PT PMA Signatory Change: Bank Resolutions, KYC, and Token Handover
A post-opening workflow for replacing signers, updating the bank mandate, refreshing KYC, transferring credentials, and proving that former access has ended.
A PT PMA signatory change requires two connected approvals: a valid corporate decision that identifies the new authority and the bank’s acceptance and implementation of that decision. A shareholder or board resolution alone does not switch the bank’s records, and a bank form cannot grant power that conflicts with the deed or governing corporate approvals. The cutover should inventory every account, currency, signature rule, digital user, token, card, API credential, beneficiary approval, statement channel, and recovery contact before any former signer leaves.
The exact documents depend on whether the change follows a director amendment, a new delegation, a temporary absence, a control redesign, or a personnel exit, and on the bank’s current requirements. OJK Regulation No. 8 of 2023 supports ongoing customer and beneficial-owner due diligence, so a change in management, ownership, control, authority, identification, residence, or transaction profile can trigger more than a signature update. The PT PMA should maintain dual control during transition where the valid mandate and bank system allow it, then revoke former access immediately at the verified cutover point.
Key takeaways
- Corporate approval and bank implementation are separate completion states.
- Read the current deed representation clause before drafting the bank resolution.
- Signer, account-opening representative, digital maker, checker, releaser, and administrator are different roles.
- Remove recovery channels and credentials as well as visible signer names.
- Close the change only after the bank confirms the mandate and the PT PMA tests the required transactions.
In this article
Signatory change cutover register
The register should cover legal authority and every operational access path. A signer is not fully removed while a token, user, card, recovery email, or beneficiary privilege remains active.
| Change object | Required action | Cutover evidence |
|---|---|---|
| Corporate authority | Adopt valid resolution and any deed amendment | Signed decision and effective date |
| Bank mandate | Submit bank forms and signatures | Bank acceptance or implemented status |
| KYC identity | Verify new and changed persons | Accepted ID and supporting record |
| Digital users | Create, amend, or revoke roles and limits | User report and approval matrix |
| Credentials | Recover, return, disable, or reissue tokens and cards | Custody and revocation record |
| Operations | Test payments, statements, alerts, and recovery | Successful controlled test and close sign-off |
Map the full signatory change surface
Inventory every account, mandate, digital role, token, recovery route, and critical payment before drafting the resolution.
Identify every account and authority path affected
The PT PMA should begin with a complete inventory of bank accounts, currencies, products, branches, signatory combinations, transaction thresholds, digital users, administrators, tokens, cards, APIs, cheque facilities, statements, alerts, and recovery channels. The inventory must include accounts believed to be dormant because old credentials or authority can remain a control risk even when the balance is low.
The trigger should be classified as a director or officer change, a delegated signer change, a temporary arrangement, an internal-control redesign, or an emergency access event. Each trigger has different corporate and bank evidence. The inventory owner should also identify pending payments and periods when the old and new mandates could overlap or leave no one able to transact.
Stop condition
Do not draft the resolution until the company knows every system and authority object that the change must reach.
- List all banks, accounts, currencies, facilities, and home branches.
- Export current signer, user, role, limit, and credential reports.
- Identify pending transactions, standing instructions, and critical payment dates.
- Mark former employee, director, shared, generic, and dormant access for review.
Use the Indonesia company bank evidence guide to connect each account to its current mandate file.
Draft authority from the deed and effective corporate records
The new bank resolution should follow the PT PMA’s current representation clause, corporate organs, and approval rules. Indonesia’s Limited Liability Company Law framework governs directors and company authority, while the deed and amendments state the company-specific position. A director amendment may require notarial and Ministry steps before the bank accepts the new management record; a delegated signatory may need a narrower resolution or power.
The resolution should identify the bank, affected accounts or account classes, authorized signers, signing combinations, limits, digital roles, delegation and substitution, credential receipt, document authority, effective date, revocation, and superseded decisions. Ambiguous language such as ‘all banking matters’ can grant more power than the control model intends.
Record standard
Adopt one prospective effective position and preserve the superseded mandate rather than backdating the change.
- Verify current directors, representation clauses, and approval thresholds.
- Address conflicts, joint authority, and temporary transition rules.
- Name the revoked resolutions, powers, and people explicitly.
- Coordinate any deed amendment and Ministry evidence needed by the bank.
Read the PT PMA power-of-attorney guide before delegating to a non-director.
Pre-clear the resolution and bank refresh
Align deed authority, effective corporate records, bank forms, identity evidence, attendance, and implementation timing.
Pre-clear the bank forms and KYC refresh
The PT PMA should ask each bank and branch for the current change-of-mandate forms, identification rules, original or certified documents, signatures, attendance, turnaround, and digital-user procedures before executing the corporate pack. Published requirements from Bank Mandiri and BCA show that corporate authority, identification, management, and powers matter, but the bank may request additional current evidence.
