Business owner reviewing checks, bank records, and account balances at an organized financial workspace

This blog is published by TLC Business Solutions and promotes our own services.

Updated October 2026: corrected a regulatory citation, refined the framing on reporting deadlines, clarified the attribution of the document-retention experience described in this article, clarified how the check information was exposed, clarified how federal minimum retention requirements can apply to records without preserving the paper original under modern check processing, and added a clarification about remote-deposit retention and destruction duties.

Your business bank account is not protected the way your personal account typically is. That is one of the most important fraud-risk realities for owners to understand. Many business owners have heard about consumer debit-card and ACH protections and assume those same protections apply to business or commercial accounts. They commonly do not.

A signed check can contain more information than many business owners realize: your business name, bank name, routing information, account number, check number, and an example of an authorized signature. In one client incident shared by Tena Wallace, owner of TLC Business Solutions, someone used a scan of a signed check to create a signature stamp and then produced fraudulent checks.

The purpose of this article is not to create panic. It is to help you convert a serious risk into manageable controls that support stability, cash flow visibility, and better financial decisions.

Important: The timeframes discussed below reflect professional experience, common banking practices, account agreements, or payment-network rules that may vary. Your bank agreement, account type, state law, and payment method can affect your rights and responsibilities.

Current as of October 2026. Payment-network rules and retention practices change; confirm current requirements with your bank and in the Nacha Operating Rules. This article is reviewed annually.

Part 1: Understand How Bank-Account Fraud Can Happen

I. Define the Key Terms

Check fraud is the unauthorized creation, alteration, or use of a check drawn against an account.

ACH debit is an electronic transaction in which a company or organization pulls funds from your bank account using account and routing information.

Bill pay is a bank service that lets you initiate payments through your financial institution. Depending on the bank and payee, the bank may send an electronic payment or issue a check.

Positive Pay is a commercial bank service that compares presented checks with checks your business has issued. The bank may ask you to approve or reject exceptions.

Source documents are original records or transaction materials, such as checks, deposit items, signature documents, and other records maintained by a bank or business.

Understanding these terms helps you identify where the risk occurs and which control may address it.

II. What May Happen When a Signed Check Is Copied

A criminal does not necessarily need access to your checkbook to attempt check fraud. A clear scan or photograph may provide enough information to imitate the check’s appearance and signature.

A copied check may be used to:

  • Reproduce the account and routing information.
  • Create a counterfeit check with a different payee or amount.
  • Reproduce or imitate an authorized signature.
  • Deposit the check through a financial institution, mobile deposit system, or third-party account.
  • Test whether fraudulent items clear before creating additional transactions.

The incident Tena encountered involved a scan of a signed check being used to create a signature stamp. In this case, the check was deposited through an ATM rather than handed across a counter. ATMs are commonly serviced by outside crews rather than bank employees, and this ATM was in a high-risk location. Tena's understanding is that the exposure most likely had less to do with the vendor and more to do with how the physical check moved through the network. A paper check can pass through many hands between deposit and clearing — whoever receives and deposits it, whoever services and empties the ATM, whoever transports it, and the processing and imaging steps at each institution along the way. Each of those can be a point at which the account and signature information on the check is exposed. The fraud was not attempted immediately; it was timed to land a few days after the original check would have been destroyed. The details of the client are not being disclosed, but the underlying lesson applies to many businesses: a signed check should be treated as sensitive financial information.

Accounting workspace with ledgers, calculators, and financial records used for payment review

III. Why Business Accounts Need More Attention Than Consumer Accounts

This is the central issue for many owners: Regulation E's consumer liability limits do not generally apply to business or commercial accounts.

For consumers, Regulation E generally provides a tiered liability framework for certain unauthorized electronic fund transfers, with stronger protections when the issue is reported quickly. Card-network zero-liability policies may, in practice, give consumers more protection than Regulation E's minimum floor in some situations. Business owners often hear the consumer version of these protections and assume they also apply to company accounts. They generally do not.

For a business account, the governing framework is usually more contract- and operations-based. Your rights and obligations may depend on:

  • Your bank account agreement.
  • UCC Article 4 and other applicable state-law rules.
  • Nacha Operating Rules for ACH transactions.
  • The specific payment channel involved, such as check, ACH, card, wire, or bill pay.
  • How quickly the activity is identified and reported.

