Resources
Practical guides for bookkeeping and accounting firms that run accounts payable for clients — how to verify vendor bank-detail changes, the controls insurers and auditors expect, and what to document.
Guide
Gusto verifies a contractor's new bank account with Plaid or test deposits and pushes edits to the contractor's own 2FA-protected profile — but admins can still change details on a contractor's behalf, and no check confirms the request itself was real. The callback step firms running client payroll must add.
Read the guide →Guide
Wise name-checks recipients in corridors with Confirmation of Payee — and a saved recipient can't be edited at all, so every bank change is a delete-and-recreate with no change history. What Wise checks, the USD gap, and the callback step firms must add.
Read the guide →Guide
Brex sends vendors a secure onboarding link and layers multi-level approvals on every bill — but neither step confirms that the change request was authored by the real vendor. What firms running client AP on Brex through Pro Access must add for NACHA Phase 2.
Read the guide →Compliance
NACHA Phase 2 now requires every ACH originator — no volume floor — to have a written, risk-based fraud-monitoring program on file, reviewed annually. The sections a small firm's program actually needs, the one control auditors and insurers keep landing on, and how to draft the document in an afternoon.
Read the guide →Concept
The rule that decides whether a callback was real verification or a call to the fraudster: use a contact record that existed BEFORE the change request. What counts as an independent source, the traps small firms fall into, and how to apply it across many client ledgers.
Read the guide →Guide
Dual approval at a solo or two-person bookkeeping firm doesn't require a second internal employee — the client engagement owner counts when the approval lands on a known, independent channel. The defensible small-firm setup, the $500 threshold question, and the five things to document on every change.
Read the guide →Guide
The five AP controls a firm running client AP should document — segregation of duties, an approval threshold, vendor master-file discipline, three-way matching, and out-of-band verification of bank changes — and the tamper-evident record auditors, clients, and insurers actually ask to see.
Read the guide →Guide
Plooto checks that bank details are well-formed and lets contacts self-manage banking through its network, with configurable approval chains and a full audit trail — but none of that confirms the change request was real. What firms running client AP on Plooto must add for NACHA Phase 2.
Read the guide →Guide
A vendor refuses the callback, can't get anyone on the phone, or steers you to their own number — here's the decision tree for firms running client AP, why you hold the payment, and how to document the hold so it's defensible to a client, auditor, or insurer.
Read the guide →Guide
AvidXchange enrolls suppliers in the AvidPay Network, collects signed ACH forms, and screens payments — but for a property-management or HOA firm running client AP, the change request that lands in your inbox still needs your callback. What to document for NACHA Phase 2.
Read the guide →Guide
Sage records every supplier bank-detail change in an audit log and can email your team when one happens — strong traceability, but both fire after the new number is saved, and neither confirms the request was real. What firms running client AP on Sage must add for NACHA Phase 2.
Read the guide →Guide
Xero stores supplier bank details and shows them at bill entry for a visual check, and US online bill payments run through Melio — but neither confirms the change request is real. What firms running client AP on Xero must add for NACHA Phase 2.
Read the guide →Compliance
NACHA Phase 2 is in effect as of June 22, 2026 — every ACH originator now needs written, risk-based fraud-monitoring procedures, no volume threshold. The seven-step checklist for a small firm running client AP, and the one record most firms are still missing.
Read the guide →Vertical
Bookkeepers running AP for law-firm IOLTA accounts: what to verify before a vendor disbursement leaves trust, how the callback record holds up in front of the state bar, and how NACHA Phase 2 applies to IOLTA originators too.
Read the guide →Guide
Stampli's vendor portal lets vendors self-serve their bank details, with internal approvals and an immutable audit trail — strong data hygiene, but the change request itself still needs your callback. What firms running client AP on Stampli must add for NACHA Phase 2.
Read the guide →Guide
Ramp's micro-deposits, Plaid link, and Vendor Portal payer-approval banner are the strongest of the SMB AP set — but none of them verify the change request itself. What firms running Ramp Stack still have to document for NACHA Phase 2.
Read the guide →Script
The word-for-word script for the call you are about to make: how to open, how to make the vendor read the new account details back to you, what to do if they push back, and what to log so the verification is provable later.
Read the guide →Guide
Melio's micro-deposits confirm an account can receive ACH, and its “verified vendor” lock blocks one attack path — but neither confirms a change request is real. What bookkeepers must document for NACHA Phase 2.
Read the guide →Compliance
NACHA Phase 2 takes effect Jun 22, 2026 — every ACH originator must document vendor bank-change verification. The minimum control set, what to update in the next seven days, and the evidence an ODFI or auditor will actually ask for.
Read the guide →Use case
The vendor bank-change verification routine that actually works for a firm running AP across multiple clients: per-client independent-contact callback, dual approval even at two people, and the log entry that holds up under an auditor or insurer's review.
Read the guide →Guide
BILL's one-cent test deposit confirms a vendor account can receive ACH — but not that the change request is real. BILL itself recommends verbally confirming new bank details. Where the gap is, and the one step that closes it.
Read the guide →Guide
When an auditor asks for your vendor verification documentation, they’re testing four things. The exact list of artifacts to produce, where the gap usually lives, and how to be ready in five minutes instead of five days.
Read the guide →Guide
QuickBooks Bill Pay’s penny test confirms an account can receive funds — but not that the change request is genuine, and you can’t independently re-verify after setup. Where the gap is, and the one step that closes it.
Read the guide →Guide
Most social-engineering coverage is conditional on a documented out-of-band callback before you change a vendor’s bank details — and claims get denied when it’s skipped or unrecorded. What insurers expect, and how to prove it.
Read the guide →Guide
You got the email and you’re not sure. How to tell a real request from a scam, the red flags to check, what to do before you pay, and how to recover if you already did.
Read the guide →Guide
The independent-contact rule, the exact callback to make, the red flags to watch, and what to record so you can prove you checked.
Read the guide →