The Checking Post THECHECKINGPOST.COM
← The Checking Post/Fraud liability
Fraud liability

Does Regulation E apply to business accounts, and what protects the company money instead

The 50 dollar cap, the 500 dollar cap and the 60 day rule all live in a definition that says personal, family or household. A company account is outside it, and the contract takes over.

CPBy the comparisons desk.9 min read. 18 August 2026

A bookkeeper rang me in June about 14,000 dollars that left a company account overnight, and I gave her the wrong first instruction. Report it in writing within 60 days and your liability is capped, I said, because that is the rule I have repeated to people for years without checking which people it covers. It covers her personally, and it does not cover the company she works for, and I sent her into a bank conversation with the wrong lever in her hand.

You should read your deposit agreement this week if you have not, and you should do it before anything goes wrong rather than after. That sentence is the whole practical content of this piece, and everything below is why I now say it in that order.

Does Regulation E apply to business accounts. The answer is in the definitions, it is one sentence long, and it has been sitting there the entire time.

The sentence that decides it

Regulation E defines the accounts it governs in section 1005.2, and the definition ends with a phrase that does all the work: an account means “a demand deposit (checking), savings, or other consumer asset account … held directly or indirectly by a financial institution and established primarily for personal, family, or household purposes.”

Personal, family or household is the whole test. A company operating account is none of the 3, so the protections that everybody quotes are not available to it. That is not a bank policy you can argue with, and it is not something a better bank fixes for you. It is the perimeter of the regulation.

What sits inside that perimeter is worth knowing precisely, because it is the thing you have been imagining you had. If a consumer reports a lost or stolen access device within 2 business days, liability “shall not exceed the lesser of $50 or the amount of unauthorized transfers that occur before notice”. Miss that window and the ceiling becomes 500 dollars. Miss the 60 day statement window and the cap goes away for transfers after it.

Ceiling on your loss from an unauthorised transfer Personal account, notice within 2 business days $50 Personal account, notice later than that $500 Company account, any notice whatever the deposit agreement says Caps from 12 CFR 1005.6, perimeter from 1005.2(b). Read 18 August 2026.

What replaces it on a company account

Nothing federal replaces it in the same shape. What governs instead is the contract you signed when the account was opened, plus state commercial law for wires and cheques. The contract is the part you can actually read tonight, and it is the part almost nobody has read.

I had assumed banks would keep those clauses vague. They do not keep them vague at all. The agreements I have gone through set out reporting windows in days, name the security procedures you are deemed to have accepted, and say plainly what happens if you fail to review a statement in time. The windows are usually shorter than the 60 days people expect, and the shortest I have read in an agreement for a small business account was 14 days from the statement being made available, which is a fortnight to notice a line you were not looking for.

Read the clause about the security procedure twice, because it decides who eats a fraudulent wire. It turns on whether the bank offered a commercially reasonable procedure and whether you agreed to it. A company that declined dual authorisation to save 2 minutes a day has usually signed the argument away in advance.

The 3 questions I would ask my own bank

How many days do I have to report an unauthorised item before the loss is mine. Ask for the number and the clause rather than the reassurance. Different products in the same bank can carry different windows, and I have seen 30 and 60 in the same agreement for different transaction types.

What security procedure is on this account today, and what is the next one up. Dual control on outgoing wires and a callback on new payees are the 2 that change the argument most, and both are usually available and switched off by default.

What does reimbursement actually look like when the bank agrees it is their loss, in days rather than in principle. A company that gets its 14,000 dollars back in 9 weeks has still missed a payroll run, and the payroll run is the thing that ends companies.

QuestionPersonal accountCompany account
Who sets the rulesRegulation Ethe deposit agreement
Cap with prompt notice$50none by law
Statement review window60 daysoften 14 to 30

The word unauthorised is narrower than it sounds

Even inside consumer law the protection has a shape people misread, and the shape matters for a company because it is the same trap with no cap behind it. Regulation E defines an unauthorised transfer as one “initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit.”

Then it names an exclusion that catches most real cases. The term does not include a transfer initiated “by a person who was furnished the access device to the consumer's account by the consumer, unless the consumer has notified the financial institution that transfers by that person are no longer authorized.” You handed over the card or the credentials, so the transfer is not unauthorised in the regulatory sense.

