The RoadmapSetupSetting Up a Business Bank Account

Best Practices for Authorizing Others on Your Account

A detailed UK guide to safely and efficiently authorising employees, directors, or third parties on your business bank account

10 minute read
Setup — Setting Up a Business Bank Account
✓ Verified against GOV.UK
Claire Henderson
Written by Claire Henderson
Finance & Tax Editor · GuideToBusiness
Back to Setup

Authorising someone else to access or manage your business bank account is a decision that carries significant responsibility and risk. Whether you’re expanding, delegating, or simply need cover for holidays, getting this process right is crucial for protecting your business’s finances and reputation. This guide gives UK small business owners the practical, step-by-step advice, legal context, and real-world best practices you need to confidently handle authorisations—without leaving yourself exposed.

Understanding Account Authorisation: What It Means and Why It Matters

When you authorise someone else on your business bank account, you’re granting them legal permission to perform certain actions on behalf of your business. This might include viewing balances, making payments, setting up direct debits, or even applying for credit. In UK banking, these individuals are typically called "authorised signatories" or "account operators." The precise rights and controls you can assign depend on your bank, your business structure (sole trader, partnership, limited company), and your own preferences.

Why does this matter so much? Because the person you authorise will have partial or even full access to your business’s money. If you don’t set clear boundaries or choose the right people, you risk fraud, financial loss, or regulatory breaches. Moreover, UK anti-money laundering (AML) and know-your-customer (KYC) regulations mean banks must identify and vet every individual with account access. Your choices affect not just internal controls, but how your business is seen by banks, HMRC, and possibly even clients.

It’s also important to understand the difference between giving someone view-only access (to check balances, for example) and granting them transaction authority (to transfer money, pay suppliers, or sign cheques). Authorisation isn’t all-or-nothing—most banks allow you to customise what each person can do. Setting up the right level of access for each individual is one of the most important best practices you can follow.

Who Can Be Authorised?

Typically, you can authorise directors, employees, accountants, or even external bookkeepers. However, your bank may have restrictions—especially for non-UK residents or people with certain criminal records. Always check with your bank before starting the process.

Common Scenarios: When and Why UK SMEs Authorise Others

There are many situations where authorising someone else on your account makes sense. For example, if your business is growing and you can’t handle all payments yourself, you might delegate to a trusted finance manager. If you’re a limited company with multiple directors, the bank will often require at least two signatories for fraud prevention. Even as a sole trader, you might wish to grant your accountant view-only access to help with bookkeeping or VAT returns.

Temporary situations also arise—like authorising someone to cover for you during annual leave or illness. In family businesses, it’s common to authorise a spouse or relative, though this brings its own risks if not handled carefully. Some businesses need to authorise third-party bookkeepers or payroll providers, which requires extra diligence and clear contracts.

A less common but important scenario is when a business needs to grant power of attorney to someone, often due to incapacity or long-term absence. This is a legal process and should be handled with professional advice, as it gives sweeping powers to the attorney.

  • Delegating routine payments to a finance assistant or manager
  • Allowing an external accountant view-only access for audits and tax
  • Meeting dual authorisation requirements for limited companies
  • Granting temporary access to cover holidays or sick leave
  • Authorising bookkeepers to reconcile accounts and manage payroll
Did You Know?

According to UK Finance, around 73% of UK SMEs use dual authorisation or multi-person access for their business bank accounts, citing fraud prevention as the main reason.

Choosing the Right People: Assessing Trustworthiness and Skills

The most important decision you’ll make is who you trust with access to your business bank account. In the UK, banks are legally required to carry out identity and background checks on all authorised signatories, but this is just the starting point. As the business owner, you’re ultimately responsible for financial losses or fraud—even if the bank’s checks didn’t catch a problem.

Ask yourself: Does this person understand basic financial controls? Have they handled money responsibly before? Are there any potential conflicts of interest (for example, a bookkeeper who also has access to make payments)? It’s best to choose people who are already subject to some internal oversight, such as directors, senior managers, or long-standing employees. If you must authorise someone external (like an accountant), ensure there’s a formal contract in place outlining their responsibilities and limitations.

