-
Internal controls

Internal controls

The first line of defence

Internal controls are crucial in the fight against fraud.

Follow our best practice guide to help keep the fraudsters out.

Accessing Digital Channels

Add iPortal (https://iportal.barclays.com/) to your bookmarks/favourites and trusted sites. Do not use a search engine to access our digital channels as you may be presented with links to malicious websites (such as fake Barclays sites).

Smart cards/Smart SIMs

Keep your smart card/smart SIMs secure at all times so only the relevant user can access it. Do not share smart cards. We recommend that you remove your smart card/ SIM from the reader once you have logged in.

Device reader/ mobile app

Keep access to the mobile app secure at all times and don’t share mobile devices or access to the app itself. The transaction message displayed on your security device will always accurately reflect the activity taking place. If someone asks you to generate a QR code and provide it to them by any method, they are a fraudster.

Administration privileges and transaction limits/ functionalities

Ensure that only necessary payment types are included for each role profile. Only include payment types in role profiles that are used by your organisation. Be vigilant when assigning role profiles to each users in line with their duties.

Dual authorisation vs sole authorisation

Choose the 'authorisation required'/ 'dual authorisation' option to significantly reduce the risk of fraud, as it makes it more difficult for a rogue administrator, user or third party who has gained access to make fraudulent changes or payments. Use two separate devices to upload and approve the payment instruction.

Protect your organisation against malware and unverified downloads

We strongly recommend that you assess your cyber security. Prevent staff from downloading applications from the internet through role appropriate restrictions and educate them regarding the risks and red flags. Permissions to download applications should be given to only those who need it (i.e. IT administrators).

Red flags

Someone may be trying to remotely access your computer if:

  • You’re instructed to type in a web address or download a chat function
  • Your computer screen turns black, or you are asked to turn off your screen
  • You receive security software warnings – these should not be ignored

Remember–Barclays will never call you and ask you to provide or enter your PIN or use your biometric device, for ANY reason.

Reporting fraud

Think you’ve fallen victim to fraud or a scam? Contact us right away.

Please call the Barclays corporate fraud team on 0330 156 0155* to report concerns of fraud or scams.

Barclays will never send you an email requesting personal information or your bank security details. If you receive a suspicious email, please send it as an attachment to internetsecurity@barclays.co.uk and delete the email immediately.

Fraud and Scam Toolkit