The practical takeaway is straightforward: do not assume your business account carries the same timing, liability, or dispute protections you may have on your personal account.

IV. Why Your Own Records Matter

Tena advises business owners to keep their own copies of signed checks and other important financial documents. Her recommendation comes from experience with a client who needed an original source document after a problem occurred.

Under Check 21, banks commonly convert paper checks into images, and the image is the legal equivalent of the original check. That means the physical paper item does not necessarily have to be retained for the same period as the bank's records. In the incident Tena described, she later asked the bank whether the original check could be dusted for fingerprints, because the original was the only physical evidence that could have carried fingerprints. The bank explained that the original had already been destroyed. According to the bank, the destruction was done in accordance with federal retention requirements. Tena's experience was that this had happened after roughly 60 days, and the fraud was timed to land a few days after the original document would have been shredded.

Federal rules do set minimum retention periods for financial records, but the period depends on the type of record and the rule that applies to it. Different rules impose their own minimums, and those requirements can operate independently of each other. This incident was some years ago, and retention requirements can change over time, so the specific period and what it covers should be confirmed with the bank for any particular record.

The key nuance is that a retention requirement is generally satisfied by keeping a record of the item — commonly an image or copy, including under Check 21 substitute-check rules — rather than the physical paper itself. In this specific incident, the reason the physical original mattered was narrow: it was the only item that could have carried fingerprints. The paper was evidence, not paperwork. Under modern check processing, that avenue largely closes on its own. Paper checks are commonly truncated in the collection process and replaced by substitute checks or electronic images, and the physical original is frequently not retained at all, or not retained in a form anyone could dust. That is why a bank can be fully compliant with federal retention requirements and still no longer have the paper original. The bank's explanation to Tena was that destruction was done in accordance with federal requirements, and that is consistent with the original having been imaged and then destroyed. This cuts both ways: the paper original an owner might hope to examine may not exist, and the reason it may not exist is often the system itself rather than carelessness by the institution. The practical takeaway remains the same: because the original is not something an owner can count on under modern check processing, treat your own copy as the one you control and report quickly.

The chain-of-custody point also matters here. A paper check may pass through many hands between deposit and clearing, so the fewer hands that touch a payment, the fewer points of exposure. That is part of the structural case for electronic payment methods over paper checks, even though no payment method eliminates risk.

For example, the Bank Secrecy Act generally requires certain records, including records of checks and other monetary instruments above a threshold, to be retained for around five years under 31 CFR 1020.410 and the general record-retention framework in 31 CFR 1010.430. Regulation E also requires evidence of compliance to be retained for at least two years. These examples illustrate that federal minimums exist and can differ by record type, but they should not be treated as a promise about what applies to any particular item. Confirm the current requirements and availability periods directly with your bank.

A related point matters for remote deposit capture. When you deposit a check by phone or scanner rather than at a branch, the deposit agreement commonly requires the depositor to retain the physical check for a set period and then destroy it securely. In Tena's own experience, her agreement instructed her to keep the physical check for 60 days and then destroy it. That kind of term varies by bank and by agreement, so readers should confirm the exact retention period in their own remote-deposit terms rather than treating 60 days as universal. The reason for the requirement is fraud control: while the paper check still exists after remote deposit, it could potentially be deposited a second time somewhere else. Retaining it lets the depositor answer a challenge, and secure destruction after the retention period helps close off duplicate-presentment risk. Under this arrangement, the party most likely to still have the physical item for that window is the depositor, not the bank. After the retention period, the paper is typically gone by requirement, and the bank has its image or record instead. An owner who later wants the original cannot assume any party still holds it.

You can reduce uncertainty by:

  • Keeping a secure copy of every signed check.
  • Saving the front and back of cleared checks when available.
  • Retaining payment approvals, invoices, and vendor instructions.
  • Storing records in a restricted-access digital system.
  • Using a consistent naming convention for payment documentation.
  • Asking your bank how long specific check images and bill-pay records remain available.
  • Knowing your own remote-deposit retention term and destroying deposited paper checks securely when your agreement requires it.

V. Debit Cards, Credit Cards, and Exposure

Tena generally advises clients to use a credit card for business purchases instead of a debit card, when appropriate for the business and permitted by the card agreement.

