Who Bears The Loss When ACH Or Wire Fraud Occurs Under Minnesota’s UCC Article 4A


Often, it starts with a phone call or email that looks legit. An employee at a Minnesota business clicks a link, enters their online banking credentials into a convincing fake login page or reads a security code to someone claiming to be calling from the bank. Wire transfers or ACH credit files are sent from the company’s account to accounts the company has never paid before within hours. By the time anyone notices, the money has usually passed through several banks and is often gone. 


The first question any business owner asks is, “Does the bank have to pay the money back?” The first question all bankers ask is did the bank do anything wrong? Many business owners believe the answer is the same as a consumer who has their debit card stolen, when federal law severely limits the account holder’s liability. That assumption is usually wrong for business accounts. The answer is found in Article 4A of the Uniform Commercial Code, which is codified in Minnesota as Minn. Stat. § 336, Article 4A. This has less to do with who was careless and more to do with the security procedure the bank and the customer agreed to use. 


What Law Applies to Business Wire and ACH Fraud? 

Article 4A covers “funds transfers,” including wire transfers and ACH credit transfers that a business initiates to pay another. It does not apply to funds transfers any part of which is governed by the federal Electronic Fund Transfer Act, the statute (implemented through Regulation E) that protects consumers. In practice, that means a business making a payment from a commercial account is usually outside the consumer-protection regime and inside Article 4A, where the rules are built around negotiated security procedures rather than fixed liability caps. Disputes over unauthorized ACH debits pulled from an account follow a different path. These disputes are largely guided by the NACHA Operating Rules and the account agreement and are beyond the scope of this article. 


The Beginning: Bank’s Loss of an Unauthorized Payment Order 

Article 4A starts from a customer-friendly position. If a payment order has not been authorized by the customer, the bank shall refund the payment with interest unless it can prove that the payment order is nevertheless effective against the customer. (Minn. Stat. 336.4A-204). The fact that the instruction was sent through the customer’s online banking portal does not make it a fraudster’s instruction. 


The statute then provides the bank a mechanism to pass that loss onto the customer. According to Minn. Stat. § 336.4A-202(b), a payment order is effective as the customer’s order, whether or not the customer actually authorized it, if three things are true: (1) the bank and customer agreed that orders would be verified by a security procedure; (2) the security procedure is a commercially reasonable method of providing security against unauthorized payment orders; (3) and the bank proves it accepted the order in good faith and in compliance with the security procedure and any written instructions from the customer restricting acceptance of orders. That burden is on the bank. The loss then passes over to the customer. 


What is a “reasonably commercial” security procedure? 

Whether the sale was commercially reasonable is a question of law for the Court to decide. The statute requires courts to consider the customer’s expressed wishes to the bank, the circumstances known to the bank about the customer (including the size, type and frequency of the customer’s usual payment orders), the alternative security procedures offered by the bank and the procedures in general use by similarly situated customers and banks. Minn. Stat. § 336.4A-202(c). 


The statute also provides banks with a powerful safe harbor. A security procedure is commercially reasonable if the bank has offered the customer a commercially reasonable alternative security procedure, the customer has refused to accept such alternative and has selected a different security procedure, and the customer has expressly agreed in a record to be bound by any payment order accepted by the bank in compliance with the security procedure selected by the customer. Thus, if a bank offers stronger protection in writing and the business refuses it, the business will have a very difficult time blaming the bank later.
Minnesota’s 2024 amendments to Article 4A added an important limitation on what counts as a security procedure at all. A requirement that a payment order be transmitted from an email address, IP address, or telephone number known to the financial institution is not, by itself, a security procedure. Minn. Stat. § 336.4A-201. Banks that rely solely on that sort of screening should not expect it to provide the statutory defense. 


Two rulings by federal appeals courts illustrate how these rules operate. In Choice Escrow & Land Title, LLC v. BancorpSouth Bank, 754 F.3d 611 (8th Cir. 2014), the federal appeals court that oversees Minnesota ruled that a title company lost about $440,000 in a fraudulent overseas wire when an employee’s computer was hit with a phishing attack. The bank had offered dual control on several occasions, which would have required a second user to approve each wire, and the customer declined in writing. The Eighth Circuit held that the bank’s procedures were commercially reasonable and the loss was to stay with the customer. In Patco Construction Co. v. People’s United Bank, 684 F.3d 197 (1st Cir. 2012), the bank’s own system designated a number of withdrawals as high risk for fraud, but the bank did nothing further to verify them and permitted the payments to proceed. The First Circuit held the procedure was not commercially reasonable. Both stories have the same moral: it’s not about whether the bank had security tools, but whether they were reasonable for that customer, and whether the bank actually used them. 


