JPMorgan Access Security & Fraud Prevention Guide

Security is the foundation of JPMorgan Access. The platform employs a multi-layered security architecture designed to protect corporate banking transactions and data at every level. This guide covers the key security features, fraud prevention tools, and best practices that help keep your organization's financial operations secure.

Multi-Layered Security Architecture

JPMorgan Access is built on a multi-layered security model where each layer adds an additional barrier against unauthorized access and fraudulent transactions. The layers work together to create defense-in-depth, ensuring that even if one layer is compromised, others continue to protect the system.

The key security layers include:

RSA SecurID Authentication

RSA SecurID is the cornerstone of JPMorgan Access authentication. It provides two-factor authentication by requiring something the user knows (password) and something the user has (token). The RSA SecurID token generates a new six-digit passcode every 60 seconds, making it extremely difficult for attackers to gain access even if they obtain login credentials.

RSA SecurID is available in two forms:

RSA SecurID® is a trademark of RSA Security LLC or its affiliates, as noted on the JPMorgan Access login page.

IP Security

IP Security adds a network-level access control by restricting login attempts to specific, pre-approved IP addresses. This means that even if an attacker obtains valid credentials and a token, they cannot access the system from an unapproved network location. IP Security can be configured at the company level (applying to all users) or at the user level (applying to individual users).

Primary Administrators should activate IP Security as part of their initial security configuration. This is done through the Access & Security Manager tab in conjunction with the RSA Authenticator setup.

Payment Control

Payment Control is a fraud prevention feature that allows organizations to define rules and policies that automatically flag, hold, or block payments based on specific criteria. This adds an automated layer of protection against fraudulent payment attempts.

Payment Control rules can be based on:

Dual Control for Transactions

Dual control ensures that no single individual can independently complete a sensitive transaction. For payments, this means one user initiates the payment and a different user must approve it before processing. For administrative changes, Dual Control Administration requires a second administrator to approve changes to user profiles, entitlements, or security settings.

This separation of duties is one of the most effective controls against both external fraud and insider threats, as it requires collusion between two authorized users to bypass the control.

Audit & Event Logs

JPMorgan Access maintains comprehensive audit trails of all activities within the platform. The Audit & Event Logs feature allows administrators to:

The Global ACH Audit Log specifically tracks all Global ACH transactions, providing a dedicated audit trail for international ACH payment activity.

User Entitlements as Security Controls

Entitlements are not just about feature access — they are a fundamental security control. By limiting each user's access to only what they need (the principle of least privilege), organizations reduce the attack surface and minimize the potential impact of compromised credentials. Security Administrators should regularly review and update entitlements to ensure they remain appropriate as roles change.

Security Best Practices

For All Users

For Administrators

Recognizing Phishing Attempts

Phishing is one of the most common attack vectors against corporate banking users. Be alert for:

J.P. Morgan will never ask for your password or RSA token code via email or phone. If you receive a suspicious communication, report it immediately to your Security Administrator and to J.P. Morgan.

Related Guides