Treat every change to where money goes as untrusted until an out-of-band callback to the number already on file confirms it, with a second approver above a threshold and the evidence logged.
Business email compromise is the most expensive thing that happens in an accounts-payable inbox. The FBI's Internet Crime Complaint Center reported $3,046,598,558 in BEC losses for 2025, up from $2,770,151,146 in 2024, inside an overall $20.877 billion across 1,008,597 complaints. The same report's section on AI in cybercrime counted 22,364 complaints reporting AI-related information, with $893,346,472 in adjusted losses, and states plainly that "voice cloning can also be used to request wire payment," with businesses reporting losses of over $30 million to BEC scams involving AI in 2025. The pattern is consistent: a vendor "updates" its bank details by email, or an executive's voice "approves" an urgent wire by phone, and the money is gone before anyone compares the request to what was on file. The defense is not better fraud detection on the email. It is a control: no payment-detail change takes effect until someone calls the vendor back at the number already in the vendor master — not the number in the request — and a second person approves anything above a threshold. An AI agent makes that control cheap enough to apply to every change rather than only the ones that feel suspicious: it parses the request, diffs it against the vendor master, generates the callback script, logs the outcome, and refuses to let the change through without the evidence. This pairs with the AP invoice capture and three-way matching workflow already in the library, but it is a control, not a throughput play, and it should be measured as one.
Bank account or routing number, payee name, remittance address, payment method, payment email, and any request to expedite or redirect a payment already scheduled. Also: any new vendor. Write the list down and put it in the AP platform (Bill.com, Stampli, Ramp, or Brex, depending on where your payables run) as a required workflow state, so that no change can be saved without entering the verification path.
The rule that defeats both email compromise and voice cloning is the same: verify through a channel the attacker does not control. The callback goes to the phone number in the vendor master that was recorded before the change request arrived — never the number in the email signature, never a number the caller offers. If no verified number exists, the change waits until one is established through a second independent route, such as the contract or the vendor's published main line.
Using the Claude API inside an n8n flow, the agent reads the change request, extracts the proposed values, pulls the current vendor master record, and produces a one-page diff: what is changing, how long the vendor has been on file, payment volume over the last twelve months, and whether the request carries urgency or secrecy language. It drafts the callback script with the verification questions pre-filled. It does not decide. A model that can be talked into approving a wire is a model that will be.
A named AP team member calls the number on file and runs the script: confirm the requester's identity, read back the proposed details, ask for a detail only the real vendor would know (last invoice number and amount), and confirm the change was initiated by them. Twilio can place and record the call with a disclosure where recording is lawful; the recording reference and the caller's answers go into the verification log. A vendor who cannot be reached is a change that does not happen yet.
Set a threshold — commonly the amount above which a single person should never move money alone — and route anything above it to a second approver in Slack, where the approval is tied to an authenticated identity and timestamped. The approval request includes the diff and the callback log. No approval by forwarded email, no approval by phone. If the request originated as a voice call claiming to be an executive, that executive confirms in Slack or in person; a second phone call is not independent.
The agent checks the log for all required artifacts — request captured, diff produced, callback to a pre-existing number completed with a positive match, second approval where required — and only then updates the vendor master. Missing artifact, no update. The first payment after any change is flagged for a manual eyes-on review regardless of amount.
Once a quarter, have someone outside AP send a realistic fake change request, including one by phone with urgency language. Measure whether the control held and how long verification took. Review every change in the log for completeness. Train AP staff on the current patterns in the IC3 report, particularly that a convincing voice is no longer evidence of anything.
Use these templates as-is or customize for your business.
BEFORE DIALING - Pull the vendor record as it existed BEFORE the request arrived. Use only the phone number stored there. - Have the proposed change, the last paid invoice number, and the last paid amount in front of you. - If no pre-existing verified number is on file: STOP. Establish one via the signed contract or the vendor's published main line and a named contact, then restart. ON THE CALL "Hi, this is [name] in accounts payable at [company]. We received a request to change your [bank details / remittance address / payment email]. Before we make any change we confirm it by phone with the number we have on file. Can I speak with [named contact from the vendor master]?" 1. "Can you confirm you — or someone at your company — sent a request on [date] to change [field]?" 2. "I'm going to read the new details back. Please confirm each one." (Read every digit. Do not accept 'yes, that's right' to a summary.) 3. "For verification, can you tell me the invoice number and amount of the last payment we sent you?" (Compare to the record. A mismatch ends the call and the change.) 4. "Who at your company authorized this change, and what is their role?" 5. "We'll apply this after a second internal approval. Your next payment will go to the new details on or after [date]. If that's not what you expect, call us back on our main number." RED FLAGS — stop and escalate if any appear - The contact asks you to call a different number or says the number on file is outdated - Urgency, secrecy, or 'the CFO already approved this' - The contact does not know the last invoice details - The request came by phone and the voice is being offered as the proof LOG: caller, number dialed, time, each answer, match/no-match, recording reference.