The reason is related to where the money sits:

  • A fraudulent debit-card transaction may remove funds directly from your operating account.
  • A credit-card transaction may involve the issuer’s funds until your business pays the statement.
  • Credit-card issuers often have a dispute or chargeback process that differs from a debit-card process.
  • The available reporting and dispute window depends on the issuer agreement and transaction type.

This distinction matters even more because a business account may not receive the same consumer-law protections that apply to a personal account. Regulation E's consumer liability limits do not generally apply to business or commercial accounts, so a business owner should not assume that a familiar consumer deadline applies to a company account. Instead, confirm the controlling terms in your account agreement, UCC Article 4, and the Nacha Operating Rules.

Tena's practical guidance is to report suspicious activity the same day it appears. The practical reporting window for some payment types is measured in banking days from settlement, not from when the problem comes to light — so the sooner you call, the more options remain. That is a risk-management warning, not a universal legal deadline or promise of recovery.

A credit card does not make fraud impossible. You should still:

  • Use transaction alerts.
  • Restrict employee card access.
  • Set reasonable spending limits.
  • Review card activity frequently.
  • Report unauthorized transactions through the issuer’s prescribed process.
  • Dispute only transactions that are genuinely unauthorized.

Part 2: Set Up Controls That Reduce Exposure

VI. Prefer Controlled Payment Methods

Tena also recommends using your bank’s bill-pay service when practical, rather than giving vendors unrestricted access to your account and routing numbers.

The distinction is important:

  • A bill-pay payment initiated by you generally functions as a controlled “push” from your account.
  • A vendor-authorized ACH debit allows the vendor or its processor to initiate a “pull” from your account.
  • A check sent through bill pay may be issued by the bank, which can limit the need to share your operating-account information directly.
  • The exact payment rail varies, so ask your bank how its bill-pay service processes each payment.

Bill pay reduces how many parties hold your account information. It does not remove the need to reconcile and monitor — the payment still has to be reviewed.

Rule references in this article summarize regulatory requirements and common banking practices at the time of writing. Confirm current requirements with your bank and in the Nacha Operating Rules, which control.

This is also where the business-versus-consumer gap becomes especially important. The sharpest illustration is that the bank's return deadline for an unauthorized ACH debit is commonly much tighter for a non-consumer account than for a consumer account, and the banking-day clock runs from settlement, not from when the owner notices the problem.

  • Consumer — 60 calendar days — the return must be made available to the ODFI by opening of business on the banking day following the 60th calendar day after settlement.
  • Non-consumer — 2 banking days — the return must be made available to the ODFI no later than opening of business on the second banking day following settlement.

These timing rules are important because they help explain why a business owner may have less room for delay than expected. They do not mean a customer personally has a guaranteed 60-day or 2-day notice period in every case. Your protection depends on the account agreement and on how quickly the activity is reported and returned under the applicable network rules. Ask your bank what it requires from you and by when.

Before using bill pay, ask:

  • Will the bank send a check, ACH payment, or another payment type?
  • What information is shared with the payee?
  • What cutoff time applies to payment changes or cancellations?
  • How are new payees added?
  • Can two people approve new payees?
  • How long are payment instructions and audit logs available?

VII. Establish a Small-Business Fraud-Control Checklist

Your controls do not need to be complicated to be useful. Consider the following framework:

A. Separate accounts

  • Use a primary operating account for appropriate operating activity.
  • Consider a separate account for payroll, taxes, or reserves.
  • Limit the balance in accounts used for routine purchasing where practical.
  • Avoid linking every vendor or service provider to your main operating account.

B. Use bank monitoring tools

Ask your bank about:

  • Check Positive Pay.
  • Payee-name and amount matching.
  • ACH Positive Pay.
  • ACH debit blocks or filters.
  • Dual approval for payments.
  • Daily transaction alerts.
  • New-user and password-change alerts.
  • Callback verification for account changes.

Positive Pay can help identify checks that do not match your issued-check file, but it requires timely review and careful configuration. Exception-response deadlines also matter.

C. Reconcile more frequently

Monthly reconciliation may not provide enough visibility for a business with significant transaction volume or fraud exposure. Consider reviewing bank activity weekly, or more frequently when circumstances justify it.

