# UCC Article 4A and the AI Wire-Verification Architecture: Commercially Reasonable Security Procedures When the Caller Is Verified But the Instruction Is Not

*June 26, 2026 · 14 min read · Ramkumar Venkataraman*

> Wire fraud losses are running at multi-billion-dollar annual totals and the legal allocation of those losses runs through UCC Article 4A's commercially-reasonable-security-procedure standard. AI voice authentication of the caller does not, by itself, satisfy the security procedure for a payment instruction. The architecture we run so the bank's Article 4A position holds in court when the instruction was the fraud.

## The Loss-Allocation Rule Behind Every Wire Fraud Case

A wire-transfer fraud case is, after the FBI is called and the funds are chased, fundamentally a contract case under [Uniform Commercial Code Article 4A](https://www.law.cornell.edu/ucc/4A). The bank executed a payment order. The "customer" who originated the order says the order was not authorized. Article 4A allocates the loss between the customer and the bank based on the bank's compliance with a "security procedure" that the customer agreed to and that is "commercially reasonable" under the statute. The court reads the procedure, the bank's compliance with it, and the procedure's reasonableness against the facts. The bank that wins the case wins it on the security procedure. The bank that loses the case usually lost it before the wire moved, by allowing an instruction through a procedure that the court reads as failing the commercial-reasonableness standard.

The AI agent that sits on the bank's voice and chat channels intersects this rule in two places. The agent authenticates callers. The agent helps customers initiate wire transfers. Both functions are inside Article 4A's perimeter, and the architecture has to encode the bank's security procedure in a way that a court reading the procedure against the rule's standard will find commercially reasonable. The institutions whose AI program treats Article 4A as a back-office problem rather than as a voice-channel problem are the institutions whose first significant fraud case will read against them.

We build the agent that runs on bank voice and chat channels for commercial and retail wire activity. The architecture below is the one our customers' wire-operations, treasury-services, and fraud teams have validated against the rule's text and against the published case law on commercial-reasonableness disputes.

## What Article 4A Allocates and How

[UCC 4A-202](https://www.law.cornell.edu/ucc/4A/4A-202) sets the structure. A payment order is "authorized" if the person identified as sender authorized the order or is bound by it under the law of agency. A payment order is "verified" if the bank accepted it in compliance with a security procedure to which the bank and the customer have agreed. The bank that accepted a verified-but-unauthorized order can enforce the order against the customer if (1) the security procedure is a commercially reasonable method of providing security against unauthorized payment orders, and (2) the bank proves it accepted the order in good faith and in compliance with the security procedure and any written agreement or instruction restricting acceptance.

The first prong is the doctrinal centerpiece. The court assesses commercial reasonableness against the wishes of the customer expressed to the bank, the circumstances of the customer known to the bank including the size, type, and frequency of payment orders normally issued, alternative security procedures offered to the customer, and security procedures in general use by similarly situated customers and banks. The reasonableness is a question of law for the court, not a question for the jury.

The second prong is the bank's compliance with the procedure and its good faith. Compliance and good faith are factual; the court reads the bank's actual conduct against the procedure's specifications, with the bank's burden to prove that the conduct met the procedure.

For consumer-facing wire activity, Regulation E and the [CFPB's remittance transfer rules at Subpart B of Reg E](https://www.consumerfinance.gov/rules-policy/regulations/1005/30/) and the consumer-protection layer of P2P fraud apply alongside Article 4A; for commercial wires, Article 4A is generally the only contractually-allocable framework, modified for Fedwire transfers by [Regulation J](https://www.federalreserve.gov/paymentsystems/regj-faqs.htm) and for CHIPS by CHIPS rules. The architecture has to know which layer applies to a given customer and instruction set, and the consumer-side overlay does not change the underlying Article 4A analysis on the bank-side.

## The Caller Authentication Layer the Agent Owns

The AI agent's first job in the wire workflow is to authenticate the caller. The authentication has to land at the NIST 800-63 authenticator assurance level the bank's risk policy sets for the transaction class, which for any meaningful wire is typically AAL2 or AAL3 with at least one phishing-resistant factor. We wrote separately on the [voice cloning threat and the caller-authentication architecture](/blog/voice-cloning-deepfake-caller-verification-banks-phishing-resistant) banks need to run on the phone channel; the wire-instruction context is the most consequential application of that architecture.

