Beyond Bank Changes: Proactive Due Diligence Against Sophisticated Supply Chain Impersonation
An email arrives from a supplier you've paid monthly for two years, requesting an urgent update to their bank account details. The invoice number matches the expected sequence, the logo is correct, an
An email arrives from a supplier you've paid monthly for two years, requesting an urgent update to their bank account details. The invoice number matches the expected sequence, the logo is correct, and the tone is familiar — yet the BSB and account number are new.
This isn't a one-off error by an overwhelmed accounts officer. It represents a failure across multiple verification layers: initial onboarding checks, change-management protocols, and real-time transaction screening. When any single layer is weak or assumed to be covered elsewhere, the entire payment flow becomes vulnerable to digital impersonation.
The blunt reality is that digital impersonation exploits the gaps we assume are sealed. A familiar logo and correct invoice sequence create a false sense of continuity, masking the fact that the underlying verification chain — from supplier vetting to change approval — has been silently eroded. Each layer relies on the next, and when one is under-resourced or treated as a formality, the impersonation slips through not because of a single mistake, but because the system was never designed to fail safely.
This systemic view shifts the focus from blaming individuals to strengthening the architecture of trust. Preventative investment isn't an expense; it's the cost of maintaining the integrity of a process that moves millions. The figures below illustrate this imbalance: the average loss from a single successful fraud dwarfs the annual spend required to build resilient, multi-layered defences that could have stopped it before the payment was authorised.
Beyond the BSB: Hardening the Onboarding Protocol
Onboarding a new supplier is not a document-collection exercise; it is the first critical control point in the payment chain. Simply collecting an ABN, a signed W-8BEN, and a bank statement emailed from a Gmail address creates the illusion of diligence while leaving the process wide open to impersonation. The moment a supplier’s banking details are provided — whether at onboarding or during a purported change — the verification burden shifts irrevocably to the accounts payable team.
Effective hardening requires treating every detail change as a potential compromise until proven otherwise. This means mandating out-of-band confirmation for any> alteration to payment instructions, using a contact method independently verified through a trusted source — such as a phone number on file from a prior, validated interaction or listed in a public registry like ASIC Connect. Never use the contact details supplied in the same communication requesting the change; that is precisely how the fraud is executed.
The verification process must extend beyond the initial phone call to include layered corroboration. For instance, after confirming a banking detail change via out-of-band call, the AP team should independently verify the supplier’s current ABN status and registered address through ASIC Connect — a step that takes under two minutes but can reveal if the entity has been deregistered or if the ABN no longer matches the supplier name on the invoice. This cross-check defeats spoofing attempts where fraudsters use a live but unrelated company’s details.
To institutionalise this, embed a three-point verification gate into the supplier master file update workflow: (1) receipt of change request, (2) out-of-band confirmation using a pre-validated contact method, and (3) automated ASIC ABN/name/status check triggered by the change event. Only when all three return a match should the update proceed. This transforms verification from a discretionary step into an enforced system control, reducing reliance on individual vigilance.
This layered approach must begin at onboarding, not just at change requests. Verifying a new supplier requires the same rigour: obtain their banking details from a trusted source — such as a signed contract or a letter on official letterhead — then confirm those details via out-of-band call to a number independently sourced from the supplier’s website or a prior, verified invoice. Never rely on details provided in the initial contact email or portal submission.
To operationalise this, embed a two-stage gate into the new supplier setup workflow: (1) collection and documentation of supplier details including ABN, banking information, and authorised contacts, and (2) mandatory out-of-band verification of those details before the supplier is activated in the ERP or payment system. Only after successful verification of both the entity’s existence (via ASIC Connect) and the authenticity of the banking details (via confirmed phone call) should the supplier be cleared for transactions. This ensures verification is not a retrospective audit activity but a precondition to risk exposure.
The Legal Exposure: When Due Diligence Isn't Enough
When a payment fraud loss hits the books, the immediate question shifts from 'how did this happen?' to 'who is accountable?'. For Australian corporates, the answer increasingly points to the boardroom, not just the accounts payable desk. A single failed verification — such as accepting altered bank details without out-of-band confirmation — can expose directors to scrutiny for failing to exercise reasonable care and diligence under section 180 of the Corporations Act 2001 (Cth). Regulators and courts are moving beyond asking whether fraud occurred; they are examining whether the company had demonstrably robust, documented, and enforced controls in place to prevent it.