Look for:

  • Unknown payees.
  • Duplicate checks.
  • Unexpected ACH debits.
  • Unfamiliar card transactions.
  • Changes in recurring payment amounts.
  • Payments that do not match invoices or approvals.

D. Separate payment duties

Where staffing permits:

  • One person prepares a payment.
  • Another person reviews the invoice and authorization.
  • A designated owner or manager approves unusual transactions.
  • Bank access is assigned according to job responsibilities.
  • Former employees and inactive users are removed promptly.

Professional bookkeeper reviewing documents and payment records in an organized office

VIII. Call Your Bank Before There Is a Problem

Ask your banker or treasury-management representative:

  1. What is the bank’s deadline for reporting unauthorized checks, debit-card transactions, and ACH debits?
  2. Which rules apply to my business account?
  3. What records are retained, and for how long?
  4. Can the bank provide front-and-back check images?
  5. Is Positive Pay available for my account?
  6. Can I use ACH blocks, filters, or approval rules?
  7. What happens if an employee or vendor’s bank information changes?
  8. Which phone number should I use to report suspected fraud outside normal business hours?
  9. What documentation is required for a dispute?
  10. Can the bank provide a written explanation of its process?

Save the answers with your financial records. The goal is to know the procedure before an urgent event occurs.

FAQ

How soon should I report suspected business-account fraud?

Report it as soon as you identify it through the bank’s approved fraud-reporting channel. Business-account timelines are often much tighter than consumer-account timelines, and you should not rely on a general 24-hour, 30-day, or 60-day assumption.

Should my business stop using checks?

Not necessarily. You can discuss options such as Positive Pay, secure check stock, dual approvals, controlled check issuance, and more frequent reconciliation with your bank.

Is bill pay safer than giving a vendor my account number?

Bill pay may reduce the number of vendors with direct access to your account information, but the protection depends on how your bank processes the payment. Confirm whether the payment is sent by check or ACH and review the service agreement.

Does a credit card guarantee that my business will recover fraudulent charges?

No. A credit card may provide a different dispute process and may reduce the immediate exposure to your operating cash, but outcomes depend on the issuer agreement, the facts, and timely reporting.

What if I need help reviewing my controls?

TLC Business Solutions provides bookkeeping and accounting services and business management consulting services for US-based businesses. Based in Ukiah, California, TLC supports businesses throughout the United States, including businesses whose owners or responsible parties are located outside the country. Services are limited to US GAAP and US tax law. Contact: marketing@tlcbusinesssolutions.com or 916-596-0803.

For related accounting-control reading, see Combining Two Sets of Books: The 7-Step Cleanup That Saves Your Business From a Year-End Mess.

Conclusion: Treat Payment Security as Part of Cash Flow Management

Bank-account fraud can affect more than a single transaction. It may disrupt payroll, vendor relationships, tax payments, and your ability to make timely operating decisions.

The main lesson is clear: your business bank account is not typically protected the way your personal account is. That makes speed, documentation, and account controls especially important.

You can reduce exposure by:

  • Keeping your own copies of signed checks.
  • Reviewing bank activity frequently.
  • Using controlled purchasing methods.
  • Asking about bill-pay protections.
  • Separating payment duties.
  • Activating alerts and positive-pay tools where available.
  • Reporting suspicious transactions promptly.
  • Confirming deadlines directly with your bank.

Strong controls support cash flow management for small business, accurate records, and informed decisions. They also complement reliable small business accounting in the United States, including small business accounting in California and bookkeeping services in Ukiah.

Clearer numbers. Better decisions.

External Resources

Nacha is a trademark of Nacha. This article is independent educational content and is not affiliated with, endorsed by, or sponsored by Nacha.

Disclaimer: This article is for general educational purposes and does not constitute professional tax, accounting, legal, or financial advice. Bank agreements, payment-network rules, state law, account type, and transaction details can affect your rights and responsibilities. Retention periods, liability standards, and dispute windows can vary by account agreement and facts. Retention periods, reporting deadlines, and recovery outcomes vary by bank, account type, and transaction, and nothing in this article guarantees a particular recovery or result. Discuss your specific situation with your bank and, where appropriate, your attorney, accountant, or other qualified advisor.