Bank signatory recertification is the exercise by which a company verifies, at regular intervals, that the signing authorities declared to its banks match reality: the right people, on the right accounts, with the right ceilings and the right signing rules. It ends either in a formal confirmation or in corrections: revocations, mandate updates, ceiling adjustments.
Why does your bank require it?
Banks are bound by know-your-customer (KYC) and anti-money-laundering obligations that require them to keep their records current, including the list of people authorised to operate the accounts. When your bank asks you to confirm or recertify your signatories, it is meeting its own regulatory obligations. Three actors push in the same direction:
- The bank, as part of its periodic KYC reviews.
- The auditors, for whom comparing the personnel register with the mandates on file at the banks is a classic control.
- Internal control, since the separation of bank signing authorities is a pillar of any anti-fraud framework.
What does a recertification cover?
A serious campaign reviews, for each entity and each bank:
- The signatories: is every person declared to the bank still with the company, in the same role?
- The ceilings and signing rules: do the amounts and combinations (single, joint, group-based signature) still match the organisation?
- The accounts: are there dormant or forgotten accounts still carrying active signing authorities?
- The gaps: any difference between the internal referential and what the bank actually has on file.
The most frequent gap remains the departed signatory whose authority is still active at the bank: catching it is precisely what recertification is for.
How does a campaign run, step by step?
- Set the scope: which entities, which banks, which accounts. A partial campaign produces partial assurance.
- Rebuild the current state: obtain from each bank the list of signatories and authorities it has on file. This is often the longest step.
- Compare with internal reality: personnel register, organisation chart, internal delegations in force.
- Have the owners confirm: each entity or scope owner validates or flags corrections.
- Correct, bank by bank: revocations, new mandates, ceiling adjustments, in the format each institution requires (paper or eBAM where supported).
- Close with the proof: keep the confirmations, the updated mandates and the acknowledgements. For an auditor, a campaign only exists if it is documented.
How often should you recertify?
Annual is the common practice, sometimes twice a year for exposed groups. But frequency is not the real issue: an annual campaign run on a wrong referential spends the year certifying errors. Life events in the group (a departure, an acquisition, a change of executive, a reorganisation) should trigger updates as they happen; recertification then confirms that nothing slipped through.
What are the classic pitfalls?
- Certifying the spreadsheet, not the bank. If the review relies on the internal Excel file without rebuilding what each bank actually has on file, you are certifying a snapshot that is already wrong.
- Treating the campaign as a one-shot. Without handling the events between two campaigns, every recertification rediscovers the same gaps.
- Missing the blind spots: secondary subsidiaries, local banks inherited from an acquisition, dormant accounts.
- Not documenting. A campaign without written proof protects you neither in an audit nor in a dispute.
How to make recertification painless?
The cost of a recertification is inversely proportional to the quality of the referential. When entities, accounts, banks, signatories and signing rules live in a single referential, kept current as events happen and backed by an audit trail, the campaign shrinks to a confirmation: the inventory already exists, the gaps are immediately visible, and every correction leaves its proof. That is Kable’s approach: a continuously current referential of bank signing authorities, turning recertification from a weeks-long project into a documented formality.