Payment redirection fraud works the same way every time: an email that looks like it came from a provider says the bank details have changed, and the next payment run sends the money somewhere else. It is the single largest fraud risk a plan manager carries, and it is preventable with process.
Provider bank change verification — how it works
When a provider’s bank details change, that provider’s invoices go on hold and stay there until the new account is verified. Verification is recorded with the method — who was called, on which number, from which source that number came — and by whom, so the check is evidence rather than an assurance.
The same controls cover ABN status and registration. Payment batches carry their own approval, which can require a different person from the one who entered the invoices and can require two-factor authentication, so a single compromised account cannot both create and release a payment.
Why it matters for NDIS providers
A single successful redirection can exceed a year of plan-management fees for a participant, and the money is rarely recoverable. Auditors and insurers now expect documented controls, not intentions — and the documentation is what turns a control into a defence.
- Change triggers a hold: invoices for that provider stop until the new account is verified.
- Verification is evidence: the number called and where it came from are recorded, not just that a call happened.
- Release is separated: batch approval can require a different user and a second factor.
What's included
- Automatic hold on bank change. Any change to provider banking details holds their invoices.
- Recorded verification. Method, contact, source of the number, verifier and timestamp.
- ABN and registration checks. Provider ABN status and registration tested as part of validation.
- Segregation of duties. Payment approval can be required from a different user than invoice entry.
- Two-factor on payment. A second factor can be required before a batch is released.
Who it's for
Every plan manager who pays providers by bank transfer — which is all of them. It matters most to organisations that have grown past the point where one person recognises every provider by name, and to anyone who has been asked by an auditor, insurer or board to describe their payment controls.
Getting started
Bank Change & Fraud Controls is included in your Rostery plan and works the moment your data is in — there is no separate module to buy or set up. Book a demo and we will show it on your own workflows, and use Rostery's “Smart Switch” data migration to bring your existing clients, staff, shifts and notes across from your current software in minutes.
Terms used on this page
Related capabilities
Source
The rules this feature works to are set by NDIS — Pricing Arrangements and Price Limits, which is the authority on them and is updated more often than any page here.