The Customer’s Counter-Argument: What’s With the Breach? 

Even if the bank complies with Section 336.4A-202, the customer has another method for passing the loss back. The bank is not entitled to enforce the order if the customer proves that the order was not caused, directly or indirectly, by a person entrusted with duties relating to payment orders or the security procedure, or by a person who obtained access to the customer’s transmitting facilities or security information from a source controlled by the customer. (Minn. Stat. § 336.4A-203(a)(2)). The statute applies that test without regard to the means by which the information was obtained or the fault of the customer.
That last phrase is very important in modern fraud. If the fraudster stole credentials from a customer’s employee using phishing, social engineering or malware on the customer’s computer, the fraudster accessed the system from a source controlled by the customer, even if the employee acted in complete good faith. If, however, the evidence shows that the breach was on the bank’s side, the customer may be able to escape the loss. That is why forensic evidence as to how the credentials were compromised often settles these disputes.

 
Deadlines That Could Cost You Your Claim 

If a business finds out about an unauthorized transfer, it shouldn’t wait. A customer who does not use ordinary diligence to discover and report an unauthorized order within a reasonable time not to exceed 90 days after notice of the order is given, shall lose the right to interest on any refund. (Minn. Stat. § 336.4A-204). More seriously, a customer who does not object to a debit within one year after receiving notification reasonably identifying the payment order is precluded from claiming that the bank is not entitled to retain the payment. Minn. Stat. § 336.4A-505. Beyond the limits of the law, the real chance of recovering money from receiving banks falls away quickly every single day. 


Minnesota Banks – Practical Steps 

Community banks can do a lot to fortify their position before a fraud ever happens: 

• Provide more powerful choices in writing. Commercial customers should have dual control, callback verification and transaction limits available on record and a customer’s decision to decline them should be documented and signed. 

• Fit the procedure to the customer. A reasonable procedure for a small business that is sending payroll files only occasionally is not a reasonable procedure for a title company that is sending high dollar wires every day. Periodically review customer risk profiles. 

• Follow your own procedure consistently. The Section 336.4A-202 defense requires a showing that the bank followed the agreed procedure. Convenience exceptions can kill the defense. 

• Listen to your own red flags. Have a documented process for what to do next if your fraud monitoring identifies an order as unusual. 

• Regularly review agreements. Treasury management, ACH origination and online banking agreements should clearly define the security procedure and reflect the current statute. 


Minnesota Businesses: Practical Steps 

Business owners have far more control over these losses than they think: 

• Accept call-back verification and dual control. The minor inconvenience of a second approver is nothing compared to an uninsured loss of six figures. 

• Confirm changes to payment instructions by telephone. Any request to change a vendor’s bank account should be verified against a phone number already on file, not a phone number supplied as part of the request. 

• Train staff to recognize phishing and impersonation calls. Banks will never call you and ask for your passwords or one-off security codes. 

• Daily account activity monitoring and immediate reporting. Prompt reporting increases the likelihood that a wire can be recalled, or an ACH credit returned and preserves statutory rights. 

• Check your insurance. Many general commercial policies do not cover funds transfer fraud. Cyber and crime coverage should be reviewed pre-loss, not post. 


When a Loss Has Occurred 

The first few days after a fraud are critical for banks and businesses. Save online banking records, login and device information, emails and phone records. Notify insurers immediately. If possible, consider getting a forensic examiner through counsel so the investigation is protected as much as possible. Most importantly, do not make admissions or definitive statements about fault until you know the facts, because the outcome under Article 4A often depends on details that are not clear in the first week, such as how credentials were obtained and exactly what procedure was followed. 

Summary
Article 4A does not ask who was most negligent. It asks the questions of whether the bank and customer agreed to a security procedure, whether it was commercially reasonable, whether the bank followed it in good faith, and where the breach originated. Those banks that have documented their procedures and the options they provide are in a good position to defend these claims. The companies with the strongest protection and the quickest fraud reporting are best placed to avoid the loss in the first place. 


DISCLAIMER

This article is provided for informational purposes only and does not constitute legal advice. The information contained herein is general in nature and may not apply to your specific situation. No attorney-client relationship is created by reading this article or contacting the author in response to it. For legal advice regarding your particular circumstances, please consult with a qualified attorney.


About the Author:

David Lutz is a Minnesota attorney and the owner of Lutz Law Firm in Minneapolis, Minnesota, representing financial institutions, businesses, and individuals in banking law, secured transactions, real estate, and commercial litigation. He can be reached at [email protected] or 612-424-2110.