Dual Approval for ACH and Wire Payments: Setting It Up Properly

Dual approval is the strongest simple control against payment fraud, but only if configured correctly. Learn thresholds, bank settings, and common weak spots.

3 min readBy Ironfield Cyber Team

If a single person can create, approve, and release a payment, a single mistake or a single compromised account can move money out the door. Dual approval, sometimes called dual control, puts two independent people between a request and a transfer. For contractors that move large sums on progress payments, subcontractor draws, and equipment purchases, it is among the most effective controls available.

But dual approval only works when it is actually independent. Here is how to set it up well.

What Dual Approval Really Means

Two principles matter:

  • Two different people. The person who initiates the payment and the person who releases it must be different individuals using their own credentials.
  • Two different decision points. The second person must see the payment details and make a real decision, not merely click through a prompt.

A control that exists on paper but is bypassed by shared logins or by one person holding both roles provides little protection.

Configure It at the Bank

Most business banking platforms offer settings for entitlements and approval workflows. Work with your bank representative to configure:

  1. Separate roles for creating, approving, and releasing payments
  2. Dual approval above a defined dollar threshold, or on all wires and ACH files
  3. Limits on daily or per-transaction amounts for each user
  4. Restrictions on creating new payees and on editing existing payee details
  5. Alerts to a separate person whenever a new payee is added or banking details change
  6. Positive pay and payee validation services for checks and ACH, where available

Ask the bank which controls are enforced by the system rather than by policy. Request a written summary of your current entitlements. Many companies discover that former employees still have access or that the settings are broader than anyone intended.

Set Thresholds Thoughtfully

Thresholds should reflect your actual payment patterns and risk tolerance. Lower thresholds mean more friction but more protection. Consider:

  • Dual approval for all wires and for any new payee, regardless of amount
  • A higher threshold for routine, recurring payments to verified vendors
  • Special handling for payments that deviate from normal patterns, such as a first payment to a new account or an amount well above the usual

Review thresholds at least annually, and after any near miss.

Make the Approver Informed

The second approver is only useful if they know what to check. Give approvers a short checklist:

  • Is the payee in the approved vendor master?
  • Has the banking information changed recently, and was the change verified by callback?
  • Does the amount match the invoice, contract, or pay application?
  • Is the approval consistent with the project budget?
  • Does anything about the request feel rushed or unusual?

Approvers should have the authority and the support to pause a payment. Make clear that delay for verification is never a failure.

Protect the Credentials

Dual approval fails when one person can use both sets of credentials. Prohibit sharing of tokens and passwords. Use hardware tokens or strong multifactor authentication for banking access, and keep banking on dedicated, well-protected computers where practical. Do not do banking from a device used for general web browsing and email.

Plan for Absences

Small teams often weaken controls when someone is out. Define backup approvers in advance, and formally delegate rather than sharing credentials. Holidays and vacations are periods when attackers expect weaker oversight.

Watch for Weak Spots

Common gaps include:

  • Approvers who approve on mobile without reviewing details
  • An executive who regularly overrides the process because they trust the request
  • Emergency exceptions that become routine
  • Payment instructions arriving by email with no independent verification
  • Controls applied to wires but not to ACH batches or virtual card payments

Test the Control

Once or twice a year, run a drill: ask someone to submit a small test payment request that should be blocked and see whether the process works. Review the bank's audit log to confirm separate users performed each step.

Document and Train

Write a one-page procedure covering who can initiate, who can approve, how banking changes are verified, and what to do when something looks wrong. Train everyone involved, including executives.

Ironfield Cyber helps finance teams pair strong banking controls with email protection and staff training. If you would like help reviewing your payment workflow and bank settings, we can work alongside your controller and your banker.