7 minute read

7 ways to improve your business banking security

Cover Image for 7 ways to improve your business banking security

A spoofed vendor email or a stolen login can make a fraudulent wire look completely routine, especially when one person controls both entry and approval. These seven controls cover access, approvals, account separation, and what to do the moment something slips through.

Ordinary-looking payments are a common business banking security risk. Stolen credentials or a spoofed vendor email can make a fraudulent transfer look routine. Even a mistyped wire can clear before anyone notices, especially when one person controls payment entry and approval.

Strong business banking security combines controls that prevent bad payments with prompt detection when something gets through. A strong setup limits who can move money and requires a second review for risky payments. It also separates exposed cash from reserves and pairs fraud prevention with a clear response process.

Control access and payment approval

Limit who can enter payments, then require someone else to approve the risky ones. Set permissions for each person before adding a second review where the risk is highest.

1. Give every person their own login, with permissions to match their job

Give every person their own credentials instead of sharing a login that can enter and send payments. Turn on multi-factor authentication (MFA), which adds a verification step beyond the password, and limit access to what each job requires. Individual credentials preserve an audit trail and make same-day access removal easier when someone leaves.

Your bookkeeper may need transaction visibility and bill-data access for reconciliation but not wire permissions. Your office manager may need card management without the ability to create new payees. Relay's business banking platform gives you Relay Visa® Debit Cards³ with card-level controls, so you can set spending limits and category restrictions per card without opening the whole account. Apply the same review to software that connects to the account.

³The Relay Visa® Debit Card is issued by Thread Bank, Member FDIC, pursuant to a license from Visa U.S.A. Inc. and may be used anywhere Visa debit cards are accepted.

2. Require dual approval for payments above a threshold

Require a second person to approve bill payments and any ACH or wire above your chosen threshold. Wires settle quickly and are hard to recall, so dual approval matters most for wires and large ACH batches. Businesses use the Automated Clearing House (ACH) network to move money between bank accounts, including payroll and vendor payments. Configuring approval in the account separates payment entry from release instead of relying on a written policy.

Your finance team may rely on one bookkeeper for payments and reconciliation, but that setup gives one person too much control. Relay Bill Pay has multi-step approval rules on Grow at $30/month and Scale at $120/month. The second review happens within the bill-payment workflow.

Set the threshold around your payroll and vendor-payment patterns, then adjust it as they change. Ask your bank or banking platform how to configure approvals before assigning payment roles.

Separate and protect payment accounts

Split balances based on how you'll use the money so routine payments don't expose all your cash. Start with the account that appears on checks and vendor forms. Then add bank-side controls that flag or reject suspicious checks and electronic withdrawals.

3. Split your cash across multiple accounts

Separate accounts can limit the effect of a stolen check, unauthorized debit, or account freeze. Checks and vendor forms point to a payment account rather than your full operating balance, so one incident is less likely to expose cash held elsewhere. Divide your money by purpose:

  • Use one exposed account for checks and vendor forms.

  • Keep payroll in a separate account.

  • Hold tax reserves apart from operating cash.

  • Protect the main operating balance from routine payment activity.

  • Fund a disbursement account only for upcoming payments.

  • Isolate card spending so one incident doesn't affect every dollar.

Relay lets you put disbursements, payroll, and tax reserves in separate accounts in one place, with up to 20 checking accounts on Starter and Grow (10 for sole proprietorships), 50 on Scale, and two savings accounts on every plan.

Once you've separated routine payment cash, add controls that inspect withdrawals from the exposed account.

4. Turn on Positive Pay and ACH debit blocks

Turn on Positive Pay and ACH debit blocks so the bank inspects each item before it clears. Every mailed check exposes your account and routing numbers, and every published vendor form points a potential debit at the same account. These controls stop mismatched checks and unauthorized ACH debits at the bank, before the money leaves.

Each control targets a specific attack. Positive Pay compares a presented check with your issued-check records and flags a mismatch in the check number or amount; payee-name matching also checks the recipient. For electronic withdrawals, an ACH debit block rejects ACH debits, while a filter allows approved originators or debits that meet preset rules. Pair the controls with a small balance in the exposed account so a slip still limits the loss. If your banking platform doesn't provide these controls, keep less cash in the exposed account.

Before you rely on these controls, pin down how they work in your account:

  • Does Positive Pay include payee name matching, or only check number and amount?

  • How do you submit the check-issue file: upload, integration, or manual entry?

  • What is the submission cutoff time for that file?

  • Who reviews flagged items, and who receives the alert?

  • Does the same account offer ACH debit blocks or filters for pre-approved originators?

A missed submission cutoff can leave the next check run outside the control. Accurate, timely records keep the controls working. Assign a primary and backup reviewer, then test the next check run.

Verify payment changes and connected access

Verify payment changes outside email, and remove connections your business no longer uses. A convincing request can redirect a legitimate invoice. An old app can leave a forgotten path into your account.

5. Verify every payment-detail change through a second channel

Confirm every emailed change to a vendor's payment instructions by calling the vendor at a number already on file. Use the following process:

  1. Treat every emailed change to payment details as unverified, regardless of how routine the request looks or how familiar the sender seems.

