A detailed UK guide to safely and efficiently authorising employees, directors, or third parties on your business bank account

Authorising someone else to access or manage your business bank account is a decision that carries significant responsibility and risk. Whether you’re expanding, delegating, or simply need cover for holidays, getting this process right is crucial for protecting your business’s finances and reputation. This guide gives UK small business owners the practical, step-by-step advice, legal context, and real-world best practices you need to confidently handle authorisations—without leaving yourself exposed.
When you authorise someone else on your business bank account, you’re granting them legal permission to perform certain actions on behalf of your business. This might include viewing balances, making payments, setting up direct debits, or even applying for credit. In UK banking, these individuals are typically called "authorised signatories" or "account operators." The precise rights and controls you can assign depend on your bank, your business structure (sole trader, partnership, limited company), and your own preferences.
Why does this matter so much? Because the person you authorise will have partial or even full access to your business’s money. If you don’t set clear boundaries or choose the right people, you risk fraud, financial loss, or regulatory breaches. Moreover, UK anti-money laundering (AML) and know-your-customer (KYC) regulations mean banks must identify and vet every individual with account access. Your choices affect not just internal controls, but how your business is seen by banks, HMRC, and possibly even clients.
It’s also important to understand the difference between giving someone view-only access (to check balances, for example) and granting them transaction authority (to transfer money, pay suppliers, or sign cheques). Authorisation isn’t all-or-nothing—most banks allow you to customise what each person can do. Setting up the right level of access for each individual is one of the most important best practices you can follow.
Typically, you can authorise directors, employees, accountants, or even external bookkeepers. However, your bank may have restrictions—especially for non-UK residents or people with certain criminal records. Always check with your bank before starting the process.
There are many situations where authorising someone else on your account makes sense. For example, if your business is growing and you can’t handle all payments yourself, you might delegate to a trusted finance manager. If you’re a limited company with multiple directors, the bank will often require at least two signatories for fraud prevention. Even as a sole trader, you might wish to grant your accountant view-only access to help with bookkeeping or VAT returns.
Temporary situations also arise—like authorising someone to cover for you during annual leave or illness. In family businesses, it’s common to authorise a spouse or relative, though this brings its own risks if not handled carefully. Some businesses need to authorise third-party bookkeepers or payroll providers, which requires extra diligence and clear contracts.
A less common but important scenario is when a business needs to grant power of attorney to someone, often due to incapacity or long-term absence. This is a legal process and should be handled with professional advice, as it gives sweeping powers to the attorney.
According to UK Finance, around 73% of UK SMEs use dual authorisation or multi-person access for their business bank accounts, citing fraud prevention as the main reason.
The most important decision you’ll make is who you trust with access to your business bank account. In the UK, banks are legally required to carry out identity and background checks on all authorised signatories, but this is just the starting point. As the business owner, you’re ultimately responsible for financial losses or fraud—even if the bank’s checks didn’t catch a problem.
Ask yourself: Does this person understand basic financial controls? Have they handled money responsibly before? Are there any potential conflicts of interest (for example, a bookkeeper who also has access to make payments)? It’s best to choose people who are already subject to some internal oversight, such as directors, senior managers, or long-standing employees. If you must authorise someone external (like an accountant), ensure there’s a formal contract in place outlining their responsibilities and limitations.
Remember, authorising someone is not just about trust—it’s about competence and risk management. The best practice is to segregate duties: for example, the person who reconciles the bank account should not be the same person who authorises payments. This is a cornerstone of good financial governance and is recommended by the UK’s Financial Conduct Authority (FCA) for all businesses, not just regulated firms.
Even the most trusted employee can make mistakes—or worse. Always combine personal trust with strong internal controls and clear limits on what an authorised person can do.
Setting up authorisation is a formal process. UK banks are legally obliged to know exactly who can access or operate a business account. For limited companies and partnerships, this usually means providing Companies House details, ID documents, and proof of address for each signatory. For sole traders, banks may only permit one named account holder, but some allow you to add an "authorised user" for certain functions.
