Adding or removing a business bank account signatory in the UK
How UK businesses should update bank mandates when directors, partners, trustees or staff change, and how to avoid leaving the wrong people with access.
Ask the bank which mandate or user-access process applies to your account, then update it promptly when an authorised person joins, leaves or changes role. Removing an app user is not always the same as changing the legal bank mandate, so confirm both. Keep board, partnership or trustee approval records where your organisation requires them, and test the new approval setup before a time-critical payment is due.
A bank signatory and an online-banking user are not always the same thing
A signatory is a person the bank recognises as authorised to act under the account mandate. Online banking can add another layer of permissions: one user may be able to view transactions, another to create payments, and a director or second user may be required to approve them. When staff change, treat the legal mandate and digital access as two separate checklists. Removing a former employee from the app does not necessarily remove every authority recorded by the bank, while changing a mandate does not automatically tell your accounting platform or expense-card system that the person has left.
Before making changes, list every place the person can act for the business: the bank mandate, online banking, mobile app, payment approval workflow, employee cards and connected accounting software. Our guide to controlling employee business debit cards covers the card side of the same problem.
Use the organisation’s own approval rules before contacting the bank
For a limited company, the bank may want evidence that the people requesting the change have authority to do so. Partnerships, charities and community organisations can have different governing documents and approval rules. A charity, for example, should keep a clear record of who is on its bank mandate and should regularly review whether that mandate is still appropriate. The Charity Commission also recommends strong separation of duties and, where available, dual authorisation for online banking.
Keep the internal decision with the banking record. Depending on the organisation, that might be a board minute, trustee decision, partnership record or signed mandate form. The purpose is not paperwork for its own sake: it gives the bank a clean audit trail and prevents a later dispute about who authorised the change.
Remove access quickly when someone leaves or a role changes
The highest-risk moment is often when an authorised person leaves unexpectedly. Do not wait for the next monthly reconciliation if they still have access to payment systems. Use the bank’s official business-banking channel to ask what can be disabled immediately and what requires a formal mandate change. Also reset shared operational processes: stop using shared credentials, recover security devices, revoke connected-app access and review standing payment authorities that person controlled.
If the business uses maker-checker controls, make sure removing one person does not leave the company unable to approve payroll or suppliers. Add the replacement approver before a deadline where possible, then run a low-risk test payment so the new workflow is understood.
Adding a new signatory usually triggers identity and authority checks
Banks must know who controls and operates business accounts, so a new authorised person may be asked for identity information and the bank may need to verify their relationship to the organisation. The exact evidence varies by provider and legal structure. Give the bank consistent names, addresses and dates across your company, partnership or charity records; mismatches can slow an otherwise routine update.
If the change follows a company restructure or new director appointment, update the underlying public or constitutional records first where required. If the business name is changing too, handle that separately using our guide to changing the legal name on a business bank account.
Rebuild payment controls after the mandate changes
Once the bank confirms the change, review payment limits and approval roles rather than assuming the old setup is still suitable. A growing company may need two approvers for large transfers, different limits for finance staff, and separate cards for employees. Charities and other organisations handling money on behalf of others often benefit from stronger segregation of duties even when the bank does not force it.
Keep one current register of bank users and signatories, with the date each person gained or lost access. Reconcile it against the bank at regular intervals. This is a simple control that can catch forgotten users before they become a security problem.
What to do if the bank does not action the change correctly
If an old signatory still appears, a new user cannot approve payments or the bank says it has not received the mandate, ask for a case reference and the exact missing item. Do not submit multiple contradictory forms unless the bank tells you to; duplicates can create further confusion. For urgent security concerns, ask the bank to restrict access first and complete the paperwork second.
If the problem becomes a service complaint, document when the request was submitted, who was meant to be added or removed, what the bank confirmed and any direct loss caused by the delay. That gives the bank a specific outcome to investigate rather than a general complaint that “access is wrong”.
Frequently asked questions
Can I remove a signatory without closing the business account?
Usually yes, provided the remaining people have authority under the account mandate and the bank’s rules. The provider may require a new mandate or formal approval evidence.
Should every employee with a business debit card be a signatory?
No. Cardholder permissions and legal account-signatory authority are separate concepts. Use the minimum access needed for each role.
What should I do first when an authorised employee leaves suddenly?
Secure access immediately through the bank’s official channel, then update the formal mandate and connected systems. Do not rely only on changing an app password.
Sources and verification
- Charity Commission — Internal financial controls for charities
- FCA — Financial crime guide: customer due diligence
Oliver Grant — Markets & Regulation Writer
For a business, signatory maintenance is a control issue rather than an administrative afterthought. I would keep the bank mandate deliberately small, give operational users only the permissions they need and review access whenever a director, partner, trustee or employee changes role. The most common mistake is to think that removing a person from online banking has solved the whole problem. It may not have changed the mandate, card authority, accounting connection or payment workflow. I would therefore use one written offboarding checklist that covers the bank, cards, security devices and connected services together. When adding a new person, I would prepare the authority evidence before starting the bank request and make sure names and addresses match the organisation’s official records. After the change is confirmed, I would test the approval chain before payroll or a large supplier payment is due. For charities and organisations with several decision-makers, dual authorisation and separation of duties are particularly valuable because they reduce the risk that one person can both create and approve a payment. The objective is simple: at any point the business should be able to say exactly who can view, create and authorise movement of money, and the bank’s records should match that answer.
MyBankAnswers uses official provider and UK regulatory sources wherever practical. Information is general and does not constitute financial advice.