Skip to article
HSJGlobal
Bank authority cutover

PT PMA Signatory Change: Bank Resolutions, KYC, and Token Handover

A post-opening workflow for replacing signers, updating the bank mandate, refreshing KYC, transferring credentials, and proving that former access has ended.

A PT PMA signatory change requires two connected approvals: a valid corporate decision that identifies the new authority and the bank’s acceptance and implementation of that decision. A shareholder or board resolution alone does not switch the bank’s records, and a bank form cannot grant power that conflicts with the deed or governing corporate approvals. The cutover should inventory every account, currency, signature rule, digital user, token, card, API credential, beneficiary approval, statement channel, and recovery contact before any former signer leaves.

The exact documents depend on whether the change follows a director amendment, a new delegation, a temporary absence, a control redesign, or a personnel exit, and on the bank’s current requirements. OJK Regulation No. 8 of 2023 supports ongoing customer and beneficial-owner due diligence, so a change in management, ownership, control, authority, identification, residence, or transaction profile can trigger more than a signature update. The PT PMA should maintain dual control during transition where the valid mandate and bank system allow it, then revoke former access immediately at the verified cutover point.

Key takeaways

  • Corporate approval and bank implementation are separate completion states.
  • Read the current deed representation clause before drafting the bank resolution.
  • Signer, account-opening representative, digital maker, checker, releaser, and administrator are different roles.
  • Remove recovery channels and credentials as well as visible signer names.
  • Close the change only after the bank confirms the mandate and the PT PMA tests the required transactions.

In this article

Signatory change cutover register

The register should cover legal authority and every operational access path. A signer is not fully removed while a token, user, card, recovery email, or beneficiary privilege remains active.

Change object Required action Cutover evidence
Corporate authority Adopt valid resolution and any deed amendment Signed decision and effective date
Bank mandate Submit bank forms and signatures Bank acceptance or implemented status
KYC identity Verify new and changed persons Accepted ID and supporting record
Digital users Create, amend, or revoke roles and limits User report and approval matrix
Credentials Recover, return, disable, or reissue tokens and cards Custody and revocation record
Operations Test payments, statements, alerts, and recovery Successful controlled test and close sign-off

Map the full signatory change surface

Inventory every account, mandate, digital role, token, recovery route, and critical payment before drafting the resolution.

Identify every account and authority path affected

The PT PMA should begin with a complete inventory of bank accounts, currencies, products, branches, signatory combinations, transaction thresholds, digital users, administrators, tokens, cards, APIs, cheque facilities, statements, alerts, and recovery channels. The inventory must include accounts believed to be dormant because old credentials or authority can remain a control risk even when the balance is low.

The trigger should be classified as a director or officer change, a delegated signer change, a temporary arrangement, an internal-control redesign, or an emergency access event. Each trigger has different corporate and bank evidence. The inventory owner should also identify pending payments and periods when the old and new mandates could overlap or leave no one able to transact.

Stop condition

Do not draft the resolution until the company knows every system and authority object that the change must reach.

  • List all banks, accounts, currencies, facilities, and home branches.
  • Export current signer, user, role, limit, and credential reports.
  • Identify pending transactions, standing instructions, and critical payment dates.
  • Mark former employee, director, shared, generic, and dormant access for review.

Use the Indonesia company bank evidence guide to connect each account to its current mandate file.

Draft authority from the deed and effective corporate records

The new bank resolution should follow the PT PMA’s current representation clause, corporate organs, and approval rules. Indonesia’s Limited Liability Company Law framework governs directors and company authority, while the deed and amendments state the company-specific position. A director amendment may require notarial and Ministry steps before the bank accepts the new management record; a delegated signatory may need a narrower resolution or power.

The resolution should identify the bank, affected accounts or account classes, authorized signers, signing combinations, limits, digital roles, delegation and substitution, credential receipt, document authority, effective date, revocation, and superseded decisions. Ambiguous language such as ‘all banking matters’ can grant more power than the control model intends.

Record standard

Adopt one prospective effective position and preserve the superseded mandate rather than backdating the change.

  • Verify current directors, representation clauses, and approval thresholds.
  • Address conflicts, joint authority, and temporary transition rules.
  • Name the revoked resolutions, powers, and people explicitly.
  • Coordinate any deed amendment and Ministry evidence needed by the bank.

Read the PT PMA power-of-attorney guide before delegating to a non-director.

Pre-clear the resolution and bank refresh

Align deed authority, effective corporate records, bank forms, identity evidence, attendance, and implementation timing.

Pre-clear the bank forms and KYC refresh

The PT PMA should ask each bank and branch for the current change-of-mandate forms, identification rules, original or certified documents, signatures, attendance, turnaround, and digital-user procedures before executing the corporate pack. Published requirements from Bank Mandiri and BCA show that corporate authority, identification, management, and powers matter, but the bank may request additional current evidence.

A new signer’s identity, tax or residence evidence, role, employer, source of authority, and contact data must be consistent. If the change also affects directors, shareholders, beneficial owners, address, business activity, or expected transactions, the bank may refresh the broader customer file. The company should answer that refresh with the same authoritative data used in its corporate and OSS records.

Decision rule

Do not assume the bank will implement the mandate on the day it receives the resolution; obtain the process status and effective confirmation.

