Business banking security: organise access and prevent payment fraud

Organise company payments, user permissions and records, then establish practical checks for account access, beneficiary changes and suspicious activity.

  • 3 min read
  • Last updated:
  • Exporya editorial team

Define the account’s operating purpose

List the transactions the account should support: customer invoices, supplier payments, operating expenses and taxes relevant to the activity. Distinguish them from personal spending, and give each transaction a reference linked to evidence. Clear records make an unusual payment easier to recognise before it becomes a repeated operating problem.

Test statement downloads and invoice reconciliation, then schedule a regular review. Checking the balance is not the same as checking transactions. A plausible closing balance can conceal a duplicated payment, an unexplained charge or money sent to the wrong beneficiary. Record corrections so the same question is not rediscovered every month.

Allocate permissions instead of sharing credentials

Where the provider supports multiple users, assign access according to each person’s job. Entering an invoice does not necessarily require changing account settings or executing a transfer. Establish who can create beneficiaries and who approves payments, using arrangements proportionate to the size and transaction volume of the business.

Keep a current user and device list, and review it when roles change or somebody leaves. Do not rely on an agreement that a former employee will stop using a shared password. Revoke access in the system, examine connected applications and maintain the contact details used for account recovery.

Protect login and recovery channels

Use a strong, unique password and an additional authentication method supported by the provider. Protect the company email receiving banking notifications as well, since control of that mailbox may assist an attacker seeking account access. Store recovery information securely without making it available to everyone who handles routine company payments.

Keep devices and browsers updated and install the provider’s application from its official source. Avoid making transfers on shared devices you cannot supervise. Treat these practices as continuing operations: decide who maintains updates and what the business will do if the authentication phone is lost or its contact number changes.

Verify requests before moving money

A request to change a familiar supplier’s bank details can appear convincing because it includes their name and a genuine invoice. Confirm a new beneficiary through a previously established contact route, not a telephone number supplied in the suspicious message. Keep the confirmation and the original invoice with the payment record.

NCSC guidance explains that phishing can arrive by email, text or telephone. Do not disclose authentication codes to someone claiming to be support staff or log in through an unexpected urgent-action link. Use the established app or saved website address and check whether the claimed notification appears in the account itself.

Monitor changes and prepare an incident response

Enable relevant alerts for payments, users and beneficiary changes, and name somebody who will review them when the usual account operator is absent. Compare transactions with their supporting documents and query discrepancies. Keep a short record of the issue, its discovery time and the action taken rather than relying on memory.

If compromise is suspected, contact the bank through its official channel promptly and request the appropriate action to secure access or stop transactions. Change credentials from a trusted device and review connected email and user accounts. Preserve evidence; changing a password alone should not be assumed to resolve every consequence of an incident.

Make security part of everyday administration

Write a concise payment procedure covering the required document, responsible person, beneficiary check, approval and accounting entry. Revisit it when a new banking service or team member is introduced. Even a small company benefits from a process that reduces dependence on one person remembering every transaction and access arrangement.

If you are still choosing a provider, read our online banking guide and assess fund protection and product conditions alongside technical security. For organising company documents before an application, review UK company formation or contact us with the details of the intended activity and account requirements.

Official references

NCSC: small organisations cyber security

NCSC: phishing scams

Share

Exporya editorial team

Company-formation and trademark experts — and a Companies House authorised agent (ACSP) for UK formation and identity verification.