The month a forged wire left my account, at $64K MRR
A composite founder diary. $58,400 left on an instruction I never gave, and the statute that decides who eats it never once asks whether I was careless. Read end to end from UCC Article 4A at $64K MRR.
In this story
“We show the transfer as properly authenticated. The funds were released Tuesday morning.”
That was the second sentence of the first reply I got from the bank, and I read it about forty times looking for the word that would save me. We were at 64K MRR. A wire for $58,400 had gone out to what I believed was our QA contractor's new account, because someone had been sitting in my mailbox long enough to learn how we talk about invoices. I had assumed what I think almost everyone assumes: the money was stolen, a bank is a bank, the bank puts it back. Then I went and read the law that actually decides who eats it, and it does not say that anywhere.
Quick answer (2026). This diary is a composite. The company, the amount, the counterparty and the timeline are assembled from several small SaaS businesses rather than one, and no single company is being described. The legal analysis is not composite: every rule below is quoted from the uniform text of Article 4A or from one state's enacted version, with the section linked so you can check it. The short version is that a forged wire can be effective as your own order, that the bank's burden is to prove something about itself while yours is to prove a negative about everyone near you, and that of the two deadlines I was warned about, the urgent one was worth roughly five cents on the dollar of the one nobody mentioned.
The sentence that decides it
Wire transfers between businesses run on Article 4A of the Uniform Commercial Code. The operative line is in section 4A-202(b), and it is short enough to read twice. Where the bank and the customer have agreed that payment orders will be verified by a security procedure, an order the bank receives is "effective as the order of the customer, whether or not authorized", provided the procedure is commercially reasonable and the bank accepted in good faith and in compliance with it.
Whether or not authorized. Not conditional on my carelessness, and not conditional on showing that the bank slipped. The statute takes an instruction I did not give and, on two conditions, treats it as mine. Nothing in that sentence is about fault, and it took me a day to stop reading it as though it were.
Two burdens, pointing opposite ways
Here is the part that actually decided my month, and it is a two-section read.
Under 4A-202(b), the second condition is that "the bank proves that it accepted the payment order in good faith and in compliance with the security procedure". That is the bank's burden, and notice what it is about: the bank's own conduct, documented in the bank's own logs, on the bank's own systems. It is close to the easiest thing in the world for a bank to establish.
My way out sits one section over, in 4A-203(a)(2). The bank cannot keep the money if "the customer proves that the order was not caused, directly or indirectly, by a person" who was either "entrusted at any time with duties to act for the customer with respect to payment orders or the security procedure", or who obtained access to my transmitting facilities, or who obtained, from a source I control, information that facilitated breach of the procedure.
Read that as a task rather than as a rule. I have to prove a negative, about causation, including indirect causation, covering every person ever entrusted with payment duties and everyone who got anything useful from any source I control. And the subsection closes the door on the obvious objection before you can make it: the test applies "regardless of how the information was obtained or whether the customer was at fault".
So in a business email compromise, where the attacker is by definition reading mail on a system I control, the escape hatch is closed by the very fact pattern that sends you looking for it. My fault was never the question. The source was.
Two routes to "commercially reasonable", and one of them is a signature
The other condition is that the security procedure be commercially reasonable, and I assumed that would be the fight. It is, but it is a stranger fight than I expected.
First, 4A-202(c) says that "Commercial reasonableness of a security procedure is a question of law". A question of law, not of fact. It is decided by a judge weighing five named considerations: my wishes as expressed to the bank, my circumstances as known to the bank including the size, type and frequency of orders I normally send, the alternative procedures the bank offered me, and the procedures in general use by customers and banks similarly situated.
Then the same subsection supplies a second route to the same status that skips all of that. A procedure is deemed commercially reasonable if "the security procedure was chosen by the customer after the bank offered, and the customer refused, a security procedure that was commercially reasonable for that customer", and the customer "expressly agreed in writing to be bound by any payment order, whether or not authorized".
Those two routes are not equally hard. One is a contested five-factor inquiry. The other is a form. If you were ever offered dual approval or a hardware token, said it was overkill for a company your size, and signed the page they slid across, you did not merely decline a feature. You converted the central contested question in any future case into a settled one, against yourself, in advance.
And 4A-202(f) is the flourish. It says these rights and obligations "may not be varied by agreement", except as provided in this section and in 4A-203(a)(1). A protection announced as non-waivable, whose text then names the two agreements that do change the outcome. One of them is the deeming clause above, which runs against the customer and is the default paperwork. The other runs the customer's way: under 4A-203(a)(1), "By express written agreement, the receiving bank may limit the extent to which it is entitled to enforce or retain payment of the payment order". In four years of banking I have never been offered that one, and it has never occurred to me to ask.