A new signer’s identity, tax or residence evidence, role, employer, source of authority, and contact data must be consistent. If the change also affects directors, shareholders, beneficial owners, address, business activity, or expected transactions, the bank may refresh the broader customer file. The company should answer that refresh with the same authoritative data used in its corporate and OSS records.
Decision rule
Do not assume the bank will implement the mandate on the day it receives the resolution; obtain the process status and effective confirmation.
- Confirm form version, signatories, witness or specimen rules, and attendance.
- Prepare current deed, amendments, Ministry evidence, NIB, NPWP, and IDs as requested.
- Disclose linked management, ownership, UBO, address, or business changes.
- Record the bank case number, owner, expected cutover, and escalation path.
Use the PT PMA bank requirements guide to build the refresh pack.
Execute a controlled token and user cutover
The operational change should create and test the new user and credential path before disabling the old path when the valid authority and bank system permit a controlled overlap. The PT PMA should never ask an outgoing signer to transfer a password, PIN, one-time code, biometric profile, or personal recovery access. Tokens, cards, devices, and administrator rights should be returned, reissued, or revoked through the bank-approved process.
The cutover runbook should specify the exact time, responsible bank officer, company administrator, new and former users, accounts, roles, limits, pending payments, beneficiary controls, and emergency rollback. Recovery emails, mobile numbers, physical delivery addresses, and service contacts are as important as visible transaction roles because they can re-enable access.
Evidence rule
The outgoing person is removed only when every credential and recovery route is disabled or reassigned and evidenced.
- Create and verify new users under the approved role matrix.
- Return or disable tokens, cards, cheque books, APIs, and shared devices.
- Change recovery contacts, alert recipients, and statement delivery.
- Review saved beneficiaries, standing instructions, and pending approvals.
Connect the runbook with the post-registration control checklist when the change follows a new director or address.
Regulatory Notes and Limitations
Corporate and bank authority depend on the actual deed, valid resolutions, effective officer records, account terms, and bank procedures. A change can require broader legal, notarial, Ministry, OSS, tax, UBO, contract, or KYC work.
- A corporate resolution does not become a bank-system change until the bank accepts and implements it.
- Passwords, PINs, one-time codes, and personal biometric or recovery access should not be transferred between users.
- A director, ownership, control, or business-profile change may trigger full or partial ongoing due diligence.
- Emergency continuity should not leave an unauthorized former signer or convenient nominee with account control.
Official References and Review Basis
Primary materials were checked on July 31, 2026. These links support the regulatory and banking framework used in this article; they do not replace a matter-specific legal, tax, licensing, accounting, security, or bank review.
- Limited Liability Company Law No. 40 of 2007 : Company-law framework for shares, capital, corporate organs, records, and authority, as amended.
- OJK Regulation No. 8 of 2023 : Customer due diligence, beneficial-owner review, ongoing monitoring, and electronic verification framework.
- BNI Giro corporate-account requirements : Published checklist covering the deed, NIB, NPWP, management composition, authorized official, and initial deposit.
- Bank Mandiri Giro requirements : Published corporate current-account documents, identity, authority, and power-of-attorney conditions.
- BCA Current Account requirements : Published corporate account, representative, power-of-attorney, management, shareholder, NIB, and license requirements.
Test the new mandate and retain the close pack
The PT PMA should test the new authority with low-risk transactions that exercise the required combinations, limits, currencies, statements, alerts, and recovery procedures. A successful login does not prove that a joint approval, higher-value payment, FX instruction, beneficiary creation, payroll file, or emergency recovery will work. Test only transactions the company is authorized to perform and document the result.
The close pack should contain the trigger, approvals, effective corporate records, bank forms, KYC evidence, bank confirmation, before-and-after access reports, credential custody, test results, outstanding facilities, and a sign-off from corporate, finance, and control owners. Failed or pending functions remain exceptions with an interim payment plan.
Control point
Close the project when former access is evidenced as revoked and the new mandate can complete the company’s critical payment scenarios.
- Test view, maker, checker, releaser, administrator, and statement roles.
- Verify transaction limits and joint-signature combinations.
- Confirm alerts, recovery, contact centers, and escalation identities.
- Schedule the next access recertification and KYC refresh date.
Use the post-incorporation compliance guide to retain the close evidence under the company’s ongoing control calendar.
Compare the proposed action with HSJGlobal’s Indonesia company registration scope before changing the company or operating plan.
Close a PT PMA signatory change only after old access is revoked and tested
The effective mandate is the position that valid corporate records and the bank system both recognize. Build the change from the deed, adopt a precise resolution, pre-clear the bank process, and treat every digital role, token, card, and recovery channel as part of the same authority cutover.
Do not close on the strength of a signed resolution or new login alone. Require evidence that former access is gone and test the combinations, limits, statements, and recovery path the PT PMA needs for real operations.
Prove former access has ended
Close the change with bank confirmation, before-and-after user reports, credential revocation, transaction tests, and signed exceptions.
Frequently asked questions