1. Purpose and Relationship to Governing Documents
This Client Financial Access & Payment Security Policy ("Policy") is published by VA WORKS, LLC ("Consultant") and forms part of the Governing Policies referenced in the Master Service Agreement (MSA), the MSA Terms and Conditions (https://vaworks.com/MasterServiceAgreement), and any applicable Scope of Work Terms and Conditions (https://vaworks.com/SOWSelection). In the event of conflict, priority shall be determined in accordance with the MSA.
The purpose of this Policy is to protect the financial assets, confidential information, and security of Company clients by establishing strict controls governing access to financial credentials, payment methods, banking information, and purchasing authority by Consultant personnel.
2. Policy Statement
VA WORKS is committed to maintaining the highest standards of financial security, confidentiality, and risk management. Consultant personnel are engaged to perform administrative, operational, and business support services—not to assume custody of client financial instruments or confidential financial credentials.
Accordingly, Consultant prohibits its personnel from requesting, receiving, storing, possessing, recording, or retaining unmasked financial credentials belonging to any Company client except where expressly authorized in writing by Consultant's executive management and required by law or contractual obligation.
This Policy is intended to minimize fraud risk, reduce unauthorized access to financial assets, and protect both the Company and Consultant from avoidable financial loss.
3. Scope
This Policy applies to:
- All Consultant employees.
- All Contractor of Record personnel.
- All Employee of Record personnel.
- Independent contractors.
- Temporary personnel.
- Subcontractors.
- Interns.
- Vendors performing services on behalf of Consultant.
- Any other individual performing services through VA WORKS.
4. Prohibited Access to Financial Credentials
Under no circumstances shall Consultant personnel request, receive, maintain, copy, photograph, transmit, record, save, export, or otherwise possess any of the following belonging to a Company client:
- Full credit card numbers.
- Full debit card numbers.
- Card security codes (CVV/CVC).
- Card expiration dates when combined with account numbers.
- Bank account numbers.
- Routing numbers.
- ACH credentials.
- Wire transfer credentials.
- Online banking usernames.
- Online banking passwords.
- Multi-factor authentication (MFA) codes for financial institutions.
- Security questions or authentication tokens.
- Cryptocurrency wallet recovery phrases or private keys.
- Payment processor credentials.
- Payroll credentials.
- Tax payment credentials.
- Any other financial authentication credentials capable of authorizing or facilitating the movement of funds.
The foregoing prohibition applies regardless of whether such information is communicated verbally, electronically, in writing, by photograph, by screen sharing, or through any other medium.
5. Prohibited Client Practices
Company clients shall not provide Consultant personnel with:
- Credit card information.
- Debit card information.
- Banking credentials.
- Wire instructions containing account credentials.
- Financial passwords.
- Authentication codes.
- Personal payment accounts.
- Personal banking access.
- Financial account ownership credentials.
Consultant personnel are expressly prohibited from accepting such information.
6. Payment Processing Standards
Consultant personnel may perform administrative purchasing or payment-related activities only when all of the following conditions exist:
- The Company maintains exclusive ownership and control of the purchasing platform.
- Financial credentials remain encrypted or tokenized.
- Complete payment credentials are not visible to Consultant personnel.
- Consultant personnel cannot retrieve or reconstruct complete payment credentials.
- Consultant personnel cannot export financial credentials.
- Consultant personnel cannot add, replace, or modify payment methods unless specifically authorized by the Company within the secure platform.
Examples include:
- Amazon Business accounts with stored payment methods.
- Microsoft or Google subscriptions utilizing stored payment profiles.
- ERP systems with masked payment credentials.
- Secure procurement platforms.
- Accounting systems displaying only tokenized or masked payment information.
7. Personal Account Prohibition
Under no circumstances may Consultant personnel:
- Save a Company payment method to a personal Amazon account.
- Save a Company payment method to a personal online marketplace.
- Save a Company payment method to a browser.
- Save a Company payment method to a mobile wallet.
- Save a Company payment method to a password manager.
- Associate Company payment credentials with any personally owned account or profile.
- Use Company payment methods for personal purchases.
- Utilize Company credentials outside Company-authorized systems.
This prohibition applies even if authorized verbally by the Company.
8. Financial Transactions Requiring Sensitive Credentials
If a requested task requires Consultant personnel to view or receive:
- a full credit card number;
- a full debit card number;
- a bank account number;
- a routing number;
- online banking credentials;
- payment authentication credentials; or
- any other confidential financial information,
the Consultant personnel shall immediately decline the request and notify Company that the requested activity cannot be performed under this Policy.
Such tasks must instead be completed directly by Company personnel or through a secure system that masks or tokenizes the required financial information.
9. Client Responsibility
Company retains sole responsibility for:
- determining appropriate access permissions;
- granting purchasing authority;
- configuring financial systems;
- maintaining internal security controls;
- selecting payment methods;
- revoking user access;
- monitoring financial transactions; and
- protecting its own financial accounts.
Consultant does not supervise, administer, or control Company financial systems or internal authorization procedures.
Company acknowledges that voluntarily providing financial credentials or unrestricted purchasing authority contrary to this Policy materially increases operational risk.
10. Reporting Requirements
If Consultant personnel receive financial credentials contrary to this Policy, they shall:
- Immediately cease handling the information.
- Decline acceptance of the credentials.
- Notify Company that the request violates Consultant policy.
- Immediately report the incident to Consultant management.
- Permanently delete or destroy any inadvertently received financial information when legally permissible.
Failure to report such incidents may result in disciplinary action.
11. Access Revocation
Upon separation, reassignment, or termination of any Consultant personnel assigned to a Company account, Company is solely responsible for promptly revoking access to:
- Microsoft 365.
- Google Workspace.
- Amazon Business.
- CRM platforms.
- Accounting systems.
- Purchasing systems.
- Password managers.
- Single Sign-On (SSO) systems.
- Any other Company-controlled applications or services.
Consultant may notify Company of personnel changes but cannot revoke access to systems owned or controlled by Company.
12. Confidentiality
Any financial information inadvertently disclosed shall remain Confidential Information under the MSA and all applicable confidentiality obligations.
Receipt of such information shall not create authorization to use, store, disclose, copy, retain, or transmit the information.
13. Violations
Violation of this Policy by Consultant personnel may result in:
- Immediate removal from Company accounts.
- Immediate termination of assignment.
- Termination of employment or contractor relationship.
- Civil action.
- Criminal referral where applicable.
- Any additional remedies available under applicable law or contract.
Nothing in this Policy limits Consultant's right to pursue damages or equitable relief.
14. No Assumption of Financial Custody
Consultant is not a bank, financial institution, escrow agent, fiduciary, payment processor, or custodian of Company financial assets.
Nothing contained in this Policy shall be interpreted as creating a duty for Consultant to manage, monitor, insure, or safeguard Company financial accounts beyond the obligations expressly assumed under the governing agreements.
15. Policy Updates
Consultant reserves the right to amend this Policy from time to time. Updated versions shall become effective in accordance with the amendment provisions contained in the Governing Documents.
