Acceptable use
What FinCheqIQ enforces, and what it records while you work. These rules are the same in every deployment because the platform implements them — they are not a summary of the bank's policy document.
Your account is yours alone
Accounts are provisioned by an administrator and activated with a bank-issued code. There is no self-service registration anywhere in the product, and no shared or team account: every action carries the identity that performed it into the audit trail, so a shared credential makes the record meaningless rather than merely untidy.
You act within your role
Least privilege is enforced by the platform, not by convention. Affordances your role cannot use are removed from the page rather than greyed out, and a blocked attempt is logged with your identity and the resource you tried to reach. Nothing about that is held against you — it is how least privilege is evidenced at audit.
You do not approve your own work
Maker-checker separation is structural. A decision you submit as maker cannot be approved by you as checker; a different authorised approver must agree before anything is released. The same rule governs configuration: a threshold, a limit, a role assignment or a reference signature always needs a second administrator.
Sensitive material is opened for a reason
Reference signatures and core banking credentials are masked by default. Revealing one is a deliberate action, and the access entry is written against your identity and cannot be edited or removed afterwards. Security Monitoring surfaces an unusual volume of reveals as an indicator — a pattern worth a person looking at, not a finding and not an accusation.
The record cannot be amended
The audit trail is append-only and hash-chained. It has no edit or delete affordance for any role, including administrators, because a record you can amend is not evidence. Removing or altering an entry breaks the chain visibly.
What the bank defines
These are policy rather than platform, and are supplied by the bank at deployment.