The voice channel cannot natively carry a FIDO2 handshake. The architecture we deploy uses a callbreak pattern: the agent identifies the caller's request as a wire instruction, classifies the risk tier of the request based on amount, beneficiary type, and other parameters, and routes the customer to a phishing-resistant authentication challenge on their enrolled device. The customer completes the challenge in the bank's app and returns to the call to continue. The voice channel carries the conversation. The credential lives on the phone or hardware token.

A customer who lacks an enrolled phishing-resistant factor is routed to an in-branch wire desk for any instruction above the lowest risk tier, or to a video-supervised banker if the bank operates that channel. The "fall back to voiceprint" path is the path the synthetic caller exploits, and the institutions whose security procedure allows it for instructions above the lowest tier are the institutions whose first deepfake wire fraud has the worst Article 4A posture.

The verification we apply is documented in the security procedure the customer agreed to. The bank's wire agreement names the factors the customer has enrolled, the conditions under which the agent will challenge, and the alternatives available when a factor is not available. A customer who agreed to a security procedure that requires the phishing-resistant challenge is a customer whose wire instruction, accepted without the challenge, was accepted out of procedure. The bank's Article 4A position on that order is weak regardless of how the rest of the workflow looked.

## The Instruction Verification That Caller Authentication Does Not Cover

Caller authentication answers the question "is this person who they say they are." It does not answer the question "did this person actually intend to send this wire." The two questions are conceptually separate and the architecture has to answer both.

The most common pattern in modern wire fraud is the social-engineering attack where the actual customer, authenticated correctly, is the one sending the wire on the fraudster's instructions. The customer believes they are sending the wire to their attorney for a real estate closing; the wire is actually going to the fraudster's account because the fraudster compromised the email thread and substituted account details. The customer's authentication was real. The customer's intent was real. The instruction was the fraud.

Article 4A on these cases is harder for the bank, because the order was both authorized in the agency-law sense and verified by the security procedure. The "unauthorized" prong does not save the customer, and the customer's recovery against the bank is correspondingly limited. The published case law, including the New York and California decisions on business-email-compromise wire fraud, has generally held banks not liable for these losses under Article 4A's text. The CFPB has, separately, pursued some consumer-facing P2P fraud cases under UDAAP and Reg E theories, but the commercial wire context remains an Article 4A analysis primarily.

The bank's Article 4A win on these cases is a Pyrrhic victory if the customer relationship suffers. A customer who lost $300,000 to a wire fraud the bank "could have caught" by checking the unusual beneficiary against the customer's prior pattern, but did not, is a customer the bank loses commercially even if it wins the legal case. The bank's wire program has to consider the customer-retention and reputational economics alongside the legal allocation, and the AI agent is the cheapest place to add a substantive instruction-verification layer that does both.

## The Out-of-Band Confirmation Pattern That Catches the Social-Engineering Case

The architecture we deploy adds an out-of-band confirmation step for wire instructions that match high-risk patterns. The agent identifies the instruction's risk score on a model that considers amount relative to the customer's history, beneficiary novelty (new beneficiary or beneficiary not in recent history), beneficiary type (individual versus institutional, domestic versus international, high-fraud-flag countries), the timing of the instruction (urgency claims, end-of-day rushes), the channel pattern (out-of-character channel for the customer), and the customer's behavioral signals during the conversation (stress markers, conversational anomalies, third-party suggestions audible in the background).

A high-risk instruction triggers an out-of-band confirmation through a channel the customer has separately enrolled (typically the mobile app), with a confirmation message that includes the beneficiary name, the account routing or IBAN, and the amount, and that requires the customer to read the details and explicitly confirm. The confirmation is independent of the voice conversation; the fraudster who is on a separate call with the customer cannot prevent the customer from reading the actual details from the bank's notification.