Remember, authorising someone is not just about trust—it’s about competence and risk management. The best practice is to segregate duties: for example, the person who reconciles the bank account should not be the same person who authorises payments. This is a cornerstone of good financial governance and is recommended by the UK’s Financial Conduct Authority (FCA) for all businesses, not just regulated firms.

  • Prioritise employees or directors with proven financial responsibility
  • Avoid single points of failure—never let one person control everything
  • Check for conflicts of interest, especially with external providers
  • Consider criminal record checks for high-risk or finance-focused roles
  • Always have a clear, written agreement for third-party access
Don’t Rely On Trust Alone

Even the most trusted employee can make mistakes—or worse. Always combine personal trust with strong internal controls and clear limits on what an authorised person can do.

Setting Up Authorisation: How UK Business Bank Accounts Handle Access

Setting up authorisation is a formal process. UK banks are legally obliged to know exactly who can access or operate a business account. For limited companies and partnerships, this usually means providing Companies House details, ID documents, and proof of address for each signatory. For sole traders, banks may only permit one named account holder, but some allow you to add an "authorised user" for certain functions.

Most UK banks let you set up different types of access. For example, you might allow someone to view statements but not make payments. Digital banks (like Starling, Tide, and Monzo Business) offer granular controls via their apps, while traditional banks often require paper forms and signatures. Dual authorisation—where two people must approve each payment—is common for limited companies and is strongly recommended for fraud prevention.

It’s vital to document exactly what each person can and cannot do, both in your bank mandate (the legal document governing account access) and in your own internal records. If you change or remove an authorised person, notify your bank immediately—delays can leave your business exposed.

BankType of AuthorisationTypical Setup TimeDual Authorisation?Digital Controls
BarclaysFull/partial signatory3-5 daysOptionalLimited
NatWestSignatory or view-only2-7 daysYesGood
Starling BankTeam access (custom roles)Same dayYesExcellent
LloydsMandate signatory3-10 daysOptionalModerate
TideTeam member (custom permissions)1-2 daysYesVery good
Tip: Start With Limited Access

If you’re unsure about a new employee, start with view-only access and increase permissions as trust and competence are proven.

Setting Permissions and Controls: Limiting Risk and Fraud

Once you’ve decided who to authorise, the next best practice is to set the minimum necessary permissions. This is sometimes called the "principle of least privilege." For example, a junior finance assistant might only need to view incoming payments and reconcile statements, not make outgoing payments or change account details. Most UK banks now allow you to define access for each user, particularly through online banking platforms.

Dual authorisation is particularly powerful: it requires two people to approve every outgoing payment, which dramatically reduces the risk of fraud or error. Even if your bank doesn’t require this as standard, it’s worth implementing if possible—especially for payments over a certain threshold. Some banks also let you set daily or transaction limits for each authorised user, which can stop small errors from becoming major disasters.

Regular reviews are critical. At least once a year (or whenever someone leaves the business), check who is authorised, what permissions they have, and whether these are still appropriate. Remove or downgrade access immediately if someone changes roles or leaves—delays here are a common source of both accidental and malicious losses.

  • Use dual authorisation for all payments above your normal threshold
  • Limit junior staff to view-only access where possible
  • Set transaction and daily limits for new or less experienced users
  • Regularly review and update permissions, especially after staff changes
  • Document all permissions and changes for audit and legal protection

Formalising Authorisation: Internal Policies and Legal Considerations

Beyond the bank’s own systems, you should have clear internal policies for who can be authorised, how, and under what conditions. This is especially important for limited companies, where directors have legal duties under the Companies Act 2006 to safeguard company assets. Your Board (even if it’s just you and one other) should formally approve all changes to signatories, and record this in meeting minutes.

Include a section in your staff handbook or internal policies covering how authorisation works, what is expected of signatories, and what the consequences are for misuse. For third parties (like bookkeepers or accountants), have a written contract specifying what they can and cannot do, and require them to comply with your confidentiality and data protection policies. This can help you demonstrate compliance if HMRC or an auditor ever investigates your business.

