import { Callout } from "zudoku/ui/Callout";

# Bank access: company, personal and EBICS participant

This page describes how Business Central identifies itself to the bank: through the company bank access, personal bank access and EBICS participants in 365 business Banking.

An access belongs to the [bank connection](choose-bank-connection.mdx), not to a single bank account. You therefore set it up once per company. After that, you can connect every further bank account without setting up the access again.

| | **Company bank access** | **Personal bank access** | **EBICS participant** |
|---|---|---|---|
| For | PSD2/XS2A via finAPI and verification of payee | PSD2/XS2A via finAPI, when your bank issues personal credentials | EBICS |
| Number | exactly one per company | one per person | one per bank |
| Applies to | every bank account of the company | the accounts this person connected themselves | the accounts in this bank's EBICS contract |
| Location | **Banking Setup** > **Company Bank Access** | **Personal Bank Accesses** | **EBICS Participants** |
| Created | during setup | via **Use With My Own Bank Login** on the bank account card | by creating and initializing it |

Bank accounts that you keep via [camt/pain files](../connections/iso20022-file/index.mdx) require no access, because Business Central does not communicate with a bank for them.

## Company bank access (always required)

The **company bank access** is the identity that Business Central uses towards finAPI. There is one per company, and it applies to every bank account.

<Callout type="caution" title="Set it up in every case">
**Verification of payee** runs exclusively via finAPI and signs in with the company bank access. This also applies if you do not connect any account via finAPI but only via EBICS or by file. Without this access, no verification of payee takes place.
</Callout>

You do not need to enter a password. Business Central generates one and stores it securely. You only check the **Email Address** and **Phone Number** that finAPI uses to contact you when a bank requires renewed consent. The procedure is described under [Banking setup](../setup/banking-setup.mdx).

## Personal bank access

Some banks issue **personal online banking credentials**: every person has their own login and TAN method. In this case, the bank requires the credentials and TAN of the person who makes the payment.

For this purpose, each person creates a **personal bank access** with **Use With My Own Bank Login**. If they connect another bank account later, their existing access is reused. Towards finAPI, they are **one** user.

<Callout type="info" title="Not required with a shared company login">
If your bank issues a shared login for the company, the company bank access is sufficient. Personal bank access is not relevant for EBICS and the file route.
</Callout>

How to create and remove a personal bank access is described in [Use with my own bank login](../connections/psd2/personal-bank-access.mdx).

## EBICS participant

An **EBICS participant** is your access to **one** bank. It consists of the bank URL, host ID, partner ID, user ID and a key pair that belongs exclusively to your company. If you have EBICS contracts with several banks, create one participant per bank.

A participant belongs to the company, not to a person. It signs payments with its key, without a TAN and also in the background. Only a participant with the status **Ready** can connect bank accounts. Because of the initialization letter, setup takes a few days. See [Set up an EBICS participant](../connections/ebics/participant.mdx).

## Who reads, who pays

A bank account is read through **exactly one** access, usually the company bank access. In addition, any number of people can **pay** from it with their own access.

The access through which transactions are retrieved determines the numbers under which they arrive. If two accesses read the same account, every booking would arrive twice, under numbers that cannot be matched to each other.

On the bank account card, the **Who Can Use This Account** FactBox shows **Reads Transactions** and **Can Pay** for each access. It is only displayed if at least one personal bank access is assigned to the bank account.

## Which access Business Central uses when

Business Central determines the following two points separately and without prompting you:

| Operation | Access used |
|---|---|
| **Retrieving transactions** | The account's single reading source, regardless of who starts the retrieval, on screen or in the job queue. |
| **Payment** | The signed-in person's own access, if they have one for this account. Otherwise, the company bank access. |

<Callout type="info" title="An assignment alone is not enough">
A personal access is only used for an account once the person has connected the account themselves in their bank's web form. Until then, **Assigned Bank Accounts** shows the status *Not connected yet*, and the company bank access applies.
</Callout>

You cannot pay on behalf of another person, because Business Central never uses another person's credentials. If another person is to pay, that person carries out the payment themselves.

## See also

- [Banking setup](../setup/banking-setup.mdx)
- [Use with my own bank login](../connections/psd2/personal-bank-access.mdx)
- [Set up an EBICS participant](../connections/ebics/participant.mdx)
- [One bank access for several companies](../connections/multi-company.mdx)
- [Account information service and payment initiation service](account-information-payment-initiation.mdx)