The pattern catches a meaningful fraction of business-email-compromise fraud where the customer, faced with the bank's out-of-band confirmation reading the actual beneficiary details rather than the customer's understanding of where the wire is going, recognizes the discrepancy. The pattern does not catch sophisticated fraud where the fraudster has also compromised the customer's mobile-app channel, but the layered defense raises the cost of the attack to the point where the marginal fraud the bank's program faces shifts to less-prepared institutions.

The bank's wire agreement names the out-of-band confirmation as part of the security procedure for the relevant risk tier. The procedure's text states that the bank will not execute high-risk wire instructions absent the confirmation, that the bank will hold instructions until the confirmation is received or affirmatively declined, and that the customer agrees the confirmation is part of the procedure they have selected. The customer who chooses to opt out of the confirmation has, in the agreement, declined the higher-protection procedure, and the Article 4A reasonableness analysis treats the customer's choice as the customer's choice. The bank's offering of the higher procedure and the customer's documented decision against it is the third factor in the commercial-reasonableness assessment under [UCC 4A-202(c)](https://www.law.cornell.edu/ucc/4A/4A-202): "the wishes of the customer expressed to the bank."

## The Beneficiary-Validation Layer the Agent Implements

The beneficiary-validation step is where the bank's substantive defense lives on the social-engineering case. The agent's verification of the beneficiary name against the bank's own knowledge of the beneficiary account is a control the rule's reasonableness analysis credits. The [NACHA Operating Rules](https://www.nacha.org/) require ACH originators to use commercially reasonable methods to validate account information for WEB Debits since 2021, and while the rule applies to ACH and not wires, the underlying control concept (the bank validates that the beneficiary name matches the account before transmitting) is a control the wire program can apply.

The Confirmation of Payee schemes deployed in the UK and increasingly globally (the [UK's CoP](https://www.psr.org.uk/our-work/confirmation-of-payee/) and the EU's similar schemes) match the beneficiary name the customer supplied against the name on file at the beneficiary's bank, and the originating bank surfaces a match-or-mismatch result to the customer before execution. The US wire system does not have a standardized CoP equivalent for cross-bank wires, but bilateral arrangements between banks and beneficiary-validation services through correspondent and FedWire channels can produce the equivalent for high-risk instructions.

The agent's beneficiary-validation step varies by what the wire system in question can support. For Fedwire instructions where the bank has a relationship with the receiving institution that supports name-matching, the agent surfaces the match result. For instructions to beneficiaries the bank has no name-validation path to, the agent surfaces that the validation is unavailable and the customer accepts the additional confirmation through the out-of-band step. The transparency is the control: the customer knows what the bank can and cannot verify, and the customer's authorization to proceed is informed by that knowledge.

## What "Commercially Reasonable" Has Looked Like in Recent Cases

The published case law on Article 4A's commercial-reasonableness standard has evolved with the threat environment. The [Patco Construction v. People's United Bank](https://law.justia.com/cases/federal/appellate-courts/ca1/11-2031/11-2031-2012-07-03.html) decision (1st Cir. 2012) is the canonical First Circuit holding that a security procedure incorporating only username, password, and challenge questions for commercial wire transfers was not commercially reasonable given the threat environment at the time and the alternatives available. The court emphasized that "commercial reasonableness" is assessed against the procedure's alignment with the customer's expressed wishes, the circumstances of the customer the bank knew or should have known, the alternatives offered, and the procedures in general use by similarly-situated customers and banks.

Subsequent decisions have continued in the same direction. A security procedure that does not include multi-factor authentication, that does not consider transaction-pattern anomalies, that does not implement out-of-band confirmation for high-risk instructions, and that does not surface the bank's own knowledge of the customer's history to the verification decision is, on a reasonable reading of the case law, a procedure that the next court will likely find not commercially reasonable.

What this means for the AI agent's design is that the bank's security procedure has to anticipate the case law's direction rather than meeting only the historical baseline. The court reading the procedure today will measure it against today's threat environment. A procedure that was commercially reasonable five years ago because the threat environment did not include high-fidelity voice cloning is not necessarily commercially reasonable today, and the bank that has not updated the procedure since is the bank whose Article 4A defense rests on a stale foundation.

