Changing a vendor's IBAN is one of the most common fraud scenarios in accounting: a fake email announcing new bank details, an edit made in the ERP, and the next transfer goes to a fraudulent account. This article explains why control cannot rest on one person or one system, and how dual validation between Sage Intacct and Arkaio reduces the risk.
Why IBAN changes are a weak point
In a traditional setup, an authorized user edits the vendor record, sometimes on the strength of a simple email. The next payment uses the new details with no further check. The consequences for finance teams are serious: funds that are hard to recover, an internal investigation, a strained supplier relationship. The risk comes from external fraud as much as from keying errors.
The principle: one change, two validations
- Change made in Sage Intacct: it generates an approval request in Arkaio.
- Change made in Arkaio: Sage Intacct is only updated once the change has been accepted.
A compromised account or a single entry is therefore not enough to redirect a payment. This complements the separation of duties described in our article on distributed electronic signature (VEU).
Additional controls before payment
- IBAN and BIC verification before payment is prepared: a non-compliant invoice cannot be selected.
- Frozen amounts as soon as the user enters them.
- Abnormal behavior detection through machine learning (unusual activity, IP address changes): the affected payments are blocked.
- Configurable rights and workflow: approving or cancelling a payment depends on the roles defined in Arkaio.
Use cases
- SMEs: with a small finance team, dual validation brings a second pair of eyes without heavy procedures.
- Mid-market and multi-entity groups: approvals follow the roles of each entity.
- Accounting firms: bank detail changes are traced per client file, as covered in centralizing multi-client payments.
Limits to keep in mind
Dual validation protects the payment flow, not the origin of the request. If a vendor's email is convincingly spoofed, the approver can still be misled. Calling the vendor back on a known number remains a good practice.
A complete audit trail
Every action is logged: who changed what, who approved, and when. The evidence is available in Arkaio for an auditor, CFO or CISO.
Key takeaways
Securing IBANs should not slow payments down. With Intacct/Arkaio dual validation, control is built into the flow: legitimate changes follow a clear approval path, and fraudulent attempts stop before the bank.