When money moves, authority matters.
Payments, financial commitments, and the limits that apply across connected systems.
Discuss a workflow ↗
Banks already control who can access payment systems and how transactions move through them. A separate question remains: is the resulting payment or obligation within the limits the bank has authorized? This page follows that question through payments, automated operations, and periods when trust is uncertain.
Documented case
A valid payment instruction can still create an unauthorized result.
In the 2016 Bangladesh Bank theft, attackers used compromised systems to send fraudulently authenticated SWIFT messages attempting approximately $951 million in transfers.[1][2] About $81 million reached accounts in the Philippines.[2] A New York appellate court later described the transactions as unauthorized payment orders.[3]
The messages could be authenticated. That did not establish organizational authority for the transfers.
Public records do not establish the bank's internal authority rules at the time. The case illustrates the distinction between authenticated execution and organizational authority. It does not establish that Authority Control would have prevented the incident.
Illustrative application
Payments and financial commitments
Banks already control identity, access, fraud, workflow, and payment execution. Authority Control adds a separate question before a result takes effect: is this payment or financial commitment within the limits the organization has established?[note]
Within the individual limit, beneficiary scope, and the daily limit across related payments.
PermitThe configured confirmation evidence is missing when the payment is proposed.
DeferThe proposed payment exceeds the per-payment authority granted.
BlockThese outcomes belong to the illustrative configuration. Each payment is evaluated against current applicable authority, and the determination creates a durable authority record.
Deeper readingLondon Whale →Critical Changes →Crown Jewel Protection →
Illustrative application
Automation can multiply activity without multiplying authority.
People, services, and agents can act across payments, treasury, and operations. Changes in technical capacity do not automatically expand the bank’s authority for amounts, beneficiaries, destinations, or purposes.
Authority Control evaluates results against the authority that currently applies as models, agents, and execution paths change.
Illustrative application
A bank may need to keep operating while trust is uncertain.
During suspected compromise, broad shutdown can disrupt essential operations. Where integrated and configured, Authority Control can apply narrower authority to selected results alongside existing security and response controls.
The organization may apply different conditions to routine payments, new beneficiaries, unusual destinations, large transfers, and changes to authority limits.
Documented governance example
Authority already exists in financial institutions
Financial institutions already operate through mandates, delegations, limits, approval structures, investment universes, and signing authority.
The current investment mandate issued by Norges Bank’s Executive Board states that authority for investment decisions may be delegated, and that formal investment mandates are required for internally and externally managed portfolios with at least the investment universe and risk limits specified.[4]
Those limits belong to the organization. Authority Control applies them to consequential results before those results take effect.
Works alongside the controls banks already have
establishes who or what is acting.
establish what systems and data can be reached.
assess behavior and operating conditions.
carry the transaction into effect.
evaluates whether the consequential result is within the limits the organization established, and preserves a durable record of each determination.
Sources
[1] US Department of Justice, 6 September 2018. Network compromise and fraudulently authenticated SWIFT messages directing transfers from Bangladesh Bank’s account.
[2] US Department of Justice indictment. Approximately $951 million in attempted false and fraudulent wire transfers, with approximately $81 million transferred to the Philippines and $20 million to Sri Lanka.
[3] Bangladesh Bank v. Rizal Commercial Banking Corp., New York Appellate Division, 2024. Court recitation describing unauthorized payment orders, processing through the New York Fed, correspondent accounts, and subsequent movement of funds.
[4] Norges Bank Investment Management, Investment mandate · Government Pension Fund Global. Current Executive Board mandate to the NBIM CEO; sets the management assignment, permits delegated investment authority, and requires formal investment mandates specifying the investment universe and risk limits for internally and externally managed portfolios.
[note] Sections marked Illustrative application describe how Authority Control can be applied in a representative organization. They describe a representative application. Named organizations appear only in sourced case material. Workflow basis for the banking example: Federal Reserve Operating Circular 6, Regulation J, and official Fedwire operating materials, per Sources and evidence.
Start with one consequential banking workflow.
Choose a payment, treasury, settlement, production-change, or AI workflow. Map its authority, observe proposed results, and assess where selective enforcement adds value.