HomeInsightsPayment-request security

Supplier Payment Changes: Callback Script and Log

When a supplier asks you to change payment details, pause the change and verify it through a contact route you already trust. Record who confirmed the request, what they confirmed and who authorised the update before releasing payment.

This guide is for Canadian small-business owners and staff who maintain supplier records or approve invoices. It includes North Star's original callback script and verification log, designed for adaptation to your existing payment procedures. It is not a bank-issued form, a tested fraud-prevention guarantee or a legal compliance assessment.

Make the payment change the trigger

The Canadian Anti-Fraud Centre describes a supplier swindle in which a message appears to come from an established vendor and directs future payments to a different account. The existing business relationship is part of the deception. Read the CAFC's supplier and contractor warning.

Apply your verification procedure whenever the destination or method changes: a new account, a different payment portal, a substitute payee or an unexpected request to use an e-transfer. Do not wait for poor spelling, an unfamiliar logo or an unusually large invoice before checking.

Keep the original request in your approved records system and mark the proposed change as pending. Tell the person preparing the payment that the new instructions have not been approved. Establish an escalation owner before a payment deadline makes everyone feel rushed.

Choose the contact independently of the request

The CAFC recommends checking changed payment instructions using a trusted phone number rather than one supplied in the message. It also encourages internal controls such as dual authorisation for wire transfers. See the CAFC's business email compromise prevention guidance.

For your internal procedure, start with the supplier contact recorded during approved onboarding or another previously verified business record. Document where the number came from. A number in the new invoice, its signature or an attached "confirmation letter" belongs to the request you are checking; it does not independently verify it.

If the contact record was recently changed, the usual person is unavailable or the records disagree, leave the request pending and ask the designated business owner to establish a reliable contact route. An incoming call repeating the email is not the outbound callback recorded in this procedure.

Use a short script, then document the outcome

Call the established contact route yourself. Ask for the person authorised to confirm payment arrangements. The following wording is an original operational template, not a quotation from a regulator:

  1. Introduce the purpose: "I am calling about a request to change payment instructions for our supplier account. We verify these changes before updating our records."
  2. Establish responsibility: "Who is authorised to confirm this change? I can arrange a callback through our established contact route if that person is unavailable."
  3. Confirm the request: "Did your organisation request a change? What is changing, when should it take effect, and which invoices or future payments does it cover?"
  4. Confirm the handoff: "Please provide the approved instructions through our agreed secure process. We will compare them with the request and complete our internal review before applying a change."

Do not disclose passwords, one-time codes or banking-login credentials. Keep actual payment details in the approved supplier or payment system, not in a widely shared checklist. A callback is evidence for your review; it does not independently prove account ownership or replace your organisation's other payment controls.

Separate verification, record changes and payment release

Assign the verifier and approver before using this template. Where your procedure requires two people, the second person should review the evidence rather than merely acknowledge that a call happened. A team that cannot obtain the required reviewer should use its approved escalation process, not silently waive the control.

Suggested outcomes for the verification log
FindingRecordNext action
Request confirmedContact source, authorised respondent, scope and evidence reference.Submit for the required internal approval; update and release only when those controls are satisfied.
Unable to verifyMissing contact, unanswered call or unresolved discrepancy.Keep the change pending and assign an owner. Lack of confirmation is not proof of fraud.
Supplier denies requestDenial, date and protected message reference.Do not apply the disputed change. Escalate through the incident process.
Details do not matchMismatch category without copying full account details into the log.Pause and resolve through the established contact and approval route.

After an approved update, have the responsible person confirm that the payment system reflects the authorised destination and effective date. Record the change reference and completion time. The log should distinguish a verified request from an applied change and from an actual payment.

Download the script and verification log

Download the payment-change verification template

The text file includes the callback wording, source-of-contact check, outcome choices, approval fields and change-completion record. Store the completed version with restricted business records. The download requires no email address and sends no supplier information to North Star.

Rehearse with a fictional request

Use a made-up supplier and sample invoice reference. Have one person present changed instructions with an urgent deadline, while the established contact is temporarily unavailable. The expected result is a documented pending request and escalation, not a guessed approval. Repeat with a confirmed request and check whether the reviewer can follow the evidence without needing the original verifier to explain it.

This is a proposed practice scenario, not a customer case study or measured result. Adapt it to your payment platform, staffing and authority rules.

Contact the financial institution that transferred the money promptly and report the suspected fraud. The CAFC advises gathering relevant records, contacting local police and reporting the incident through its reporting channels. Keep email, transaction and report references available; do not delay contacting the institution to finish this worksheet. Follow the CAFC's current victim guidance.

Alert your internal incident owner and IT provider through a trusted route. They can assess whether an email account or supplier record may be affected. Reporting does not guarantee that funds can be recovered.

Connect the procedure to email security and staff handoffs

The Cyber Centre recommends verifying unusual requests through another communication channel and involving IT when messages raise concerns. Read its email security guidance. For background, see our phishing explainer and email authentication guide.

Keep approval ownership current through employee handoffs, and connect suspicious requests to your incident response plan. For help with supporting account controls, see managed Microsoft 365 or contact North Star. Do not send account details through a public contact form.