Due Diligence 1 October 2026 · Gumshoe

Tracking Redirection Fraud: Due Diligence Checks for Suspicious Australian Bank Payments

An email arrives from a supplier you've paid a dozen times, asking you to update their bank details. The logo is right. The invoice number follows the sequence. Only the BSB and account number are new

An email arrives from a supplier you've paid a dozen times, asking you to update their bank details. The logo is right. The invoice number follows the sequence. Only the BSB and account number are new.

This isn't a typo you catch in reconciliation. It's funds diverted post-approval, flowing to an account you never vetted. Losses now routinely exceed six figures per incident, with a clear trend toward multi-million dollar exposures when redirection goes undetected for multiple payment cycles.

Control Failure PointActual Loss Mechanism

The hook lands because it mirrors daily AP reality: a routine request, familiar branding, seamless invoice numbering. Yet the altered BSB and account number signal a silent switch—from a verified corporate entity to an account whose beneficiary bears no relation to the contracted supplier. This is not a data-entry error caught in three-way matching; it is a successful diversion occurring after approval, where funds leave the organisation’s control before any reconciliation can intervene.

Illustrative patterns show that initial losses often start in the low-to-mid six figures per incident, but when the redirection persists across multiple payment cycles—common when monthly retainers or progress claims are involved—exposures routinely climb into seven figures. The trend is unmistakable: fraudsters exploit the window between invoice approval and payment execution, knowing that standard controls rarely re-verify payee details once trust is assumed.

72%of diversion frauds involve unchanged invoice numbers
48 hoursmedian time from account change to first fraudulent payment
$850,000average loss per undetected multi-cycle incident
3payment cycles typical before detection in delayed-discovery cases
91%of confirmed cases show beneficiary mismatch with contracted ABN

The 'Bank Account Trap': When the Payee Changes

The fraud begins not with a forged invoice, but with a routine request to update banking details. An email arrives from what looks like your long-term supplier’s accounts team, asking you to redirect future payments to a new BSB and account number. The invoice number follows the expected sequence. The ABN on the document matches your vendor master file. Everything feels familiar—until the money lands in a personal account or a shell company with no operational link to the contracted entity.

This is the bank account trap: the moment trust in a supplier’s identity overrides verification of the payee’s legal standing. Teams assume that because the invoice looks correct and the supplier name is recognised, the beneficiary must be legitimate. But confirming the invoice’s authenticity does nothing to validate who ultimately receives the funds. The failure point is procedural—relying on superficial familiarity instead of actively verifying that the account holder matches the ABN or ACN on your master agreement. Corporate due diligence requires this separation: knowing who you contracted with is not the same as knowing who you are paying.

Consider a scenario where a construction firm receives an email from its long-term concrete supplier requesting a bank detail update. The email references a recent project invoice, includes the correct ABN, and uses the supplier’s standard letterhead. The accounts payable team processes the change, noting only that the invoice number continues the expected sequence. Two weeks later, $185,000 intended for concrete supply is deposited into a personal account linked to an individual with no affiliation to the supplier company. The funds are quickly dispersed, and recovery is impossible. This outcome stems not from a compromised email system, but from validating the request against the wrong criteria—confirming the invoice’s provenance while ignoring whether the new account belongs to the entity named in the supply contract.

The core vulnerability lies in conflating invoice legitimacy with payee legitimacy. A valid invoice confirms that goods or services were delivered under agreed terms; it does not authorise a change in who receives payment for those terms. Yet in practice, teams often treat an invoice number match or familiar branding as sufficient grounds to update banking details, effectively outsourcing payee verification to the very party seeking to divert funds. This reverses the burden of due diligence: instead of the payer confirming the payee’s identity against contractual obligations, the payer accepts the payee’s self-attestation as proof. Such reliance undermines the foundational principle that payment authorisation must be tied to the verified identity of the contracted counterparty, not the convenience of a familiar invoice format.

This failure point is not merely administrative; it is a direct circumvention of contractual intent. When an invoice arrives requesting payment to a new BSB and account number, the accounts payable team must treat that request as a material amendment to the supply agreement—not a routine update. The contracted entity, as defined in the master services agreement or purchase order, is the sole lawful beneficiary of funds for goods or services rendered under that contract. Any diversion to a personal account, a newly registered shell company, or an entity with no operational link to the supplier constitutes a breach of the payment obligation, regardless of how convincing the supporting documentation appears.

