iBanFirst gives you multiple layers of protection, from controlling who can access your platform, to verifying payments before they leave your account.
We recommend following the guidelines below to keep your account and your financial operations secure.
Bookmark the login page
In order to prevent any fraudulent attempts, we strongly recommend you to bookmark the login page and use this page exclusively if you want to login.
Two-factor authentication with the iBanFirst mobile app
The iBanFirst authentication mobile app is your first line of defence. It secures sensitive operations on the platform by requiring you to approve or deny each request individually directly from your phone, via push notification or face/touch ID.
The app protects the following operations:
Login attempts
Payment creation and validation
Currency exchanges
Beneficiary creation
New user creation
Each notification shows you exactly what you are approving, so nothing can slip through unintentionally.
The iBanFirst mobile app replaces Google Authenticator, which is increasingly vulnerable to phishing attacks. Unlike a time-based code, the app ties each approval to a specific operation, making it far harder for attackers to intercept or replicate your codes.
Setting up the app takes just a few minutes. Go to Settings > Security > Two-Factor Authentication in your iBanFirst account to get started.
Verification of Beneficiaries (VoB)
Our Verification of Beneficiaries (VoB) feature automatically checks that a beneficiary's account details match the name you have provided before a payment is sent. It applies to EUR and GBP payments, including cross-currency scenarios.
VoB runs automatically when you:
Add a new beneficiary or modify an existing one in the Eurozone or the UK
Make a payment to a recipient in the Eurozone or the UK
Send a GBP payment from a EUR account
Send an EUR payment from a GBP account
You will receive one of three results:
1. Match: The account details match the information provided and your payment can be finalised.
2. Partial match: If a few details don't match, review them before proceeding.
3. No match: If the details don't match, verify with your contact before proceeding.
Once verified, a beneficiary's status is automatically updated in the Beneficiaries section of the platform, giving you clear visibility for future payments.
If you receive a partial match or no match notification, we strongly recommend you confirm the account details directly with your contact before sending any funds.
User rights and access control
To keep your account secure, make sure you understand what each team member can do on the iBanFirst platform. Review their permissions to see who can carry out sensitive operations, such as creating beneficiaries, preparing payments and validating them.
You can control exactly what each person in your team can see and do on the iBanFirst platform. There are four user roles available:
Role | Description |
Admin | Full access to all features, including user management, settings and financial operations. |
Payments & Trades | Can create and validate payments and FX trades. Cannot manage users or settings. |
Custom | A flexible role with permissions tailored to your company's needs. Contact your account manager to configure. |
Read-only | Can view accounts, transactions and documents, but cannot create, validate or modify anything. |
Key permissions by role:
Creating and validating payments: available to Admin and Payments & Trades roles
Managing beneficiaries: available to Admin and Payments & Trades roles
Adding and modifying users: available to Admin only
Viewing accounts and transactions: available to all roles
You can manage user roles at any time under Settings > Users > Modify User.
Remember to remove people that are not in your team anymore.
Payment validation rules
Beyond user roles, you can add an extra layer of control by setting up payment validation rules. These determine how many approvals a payment needs before it can be executed.
The available validation rules are:
1. Separate creation and validation roles. Prevent the same person from both creating and approving a payment. This separation reduces the risk of unauthorised transactions.
2. Number of required signatures. Set how many users must sign off on a payment before it can be sent — from one signature up to however many your process requires.
3. Payment amount thresholds. Assign a maximum payment amount to individual users. Any payment above that amount requires validation from another user.
4. User group-based approval. Require signatures from users in different teams or locations — for example, one approval from a local office and one from headquarters.
Note that the final signature does not automatically execute the payment. The payment must still be validated within the platform after all required signatures are collected.
To set up number of signatures or group-based rules, contact your account manager.
Monitoring and controlling access
Approving login attempts
Every time someone logs in to the iBanFirst platform, a notification is sent to the account holder's iBanFirst mobile app. You can approve or deny each login attempt individually. If you receive a notification you don't recognise, deny it immediately and contact our support team.
Locking and unlocking devices
If a device is lost, stolen or no longer in use, you can lock it directly from the platform. Go to Settings > Security to manage your registered devices. Admin users can also lock or unlock devices for other users in their organisation.
Best practices
Keep your iBanFirst mobile app installed and notifications enabled at all times.
Review your user list regularly and remove access for anyone who has left your organisation.
Set payment amount thresholds for users who don't require high-value transaction rights.
Contact your account manager if you want to review or tighten your validation rules.
Have a question? Reach out to our team at [email protected].