Don’t overlook data protection. Under the UK GDPR, you must keep records secure and only share account access with those who need it. If you’re authorising someone to use online banking, ensure your IT policies cover secure passwords, two-factor authentication, and safe device usage. The Information Commissioner’s Office (ICO) recommends regularly reviewing who has access to financial systems to prevent data breaches.

Establishing and Managing Account Authorisation for Your Business

1
Define Your Internal Policy
Document who can be authorised, by whom, and the approval process (e.g., board meeting or owner’s decision). Set out minimum requirements for authorisation.
2
Approve and Record Authorisation
Get formal approval (e.g., board minutes, written owner consent) before adding or changing signatories. Keep records for at least seven years.
3
Submit Authorisation to Your Bank
Complete the bank’s forms—online or paper. Provide all necessary ID and address proof for each person. Specify permissions clearly (full, payment-only, view-only, etc.).
4
Implement Controls and Limits
Set up payment limits, dual authorisation, and periodic reviews in your banking platform or with your relationship manager.
5
Regularly Review and Remove Access
Schedule annual reviews and immediate revocation when staff leave or change roles. Document all changes and communicate them to your bank without delay.
Legal Minimums

For limited companies, Companies House does not need to be notified of every account signatory. However, you must keep accurate records internally and comply with your Articles of Association and board procedures.

Removing or Changing Authorised Persons: Avoiding Common Pitfalls

One of the biggest risks UK SMEs face is failing to promptly remove or update authorised persons. If someone leaves your business—or even just changes role—their access should be revoked immediately. Too often, businesses assume this happens automatically or forget about dormant signatories. This can leave you exposed to fraud or errors by people no longer involved with your company.

Every UK bank has its own process for removing an authorised person, but most require a formal instruction—ideally in writing, signed by a director or owner. Digital banks simplify this, but you must still confirm and document the change. Always get confirmation from the bank that access has been removed, and keep this for your records. Failure to do so may mean you are still liable for transactions made by a former employee or partner.

If you’re removing someone for misconduct or after a dispute, act quickly and seek legal advice if necessary. Change all passwords, revoke all device access, and notify your team to prevent any unauthorised action. If fraud or theft is suspected, inform your bank immediately—many banks have 24/7 fraud lines—and consider reporting to Action Fraud (the UK’s national fraud and cybercrime reporting centre).

SituationAction RequiredRisk if Not ActionedTypical Bank Requirement
Employee leaves businessRemove authorisation immediatelyFraud, unauthorised paymentsWritten instruction, new mandate
Role change (e.g., promoted)Review and update permissionsExcessive accessOnline or written update
Suspicion of fraudImmediate removal, contact bankFinancial loss, data breachFraud team notification
Change of directorsUpdate Companies House and bankBreach of legal dutiesFormal documentation
  • Always confirm removal of access directly with your bank
  • Update internal records at the same time as informing the bank
  • Change online banking passwords and revoke device access
  • Communicate changes promptly to all relevant staff
  • Seek legal advice if removal is disputed or sensitive

Protecting Yourself: Fraud, Liability, and Dispute Resolution

Authorising others on your business bank account introduces new risks—both from within and outside your business. UK Finance data shows that small businesses are increasingly targeted by payment fraud, often due to weaknesses in internal controls or out-of-date signatory lists. Ultimately, the legal responsibility for losses often falls on the business owner or directors, not the bank, unless you can prove the bank acted negligently.

Best practice is to combine technical controls (like dual authorisation and transaction limits) with procedural safeguards: regular audits, reconciliations, and a clear separation of duties. Make use of your bank’s fraud prevention features—such as real-time payment alerts and transaction monitoring. Train all authorised users on how to spot common scams, such as invoice redirection or CEO fraud, which are increasingly sophisticated in the UK market.

If a dispute arises between signatories, or between you and your bank, act quickly. Most banks have a dedicated business support team and a formal complaints process. If you can’t resolve the issue, you can escalate to the Financial Ombudsman Service (FOS), which handles disputes between UK banks and small businesses. In cases of suspected crime, Action Fraud should be your first port of call.

Financial Responsibility Rests With You

Unless fraud is clearly proven and reported immediately, you are likely to be held liable for losses caused by someone you authorised. Protect yourself with clear policies, technical safeguards, and regular reviews.

