Post-opening banking controls
Indonesia Business Banking Controls for New PT PMAs: Payments, Tokens, and Approval Limits
Turn an approved corporate account into a secure payment system with maker-checker roles, controlled credentials, evidence, limits, and recovery.
A new PT PMA bank account is not operationally complete until the company has controlled users, payment roles, approval limits, token and credential custody, beneficiary rules, capital and transaction evidence, statement access, reconciliation, and an incident process. The deed and bank mandate define who may act, while the digital platform implements maker, checker, releaser, administrator, or view-only permissions. Configure the system from the board’s payment policy rather than accepting default access.
Bank platforms differ, and some internal approval rules cannot be implemented electronically. The company may need manual compensating controls for related parties, international payments, new beneficiaries, or budget exceptions. Foreign directors and finance teams also need workable token delivery, overseas access, call-back, and recovery. Test all controls with low-risk transactions before payroll, tax, supplier, or capital-use deadlines depend on them.
Configure controls before the first payment
Map deed authority, bank mandate, users, tokens, limits, beneficiaries, and evidence into a tested control design.
In this article
Key takeaways
- Separate platform administration, payment creation, approval, release, and reconciliation where practical.
- Apply stronger controls to new beneficiaries, related parties, cross-border payments, and unusual currencies.
- Treat tokens, cards, passwords, recovery contacts, and registered devices as controlled company assets.
- The first capital and operating transactions should be pre-indexed and reconciled.
- Review users and limits after any director, employee, provider, budget, or bank change.
The minimum post-opening control stack
Each layer protects a different failure mode. Strong approval limits do not help if one uncontrolled administrator can add users or replace tokens.
| Control layer | Primary risk | Minimum evidence |
|---|---|---|
| Authority | Unauthorized company or bank action | Deed, resolution, mandate |
| User roles | One person creates and releases payments | Role matrix and platform configuration |
| Credentials | Token, password, or recovery takeover | Custody register and secure issue process |
| Limits and beneficiaries | Excess or diverted payment | Approved thresholds and beneficiary controls |
| Transaction evidence | Payment cannot be justified | Invoice, contract, approval, tax and bank record |
| Monitoring and recovery | Late detection or locked operations | Alerts, reconciliation, incident and continuity plan |
Translate the deed and mandate into system roles
Start with the current deed representation clause and the bank mandate, then map authorized acts to the platform’s actual functions. A joint representation requirement may need two releasers or a corporate resolution, while a platform may support maker-checker but not every reserved matter. Document where technology ends and manual governance begins.
Readiness test
No digital user should receive broader practical access than the underlying company and bank authority permits.
- Company representative and account signatory authority.
- Administrator, maker, checker, releaser, and view-only roles.
- Sole, joint, amount, transaction-type, and currency conditions.
- Manual approvals required outside the platform.
Use the PT PMA bank requirements to retain the authority evidence behind the configuration. A document is ready only when its names, dates, authority, and business purpose match the rest of the file.
Protect tokens, credentials, and recovery channels
A physical or digital token, password, registered device, email, phone number, and call-back contact can each control access. Keep an issuance register, named custodian, location, activation date, permitted user, backup, replacement process, and return record. Do not leave root credentials with an external provider or shared personal phone without documented risk acceptance.
Decision test
Test who can reset a password, replace a token, change a phone number, add an administrator, or recover access when the primary director is overseas.
- Company-controlled email, phone, device, and recovery contacts.
- Token and card custody, storage, travel, and return.
- No shared credentials and prompt access revocation.
- Emergency replacement and suspected-compromise process.
Record every credential event and reconcile physical custody during access reviews. Use the result to decide what must be fixed before the next filing or bank contact.
Set payment limits by risk and purpose
A single amount threshold is rarely enough. Routine payroll, tax, approved supplier, new-beneficiary, related-party, capital expenditure, foreign-currency, and international payments have different risks. Use budget status, beneficiary maturity, transaction type, amount, geography, evidence, and related-party status to determine approval.
Evidence test
Design limits from the cash forecast and board authority, then test whether the bank platform can enforce them without blocking ordinary operations.
- Per-user, per-transaction, daily, currency, and account limits.
- New-beneficiary cooling, verification, or second approval.
- Enhanced approval for related-party and cross-border payments.
- Budget exception and urgent-payment documentation.
Review limit increases independently and time-limit temporary changes. Keep the evidence together so the same answer can be supported across the notary, OSS record, tax file, and bank review.