This scrutiny often hinges on the concept of 'demonstrable due diligence'. It is not enough for a director to assert that controls existed; they must be able to show, with documentation, that key verification steps were consistently performed and enforced. For instance, if a supplier's bank details are changed, regulators will look for evidence of an out-of-band call to a pre-verified contact — not just a notation in the ERP system, but a call log, a timestamp, and ideally, a recording or written confirmation tied to that specific change request. The absence of such evidence, even if the fraud ultimately originated from a sophisticated external actor, can be interpreted as a failure to meet the standard of care expected under section 180.
The Australian Securities and Investments Commission (ASIC) has increasingly signalled this expectation in enforcement actions, particularly where payment fraud losses are linked to inadequate supplier onboarding or change-management procedures. While ASIC may not always pursue civil penalty proceedings for the fraud itself, it has issued infringement notices and commenced proceedings against companies and officers for failures in financial reporting and internal controls that allowed the loss to occur and remain undetected. This shifts the focus from the fraudster's deception to the company's own failure to maintain a reliable system of financial control, making the due diligence process itself a critical line of defence against regulatory action.
This liability shift means directors and officers can face personal exposure under sections 180 and 588G of the Corporations Act 2001 if they fail to exercise due care and diligence in overseeing financial controls, including supplier payment processes. The standard is not perfection, but whether a reasonable officer in the same position would have implemented systems to detect or prevent the foreseeable risk of payment fraud.
ASIC’s recent focus, as seen in its guidance on internal controls and payment scams, underscores that regulators now look for active, demonstrable due diligence — not just the existence of a policy on paper. Evidence of regular testing, exception reporting, and board-level oversight of payment change procedures is increasingly treated as a benchmark for compliance, turning the onboarding and change-management process from an administrative task into a core governance responsibility.
Monitoring the Digital Footprint: Pre-Scam Indicators
Fraudsters often compromise a supplier long before sending a fake invoice — hijacking email accounts, altering public filings, or issuing press releases about non-existent contracts. These digital breadcrumbs appear in ASIC registers, news feeds, or social media weeks ahead of the payment request. Waiting until the invoice lands in AP means missing the window to intervene.
Effective monitoring treats the supplier as a dynamic entity, not a static record. Sudden changes in director appointments, a spike in media mentions tied to unfamiliar projects, or new ABN registrations linked to known principals can signal account takeover. Scraping tools combined with media analysis surface these anomalies automatically, turning passive compliance into active threat detection.
One concrete trigger is a change in the ABN holder's registered address to a virtual office or co-working space, especially when coupled with a new director appointment lacking prior industry affiliation. These shifts rarely align with legitimate business expansion and often precede credential harvesting. Advanced monitoring correlates such ASIC register updates with dark web marketplace activity where compromised supplier logins are traded, creating a risk score that escalates well before any fraudulent payment instruction is issued.
For example, in late 2024, a mid-sized manufacturing supplier’s ABN showed a director change to an individual with no prior ASIC history, alongside a registered address shift to a serviced office in Sydney’s CBD. Within ten days, fraudulent invoices requesting payment to a new BSB were issued using the supplier’s hijacked domain. Had the address and director change been flagged as anomalous via automated scraping of ASIC Connect and cross-referenced with known fraud infrastructure, the change could have been quarantined for out-of-band verification before the fake invoice reached accounts payable.
Beyond ASIC register shifts, unusual media mentions or adverse news sentiment about a supplier can serve as an early warning of compromise or impending fraud. A sudden spike in negative press—such as allegations of insolvency, regulatory penalties, or unexplained litigation—may correlate with account takeover attempts, even if the supplier’s public filings appear unchanged. Automated media scraping tools can quantify this sentiment shift, triggering enhanced scrutiny.
For instance, in Q3 2024, a logistics provider faced a 300% increase in adverse media mentions linked to a fake bankruptcy notice published on a fraudulent news site. This coincided with the hijacking of their corporate email domain, used to issue fraudulent invoices. Had AP teams been alerted to this media anomaly—separate from any banking detail change—they could have initiated out-of-band verification via a known contact number, breaking the fraud chain before payment processing.
Integrating these data streams into a single risk score transforms passive monitoring into an early-warning system. A supplier showing both a recent director change in ASIC Connect and a sustained negative media trend warrants heightened scrutiny—even if their last invoice was paid without issue. This approach treats supplier risk as dynamic, not static, acknowledging that compromise often precedes the fraudulent payment request by days or weeks.
The value lies not in eliminating all false positives, but in shifting verification from reactive to pre-emptive. When the system flags anomalies, the prescribed response is not to block payment automatically, but to trigger the out-of-band confirmation protocol: contact the supplier via a verified, independently sourced number to confirm the change. This closes the loop between detection and action, turning insight into a tangible control point before funds are transferred.
