Direct-deposit change verification is the procedure an employer follows to confirm that a request to change an employee's banking details genuinely came from that employee. It is a single control, it takes about two minutes to execute, and it is the most cost-effective fraud prevention measure available to a payroll function.
Payroll diversion — the scheme this control defeats — succeeds almost entirely because the verification step is absent. Where it exists and is applied consistently, the scheme fails regardless of how convincing the request appeared.
The critical property is that verification must travel through a different channel than the request, using contact details the employer already holds.
This distinction is where most implementations fail. Replying to the requesting email is not verification, because if the address is fraudulent the reply reaches the attacker. Calling a phone number supplied within the request is not verification, for the same reason. Neither is confirming details that appear in the request itself, since the attacker chose them.
Genuine verification means retrieving a phone number from the HR system of record and calling it, or confirming in person. Nothing in the request is treated as trustworthy — not the sender address, not the phone number, not the attached form.
This also handles the harder case. When an employee's actual email account has been compromised, the request arrives from the legitimate address and passes every check based on the sender. Only a separate channel catches it.
Step four is a small detail that matters. Asking the employee to supply the digits rather than confirming digits you read to them prevents an attacker who has intercepted the call from simply agreeing.
Verification is strongest when it is not the only barrier:
The barrier to this control is almost never technical. It is that verification feels like distrust, and HR teams are reluctant to treat employees as suspects.
The resolution is framing and consistency. Verification protects the employee — they are the one who loses a paycheck — and it applies to everyone without exception. Communicating the policy to the workforce in advance, so employees expect a call when they change their banking details, converts the step from an accusation into a service.
Consistency also matters for a second reason. A policy applied selectively invites exactly the pressure that defeats it: the request that arrives on deadline, from a senior person, with an explanation for why this one should be handled quickly. A rule with no exceptions gives staff a defensible position, which is precisely what they need when someone is pressing them.
Employers using employee self-service portals sometimes assume the risk is handled because employees update their own details. It is not. Compromised employee credentials let an attacker make the change directly, and portals frequently lack any notification or approval step.
Portals should be configured to require multi-factor authentication for banking changes, send an automatic notification to the address of record, and where possible route changes for review rather than applying them immediately.
Payroll diversion losses are difficult to recover, because funds are typically withdrawn within hours and the fraud is usually discovered only when an employee reports a missing paycheck days later. Prevention is effectively the entire strategy, and this is the control that provides it.
Employer's Guardian helps employers establish and operate these verification practices within payroll operations through payroll services, including change procedures, approval requirements, and pre-run reconciliation.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.