If a single person can create, approve, and release a payment, a single mistake or a single compromised account can move money out the door. Dual approval, sometimes called dual control, puts two independent people between a request and a transfer. For contractors that move large sums on progress payments, subcontractor draws, and equipment purchases, it is among the most effective controls available.
But dual approval only works when it is actually independent. Here is how to set it up well.
What Dual Approval Really Means
Two principles matter:
- Two different people. The person who initiates the payment and the person who releases it must be different individuals using their own credentials.
- Two different decision points. The second person must see the payment details and make a real decision, not merely click through a prompt.
A control that exists on paper but is bypassed by shared logins or by one person holding both roles provides little protection.
Configure It at the Bank
Most business banking platforms offer settings for entitlements and approval workflows. Work with your bank representative to configure:
- Separate roles for creating, approving, and releasing payments
- Dual approval above a defined dollar threshold, or on all wires and ACH files
- Limits on daily or per-transaction amounts for each user
- Restrictions on creating new payees and on editing existing payee details
- Alerts to a separate person whenever a new payee is added or banking details change
- Positive pay and payee validation services for checks and ACH, where available
Ask the bank which controls are enforced by the system rather than by policy. Request a written summary of your current entitlements. Many companies discover that former employees still have access or that the settings are broader than anyone intended.
Set Thresholds Thoughtfully
Thresholds should reflect your actual payment patterns and risk tolerance. Lower thresholds mean more friction but more protection. Consider:
- Dual approval for all wires and for any new payee, regardless of amount
- A higher threshold for routine, recurring payments to verified vendors
- Special handling for payments that deviate from normal patterns, such as a first payment to a new account or an amount well above the usual
Review thresholds at least annually, and after any near miss.
Make the Approver Informed
The second approver is only useful if they know what to check. Give approvers a short checklist:
- Is the payee in the approved vendor master?
- Has the banking information changed recently, and was the change verified by callback?
- Does the amount match the invoice, contract, or pay application?
- Is the approval consistent with the project budget?
- Does anything about the request feel rushed or unusual?
Approvers should have the authority and the support to pause a payment. Make clear that delay for verification is never a failure.
Protect the Credentials
Dual approval fails when one person can use both sets of credentials. Prohibit sharing of tokens and passwords. Use hardware tokens or strong multifactor authentication for banking access, and keep banking on dedicated, well-protected computers where practical. Do not do banking from a device used for general web browsing and email.
Plan for Absences
Small teams often weaken controls when someone is out. Define backup approvers in advance, and formally delegate rather than sharing credentials. Holidays and vacations are periods when attackers expect weaker oversight.
Watch for Weak Spots
Common gaps include:
- Approvers who approve on mobile without reviewing details
- An executive who regularly overrides the process because they trust the request
- Emergency exceptions that become routine
- Payment instructions arriving by email with no independent verification
- Controls applied to wires but not to ACH batches or virtual card payments
Test the Control
Once or twice a year, run a drill: ask someone to submit a small test payment request that should be blocked and see whether the process works. Review the bank's audit log to confirm separate users performed each step.
Document and Train
Write a one-page procedure covering who can initiate, who can approve, how banking changes are verified, and what to do when something looks wrong. Train everyone involved, including executives.
Ironfield Cyber helps finance teams pair strong banking controls with email protection and staff training. If you would like help reviewing your payment workflow and bank settings, we can work alongside your controller and your banker.