Security and Fraud Prevention Controls in Synovus Gateway
Commercial digital banking / risk configuration guide
Security and fraud prevention in Synovus Gateway is a stack of overlapping controls that together decide who can log in, what each person may do, which payments require a second set of hands, and how unusual activity is surfaced before money leaves an account. This page explains how those controls fit together inside Synovus Gateway, how a company administrator configures them, and where the responsibility for keeping funds safe sits between the bank and the business. Everything described here lives within the same Synovus Gateway platform that treasury teams use day to day.
The guiding principle across Synovus Gateway is defense in depth. No single control is treated as sufficient on its own. Strong authentication reduces the chance an outsider ever reaches the platform, granular entitlements limit what a compromised or careless insider can touch, dual control forces collusion or oversight on high-risk actions, and continuous monitoring provides a safety net for the cases the earlier layers miss. Understanding each layer, and how it interacts with the others, is the difference between a Synovus Gateway deployment that merely functions and one that genuinely protects the business.
Nearly every control described here is configurable, which means the security posture of a given company on Synovus Gateway is largely a reflection of the choices its administrators make. Synovus Gateway ships defaults that lean conservative, but the tightest protection comes from deliberately tuning entitlements, approval thresholds, and alerts to the way the organization actually moves money. In other words, Synovus Gateway hands the company a set of tools, and the outcome depends on how carefully those tools are wired together.
Authentication and Secure Access
The first layer
Authentication is where the security story of Synovus Gateway begins. Before any user can view a balance or stage a payment, Synovus Gateway has to be confident that the person logging in is who they claim to be. That confidence is built from more than a password, because passwords alone are the single weakest point in any commercial banking system and the most frequent target of phishing and credential theft.
Synovus Gateway pairs the standard company ID, user ID, and password with multi-factor authentication, so that a stolen password is not enough to complete a login. The additional factor comes from something the user physically controls, typically a one-time code delivered to a registered device or generated by a token. The intent is straightforward. An attacker who has phished a password still cannot reach the account in Synovus Gateway, because they cannot produce the second factor tied to the legitimate user's device.
Device recognition works alongside multi-factor authentication in Synovus Gateway. When a user logs in from a machine the platform has seen and trusts before, the experience is smoother. When the login originates from an unrecognized device, an unusual location, or an unexpected time, Synovus Gateway can escalate to a stronger challenge. This adaptive behavior means routine access stays low-friction while anomalous access is met with additional scrutiny, which is exactly where the risk concentrates.
Session controls form another quiet but important part of the authentication layer. Synovus Gateway enforces inactivity timeouts, so an unattended workstation logs itself out rather than sitting open to whoever walks by. Sessions are encrypted end to end, and Synovus Gateway limits how long a session can remain valid. These measures address a category of risk that has nothing to do with stolen credentials and everything to do with physical access to an already-authenticated screen.
Administrators should treat multi-factor authentication as mandatory for every user of Synovus Gateway, not optional for a privileged few. The cost of an exempted user is a single unprotected door in an otherwise locked building.
Entitlements, Roles, and Least Privilege
Limiting the blast radius
Once a user is authenticated, the question shifts from who they are to what they are allowed to do. This is the domain of entitlements, and it is where Synovus Gateway gives administrators the most direct control over risk. The core idea is least privilege. Every user should hold exactly the permissions their job requires and nothing more, because a permission a user does not have cannot be abused, whether the abuse comes from the user or from an attacker who has taken over their account.
Entitlements in Synovus Gateway are granular. They can be set per account, per service, and per function. A user might be entitled to view balances on one set of accounts but not another, permitted to originate ACH payments but not wires, or granted reporting access with no ability to move funds at all. This precision matters because commercial fraud often exploits the gap between what a user needs and what a user can technically do. Closing that gap in Synovus Gateway shrinks the surface an attacker can act upon.
Dollar limits add a second dimension to entitlements. Beyond deciding whether a user can originate a payment type, Synovus Gateway lets administrators cap how much a user can move, both per transaction and in aggregate over a period. A clerk who routinely processes small vendor payments does not need the authority to send a seven-figure wire, and setting the limit in Synovus Gateway to match reality means that even a fully compromised account cannot generate a catastrophic loss on its own.
Role templates make this manageable at scale. Rather than configuring each user by hand, administrators can define standard roles that bundle the appropriate entitlements and limits, then assign users to those roles. Synovus Gateway keeps the roles consistent, so a company with dozens of users does not drift into a patchwork of ad hoc permissions that nobody fully understands. Consistency is itself a security property, because unexamined exceptions are where risk hides, and Synovus Gateway is designed to keep those exceptions visible.
