to appear legitimate.
Defense: Out‑of‑band verification stops it. Approval delays and dual control prevent a rushed payout if someone starts to process it.
Account takeover of online banking
Typical play: Stolen credentials allow an attacker to add a beneficiary and send a wire immediately.
Defense: A beneficiary hold delays the payout; dual control requires a second user and additional factors; alerts give time to freeze the account.
Insider or single‑point failure
Typical play: One staff member is tricked or coerced into changing payee details and sending funds.
Defense: Dual control and separation of duties remove unilateral authority.
For individuals and families: simple adaptations
- Ask your bank for “new payee hold” and “call‑back on first‑time wires.” Many wealth‑management and credit union platforms support this on request.
- Use a password manager and phishing‑resistant authentication (security keys or verified app prompts) for your bank login to reduce account takeover risk.
- When paying contractors or tuition, verify changes by calling a number on the official website, not one sent by email or text.
- Keep transfer limits low by default; raise them temporarily only when needed, then lower them immediately.
- Turn on alerts for new devices, profile changes, and payee adds. Confirm that notifications go to at least two contacts (you and a spouse/partner) when possible.
Configuration examples you can copy
- Wires: New or edited beneficiary: 72‑hour hold; dual control to approve both the beneficiary and the payment; bank call‑back over $5,000.
- ACH: New template: 24‑hour hold; dual control for template creation and batch release; daily limit capped at expected volume plus 20%.
- Bill pay: New payee: 24‑hour hold; edit to address or account: 24‑hour hold; alerts to two contacts.
- User access: Creator cannot release payments; Approver cannot create or edit beneficiaries; Admin cannot both create users and approve payments.
When your bank says it can’t: practical workarounds
- Manual delay: Institute a policy that new or changed payees cannot be paid until the next business day after out‑of‑band verification.
- Two‑key sign‑off: Require two signatures on a payment authorization form stored in a shared drive with audit history.
- Third‑party escrow for first payment: For high‑value first‑time payments, consider a reputable escrow or payment service that adds verification steps.
- Daily reconciliation: Review pending wires/ACH each afternoon. Many scams are caught during same‑day review.
Incident response if you suspect a fraudulent change
- Call your bank’s fraud line immediately. Ask for a wire recall or ACH return (R06/R10 as applicable) and place holds on outbound transfers.
- Lock access. Reset banking passwords, revoke sessions, and rotate tokens or app authenticators for all users.
- Freeze changes. Instruct your bank to freeze beneficiary edits until further notice and enable call‑back on all releases.
- Notify the payee/vendor. Use out‑of‑band contact details to warn them of potential compromise.
- File reports. Consider filing with your local authorities and appropriate regulators. Faster action increases recovery odds.
- Review and harden controls. After containment, enable the delay, dual control, and verification steps you were missing.
How this protects your identity, not just your balance
Payment‑change fraud is often part of a larger identity attack. If an attacker can modify payees, they may also change contact details, attempt credit pulls, or open new accounts in your name. Strong controls at your bank reduce the chance of successful account takeover and create an audit trail that helps you prove fraud if needed.
Pairing these banking controls with ongoing credit and identity monitoring can help you spot related misuse—like new inquiries, unexpected accounts, or address changes—so you can act quickly. If you want an easy way to keep watch for identity‑related financial activity while you harden your payment processes, consider using a dedicated monitoring service such as SmartCredit.
Quick setup checklist
- Turn on alerts for new/edited payees, templates, device/profile changes, and high‑value payments.
- Enable approval delays for new and modified beneficiaries (longer for wires).
- Implement dual control for beneficiary changes and payment releases.
- Adopt strict out‑of‑band verification for any change requests.
- Set conservative limits and require secondary approvals over thresholds.
- Review users, payees, and templates quarterly; remove anything unused.
Conclusion
Most payment redirection losses can be prevented by slowing down and splitting control at the exact moment fraud tends to occur: when payee details change. Ask your bank to add approval delays, require dual control, and enforce out‑of‑band checks, then back those controls with clear internal procedures and proactive alerts. These steps are simple, teachable, and highly effective—protecting both your money and your identity against one of today’s most common scams.
Good to Know
Most wire and ACH fraud succeeds during a narrow window right after a payee or routing detail is changed; slowing changes with a delay and second approval removes that window.