change_id | auto vendor_id | vendor master id requested_at | ISO timestamp request_channel | email | portal | phone | letter request_artifact_ref | REQUIRED — stored copy of the email / recording / document requester_claimed_identity | name and title as claimed fields_changing | REQUIRED — e.g. bank_account, routing, remittance_address, payment_email old_values | REQUIRED — from the vendor master BEFORE the request new_values | REQUIRED — exactly as requested vendor_tenure_months | agent-computed trailing_12m_paid | agent-computed urgency_or_secrecy_language | yes | no (agent-flagged, human-confirmed) callback_number_source | REQUIRED — vendor_master_pre_request | contract | published_main_line callback_number | REQUIRED callback_by | REQUIRED — named AP employee callback_at | REQUIRED callback_contact_reached | REQUIRED — name and role last_invoice_check | REQUIRED — match | mismatch callback_result | REQUIRED — confirmed | denied | unreachable | mismatch callback_recording_ref | where lawfully recorded threshold_exceeded | yes | no second_approver | REQUIRED if threshold_exceeded — Slack user id second_approval_at | REQUIRED if threshold_exceeded second_approval_message_ref | Slack permalink applied_at | set by the agent only when all REQUIRED fields are complete and callback_result = confirmed applied_by | system | named employee first_payment_review_by | REQUIRED — named employee who eyeballed the first payment after the change RETENTION: keep for seven years. A fraud investigation or an auditor will ask for exactly this.
1. SCOPE. Any change to bank account, routing number, payee name, remittance address, payment method, or payment email for an existing vendor; any new vendor; any request to expedite or redirect a scheduled payment. 2. NO CHANGE WITHOUT CALLBACK. Every in-scope change is confirmed by a phone call placed by AP to a number recorded in the vendor master before the request arrived. Numbers supplied in the request, in an email signature, or by the caller are never used for verification. 3. NO SINGLE APPROVER ABOVE THE THRESHOLD. Changes affecting vendors with trailing-12-month payments above $[THRESHOLD], or any single scheduled payment above $[THRESHOLD], require a second approver recorded in Slack with the verification record attached. Email and phone approvals do not count. 4. VOICE IS NOT EVIDENCE. A phone call or voicemail that sounds like an executive or a vendor contact is treated as an unverified request. Executive instructions to move money are confirmed in Slack or in person with that executive, never by calling back the number that called us. 5. URGENCY IS A FLAG, NOT A REASON. Requests citing deadlines, confidentiality, or prior approval by someone unavailable are escalated to the controller before any other step. 6. AGENTS PREPARE, HUMANS DECIDE. The AI agent parses requests, prepares the diff and the callback script, and checks the evidence record. It has no authority to approve or apply a change and no write access to the vendor master until the record is complete. 7. FIRST PAYMENT REVIEW. The first payment after any change is reviewed by a named person regardless of amount. 8. DRILLS. Quarterly simulated change requests, including at least one by phone. Results reviewed with the team. Owner: [Controller] Review date: [quarterly]
Get a new AI workflow every week. Prompts, tool stacks, and ROI math included.
AI does the categorization or first-draft work, a human approves before action is taken. The pattern of choice for anything irreversible, externally visible, or financially sensitive.
Learn the agentic glossary →Where this workflow tends to break in production — and what to put in place before you ship it.
Callback placed to the phone number supplied in the fraudulent request
Mitigation: Script and record require callback_number_source from the pre-request vendor master, contract, or published main line; the agent pre-fills the stored number and flags any other.
Cloned executive voice approves an urgent wire by phone
Mitigation: Policy states voice is not evidence; executive instructions confirmed in Slack or in person; urgency language escalates to the controller.
Agent is manipulated by instructions embedded in the change request
Mitigation: Agent has no approval authority and no write access until the evidence record is complete; a human performs the callback and the approval.
Control is bypassed under deadline pressure
Mitigation: AP platform workflow state blocks saving a change outside the verification path; quarterly drills measure whether the control held.
Evidence record incomplete when an investigator asks
Mitigation: Required fields enforced before apply; seven-year retention; first-payment review recorded by name.
Do not deploy this as a throughput or automation win — it adds a step to every change on purpose, and if your team experiences it as friction to be routed around, the control is already failing. Skip the agent and run the control manually if you process fewer than a handful of vendor changes a month; the policy and the callback are what protect you, and a spreadsheet log is enough at that volume. Never let the model approve, apply, or waive a step, no matter how clean the diff looks — the attacker is writing the input it reads. And do not let a convincing voice on a callback stand in for the number-on-file rule; the callback protects you only because you chose the number, and voice cloning is now explicitly part of the pattern the FBI describes.
A phased approach to get this workflow running and delivering ROI.
Days 1–30
Foundation
Days 31–60
Optimization
Days 61–90
Scale
Both now ship AI agents that categorize and reconcile. The feature gap is smaller than the price gap, and the price gap is mostly about one thing nobody mentions: user seats.
Three of these four have a $0 tier and none of them are free. The money is in your card spend, and once you see how each one collects it, the choice gets simple.
One of these lets other people book you. The other two defend your calendar from the work you already agreed to. Buying the first when you needed the second is the most common mistake in this category.
One practical AI workflow per week. No fluff.
Get the full guide with step-by-step setup, workflow templates, and copy-paste assets.