## The Reg J Layer for Fedwire and the CHIPS Layer for the Other Volume

[Regulation J Subpart B](https://www.federalreserve.gov/paymentsystems/regj-faqs.htm) governs Fedwire funds transfers and incorporates Article 4A with specific Federal Reserve modifications. The Reg J adoption of 4A means the substantive analysis on Fedwire wires runs through 4A, with Reg J's modifications addressing the Federal Reserve's role as an intermediary. The bank's compliance with Reg J's specific provisions is part of the security procedure's overall posture, and the bank that runs a procedure for Fedwire that does not consider Reg J's text is missing layers of the analysis.

[CHIPS](https://www.theclearinghouse.org/payment-systems/chips) runs under its own rules adopted by the Clearing House Interbank Payments System, with substantial coordination with Article 4A's underlying structure. Banks that participate in CHIPS are bound by the CHIPS rules and the bank's wire instruction handling for CHIPS instructions reflects the CHIPS rules' specifics. The agent's wire workflow recognizes the system the instruction will travel and runs the verification appropriate to the system.

For international wires through SWIFT, the analysis runs through the bank's correspondent-banking relationships and the contractual frameworks they encode. The OFAC sanctions screening we wrote about [separately](/blog/ofac-sanctions-screening-ai-agents-50-percent-rule) applies to every wire and is part of the agent's pre-execution check, with the OFAC analysis treated as a separate gate from the Article 4A authentication analysis.

## The Customer Notification Window and the One-Year Rule

[UCC 4A-505](https://www.law.cornell.edu/ucc/4A/4A-505) provides that if the receiving bank sends a notification of the receipt of a payment order to the sender or the sender's customer, the customer is precluded from objecting to the bank's retention of the payment if the customer does not object within one year after receiving notification. The notification rule creates a constructive ratification layer that runs alongside the authorization-and-verification analysis, and the bank's notification to the customer is a control the analysis depends on.

The agent's role on the notification side is to ensure the customer receives the notification through a channel the customer reads, in a form that surfaces the wire's details prominently, with a clear mechanism for objection. A notification that the customer does not read or that is buried in a statement is a notification that the constructive-ratification argument may not survive on. The institutions we serve render real-time notifications through the customer's preferred channel for any wire above a customer-configured threshold, with the customer's choice of channel documented in the wire agreement.

The customer that objects within the one-year window is the customer whose Article 4A case proceeds. The bank's posture on the case depends on the security procedure and the bank's compliance with it, but the procedural gate of timely objection is the first one the customer has to clear, and the bank's notification is what either makes or precludes the timely objection.

## The Agent's Audit File the Litigation Will Pull

The artifact set the bank's litigation team will pull when an Article 4A case lands is the artifact the AI agent has to produce as it runs. Per wire instruction, the file contains the caller authentication event with the factors used, the timestamps, the AAL level achieved, and any failure or fallback path taken; the agent's risk-tier classification of the instruction with the inputs the model used; the out-of-band confirmation event with the channel, the timestamp, the content rendered to the customer, the customer's confirmation or decline, and any second-factor verification the confirmation required; the beneficiary validation event with the bank's match result or non-availability indication; the OFAC and sanctions screening result; the instruction's execution decision with the agent's classification and the human reviewer's signoff for any instruction above the threshold requiring human signoff; the notification to the customer of the executed wire with the channel, the timestamp, and the content; and any customer interaction with the notification including objections, questions, or confirmations.

A file that produces this set for the wire that became the fraud case is the file that supports the bank's Article 4A defense. The bank's testimony in court is anchored in the per-wire file, the security procedure document the customer agreed to, and the bank's compliance with it. The bank that cannot produce the file in the discoverable form the court expects is the bank whose testimony is harder to support, and the bank whose Article 4A position erodes as the case proceeds.

## The Customer Education That Sits Alongside the Architecture

The bank's commercial-reasonableness posture is partly about the procedure and partly about the customer's understanding of the procedure. A customer who does not understand the security procedure they agreed to is a customer whose post-fraud claim against the bank often turns on the procedure's reasonableness and the bank's adequate disclosure. The bank's wire-agreement document and the bank's customer onboarding for wire activity have to render the procedure in language the customer reads and acts on.

