Remote PT PMA Banking Continuity: Token Loss, Access Recovery, and Director Changes
A recovery design for tokens, devices, users, mandates, overseas directors, local continuity, bank outages, and emergency payment control.
A remotely managed PT PMA should maintain bank-approved recovery paths for token or device loss, user lockout, mobile-number or email failure, overseas delivery, personnel departure, director or signatory change, bank outage, and suspected compromise. The plan should identify who may report the incident, who can authenticate with the bank, which corporate authority remains effective, how credentials are revoked or reissued, how critical payments are approved during the gap, and what evidence closes recovery. Password, PIN, one-time-code, or token sharing is not continuity.
The recovery route depends on the selected bank, product, account mandate, users, director and signer status, location, identification, and incident. OJK Regulation No. 8 of 2023 provides customer due-diligence and electronic-verification context, but a bank can require current forms, KYC, signatures, originals, attendance, or branch action for recovery and mandate changes. The PT PMA should confirm those procedures while access is healthy, keep verified contacts outside the compromised channel, and test only low-risk scenarios under bank and company approval.
Remote banking continuity scenarios
Each scenario needs a distinct first action and authority check. Treating every failure as a password reset can preserve unauthorized access or delay the real mandate change.
| Scenario | Immediate control | Recovery owner |
|---|---|---|
| Token or device lost | Block credential and preserve incident facts | Bank user and security owner |
| User locked out | Verify identity and approved reset channel | System administrator and bank |
| Phone or email lost | Secure recovery route and change contacts | Corporate KYC owner |
| Employee departure | Revoke all users, devices, alerts, and recovery rights | HR, treasury, and bank |
| Director or signer change | Use valid corporate and bank mandate cutover | Corporate records and treasury |
| Bank platform outage | Activate approved alternate channel or contingency bank | Treasury continuity lead |
| Suspected compromise | Freeze affected access and payments; escalate | Security, board, bank, advisers |
Key takeaways
- Confirm bank recovery procedures before remote access fails.
- Keep an independent inventory of users, tokens, devices, contacts, limits, and authority.
- A user reset, signatory change, and director amendment are different recovery projects.
- Emergency payments must remain within valid corporate and bank authority.
- Test the recovery and contingency route without sharing credentials or granting nominal local control.
Map remote banking dependencies
Inventory every user, signer, token, device, contact, recovery path, limit, critical payment, and branch escalation without storing secrets.
In this article
Inventory remote access, authority, and recovery channels
The PT PMA should maintain a controlled register of every bank, account, currency, signer, maker, checker, releaser, viewer, administrator, token, card, device, registered phone, email, physical delivery address, recovery question, contact-center identity, branch, officer, statement channel, alert, and transaction limit. The register should not contain live passwords, PINs, or one-time codes.
The inventory should link each digital user to current corporate and bank authority and identify country, time zone, device custody, backup person, and revocation trigger. It should distinguish company-controlled contacts from personal contacts and show which failure would prevent the next payroll, tax, supplier, or customer transaction.
Evidence rule
Continuity cannot be approved until management can see every access and recovery dependency from one secure register.
- Export current users, roles, limits, and credential status from each bank.
- Verify branch and contact-center details through official channels.
- Record company-owned phones, emails, addresses, and administrators.
- Map critical payments to required users, combinations, cut-offs, and fallback.
Use the company bank evidence guide to connect users to the accepted mandate.
Respond to token, device, and credential loss
A lost token, phone, card, or device should trigger immediate bank notification through a verified channel, blocking or revocation of the affected credential, preservation of incident facts, and review of pending and recent transactions. The PT PMA should not ask another user to share a token or approve an unfamiliar payment while access is being restored.
The recovery runbook should record the time of loss, user, device, last known location, account access, suspicious activity, bank case, corporate approver, identification required, reissue method, delivery location, interim restrictions, and activation test. If the device may be compromised, company security and legal owners should assess broader systems and notification duties.
Control point
Restore only the minimum required access after the bank and company verify identity, authority, and a clean device or credential path.
- Block the credential and review transactions and beneficiaries immediately.
- Use official bank contacts independent of the lost phone or email.
- Document identification, forms, delivery, activation, and old-token invalidation.
- Change recovery contacts and related credentials when compromise is possible.
Read the remote bank account promise risks before accepting an unofficial recovery shortcut.
Cut over access after a director or personnel change
A director, signer, administrator, or employee change should be managed as an authority cutover, not only a user deletion. The PT PMA must identify the effective corporate position, adopt the required resolution or power, update the bank’s KYC and mandate, create new roles, revoke old roles and recovery channels, recover devices, and test the new combinations.
The company’s corporate authority framework , deed, amendments, and resolutions establish the internal basis, while the bank decides its update forms and implementation. If the director amendment is pending, management should not present the future appointee as already authorized. If the former person remains in a corporate role but loses bank access, the resolution should describe that narrower change.
