What we are doing
What we are doing to protect you
We know you want the convenience of banking online without constantly worrying about the security of your money and your personal information.
We take your online safety seriously, that’s why we use state of the art anti-fraud systems to identify unusual activity and a telephone challenge process to block fraudsters even in in the unlikely event that they get hold of your details.
We also give you peace of mind with our online fraud guarantee.
Our online anti-fraud system
Card readers and password tokens are one security option but we use a different online anti-fraud system for customers. We're constantly improving our security to prevent online fraud and Enhanced Internet Authentication is another measure to make you even safer online. If a fraudster acquires your sign in details and gains access to your accounts, they are unlikely to have access to your phone as well.
How Enhanced Internet Authentication works to prevent fraud.
When you set up a new recipient, new standing order or reset your online security details, we may call you to make sure the request is genuine. All you need is a phone nearby. You'll be able to choose which number we call you on, provided it's a number we already hold for you. You'll receive an automated call asking you to confirm the details about your transaction and then to enter a four digit number that will appear on your computer screen into your phone keypad.
Unfortunately, the phone security check isn't compatible with a Textphone. Customers with a hearing impairment can follow the onscreen instructions while the security check is in progress. If you use a mobile to text friends and family, we recommend you include this number in the mobile section of your phone details. If security checked, you can then select your mobile number and follow on screen instructions. If you are unable to do this then please visit your local branch or contact us by textphone and we will arrange the payment for you.
Help us contact you
In order for the phone security check to be effective we need you to provide us with up to three phone numbers, for example work, mobile and home, as we may need to contact you to verify your activity whilst you are logged in to our online service.
It’s important that you provide as many different phone numbers as you can to make it easier for us to contact you.
You can find more information on how the phone security process works.
When using our Online Banking service your security is our number one priority. Card readers and password tokens are one security option but we use a different online anti-fraud system for customers. We're constantly improving our security to prevent online fraud and Enhanced Internet Authentication is another measure to make you even safer online.
What is Enhanced Internet Authentication (EIA)?
Why have you introduced phone security checks?
Is there a charge for this service?
What happens if I don’t supply my phone numbers?
If I update my phone number online will I be able to use this number immediately?
What happens if I do not answer the call?
What should I do if my access is suspended?
What if I receive a call asking me to confirm a recipient I did not set up, what do I do?
Will I need to have my phone with me every time I want to make a payment?
You don’t hold any numbers for me so how can I set up a new recipient?
I have a dial up connection; can I give my landline number?
How will the security call work for dial up users?
Can I use a Textphone to receive the phone security check?
Can I use VoIP (Voice over Internet Protocol) to receive the phone security check?
Find out more about how to update your phone details.
When you set up a new recipient, new standing order or reset your online security details, we may call you to make sure the instruction is genuine. All you need is a phone nearby. You'll be able to choose which number we call you on, provided it's a number we already hold for you. You'll receive an automated call asking you to confirm the details about your transaction and then to enter a four digit number that will appear on your computer screen into your phone keypad. The whole process takes less than a minute and you can see it on our demo.
Some banks are using card readers or password tokens to generate unique passwords when customers undertake specific transactions. This involves sending customers a particular gadget that they will need to keep with them when using online banking. We believe this extra gadget is unnecessary and so have chosen a common item, such as your phone, to communicate with you during your online banking session.
If a fraudster acquires your sign in details and gains access to your accounts, they are unlikely to have access to your phone as well.
We recommend you read and follow instructions about staying safe online by looking at our security help centre. There is advice about the dangers of 'phishing' emails, and about keeping anti-virus and anti-spyware software up-to-date.
No, however your mobile service provider may charge you for receiving the call if you are abroad.
If you do not supply us with a number you may be unable to use parts of the online service such as setting up new recipients.
For security reasons, new phone numbers entered will take three days to become active.
During this time we will be unable to call you on any of the numbers you have provided.
You'll be directed to our phone support team who'll be able to assist you.
If you don't answer the call or a connection can't be established, you'll have two further attempts to choose one of the phone numbers we have for you so we can contact you. If we can't reach you after three attempts we won't be able to set up your new recipient.
Our security team will try to contact you within the next 3 hours during the working day (8am - 9pm Monday to Friday, 8am - 8pm weekends). If they can't reach you within 24 hours they'll send you a letter with further instructions.
