Does Reg E Apply to Business Accounts? Payroll Cards and UCC 4A

Regulation E generally does not apply to business accounts. The Consumer Financial Protection Bureau’s rule, issued under the Electronic Fund Transfer Act, protects accounts established primarily for personal, family, or household purposes, which leaves corporations, LLCs, partnerships, and most other entities outside its liability caps and error resolution rights.1eCFR. 12 CFR Section 1005.2 A one-person LLC with modest revenue gets the same treatment as a Fortune 500 company: no Reg E coverage. What governs the account instead puts far more responsibility on the business.

The Consumer Protections a Business Account Loses

Two Reg E protections matter most, and business accounts get neither by default.

The first is a tiered cap on liability for unauthorized electronic transfers, set by 12 CFR ยง 1005.6.2Consumer Financial Protection Bureau. 1005.6 Liability of Consumer for Unauthorized Transfers A consumer who reports within two business days is liable for no more than $50. Reporting after two business days but within 60 days of receiving a statement can push liability to $500, and only for transfers the bank can show earlier notice would have prevented. Silence beyond 60 days after a statement showing the unauthorized transfer exposes the consumer to unlimited liability for later transfers, but even then the bank has to prove the losses would have been avoided by earlier reporting.

The second is the error resolution framework. When a consumer reports an error, the bank must complete its investigation within 10 business days. If it needs the full 45-day extension the rule allows, it has to provisionally credit the account within those first 10 business days so the consumer has access to the disputed funds while the investigation continues.3eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors Findings must be reported within three business days of completing the investigation.

A business disputing a fraudulent wire has no right to either. There is no $50 cushion, no $500 fallback, no mandated investigation timeline, and no provisional credit. If a fraudster drains a business checking account through unauthorized ACH debits or a fraudulent wire, the bank’s obligations depend on the commercial deposit agreement and on state law, and those agreements routinely shift risk to the business in ways that would be illegal for a consumer account.

The Business Accounts That Might Still Be Covered

Sole Proprietorships

Sole proprietorships are the clearest exception. Because a sole proprietorship is not a separate legal entity from the owner, the account holder is a natural person, and Reg E’s definition of “consumer” can be satisfied. The deciding factor is the account’s primary purpose.1eCFR. 12 CFR Section 1005.2 A personal checking account that happens to receive some side-business income is likely still covered because it was established for personal purposes. A separate account opened specifically to run the sole proprietorship’s commercial operations is not, because its primary purpose is business.

The line between “personal account with some business use” and “business account owned by a person” is where disputes arise. Banks look at how the account was described at opening, how it’s titled, and the pattern of transactions flowing through it. A sole proprietor who wants Reg E protection should keep personal and business banking genuinely separate and avoid routing significant commercial volume through the personal account.

Payroll Card Accounts

Reg E explicitly covers payroll card accounts, meaning accounts an employer establishes to deposit wages electronically on a recurring basis.1eCFR. 12 CFR Section 1005.2 The employee is the protected consumer, not the employer. If your company pays workers by payroll card, the program must satisfy Reg E’s disclosure, error resolution, and liability requirements for each cardholder.

What Doesn’t Qualify Even Though It Looks Like It Should

Health Savings Accounts, Flexible Spending Accounts, and similar tax-advantaged health accounts are not covered by Reg E, even though individual employees fund and use them. They are excluded from the regulation’s definition of “account” because they qualify as trust arrangements or are carved out of the prepaid account definition.1eCFR. 12 CFR Section 1005.2 If an unauthorized transaction hits an HSA debit card, Reg E’s caps and timelines don’t apply. Any protection comes from the card network’s fraud policy or the account custodian’s terms.

What Governs Business Transfers Instead

When Reg E doesn’t apply, business electronic transfers fall primarily under Article 4A of the Uniform Commercial Code, adopted in some form by every state. UCC 4A explicitly excludes consumer transactions already covered by the Electronic Fund Transfer Act, drawing a clean line: consumers get Reg E, businesses get UCC 4A.4Legal Information Institute. UCC 4A-108 – Relationship to Electronic Fund Transfer Act

UCC 4A governs wire transfers and other high-value fund transfers between banks and their commercial customers. The framework is built around a “security procedure,” an agreed-upon method for verifying that a payment order genuinely comes from the business.5Legal Information Institute. UCC 4A-202 – Authorized and Verified Payment Orders If a fraudster sends a payment order in the business’s name, who bears the loss depends on whether the bank’s security procedure was “commercially reasonable” and whether both sides followed it.

