SumUp Business Account Security Settings: Trusted Devices, Verification PIN, and Biometric Usage Checklist (UK)

Sumup

When configuring the security settings for a SumUp Business Account, first confirm the account's region and product version. This article outlines management principles for trusted devices, verification PINs, and available biometric features based on the official advanced security guidelines for the UK Business Account; these features do not eliminate all risks, and actual options and interfaces are subject to current prompts within your account.

First, confirm that this is the current feature of the UK Business Account.

Security options may vary depending on your country, product, and member role. Before proceeding, check whether advanced security settings are available in the official app or account page you're currently logged into, and then review the relevant UK help instructions. Do not install unofficial apps or change device settings based on social media screenshots or unfamiliar tutorials.

Companies should clearly define who is responsible for account security settings, who can authorize sensitive operations, and who maintains the registered contact information and devices. The clearer the role assignments, the easier it will be to determine which access rights need to be revoked, who should carry out recovery procedures, or who should handle support requests in cases of personnel changes or device loss.

Treat trusted devices and verified PINs as controlled assets

Trusted devices used to verify specific sensitive operations should be under corporate control, have screen lock enabled, and be kept by a clearly designated individual. Do not rely on an unmanaged personal device as the sole secure access point over the long term, and never share device verification codes with colleagues, outsourced personnel, or any impersonating customer service representatives.

The PIN should be set and kept confidential by authorized personnel, and must not be written in public documents, chat groups, or handover emails. Organizations may document the responsibilities for PIN custody and recovery procedures, but must not record the PIN itself in locations accessible to a broad audience.

Biometrics and notifications should be integrated with device management.

Biometric options should only be enabled on devices that are under corporate control and explicitly authorized by the user. When an employee leaves, changes roles, replaces a device, or transfers device usage to another person, the status of trusted devices and application logins should be promptly reviewed, rather than assuming old settings will automatically expire.

Enabling notifications helps identify sensitive actions requiring confirmation, but notifications themselves do not constitute authorization. When receiving an unfamiliar operation request, first verify it through the official app—do not confirm immediately based on prompts from text messages, phone calls, or chat apps.

Protect your account first when a device is lost or suspicious activity is detected

If a trusted device is lost, stolen, or shows unusual activity, promptly check your session and security settings through the official account access point and report the issue via the official support process. Do not send one-time verification codes, confirmation PINs, or personal identification information to anyone claiming they can immediately unlock your account.

It is recommended to review the list of trusted devices, member permissions, and internal approvers on a quarterly basis. While regular reviews cannot guarantee prevention of all unauthorized activities, they help reduce the risk of outdated devices, former employees, or unclaimed recovery methods remaining in accounts indefinitely.

Official Information and Frequently Asked Questions

The final verification date of this document is September 2026. Platform rules, available regions, document requirements, fees, and review processes may be subject to change; please refer only to SumUp UK Business Account Advanced Security Official Guide Please refer to the notifications within the account, and only submit genuine, valid, and personally owned corporate documents.

Can all SumUp users see the same security settings?

Not necessarily. Available features may vary by region, product, device, and member permissions, and should be based on the official instructions within your current account.

Can advanced security features completely prevent fraud?

No. They are one of the measures to reduce the risk of unauthorized access, but still require complementary practices such as device management, least privilege principle, official notification verification, and proper internal handover procedures.

What should I do if a regular member cannot manage security settings?

It should be handled by the account owner or someone with appropriate administrative privileges following official procedures. Do not use shared PINs, shared verification codes, or borrow others' devices as substitutes for proper role management.

Share Article