You will be given two opportunities during the security check call to advise us that were not expecting the call and it’s not you trying to set up the recipient. We will then suspend your online access/accounts and our security team will contact you.
No, you may only receive a phone call when you create a new recipient, set up a standing order or reset your security details.
Unfortunately, if we don't hold any number for you, you'll need to call us on 0345 721 3141, 24 hours a day, 7 days a week so we can set up the new recipient for you.
If you’re calling from abroad or would prefer not to use the 0345 number, you can call us on +44 (0) 1313 37 42 18.
You must be registered for phone banking to use this service. Alternatively, you'll need to call into your local branch. Please make sure that you update your phone numbers for future.
If we verify your activity we'll need to be able to contact you whilst you are online. You can provide up to 3 numbers - mobile, work and home - which should mean you are contactable wherever you are.
If the number we call you on is engaged, we will enable you to select again from the set of numbers you gave us.
Unfortunately, the phone security check is not compatible with a Textphone. However, customers with a hearing impairment can still receive a challenge on another phone and follow on screen instructions. If you are customer with a hearing impairment that uses a mobile to text friends and family, we recommend you include this number in the mobile section of your phone details. If security checked, you can then select your mobile number and follow onscreen instructions. You can update your telephone numbers in the 'Change details' section of online.
Unfortunately, VoIP technology is not compatible with our phone security check process. You'll need to use a standard phone or mobile to receive the automated call. However, most internet-enabled phones (such as the iPhone) will accept security checks while you're on online banking on your phone.
Examples of VoIP providers include Skype and Vonage. Please note that Bank of Scotland is not affiliated with these service providers.
Our Fraud Guarantee
We guarantee to refund your money (including charges and interest that you’ve paid or not received as a result) in the unlikely event that you experience fraud with our Internet Banking service. We will take steps to protect you 24/7, using technology and safeguards that meet or exceed industry standards, but you must also use our online banking services carefully.
Being careful when you use our services includes, for example, that you:
- Do all that you reasonably can to keep your Security Details (such as online and mobile username, password, and memorable information) secure, and you log off after each Internet Banking session.
- Don’t let anyone else have access to your account or Security Details, or transact using them, even if they share a joint account with you through our Internet Banking services.
- Tell us, as soon as you can if you think your Security Details have been lost, stolen, damaged or are being misused; or think someone may be accessing your accounts without your authority, or has discovered your Security Details.
- Carry out regular virus checks on your devices.
If you've been grossly negligent, we will not refund any money taken from your account before you have told us your Security Details have been lost, stolen or could be misused.
We won't give you a refund if you have acted fraudulently.
For further guidance on using our online banking services - see our Internet Banking service conditions.
Worried that your online personal or security details may have been compromised? Call 0345 602 0000, 24 hours a day, 7 days a week.
If you’re calling from abroad or would prefer not to use the 0345 number, you can call us on +44 (0) 113 279 8302.
Stay secure online - New security certificate
We have introduced a new feature to our online banking service, designed to give you even more confidence when using our service.
How does it work?
Extended Validation Secure Socket Layer, or EVSSL for short, means that our site has undergone many rigorous checks to confirm its validity, and has been provided with a 'certificate of authenticity' which can be recognised by your browser.
In the majority of cases, this validation is shown within your address bar, displaying a 'traffic light' style response of green or red.
This feature gives you the added confidence of knowing the site you're using has been confirmed as genuine.
What will you see?
This certificate of authenticity is recognised by most current browsers, though there are variations in the way the different browsers display the validation.
The majority of users running Internet Explorer, Mozilla Firefox, Opera and Safari will see the following “traffic light” responses on their address bars.
- Websites recognised as authenticated will display a GREEN address bar plus a padlock symbol, referencing the certificate and the authenticated website provider
- Websites identified as fraudulent and a phishing site, or as having a revoked or expired validation certificate, will display a RED address bar
Update your browser version
We recommend you always upgrade your browser to the latest version that is compatible with EVSSL as it provides you with important security features.
Cyber Essentials is a government-backed scheme that certifies that we meet their requirements in a range of essential precautions to protect the bank and our customers against internet-based threats.