  2. Call the vendor at a number already on file. Avoid any number supplied in the email requesting the change.

  3. Confirm the change verbally, then log who confirmed it and when.

Use the same process for internal requests. If an "urgent wire" email appears to come from the owner, call the owner before moving any money.

The attack this stops is business email compromise (BEC), where someone spoofs or compromises a vendor mailbox and sends a routine-looking request that redirects the next payment while the transaction still appears normal. The FBI Internet Crime Report recorded $2.77 billion in reported BEC losses in 2024, and second-channel verification catches the request before the payment leaves.

Once you've verified a payment change, check whether any connected app still has access it no longer needs.

6. Audit the apps connected to your bank account

List every service with account access, then decide what to keep and what to cut. An old payroll or accounting app can retain a stored login or application programming interface (API) token long after you stopped using it, leaving a forgotten path into your account.

Check five categories when you build the list:

  • Accounting software connected for bank feeds and reconciliation

  • Your payroll platform

  • Payment processors that deposit into or debit the account

  • Any accounts payable (AP) or invoicing tool holding bank credentials or API tokens

  • Any reporting dashboard or data-aggregator connection pulling transaction data

For each active connection, record whether it stores credentials or uses a token, along with the steps for revoking access. An API token is a saved digital permission that lets an app access account data without repeated password entry; accounting software may use one to keep pulling transactions into your books. If you need to cut off an app during an incident, that record tells you whether to revoke a token or change stored credentials.

Review connections quarterly with team access, and disconnect anything you no longer use. If a departing team member administered a tool, reconnect it with fresh credentials.

Detect and respond to suspicious activity

A daily transaction review gives you the best chance to catch an unauthorized payment while a recall or dispute may still be available. Assign the account reviewer and escalation owner in advance so a flagged payment leads to an immediate call.

7. Review transactions daily and report fraud the same day

Check the morning transaction list for unfamiliar payments, and report anything suspicious the same day you see it. Recall and dispute deadlines vary by payment type and account agreement, so speed protects your options. A 2025 AFP fraud survey found that only 22% of businesses recovered 75% or more of money lost to payment fraud in 2024.

Prompt reporting matters more for business accounts than for consumer ones. Business accounts don't receive the same transfer protections as consumer accounts. Your account agreement and commercial law often determine who bears the loss. The Uniform Commercial Code (UCC) Article 4A often governs commercial electronic transfers, while other rules apply to checks. Your business may bear the loss when the bank follows the security procedures in your agreement.

Give the daily review to a specific person and make it part of that person's morning. Keep the institution's fraud contact and the account owner's details where the reviewer can find them; otherwise, a flagged payment can sit while someone works out whom to call. Decide who will preserve invoices and approval records as well. Contact your bank or banking platform as soon as the reviewer finds a suspicious transaction, even if you don't yet know how it happened.

Start with your highest-risk payment scenario

Start with the payment scenario that could cause the largest loss or disruption. Pair one preventive control with a clear response process, assign an owner and completion date, and record any failed approval, missed Positive Pay exception, or unauthorized debit that points to another gap.

When routine payments expose too much cash, opening a Relay account lets you separate disbursements from reserves and add approval rules to bill payments. Your account structure and payment review then work together, so a routine payment doesn't expose every dollar or depend on one person's review.


Frequently asked questions

Are business bank accounts protected the same way as personal accounts?

No. The rules vary by transaction type and account agreement, and prompt reporting may affect which dispute or recall options remain available.

What is Positive Pay?

Positive Pay compares presented checks with the records of checks you issued and flags mismatches. Confirm whether your institution also checks the payee name and when it requires you to review exceptions.

Does FDIC insurance cover fraud losses?

No. FDIC insurance2 covers eligible deposits when an insured bank fails; it doesn't cover unauthorized transactions. Fraud disputes follow separate rules and deadlines.

2Your deposits qualify for up to $3,000,000 in FDIC insurance coverage when Thread Bank places them at program banks in its deposit sweep program. Your deposits at each program bank become eligible for FDIC insurance up to $250,000, inclusive of any other deposits you may already hold at the bank in the same ownership capacity. You can access the terms and conditions of the sweep program at https://thread.bank/sweep-disclosure/ and a list of program banks at https://thread.bank/program-banks/. Please contact customerservice@thread.bank with questions on the sweep program. Certain conditions must be satisfied for pass-through deposit insurance coverage to apply.

How often should I review banking permissions?

Quarterly is a practical default for team access and connected apps. Remove access the same day someone leaves, using the connection records described above.

How fast do I need to report a fraudulent business transaction?

Immediately. Contact your bank or banking platform as soon as you spot the transaction, so they can start any available dispute or recall process before the applicable deadline.

Making money make sense

Try Relay for free

More about the authorThe Relay Editorial Team produces practical, expert-backed content for small business owners navigating the financial side of running a company. Our work is informed by contributions from CPAs, advisors, and experienced operators, and held to rigorous editorial standards for accuracy and relevance. Relay is a banking platform built for small businesses—and our editorial mission reflects that focus.View more articles by Relay Editorial Team

Relay is a financial technology company and is not an FDIC-insured bank. Banking services provided by Thread Bank, Member FDIC.