Skip to content
PAY-011 Payments & Banking

Could a payment account be shared?

Yes. A payment account may be used by more than one person, whether formally, informally or without the provider’s approval.

Avoid this assumption: Every transaction on an account was made by the named account holder.

A joint bank account may have several authorised holders. A business account may be operated by directors, employees, accountants or payment administrators. Family members may share credentials, cards or devices. An online wallet or payment application may remain logged in across several devices.

Sharing may also be informal. One person may allow another to make purchases, send transfers or withdraw cash. Credentials may be stored in a browser, written down or known to others.

There may also be unauthorised access. An offender may use stolen credentials, an existing session, remote-access software or a compromised device.

The provider’s customer record usually identifies who opened or holds the account. It may not identify every person who could access it.

To assess shared use, examine account roles, additional cards, registered devices, login history, IP addresses, authentication methods, contact details and transaction patterns.

Look for differences between normal and disputed activity. A new device, unusual location, newly added beneficiary or changed authentication route may be relevant. So may evidence that several people routinely used the account.

Communications and witness evidence can clarify permission, control and knowledge. Device examination may show which applications, credentials or sessions were available on a particular device.

Do not treat shared access as an automatic innocent explanation. It is an alternative explanation that should be tested. Equally, do not ignore it where the evidence does not distinguish between users.

When reporting, identify the activity as associated with the account unless there is evidence linking it to a specific user.

Where several users may have access, preserve provider and device records early because session and device history may be retained for limited periods.

Operational takeaway

Assume an account may have multiple authorised or unauthorised users until provider, device and contextual evidence establishes who controlled the relevant transaction.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.