The agent's onboarding flow for new wire authority renders the procedure's options to the customer, explains the trade-offs between higher and lower friction levels, captures the customer's choices in writing, and provides ongoing notice as the bank updates the procedure. A customer who chose a lower-friction procedure five years ago and whose threat environment now requires the higher-friction procedure is a customer the bank reaches out to, explains the situation to, and either upgrades or documents the customer's decision to remain on the lower procedure with the increased risk acknowledged.

This is a customer-relationship activity as much as a compliance activity, but it is a compliance activity in the Article 4A sense because the bank's procedure has to be one the customer agreed to with informed understanding. The agent that handles routine wire activity for the customer is the cheapest channel to keep the procedure conversation current, because the agent is in conversation with the customer regularly and can surface the procedure's evolution as part of the routine flow.

## The Failure Mode We Engineer Against

The pattern that produced the worst outcome on a customer's program before our involvement was a security procedure that the bank's wire-services team had updated in 2019 to include two-factor authentication, that the bank's product team had documented in a wire agreement the customer signed at onboarding, and that had then not been updated as the threat environment evolved. A wire fraud in 2024 ran through the procedure successfully because the fraudster had compromised the customer's SMS-OTP path; the customer's loss was significant; the customer sued; the discovery produced a procedure that was current to 2019 and a threat environment that had moved past it; and the court found the procedure not commercially reasonable in the current environment despite having been reasonable at the time of execution.

What we changed is that the procedure refresh cycle runs continuously rather than at long-cycle review. The agent's instruction-verification model is updated as new fraud patterns emerge in the institution's monitoring or in the industry-wide threat intelligence. The security procedure document the customer agreed to has version control and the customer is notified of substantive updates with an opportunity to either accept the update or decline (with the documented decline being part of the bank's Article 4A position). The bank's wire program now reads more like an ongoing security service the customer receives than like a once-signed contract, and the commercial-reasonableness assessment in any future case will read against the program's current state rather than against a stale document.

## The Honest Read

Article 4A is the rule the wire-fraud litigation actually turns on, and the AI agent on the bank's voice channel is the place the rule's procedural requirements become operationally observable. The institutions that treat caller authentication as a security control sufficient for wire activity are the institutions whose commercial-reasonableness posture rests on a foundation the case law has already moved past. The institutions that treat instruction verification as a separate problem from caller verification, that build the out-of-band confirmation pattern, that maintain the audit file per wire, and that keep the security procedure current with the threat environment are the institutions whose Article 4A position will hold.

The customer's wire-loss case is a hard case for the bank emotionally and a manageable case for the bank legally, if the architecture is right. The architecture's purpose is not to win every case; it is to make sure the bank's procedure stands up to the rule's text and the case law's evolution, and that the bank's compliance with the procedure is documented in the form the litigation will read. The institutions whose AI program runs this way produce wire programs with materially lower fraud losses, materially fewer legal cases, and materially better customer outcomes when the fraud does happen, because the architecture catches more of the social-engineering vector before it executes and supports better customer-side communication when execution has already happened.

We have written separately on the [voice cloning architecture](/blog/voice-cloning-deepfake-caller-verification-banks-phishing-resistant) the caller-authentication layer depends on, on the [OFAC screening](/blog/ofac-sanctions-screening-ai-agents-50-percent-rule) that runs alongside Article 4A for every wire, on the [BSA/AML transaction monitoring](/blog/ai-agents-bsa-aml-sar-narratives-transaction-monitoring) that catches the patterns at portfolio level, and on the [Reg E error resolution layer](/blog/regulation-e-error-resolution-ai-agents-dispute-intake) for the consumer-facing dispute pathway. Article 4A is the most underappreciated of the wire-side rules because it lives in commercial law rather than in regulatory text, but it is the rule the actual cases turn on, and the architecture has to encode it accordingly.

---

_Source: [https://www.seiright.com/blog/ucc-article-4a-wire-fraud-ai-verification-commercially-reasonable](https://www.seiright.com/blog/ucc-article-4a-wire-fraud-ai-verification-commercially-reasonable) · Sei AI_
