Skip to main content

Keeping your account secure

Learn how iBanFirst helps protect your account and financial operations with secure login, two-factor authentication, beneficiary checks and payment controls.

iBanFirst gives you multiple layers of protection, from controlling who can access your platform, to verifying payments before they leave your account.

We recommend following the guidelines below to keep your account and your financial operations secure.

Bookmark the login page

In order to prevent any fraudulent attempts, we strongly recommend you to bookmark the login page and use this page exclusively if you want to login.

Two-factor authentication with the iBanFirst mobile app

The iBanFirst authentication mobile app is your first line of defence. It secures sensitive operations on the platform by requiring you to approve or deny each request individually directly from your phone, via push notification or face/touch ID.

The app protects the following operations:

  • Login attempts

  • Payment creation and validation

  • Currency exchanges

  • Beneficiary creation

  • New user creation

Each notification shows you exactly what you are approving, so nothing can slip through unintentionally.

The iBanFirst mobile app replaces Google Authenticator, which is increasingly vulnerable to phishing attacks. Unlike a time-based code, the app ties each approval to a specific operation, making it far harder for attackers to intercept or replicate your codes.

Setting up the app takes just a few minutes. Go to Settings > Security > Two-Factor Authentication in your iBanFirst account to get started.

Verification of Beneficiaries (VoB)

Our Verification of Beneficiaries (VoB) feature automatically checks that a beneficiary's account details match the name you have provided before a payment is sent. It applies to EUR and GBP payments, including cross-currency scenarios.

VoB runs automatically when you:

  • Add a new beneficiary or modify an existing one in the Eurozone or the UK

  • Make a payment to a recipient in the Eurozone or the UK

  • Send a GBP payment from a EUR account

  • Send an EUR payment from a GBP account

You will receive one of three results:

1. Match: The account details match the information provided and your payment can be finalised.

2. Partial match: If a few details don't match, review them before proceeding.

3. No match: If the details don't match, verify with your contact before proceeding.

Once verified, a beneficiary's status is automatically updated in the Beneficiaries section of the platform, giving you clear visibility for future payments.

If you receive a partial match or no match notification, we strongly recommend you confirm the account details directly with your contact before sending any funds.

User rights and access control

To keep your account secure, make sure you understand what each team member can do on the iBanFirst platform. Review their permissions to see who can carry out sensitive operations, such as creating beneficiaries, preparing payments and validating them.

You can control exactly what each person in your team can see and do on the iBanFirst platform. There are four user roles available:

Role

Description

Admin

Full access to all features, including user management, settings and financial operations.

Payments & Trades

Can create and validate payments and FX trades. Cannot manage users or settings.

Custom

A flexible role with permissions tailored to your company's needs. Contact your account manager to configure.

Read-only

Can view accounts, transactions and documents, but cannot create, validate or modify anything.

Key permissions by role:

  • Creating and validating payments: available to Admin and Payments & Trades roles

  • Managing beneficiaries: available to Admin and Payments & Trades roles

  • Adding and modifying users: available to Admin only

  • Viewing accounts and transactions: available to all roles

You can manage user roles at any time under Settings > Users > Modify User.

Remember to remove people that are not in your team anymore.

Payment validation rules

Beyond user roles, you can add an extra layer of control by setting up payment validation rules. These determine how many approvals a payment needs before it can be executed.

The available validation rules are:

1. Separate creation and validation roles. Prevent the same person from both creating and approving a payment. This separation reduces the risk of unauthorised transactions.

2. Number of required signatures. Set how many users must sign off on a payment before it can be sent — from one signature up to however many your process requires.

3. Payment amount thresholds. Assign a maximum payment amount to individual users. Any payment above that amount requires validation from another user.

4. User group-based approval. Require signatures from users in different teams or locations — for example, one approval from a local office and one from headquarters.

Note that the final signature does not automatically execute the payment. The payment must still be validated within the platform after all required signatures are collected.

To set up number of signatures or group-based rules, contact your account manager.

Monitoring and controlling access

Approving login attempts

Every time someone logs in to the iBanFirst platform, a notification is sent to the account holder's iBanFirst mobile app. You can approve or deny each login attempt individually. If you receive a notification you don't recognise, deny it immediately and contact our support team.

Locking and unlocking devices

If a device is lost, stolen or no longer in use, you can lock it directly from the platform. Go to Settings > Security to manage your registered devices. Admin users can also lock or unlock devices for other users in their organisation.

Best practices

  • Keep your iBanFirst mobile app installed and notifications enabled at all times.

  • Review your user list regularly and remove access for anyone who has left your organisation.

  • Set payment amount thresholds for users who don't require high-value transaction rights.

  • Contact your account manager if you want to review or tighten your validation rules.

Have a question? Reach out to our team at [email protected].

Did this answer your question?