---
title: "A customer reports a new IBAN: verify before acting"
canonical: https://www.billabex.com/en/blog/customer-new-iban-verification/
lang: en
alternate: https://www.billabex.com/fr/blog/nouvel-iban-client-verification.md
updated: 2026-09-25
index: https://www.billabex.com/llms.txt
---

# A customer reports a new IBAN: verify before acting

A customer announces a change of bank and attaches new account details. For a team managing overdue invoices, the message may initially look unimportant: the customer owes your business money. Yet the same thread may request a refund, change a destination used for an outgoing transaction or introduce an unfamiliar person into a sensitive account. Start by establishing the direction of the funds: who is supposed to pay whom, why, and into which account?

Do not immediately replace the stored details. Record the request as information awaiting verification, linked to the operation it concerns. Proposed bank details, verified bank details and an authorised transaction represent three separate decisions. Combining them into a single “bank details updated” status prevents the next person handling the account from understanding which checks have actually taken place.

## Establish what the change could trigger

If the customer pays you by credit transfer, their new bank does not change your own beneficiary IBAN. It may explain why an incoming payment arrives from a different account, but it does not justify replacing the payment instructions in your reminders. A request that mixes up the customer's bank details and your business's payment destination requires clarification before anyone changes the record or sends revised instructions.

If your business must return money, the new account does become a payment destination. You then need to verify the request, the beneficiary and the amount actually available for repayment. The accounting question remains separate from the banking question. Authentic account details do not establish that money is owed, and a valid credit note does not establish that its sender has authority to choose where a refund should go.

A third situation involves details associated with a direct debit. Route that through your mandate management procedure and payment provider. Do not treat an email as general permission to amend every payment method associated with the customer. Specifying the affected operation prevents a local update from affecting transactions outside the customer's request or the scope approved by the person reviewing it.

## Recognise why confirmation in the same thread is insufficient

France's Cybermalveillance.gouv.fr describes bank detail fraud that can involve a compromised email account. A message arriving from a familiar address is therefore not independent confirmation of its contents. The official guidance recommends procedures for authenticating and approving unusual payment requests or changes of bank details. [FOVI guidance, sections 1 and 2](https://www.cybermalveillance.gouv.fr/tous-nos-contenus/fiches-reflexes/escroquerie-faux-ordres-virement-fovi).

In your process, use an established channel separate from the message received. If the sender writes “call my new number below”, that number is part of the information awaiting verification. It is not yet an independent reference. France's national payments committee recommends calling the beneficiary on their usual number when there is doubt. [CNMP guide, page 7](https://www.banque-france.fr/system/files/2025-09/CNMP_Guide-d-utilisation-Verification-du-beneficiaire.pdf).

Prepare the call with the legal entity, purpose of the transaction and account references. The aim is to confirm the particular instruction with an authorised person, rather than obtain a vague acknowledgement that the company has changed banks. If the familiar accounts payable contact has left, follow the approach for [rebuilding the customer's payment contact route](https://www.billabex.com/en/blog/accounts-payable-contact-left-payment-route/) before assuming their apparent replacement has the relevant authority.

## Use verification of payee for the question it answers

Verification of payee compares the name and IBAN for an applicable transfer. The French guide distinguishes a match, a close match, no match and an unavailable verification. An unavailable technical response therefore does not mean a positive confirmation. Coverage depends, among other things, on the country and banking service involved. [CNMP guide, pages 4 to 6](https://www.banque-france.fr/system/files/2025-09/CNMP_Guide-d-utilisation-Verification-du-beneficiaire.pdf).

That comparison answers a limited banking question. Our operational conclusion is that even a match cannot establish the authority of the person requesting a refund or its commercial justification. Keep those checks separate. Conversely, a mismatch is not enough to label the customer fraudulent: it may require a correction or further investigation. The reviewer needs to know what evidence would resolve the discrepancy before deciding whether the transaction can proceed.

