1. Scope

This is a controls note. It is not legal advice, not a fraud-prevention product review, and not a claim that any product satisfies any regulation. It takes no position on whether accounts payable should be automated. The distinction held throughout is the same one used in the companion note on customer due diligence: a record is something a system writes about itself; evidence is a contemporaneous record that a party outside the operating system can verify without trusting it.

2. The Control That Predates the Technology

Payment redirection, also called invoice fraud or business email compromise, is the fraud this order rule exists to stop. A criminal impersonates a supplier, or takes over its email, and tells the business that pays it that the supplier's bank details have changed. Australia's cyber security agency describes the common form directly: attackers compromise a vendor's email account, "edit contact and bank details on those invoices and send them to customers with the compromised email account. The customer pays the invoice, thinking they are paying the vendor" [1].

It is not a marginal problem. Australians reported losing $166.8 million to payment re-direction scams in 2025, the second-largest scam type by loss after investment scams [3].

The guidance is consistent across agencies, and it is a rule about order. The Australian Signals Directorate's first business-process recommendation is to "establish a clear and consistent business process to verify requests involving payments, account changes and sensitive information", and it lists "an unexpected change of bank details" among the warning signs [1]. New Zealand's National Cyber Security Centre is blunter: "If the email or invoice requests a change to the payment information, such as bank account details, you should be suspicious immediately. Verify the change via publicly available contact details, do not reply to the email" [2]. And it records who carries the loss when that step is skipped: "you may still owe money to the real vendor" [2].

Every one of those instructions has the same shape. The verification is not valuable because it happened. It is valuable because it happened before the payment. A call-back made after the money has left is a fraud report, not a control.

3. The Three Sequences

Accounts payable work decomposes into three sequences where order is the control. Each is written below as a declared order: the steps, in the sequence they must be permitted, named as they would be in an enforcement call.

Supplier onboarding

supplier_details_received → registry_check → ownership_check → sanctions_check → bank_account_confirmed → supplier_approved → supplier_activated

The rule that matters: no supplier is active, and so no supplier can be paid, until its registration, its owners, its sanctions status and its bank account have each been checked. Approval sits after the checks, not alongside them, and is given by someone other than the person who requested the supplier (see segregation of duties).

Change of bank details

change_request_received → independent_callback → second_approval → bank_details_updated → first_payment_released

The rule that matters: the new account is confirmed through a channel the requester does not control, using contact details the business already held, before the record is changed and before any money is sent to it [1][2]. This is the sequence payment redirection attacks.

Invoice to payment

invoice_received → po_and_receipt_matched → supplier_status_confirmed → payment_approved → payment_released → payment_recorded

The rule that matters: an invoice is matched to what was ordered and what was received, and the supplier is confirmed as active with verified bank details, before the payment is approved and released.

4. The Failure Shape — the agent pays, and reports on itself

Handed to an autonomous agent with access to email, the supplier master record and the payment system, each step above becomes a tool call the agent selects and issues. Three properties of that arrangement matter for evidence.

The result is a business that may well have followed its process and cannot prove the part that mattered: that the verification came first.

5. Who Carries the Loss, and Who Carries the Duty

The business that pays carries the loss. New Zealand's guidance, written for individuals and businesses alike, is explicit that whoever pays a scammer instead of the real vendor "may still owe money to the real vendor" [2]. The ordering failure is the payer's, and so is the bill.

In Australia, banks now carry a duty as well. The Scams Prevention Framework Act 2025 inserted a framework into the Competition and Consumer Act 2010 under which a regulated entity contravenes a civil penalty provision if it "fails to take reasonable steps to prevent another person from committing a scam relating to, connected with, or using a regulated service of the entity" (s 58BJ), and must document and implement governance policies and procedures that are "reviewed, and certified by a senior officer of the entity, at least annually" (s 58BC) [4]. The people it protects include small businesses: a small business operator is one with fewer than 100 employees and annual turnover under $10 million (s 58AH and definitions) [4]. Which sectors are regulated, and from when, is set by designation rather than in the Act.

The duty and the loss land in different places, and neither lands on the agent. That is the point of an independent record: it serves whichever party has to show what happened.

6. The Instrument, and a Test Anyone Can Run

What closes the gap in §4 is not better logging. It is a separate component that holds the declared order, refuses a step attempted out of that order, and produces a signed record of the refusal as well as of the permission — so that a payment attempted before its verification becomes a positive artifact rather than a silence.