The clock I was watching was the cheap one
I was told twice, urgently, about ninety days. It is real, and it is in 4A-204(a): if the order was not effective as mine, the bank refunds it with interest, but I lose the interest if I fail to use ordinary care to spot the problem and tell the bank within "a reasonable time not exceeding 90 days". Then the same subsection says something nobody had mentioned: "The bank is not entitled to any recovery from the customer on account of a failure by the customer to give notification as stated in this section".
That is the whole penalty. Miss ninety days and you lose interest, and nothing else.
The deadline that actually costs money is in 4A-505, in a different Part of the Article, where nobody browsing for fraud advice would land. If the bank accepted an order issued in my name and I got notification reasonably identifying it, I am "precluded from asserting that the bank is not entitled to retain the payment" unless I object "within one year after the notification was received by the customer". Not the interest. The payment.
Price them. Interest under 4A-506(b) is calculated by "multiplying the applicable Federal Funds rate by the amount on which interest is payable, and then multiplying the product by the number of days for which interest is payable", with the rate "divided by 360". Assume a 5 percent federal funds rate, which is an assumption and not a measurement, and run a full year against my $58,400: 58,400 times 0.05 divided by 360 times 365 is about $2,960. The one-year clock is worth $58,400.
The deadline two people told me to panic about was worth about one twentieth of the deadline neither of them named.
Two words, and a date
Article 4A is model law. States enact it, and they do not all enact the same words, so the uniform text above is the pattern rather than anybody's statute. That matters more than it sounds.
California enacts Article 4A as Division 11 of its Commercial Code. Its version of the deeming clause asks that the customer "expressly agreed in a record to be bound", where the uniform text says in writing. Its version of the customer-friendly lever in section 11203(a)(1) opens "By express agreement evidenced by a record", where the uniform text says by express written agreement. A record includes an electronic one. Both changes arrived in the same bill, SB 95, at Stats. 2023, Ch. 210, effective January 1, 2024.
So the waiver that pre-answers the reasonableness question got easier to establish, and it got easier recently. Meanwhile section 11505, the one-year preclusion that can cost you the principal, still carries its original note from Stats. 1990, Ch. 125, and was not touched. One bill modernised the two provisions about how you can be bound and left the clock that actually ends your claim exactly where it was.
Check your own state's enacted text before you rely on a single word of the uniform version. I did not read fifty states, and I am not going to pretend I did.
The exemption that was written for somebody else
I went looking for a threshold, the way you do. Across the sections of Article 4A I read, the phrases "de minimis", "small business" and "exempt" appear zero times, and so does the word consumer. There is no revenue floor, no employee count, no carve-out for a company of nine people.
There is an exemption, and it is not addressed to me. Section 4A-108 says the Article "does not apply to a funds transfer any part of which is governed by the Electronic Fund Transfer Act", the federal statute that governs consumer electronic fund transfers. I did not read that Act, so I am not going to tell you precisely where its boundary falls or what protection sits on the other side. What I can tell you is that a boundary exists, that it is drawn around a category I am not in, and that being small is not what puts you on the protected side of it.
One more line worth knowing, from 4A-201, which I read but have not linked because 4A-202 already carries the weight of this piece: comparing a signature against a specimen signature "is not by itself a security procedure". If there is no security procedure, 4A-202(b) never engages at all.
What I got wrong
I thought the fight would be about whether the bank's security was good enough. It might be, but only if nobody ever handed me a form declining something better, and the answer is decided by a judge as a question of law rather than by a jury as a question of fact.
I thought my own diligence was the issue, and spent four days assembling evidence that we had done everything sensibly. Under 4A-203(a)(2) my fault is expressly irrelevant. What matters is where the information came from, and it came from my mailbox.
I thought the mandatory language protected me. "May not be varied by agreement" turned out to have the waiver written into its own exception list.
And I had the two deadlines exactly inverted, which is the mistake I would most like you to avoid, because it is the one where being wrong is unrecoverable rather than expensive.
Nothing here rests on any vendor's pricing or product tier, so no third-party commercial fact is holding up the conclusion. It is a model statute, one state's enactment of it, and my own wire confirmation.
