FIN-08 Financial Regulation & Digital Assets Money Movement Controls Federal + state overlay
Wire Transfer Losses Under UCC Article 4A: Who Bears the Fraud
Article 4A does not ask who was at fault. It asks whether the bank and the customer agreed a commercially reasonable security procedure and whether the bank followed it. This brief walks that analysis and its exits.
Briefing in 60 seconds
- Article 4A allocates unauthorised payment-order loss through the security procedure: an order verified under a commercially reasonable procedure can bind the customer.
- A customer can shift the loss back by proving the order did not come from anyone entrusted with, or who obtained access through, the customer's own systems.
- Consumer transfers governed in any part by the Electronic Fund Transfer Act are excluded from Article 4A, so the two regimes rarely overlap.
- Article 4A is state law enacted state by state, and Fedwire transfers are additionally subject to Federal Reserve Regulation J.
Controlling variables
- Contract terms
- Whether a security procedure was actually agreed in writing, what it required, and whether the customer refused a stronger procedure the bank offered.
- Facts
- How the credentials were obtained. An intrusion into the customer's environment and an intrusion into the bank's produce different outcomes.
- Jurisdiction
- Article 4A applies as enacted in the governing state, with local variations and case law; Fedwire transfers also run under Regulation J.
- Timing
- How fast the customer notified the bank and objected to the debit. Article 4A sets an outer period for objecting to an unauthorised debit.
- Status
- Whether the account is a consumer account. Transfers governed by the Electronic Fund Transfer Act sit outside Article 4A entirely.
General legal information about United States law. Not legal advice, not representation, and no attorney–client relationship is created by reading it. Rules differ by jurisdiction and change — verify against the official sources listed below.
When a business loses money to a fraudulent wire, the instinct is to argue about fault — who clicked the link, who failed to call back, who should have noticed the domain was off by one letter. Article 4A of the Uniform Commercial Code largely ignores that argument. It asks a narrower and colder set of questions, and the answers usually decide the case before negligence is ever reached.
The framework is a self-contained loss-allocation scheme for commercial funds transfers, adopted as state law in every state. It governs payment orders sent to a bank, and it deliberately displaces most common-law claims that would otherwise reach the same conduct. Consumer transfers are handled elsewhere: a funds transfer governed in any part by the Electronic Fund Transfer Act falls outside Article 4A, which keeps the two regimes largely separate.
The security procedure is the case
Article 4A starts from a simple default: a payment order is effective as the customer's order only if the customer authorized it. Then it adds the provision that decides most disputes. If the bank and the customer agreed on a security procedure for verifying payment orders, the order can be effective as the customer's order even though the customer did not authorize it, provided three things hold — the procedure was a commercially reasonable method of providing security against unauthorized orders, the bank accepted the order in good faith and in compliance with the procedure, and the bank complied with any written agreement or instruction restricting acceptance.
Each element does work. "Commercially reasonable" is assessed against the wishes the customer expressed, the circumstances known to the bank — including the size, type, and frequency of the customer's orders — and the procedures used by similarly situated customers and banks. It is a comparative standard, not a fixed technical specification, which is why a procedure that was reasonable a decade ago may not survive scrutiny today.
"Good faith" carries more weight than it appears to. It has been read to include observance of reasonable commercial standards of fair dealing, which lets a court ask whether a bank that saw an obviously anomalous order — first-time beneficiary, unusual amount, offshore destination — behaved reasonably in executing it despite technical compliance with the procedure.
Working the allocation in order
- Was the order authorized?
If the customer or its agent with authority issued the order, the customer is bound and the analysis ends. Authority is determined by the law of agency.
- Was there an agreed security procedure?
No agreed procedure, no verification defence. The bank bears the loss on an unauthorized order and must refund the amount with interest.
- Was the procedure commercially reasonable?
Assessed on the comparative standard. A procedure the customer rejected after being offered a stronger one can still be treated as reasonable if the refusal was documented in a written agreement.
- Did the bank actually comply, in good faith?
Technical compliance is not enough if the bank ignored its own restrictions or executed an order that its own monitoring flagged.
- Can the customer prove the source?
Even where the bank clears the first four steps, the customer may shift the loss back by proving the order was not caused, directly or indirectly, by a person entrusted with duties relating to payment orders, or by a person who obtained access to the customer's transmitting facilities or to information from the customer's own source.
- Was the objection timely?
The customer must object to the debit within the period Article 4A allows; delay past that outer limit can extinguish the claim regardless of the merits.
Step five is where business email compromise cases are usually lost. When the fraudster obtained credentials by compromising the customer's own mail system or an employee's device, the customer cannot show the order came from outside its sphere, and the loss stays with the customer. When the compromise happened at the bank, or through a channel the customer never controlled, the customer has a real argument.
Verify before relying: Article 4A is state law, and as of mid-2026 its enactments still vary. Courts in different states have reached different conclusions on what counts as commercially reasonable, and account agreements routinely modify the default allocation to the extent the statute permits. Read the enacted text in the governing state and the account agreement together — never the model text alone.
Misdescription, mistake, and the beneficiary problem
Not every loss involves fraud. Article 4A handles several ordinary failures with rules that surprise people encountering them for the first time.
| Situation | General treatment | Practical consequence |
|---|---|---|
| Beneficiary name and account number do not match | A bank may generally rely on the number if it does not know of the mismatch, subject to notice conditions | Payment can reach the wrong account and still be effective; verify the number, not the name |
| Duplicate or erroneous order sent by the customer | Recovery may depend on whether a security procedure designed to detect such errors was in place and followed | Error-detection procedures matter as much as fraud-detection ones |
| Order executed late or not at all | Liability is generally limited; consequential damages usually require an express written agreement | Lost-deal damages are rarely recoverable without advance contracting |
| Funds already credited to the beneficiary | Recovery runs against the beneficiary under restitution principles, not against the receiving bank as a matter of course | Speed of notice determines whether a recall has any chance |
Deadline discipline: a wire that has settled is not a card charge. There is no chargeback right. A recall request is a courtesy communication to the beneficiary's bank, and its success depends almost entirely on whether the funds are still sitting there. Report to the bank and to law enforcement within hours, not days.
