Contact - Notify all users or nominated users when supplier bank account changes.
Ability to have email notification to all users/nominated users when supplier bank account changes.
Purpose: So all people in Xero orgs will immediately know if there’s any unusual activity in supplier bank account detail.

Appreciate wanting an update from us here, everyone. We know that having more visibility of when a supplier’s bank account details change is important to you and understand that there are some security concerns around this. This is something our product teams are aware of the appetite for, however we want to be upfront that this feature is not planned in the near future.
While not a direct solution to what you’re asking here, it’s worth noting that the ability to change supplier’s bank account details is limited by the bank account admin permission. Advisors will have access to the Assurance dashboard where you’ll be able to get an easy view of any Contacts whose bank account details have been edited, and you can also view this information running the History and Notes report.
-
Accounts NPS commented
notify the person changed the bank account is useless if this is meant to prevent hacking and stealing
-
Ian McIntosh commented
It's a no brainer way to protect businesses. Currently notifying the person who changes the bank details is like telling a burglar you've successfully set yourself up to burgle a house. The notification MUST go to another Admin. In my analogy, the homeowner, so they can take precautions.
I lost almost $2K to this issue as a below average bookkeeper changed a contact's bank details to another supplier's bank details. The bookkeeper was notified but I wasn't. Unfortunately, the recipient of the funds spent the money before we found out and we could only claim about $200 back from them after 12 months and a lot of trouble. We're a not for profit and the auditor was shocked by this weakness in Xero.
My work around now is to use an email rule in the staff member's Outlook program that auto forwards the Xero bank account change email to me. This isn't foolproof though.
Please safe guard businesses by having the supplier bank account change email go to both the user and the nominated admin(s). It just commonsense.
-
Nick Katris commented
this is really important with phishing attacks being so prevalent
-
Shannon Toomey commented
This would be a great feature to add to help try and stop fraud
-
Flora van der Meer commented
Not sure why this feature is not already available. Would be a massive help to prevent fraud.
-
Stephen Martin commented
I receive notifications when a payroll account is changed by our bookkeeper so I am dumfounded that the same practice can't be implemented for changes to contact bank accounts. As a chartered accountant I can tell you this is a massive hole in Fraud prevention and needs rectified ASAP.
-
Ann O'Sullivan commented
We have the same concern, what we need is if anyone else, other than our master administrator, changes the bank account details or adds a new supplier, they will be notified of the change not the person who made the change. This needs to be addressed to prevent the possibility of any fraudulent activity. Our auditors want to know how we are addressing this!
-
Graeme Teasdale commented
We recently have had a case of fraud against us by the fact that Xero does not notify other users with credentials to changes in bank account details of suppliers.
As Shaun Walker has advised below, a note or some other notification regarding bank account change is a critical feature to minimise impropriety. Personally I would like to be able to assign to Advisors that they are notified when bank account details are changed to confirm that the change is correct
If, as in our situation, a person who has the security credentials to change bank details, is the only person notified of the change, how does Xero allow the appropriate oversight to ensure that this doesn't happen? It can't.
Under the current system it relies on a individual to go through each individual payment and cross check bank account details, that is exhaustive when batch payments get longer and longer
-
Shaun Walker commented
auditors would like to see this feature
when producing the batch payment report could there be a note (or '*') to identify a change to bank details since the previous payment run? This would allow payment authorisers to validate the new bank account