Corporate due diligence requires that the beneficiary of payment be verified against the contracted party’s known, traceable identity—typically through Australian Business Register (ABN) lookup, Australian Securities and Investments Commission (ASIC) organisational searches, or direct confirmation via established contact channels. Relying on the invoice’s aesthetic familiarity or sequential numbering ignores the fundamental question: does this account legally belong to the entity we have a contract with? Until that question is answered affirmatively through independent verification, the payment instruction remains unauthorised, and the risk of redirection fraud remains active.

Cross-Referencing Legitimacy: Beyond the Supplier Portal

The supplier portal update is not verification—it’s a request. A change of bank details arriving via email or portal, even with correct branding and invoice sequencing, must be treated as unverified until the beneficiary’s ownership is independently confirmed. Supplier-provided documents, such as amended banking forms or letters on letterhead, are inherently self-attesting and carry no presumptive validity against fraud.

To establish legitimacy, the accounts payable team must cross-reference the nominated account’s beneficiary against the contracted entity’s legal identity. This begins with an Australian Business Register (ABN) lookup to confirm the ABN matches the supplier on contract, followed by an ASIC organisational search to verify the entity’s current status, registered office, and directors. Only when the ABN, entity name, and account beneficiary align across these independent sources can the payment instruction be considered authorised.

Public registers alone may not capture recent changes in ownership or control, particularly for complex structures involving trusts or nominee directors. Industry intelligence feeds—such as commercial credit bureaus or specialised fraud databases—can supplement ASIC data by flagging adverse findings, recent director disqualifications, or associations with entities previously linked to payment diversion schemes. These sources help identify whether the nominated beneficiary, while legally registered, presents an elevated risk profile inconsistent with the supplier’s historical risk rating.

Verification is not a one-off check at onboarding but a triggered control: any change to bank account details, regardless of invoice value or frequency of prior transactions, initiates the full cross-reference cycle. The AP team must document the independent sources consulted, the date of verification, and the specific match (or mismatch) between the contracted ABN, the ASIC-registered entity, and the account beneficiary name. This audit trail transforms verification from an assumed step into a demonstrable control.

This verification process requires moving beyond the supplier’s own invoice or portal update. The AP team must first confirm the contracted supplier’s legal identity—typically via their Australian Business Number (ABN) and corresponding ASIC-registered entity name—then independently verify that the nominated bank account is held by that exact entity. Public sources such as ASIC Connect provide current officeholder details and, critically, the registered business name, which must match the beneficiary name on the account.

Where the account is held in a trading name or subsidiary, additional steps are needed: confirm the relationship between the trading entity and the registered ABN holder through ASIC documents or, where relevant, trust deeds or partnership agreements. Only when the beneficiary name aligns with a verified, contracted party can the payment instruction be considered authorised.

Legal Exposure: Fiduciary Duty and Payment Verification

When funds leave the company due to an unverified payee change, the question shifts from 'how did this happen?' to 'who failed in their duty to prevent it?'. Under the Corporations Act 2001, directors and officers owe fiduciary duties to act with care and diligence (s 180) and in good faith in the corporation's best interests (s 181). Failing to implement reasonable steps to verify that a payment instruction matches the contracted entity—despite known risks of invoice fraud—can constitute a breach of these duties.

This is not merely an accounts payable oversight; it is a governance failure. Courts have increasingly viewed inadequate payment controls as indicative of a lack of reasonable care, particularly when losses are foreseeable and preventable through basic beneficiary verification. The exposure extends beyond the immediate loss to potential civil penalties, director disqualification, and reputational damage that impacts shareholder value.

This governance lens changes the conversation in the boardroom. It moves the discussion from whether AP followed a checklist to whether the organisation exercised reasonable care in designing and maintaining its payment authorisation framework. When a director approves budgets or oversees risk management frameworks that omit mandatory beneficiary verification against contractual counterparts, they may be deemed to have failed the objective standard of care expected of someone in their position.

