The question every defrauded company asks in week one: "Won't the bank cover this?" For business accounts in the US, the honest starting answer is: usually not, if your own people sent the wire — and understanding why changes how you handle every conversation with the bank. This is general information, not legal advice; engage counsel for your actual situation.

The legal frame: UCC Article 4A

Business wire transfers in the US are governed by Article 4A of the Uniform Commercial Code, not by the consumer protections most people know from card fraud. Under Article 4A, if the bank verified the payment order using a security procedure you agreed to, that procedure was commercially reasonable, and the bank followed it in good faith, the loss generally sits with you — even for an unauthorized order — unless you can prove the fraud didn't originate from your own organization's people, systems, or credentials. That burden is steep, and in the most common scenario it doesn't even arise: in deception cases like CEO fraud and vendor impersonation, your authorized employee genuinely sent the wire. The order was authorized; the authorization was obtained by fraud. Article 4A treats those very differently.

Where consumer rules differ

Consumer electronic transfers fall under the Electronic Fund Transfer Act and Regulation E, which shift most unauthorized-transfer losses to the bank when reported promptly. Whether and how those protections reach consumer wire transfers is actively contested in US courts — but none of that contest covers business accounts. If you bank as a company, plan around Article 4A.

Where banks can still bear loss

  • Unreasonable security procedures: courts have found banks liable where their security procedures weren't commercially reasonable for the customer's situation, or weren't followed.
  • Ignored red flags: failures to act on clear anomalies have shifted outcomes in some cases — though the bar is high and outcomes vary by circuit and facts.
  • Agreement terms: your account and treasury agreements can allocate risk differently than the defaults. Most companies have never read theirs. Read yours this week.

How to talk to your bank — the practical script

  1. Separate the tracks. Track one is recovery (recalls, freezes) — cooperative, urgent, no blame. Track two is liability — slower, careful, in writing. Never let track two poison track one; you need the bank's fraud team working hard for you this week.
  2. Put everything in writing after every call. Confirmation emails with timestamps, names, and case numbers. If liability is ever contested, the record of who knew what when is the case.
  3. Request your agreements and the security-procedure documentation for the account — what you agreed to is the terrain any liability question is fought on.
  4. Don't sign anything releasing claims as a condition of recovery assistance without counsel reading it first.
  5. Ask what would have flagged this. Sometimes the bank offers callback verification, dual controls, or payee validation you never enabled. Declining offered security controls can itself affect liability — and enabling them is your fastest fix.
Protocol tipArticle 4A's logic is brutal but instructive: the law assumes the verification of a payment's legitimacy is YOUR control, not the bank's. Build it like the law already assumes you did.