Direct-deposit change verification is the procedure an employer follows to confirm that a request to change an employee's banking details genuinely came from that employee. It is a single control, it takes about two minutes to execute, and it is the most cost-effective fraud prevention measure available to a payroll function.

Payroll diversion — the scheme this control defeats — succeeds almost entirely because the verification step is absent. Where it exists and is applied consistently, the scheme fails regardless of how convincing the request appeared.

What "out-of-band" actually means

The critical property is that verification must travel through a different channel than the request, using contact details the employer already holds.

This distinction is where most implementations fail. Replying to the requesting email is not verification, because if the address is fraudulent the reply reaches the attacker. Calling a phone number supplied within the request is not verification, for the same reason. Neither is confirming details that appear in the request itself, since the attacker chose them.

Genuine verification means retrieving a phone number from the HR system of record and calling it, or confirming in person. Nothing in the request is treated as trustworthy — not the sender address, not the phone number, not the attached form.

This also handles the harder case. When an employee's actual email account has been compromised, the request arrives from the legitimate address and passes every check based on the sender. Only a separate channel catches it.

A workable procedure

  1. Receive the change request through whatever channel it arrives.
  2. Retrieve the employee's phone number from the HR system — never from the request.
  3. Call the employee and confirm they submitted it, describing the change without reading out the new account details.
  4. Ask the employee to state the last four digits of the new account, rather than confirming digits you supply.
  5. Record who verified, when, and by what method.
  6. Apply the change and send a confirmation notice to the address of record.
  7. Include the change in the pre-payroll reconciliation review.

Step four is a small detail that matters. Asking the employee to supply the digits rather than confirming digits you read to them prevents an attacker who has intercepted the call from simply agreeing.

Reinforcing controls

Verification is strongest when it is not the only barrier:

  • A waiting period. Holding banking changes until the following pay cycle removes the urgency the scheme relies on. Attackers need the change to take effect before the real employee notices a missing paycheck.
  • Confirmation to the address of record. Notifying the employee through their existing contact details gives the genuine person a chance to object before payday.
  • Two-person approval. A second reviewer for banking changes means one rushed or compromised employee cannot complete the change alone.
  • Restricted edit rights. Limiting who can modify banking details reduces the number of people an attacker can target.
  • Pre-run review. Examining all banking changes since the last cycle, as a discrete step before payroll finalizes, catches anything that slipped through.

The organizational obstacle

The barrier to this control is almost never technical. It is that verification feels like distrust, and HR teams are reluctant to treat employees as suspects.

The resolution is framing and consistency. Verification protects the employee — they are the one who loses a paycheck — and it applies to everyone without exception. Communicating the policy to the workforce in advance, so employees expect a call when they change their banking details, converts the step from an accusation into a service.

Consistency also matters for a second reason. A policy applied selectively invites exactly the pressure that defeats it: the request that arrives on deadline, from a senior person, with an explanation for why this one should be handled quickly. A rule with no exceptions gives staff a defensible position, which is precisely what they need when someone is pressing them.

Self-service portals do not remove the need

Employers using employee self-service portals sometimes assume the risk is handled because employees update their own details. It is not. Compromised employee credentials let an attacker make the change directly, and portals frequently lack any notification or approval step.

Portals should be configured to require multi-factor authentication for banking changes, send an automatic notification to the address of record, and where possible route changes for review rather than applying them immediately.

Why this control earns its place

Payroll diversion losses are difficult to recover, because funds are typically withdrawn within hours and the fraud is usually discovered only when an employee reports a missing paycheck days later. Prevention is effectively the entire strategy, and this is the control that provides it.

Employer's Guardian helps employers establish and operate these verification practices within payroll operations through payroll services, including change procedures, approval requirements, and pre-run reconciliation.

This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.

Let's Talk! Schedule a Conversation

For additional information, pricing, and/or free consultation, contact us. We'd be happy to discuss your situation.

Contact Us Today!

Want a professional to walk you through your HR needs shopping list?

At Employer’s Guardian, our experts are here to help. We are happy to work with you to understand your HR needs. Get in touch—give us a call or fill out our online contact form and we’ll promptly get back to you!

Contact Us Today!