Finance change control

Stop the payment while the right owner checks the change.

Use this worksheet when a provider asks to change bank, remittance, or other payment instructions. Record the request, compare masked references, check it through a contact route saved before the message arrived, and send the decision to authorized finance staff.

This worksheet is a coordination record, not proof that a request is genuine and not authorization to update the provider record or release payment. An assistant may log the request, compare masked references, collect evidence references, and escalate it; authorized finance staff keep approval, controlled-field updates, payment-hold decisions, and payment release.

Do not put full account numbers, routing details, credentials, tax identifiers, identity documents, or sensitive evidence in this worksheet. Follow your company policy, agreement, bank controls, and incident process.

One reviewable trail

Keep the request, check, decision, and payment state separate.

A callback result is one piece of evidence, not automatic approval. The record should show who checked the request and who still controls the provider record and the money.

Payment-change record

Request and current record

Record the provider, requester, request channel, received time, and affected invoice or payment. Point to the current approved record and the requested change with masked references instead of copying full account values.

  • Provider and requester identity status
  • Original message or ticket reference
  • Current approved record and masked reference
  • Requested document and masked reference
Payment-change record

Hold and blocked actions

Show whether the payment and vendor-record change are on hold. Name the owner, the time the hold started, and the actions that stay blocked while the check is open.

  • Payment-hold state and owner
  • Vendor-record change state
  • Assistant intake actions completed
  • Approval, edit, test-payment, and release actions held
Payment-change record

Known contact check

Use a contact route saved before the change request arrived. Record where that contact came from, who completed the check, what was confirmed or disputed, and what remains unknown.

  • Approved contact source and version
  • Contact was not supplied in the request
  • Checker, method, time, and timezone
  • Confirmed, disputed, unavailable, or partial result
Payment-change record

Evidence and escalation

Keep sensitive documents in the approved restricted location and place only their references in this record. Name the finance, provider-management, or incident route when the request cannot be confirmed.

  • Original request and approved-record references
  • Callback or confirmation-note reference
  • Restricted evidence location and owner
  • Escalation reason, route, ticket, and next owner
Payment-change record

Finance decision and controlled update

Authorized finance staff record whether the request is approved, rejected, pending, or escalated. Keep the controlled-field update, any second review, and the payment decision separate from the intake record.

  • Authorized reviewer and decision reason
  • Required second approval
  • Authorized updater and audit reference
  • Payment-hold and release decision owner
Payment-change record

Closure and open work

Close the change request only after its decision, payment state, record location, and remaining work are clear. A related incident or corrective action can stay open under its own owner and reference.

  • Approved, rejected, withdrawn, or superseded outcome
  • Provider notification route and owner
  • Open incident or corrective action
  • Closure owner, time, and final record location
Fictional blocked request

The known contact disputed the email, so the change stayed blocked.

Northstar Demo and every reference below are fictional. The example shows a record structure, not a fraud finding or a response-time standard; on smaller screens, scroll the table horizontally to see every field.

Fictional payment-detail change record using masked references, a known contact, a payment hold, and separate finance and incident decisions.
Record fieldFictional entry
RequestNorthstar Demo asked by email to use new payment instructions for invoice ND-1048. The requester identity was not independently confirmed.
ReferencesApproved provider record dated 2026-02-12 ended in ••1842. The attached request ended in ••7719; no full account values were copied into the worksheet.
HoldThe payment stayed on hold and no vendor-record change was made. The assistant logged the request, compared masked references, and sent the record to finance.
Known contact checkAn authorized finance reviewer used the contact saved in the executed agreement. That contact disputed the request and did not recognize the named requester.
EscalationThe reviewer referenced the restricted email, agreement contact, and callback note, then opened a security review. The team did not use any phone number, reply address, or link from the disputed request.
DecisionFinance rejected the change pending a new request through the established provider route. The hold remained, no payment was released, and the security review stayed open under its own reference.

The disputed callback does not by itself prove fraud. It is enough to keep this request blocked, preserve the records, and use the approved finance and incident routes.

Copy-ready worksheet

Use safe references instead of copying bank details.

Keep bank documents, call recordings, identity records, and other sensitive evidence in the approved restricted location. Put only a masked value or secure internal reference in the worksheet.

