Features How it works Pricing FAQ The Bursar's Handbook
Financial Controls

Banking Security and Payment Approval: Keeping School Money Safe

The school bank account is the heart of the money, and in most schools it runs on habits nobody ever wrote down: a shared password, a standing order, a signatory list that is out of date. This guide turns those habits into rules.

Padlock close-up representing financial security
On this page

    School banking runs on trust, and trust needs guardrails. Most school accounts have more money moving through them than anyone realises, and the way that money leaves the account is usually decided by a handful of habits that have simply grown there over the years. This guide sets out the basics, from logging in safely to approving a payment, so the habits become rules that protect the money and the people.

    The basics of online banking security

    The bank account is one of the few places where the school cannot get the money back easily, so the login is worth protecting like the door to the safe:

    • One user, one login, no sharing. The school banking profile is never shared between staff. Each person who needs access gets their own profile with their own credentials, and the school knows who logged in and when.
    • Separate the banking from personal devices. Banking sessions do not belong on a phone or laptop that is shared with family or used for personal browsing.
    • Log out, always. A saved session on a shared office machine is an open safe. The banking session ends when the task ends.
    • Use the bank's security features. Two-factor authentication, SMS confirmations and payment limits are not optional extras; they are the modern signatory. Turn them on and keep them on.
    • Review who has access, regularly. The list of users, limits and devices tied to the account gets checked at least every term, and immediately after any staffing change.

    The rule of thumb: whatever it takes for the person with access to prove it is really them, the school wants it enabled. The inconvenience of a second confirmation is nothing compared with the cost of a drained account.

    Signatories and who can move money

    Signatories are the school's written answer to the question "who can move the money?", and they go stale if nobody reviews them:

    • At least two signatories on every account. For the school's main fee account, a second authorised person should be required on larger payments where the bank allows it, and present in principle on all of them.
    • Current people only. The bursar who left last term, the principal who retired, the board member who resigned - none of them belongs on the signatory list. Removing them is a ten-minute job that schools routinely postpone for a year.
    • Write down the threshold. How much needs a second signatory, who the alternates are when someone is on leave, and how emergency payments work. Written, current, and known to the whole office.
    • Keep the list where the board can see it. The signatory list is a governance document. The board should review it once a year as a standing agenda item.

    A signatory list is only as good as the last time it was checked. The year-end checklist and a termly banking review are the two moments most schools actually do it - so put it on both.

    A payment approval routine that is actually used

    The purpose of an approval routine is not paperwork; it is a second pair of eyes on the moments that matter. A routine that works looks like this:

    • One person prepares, one person approves. The person who raises the payment is never the person who authorises it, wherever the school has two people available.
    • Approve against the invoice and the budget. The approver looks at what is being paid, whether the school owes it, and whether it was budgeted. A rubber-stamp approval is a control in name only.
    • New payees get the extra look. First payments to a new beneficiary - especially after a "changed banking details" email - get a verification call and a second approval. Every time.
    • Record the approval. The approver's name, the date and the supporting invoice live with the payment record, so the trail exists before anyone asks for it.
    • Review the payments the school made, not just the ones it planned. Month end includes a look at what actually left the account, matched back to invoices. This is the check that catches the payment nobody approved.

    Approval routines fail in two ways: they are not followed, or they are so heavy that everyone works around them. The right size is the one the school actually runs every time, with a quick second look rather than a board meeting.

    Money coming in: confirmation before spend

    Security is not only about payments leaving. The school also needs to know, quickly, when expected money did not arrive:

    • Reconcile fee receipts to the bank promptly. A parent who paid and the school has no record is either a system error or the first sign of a payment being diverted. Either way it needs a fast answer.
    • Match deposits to accounts. Every deposit on the statement should tie to a fee account, a payment or a known source. Unmatched deposits accumulate into confusion.
    • Watch for payment detail changes from parents. A parent's payment instruction changing the destination of their school fees is worth confirming directly - that is how legitimate money gets quietly redirected.
    • Check dormant and seldom-used accounts. Savings accounts, trust accounts and old accounts with balances are exactly the accounts nobody watches. The quarterly checklist covers them.

    Money coming in is the school's oxygen, and it deserves the same watchful eye as money going out. The daily and weekly fee collection routine, with reconciliations run weekly, is where most of this happens.

    Vishing, phishing and the fake invoice

    The biggest threat to school bank accounts is not someone guessing a password. It is social engineering: fraudsters calling, emailing or impersonating someone until a real payment is made to the wrong place. SABRIC's safety guidance keeps returning to the same theme - the human being persuaded, not the system hacked. The defences are simple and repeatable:

    • The bank never asks for passwords or OTPs by phone or message. Anyone asking is a fraudster. The school ends the call and phones the number on the back of the card, not the number in the message.
    • Verify changed banking details on a known number. Email, letterhead and phone numbers in the email are all suspect. The number the school already has on file is the only safe number.
    • Urgency is a script. "Pay now, confirm later" is how social engineering works. The school's answer to urgency is the same every time: verify first, pay after.
    • The principal's email can be spoofed. An instruction from leadership asking for a payment or a change of details gets confirmed out of band - a phone call, or in person.
    • Report it. If an attempt is recognised, it gets reported to the bank and to the SAPS, and the story gets shared with the office so the whole team knows the pattern.

    Schools are targeted precisely because a school office is busy, friendly and reluctant to make the principal wait. Politeness is the vulnerability. A single verification habit, applied to every unusual request, closes it.

    Cards and accounts you might not think about

    School money sits in more places than the main account, and each one is a smaller, softer target:

    • Debit and credit cards. Who holds them, what limits they carry, and what the bank's app alerts are set to. A card used online is a card that needs a spending limit and an alert on every charge.
    • Petty cash floats and cash drawers. Fixed floats, counted and signed for on every handoff, banked promptly. Cash is money too, and it is the kind nobody can trace after the fact.
    • Digital wallets and payment gateway accounts. The accounts parents actually pay into - school fee portals, payment gateways - get their own passwords, their own two-factor settings and their own review, separate from the main banking login.
    • Trust and fundraising accounts. Money held for others attracts less scrutiny and more risk. Same rules: signatories, reconciliations and review.

    Every place the school stores money is a place to protect. The review that covers all of them at once is the quarterly financial controls check - the quarterly checklist runs through bank confirmations, dormant accounts and supplier checks in one sitting.

    Sources & further reading

    This page is general information, not financial or legal advice. Banking products, features and limits differ by provider. Confirm what applies to your school with your bank before relying on it.