Row rect Shape Decorative svg added to bottom

Protecting Your Business from High-Risk Access Combinations

A toxic access combination occurs when one user has permission to perform multiple high-risk activities without the appropriate checks and balances. This may include capturing and approving payments, adding or changing beneficiary details, and adding or removing users on online channels without a second level of approval.

Without the appropriate segregation of duties (SoD), errors, unauthorised changes and fraudulent payments may occur and remain undetected.

What are Toxic access combinations

A toxic access combination occurs when one user has access to perform multiple critical functions within a payment process without the appropriate checks and balances.

The risk is not necessarily an individual permission. The risk arises when conflicting permissions are combined in a way that allows one user to complete critical stages of a payment process without independent review or approval.

Examples may include the ability to:

  • Capture and approve payments
  • Create or amend beneficiary details and approve those changes
  • Add or remove users on online banking channels without independent authorisation

These access combinations can weaken segregation of duties, reducing the oversight designed to help protect businesses from fraud and operational risk.

Understand the risk

Allowing one user to perform conflicting activities may enable them to:

  • Capture and approve their own payments
  • Add unauthorised beneficiaries
  • Change legitimate beneficiary banking details
  • Bypass approval workflows
  • Process fraudulent or unauthorised payments.

 

How the risk can arise?

High-risk access combinations may develop when permissions are added over time, responsibilities change, employees move between roles, or access is not removed when it is no longer required. If one user can initiate a payment, maintain beneficiary information and approve transactions, unauthorised activity may be more difficult to identify before a payment is processed.

The same concern applies where a user can manage access to online banking channels without an independent authorisation step. Concentrating critical permissions with one person can allow normal checks and approval workflows to be bypassed.

Protect your business

  • Ensure SoD: Separate payment capture, beneficiary maintenance and approval activities among different users.
  • Step up authentication: Apply additional authentication for high-risk transactions and account changes.
  • Implement approval hierarchies: Have independent approval in place for high-value or sensitive activities.
  • Monitor audit trails/logs: Record and monitor all critical user and payment activities.
  • Conduct regular reconciliations: Reconcile accounts regularly to detect anomalies early.
  • Follow the principle of least privilege: Grant only the access necessary for each user’s role.
  • Conduct role and access reviews: Review permissions regularly to eliminate toxic access combinations.
  • Increase fraud awareness: Educate users on fraud risks and the importance of strong controls.

 

Why segregation of duties matter

Segregation of duties is a recognised control that helps ensure key activities are performed and reviewed by different individuals. This reduces the risk of errors, unauthorised changes and inappropriate transactions going undetected.

By separating responsibilities and implementing approval controls, businesses can strengthen their payment processes and improve oversight.

Steps you can take

    1. Separate duties. Assign payment capture, beneficiary maintenance and payment approval to different users.
    2. Require independent approval. Apply independent approval to payments, beneficiary additions or amendments, and relevant user-access changes.
    3. Review access regularly. Validate delegated user access, role permissions and approval limits to confirm that they remain appropriate.
    4. Act promptly on staff changes. Update or remove access when employees change roles or leave the organisation.
    5. Apply least privilege. Give users only the access needed to perform their current responsibilities.
    6. Monitor activity continuously. Review unusual payment, beneficiary and user-administration activity that may require investigation.

Important Safeguard

Critical control

Users should not be able to capture and approve the same payment or independently create and approve beneficiary changes. Access arrangements should include appropriate independent authorisation and oversight.

Important reminders

  • Never allow one user to control an entire payment process.
  • Check your delegated user profiles and approval workflows regularly.
  • Ensure that no user can capture and approve their own transactions or independently create and approve beneficiary changes.

For assistance with reviewing your digital banking access and approval structure, please contact your Banker.

Report fraud and suspicious activity

If you would like guidance on reviewing user access permissions and payment controls, please contact your Banker, who can assist with the appropriate escalation and support process.

Contact the Corporate and Investment Banking Fraud Hotline:

Previous fraud alerts

FRAUD

Fraud Alert: Fake payment confirmations

Fraudsters are targeting businesses using fraudulent payment documents and cheque deposits to create the impression that payment has been made. These scams can result in businesses releasing goods or delivering services without receiving the funds due to them.

FRAUD

Fake Apps and Mobile Malware

We’d like to alert you to a new and emerging fraud modus operandi (MO) where fraudsters trick you into downloading malicious apps that compromise your mobile devices and banking credentials.

FRAUD

Fraud Alert – WhatsApp Fraud

WhatsApp fraud is a social engineering scam used by criminals to exploit trust through impersonation and deception. It aims to manipulate victims into sharing sensitive information or transferring funds via WhatsApp messages or calls.