Most UK banks let you set up different types of access. For example, you might allow someone to view statements but not make payments. Digital banks (like Starling, Tide, and Monzo Business) offer granular controls via their apps, while traditional banks often require paper forms and signatures. Dual authorisation—where two people must approve each payment—is common for limited companies and is strongly recommended for fraud prevention.
It’s vital to document exactly what each person can and cannot do, both in your bank mandate (the legal document governing account access) and in your own internal records. If you change or remove an authorised person, notify your bank immediately—delays can leave your business exposed.
| Bank | Type of Authorisation | Typical Setup Time | Dual Authorisation? | Digital Controls |
|---|---|---|---|---|
| Barclays | Full/partial signatory | 3-5 days | Optional | Limited |
| NatWest | Signatory or view-only | 2-7 days | Yes | Good |
| Starling Bank | Team access (custom roles) | Same day | Yes | Excellent |
| Lloyds | Mandate signatory | 3-10 days | Optional | Moderate |
| Tide | Team member (custom permissions) | 1-2 days | Yes | Very good |
If you’re unsure about a new employee, start with view-only access and increase permissions as trust and competence are proven.
Once you’ve decided who to authorise, the next best practice is to set the minimum necessary permissions. This is sometimes called the "principle of least privilege." For example, a junior finance assistant might only need to view incoming payments and reconcile statements, not make outgoing payments or change account details. Most UK banks now allow you to define access for each user, particularly through online banking platforms.
Dual authorisation is particularly powerful: it requires two people to approve every outgoing payment, which dramatically reduces the risk of fraud or error. Even if your bank doesn’t require this as standard, it’s worth implementing if possible—especially for payments over a certain threshold. Some banks also let you set daily or transaction limits for each authorised user, which can stop small errors from becoming major disasters.
Regular reviews are critical. At least once a year (or whenever someone leaves the business), check who is authorised, what permissions they have, and whether these are still appropriate. Remove or downgrade access immediately if someone changes roles or leaves—delays here are a common source of both accidental and malicious losses.
Beyond the bank’s own systems, you should have clear internal policies for who can be authorised, how, and under what conditions. This is especially important for limited companies, where directors have legal duties under the Companies Act 2006 to safeguard company assets. Your Board (even if it’s just you and one other) should formally approve all changes to signatories, and record this in meeting minutes.
Include a section in your staff handbook or internal policies covering how authorisation works, what is expected of signatories, and what the consequences are for misuse. For third parties (like bookkeepers or accountants), have a written contract specifying what they can and cannot do, and require them to comply with your confidentiality and data protection policies. This can help you demonstrate compliance if HMRC or an auditor ever investigates your business.
Don’t overlook data protection. Under the UK GDPR, you must keep records secure and only share account access with those who need it. If you’re authorising someone to use online banking, ensure your IT policies cover secure passwords, two-factor authentication, and safe device usage. The Information Commissioner’s Office (ICO) recommends regularly reviewing who has access to financial systems to prevent data breaches.
For limited companies, Companies House does not need to be notified of every account signatory. However, you must keep accurate records internally and comply with your Articles of Association and board procedures.
One of the biggest risks UK SMEs face is failing to promptly remove or update authorised persons. If someone leaves your business—or even just changes role—their access should be revoked immediately. Too often, businesses assume this happens automatically or forget about dormant signatories. This can leave you exposed to fraud or errors by people no longer involved with your company.
Every UK bank has its own process for removing an authorised person, but most require a formal instruction—ideally in writing, signed by a director or owner. Digital banks simplify this, but you must still confirm and document the change. Always get confirmation from the bank that access has been removed, and keep this for your records. Failure to do so may mean you are still liable for transactions made by a former employee or partner.
