JPMorgan Access Security & Fraud Prevention Guide
Security is the foundation of JPMorgan Access. The platform employs a multi-layered security architecture designed to protect corporate banking transactions and data at every level. This guide covers the key security features, fraud prevention tools, and best practices that help keep your organization's financial operations secure.
Multi-Layered Security Architecture
JPMorgan Access is built on a multi-layered security model where each layer adds an additional barrier against unauthorized access and fraudulent transactions. The layers work together to create defense-in-depth, ensuring that even if one layer is compromised, others continue to protect the system.
The key security layers include:
- Authentication layer — Username, password, and RSA SecurID token
- Network layer — IP Security restricting access to approved addresses
- Authorization layer — Entitlements controlling what users can see and do
- Transaction layer — Payment Control, dual control, and approval workflows
- Monitoring layer — Audit logs, event tracking, and anomaly detection
- Communication layer — Encrypted secure email and data transmission
RSA SecurID Authentication
RSA SecurID is the cornerstone of JPMorgan Access authentication. It provides two-factor authentication by requiring something the user knows (password) and something the user has (token). The RSA SecurID token generates a new six-digit passcode every 60 seconds, making it extremely difficult for attackers to gain access even if they obtain login credentials.
RSA SecurID is available in two forms:
- Hardware token — A physical device that displays the current passcode
- Software token — A mobile app (RSA SecurID Authenticate) that generates passcodes on a smartphone or tablet
RSA SecurID® is a trademark of RSA Security LLC or its affiliates, as noted on the JPMorgan Access login page.
IP Security
IP Security adds a network-level access control by restricting login attempts to specific, pre-approved IP addresses. This means that even if an attacker obtains valid credentials and a token, they cannot access the system from an unapproved network location. IP Security can be configured at the company level (applying to all users) or at the user level (applying to individual users).
Primary Administrators should activate IP Security as part of their initial security configuration. This is done through the Access & Security Manager tab in conjunction with the RSA Authenticator setup.
Payment Control
Payment Control is a fraud prevention feature that allows organizations to define rules and policies that automatically flag, hold, or block payments based on specific criteria. This adds an automated layer of protection against fraudulent payment attempts.
Payment Control rules can be based on:
- Payment amount thresholds
- Beneficiary account information
- Payment frequency patterns
- Geographic origin or destination
- Payment type (ACH, wire, etc.)
- Time-of-day restrictions
Dual Control for Transactions
Dual control ensures that no single individual can independently complete a sensitive transaction. For payments, this means one user initiates the payment and a different user must approve it before processing. For administrative changes, Dual Control Administration requires a second administrator to approve changes to user profiles, entitlements, or security settings.
This separation of duties is one of the most effective controls against both external fraud and insider threats, as it requires collusion between two authorized users to bypass the control.
Audit & Event Logs
JPMorgan Access maintains comprehensive audit trails of all activities within the platform. The Audit & Event Logs feature allows administrators to:
- Customize audit reports to review application activity history
- Track system misuse and unauthorized access attempts
- Maintain compliance records for regulatory requirements
- Investigate suspicious activities with detailed timestamps and user identification
- Export audit data for external analysis or archiving
The Global ACH Audit Log specifically tracks all Global ACH transactions, providing a dedicated audit trail for international ACH payment activity.
User Entitlements as Security Controls
Entitlements are not just about feature access — they are a fundamental security control. By limiting each user's access to only what they need (the principle of least privilege), organizations reduce the attack surface and minimize the potential impact of compromised credentials. Security Administrators should regularly review and update entitlements to ensure they remain appropriate as roles change.
Security Best Practices
For All Users
- Never share your username, password, or RSA token codes
- Keep your RSA SecurID token physically secure
- Report lost or stolen tokens immediately to your Security Administrator
- Use strong, unique passwords and change them regularly
- Always verify the URL before entering credentials
- Log out completely after each session
- Avoid using public Wi-Fi networks for banking access
- Be cautious of phishing emails pretending to be from J.P. Morgan
For Administrators
- Activate IP Security for all users
- Enable Dual Control for administrative changes
- Configure Payment Control rules for high-risk payment types
- Regularly review and audit user entitlements
- Immediately deactivate access for departing employees
- Set appropriate transaction limits based on user roles
- Review audit logs regularly for suspicious activity
- Ensure all users have RSA SecurID tokens properly configured
Recognizing Phishing Attempts
Phishing is one of the most common attack vectors against corporate banking users. Be alert for:
- Emails asking you to "verify" or "update" your JPMorgan Access credentials
- Links in emails that lead to fake login pages — always check the URL
- Phone calls claiming to be from J.P. Morgan asking for token codes or passwords
- Urgent requests to approve payments outside of normal procedures
- Any communication asking you to bypass security controls
J.P. Morgan will never ask for your password or RSA token code via email or phone. If you receive a suspicious communication, report it immediately to your Security Administrator and to J.P. Morgan.