Dual control in banking is a security practice that requires two authorized employees to be present and involved before a high-risk task can be completed. One person initiates the action, a second independently verifies and approves it, and neither can finish the job alone. Federal regulators including the OCC, FDIC, and NCUA treat the practice as a core piece of a sound internal control system, and banks that let it lapse can face enforcement action.
How the Two-Person Process Works
The mechanics are straightforward. For any operation the bank considers high-risk, one employee prepares or initiates the transaction and a second employee independently reviews and approves it before it goes through. In industry shorthand, the first person is the “maker” and the second is the “checker.” The maker might prepare a wire transfer or pull reserve cash from the vault. The checker reviews the details against internal policy, confirms accuracy, and co-signs. The task cannot be completed by one person acting alone.
This changes the math on fraud. A single dishonest employee cannot move money or issue an instrument by themselves. Any deliberate theft now requires collusion between two separate people, each of whom knows the other is watching and each of whom is exposed if the other talks. That is a much higher bar than one person acting alone, which is why regulators view dual control as one of the most effective defenses against insider theft. It also catches honest mistakes before they leave the building.
Where Banks Actually Use It
Dual control shows up wherever cash, cash-equivalent instruments, sensitive data, or high-value transactions are handled. Procedures vary by institution, but the principle is constant: two people, every time.
Vault Access and Reserve Cash
Opening the bank vault is the most recognizable example. Most banks require two designated custodians to be present, each holding a separate key or combination, before the vault door opens. Reserve cash stored inside is kept under what regulators call “dual custody,” meaning no single employee can reach it alone.1Office of the Comptroller of the Currency. Cash Accounts Night depository work follows the same rule: two employees are present when bags are opened, deposits recorded, and contents counted.
ATM Servicing
Accessing ATM cash cassettes for replenishment or balancing requires two employees, both present when cassettes are opened, counted, and reloaded, and both signing the count sheet. Captured cards held inside the ATM are also handled under dual control, by staff who are not involved in card issuance.1Office of the Comptroller of the Currency. Cash Accounts Credit unions run equivalent procedures, with examiners checking that dual control covers ATM cash, deposits, and captured cards.2National Credit Union Administration. Examiners Guide – Cash
Wire Transfers
Large wire transfers are a classic maker-checker application. One officer enters the transfer details, and a second officer with separate credentials reviews the recipient, amount, and account information before releasing the funds. The dollar threshold that triggers mandatory dual approval is not set by any single federal regulation. Each bank sets its own thresholds based on its risk profile and transaction volume. What examiners look for is that the bank has a documented process and follows it consistently.
Negotiable Instruments
Blank money orders, official bank checks, and travelers’ checks are essentially cash once signed. Banks and credit unions keep them in secured storage with inventory controls that require two people to sign items in and out. Signature plates used on automated check-signing machines are locked under dual control when not in use.2National Credit Union Administration. Examiners Guide – Cash
Safe Deposit Boxes
Safe deposit box access is the version customers experience directly. Each box has a lock with two keyholes. The bank holds a “guard key” that operates one side of the mechanism, and the customer holds a “renter key” that operates the other. A vault custodian first inserts and turns the guard key, and only then will the customer’s key retract the bolt. Neither key works without the other, so neither the bank nor the customer can open the box alone.
Encryption Keys and System Access
Dual control reaches well past the vault. Encryption keys used to scramble ATM communications, PIN data, and card transactions are managed under dual control by employees who are not involved in day-to-day operations or card issuance.1Office of the Comptroller of the Currency. Cash Accounts The same rule applies to administrative credentials on core banking systems: changing access rights for high-tier employees requires a second, independent approval. This is the area where dual control is growing fastest, as more banking work moves onto digital platforms.
Dual Control Is Not the Same as Segregation of Duties
These two terms get confused constantly, and the difference matters. Dual control means two people are involved in the same task at the same time. Both are present, both participate, and neither can finish alone. Two custodians turning vault keys simultaneously is dual control.
Segregation of duties is a broader organizational design. It means different people handle different stages of a process so that no single employee controls an entire transaction from start to finish. One person originates a transaction, a different person processes it, and a third person reconciles it to the general ledger.3Federal Reserve Bank of Minneapolis. Internal Controls Those employees may never interact directly and do not need to be in the same room or even the same shift.
A sound internal control environment uses both. Segregation of duties prevents any one person from controlling a whole workflow. Dual control prevents any one person from executing the single most dangerous step within that workflow. Regulators consider the failure to maintain adequate separation of duties an unsafe and unsound practice that can lead to serious losses.4Federal Reserve. Branch and Agency Examination Manual – Operational Controls
What Regulators Require
No single federal statute spells out “use dual control for X, Y, and Z.” Instead, multiple regulators require banks to maintain effective internal controls, and their examination manuals make clear that dual control is a baseline expectation for specific operations. The OCC’s Comptroller’s Handbook lists dozens of examination checkpoints where examiners verify dual control is in place, from vault opening to mail deposits to encryption key storage.1Office of the Comptroller of the Currency. Cash Accounts The NCUA examiner’s guide includes equivalent checklists for credit unions.2National Credit Union Administration. Examiners Guide – Cash Under Section 8(i)(2) of the Federal Deposit Insurance Act, the FDIC can assess civil money penalties in tiers of increasing severity when banks violate laws, regulations, or written agreements.5Federal Deposit Insurance Corporation. Formal and Informal Enforcement Actions Manual – Restitution and Civil Money Penalties
What Happens When It Fails
The consequences are not theoretical. In 2023, Heartland Tri-State Bank in Kansas was closed after its CEO initiated $47.1 million in fraudulent wire transfers tied to a cryptocurrency scam. Employees processed the transfers under pressure from leadership, bypassing internal controls, and the bank failed. That case illustrates the one scenario dual control cannot fully solve on its own: when the people at the top of the org chart are the ones pushing employees to skip the safeguard. Effective dual control depends on a culture where any employee can stop a transaction without fear of retaliation, regardless of who ordered it.
Smaller failures are more common and less dramatic. A single employee with unsupervised access to blank money orders quietly issues instruments to themselves. A teller with sole access to reserve cash skims small amounts over months. These are the exact scenarios dual control is designed to prevent, and they tend to happen at institutions where the procedures exist on paper but are not followed in practice. Examiners look at both: whether the policy is written, and whether employees actually execute it every time.