A discipline that pays off repeatedly is periodic entitlement review. People change jobs, leave the company, or take on new duties, and their access in Synovus Gateway should change with them. Access that outlives its purpose, the account of a departed employee that was never disabled, the elevated permissions a user kept after a temporary project ended, is a standing liability. Synovus Gateway provides the visibility to conduct these reviews, but the review itself is a business responsibility that Synovus Gateway cannot perform on the company's behalf.
Dual Control and Transaction Approvals
Separation of duties
Dual control is arguably the single most effective fraud prevention control available in commercial banking, and Synovus Gateway is built to support it thoroughly. The concept is simple. A payment that one person initiates must be reviewed and released by a different person before it takes effect. Two individuals with separate credentials have to agree that a transaction is legitimate. That requirement defeats the most common fraud pattern of all, which is a single compromised account initiating and completing a fraudulent payment without anyone else in the loop.
In Synovus Gateway, the initiator and the approver are enforced as distinct roles. The person who creates a wire or an ACH batch cannot also be the person who approves it. This separation of duties means that for a fraudulent payment to succeed, an attacker would need to compromise two independent users of Synovus Gateway, or two employees would need to collude, both of which are far harder to achieve than taking over a single account. The bar is deliberately high.
Approval workflows in Synovus Gateway can be tiered by dollar amount. A modest payment might require one approver, while a large payment requires two, and an exceptionally large one requires a senior approver in addition. Administrators configure these thresholds to match the company's own risk tolerance. Synovus Gateway then enforces them automatically, so the level of scrutiny a payment receives scales with the amount of money at stake without anyone having to remember to escalate manually.
The approver's view in Synovus Gateway is designed to make review meaningful rather than perfunctory. The person releasing a payment sees the beneficiary, the amount, the account, and the origination details, and Synovus Gateway can flag when a payment goes to a beneficiary that has not been used before. A thorough approver is the human intelligence that catches a fraudulent payment that every automated control let through, and Synovus Gateway gives that person the information needed to make the catch.
Dual control only works if the approver actually reviews. A workflow where the second person clicks approve reflexively provides the appearance of control without the substance. Train approvers in Synovus Gateway to treat every release as a decision, especially for new beneficiaries and unusual amounts.
Payment Fraud Prevention Tools
Check and ACH defenses
Beyond the controls that govern how the company's own users behave, Synovus Gateway integrates with fraud prevention services aimed at threats that come from outside. Two of the most established of these are Positive Pay and ACH debit filtering, both of which address the problem of unauthorized items posting against a company's accounts. Both are surfaced and managed inside Synovus Gateway.
Positive Pay works by comparing checks presented for payment against a list of checks the company actually issued. When the company writes checks, it uploads a file of check numbers, amounts, and often payee names to Synovus Gateway. As checks are presented, the bank matches each one against that issued file. Any check that does not match, a check number that was never issued, an amount that has been altered, or a payee that has been changed, is flagged as an exception for the company to review and decide whether to pay or return. Check fraud remains stubbornly common, and Positive Pay through Synovus Gateway is the primary defense against it.
Payee Positive Pay extends this protection to the payee name itself, which catches a class of fraud where a genuine check is intercepted and the payee is altered while the amount and check number stay the same. Reverse Positive Pay offers a lighter-weight variant where the company reviews all presented checks rather than uploading an issued file first. Synovus Gateway supports these variations so the company can choose the level of rigor that fits its check volume and its risk appetite.
On the electronic side, ACH debit filtering and blocking address unauthorized withdrawals initiated through the ACH network. A company can instruct Synovus Gateway to block all ACH debits against an account, or to allow only debits from a pre-approved list of originators. Any debit from a party not on the list is stopped and presented as an exception in Synovus Gateway. This is a powerful control for accounts that should never see an outside ACH debit, and it neutralizes a common attack where a fraudster with a stolen account number simply pulls funds electronically.
Wire transfers, being irrevocable and high value, receive particular attention in Synovus Gateway. Beyond dual control and dollar limits, Synovus Gateway supports beneficiary controls and callback verification procedures for high-value wires. Business email compromise, where a fraudster impersonates an executive or a vendor to request an urgent wire, is one of the costliest fraud schemes in commercial banking, and the layered wire controls in Synovus Gateway are specifically positioned to interrupt it before the funds move.
