Separate users and credentials
Give each user an individual login and only the permissions needed for the role. Shared administrator credentials make activity harder to audit and easier to abuse.
Use approval layers
Dual approval for wires, ACH files, payee changes and unusual amounts can reduce both internal-error and external-fraud risk. Set transaction limits by user where the bank supports them.
Turn on bank controls
Use alerts, positive pay, ACH debit filters or blocks, callback procedures and device/authentication controls appropriate to the payment channels the business uses.
Protect the operating environment
Keep treasury workstations and mobile devices updated, train staff to challenge payment-change requests, and verify sensitive instructions through a known independent channel.
Primary sources and reference material
Design controls so one compromised inbox cannot empty the account.
Good business banking decisions come from matching account structure, controls, insurance, service and payment workflows to how the company actually operates.