WritingOperations2 Oct 2026~7 min

Changed bank details: a verification workflow for letting agencies

Applies to United Kingdom. This is general information, not legal advice — check the primary legislation or take advice before acting on a specific case.

When a landlord, contractor or supplier asks to change bank details, pause the payee change and verify it through a contact route your agency already trusts. Do not use a phone number, email address or link supplied in the request. Record who completed the check, who approved the change and which payment used the new account first.

This control belongs in the payment workflow, even when the request arrives in a familiar email thread. The National Cyber Security Centre (NCSC) describes business payment fraud as an attacker impersonating a regular contact, sometimes with a convincing invoice or a request to pay a different bank account. It is also known as business email compromise.

A familiar message can still be fraudulent

A genuine-looking email can contain facts that only the agency and payee should know. In anNCSC Board Toolkit case, an attacker compromised a finance mailbox, diverted messages using email rules and altered supplier bank details. The organisation later required phone verification for new and updated supplier details.

Replying to the same email, calling the number in its signature or opening a link in the message all stay inside the route that may be compromised. Independent verification starts from a separate record: the signed management agreement, a previously verified contractor file, a known portal or a contact number already stored in the agency system.

Pause the payee record

Keep the existing bank details unchanged while the request is unverified. If a payment is already queued, hold it or send it back for review according to the agency's authority and banking process.

Use one workflow for every bank-detail change

Cover landlord disbursements, contractor invoices, supplier payments and any other regular payee. A written policy should define the change event, the evidence required and who can approve it. Staff should not have to invent a safer process while an urgent payment is due.

01

Hold

Keep the current payee record and pause affected payments.

02

Verify

Contact the payee through an independently held route.

03

Approve

Have an authorised person review the evidence and change.

04

Pay and review

Check bank warnings, authorise the payment and retain the record.

Suggested agency control. Adapt roles and limits to the size of the business and the bank mandate.

Step 1: capture the request without trusting it

Save the request and note the payment it could affect. Record the claimed payee, old account, proposed new account, requested start date and the person who received it. Escalate urgent or secretive requests, including any request to bypass the normal process.

Do not ask the sender to prove the request by providing more information through the same channel. A compromised mailbox can answer that challenge. Keep attachments available for the security or finance review, but avoid opening unexpected files or following links.

Step 2: retrieve a known contact route

Find contact details held before the request arrived. For a landlord, this may be the number verified at onboarding or in the signed management record. For a contractor, use the approved supplier file or an established portal. If there is no trusted route, escalate to the person who owns the relationship and rebuild the contact record before changing payment details.

NCSC phishing guidance recommends verifying important email requests through a second type of communication, such as a phone call, account login, post or an in-person check. The channel should be separate from the request and suitable for the value and risk of the payment.

Step 3: verify the change with the payee

Contact the known person and explain that the agency is checking a bank-detail change. Confirm that they requested it, the account name and details, when it should take effect and which invoices or disbursements it covers. If another person claims authority to make the change, verify that authority with the established contact.

Complete the check only after an actual conversation or authenticated portal confirmation. A voicemail, an unanswered call or a message saying yes from the original mailbox leaves the change unverified. If the answer conflicts with the request, stop and move to the incident process.

Step 4: separate verification, approval and payment

Report Fraud's mandate-fraud guidance says only designated employees should be able to change payment arrangements. A practical agency policy can also separate the person who verifies the payee from the person who approves the change, especially for high-value or unusual payments. Smaller teams can require a second recorded review by a director or finance lead.

The approval should show the evidence reviewed and any exception used. Avoid blanket approval of a spreadsheet containing several changed accounts. Review each payee against its own verification record, then restrict the system permission that can amend the master payee file.

Step 5: update the payee record with an audit trail

Change the record only after approval. Retain the previous details in history rather than overwriting the only evidence of what changed. Log the operator, time, source record and approval reference. Notify the verified payee through the known channel that the change has been completed, without sending full bank details in an ordinary email.

Protect the evidence file as financial information. Limit access to staff who need it for verification, approval, reconciliation or investigation. The payment system and contact record should make it possible to reconstruct the decision without relying on one employee's inbox.

Step 6: review the first payment to the new account

Match the payment to the verified payee record and the correct invoice or landlord statement. Read the bank's payee-check result. The NCSC case recommends calling the payee when online banking says the details do not match. A mismatch, partial match or unavailable check should return the payment to verification under the agency's policy.

Use the bank message alongside the independent check. The agency confirms that the intended payee requested this account, while the bank service checks the information it can compare. After payment, reconcile it promptly and investigate a chase from the old contact instead of assuming the supplier's records are late.

Keep the evidence compact and searchable

Evidence for a changed payee record
RecordWhat to retain
The requestOriginal message or document, received time, claimed payee and requested effective date.
Known contactThe contact record used before the request arrived, including where it came from.
Independent checkDate, channel, person contacted and the result. Do not copy contact details from the change request.
ApprovalNamed approver, decision time and any payment limit or exception applied.
System changePrevious payee record, new record, person who changed it and the audit reference.
First paymentInvoice or disbursement reference, bank warning outcome and final authoriser.

Set a retention period that fits the agency's legal, accounting, contractual and incident requirements. There is no single retention period for every agency and record. The team needs to find the evidence during a payment query without keeping unrestricted financial information indefinitely.

If the request may be fraudulent

Stop changes and payments connected with the request. Tell the agency's finance and IT or security contacts, preserve the messages and check whether the mailbox or account shows other suspicious activity. Do not accuse the genuine payee until you have established which account or message route was compromised.

If money has been sent, NCSC says to contact the bank directly using its official website or phone number, and to notify the organisation's IT contact promptly. The NCSC reporting guide says lost money should be reported to Report Fraud in England, Wales and Northern Ireland, or to Police Scotland in Scotland. Follow the current instructions on those official pages.

Make the control work across branches and portfolios

Put the same statuses into every branch workflow: received, held, independently verified, approved, changed, first payment reviewed and closed. Give each status an owner and prevent a payment from moving forward when the required evidence is missing. Review exceptions and failed checks so the policy reflects the requests the agency actually receives.

Tenant rent collection covers a different payment direction. Our guide to Direct Debit rent collection covers incoming payments and failed collections. The client money protection guide covers the agency's scheme, account and display obligations in England. Bank-detail verification controls who receives an outgoing payment.

Multi-office operators should also define which legal entity owns each payee and payment account. Our multi-branch operating guide explains why branch separation and group reporting need to coexist. When assessing how Tekniti could support a controlled payment workflow, start with the agency operations page and confirm the required bank, approval and audit integrations for the proposed scope before relying on them.

Tekniti runs this work for UK landlords and letting agencies — tracking it, preparing it, and holding what matters for a person to approve. See how it works for landlords or for letting agencies, or write to hello@tekniti.ai.