Setup
Subcontractors and bank details
Subcontractors need RCT filing; suppliers do not. Both need bank details, and where those come from is the single most security-sensitive thing in the product.
On this page
Subcontractors and suppliers
Suppliers are not in the interface at present
Everyone recorded is treated as a subcontractor. The distinction below is real and still decides whether RCT applies — it is simply not something you set at the moment.
A subcontractor carries out construction work for you and is within RCT. A supplier sells you goods or non-construction services and is outside it entirely.
| Subcontractor | Supplier | |
|---|---|---|
| Does construction work for you | Yes | No — sells you goods or non-construction services |
| RCT filing | Contract notification, then a payment notification before every payment | None |
| VAT on their invoice | None — reverse charged | Charged normally |
| Cost recorded | The full invoice amount | The amount excluding VAT |
Some are genuinely both — a merchant who also sends a crew to fit what they sold you. Marking both is correct, and the treatment is decided per invoice rather than per company.
What to record
- Name and tax reference number. For subcontractors the reference matters a great deal: without one, Revenue has nobody to look up and authorises every payment at 35%. See How RCT works.
- Address and contact details. Required on the contract notification.
- Bank details. IBAN, and BIC if you have it. Read the rest of this page before entering one.
Why bank details are handled separately
The realistic threat to a building company is not someone breaking into Brickie. It is an invoice that looks entirely normal, from a subcontractor you really do use, for work that was really done, with a bank account that is not theirs.
Convincing fake invoices used to take effort. They no longer do. The delivery mechanism is your own accounts process working exactly as intended, which is why the defence has to sit in the process rather than in noticing.
The rule Brickie enforces
An IBAN on an invoice is treated as a claim, never as an instruction. It is compared against the bank details held on the subcontractor record and never flows into a payment file. If they match, nothing happens. If they differ, the payment stops.
So the subcontractor record is the only route by which bank details reach a payment, and it should be populated from something you can trust — a signed onboarding form, or a phone call to a number you already had before the invoice arrived.
Changing an IBAN
Changes are sorted into three levels of scrutiny, based on how much risk the change carries rather than how much it inconveniences you.
| Level | When | What is required |
|---|---|---|
| Green | First bank details for a subcontractor never yet paid | Recorded and allowed. There is no previous account for an attacker to divert from. |
| Amber | A subcontractor who has been dormant for a long time, or other lower-risk changes | Verification, and the change is recorded with who made it and when. |
| Red | Changing the account of a subcontractor you actively pay | Verification, a recorded callback, and a waiting period before the new account can be paid. |
Until a change completes, payments to that subcontractor are blocked rather than paid to the old account. A payment held up is recoverable; a payment sent to a fraudster is generally not.
The callback
For a red change, Brickie asks you to confirm you rang the subcontractor, and on what number. This is the part people are tempted to skip, so it is worth being precise about what it does that nothing else can.
- 1
A verification code proves you approved it
It confirms the person making the change in Brickie is you. It says nothing about whether the subcontractor asked for it.
- 2
Only a callback proves they requested it
An attacker who sent the invoice can usually read the mailbox it was sent to. Confirming by replying to that email confirms it with the attacker.
- 3
On a number you already had
Not the number on the invoice, and not the one in the email asking for the change. Use the number from before the request existed.
What this is actually preventing
Invoice redirection fraud in construction typically lands in the tens of thousands, and the money is gone within hours. Brickie cannot stop you approving a fraudulent change — it can only make skipping the check a deliberate, recorded act rather than something that happened by omission on a busy Friday.
The waiting period
After a red change is approved, the new account is not immediately payable. Larger companies get this protection from having two people involved; a one-person office cannot, so time substitutes for the second pair of eyes. The delay gives the real subcontractor a window to notice they have not been paid and ring you.
Where your company has a second user, a second approver replaces the wait — an actual second pair of eyes is better than a delay, and faster.