Now put a small company under that sentence. A bookkeeper with the log-in, a contractor with the card, an office manager who kept access after leaving. Those are the 3 shapes I hear about most, and none of them is a stranger with a stolen device. On a personal account they already sit outside the caps. On a company account there was never a cap to sit outside of.

What the numbers look like when nothing is capped

Work the arithmetic once and the priorities sort themselves. A personal account with prompt notice has a worst case of 50 dollars. The same event on a company account has a worst case equal to the balance, plus whatever the overdraft line allows, minus whatever the bank chooses to return.

That is not a rhetorical point. A company that keeps 200,000 dollars in an operating account to make payroll comfortable has 200,000 dollars of exposure sitting behind a contract clause, and the clause is 3 paragraphs long and was signed by somebody who no longer works there. The sweep account article on this site is about interest. This is the other reason to keep less money in the account you pay from.

I would take that seriously in proportion to your payroll rather than your revenue. A 40 person company with a 9 day gap to the next payroll run is in a completely different position from a solo consultancy that can wait 6 weeks for a bank investigation to finish, and the difference has nothing to do with who was more careful.

The other thing I would put in the file is a note of who signed the agreement and when. Two of the 3 companies I asked could not produce their own signed copy inside a day, and one of them was told by the bank to request it in branch. That is a bad afternoon to have during a fraud, and it is a 10 minute job on a quiet Tuesday.

Where I was wrong in a way that matters

My error was not the definition. I knew Regulation E was consumer law, and on a quiet day I would have said so without prompting, which is the uncomfortable part: the knowledge was there and it did not reach the moment when somebody needed it. The error was operational. I gave a protection speech to somebody standing at a counter with a company problem, and a wrong first instruction costs a day at exactly the moment when the days matter.

That is the part I keep thinking about, and it is not the rule but the timing of the advice. The good version of the same 30 seconds is a question rather than a statement: whose name is the account in, and have you read what that contract says about reporting.

An aside that has nothing to do with regulation. The reason this confusion survives is that banks market business accounts with the same vocabulary they use for personal ones. Protection, security, peace of mind. None of those words are legal terms, and none of them mean the 50 dollar cap when the account is a company account. Right, back to the paperwork.

One more number worth keeping in view. The regulation's own caps are 50 and 500 dollars, and they were written when a stolen card meant somebody physically holding it. A company losing 14,000 dollars through a credential is not a bigger version of that event. It is a different event with no ceiling written for it, and the contract is the only document in the room.

What actually reduces the loss

Positive pay on cheques and dual authorisation on wires do more than any argument after the fact, and both are boring enough that they get postponed for years. I would rather have a 2 person rule on outgoing payments than a strong opinion about who is liable.

Reviewing statements on a schedule is the other half, and the schedule matters more than the thoroughness. A weekly 10 minute check beats a monthly hour, because every contractual window is measured in days from when the statement was made available rather than from when somebody found time to look at it.

I have not found a published figure for how often small companies recover funds fully after an unauthorised transfer, and I looked for one across the regulators and the trade press. So I cannot tell you the odds on recovering 14,000 dollars. I can tell you the shape of the answer changes with how fast you notice.

What I could not establish

Whether reporting windows have shortened in the last few years. I compared 3 agreements I had to hand and 2 of them were 30 days, which is not a dataset and does not tell you anything about the market. Nobody publishes a survey of these clauses that I could find.

Whether banks apply their own windows strictly against small business customers or negotiate in practice. I suspect there is more room than the contract implies, because a bank losing a relationship over 14,000 dollars is a bad trade for the bank, and my guess is that the outcome depends on who you are rather than what the clause says. That is a guess with nothing behind it except 3 conversations.

The detail I keep coming back to is the phrase itself, 4 words long in a definition from 1978. Personal, family, or household is the whole of it. It was written to draw a sensible line around consumer protection, and it lands as a trapdoor under every small company that assumed the protection came with the account. I am not sure anybody intended the trapdoor, and I have stopped expecting it to be closed.

Sources

  1. 12 CFR 1005.2, definition of account under Regulation E. ecfr.gov. Read 18 August 2026.
  2. 12 CFR 1005.6, liability of consumer for unauthorised transfers. ecfr.gov. Read 18 August 2026.
No mailing list yet We are keeping a register of people who want one. Nothing is sent while it is open.