Where consumer law takes over
The boundary is jurisdictional rather than practical. A funds transfer any part of which is governed by the Electronic Fund Transfer Act is excluded from Article 4A, so a consumer's unauthorized electronic transfer runs under the federal consumer regime, with its own definitions, investigation clocks, and liability caps. Certain remittance transfers that are not electronic fund transfers can still fall within Article 4A, which is a narrow carve-in worth checking rather than assuming.
The consequence is that two customers of the same bank, losing money to the same fraud ring on the same day, can hold entirely different rights. The consumer gets a fixed investigation timetable and statutory liability limits under Regulation E, described in Regulation E error resolution. The business gets the security-procedure analysis and whatever its account agreement provides. Neither result depends on which customer was more careful.
Wires are also not the only rail with its own allocation rules. Debits through the automated clearing house network are governed by network rules and by the validity of the ACH authorization, a different framework covered in ACH authorization, returns, and account-freezing risk. Where the sending account is a pooled or custodial balance, the question of whose money left the bank gets harder still — see custodial and FBO account structures.
Reducing exposure on both sides of the counter
- An undocumented procedure. If the security procedure lives only in an operations manual, the bank may have no agreed procedure to rely on. Put it in the treasury services agreement and have the customer sign.
- An unrecorded refusal. Where a customer declines dual control or callback verification, the written record of the offer and the refusal is what preserves the bank's position. An email thread is weaker than a countersigned addendum.
- Stale limits. Transfer limits set at onboarding and never revisited stop matching the customer's activity, which undercuts the reasonableness assessment.
- Alerts nobody acts on. A flagged order released without review damages the good-faith element more than having no monitoring at all.
- Delayed notice. Customers who investigate internally for a week forfeit the only window in which funds can realistically be recovered.
- Evidence destroyed in the cleanup. Rebuilding a compromised mail server before imaging it eliminates the proof of where the intrusion occurred, which is the fact step five turns on. Put a litigation hold in place immediately.
Questions the desk gets
Does the bank have to refund a fraudulent wire?
Only where the order was not effective as the customer's order. If there was no agreed security procedure, or the procedure was not commercially reasonable, or the bank did not follow it in good faith, the bank must refund the amount with interest. If the bank clears those hurdles and the fraud traced back to the customer's own systems or people, the loss generally stays with the customer. Fault, in the ordinary sense, is not the organising question.
Can an account agreement change the allocation?
Within limits. Article 4A permits variation by agreement in many respects, and treasury agreements commonly define the procedure, set notice deadlines, and disclaim consequential damages. Some provisions cannot be varied, and a bank cannot contract out of good faith where the statute forbids it. Read the agreement first in any dispute, then the enacted statute in the governing state.
Is a callback a commercially reasonable procedure?
Often, but there is no fixed answer. Reasonableness is judged against the customer's size, order patterns, and expressed wishes, and against what comparable banks and customers use. A voice callback to a number stored before the request, combined with dual authorization for orders above a threshold, is a familiar pattern. A callback to a number supplied in the fraudulent instruction itself is worse than no callback, because it manufactures a record of verification that never happened.
What about Fedwire specifically?
Transfers through Fedwire are subject to Federal Reserve Regulation J, which incorporates Article 4A rules for those transfers as a matter of federal law. That matters for uniformity: it removes some state-by-state variation for the leg running through the Reserve Banks, while the customer-to-bank relationship still turns on the account agreement and the enacted state statute. Check both layers rather than assuming one displaces the other.
Does insurance change the calculus?
It changes who ultimately pays, not who is liable. Crime and cyber policies treat social-engineering fraud, funds-transfer fraud, and computer fraud as distinct insuring agreements with different triggers and sublimits, and a loss that fails one can fail all three. Review the policy language against the actual fact pattern early, because notice conditions in these policies are short and unforgiving.
What to do next
If a loss has already happened, the first hour matters more than the first lawyer. Notify the bank and ask for a recall, file with law enforcement, preserve the affected systems without remediating them, and collect the payment order, the security-procedure record, and the account agreement in one place. Then map the facts onto the six-step sequence above.
If nothing has happened yet, the work is documentary. Confirm that a security procedure is agreed in writing and matches what operations actually does, that any customer refusal of a stronger option is recorded, and that limits reflect current activity. Read the enacted text of Article 4A in the governing state alongside your agreement, check Federal Reserve materials for Fedwire and Regulation J, and confirm supervisory expectations with the relevant prudential regulator such as the OCC or FDIC. Related payments material sits on the Financial Regulation & Digital Assets desk.
Sources
- Cornell LII — Uniform Commercial Code Article 4A (Funds Transfers)
- Federal Reserve Board — payment systems, Fedwire, and Regulation J
- FDIC — supervision of insured depository institutions
- Office of the Comptroller of the Currency — bank supervision
- Consumer Financial Protection Bureau — Regulation E (12 CFR Part 1005)
Atlas Research Desk
ATLAS briefs are researched and edited by the Research Desk, an editorial organization — not attorneys acting for you. Method and limits: editorial method · source standards · corrections.