from the inner auditor: Big risk here with allowing the bank details being supplied to a customer editable by users.
Ideally, need to have the bank details tightly controlled in a record where this is then referenced using logic (ie subsidiary, or other field dependant)
Bank details then referenced within pdf template via ${subsidiary.bankdetails}