This guide is provided by Alt21 Limited, trading as Alt21, an FCA authorised payments and FX provider and is intended for UK businesses making international payments. Please read the full disclaimer at the bottom of the page.
Payment processing security is often discussed in the context of card payments. You’ll hear about checkout encryption, tokenisation and chargeback protection.
But if your business is paying an overseas supplier, receiving money in another currency or running international payroll, there’s more to consider.
Cross-border payments can involve several banks, payment networks and regulatory requirements before the money reaches its destination. Each stage introduces different checks, processes and potential points of vulnerability.
Understanding how that journey works can help you ask better questions about the providers you trust with your payments.
Read on to understand how security works across cross-border FX payments, where risks can arise and what to look for when choosing a provider.
What payment processing security means for cross-border payments
Payment security covers the payment from the moment you initiate it until the money reaches its destination.
For cross-border payments, that journey can involve more steps.
For example, if a UK business pays a supplier in Ireland or the Netherlands, the payment may involve currency conversion before the instruction passes through banks and payment networks to reach the recipient’s account.
That means security needs to work throughout the payment journey.
The technology you use to initiate the payment needs to be secure, the payment instruction needs to remain accurate as it moves between institutions and, where a provider holds client funds during the process, those funds need to be appropriately safeguarded.
Safeguarding is the regulatory framework designed to keep certain client funds separate from a payment provider’s own money, so that they can be returned to customers if the provider fails. It does not guarantee that every customer will receive their money back in full or quickly.
So when you’re looking at the security of an international payment provider, there are three areas worth understanding:
- How you initiate and authorise payments: including the security controls around your account and payment approvals
- How payment instructions are handled: including how information is transmitted between the institutions involved
- How your money is safeguarded: including what happens to eligible funds while the provider holds them

How FX payment security differs from card payment security
Card and cross-border payments don’t carry the same security risks because they move money in different ways.
With a card payment, much of the focus is on protecting card details. Measures such as tokenisation can replace sensitive card information with a substitute value, while standards such as PCI DSS set requirements for how cardholder data is handled.
Cross-border FX payments don’t rely on card details. Instead, a business provides beneficiary information and instructs money to be sent to a bank account, sometimes alongside a currency conversion.
That means security is focused on different parts of the payment process, from controlling who can access and authorise payments to protecting beneficiary details and making sure payment instructions aren’t altered along the way. Fraud is one of the risks these controls are designed to address. For example, a fraudster could impersonate a supplier or provide false bank details so that a genuine payment is sent to the wrong account.

Security also extends beyond the payment instruction itself. Depending on where and how a provider operates, it may be regulated by authorities such as the FCA in the UK, national regulators across the EU or other relevant financial authorities. These regulatory frameworks can cover areas including safeguarding client funds, financial crime controls and operational resilience.
So when you’re assessing a provider, card security credentials only tell you part of the story. You also need to understand the controls they use for account access, payment instructions, beneficiary details and client funds.
Key security measures a payment processor should have
When you’re comparing providers for cross-border payments, security isn’t one feature or certification. It comes from several controls working together to protect your account, payment instructions, data and eligible funds.
Encryption
Encryption helps protect sensitive information both when it’s being sent and when it’s stored.
For businesses making FX international payments, that can include account information, beneficiary details and payment instructions.
Safeguarding of client funds
If a payment provider holds eligible client funds, how those funds are safeguarded is worth understanding.
In the UK, certain payment and e-money firms are required to safeguard relevant customer funds. Since May 2026, CASS 15 1 has strengthened those requirements, including rules around reconciliations, record-keeping and the segregation of relevant funds.
The distinction is worth knowing because safeguarding isn’t the same as deposit protection. Funds held by payment and e-money firms aren’t directly covered by the Financial Services Compensation Scheme (FSCS).

Strong customer authentication
A password shouldn’t necessarily be the only thing standing between someone and your business account.
Strong customer authentication (SCA) can require more than one way of verifying a user for certain payments or account actions. Depending on the circumstances, that might combine something you know, such as a password, with something you have or something unique to you.
Payment monitoring and approval controls
Security also depends on what happens once someone is inside the account.
Fraud monitoring can help identify payment activity that falls outside expected patterns, while approval controls can allow businesses to require more than one person to authorise certain payments. For finance teams, these controls can add another layer between creating a payment and money actually leaving the account.
Where security risks can arise in cross-border payments
Even when the payment system itself is secure, problems can arise at different points in the journey. Some involve fraud targeting the business making the payment, while others relate to the institutions and systems involved in moving money across borders.
Fraudulent payment instructions
A significant risk comes before the payment has even been sent.
Authorised push payment (APP) fraud happens when someone is tricked into sending money to a fraudster. For a business, that could mean receiving an invoice that appears to come from a genuine supplier but contains different bank details, or responding to an email from someone impersonating a trusted contact.
Because the payment has been authorised by the business, controls designed to identify unauthorised access may not necessarily stop it.
There’s another consideration when the payment crosses borders. UK reimbursement protections for APP fraud apply only to eligible customers, such as consumers, micro enterprises and small charities, and only for payments made through Faster Payments and CHAPS.
Many businesses will not be eligible, and the protections do not extend to international payments, which can leave businesses with fewer routes to recover money once it has been sent overseas.
Compromised payment instructions
Cross-border payments often rely on messaging networks such as SWIFT to communicate payment instructions between financial institutions.
The network itself doesn’t necessarily need to be compromised for fraud to occur. An attacker could instead target an individual institution or its access to the network, using compromised credentials to send instructions that appear legitimate.
SWIFT operates a Customer Security Programme that sets security controls for organisations connected to its network. For a business choosing a payment provider, understanding how that provider secures its payment infrastructure and access can form part of the wider security assessment.
Different regulatory environments
An international payment may involve financial institutions in several countries, which can mean different regulatory requirements apply at different stages.
That makes it worth understanding which entity you’re actually dealing with, where it is regulated and which one is responsible for your funds and payment. A familiar brand name alone doesn’t necessarily tell you how a particular payment is being handled.
What to look for in a payment processing solution
Security claims can sound reassuring, but they don’t always tell you much about what happens to your money or your payment once you press send. A few practical checks can give you a clearer picture of how a provider operates.
Check who you’re actually dealing with
Start by checking which legal entity will provide the service, where it is authorised and which regulator oversees it.
If a provider operates across several markets, don’t assume that one authorisation covers every entity or service.
You can usually verify this information through the relevant financial regulator’s register.
Ask how your money is safeguarded
If a provider holds eligible client funds, ask what safeguarding arrangements are in place.
- Where are the funds held?
- How are they kept separate from the provider’s own money?
- How frequently are they reconciled?
- Are those arrangements independently audited?

