What we require of you, what you can require of us, and what the law says about who bears a loss on a commercial payment. This page is not marketing copy and it is not optional reading for a company that originates payments.
Under Article 4A of the Uniform Commercial Code as adopted in Tennessee, a payment order that we accept in compliance with a security procedure you agreed to is effective as your order, even if it was not authorized by you, provided the procedure is a commercially reasonable method of providing security against unauthorized payment orders and we accepted the order in good faith and in compliance with the procedure and your written instructions.
In plain terms: if your credentials are used to originate a payment and we follow the agreed procedure, the loss is generally yours, not ours. This is not a term we invented and it is not negotiable, but the procedures are, and choosing weaker ones has consequences you should understand before you choose them.
The security procedures we offer for payment origination are the Company ID and User ID pair, a password, a one-time passcode from a soft or hardware token, dual control requiring approval by a second entitled user, per-user and per-day dollar limits, IP address restriction, and out-of-band callback verification. Your treasury services agreement lists the procedures you selected. If you declined dual control, your agreement says so, and it says you agreed the remaining procedures are commercially reasonable for your company.
The largest losses our commercial clients experience do not involve a compromised banking credential at all. They involve a genuine employee, correctly signed on, sending a genuine payment to an account controlled by someone impersonating a vendor or an executive. The Gateway cannot detect this, because from the system's point of view nothing is wrong.
The controls that work are dull. Verify a change to vendor payment instructions by calling a number from your own vendor file, never a number in the request. Require two people to approve a change to a beneficiary template, which is why Beneficiary Maintenance is a separate entitlement from Wire Origination in the Gateway. Treat urgency and secrecy in a payment request as the signal they are. And know that a request arriving inside a real email thread from a real address proves nothing at all about who sent it.
If you believe a payment has gone to a fraudulent account, call (423) 555-0125 immediately and ask for a recall. The window in which funds can be held at a receiving institution is measured in hours. We will file the recall regardless of how the payment was originated, and we will not wait for a written instruction to start.
Suspected fraud on a treasury relationship: (423) 555-0125 during business hours, or (423) 555-0142 at any hour to reach the on-call treasury operations officer. A written confirmation follows within one business day, but make the call first. General security guidance for all clients is in the Security Center.
Reviewed by Treasury Operations and by the Information Security office, 03/2026.