Change verification is the practice of confirming that a requested change to sensitive information genuinely came from the person authorized to make it, before the change takes effect. In an employment context the changes that matter are predictable: banking details, contact information, tax withholding, beneficiary designations, and vendor payment instructions.
It is the control that defeats most payroll and payment fraud, and it fails for a consistent reason — not because organizations lack a procedure, but because the procedure verifies through the wrong channel.
The defining requirement is that verification travels through a different channel than the request, using contact details the organization already holds.
Replying to the requesting email is not verification — if the address is fraudulent, the reply reaches the attacker. Calling a number supplied in the request is not verification, for the same reason. Confirming details the requester provided is theater: they chose them.
Genuine verification means retrieving the phone number from the system of record and calling it. This single discipline defeats both the lookalike-address attack and the harder case — a request sent from a genuinely compromised account, which passes every check based on the sender because the sender is real.
Verifying everything buries the control in volume. The changes worth the friction share a trait: they redirect money or reset the means of reaching the person.
The contact-plus-banking combination is the sharpest signal in the list. A request updating both at once is the standard fraud sequence and should never process as a routine edit.
Step four is small and meaningful: an attacker who has intercepted the call can agree to anything, but cannot supply digits they were not shown.
Employers with self-service portals sometimes conclude verification is obsolete because employees make their own changes. The risk simply moves: an attacker with the employee's credentials makes the change directly, with no human in the loop at all.
The portal equivalents are step-up authentication at the moment of a sensitive change, automatic notification to the previous contact details, and ideally a short hold before banking changes take effect — time for the real employee to see the alert and object.
The attack against this control is not technical. It is pressure: the deadline, the senior name, the plausible reason this one should skip the process. A policy applied selectively invites exactly that pressure onto whichever staff member is holding the line.
A rule with no exceptions is what protects the person applying it — they are not making a judgment call about trusting anyone, they are following the procedure that applies to everyone. Leadership stating that plainly, and confirming no one will ever be faulted for verifying, is what makes the rule survivable in practice.
Communicating it to the workforce helps too. Employees told in advance to expect a confirmation call when they change their details experience the check as service rather than suspicion.
Documented verification — who confirmed, when, through what channel — is also evidence. If a dispute later arises about whether a change was authorized, an employer that can produce the verification record is in a categorically different position than one relying on recollection.
Employer's Guardian helps employers build change verification into payroll operations, including procedures, approval steps, and pre-run review, through payroll services.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.