The following is a contributed article by Angela Anastasakis, Senior Vice President of Operations and Customer Success at Nvoicepay. The views expressed in the article are solely those of the author.

The pandemic-driven surge in businesses paying suppliers via Automated Clearing House (ACH) systems has accelerated the digital transformation of commercial payments, but it has come at a cost: in many cases, accounts payable (AP) departments did not have enough time to adequately secure remote networks or establish procedures to ensure the secure handling of supplier bank account information.

Now that the dust has settled, CFOs and their AP teams have a responsibility to ensure these security measures are implemented, starting with the secure handling of data.

ACH fraud was already on the rise before the pandemic and increased sharply last summer. According to a survey by the Association of Certified Fraud Examiners (ACFE), 90% of internal and external fraud examiners reported an increase in all types of cyber fraud.

6c242494a0e332187616f181a9b9cb587c5007f64018f01a2ac53fbb41b5e715.png
Angela Anastasakis
Image courtesy of Nvoicepay
 

Bank account update requests are the most common method of perpetrating ACH fraud. According to data from Nvoicepay, where I oversee operations and customer success, such requests are quite common. Suppliers typically change bank accounts every four years. Most requests are legitimate, but AP teams should be wary of what fraud examiners call "vendor email compromise" (VEC) attacks.

In this type of attack, a malicious actor compromises a supplier's systems, monitors the invoicing process, identifies potential weaknesses among the supplier's customers, and then contacts accounts payable personnel to request a bank account update. They often time the request just before a large payment is due. Once successful, they divert the funds to an account they have set up and close the account immediately after receiving the money.

Unfortunately, this is more common than one might think. In a recent experience of ours, a client urgently requested a bank account update for a supplier about to be paid. When we checked the new information through our verification process, we discovered that the new account was fraudulent.

AP teams often remain vigilant when receiving requests to change banking information. But from the moment supplier information is collected, there is a need to handle bank account data securely and vigilantly. If this data is intercepted, fraudsters have material to make their schemes more credible. IT departments need to secure the company's network and environment, while finance departments need to implement rigorous, repeatable processes to collect, verify, and store this information.

Here are some recommendations.

Data Collection

First, determine what information needs to be stored. In addition to routing numbers, account numbers, and other remittance information, you may also need to add security questions or other unique identifying information.

This information should never be transmitted via email, as email is not secure. It is shocking how open people are when sharing information via email. There is a lot of naivety surrounding business email compromise (BEC). FBI records show that between June 2016 and July 2019, BEC caused losses exceeding $26 billion. And according to a report by the Association for Financial Professionals (AFP), BEC was the most common type of fraud attack last year, with 75% of organizations experiencing attacks and 54% reporting financial losses.

As such attacks increase, banking data should be sent via a secure portal or encrypted email. This is especially important in the early stages of a new supplier relationship, when there is a tendency to extend trust and pay quickly and conveniently. But do not do this. Security comes first. Clearly explain to suppliers that this is to protect both companies. They should understand and appreciate this. If there is resistance to this requirement, that is a red flag. Although vendor email compromise (VEC, a subset of BEC) is not common during initial onboarding, requesting exceptions to the process—especially accompanied by urgency—is a typical sign of phishing or fraud. Ensure your team is well-trained to trigger alerts in such situations.

It is not only during supplier onboarding that this information needs protection. Suppliers often send invoices via email that include bank routing and account information. Again, this is done with good intentions—to make it easier for customers to pay—but it also carries risk. Using a secure portal is the best solution.

When receiving sensitive information over the phone, ensure there is a phone verification procedure to confirm that the caller is an authorized representative of the supplier.

Verification and Secure Storage

When first establishing a relationship with a supplier, AP should work with procurement to verify all contract information. They can also use third-party tools or service providers that connect to banking networks to verify and confirm account identity and ownership. There are many such tools on the market.

If you are converting existing suppliers from check payments to ACH payments, you may already have some knowledge of their banking data, which can serve as another way to cross-check information before making changes.

Once verified, the information must be stored securely. If stored in paper form, companies should implement a degree of physical protection, such as locking it in a file cabinet, but we know that documents are often kept in folders on someone's desk, or in the era of remote work, in someone's car or home. Many companies store supplier data in spreadsheets. If someone intercepts this information, there is risk.

When storing supplier banking information in an ERP system, ensure that access is tightly controlled through strict permission workflows and regular audits of current user activity.

As companies traditionally reliant on checks rush to meet the demand for electronic payments, they may miss critical steps in protecting supplier banking data. They should work with IT, security, and compliance teams to establish robust access, monitoring, and review systems. Where resources and skills are limited, outsourcing responsibility to a payment provider is also an option to consider.

With the pace of change and the emergence of new security threats, focusing on worst-case scenarios can leave you feeling helpless and overwhelmed. Preparation is key to successfully managing change. Identifying these scenarios will help you anticipate and prepare for future challenges and pitfalls, allowing you to securely transform your accounts payable processes.