Skip to content
Skip to main content
Payments & Banking Technical Explainer

Could a payment account be shared?

Yes. Joint holders, employees, family members, delegated administrators or unauthorised users may all access one payment account, so the named holder is not automatically the actor.

Access can be formal, informal or compromised

Business roles and additional cards may be provider-authorised. Credentials, browsers and logged-in applications can also be shared informally. Stolen credentials, remote access and existing sessions create unauthorised routes.

Identify the relevant user

Preserve account roles, cards, registered endpoints, logins, IP-related records, authentication, contact changes and transaction patterns. Compare disputed activity with normal use, device evidence, communications and witnesses.

Sharing is neither an automatic innocent explanation nor something to ignore. Test who could access the account and which session performed the event. Compromise is the next distinct possibility.

The point to remember

Treat an account as potentially multi-user until provider, endpoint and contextual records identify who controlled the disputed transaction.

Reference: PAY-011Payments & Banking