Skip to content
PAY-218 Payments & Banking

Does authorisation prove informed consent?

No. Payment authorisation proves that the required technical approval process was completed, not that the payer understood the true purpose, recipient or consequences.

Avoid this assumption: That a correct password, PIN, biometric check or one-time code proves a genuinely informed and voluntary decision. A person may authorise a payment while acting under deception, coercion, impersonation or false instructions.

They may believe they are protecting funds, paying a genuine invoice, helping a relative, making an investment or assisting an official investigation.

An offender may remain on the telephone, use messaging or operate remote-access software while the victim completes the payment.

Provider records may therefore show the victim’s normal device, network and authentication method.

That evidence can prove the technical steps.

It does not show what the victim was told or what they believed.

Preserve authentication events, beneficiary creation, payment warnings, transaction details, device records and the timing of each stage.

Preserve the communications that led to the payment, including calls, emails, messages and altered invoices.

Establish whether warnings were shown and whether the offender coached the victim to ignore or answer them.

Do not use “authorised” as shorthand for “informed”, “legitimate” or “not fraudulent”.

Equally, do not assume lack of informed consent without testing the account against communications and surrounding conduct.

When reporting, separate technical approval from personal understanding and genuine agreement.

Operational takeaway

Treat payment authorisation as evidence that a technical approval step occurred, and establish informed consent separately through the payer’s understanding, communications and surrounding circumstances.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.