Ask the person preparing payment to retain the useful result and resulting decision, without distributing additional copies of bank documents through uncontrolled channels. If verification cannot be completed, specify the next action: contact the bank, obtain independently verified information or have an authorised person examine the exception. The fact that a banking form allows its user to continue is not, by itself, a business justification for doing so.

## Distinguish observed losses from an invented probability

The December 2025 EBA-ECB report states that payment service users bore approximately **85% of losses arising from credit transfer fraud in 2024** within its European reporting scope. It uses payment provider reporting. That percentage describes how recorded losses were distributed, rather than the probability that a bank detail change received by your French SME is fraudulent. [Report, pages 7 and 47](https://www.ecb.europa.eu/press/intro/publications/pdf/ecb.ebaecb202512.en.pdf).

The practical implication is to treat approval before funds leave as a substantive decision, without treating every customer as a suspect. Explain the procedure consistently: any new destination for an outgoing payment receives the same checks. A predictable rule is easier to apply than a control improvised only when an amount looks large or the sender's tone seems unusual. Consistency also makes legitimate customer requests easier for colleagues to explain and handle.

## Test the file against a simulated refund

Consider a fictional example unrelated to any actual customer. An email requests repayment of a €2,400 credit note into a new account. Finance finds the credit note but establishes that €1,400 has already been allocated against an invoice under the arrangement applicable to that account. The remaining available amount in this scenario is €2,400 − €1,400 = €1,000, before approval of the refund itself.

Checking the new IBAN does not resolve that difference. Even with a confirmed account, paying €2,400 would send €1,400 too much in this example. Equally, limiting the payment to €1,000 would not make its destination trustworthy. This is why [checking the credit note and its allocation](https://www.billabex.com/en/blog/unallocated-credit-note-balance-check/) supports accounting approval, while the bank detail amendment follows a separate verification process. Neither check substitutes for the other.

Suppose the independent call confirms the refund request but reveals an error in the beneficiary name entered. The record can separately show the confirmed request, the approved €1,000 amount and bank details still awaiting correction. None of these stages means a transfer has been executed. Once payment actually occurs, reconcile the real movement and prevent another copy of the same request from remaining open in a separate conversation.

## Make authorisation visible and respond promptly to anomalies

The colleague receiving the email can prepare the case without having authority both to change the destination and approve payment alone. Define that separation for your organisation and identify cover for absences. A sender's stated urgency should reach the decision maker; it should not silently remove the checks that person is expected to exercise. Record the scope of approval so another colleague can complete the agreed action without having to infer its limits.

If fraud is suspected, interrupt the affected process and promptly alert the appropriate people. Cybermalveillance.gouv.fr recommends contacting the bank immediately, requesting recovery where necessary and preserving evidence; taking these steps does not guarantee that transferred funds will be recovered. [FOVI guidance, section 3](https://www.cybermalveillance.gouv.fr/tous-nos-contenus/fiches-reflexes/escroquerie-faux-ordres-virement-fovi).

Your [collections activity trail](https://www.billabex.com/en/blog/collections-audit-trail-automation/) should connect the request with subsequent actions without confusing receipt and approval. [Billabex's customer view](https://www.billabex.com/en/product/customer-view-360/) helps bring invoices and conversations together for that preparation. Banking decisions remain with your procedure and authorised people, supported by an account status that is understandable before anyone initiates the operation.

## Sources

- EBA and ECB, December 2025, pages 7 and 47: [payment fraud report, 2024 data](https://www.ecb.europa.eu/press/intro/publications/pdf/ecb.ebaecb202512.en.pdf).
- France's national payments committee, September 2025, pages 4 to 7: [verification of payee guide](https://www.banque-france.fr/system/files/2025-09/CNMP_Guide-d-utilisation-Verification-du-beneficiaire.pdf).
- Cybermalveillance.gouv.fr, updated 3 August 2026: [fraudulent credit transfer instructions](https://www.cybermalveillance.gouv.fr/tous-nos-contenus/fiches-reflexes/escroquerie-faux-ordres-virement-fovi).