PROVIDER PAYMENT-DETAIL CHANGE VERIFICATION RECORD

RECORD CONTROL
Record ID:
Record owner:
Created date, time, and timezone:
Current status: [New / Checking / Awaiting provider / Awaiting finance / Escalated / Approved / Rejected / Closed]
Restricted case or folder reference:

REQUEST
Provider approved record name and ID:
Received date, time, and timezone:
Request channel:
Original message or ticket reference:
Requester name and stated role:
Requester identity status: [Unconfirmed / Confirmed through approved process / Disputed]
Requested effective date:
Affected invoice, contract, payment, or service reference:
Reason stated for the change:

CURRENT AND REQUESTED DETAIL REFERENCES
Current approved record and date:
Current masked reference:
Requested document or secure-record reference:
Requested masked reference:
Fields reported as changed:
Full payment details kept out of this worksheet? [Yes / No]
Difference summary:

INITIAL HOLD AND INTAKE
Payment hold applied? [Yes / No / Not applicable]
Hold owner and time:
Vendor-record change blocked pending review? [Yes / No]
Assistant or intake owner:
Intake actions completed:
Actions held:
Finance reviewer notified at:
Incident route used? [Yes / No]
Route or ticket reference:

KNOWN CONTACT SOURCE
Approved contact source used:
Source record date or version:
Contact name and role:
Contact route:
Was this route supplied in the change request? [Yes / No]
If yes, stop and find an independently held source:
Person who selected the contact source:
Person who completed the check:
Check date, time, and timezone:
Check method:

CHECK RESULT
Result: [Confirmed / Partly confirmed / Disputed / No response / Approved contact unavailable]
What the known contact confirmed:
What the known contact disputed:
Important unknowns:
Follow-up requested:
Request remains blocked? [Yes / No]
Reason:

EVIDENCE AND ESCALATION
Original request reference:
Current approved record reference:
Requested-change document reference:
Callback or confirmation-note reference:
Approved secure evidence location:
Known evidence gaps:
Escalation reason:
Finance escalation owner:
Security or incident owner, if applicable:
Incident or case reference:
Action held while waiting:

FINANCE REVIEW AND CONTROLLED UPDATE
Authorized finance reviewer:
Decision: [Approve / Reject / Keep pending / Escalate]
Decision reason:
Required second approval, if any:
Approval record reference:
Authorized provider-record updater:
Update status: [Not approved / Pending / Completed / Reversed]
Update audit reference:
Update reviewed by and result:

PAYMENT DECISION
Payment remains on hold? [Yes / No]
Hold decision owner:
Payment may proceed under the normal approval process? [Yes / No]
Payment release decision owner:
Payment released? [Yes / No]
Payment reference and release time, if applicable:
Worksheet completion alone does not authorize payment.

CLOSURE
Request outcome: [Approved / Rejected / Withdrawn / Superseded / Closed with incident follow-up]
Provider notified through:
Open incident, corrective action, or follow-up:
Open-item owner and due date:
Closed by:
Closure date, time, and timezone:
Final restricted record location:

An assistant may receive the request, preserve its source, compare masked references, collect approved evidence references, update status, and escalate discrepancies. Authorized finance staff alone approve provider-record changes, decide whether a payment hold can be removed, and release payment.

Do not place full account numbers, routing details, credentials, tax identifiers, identity documents, call recordings, or other sensitive evidence in this worksheet. Store them only through the company's approved restricted process.

The full worksheet stays visible and selectable. Nothing is uploaded or saved.

Review flow

Move the record forward without moving the money.

Do not use the phone number, reply address, or link in the change request as the independent contact route. If an approved contact cannot be established, keep the change blocked and escalate it.

  1. Log the original request and apply the payment hold required by your existing process.
  2. Compare masked references with the current approved provider record without editing controlled fields.
  3. Choose a contact route from an approved source saved before the request, not from the change message.
  4. Record the check result, evidence references, and unknowns, then escalate disputed or incomplete requests.
  5. Let authorized finance staff record the decision, controlled update, payment state, and closure.
Official source notes

Use known channels and report suspicious requests.

These sources support the known-contact, phishing-reporting, access, and preparation steps. They do not certify this worksheet or replace your finance policy.

Before the next request

Review the finance handoff without sending payment details.

Bring the planned roles, held actions, contact source, and escalation route. Do not paste bank details, credentials, or a live payment request into the contact form.

Build your handoff system

Ready to plan your first offshore role?

Use OutsourcedU to write the role, SOPs, onboarding steps, and weekly review before you hire more people.