  • Confirm form version, signatories, witness or specimen rules, and attendance.
  • Prepare current deed, amendments, Ministry evidence, NIB, NPWP, and IDs as requested.
  • Disclose linked management, ownership, UBO, address, or business changes.
  • Record the bank case number, owner, expected cutover, and escalation path.

Use the PT PMA bank requirements guide to build the refresh pack.

Execute a controlled token and user cutover

The operational change should create and test the new user and credential path before disabling the old path when the valid authority and bank system permit a controlled overlap. The PT PMA should never ask an outgoing signer to transfer a password, PIN, one-time code, biometric profile, or personal recovery access. Tokens, cards, devices, and administrator rights should be returned, reissued, or revoked through the bank-approved process.

The cutover runbook should specify the exact time, responsible bank officer, company administrator, new and former users, accounts, roles, limits, pending payments, beneficiary controls, and emergency rollback. Recovery emails, mobile numbers, physical delivery addresses, and service contacts are as important as visible transaction roles because they can re-enable access.

Evidence rule

The outgoing person is removed only when every credential and recovery route is disabled or reassigned and evidenced.

  • Create and verify new users under the approved role matrix.
  • Return or disable tokens, cards, cheque books, APIs, and shared devices.
  • Change recovery contacts, alert recipients, and statement delivery.
  • Review saved beneficiaries, standing instructions, and pending approvals.

Connect the runbook with the post-registration control checklist when the change follows a new director or address.

Regulatory Notes and Limitations

Corporate and bank authority depend on the actual deed, valid resolutions, effective officer records, account terms, and bank procedures. A change can require broader legal, notarial, Ministry, OSS, tax, UBO, contract, or KYC work.

  • A corporate resolution does not become a bank-system change until the bank accepts and implements it.
  • Passwords, PINs, one-time codes, and personal biometric or recovery access should not be transferred between users.
  • A director, ownership, control, or business-profile change may trigger full or partial ongoing due diligence.
  • Emergency continuity should not leave an unauthorized former signer or convenient nominee with account control.

Official References and Review Basis

Primary materials were checked on July 31, 2026. These links support the regulatory and banking framework used in this article; they do not replace a matter-specific legal, tax, licensing, accounting, security, or bank review.

Test the new mandate and retain the close pack

The PT PMA should test the new authority with low-risk transactions that exercise the required combinations, limits, currencies, statements, alerts, and recovery procedures. A successful login does not prove that a joint approval, higher-value payment, FX instruction, beneficiary creation, payroll file, or emergency recovery will work. Test only transactions the company is authorized to perform and document the result.

The close pack should contain the trigger, approvals, effective corporate records, bank forms, KYC evidence, bank confirmation, before-and-after access reports, credential custody, test results, outstanding facilities, and a sign-off from corporate, finance, and control owners. Failed or pending functions remain exceptions with an interim payment plan.

Control point

Close the project when former access is evidenced as revoked and the new mandate can complete the company’s critical payment scenarios.

  • Test view, maker, checker, releaser, administrator, and statement roles.
  • Verify transaction limits and joint-signature combinations.
  • Confirm alerts, recovery, contact centers, and escalation identities.
  • Schedule the next access recertification and KYC refresh date.

Use the post-incorporation compliance guide to retain the close evidence under the company’s ongoing control calendar.

Compare the proposed action with HSJGlobal’s Indonesia company registration scope before changing the company or operating plan.

Close a PT PMA signatory change only after old access is revoked and tested

The effective mandate is the position that valid corporate records and the bank system both recognize. Build the change from the deed, adopt a precise resolution, pre-clear the bank process, and treat every digital role, token, card, and recovery channel as part of the same authority cutover.

Do not close on the strength of a signed resolution or new login alone. Require evidence that former access is gone and test the combinations, limits, statements, and recovery path the PT PMA needs for real operations.

Prove former access has ended

Close the change with bank confirmation, before-and-after user reports, credential revocation, transaction tests, and signed exceptions.

Frequently asked questions

Does a new board resolution immediately replace the bank signatory?
No. The resolution provides corporate authority, but the bank must accept the required documents and implement the mandate in its own records and systems before the change is operational.
Must every signatory be a PT PMA director?
Not necessarily, subject to the deed, valid corporate authority, and bank acceptance. A delegated signer or representative may need a specific resolution or power and separate KYC.
Can an outgoing signer hand a bank token to the replacement?
Use the bank-approved return, revocation, reassignment, or reissue process. Do not share passwords, PINs, one-time codes, biometrics, or personal recovery channels.
What if the new mandate is not ready before the director leaves?
Create a lawful interim payment and authority plan with the bank and company advisers. Do not keep undisclosed former access or grant uncontrolled authority merely for convenience.
What should be tested after the change?
Test required account views, user combinations, limits, beneficiaries, payments, FX or payroll functions, statements, alerts, administrator controls, and recovery procedures, then record exceptions.
Jaslyn

Hey! I'm Jaslyn

Leave our friendly team a message and we'll be in touch in no time.

We will never share your details with any third party. Please see our Privacy Policy for more details.

Submission Successful!

Thank you for your inquiry. Our expert team will contact you shortly with a customized solution.

On this page
Talk to an Expert