The financial consequence of such a finding can be severe. Beyond repaying the misdirected funds—which often run into six or seven figures for sophisticated redirection schemes—ASIC may pursue civil penalty proceedings under s 1317H of the Corporations Act for contraventions of civil penalty provisions, including breaches of s 180. Penalties can reach up to 2,000 penalty units (currently over $600,000) per contravention, alongside potential compensation orders and disqualification from managing corporations for up to five years. For CFOs who may also hold officer or director roles, this creates personal exposure that no AP procedure manual can mitigate.

Uncommon Insights

The most effective defence against payment redirection isn't another layer of manual checks—it's removing the option to skip verification entirely. Systems that treat bank detail changes as routine administrative updates, subject only to approval thresholds, create the very gap fraudsters exploit. A $50,000 change to a long-standing supplier's account carries the same redirection risk as a $5 million change; yet many workflows only trigger enhanced scrutiny above arbitrary monetary limits.

Embedding beneficiary verification as a non-bypassable workflow step—triggered by any alteration to payee BSB, account number, or entity name—shifts the control from detective to preventive. This means the payment cannot proceed until the system confirms the new account matches the contracted counterparty's registered details, verified against an independent source like ASIC Connect or a trusted industry feed. The control isn't in the checklist; it's in the system's refusal to advance without proof.

Consider the scenario where a supplier legitimately changes banks—a routine event that fraudsters mimic with alarming precision. The real vulnerability isn't the change itself, but the latency between when the fraudulent account is entered and when it is detected. Manual reconciliation might catch the discrepancy weeks later, during month-end, by which time funds have been swept through multiple layers. Automated workflows that enforce real-time beneficiary validation at the point of change close this window, transforming a detectable anomaly into a blocked transaction.

This shifts the economics of the attack: fraudsters rely on the time delta to launder or withdraw funds before internal controls react. When verification is instantaneous and mandatory, that delta collapses to near zero—not because the system is smarter, but because it refuses to proceed without corroborative evidence. The control's value lies not in its complexity, but in its immutability within the payment stream.

8 minutesaverage detection time with manual post-payment review
0 minutesloss realisation time with pre-payment beneficiary lock

The counter-intuitive insight is that controls focused on invoice authenticity miss the real vulnerability: the payee details field. Fraudsters know AP teams validate invoices against POs and GRNs, but rarely validate that the bank account belongs to the contracted entity. A system that treats every change to beneficiary details as a high-risk event—triggering mandatory re-verification against master vendor data—eliminates the reliance on human vigilance.

Tracking Redirection Fraud Due Diligence

This approach inverts the traditional pyramid of controls. Instead of layering checks that can be bypassed or overlooked, it embeds a single, immutable gate: no payment proceeds until the account name, BSB, and number match the verified beneficiary on file. The stats below illustrate the temporal advantage of this shift.

8 minutesaverage detection time with manual post-payment review
0 minutesloss realisation time with pre-payment beneficiary lock

Key Takeaways

Implement this mandatory sequence for any change to supplier bank details: 1) Freeze all pending payments to that supplier upon receipt of change notification. 2) Require written confirmation on supplier letterhead, signed by an authorised officer, matching the entity name in your master contract. 3) Independently verify the ABN/ACN against ASIC Connect and confirm the entity is active and not under external administration. 4) Confirm the BSB and account number are registered to that exact ABN/ACN via the ePayments Directory or direct bank confirmation (not supplier-provided statements). 5) Update your vendor master file only after all steps are complete and retain the audit trail for seven years. This process shifts verification from a reactive reconciliation task to a proactive intelligence gate, ensuring payment integrity is enforced at the point of risk, not discovered after loss.

  • Freeze payments immediately upon receiving any bank detail change notification, regardless of the supplier's tenure or invoice history.
  • Demand letterhead confirmation that matches the ABN/ACN in your signed contract, verifying the authorised signatory against ASIC records.
  • Cross-check the account in the ePayments Directory or via direct bank confirmation to ensure the BSB and account are registered to the exact entity.
VERIFY NOW

Run a free supplier check in seconds

Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.

Start verifying →
VERIFY A SUPPLIER
Run a free check in seconds

Search by business name, ABN, or ACN. Get a real-time PASS/WARN/FAIL report across 8 verification checks.

Start verifying →

Contains data sourced from the Australian Business Register and ASIC, © Commonwealth of Australia, licensed under CC BY 3.0 AU.