General Contractor

  • 1.  ACH Payments to Vendors

    Posted 16 days ago

    We are currently processing ACH payments to vendors thru our software ECMS.  Our concern is when setting up the ACH information if the information is correct.  Just wanting to see what safeguards are being taken to ensure the information is correct.  We have seen so much fraud lately there should be a way to double check the information that is provided   Any suggestion would be greatly appreciated.  



    ------------------------------
    Mary Miller
    Sun Builders Co.
    Houston TX
    (281) 815-1020
    ------------------------------


  • 2.  RE: ACH Payments to Vendors

    Posted 8 days ago

    Mary,

    I am seeing more man-in-the-middle attacks (cyber). Make your you sit down with your broker and review your safeguards. A recent attack robbed a hard-working company of $128,000.

    John Hubbard, CRIS



    ------------------------------
    John Hubbard
    Broker
    USI Insurance Services
    IRVINE CA
    (714) 240-9085
    ------------------------------



  • 3.  RE: ACH Payments to Vendors

    Posted 7 days ago

    Hi Mary -

    I am not that familiar with eCMS, but this is something that a lot of contractors are worried about these days.  We had a client not too long ago that had a $250k check sent to a fraudulently changed account after a vendor of theirs got "hacked" via social engineering.

    I'll describe what we're building for clients who are on Trimble ERPs (Spectrum + Vista), but the overall thought process here could be applied anywhere.  I'm sure you have an eCMS expert you work with that can assist if you (or anyone else) would want to go down this path.

    At a high level, we're adding an audit process using Trimble's integration platform AppXchange, because it's secured from the normal AP users.  AP does ACH updates for Vendors etc. using their existing internal process, which includes whatever verifications you have in place today.  The technical part is that we then scrape all bank/ACH/EFT related changes and secure send those to a separate repository and then automatically email the Controller/CFO/Compliance/whoever needs to be notified as a secondary check that someone's bank details have changed.  

    The key is that there is no way for a run of the mill AP clerk or back office employee to get at that secondary repository and automation to disable it or override it there.  It adds a secure way for a second or even third level validation that the change was:

    1. Intentional
    2. Properly documented

    Again, we are not an eCMS shop but the above process could be replicated for any accounting/ERP system by your trusted technology partner.  The mechanics of it would change, but the theory is applicable to everyone.  



    ------------------------------
    Chris Lounsbury
    Director of Development & Data Architecture
    Business Information Group, Inc.
    Sherwood OR
    (717) 659-2737
    ------------------------------