These aren’t questions to overlook simply because a provider is regulated.
In a press release in August 2025, the FCA reported 2 that payment firms that became insolvent between Q1 2018 and Q2 2023 had average shortfalls of 65% of their customers’ funds.
The safeguarding regime has since been strengthened, but it’s still worth understanding how your provider handles your money.
Look beyond security badges
A security certification is more useful when you know what sits behind it. Look for a named security standard, when the provider was last assessed and whether testing or certification was carried out independently.
The same applies to claims such as “bank-grade security”. Without information about the actual controls in place, the phrase doesn’t tell you very much.
Check what controls you have
Some security measures should give your finance team greater control over how payments are made.
For example:
- Can you set different permissions for different users?
- Can one person create a payment while another approves it?
- Can you control who can add or change beneficiary details?
These controls can add another checkpoint before money leaves the account, particularly when fraudsters use impersonation or social engineering to target employees.
Find out what happens when something goes wrong
Even strong security controls can’t prevent every mistake or fraud attempt.
Before choosing a provider, find out what happens if you send money to the wrong account, spot an unfamiliar payment or believe you’ve been targeted by fraud.
Check who you need to contact, how quickly the provider can respond and what steps they can take to try to trace or recover a payment.
You may be interested in reading our blog on common international payment mistakes.
Payment app security: what matters for FX platforms
There’s another part of payment security to consider:
The platform your team uses to manage payments.
Whether you access it through a web platform or mobile app, the security controls around your account can affect who can view information, create payments, change beneficiary details and approve transactions.
The UK’s National Cyber Security Centre (NCSC) Cloud Security Principles 3 provide a useful framework for assessing cloud-based services. They cover areas including authentication, access controls, data protection, operational security and audit information.
For your finance team, those principles translate into some much more practical things to look for:

Login and authentication
Look at how the platform verifies users when they log in and when they carry out sensitive actions.
Additional authentication around actions such as adding or changing a beneficiary can provide another checkpoint before payment details are updated.
User roles and permissions
If several people use the platform, you may not want everyone to have the same level of access.
Role-based permissions can give different team members different responsibilities, such as allowing one person to create a payment and another to approve it. An audit trail can also give you a record of who created, changed or approved an action and when.
Device and session management
It should also be possible to understand where and how your account is being accessed.
Features such as active-session management, the ability to revoke access and notifications about unfamiliar logins can help your team identify account activity that doesn’t look right.
Monitoring and incident response
Security also depends on what happens behind the scenes. Look at how a provider monitors suspicious activity, protects its own administrative access and responds when a potential security incident is detected.
Checklist for choosing an FX payment provider
Before you trust a provider with your international payments, there are a few things worth checking:
Who regulates the provider?
Check the relevant regulator’s register and make sure you understand which legal entity will provide your service.
How are eligible client funds safeguarded?
Ask where funds are held, how they’re kept separate and how the provider reconciles and reviews its safeguarding arrangements.
What controls does the platform give your team?
Look for features such as strong authentication, user permissions and multiple levels of payment approval.
Can its security credentials be verified?
Look for recognised security standards or independent assessments rather than broad claims about being “secure”.
What happens if something goes wrong?
Find out who you contact if a payment is sent incorrectly or you suspect fraud, and what processes the provider has for responding.

These are questions you can ask of any provider, including Alt21.
Alt21 Limited is authorised and regulated by the Financial Conduct Authority (FRN: 783837) and provides services to UK clients. You can find details of our regulatory status, including the relevant regulators and registration information, on our regulatory information page.
Whichever provider you’re considering, look beyond security claims on its website. Check its regulatory status independently, understand how your money and payment instructions are handled and look at the controls your team will have when using the platform.
ALT21 Limited is authorised and regulated by the Financial Conduct Authority (FRN: 783837) and is a company registered in England and Wales (number 10723112). The registered address is 45 Eagle Street, London WC1R 4FS, United Kingdom. This article has been produced by ALT21 Limited for information purposes only. It does not constitute financial advice or an offer to sell or the solicitation of an offer to buy any products referenced. Hedging products are not suitable for every business. Before entering into any FX product, you should consider whether it is appropriate for your needs and circumstances. ALT21 Limited assumes no liability for errors, inaccuracies or omissions. Eligibility criteria and terms and conditions apply to all products and services offered by ALT21 Limited. Not all applications will be accepted.