The order is declared by the business, not by the agent. An order the agent declares for itself can leave out the call-back, and the record would then faithfully show a shorter process. The order belongs in the integration code or the deployment configuration, set by the people accountable for the payment process. Once the first step of a sequence is permitted, its order is locked: a later call cannot shorten it to skip a step.

Each step is submitted for a verdict before it runs. A step out of order is denied, and the denial is signed and chained. The sequence is sealed at its final step. Each receipt is signed with Ed25519 and carries the exact byte string that was signed, so it can be verified offline against a published public key by a party who does not trust the operator. The verification report shows the declared order and which of its steps were permitted, so an accounts payable lead or an auditor can read, step by step, whether the verification came before the payment.

This is testable without an agreement or an account. The public verification endpoint is at report.agenticrail.nz/report, and the enforcement rules, denial codes and receipt schema are published at agenticrail.nz/spec/ [5].

7. A Deliberate Boundary — what this does not do

8. Questions

What is payment redirection fraud?

Payment redirection, also called invoice fraud or business email compromise, is when a criminal impersonates a supplier, or takes over its email, and tells the business that pays it that the supplier's bank details have changed. The next payment goes to the criminal's account. Australia's cyber security agency describes the common form: the attacker edits the bank details on a legitimate invoice and sends it from the compromised account, and the customer pays it believing it is paying the supplier. Australians reported losing $166.8 million to payment re-direction scams in 2025, the second-largest scam type by loss.

How do you stop an AI agent paying an invoice before a change of bank details has been verified?

Declare the order before the agent starts, and check every step against it before the step runs. If the declared order puts an independent verification of the new bank details before the first payment to them, a payment attempted first is refused, and the refusal is itself recorded and signed. The agent can still be wrong about everything inside a step. What it cannot do is reach the payment step without the verification step having been permitted first, and the attempt to do so leaves a record rather than a silence.

Who should declare the order, the business or the agent?

The business. An order the agent declares for itself can leave out the step that matters, and the record would then faithfully show a shorter process. The order should be set in the integration code or the deployment configuration, by the people accountable for the payment process, never by the model at run time.

Does a sequence gate verify the bank account or screen the supplier?

No. It performs no checks and holds no supplier or bank data. It enforces that the verification steps were permitted before the payment step, and it records the decision at each step. Whether the call-back reached the real supplier, or whether the sanctions list was current, is a matter for the step itself.

9. References

  1. Australian Signals Directorate (cyber.gov.au), Protecting against business email compromise, published 23 October 2020, last reviewed 24 March 2023 — invoice fraud described; key action to "establish a clear and consistent business process to verify requests involving payments, account changes and sensitive information"; warning signs including "an unexpected change of bank details" and "requests to circumvent protective business processes". cyber.gov.au.
  2. National Cyber Security Centre (New Zealand), Own Your Online, Protect yourself from invoice scams — verify a change of payment details via publicly available contact details and do not reply to the email; a business that pays a scammer "may still owe money to the real vendor". ownyouronline.govt.nz.
  3. Australian Competition and Consumer Commission, Continued action critical to combat fraud as annual scam losses exceed $2 billion, media release, 30 March 2026, reporting the National Anti-Scam Centre's Targeting Scams Report for calendar year 2025 — payment re-direction scams $166.8 million, second of the top five scam types by loss. accc.gov.au.
  4. Scams Prevention Framework Act 2025 (Cth), No. 15, 2025, inserting Part IVF into the Competition and Consumer Act 2010 — s 58AH (meaning of SPF consumer), s 58BB (meaning of reasonable steps), s 58BC–58BD (governance, certified by a senior officer at least annually), s 58BJ (taking reasonable steps to prevent scams, civil penalty provision). legislation.gov.au.
  5. AgenticRail enforcement specification and receipt schema — agenticrail.nz/spec/.
Document type Controls Note — Evidence Brief
Subject Supplier onboarding, change of bank details and invoice payment where an autonomous agent performs the accounts payable work and also records that it performed it
Published by TUARA KURI LIMITED — trading as AgenticRail, Hokianga, Aotearoa New Zealand
Date 2026-10-07
Version 1.0
Status Published — open for citation
Related Customer due diligence · Know your business · Segregation of duties · Sequence verification