Exception handling ties these tools together. Positive Pay and ACH filtering only protect the company if someone actually reviews the exceptions Synovus Gateway surfaces and makes a pay or return decision within the bank's cutoff window. An exception that is ignored defaults according to the company's configured setting in Synovus Gateway, so administrators should set those defaults thoughtfully and assign clear ownership for daily exception review.
Monitoring, Alerts, and Audit Trails
The safety net
Prevention controls stop most fraud, but detection controls catch what prevention misses, and Synovus Gateway invests heavily in giving companies visibility into their own activity. Real-time alerts are the front line of detection. Administrators and users can configure Synovus Gateway to notify them when specific events occur, and the value of these alerts is that they compress the time between a suspicious event and a human noticing it.
Useful alerts to enable in Synovus Gateway include notifications for large transactions above a threshold, for new user creation or entitlement changes, for logins from new devices, for wires initiated or approved, and for balances crossing a set level. A wire alert that reaches a treasurer's phone within seconds of a payment being approved in Synovus Gateway gives the company a chance to intervene while the funds may still be recoverable, which is a materially different outcome than discovering the loss on a monthly statement.
Audit trails provide the forensic record. Synovus Gateway logs who did what and when across the platform, capturing logins, entitlement changes, payment initiations, approvals, and administrative actions with timestamps. When something goes wrong, the audit trail in Synovus Gateway is how the company reconstructs what happened, identifies which account was involved, and determines whether a control failed or was bypassed. It is equally valuable as a deterrent, because users who know their actions are logged behave differently than users who believe they are anonymous.
The administrative activity report deserves special mention. Changes to users, roles, entitlements, and limits are among the most sensitive events in Synovus Gateway, because an attacker who gains administrative access can quietly weaken every other control. Reviewing the administrative activity log in Synovus Gateway on a regular cadence is one of the highest-value routine tasks a company can perform, since it is often the earliest place an account takeover or an insider abuse becomes visible.
On the bank's side, Synovus Gateway is backed by fraud monitoring that watches for patterns a single company might not recognize on its own. Behavioral analytics can flag activity that deviates from a company's established baseline, and this bank-side layer operates continuously behind the company-facing controls of Synovus Gateway. Together, the company's configured alerts and the bank's monitoring form the detection safety net beneath the prevention layers of Synovus Gateway.
Control Reference
The table below summarizes the principal security and fraud controls available in Synovus Gateway, the threat each one addresses, and who is responsible for configuring it. Use it as a checklist when reviewing a Synovus Gateway deployment.
| Control | Threat Addressed | Layer | Owner |
|---|---|---|---|
| Multi-factor authentication | Credential theft, phishing | ACCESS | ADMIN |
| Granular entitlements | Insider abuse, account takeover reach | ACCESS | ADMIN |
| Dollar limits | Large fraudulent transfers | ACCESS | ADMIN |
| Dual control / approvals | Single-account fraud, BEC | PREVENT | ADMIN |
| Positive Pay | Check fraud, altered checks | PREVENT | COMPANY |
| ACH debit filter / block | Unauthorized ACH withdrawals | PREVENT | COMPANY |
| Real-time alerts | Delayed detection | DETECT | USER |
| Audit trails | Forensics, deterrence | DETECT | BANK/ADMIN |
| Behavioral monitoring | Anomalous patterns | DETECT | BANK |
Read across the rows and a pattern emerges. The access and prevention layers of Synovus Gateway are overwhelmingly owned by the company and its administrators, while only the deepest monitoring sits with the bank. That distribution is the whole point of the shared model, and it is why a review of any Synovus Gateway deployment should start with the controls the company itself is expected to configure.
Configuring Your Controls
Turning the capabilities of Synovus Gateway into an actual security posture is a sequence of deliberate configuration decisions. The following steps are ordered so that each builds on the one before it, and each is carried out within Synovus Gateway.
-
01
Enforce authentication
Require multi-factor authentication for every user of Synovus Gateway without exception, and confirm that session timeouts are set to a value appropriate for your environment.
-
02
Map roles and entitlements
Define role templates in Synovus Gateway that reflect real job functions, apply least privilege, and set per-transaction and aggregate dollar limits that match how each role actually operates.
-
03
Enable dual control
Turn on separated initiator and approver roles in Synovus Gateway for wires and ACH, and set tiered approval thresholds so higher amounts require additional approvers.
