This takes a few days and several people. That is on purpose, and this
page explains why so the delay does not surprise you.
The commonest way organisations like ours lose money is not a stolen
password or a hacked website. It is an email, apparently from a supplier,
saying the bank account has changed.
It is convincing. It usually comes from the supplier's real email address,
because that address has been broken into. By the time anybody notices, a
payment has gone.
So we treat a change of bank details as the highest risk thing a supplier
can ask us to do.
We will. Use a number you already had for us, not one in an email asking
for the change. If somebody is trying this on, the number in their email
reaches them.
If the bank tells us the account is in a different name, we stop. We do
not retry and we do not ask you to confirm by email. Somebody looks at it.
A real account in the wrong name is what a diversion attempt looks like.
If it is an innocent mismatch, a phone call sorts it out quickly.
You cannot have two changes in progress. Two parallel requests over one
account is exactly the confusion somebody trying this would want.
They are kept. Any payment already being prepared stays pointed at the old
account until a person decides otherwise. We never silently redirect money
that is already on its way.