Contact: Email notification - Notify all users or nominated users when supplier bank account changes.
Ability to have email notification to all users/nominated users when supplier bank account changes.
Purpose: So all people in Xero orgs will immediately know if there’s any unusual activity in supplier bank account detail.
-
Elaine Farrell commented
Adding my agreement, that this should be standard.
Everyone needs this level of control in 2023.
-
Jack Moore commented
As part of our organisation's security and compliance measures, we need to ensure an extra layer of protection when it comes to bank account changes. To enhance the security of our financial transactions, we urgently request the implementation of an independent email notification system.
Specifically, we need Xero to send an automated and independent email to our designated senior manager whenever a bank account change request is initiated or processed through the platform. This additional notification will serve as a crucial safeguard against any unauthorised or fraudulent activity related to our finances.
Extremely disappointing that a platform like Xero already does not have this feature and that customers have to request it. This “idea” was raised in March 2022, it is now August 2023. One would think this is an easy feature to include. All other systems I have used have this “feature” already built in.
Why do we need to vote? This is a compliance issue, not a nice to have. -
Tara Osborn commented
Essential for audit purposes! Thank you
-
Penny Brown commented
Xero Admin Team - do you have an ETA on this IDEA!!!!!
-
Tara Osborn commented
required for our audit purposes
-
Kyle Stutter commented
Agree
-
Tacia Strawbridge commented
This is an important and simple governance feature against fraud and should be considered as a priority.
-
Rachel Armishaw commented
I'm very concerned that this is not already a feature. I have previously been an MYOB user where this is standard. This leaves payees in the system very vulnerable to having their bank account details changed and those approving payments not being alerted. Please let me know if you are going to consider this as an update.
-
Ann-Marie Tulloch commented
A must for financial controls in a business. As Finance Director for a £20m turnover business I need to know if one of my finance team members changes a bank account. We use bulk uploads to the bank so there's little other opportunity to pick up changes without trawling through the assurance dashboard, which cannot be filtered by date to focus on one financial year at a time.
Critical that a bank account change notification is sent to nominated individuals, not all bank admin as this can include and involve far too many people in the finance team with unnecessary email traffic.
Critical that the assurance dash board can be filtered by date or financial year. I don't need to see assurance for events that happened years ago.
-
Michelle Gradwell commented
This isn't already happening, how insecure is this!. Yes get this done asap.
-
Penny Brown commented
Get this done ASAP! For an accounting software product not to have this already implemented is beyond me. Worked in many accounting products and this was never an "idea" I had to ever vote on. Accounting 101...
-
Ian McIntosh commented
Update - my new work around is to add an email rule at the Office 365 - Exchange Admin level. That way any email from Xero re a Bank Account change comes direct to me. If you use a bookkeeper that logs in with their own email I suggest you make them login with an email that you control.
The above only covers Contacts that have existing bank details changed.
As you don't get emails when new or existing Contacts have bank details added for the first time you really need to run the "History and Notes" screen report. (Accounting menu --> Advanced --> History and notes). In the Item section select "Contact", then search (Ctrl + F) for "bank" and you'll be able to locate all bank account changes with a link to the Contact that was changed.
-
Accounts NPS commented
notify the person changed the bank account is useless if this is meant to prevent hacking and stealing
-
Ian McIntosh commented
It's a no brainer way to protect businesses. Currently notifying the person who changes the bank details is like telling a burglar you've successfully set yourself up to burgle a house. The notification MUST go to another Admin. In my analogy, the homeowner, so they can take precautions.
I lost almost $2K to this issue as a below average bookkeeper changed a contact's bank details to another supplier's bank details. The bookkeeper was notified but I wasn't. Unfortunately, the recipient of the funds spent the money before we found out and we could only claim about $200 back from them after 12 months and a lot of trouble. We're a not for profit and the auditor was shocked by this weakness in Xero.
My work around now is to use an email rule in the staff member's Outlook program that auto forwards the Xero bank account change email to me. This isn't foolproof though.
Please safe guard businesses by having the supplier bank account change email go to both the user and the nominated admin(s). It just commonsense.
-
Nick Katris commented
this is really important with phishing attacks being so prevalent
-
Shannon Toomey commented
This would be a great feature to add to help try and stop fraud
-
Flora van der Meer commented
Not sure why this feature is not already available. Would be a massive help to prevent fraud.
-
Stephen Martin commented
I receive notifications when a payroll account is changed by our bookkeeper so I am dumfounded that the same practice can't be implemented for changes to contact bank accounts. As a chartered accountant I can tell you this is a massive hole in Fraud prevention and needs rectified ASAP.
-
Ann O'Sullivan commented
We have the same concern, what we need is if anyone else, other than our master administrator, changes the bank account details or adds a new supplier, they will be notified of the change not the person who made the change. This needs to be addressed to prevent the possibility of any fraudulent activity. Our auditors want to know how we are addressing this!
-
Graeme Teasdale commented
We recently have had a case of fraud against us by the fact that Xero does not notify other users with credentials to changes in bank account details of suppliers.
As Shaun Walker has advised below, a note or some other notification regarding bank account change is a critical feature to minimise impropriety. Personally I would like to be able to assign to Advisors that they are notified when bank account details are changed to confirm that the change is correct
If, as in our situation, a person who has the security credentials to change bank details, is the only person notified of the change, how does Xero allow the appropriate oversight to ensure that this doesn't happen? It can't.
Under the current system it relies on a individual to go through each individual payment and cross check bank account details, that is exhaustive when batch payments get longer and longer