How Commercially Reasonable Is Determined

Whether a security procedure is commercially reasonable is a question of law. Courts weigh four things:

  • The customer’s expressed preferences when the account was set up.
  • The customer’s circumstances known to the bank, including the size, type, and frequency of payment orders normally sent.
  • The alternatives the bank offered, particularly any more secure procedure the business declined.
  • Industry norms for similarly situated banks and customers.

Here is the detail that catches many businesses off guard. If the bank offered a commercially reasonable security procedure and the business chose a weaker one instead, the weaker procedure is deemed commercially reasonable simply because the customer selected it.5Legal Information Institute. UCC 4A-202 – Authorized and Verified Payment Orders A business that declined multi-factor authentication or callback verification to save hassle has effectively agreed to absorb the fraud those tools would have prevented.

Reporting Deadlines Under UCC 4A

UCC 4A imposes its own reporting obligation, and it works differently from Reg E. When a bank accepts an unauthorized payment order and notifies the customer, the business has one year from that notification to object or lose the right to challenge the debit entirely. Within that year, the business should notify the bank within a reasonable time, generally interpreted as no more than 90 days, after receiving notice that the order was accepted or the account was debited. Missing that 90-day window doesn’t eliminate the bank’s refund obligation, but it forfeits the business’s right to interest on the refund.

The business timeline is more generous in raw calendar time than the consumer’s two-business-day trigger, but it delivers far less. No provisional credit. No capped liability. The refund itself depends on whether the security procedure was followed.

Stop-Payment Rights

Under UCC Article 4, a business customer can stop payment on an item drawn on its account by giving the bank enough detail to identify the transaction, provided the bank receives the order in time to act on it.6Legal Information Institute. UCC 4-403 – Customer’s Right to Stop Payment; Burden of Proof of Loss A stop-payment order lasts six months and can be renewed. An oral order expires after 14 calendar days unless confirmed in writing. If the bank pays an item despite a valid stop-payment order, the burden of proving the loss falls on the business, another contrast with Reg E, where the institution carries the investigative burden.

Card Network Protections as a Partial Backstop

Business debit and credit cards may carry some fraud protection through the card network itself. Visa and Mastercard offer zero-liability or liability-waiver programs that can extend to business cards, but the terms differ significantly from what consumers receive by statute. These programs are contractual, so the network or issuing bank can change the terms, impose conditions, or cap coverage.

Typical limitations include exclusions for transactions by owners or principal shareholders, tight reporting and card-cancellation windows (often two business days), and caps on total waivable charges per cardholder. Cash advances and transactions that benefit the company generally aren’t covered. The protections also won’t reach unauthorized ACH debits or wire transfers, which bypass the card networks entirely. Treat card network fraud policies as a supplement, not a replacement.

Closing the Gap on Your Own

Because the law puts more responsibility on business account holders, prevention and early detection fall to the business. Several tools help:

  • Positive pay. Your business sends the bank a daily file of authorized checks or ACH transactions, and the bank rejects anything that doesn’t match. It is probably the single most effective tool for stopping unauthorized debits.
  • ACH debit blocks or filters. You can instruct the bank to reject all incoming ACH debits, or to accept only from a pre-approved list of originators. A full block eliminates that attack vector if your business doesn’t need to receive ACH debits.
  • Dual authorization. Require two people to approve any outgoing wire or ACH payment above a set threshold, so a single compromised credential can’t drain the account.
  • Daily reconciliation. Under UCC 4A, recovery depends on catching problems quickly. Reviewing once a month gives fraudsters a 30-day head start.
  • Dedicated banking computers. Use a machine that does nothing but access online banking. No email, no browsing, no downloaded software. Business email compromise is the entry point for a large share of commercial account fraud.

The commercial deposit agreement itself deserves attention before signing. Look at how liability for unauthorized transactions is allocated, what security procedures the bank offers, and whether declining a stronger option shifts risk to you. Under UCC 4A that declination is legally meaningful, because the weaker procedure you accept becomes the benchmark for whether the bank met its obligations.5Legal Information Institute. UCC 4A-202 – Authorized and Verified Payment Orders Take the strongest security option offered, even when it adds friction.