Test the high-risk payment scenarios
Run capital, new-vendor, related-party, international, urgent, and unavailable-signer cases through the proposed workflow.
Control beneficiaries and payment evidence
Beneficiary fraud can occur even when the payment amount is approved. Independently verify new or changed bank details using a trusted contact channel, retain contracts and invoices, confirm goods or service acceptance, and match tax treatment. Payment references should state the commercial purpose and support bank or audit follow-up.
Execution test
Separate vendor onboarding from payment release and use call-back controls for bank-detail changes.
- Vendor identity, contract, tax, and bank account ownership.
- Independent verification of new or changed bank details.
- Purchase, receipt, invoice, approval, and payment match.
- Sanctions, geography, currency, and related-party screening as applicable.
Apply the same discipline to the first capital transfer using the capital evidence guide. Assign an owner and a completion condition instead of treating the item as a general reminder.
Reconcile statements and monitor unusual activity
Finance should retrieve statements independently and reconcile them to the ledger, invoices, tax, payroll, and funding instruments promptly. Alerts should cover large, unusual, failed, reversed, new-country, new-beneficiary, cash, and after-hours activity. A service provider that prepares the reconciliation should not be the only person with bank access or authority to clear exceptions.
Mismatch test
Define daily, weekly, and monthly reviews and an unresolved-item age limit. Escalate unexplained transactions immediately.
- Daily review of alerts, balances, and high-risk activity.
- Regular bank reconciliation by an independent reviewer.
- Funding instrument and capital-use reconciliation.
- Exception log with owner, evidence, age, and resolution.
Retain statements and audit logs in a company-controlled repository. If two records give different answers, resolve the source record first and then refresh downstream documents.
Prepare fraud response and business continuity
The company should know how to freeze users, contact the bank, preserve logs, notify management, replace credentials, continue payroll or tax, and investigate without destroying evidence. Continuity also covers unavailable signers, bank system outages, branch closures, director changes, and lost tokens. A secondary account may help only if it is funded, controlled, and maintained.
Control test
Run a tabletop exercise for a changed vendor account, stolen token, unauthorized payment, unavailable joint signer, and blocked international transfer.
- Bank emergency contact and authorized incident spokesperson.
- Immediate freeze, evidence preservation, and decision authority.
- Backup signer, credential, statement, and critical-payment route.
- Post-incident KYC, mandate, limit, and control remediation.
Include access and payment review in the PT PMA compliance calendar. Document who can approve the decision, who can execute it, and what record will prove completion.
Before execution, align these controls with the Indonesia company registration service scope and the company’s licensed operating plan. Review the Indonesia company registration scope .
Regulatory Notes and Limitations
Internal controls should be proportionate to the PT PMA’s scale and risks and aligned with bank functionality. This article does not replace cyber, fraud, sanctions, tax, or audit advice.
- Digital platform rights should not exceed lawful company and bank authority.
- Bank transaction monitoring and evidence requests continue after account opening.
- Payment evidence should be retained under applicable company, tax, accounting, contract, and data rules.
- External providers should not hold uncontrolled root access or sole reconciliation authority.
- Notify the bank promptly through its process after compromised credentials, unauthorized activity, or mandate changes.
Official References and Review Basis
Primary materials were checked on July 28, 2026. The links below support the regulatory and banking framework used in this article; they do not replace a matter-specific legal, tax, licensing, or bank review.
- Limited Liability Company Law No. 40 of 2007 : Company-law framework for share capital, corporate organs, records, and shareholder rights.
- OJK Regulation No. 8 of 2023 : CDD, beneficial-owner review, enhanced measures, and face-to-face or electronic verification framework for financial services.
- BNI Giro corporate-account requirements : Published bank checklist for deeds, NIB, NPWP, management composition, authorized officials, and initial deposit.
- Bank Mandiri Giro requirements : Published eligibility, supporting-document, blacklist, and power-of-attorney conditions for corporate current accounts.
- BCA Current Account requirements : Published corporate current-account rules, including authorized representatives and powers of attorney.
Practical conclusion
A new PT PMA account becomes a business system only after authority, users, credentials, limits, beneficiaries, evidence, monitoring, and recovery are controlled. Defaults chosen during onboarding can create fraud or continuity problems months later.
Translate the deed into platform roles, protect credentials, set risk-based limits, verify beneficiaries, reconcile independently, and rehearse the incident plan before high-value operations begin.
Build a recoverable banking system
Document monitoring, reconciliation, revocation, fraud response, token replacement, and business continuity.
Frequently asked questions