A practice can have money in the bank and still be unable to make the payments that keep it operating. The practical question is not only who knows the banking password, but who is authorised, within what limits, through which bank or provider process, and with what backup control.
Payroll, routine suppliers, refunds, trust or client money, emergency purchases and large commitments should not automatically be treated the same way. A workable plan separates categories and defines limits and escalation.
Having a banking token, login or mobile device does not itself create permission to approve a payment. The bank’s mandate, authentication rules and account settings still control what it will allow.
PCO tests the intended approver, backup approver, maker-checker or dual-control requirements, payment ceilings, evidence, escalation and what happens when the usual approval chain is unavailable.
Legal trust money, medical refunds, pharmacy controls, client funds, insurer or funder processes and other profession-specific payments may have additional rules. Those rules remain with the relevant regulator, bank, provider or professional adviser.