# Payment Safety on a First Order From China | Cheery

> Most payment losses in cross-border sourcing are instructions nobody verified. The four checks that stop them, and the one that gets skipped.

Source: https://luressource.com/insights/payment-safety-first-order-from-china/

Direct answer. Payment safety is four separate checks, not one - who the beneficiary is, whether the instruction is genuine, whether the funds actually arrived, and who inside the company is authorised to release the goods. Losses usually happen because two of the four were treated as one. The rule that prevents most of them is a callback on a known number, never a number supplied in the message that asked for the change. Key facts. 1) A bank detail change is the single most common opening move in business email compromise. 2) Replying to the same email thread, or confirming in the same chat account, is not independent verification. 3) A payment screenshot is a claim, not a receipt; finance checks the platform or bank record. 4) Entity mismatch between the contract, the platform account and the beneficiary is a stop condition, not a formality. Frequently asked questions. Q: Is it safe to pay a Chinese supplier by bank transfer? A: It is common and it can be safe, provided the three names match - the contracting entity, the platform or store account, and the bank beneficiary. Where those three diverge, stop and ask why in writing. The risk is rarely the payment method; it is an instruction that was never verified against an independent source. Q: The supplier emailed new bank details. What should I do? A: Verify by calling a number you already had, from before the change, or one you found through an independent channel. Do not use the number in the email. A reply in the same thread is not verification, because if the mailbox is compromised the reply goes to the same person who sent the change. Q: The supplier sent a payment screenshot. Can we ship? A: Not on the strength of the screenshot. Screenshots are easy to produce and easy to edit, and they show a moment rather than a settled balance. Finance should confirm the amount, currency and order against the actual bank or platform record before goods are released. Q: How do I check that the company I am paying actually exists? A: Match the legal name on the contract against an official register, then match the bank beneficiary against that same legal name. A trading name, a store name and a bank account name are three different things, and the mismatch between them is exactly where a payment goes wrong. Q: What if we have already sent money to the wrong account? A: Treat it as an incident with a clock on it. Contact your own bank and the receiving institution immediately, keep every message and timestamp, and report it. Recovery depends on how fast the receiving bank acts and whether the funds have moved on, so there is no reliable promise anyone can make about getting it back. Sources (9). 1) Guidance on business email compromise and payment instruction fraud - FBI — https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise 2) Incoterms rules and where risk transfers - International Chamber of Commerce — https://iccwbo.org/business-solutions/incoterms-rules/ 3) The four verification gates we apply to supplier records — /verification/ 4) Our editorial rules on what this column will not publish — /opportunities/editorial-rules/ 5) Chinese business registration lookup — National Enterprise Credit Information Publicity System — https://www.gsxt.gov.cn/ 6) Incoterms rules — FOB, EXW and who carries cost and risk — https://iccwbo.org/business-solutions/incoterms-rules/ 7) ISO standards catalogue — quality and testing frameworks — https://www.iso.org/ 8) EU data protection rules this notice follows — European Commission — https://commission.europa.eu/law/law-topic/data-protection_en 9) China Customs (GACC) — the authority behind export records — http://www.customs.gov.cn/ Almost every cross-border payment loss we hear about has the same shape. The money went where somebody was told to send it, by a message that looked exactly like the last twenty messages. The failure was not the bank and not the platform. It was that one instruction was never checked against a second source. This page sets out the four checks that make up payment safety, in the order they matter, and the one that gets skipped because it is slightly awkward to do. The four checks Check The question Who should own it Identity Is the beneficiary the same legal entity that signed the contract and holds the platform account? Whoever signs the contract Instruction Did this payment request come through a channel we verified independently? Whoever receives the message, escalated to finance Funds Has the money actually settled, in the amount and currency expected, against this order? Finance, against the real record Authorisation Who is allowed to release the goods, and have they? Named in the contract, not assumed Most organisations do two of these well. The identity check is usually done once at onboarding and then never again, the funds check is often replaced by a screenshot, and the authorisation check frequently does not exist at all until somebody asks who approved a release. The callback rule If a supplier asks to change bank details — and it happens for legitimate reasons, a new account, a restructured entity, a different receiving bank — the verification has to come from a channel that the request itself cannot reach. In practice that means calling a number you already held, or one you found through an independent route such as the company register or the platform's own contact record. It does not mean replying to the email. It does not mean asking in the same chat thread. Both of those travel through the same compromised channel as the request, which is precisely the weakness. The pattern has a name. Business email compromise works by inserting a plausible instruction into a real conversation, and it succeeds because the conversation is genuine — the order number, the contact name and the tone are all correct. The FBI's guidance on business email