Release test
The cutover closes only when former authority and all digital recovery paths are removed and the new users can complete critical transactions.
- Record the corporate trigger, effective date, and superseded authority.
- Pre-clear bank forms, KYC, signatures, attendance, and turnaround.
- Revoke users, tokens, devices, cards, alerts, and contact details.
- Test new roles, joint approvals, limits, statements, and recovery.
Use the post-registration steps guide when the change affects corporate and OSS records.
Build the access-recovery runbooks
Separate token loss, lockout, contact failure, personnel exit, director change, outage, and compromise into bank-approved actions.
Create a lawful emergency payment and outage route
The continuity plan should define which payments are critical, which can wait, and which approved bank channel, branch instruction, contingency account, or alternative user combination can be used during an outage. The route must remain within valid corporate authority, account terms, security controls, and supporting evidence. A personal account, shared credential, blank signed form, or undisclosed local controller is not an acceptable fallback.
The runbook should include payroll, taxes, essential suppliers, insurance, rent, and customer refund scenarios with deadlines, limits, preparer, approvers, bank contacts, fraud verification, and post-event reconciliation. If a second bank is used, it should already have current KYC, active credentials, controlled funding, and a tested mandate rather than being opened during the emergency.
Stop condition
Activate the fallback only for a defined event and return to normal routing through a documented recovery and reconciliation decision.
- Classify critical, deferrable, and prohibited emergency payments.
- Confirm branch, contact-center, alternate channel, and contingency-bank procedures.
- Use independent beneficiary and bank-detail verification.
- Reconcile every emergency payment, fee, manual form, and later duplicate risk.
Use the bank delay guide when the outage is actually a KYC or mandate hold rather than a technical failure.
Official References and Review Basis
Primary materials were checked on July 31, 2026. These links support the regulatory and banking framework used in this article; they do not replace a matter-specific legal, tax, licensing, accounting, security, or bank review.
- Limited Liability Company Law No. 40 of 2007 : Company-law framework for shares, capital, corporate organs, records, and authority, as amended.
- OJK Regulation No. 8 of 2023 : Customer due diligence, beneficial-owner review, ongoing monitoring, and electronic verification framework.
- BNI Giro corporate-account requirements : Published checklist covering the deed, NIB, NPWP, management composition, authorized official, and initial deposit.
- Bank Mandiri Giro requirements : Published corporate current-account documents, identity, authority, and power-of-attorney conditions.
- BCA Current Account requirements : Published corporate account, representative, power-of-attorney, management, shareholder, NIB, and license requirements.
Regulatory Notes and Limitations
Recovery, electronic verification, credentials, account holds, manual channels, mandate changes, and attendance are bank-specific. Cybersecurity, privacy, fraud, sanctions, employment, corporate, and incident-notification duties require fact-specific review.
- Do not share passwords, PINs, one-time codes, biometrics, or personal recovery access as a continuity measure.
- A user reset cannot replace a valid corporate and bank mandate change after authority ends.
- Emergency payment routes should not bypass a bank inquiry, legal hold, sanctions control, license restriction, or customer due diligence review.
- A local employee or provider should not receive nominee ownership or sole bank control merely because directors operate overseas.
Test remote recovery before the next incident
The PT PMA should run periodic tabletop and low-risk operational tests for user lockout, token reissue, overseas credential delivery, phone or email change, signer removal, bank outage, and contingency payment. Testing should not simulate fraud against the bank or trigger an uncontrolled block; the bank should be consulted where a live step is involved.
The test record should show the scenario, authority, participants, bank confirmation, time to detect, time to block, required documents, communications, workarounds, payment impact, data exposure, result, and remediation owner. Failures should update the inventory, resolutions, contact list, access design, travel fallback, and KYC calendar. Management should repeat high-impact scenarios after bank or personnel changes.
Record standard
A continuity plan is effective only when the tested path can restore lawful access without transferring secrets or control to an unauthorized person.
- Run tabletop scenarios at least when risk, bank, or key personnel changes.
- Use low-value test transactions only with proper approval.
- Verify official contacts and out-of-band escalation routes.
- Track remediation to closure and retest material failures.
Connect the test schedule with the PT PMA compliance and control calendar.
Connect this control to the wider Indonesia company registration workstream before committing people, travel, or funds.
Test the PT PMA remote banking recovery path before the next access failure
Remote banking resilience starts while access is healthy. Inventory authority and credentials, verify official recovery contacts, prepare distinct runbooks for loss, lockout, personnel change, director change, outage, and compromise, and maintain a lawful emergency payment route.
Do not call credential sharing or informal local control a fallback. Test the bank-approved path, prove old access is revoked, and require every restored user and payment to return to the PT PMA’s valid mandate and reconciliation controls.
Test lawful remote banking resilience
Run the tabletop, low-risk transaction test, revocation check, contingency route, and remediation close before an incident.
Frequently asked questions