A payment approval process should make routine payments fast while forcing extra evidence around high-risk actions. The main objective is to prevent one stolen login, one rushed employee or one bad bank-detail change from moving a material amount without challenge.
Give each user only the permissions needed for their job
The NCSC's access-management guidance treats users who can approve financial payments as privileged users. Apply least privilege: a person who needs to upload an invoice does not automatically need to add beneficiaries or release payments. A bookkeeper who needs transaction exports may not need authority to move funds. Individual credentials also create a clearer audit trail than a shared finance login.
Map the process into actions: view, create, change beneficiary, approve, release, administer users and change limits. Then assign each action to roles. In a small company, one director may hold several roles, but the map still reveals where too much power is concentrated. The goal is not bureaucracy. It is knowing which account compromise could cause the largest loss.
Set approval thresholds around impact, not habit
Use one-person approval for genuinely low-risk routine payments if that suits the business, then add a second approver as value or risk increases. The threshold should reflect what the company could lose without threatening payroll, tax or supplier continuity. A £5,000 threshold may be sensible for one company and meaningless for another.
Risk is not only amount. A first payment to a new supplier, a changed bank account, a payment to an unusual country or an urgent request from a senior executive can deserve extra approval even below the normal value threshold. Build rules around the transaction that is unusual, not just the transaction that is large.
Treat new and changed beneficiary details as a separate approval event
Payment fraud often succeeds before the payment screen, when an attacker persuades staff to change supplier bank details. Do not let the same email act as both the request and the evidence. Verify changes through a known phone number, supplier portal or another independent channel, then record who completed that verification.
If the banking platform allows it, separate the ability to add or amend beneficiaries from the ability to approve payments. For material suppliers, consider a cooling-off or second-person check before the first payment to new details. This is more effective than relying on the person releasing the payment to notice a subtle difference in an account number under time pressure.
Use strong MFA for payment users, especially approvers and administrators
The NCSC recommends MFA for sensitive online services and says privileged access should be strongly authenticated. It also describes step-up authentication for high-risk actions such as approving a large financial transaction. Prefer provider controls that use strong device-based or phishing-resistant methods where available rather than relying only on passwords.
Keep email security in scope because finance approvals often begin with email instructions. A compromised mailbox can defeat a strong banking login if the attacker convinces a genuine authorised user to approve the wrong payment. MFA, secure recovery methods and prompt removal of leavers should apply to the surrounding finance systems as well as the bank portal.
Plan for holidays, lost devices and emergency payments without sharing credentials
A control that works only when one director is available will eventually be bypassed. Maintain at least one properly authorised backup for genuinely critical payments, with their own credentials and MFA. Define who can take over when an approver is absent and what evidence is required. Do not solve continuity by writing down the director's password for someone else.
Also create an emergency route for payroll, tax and critical suppliers. This may involve a second bank user, a secondary operating account or a documented process for escalating access with the provider. Test the route before an emergency. The most secure control on paper is weak if the business abandons it the first time a phone is lost on payroll day.
Review access, thresholds and approval evidence on a schedule
The NCSC recommends regular reviews of unnecessary privileges and prompt revocation when access is no longer needed. Run at least a periodic user review and trigger an immediate review when staff leave, change role or a banking administrator changes. Confirm that former employees, contractors and accountants no longer have unnecessary access.
Sample recent high-value payments and check whether the approval evidence is clear. Were bank-detail changes independently verified? Did the second approver meaningfully review the payment, or simply click approve? If every transaction is waved through automatically, dual approval has become a ceremony rather than a control. Adjust thresholds and roles when the transaction pattern changes.
Editorial Verdict
A good payment approval process puts the strongest friction around the actions that can cause the largest or hardest-to-recover loss. Individual users, least privilege, independent beneficiary verification, MFA and risk-based dual approval are more useful than a blanket rule that treats every payment the same.
Continuity matters as much as restriction. Give the business a secure backup route so staff do not share credentials when the main approver is absent. Review users and recent approvals regularly, because a control that was sensible for a two-person company may be too weak once payment values and staff numbers increase.
Sources
- National Cyber Security Centre, introduction to identity and access management: https://www.ncsc.gov.uk/guidance/introduction-identity-and-access-management
- National Cyber Security Centre, identity and access management, 10 Steps to Cyber Security: https://www.ncsc.gov.uk/collection/10-steps/identity-and-access-management
- National Cyber Security Centre, phishing attacks: https://www.ncsc.gov.uk/guidance/phishing
- National Cyber Security Centre, MFA for sensitive data and high-risk actions: https://www.ncsc.gov.uk/collection/mfa-for-your-corporate-online-services/mandating-strong-mfa-for-access-sensitive-data