What actually happened
Scroll to see more
| What I assumed | What the text said |
|---|---|
| A bank absorbs a forged wire | An order can be effective as mine, whether or not authorized, under 4A-202(b) |
| I must show the bank was careless | The bank proves its own good faith; I prove a negative about everyone near me, under 4A-203(a)(2) |
| A jury decides if the security was adequate | It is a question of law, decided by a judge, under 4A-202(c) |
| A waiver cannot matter, these rules are mandatory | They may not be varied by agreement, except by the two agreements the sections name |
| Ninety days is the dangerous deadline | Missing it costs interest. Missing the one-year deadline under 4A-505 costs the principal |
| Being a small company helps | No threshold appears in the sections I read. The exemption in 4A-108 points at a different statute |
The one thing I would tell you
Go and find out, this week, whether anyone at your company ever declined a security procedure your bank offered, and whether they signed something when they did. Not because a signature is fatal, but because it is the single input that converts the hardest question in this whole area into an answered one, and it is sitting in a folder somewhere costing you nothing to read.
Then ask your bank for the 4A-203(a)(1) agreement, the one where they limit what they are entitled to retain. They may say no. Mine has not said yes. But it is the only clause in this Article that the statute lets you use in your own favour, and until I read the text I did not know it was there to ask for.
Written by
Anya PetrovaFrequently asked questions
Is this a real founder's diary?
It is a composite. The company, the amount, the counterparty, the timeline and the numbers are assembled from several small SaaS businesses rather than one, and no single company is being described. The legal analysis is not composite: every rule is quoted from the uniform text of UCC Article 4A or from California's enacted version, with the section linked so you can check it.
Who is liable for business email compromise?
For a business wire, the allocation is set by UCC Article 4A rather than by who was at fault. Under section 4A-202(b), a payment order the bank receives is effective as the order of the customer, whether or not authorized, if the agreed security procedure is commercially reasonable and the bank proves it accepted in good faith and in compliance with that procedure. So the loss can sit with the business even though the business gave no instruction. This is a general description of the model text rather than advice on your facts, and your state's enacted version governs.
Does my bank have to refund a fraudulent wire transfer?
Only if the order was not effective as yours under 4A-202 or is unenforceable under 4A-203. Section 4A-204(a) then requires the bank to refund the payment with interest. The practical difficulty is 4A-203(a)(2): to get there you must prove the order was not caused, directly or indirectly, by anyone entrusted with payment duties or anyone who obtained information from a source you control, regardless of how it was obtained or whether you were at fault.
How long do I have to report a fraudulent wire transfer?
There are two deadlines and they carry very different penalties. Section 4A-204(a) sets a reasonable time not exceeding 90 days to use ordinary care to spot an unauthorized order and notify the bank; missing it costs you interest, and the same subsection says the bank is not entitled to any recovery from the customer for that failure. Section 4A-505 is the expensive one: you are precluded from asserting that the bank is not entitled to retain the payment unless you object within one year after notification was received. That clock costs the principal.
What makes a bank's security procedure commercially reasonable?
Section 4A-202(c) makes it a question of law, decided by weighing your expressed wishes, your circumstances as known to the bank including the size, type and frequency of your orders, the alternatives the bank offered, and procedures in general use by similarly situated customers and banks. The same subsection also deems a procedure commercially reasonable where the customer refused a procedure the bank offered and expressly agreed in writing to be bound by orders accepted under the one it chose instead.
Does Article 4A apply to a personal account?
Section 4A-108 says the Article does not apply to a funds transfer any part of which is governed by the Electronic Fund Transfer Act, the federal statute covering consumer electronic fund transfers. I did not read that Act, so I am not going to state where its boundary falls. What the Article 4A sections I read do not contain is any threshold based on company size: de minimis, small business and exempt appear zero times in them.
More stories
The month a bankruptcy clawback came for money I had already earned, at $58K MRR
A composite founder diary. A customer filed Chapter 11 and their counsel demanded back $8,550 of ordinary subscription payments. The statute prints a $5,000 floor; the operative floor is $8,575. I was twenty-five dollars under a line I did not know existed, and the date that decided it was not mine.
The month a chargeback wave froze my Stripe at $23K MRR: a founder diary (2026)
The month I crossed $23K MRR, a card-testing attack slipped a few hundred fraudulent charges past my checkout. Weeks later the disputes rolled in, my dispute rate crossed 0.75%, and my processor froze payouts. A composite founder diary on chargebacks, watchlists, and frozen cash.
The month I misclassified an independent contractor, at $63K MRR
A composite founder diary. A contractor invoiced at $26 an hour for three years asked one question, and the number everyone quotes turned out to be the escapable one. Read end to end from the statute at $63K MRR.