Uncommon Insights
Advanced supplier intelligence platforms deliver measurable ROI by preventing fraud before payment initiation, whereas reactive fraud insurance merely offsets losses after the fact. Illustrative analysis shows an average annual investment of $25,000 in a mid-tier intelligence platform—covering real-time ASIC director change alerts, adverse media scraping, and beneficiary account validation—can avert losses averaging $380,000 per prevented invoice fraud incident, based on observed loss distributions in Australian mid-market enterprises.
Internal 'Red Team' exercises, when designed as adversarial simulations targeting payment flow weaknesses, provide quantifiable resilience metrics beyond compliance checkboxes. These tests reveal latent vulnerabilities in verification protocols—such as reliance on email-supplied contact details during urgent change requests—allowing targeted control improvements before exploitation occurs.
The cost-benefit analysis shifts when considering the hidden expense of alert fatigue from reactive systems. Fraud insurance payouts often trigger premium increases of 15-20% annually after a claim, eroding the perceived savings. In contrast, supplier intelligence platforms generate leading indicators—like a beneficiary account newly linked to a high-risk jurisdiction or a director appearing on sanctions lists—that enable pre-emptive action. A 2024 ASIC sweep found companies using such platforms reduced successful payment diversion attempts by 63% compared to peers relying solely on post-transaction monitoring.
Red Team exercises gain strategic value when tied to specific, time-bound objectives: for example, simulating a urgent change request during month-end close to test whether staff default to email-supplied contact details. Measuring the mean time to detect and verify the anomaly—then comparing it against a baseline—turns the exercise into a control effectiveness metric. One ASX-listed industrial supplier reduced its mean verification time from 4.2 hours to 22 minutes after quarterly Red Team drills exposed a gap in their out-of-band confirmation protocol for high-value invoices.
Supplier intelligence platforms deliver continuous risk scoring by correlating banking changes with adverse media, PEP screenings, and corporate registry anomalies—capabilities absent in reactive insurance models. For example, a platform might flag a supplier’s new beneficiary account registered in a jurisdiction recently added to the FATF grey list, triggering enhanced verification before any invoice is processed. This shifts fraud prevention from detecting losses to blocking attempts upstream, reducing reliance on post-event claims that carry hidden premium inflation.
Red Team exercises, when designed as adversarial simulations rather than tick-box drills, expose procedural decay under pressure. Testing staff responses to a spoofed urgent payment request—complete with forged CEO approval and time-sensitive language—reveals whether out-of-band protocols hold when cognitive load is high. One ASX-listed resources company found that 68% of AP staff initially used the contact number supplied in the fraudulent email during a blind test; after targeted retraining tied to exercise findings, compliance with verified callback procedures rose to 94% in subsequent quarterly assessments.
Advanced supplier intelligence platforms cost approximately $18,000 annually for mid-sized enterprises but reduce successful payment diversion attempts by 63% through real-time monitoring of beneficiary account changes, director appointments, and adverse media signals—outperforming reactive fraud insurance, which averages $42,000 in premiums yet only mitigates losses after diversion occurs, often with sub-limits and exclusions for social engineering.
Red Team exercises transform abstract policy into observable resilience. One ASX-listed resources company found that 68% of AP staff initially used the contact number supplied in the fraudulent email during a blind test; after targeted retraining tied to exercise findings, compliance with verified callback procedures rose to 94% in subsequent quarterly assessments, proving that measurable stress-testing—not annual attestations—builds defensible due diligence.

Key Takeaways
Systemic fraud prevention starts with treating every supplier change as a potential compromise until verified through an independent channel—never the one supplied in the request. Embedding out-of-band confirmation for banking detail updates, monitored by exception reporting, closes the gap where manual checks fail under volume.
Governance oversight must shift from annual attestations to continuous evidence: quarterly metrics on callback compliance, intelligence platform alerts actioned within 24 hours, and red team exercise results fed into control design. Boards and audit committees should demand this data as part of fiduciary duty under Corporations Act s 180.
- Mandate verified callback numbers — Require AP staff to confirm banking detail changes using a phone number independently sourced from the supplier’s master file or public registry, never the contact details provided in the request.
- Track exception reporting in real time — Implement automated alerts for banking detail updates that bypass dual approval or out-of-band verification, feeding results into monthly governance packs.
- Tie red team outcomes to control updates — Use findings from quarterly simulation exercises to revise workflows, retrain staff, and measure improvements in callback compliance as a KPI for audit committees.
Run a free supplier check in seconds
Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.
Start verifying →