compromise treats independent verification of payment and account changes as the core control, and that is the right shape of defence: not suspicion of the counterparty, but a rule that applies to every change without exception. Two habits make the rule survivable. Keep a written record of who called whom, on which number, when, and what was confirmed. And state the rule in the contract, so that a supplier who expects it will not treat the callback as an insult. Three names that have to match Before the first payment, put three names side by side: The legal entity on the contract or sales agreement. The account holder on the platform store or order. The beneficiary on the bank instruction. They should describe the same company. Where they do not, the gap is usually explainable — a group with several subsidiaries, a trading arm, a Hong Kong receiving entity — but explainable is not the same as verified, and the explanation should arrive in writing with a document that supports it. A register lookup through an official channel such as the National Enterprise Credit Information Publicity System will tell you whether the entity exists and what it is registered to do; it will not tell you that the bank account belongs to it. Both checks are needed. Requests to route a payment to a third party, to a personal account, or outside the platform that hosts the order are stop conditions rather than judgement calls. So is urgency: a message that manufactures a deadline is doing so because a deadline prevents verification. Screenshots, and what finance actually checks A payment screenshot is a claim about a moment. It can be edited, it can be taken before a transfer is reversed, and it can show a pending state that never settles. It is a useful signal that the buyer has acted. It is not evidence that funds arrived. What counts is the record: on a platform order, the order's own payment status; on a bank transfer, the receiving account's actual credit, matched on amount, currency and reference. Someone inside the buying company should own that check and record the date it was done, because it is also the trigger for releasing goods. The same discipline applies in reverse. If you are the buyer, expect your supplier to confirm receipt from their bank rather than from your screenshot, and treat a supplier who ships on a screenshot as one with a loose process — which is worth knowing before the order where it matters. Refunds and the alternative-account trick Refund requests are a second front. The safe sequence is to tie the refund to the original order and the original payment, confirm the identity of the person asking, and route it back through the channel the money came from. Requests to send a refund to a different account are the same shape of risk as a bank detail change, and they should trigger the same pause. A refund that cannot be traced to an original payment is not a refund, it is a new payment with a story attached. If something has already gone wrong Speed matters more than analysis. Contact your own bank and ask them to contact the receiving institution. Keep every message, header and timestamp. Notify whoever inside the company owns finance and security, and if the amount is material, report it to the relevant authority in your jurisdiction. What nobody can offer is a reliable promise of recovery. Whether funds come back depends on how quickly the receiving bank acts and whether the money has already moved, which is why the four checks exist in the first place. What to write into the agreement Three sentences cover most of it, and they cost nothing to add: Bank details will only be changed by written notice, and any change will be verified by a callback to a previously known contact before payment. Payment is confirmed by the receiving party's bank or by the platform order record, not by a payment screenshot. The contracting entity, the platform account and the bank beneficiary are the same entity, and any difference is documented before the first payment. None of this is unusual, and a supplier who has traded for a while will have seen it before. The awkwardness of the first callback is a small price for not having to test whether recovery is possible. Related reading: what a QC record should contain , the four verification gates , and FOB for where risk transfers once the goods move. Frequently asked questions Is it safe to pay a Chinese supplier by bank transfer? It is common and it can be safe, provided the three names match - the contracting entity, the platform or store account, and the bank beneficiary. Where those three diverge, stop and ask why in writing. The risk is rarely the payment method; it is an instruction that was never verified against an independent source. The supplier emailed new bank details. What should I do? Verify by calling a number you already had, from before the change, or one you found through an independent channel. Do not use the number in the email. A reply in the same thread is not verification, because if the mailbox is compromised the reply goes to the same person who sent the change. The supplier sent a payment screenshot. Can we ship? Not on the strength of the screenshot. Screenshots are easy to produce and easy to edit, and they show a moment rather than a settled balance. Finance should confirm the amount, currency and order against the actual bank or platform record before goods are released. How do I check that the company I am paying actually exists? Match the legal name on the contract against an official register, then match the bank beneficiary against that same legal name. A trading name, a store name and a bank account name are three different things, and the mismatch between them is exactly where a payment goes wrong. What if we have already sent money to the wrong account? Treat it as an incident with a clock on it. Contact your own bank and the receiving institution immediately, keep every message and timestamp, and report it. Recovery depends on how fast the receiving bank acts and whether the funds have moved on, so there is no reliable promise anyone can make about getting it back.