  • Use dual authorisation and transaction limits to prevent large losses
  • Audit your account regularly—ideally monthly
  • Train staff to recognise common payment frauds
  • Escalate unresolved disputes to the Financial Ombudsman Service
  • Promptly report all suspected fraud to your bank and Action Fraud

Special Cases: Power of Attorney, Accountants, and Third-Party Access

Sometimes, you’ll need to authorise someone outside your business—such as an accountant, bookkeeper, or legal representative. For view-only access, many UK banks now offer secure portals or read-only logins, which are ideal for external advisers. For payment authority, you must be extra cautious: always have a contract, restrict permissions to the minimum necessary, and carry out regular reviews. HMRC recommends that any agent with access to your financial systems be registered with a professional body, such as the ICAEW or ACCA.

Granting power of attorney (POA) is a special case, usually reserved for situations where you are incapacitated or unavailable for an extended period. A POA gives the attorney sweeping powers to operate your account, so it should only be used with robust legal advice. Most UK banks require a certified copy of the POA document, and may restrict or closely monitor transactions made under POA authority.

If you need to authorise a third-party payroll or bookkeeping provider, look for a provider with dedicated business banking integrations. Always check their credentials and ask for references from other UK SMEs. Never share your own login or PIN—this is a breach of most banks’ terms and can invalidate fraud protections.

Access TypeBest PracticeBank/Legal RequirementsRisks
External accountant (view-only)Use secure read-only loginID check, contractLow
Bookkeeper (transaction access)Formal contract, limited permissionsBank vetting, regular reviewMedium
Power of attorneyLegal advice, notify bank in writingCertified POA documentHigh
Payroll providerDedicated integration, no shared loginProvider vettingLow-Medium
Never Share Your Login

Authorise third parties through the bank’s official process. Sharing your own login or PIN can void your bank’s fraud guarantees and put your business at serious risk.

Ongoing Oversight: Monitoring, Reviewing, and Auditing Account Access

Authorising someone is not a set-and-forget task. The best UK businesses treat access as a living control: something to be reviewed, tested, and adjusted as circumstances change. Schedule at least an annual review of your account mandate, but ideally check permissions quarterly or whenever a major staff change occurs. This is especially critical after redundancies, promotions, or structural changes (like adding new directors or merging companies).

Use your bank’s reporting features to monitor all activity by authorised persons. Set up payment alerts on your mobile or by email, especially for large or unusual transactions. Where possible, reconcile your bank statements weekly, not just at month-end. This helps catch errors or fraud early, while you can still take action.

Finally, carry out internal audits—either yourself or with your accountant/adviser. Audits aren’t just for big companies: even a simple review of signatories, permissions, and transaction logs can uncover issues before they become expensive problems. Document all reviews and keep evidence for at least seven years, as HMRC or your bank may request this during audits or investigations.

  • Schedule quarterly or annual reviews of all authorised persons
  • Use payment alerts and online monitoring tools
  • Reconcile accounts weekly to spot problems early
  • Audit permissions after every major staff or structural change
  • Keep documented evidence of all reviews and changes
Key Takeaways
  • Careful selection of authorised persons is essential. Prioritise trust, competence, and segregation of duties to minimise risk and maintain good governance.
  • Set permissions to the minimum necessary. Use your bank’s controls to limit what each person can do, and always implement dual authorisation for higher-risk payments.
  • Formalise and document all authorisations. Use board minutes, internal policies, and written contracts for third-party access. Keep records for at least seven years.
  • Act quickly to remove access when roles change. Delays in removing former employees or advisers can expose your business to fraud, errors, or legal liability.
  • Leverage your bank’s digital controls and alerts. Modern UK banks offer granular permissions, real-time notifications, and easy-to-update mandates—use them.
  • Never share your own login details. Always authorise others through official channels; sharing logins can invalidate fraud protections and breach contracts.
  • Regular reviews and audits are non-negotiable. Schedule ongoing oversight to ensure only the right people have the right access at all times.
  • Protect yourself with clear procedures and rapid response. In case of problems or disputes, act quickly, document everything, and escalate to your bank or the Financial Ombudsman if needed.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.