-
04
Activate fraud services
Enroll eligible accounts in Positive Pay and ACH debit filtering through Synovus Gateway, assign daily exception review to a named owner, and set safe default decisions for unreviewed exceptions.
-
05
Configure alerts and review
Set up real-time alerts for high-risk events in Synovus Gateway, and schedule regular reviews of entitlements and the administrative activity log to catch drift and abuse early.
None of these steps is one-and-done. The strongest Synovus Gateway deployments revisit each of them on a schedule, because a company's people, accounts, and payment patterns keep changing, and a configuration that was tight last year can quietly loosen. Treat this list as a recurring audit of Synovus Gateway rather than a launch checklist you complete once.
Shared Responsibility
Where the lines fall
Security in Synovus Gateway is a partnership, and being clear about who owns what prevents the dangerous assumption that the other party is handling it. The bank is responsible for the platform itself, the encryption of data in transit and at rest, the underlying infrastructure, and the bank-side fraud monitoring that watches for patterns across the customer base. These are the controls of Synovus Gateway the company cannot see and does not configure.
The company is responsible for how it uses Synovus Gateway. That includes managing its own users, keeping entitlements aligned with job duties, enabling and honoring dual control, subscribing to and reviewing exceptions from fraud services, and acting on alerts. Most losses in commercial banking trace back not to a failure of Synovus Gateway itself but to a configuration or process weakness on the customer side, an approver who did not review, an entitlement that was too broad, an exception that went unwatched.
Individual users carry the last mile of responsibility. They protect their own credentials, they refuse to share logins, they stay alert to phishing and business email compromise, and they treat the second factor as something never to be handed over to a caller claiming to be from the bank. No control in Synovus Gateway can protect a company from a user who willingly gives an attacker their password and their one-time code, which is precisely what social engineering is designed to accomplish.
Understanding this division is what makes the layered model of Synovus Gateway effective in practice rather than merely on paper. The strongest deployments are the ones where the bank's platform controls, the company's configuration choices, and each user's daily habits all reinforce one another inside Synovus Gateway. Reputable reporting on the scale of business email compromise and payment fraud, such as coverage from Reuters, underscores why treating any single layer as sufficient is a mistake the layered approach in Synovus Gateway is designed to prevent.
Frequently Asked Questions
Is multi-factor authentication required for all users?
Multi-factor authentication should be applied to every user of Synovus Gateway. It is the primary defense against phishing and stolen passwords, and any exempted user represents an unguarded entry point that undermines the rest of the Synovus Gateway security stack.
What is the difference between dual control and entitlements?
Entitlements decide what a single user is permitted to do in Synovus Gateway. Dual control requires that a second, different user approve certain actions before they take effect. Entitlements limit each individual's reach, while dual control in Synovus Gateway ensures no single individual can complete a high-risk payment alone.
How does Positive Pay protect against check fraud?
Positive Pay in Synovus Gateway matches checks presented for payment against a file of checks the company actually issued. Any mismatch in check number, amount, or payee is flagged as an exception for the company to pay or return, stopping counterfeit and altered checks before they clear.
Can dollar limits stop a compromised account from causing large losses?
Yes. By capping per-transaction and aggregate amounts per user in Synovus Gateway, an administrator ensures that even a fully compromised account cannot move more than the limit allows. Setting limits in Synovus Gateway to match real job needs is one of the most effective ways to contain the damage from account takeover.
What happens to a Positive Pay exception if no one reviews it?
Unreviewed exceptions default according to the setting the company configured in Synovus Gateway, either to pay or to return, within the bank's cutoff window. Because that default determines the outcome when a review is missed, administrators should set it deliberately and assign clear daily ownership of exception review.
Why review the administrative activity log?
Administrative changes to users, roles, and limits are the most sensitive events in Synovus Gateway, because an attacker with admin access can quietly weaken every other control. Reviewing the administrative log in Synovus Gateway regularly is often the earliest way to detect an account takeover or insider abuse.
Who is responsible if fraud occurs?
Responsibility is shared. The bank secures the platform and monitors for patterns, while the company owns its user management, control configuration, and exception review in Synovus Gateway. Many losses trace to a customer-side gap rather than a failure of Synovus Gateway, which is why proper configuration matters so much.
Do these controls protect against business email compromise?
The layered wire controls in Synovus Gateway, dual control, dollar limits, beneficiary review, and callback verification, are specifically positioned to interrupt business email compromise. The decisive factor is a trained approver in Synovus Gateway who scrutinizes new beneficiaries and urgent requests rather than approving reflexively.