What it means
A dual-signature rule makes one person's approval insufficient for certain actions, which can include bank transfers, cheques, contracts or access changes. The business defines the scope and the bank or counterpart may have its own formal requirements, and two names on a page are not useful if neither checks the underlying transaction.
Citi's fraud-prevention material explains dual approval for payments, NAB's banking instructions show how digital multi-authorisation can be configured, and the University of Florida's internal-control guidance discusses separation of duties, though the actual legal and banking rules depend on each entity and account. Specify the trigger, since a company might require two approvals for every transfer or only for values above a threshold, and high-risk actions such as changing a beneficiary may need a separate check even below that amount.
Write rules for currencies, batches and linked payments so a large transaction cannot be split into smaller parts to avoid review. The two people should have separate authority and credentials, because a shared password or token defeats the trail, and one employee can prepare a payment while two others approve it if the system supports that design, with roles that reflect staffing and risk, not simply the number of employees available.
The second approver needs independent evidence, so invoice, purchase order, approved supplier and bank details should be checked against trusted records, and a forwarded email saying "please approve" is not enough when it contains a changed account. Use a previously verified contact to confirm a material change outside the email thread.
A bank mandate can specify who signs jointly and which combinations are valid, so a board decision may require two directors while the online portal is still configured for one approver if the update was not completed, which is why internal decisions should be reconciled with the live bank setup by testing a low-risk transaction and inspecting the audit log. Contracts have different execution requirements, so a dual approval policy inside a company does not necessarily replace formal signing rules for deeds or government filings, and conversely a document legally signed by one director may still breach an internal approval policy, which means both the law and the company's delegation need checking.
Approval thresholds need periodic review, because inflation, transaction volumes and growth can make an old threshold too low or too high. A rule that blocks routine supplier payments for days may lead to unsafe workarounds, so use a backup approver process for leave and emergencies with the same independence.
Segregation helps prevent mistakes as well as fraud, since an approver may notice a duplicate invoice, wrong currency or extra zero, but an independent check matters most when the preparer is rushed, and collusion, inattentive approval and compromised credentials remain possible, so statements should be reconciled after payment too. Record why an exception was made, and if the bank cannot apply the normal two-person flow during an outage use a documented contingency approved by appropriate officers.
Do not send a transfer from a personal account or share a token to get around the rule, and preserve evidence for later audit. A dual-signature rule should cover changes to itself, because adding a new signatory or raising a threshold is a powerful action that should require appropriate board or senior approval and bank verification, and departed employees should be removed promptly since leaving an old approver active can nullify the intended control.
Small businesses can find segregation difficult when one owner prepares and approves every payment, so alternative controls could include an independent statement review, low limits or a trusted second officer for large transfers, and a two-person rule should not be claimed if the same person controls both accounts. Dual signatures make consequential actions slower in a useful way when the second person truly verifies them, so define the covered actions, roles and limits, configure the system and review logs, remembering that the rule is a checkpoint, not a guarantee.
In practice
Real-world examples.
Example
A construction firm requires two signatures on cheques over $50,000. A $65,000 cheque to a subcontractor is signed by the finance director and the managing director, while smaller cheques need one signature. The cheque register records both names.
Example
A distributor's accounts clerk creates a $30,000 bank transfer, and the finance manager approves it in the banking portal. Each uses a separate token, and the portal's audit log records both actions. The manager checks the invoice and payee details before approving.
Example
A second signer at a manufacturer spots that a supplier payment has an extra zero and is entered as $180,000 instead of an $18,000 invoice. She rejects it before release. The preparer corrects the amount, and the transfer goes through the next morning.
Formula
Calculation
There is no universal numerical formula for a dual-signature rule. An illustrative policy can say that a transfer above $100,000 requires two distinct authorised approvers, and the effective threshold and combination of roles come from the live bank mandate and internal delegation.
Worked example. A $120,000 transfer exceeds the $100,000 threshold, so it needs both approvers, while a $40,000 transfer needs one. If a preparer tries to send two $60,000 payments to the same supplier on the same day, the linked total is 2 x $60,000 = $120,000, which exceeds the threshold, so the rule should treat them as one transaction and require two approvals.Case study
Seen in the real world.
This illustrative and entirely fictional case follows Sandbar Engineering, an invented firm that requires two approvals for payments above $100,000. A preparer enters a supplier transfer; one approver checks the invoice and the other verifies the beneficiary against the trusted vendor record. Both use separate credentials. The case does not guarantee that all fraud is prevented.
A few months later, a fraudster emails a changed bank account for a regular supplier. The first approver is about to approve, but the second approver telephones the supplier on the number held in the vendor record and learns that no change was requested. The payment is stopped, and Sandbar adds a callback step to its written procedure for any change of beneficiary details.
Watch out
Common mistakes.
- Sharing one login or token between purportedly separate approvers.
- Approving the amount without independently checking the payee and purpose.
- Assuming an internal policy is active in the bank portal before checking the mandate settings.
Questions
People also ask.
What is a dual signature?
Two authorised people must approve a payment or document.
Why use it?
To catch errors and prevent fraud.
Does it apply to all payments?
Often only above a set amount.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%