A well-designed TMS will not let one person create and approve a payment. A poorly designed last mile will let that same person download the file, edit a beneficiary, and drop it on an SFTP folder that the bank still trusts. We have seen this pattern in host-to-host channels that were set up during a rushed bank-migration weekend and never revisited.

Integrity of the file means three things in practice. The format and signing must match what the bank will accept without a repair. The channel entitlements at the bank must match the dual-control story in the TMS. And nobody with a day-to-day operations login should be able to replace the file after it has been approved.

Encryption keys and signing certificates are often held by a single IT owner, or sit on a shared jump host. That is a privileged-access finding as much as a payments finding. We treat it as both.

If your bank still offers a portal release as a fallback, test that path too. Fallback channels are where dual control is ‘temporarily’ reduced and then left that way. The audit trail in the TMS will look clean. The money will still have moved.

More notes · Talk to the practice