NORTH STAR | SUPPLIER PAYMENT-CHANGE VERIFICATION Version 1, 6 September 2026. Adapt and approve before use. An original operational template, not a bank-issued form or guarantee. Use with your organisation's payment authority and approval procedures. Store completed records in restricted business documentation. Do not enter full account numbers, passwords, one-time codes or login details. Use protected evidence references instead of copying sensitive documents here. 1. REQUEST AND HOLD Internal request/reference: Supplier record reference: Date received and time zone: Request type (destination / method / payee / portal / other): Requested effective date: Affected invoice or payment references: Protected original message/document reference: Person responsible for keeping the change pending: Scheduled payment owner notified on: Escalation owner: 2. INDEPENDENT CONTACT Verifier: Pre-existing approved contact record/reference: How and when that contact route was previously established: Has this contact record recently changed?: If changed or uncertain, escalation/verification action: Outbound callback date and time: Authorised respondent and business role: If no authorised contact reached, leave PENDING. Do not substitute a number supplied in the disputed request. Do not treat an incoming call repeating the request as this outbound check. 3. ORIGINAL CALLBACK SCRIPT Introduce: "I am calling about a request to change payment instructions for our supplier account. We verify these changes before updating our records." Establish responsibility: "Who is authorised to confirm this change? I can arrange a callback through our established contact route if that person is unavailable." Confirm: "Did your organisation request a change? What is changing, when should it take effect, and which invoices or future payments does it cover?" Handoff: "Please provide the approved instructions through our agreed secure process. We will compare them with the request and complete our internal review before applying a change." A callback alone does not establish account ownership or authorise payment. 4. VERIFICATION RESULT Select: CONFIRMED / UNABLE TO VERIFY / DENIED / MISMATCH Scope and effective date confirmed: Approved secure instruction/evidence reference: Details comparison performed in restricted system by: Comparison outcome (do not copy full payment details): Unresolved questions: Next action, owner and due date: 5. INTERNAL APPROVAL Required approver/reviewer under your procedure: Evidence and independent contact source reviewed: Verification gaps resolved or escalation decision: Decision (approved / pending / rejected): Approved scope and effective date: Decision date and time: Reviewer/sign-off reference: If required reviewer unavailable, approved escalation route: 6. APPLY AND CHECK Record updater: Supplier/payment-system change reference: Actual update time: Authorised destination and effective date checked by: Check outcome: Payment remains pending or released under existing approval process: Payment/release reference, if applicable: Unresolved exception, owner and due date: 7. IF PAYMENT WAS ALREADY SENT Promptly contact the financial institution that transferred the money. Use its trusted contact route. Do not delay to complete this worksheet. Follow current Canadian Anti-Fraud Centre victim guidance. Preserve relevant messages, receipts and transaction references. Report to local police and the CAFC as appropriate to its guidance. Notify your internal incident owner and IT provider through a trusted route. Institution contacted on/reference: Police/CAFC report references: Internal incident owner: Protected evidence location: Next follow-up: Reporting does not guarantee recovery. 8. CLOSEOUT Request result: Change result: Payment result: Follow-up owner: Completion/review date: REHEARSAL Use a fictional supplier and sample invoice reference. Scenario A: established contact unavailable; expected outcome is pending with an assigned escalation owner, not guessed approval. Scenario B: request confirmed; reviewer must be able to follow the evidence and distinguish verification from record update and payment release. This is a proposed practice scenario, not a measured result. PRIMARY SOURCES, CHECKED 6 SEPTEMBER 2026 CAFC supplier/contractor spear-phishing warning: https://antifraudcentre-centreantifraude.ca/scams-fraudes/spear-phishing-harponnage-eng.htm CAFC trusted-number verification and internal controls: https://antifraudcentre-centreantifraude.ca/news-nouvelles/2025/2025-07-24-eng.htm CAFC victim guidance: https://antifraudcentre-centreantifraude.ca/scams-fraudes/victim-victime-eng.htm Cyber Centre email security guidance: https://www.cyber.gc.ca/en/guidance/email-security-best-practices-itsm60002