Compliance and Security Recommendations for Notifying Customers of Bank Account Changes
A company, due to a bank account change, plans to send a mass update notification to customers who previously paid via ACH. The article discusses how to convey new account information in the most secure way, including attachment encryption, BCC, and verifying customer identity.
Our company currently accepts customer invoice payments via ACH (Automated Clearing House). Recently, we changed our bank account, so we need to send a batch update notification to all customers who have previously paid via ACH, informing them to update our banking information promptly. Here, we would like to seek peer experience and discuss the safest and most effective notification format and delivery method. Our initial idea is to send the new account information as an attachment, with all customers placed in the BCC field to avoid exposing each other's email addresses.
Necessity of the Notification and Risk Considerations
Bank account changes involve sensitive financial information. If mishandled, they may lead to payment failures, fraud risks, or loss of customer trust. Therefore, the notification process must balance clear communication with information security. Based on industry practices, the following measures are recommended:
- Specify the Effective Date of the Change: State the specific date when the new account becomes active in the notification, and remind customers to stop making payments to the old account after that date.
- Provide Dual Verification Channels: In addition to email, confirm separately through the customer portal, phone, or account manager to prevent phishing emails from impersonating the company.
- Protect Attachments with Encryption: If using attachments, it is recommended to set a password on files such as PDFs and communicate the password through another channel (e.g., SMS or phone call) to reduce the risk of email interception.
- Avoid Listing Full Account Numbers Directly in the Email Body: You may only provide the account name and bank name, guiding customers to obtain complete information through a secure link or after verification with customer service.
Discussion on BCC and Attachment Usage
Using BCC (blind carbon copy) is a basic practice to protect customer privacy, preventing recipients from seeing each other's email addresses, and is worth recommending. However, relying solely on BCC does not completely eliminate security vulnerabilities—if attachments are forwarded or email accounts are compromised, sensitive information may be leaked. Therefore, we suggest:
- Set attachments to read-only or add watermarks, noting "For use by designated recipients only."
- Do not include any account numbers in the email body; simply state "New account information is in the attachment" and provide customer service contact details for verification.
- Consider using enterprise-grade file sharing services (such as encrypted links) instead of traditional attachments to track downloads and set access expiration.
Other Peer Experience References
Some companies have adopted a phased notification strategy, first sending personalized emails to high-volume customers with frequent transactions, then sending a unified notification to the rest, to reduce risks associated with a one-time mass send. Some companies also require customers to reply confirming receipt and update payment templates in their systems to ensure subsequent payments are accurate.
"We previously notified customers via encrypted PDF attachments and included a verification code in the email; customers had to call customer service to confirm their identity before receiving the password. Although the process was somewhat cumbersome, it effectively prevented fraud." — Anonymous Finance Manager
Final Recommendations and Action Checklist
In summary, the safest approach is:
- Draft a formal notification including the reason for the change (optional), the effective date, the date the old account will be deactivated, and customer service contact information.
- Create an encrypted PDF with the new account information, with the password sent separately via SMS or phone call.
- Send via BCC and include a note in the email: "Please do not reply directly to this email; contact your dedicated account manager if you have questions."
- Within one week after sending, proactively contact key customers to confirm whether they have updated, and monitor subsequent ACH payments for any failures or returns.
If your company has a small number of customers, you may also consider one-on-one phone notifications, but email remains a traceable formal record. Regardless of the method used, be sure to retain sending records and customer confirmation receipts for audit purposes.