If you’re removing someone for misconduct or after a dispute, act quickly and seek legal advice if necessary. Change all passwords, revoke all device access, and notify your team to prevent any unauthorised action. If fraud or theft is suspected, inform your bank immediately—many banks have 24/7 fraud lines—and consider reporting to Action Fraud (the UK’s national fraud and cybercrime reporting centre).
| Situation | Action Required | Risk if Not Actioned | Typical Bank Requirement |
|---|---|---|---|
| Employee leaves business | Remove authorisation immediately | Fraud, unauthorised payments | Written instruction, new mandate |
| Role change (e.g., promoted) | Review and update permissions | Excessive access | Online or written update |
| Suspicion of fraud | Immediate removal, contact bank | Financial loss, data breach | Fraud team notification |
| Change of directors | Update Companies House and bank | Breach of legal duties | Formal documentation |
Authorising others on your business bank account introduces new risks—both from within and outside your business. UK Finance data shows that small businesses are increasingly targeted by payment fraud, often due to weaknesses in internal controls or out-of-date signatory lists. Ultimately, the legal responsibility for losses often falls on the business owner or directors, not the bank, unless you can prove the bank acted negligently.
Best practice is to combine technical controls (like dual authorisation and transaction limits) with procedural safeguards: regular audits, reconciliations, and a clear separation of duties. Make use of your bank’s fraud prevention features—such as real-time payment alerts and transaction monitoring. Train all authorised users on how to spot common scams, such as invoice redirection or CEO fraud, which are increasingly sophisticated in the UK market.
If a dispute arises between signatories, or between you and your bank, act quickly. Most banks have a dedicated business support team and a formal complaints process. If you can’t resolve the issue, you can escalate to the Financial Ombudsman Service (FOS), which handles disputes between UK banks and small businesses. In cases of suspected crime, Action Fraud should be your first port of call.
Unless fraud is clearly proven and reported immediately, you are likely to be held liable for losses caused by someone you authorised. Protect yourself with clear policies, technical safeguards, and regular reviews.
Sometimes, you’ll need to authorise someone outside your business—such as an accountant, bookkeeper, or legal representative. For view-only access, many UK banks now offer secure portals or read-only logins, which are ideal for external advisers. For payment authority, you must be extra cautious: always have a contract, restrict permissions to the minimum necessary, and carry out regular reviews. HMRC recommends that any agent with access to your financial systems be registered with a professional body, such as the ICAEW or ACCA.
Granting power of attorney (POA) is a special case, usually reserved for situations where you are incapacitated or unavailable for an extended period. A POA gives the attorney sweeping powers to operate your account, so it should only be used with robust legal advice. Most UK banks require a certified copy of the POA document, and may restrict or closely monitor transactions made under POA authority.
If you need to authorise a third-party payroll or bookkeeping provider, look for a provider with dedicated business banking integrations. Always check their credentials and ask for references from other UK SMEs. Never share your own login or PIN—this is a breach of most banks’ terms and can invalidate fraud protections.
| Access Type | Best Practice | Bank/Legal Requirements | Risks |
|---|---|---|---|
| External accountant (view-only) | Use secure read-only login | ID check, contract | Low |
| Bookkeeper (transaction access) | Formal contract, limited permissions | Bank vetting, regular review | Medium |
| Power of attorney | Legal advice, notify bank in writing | Certified POA document | High |
| Payroll provider | Dedicated integration, no shared login | Provider vetting | Low-Medium |
Authorise third parties through the bank’s official process. Sharing your own login or PIN can void your bank’s fraud guarantees and put your business at serious risk.
Authorising someone is not a set-and-forget task. The best UK businesses treat access as a living control: something to be reviewed, tested, and adjusted as circumstances change. Schedule at least an annual review of your account mandate, but ideally check permissions quarterly or whenever a major staff change occurs. This is especially critical after redundancies, promotions, or structural changes (like adding new directors or merging companies).
Use your bank’s reporting features to monitor all activity by authorised persons. Set up payment alerts on your mobile or by email, especially for large or unusual transactions. Where possible, reconcile your bank statements weekly, not just at month-end. This helps catch errors or fraud early, while you can still take action.
Finally, carry out internal audits—either yourself or with your accountant/adviser. Audits aren’t just for big companies: even a simple review of signatories, permissions, and transaction logs can uncover issues before they become expensive problems. Document all reviews and keep evidence for at least seven years, as HMRC or your bank may request this during audits or investigations.

Ready for the next step? Open a business bank account to keep your finances organised.

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.
Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.


Affiliate links. We may earn a commission. Editorial independence maintained.