Shiftelio
Payroll and ComplianceIndia7 min read

Who Approves a Change to an Employee's Bank Details?

In short

The person who types a salary account number should never be the one who approves it. How to split entering from approving, and what the law leaves to you.

  • Changing where a salary lands should take two people: one to enter the new details, one to confirm them.
  • The Code on Wages, 2019 pushed wages into bank accounts. It says nothing about who is allowed to change the account.
  • The dangerous moment is not the first entry. It is the quiet edit to an account already on file.
By Oscar Jamuar, Founder, ShiftelioPublished Last updated

A salary run is a list of account numbers. Nothing else about it is really the money. The hours were counted honestly, the deductions were right, the net figure was checked twice, and then eleven digits decide where it lands.

In most small Indian businesses, one person owns all eleven of those digits. The office manager collects the bank passbook photos on WhatsApp, types them into a spreadsheet, and the spreadsheet is the payroll. Nobody else has ever read it. That is not a story about a dishonest manager. It is a story about a control that was never built, and it stays invisible until the month it does not.

The edit nobody sees

A first entry is visible. Somebody joins, somebody types their account, the first salary arrives and they say so if it does not.

An edit to an existing record has none of that. Ramesh has been paid into the same account for fourteen months. In the third week of a month, two digits change. The salary goes out on the first. Ramesh says nothing until the fourth, because he assumed it was late, and by then the money has moved twice. When you go looking, the spreadsheet shows only the current value. There is no previous value, no timestamp, and no name against the change.

Every part of that is ordinary. The fraud, if it is fraud, needed no technical skill at all. It needed a field that one person could edit alone and a record that kept only the latest answer.

The ACFE's Report to the Nations, now in its fourteenth edition and the largest global study of occupational fraud, reports the same thing every time: organisations with anti-fraud controls in place lose less and find it sooner. The controls that do that work are unglamorous. Separation of duties is the plainest of them.

Two panels compare what happens when an employee's salary bank account is changed. The left panel, headed ONE PERSON in red, reads "Typed. Live. No record." The right panel, headed TWO PEOPLE in green, shows two stacked boxes with an arrow between them: "Manager enters" above and "Owner approves" below, with the line "Previous value kept" underneath the panel. The heading above both panels reads "Changing where a salary lands".
The same change, with and without a second person on it.

Why the law got you halfway there

Section 15 of the Code on Wages, 2019 set the mode of payment:

All wages shall be paid in current coin or currency notes or by cheque or by crediting the wages in the bank account of the employee or by the electronic mode.

Code on Wages, 2019, s.15

Section 17 then fixes when: for monthly staff, before the expiry of the seventh day of the succeeding month. You can read both in the official text on the Ministry of Labour and Employment's site.

What those sections do is remove cash from the equation and put a bank account at the end of every pay run. What they do not do, anywhere, is say who inside your business is allowed to decide which account that is. That question is left entirely to you, and most businesses answer it by accident: whoever was given the spreadsheet.

A useful test. Ask yourself who, today, could change one employee's account number without a second person ever seeing it. If the answer is a name rather than "nobody", that is your exposure, and it is unrelated to how much you trust the name.

The four things a real control does

Separation of duties is a phrase from audit manuals, and in a fifteen-person business it collapses into four practical requirements.

  • Entering and approving are different abilities, held by different people.
  • A change to an existing account goes back for approval, exactly like a new one.
  • The person entering details cannot read back the ones already stored.
  • Every approval and every change keeps its own record: what the value was before, who changed it, when.

The third one is the one people forget. If the manager who enters bank details can also export the full list, you have separated the decision but not the data. A complete roster of names, account numbers and IFSC codes is worth something on its own, and it walks out of the building as a spreadsheet attachment.

The fourth is what turns an argument into a fact. Six months later, "I approved that" and "no you did not" is unanswerable unless something wrote it down at the time.

One person, one spreadsheetTwo people, with a record
Who can change an accountWhoever holds the fileAnyone with entry rights, but the change does not take effect yet
Who confirms itNobodyA separate person holding approval rights
A change to an existing accountSilentGoes back into the queue
Previous valueOverwrittenKept
Who did it, and whenNot recordedRecorded against both the change and the approval
Reading the full listAnyone with the fileRestricted, and the act of reading it is logged

How Shiftelio separates entering from approving

Shiftelio treats "Payment details" as a capability with three distinct permissions, not one: View the bank or UPI details staff get paid into, Add and edit them including in bulk, and Approve details somebody else entered. You hand those out separately. A manager who does the typing can be given the first two and not the third, and from that moment their work queues instead of applying.

Here is what that looks like in practice. A manager uploads a roster of forty people's bank details from a spreadsheet. Nothing is live. Forty rows land on the Payment approvals screen grouped as one upload, because forty separate Approve clicks is how a queue stops being read at all, and whoever holds approval rights confirms or rejects the whole upload in one decision. If one of those rows belongs to somebody who already has details waiting for a decision, the upload does not quietly overwrite them. It flags the conflict and asks for that one to be settled first.

Changing an account that is already approved behaves the same way when a manager does it. The record goes back to pending and needs confirming again, so an existing salary destination cannot move without a second person seeing it move. An owner's own entries are approved outright, which is the honest limit of this: it separates duties among your staff, not between you and yourself.

The part that is genuinely uncommon is the reading. When a manager exports the payment roster to work on it, account numbers, IFSC codes, UPI IDs, PAN, UAN and ESI numbers all come out masked as ****1234. The account holder's name is deliberately never masked, because a name paired with the wrong account is exactly the error you want visible at a glance. Leaving a masked cell untouched means "no change". Only the owner can export the roster in the clear, and when they do, that export is itself written into the history as an event with a timestamp. The list cannot be read in full by the person who maintains it, and the one person who can read it leaves a mark saying so.

Underneath, every touched row writes its previous value into a payment history table before it is overwritten, which is what makes an undo possible and what answers the six-months-later question. Nobody can edit or delete an entry in that history, and people who are allowed to see payment details can read it.

The employee is told too. Approve or reject their bank details and a notification goes to them in their own language, with the reason attached if it was a rejection. The person whose money it is finds out that something moved, which is a control in its own right and the cheapest one you own.

You can see where this sits alongside attendance, payroll and the rest on the features page.

What to do this week, whatever you use

None of this requires software to start.

1. Find out who can change an account number today

Not who should. Who can, right now, with the access they already hold. Include anyone with the spreadsheet, anyone with the login, and anyone who has ever been sent the file.

2. Name a second person

Someone who did not type it confirms it. In a small business this is usually the owner, and that is fine. The requirement is two people, not a department.

3. Write down the previous value before you change it

Even a dated note in a separate file beats an overwrite. The previous value and the date are what make a later question answerable.

4. Tell the employee when their details change

A one-line message to the person whose salary it is catches almost everything that the other three steps miss.

Is a maker-checker rule on payroll legally required for a private company in India?

Not as a specific statutory duty on a small business. The Code on Wages, 2019 governs the mode and timing of payment, not your internal authorisation. Companies carrying obligations around internal financial controls will find this falls under them, but for most small employers it is a prudence question rather than a compliance one. That does not make it optional in practice: the loss is yours either way.

The employee gave us the wrong account and the salary bounced. Does approval help?

Yes, though indirectly. The value of a second pair of eyes on an IFSC code or an account holder's name is that obvious mismatches get caught before the transfer, not after the bank returns it a week later.

We are four people. Is this overkill?

Probably, for now. The honest answer is that at four people the owner does the typing, and separation has nobody to separate. The moment somebody other than you maintains the list is the moment to put this in.

What about the transfer itself?

Separate problem, and worth being clear about. Approving a set of bank details decides the destination. Moving the money is your bank's net banking or your payment provider's authorisation, with its own approvals. Both matter. Neither substitutes for the other.

The short version

The account number is the only part of payroll that decides where the money physically goes, and in most small businesses it is the part with the fewest controls on it. Two people on every change, a record of what the value used to be, and a message to the employee. That is the whole control, and none of it is expensive.

Free to use, no signup: Payroll calculators.