The paying bank needs an expected-payment record
A business issues checks through its accounting system, while its bank later receives items presented for payment. Positive pay connects those two records. The business supplies information about checks it has issued; the bank compares presented items with that information and routes discrepancies through an exception process. The control asks whether the item agrees with an expected disbursement. It is different from checking whether a deposited check is genuine or when a depositor can withdraw its proceeds. Depending on the service, an initial account posting can precede the exception decision and a subsequent return or adjustment; the control should not be described as a promise that no provisional debit will ever appear.
The OCC's historical guide describes positive pay as cooperation between a company and its bank to identify checks the company did not issue. It is useful background, but current service agreements determine today's actual fields, response times and responsibilities. [1] The product name alone does not establish that every bank compares payee names, covers every presentation channel or promises reimbursement for every fraudulent item.
The issue file is part of the control
An issue record typically links the disbursement account, check number, amount and relevant date; the service may also use payee information. The accounting workflow should ensure that the bank receives the records it needs within the contracted schedule. A file generated correctly but never accepted by the bank is not equivalent to an active matching record. The acknowledgement and any rejected records therefore belong in the operational reconciliation.
The Chase Digital Services Agreement, last updated June 2026, provides a concrete example. For its specified Positive Pay Service, it requires issuance information by 8 p.m. Eastern on the day the item is issued and names account number, serial number, amount and issue date. It explicitly says this service does not compare the payee name. The same agreement gives positive pay a default-return exception treatment unless otherwise agreed in writing, while reverse positive pay has a different default. [2]
These terms should be read as one product example, not a universal banking timetable. They demonstrate why implementation questions matter: what exact data is required, when is it due, how is acceptance confirmed and which exceptions need a decision? A generic brochure promising fraud protection does not answer those operational questions. A business with multiple accounts or banking platforms should document the actual service on each account rather than extrapolate from one enrollment.
Payee matching is an additional capability
Wells Fargo's payments-fraud page distinguishes Positive Pay, which compares check serial numbers and amounts, from Payee Validation, which also identifies differences in supplied payee information. It describes Reverse Positive Pay as an alternative for companies unable to transmit issued-check files. [3] That separation is a useful model for evaluating any offer: the exact matching fields and workflow matter more than the broad label.
Payee-name comparison also involves data quality. The name in the business system may include abbreviations or a legal suffix, while an image may be imperfect. A mismatch can therefore be a reason for review without being proof of wrongdoing. The business and bank need to understand the service's supported format and exception handling, while preserving the meaning of the intended recipient. Quietly replacing an ambiguous name with a convenient guess would weaken the audit trail.
Even a single bank may offer different capabilities on different platforms. Chase's Digital Services Agreement says its specified Positive Pay Service does not compare the payee name, while separate Chase Connect enrollment guidance for clients transitioning from First Republic describes activating payee-name verification for applicable accounts. [2, 5] Neither statement should be used to characterize every Chase customer or every account.
A hypothetical batch shows the decision point
Assume a company issues three checks: check 4101 for $2,000, check 4102 for $3,500 and check 4103 for $4,500. The issue file totals $10,000 and is accepted under a hypothetical service. Later, the first two checks are presented with matching information, while the third is presented for $4,800. The $300 difference creates an exception. The example assumes the service compares amounts; it does not assert how a particular bank's system will classify every possible case.
The reviewer should compare the exception with authoritative internal records and the available check image. If $4,500 is the supported amount and the discrepancy cannot be resolved as an input or processing error, the business follows its authorized return or investigation procedure. The important control is a documented decision based on evidence. The existence of an exception does not itself establish that the payee committed fraud, and the amount should not be altered merely to make the records match.
Now assume instead that check 4103 is genuinely $4,500 but was accidentally omitted from the transmitted issue file. It can also appear as an exception. In that case the problem is the issuer's data pipeline, not necessarily the presented check. A process that rejects every exception without review can harm legitimate recipients. A process that automatically approves every exception because omissions are common can defeat the control. Reducing false exceptions protects both efficiency and the quality of attention given to real discrepancies.
Cutoffs convert a control into a daily obligation
Exception review is time-sensitive because the bank must handle presented items within its operating and legal framework. A company's useful deadline is the one specified for its service, account and decision channel. Email alerts are aids; they do not necessarily replace the customer's responsibility to review the bank's system. Staff need coverage during leave, holidays and outages, together with an approved escalation route when the normal reviewer cannot act.
The default decision is especially consequential. Returning unresolved exceptions reduces one kind of payment risk but can interrupt legitimate supplier or payroll payments. Paying unresolved exceptions preserves continuity but may allow an unwanted payment to proceed. Chase's current agreement illustrates that positive pay and reverse positive pay can have different defaults. [2] A company should choose and operate its workflow with that consequence understood rather than discover it after a missed deadline.
A helpful operational record captures when the exception became available, who reviewed it, the evidence considered, the selected decision and the bank's confirmation. This allows a later incident review to distinguish an alert that was never seen, a decision submitted too late and a timely instruction that did not process as expected. Each failure points to a different corrective action. A single checkbox reading reviewed loses that distinction.
Reverse positive pay changes who does the comparison
Under a reverse workflow, the bank provides presented-item information and the business compares it with its own records. This can help a company that cannot supply issue files reliably, but it moves more matching work into the customer organization. The burden depends on check volume, the quality of its ledger and the permitted review window. It should not be sold internally as the identical control with less setup effort.
Suppose a hypothetical business presents 100 checks daily. Reviewing every item for 45 seconds would take 75 minutes a day. If a conventional matching service creates five exceptions daily and each needs three minutes of research, that workflow requires 15 minutes of exception review, plus file preparation and reconciliation. The calculation is illustrative: 100 times 45 seconds equals 4,500 seconds; five times three minutes equals 15 minutes. Real time depends on the evidence available and complexity of each item.
This comparison does not automatically favor one service. An unreliable issue-file process could generate many more exceptions, and a very low-volume business might reasonably prefer another arrangement. The point is to budget the labor where the service actually places it. A control that depends on daily attention is weak if management buys the service but allocates no person or backup to operate it.
The issue record itself needs protection
Positive pay relies on the company's statement of what it intended to issue. If internal records are inaccurate or an unauthorized person can change them, the matching result can be consistent with bad input. The business therefore needs appropriate separation of duties around payment creation, issue-file changes and exception decisions. Bank matching complements procurement and payment approval; it does not determine whether the underlying purchase was commercially legitimate.
For example, the same employee should not casually create a new supplier, authorize an unsupported invoice and resolve every related exception without independent oversight. This is a governance observation, not a claim that every bank contract mandates one exact role design. The suitable control depends on organization size, account permissions and other checks. The goal is to keep the expected-payment record tied to a valid business decision rather than treating it as an unquestionable source of truth.
Reconciliation remains necessary after matching. The business still needs to compare its ledger with bank activity, investigate unexpected debits and handle corrections. Positive pay operates at a particular check-payment control point. It does not replace controls over electronic transfers, ACH debits, card spending or deposited items. Wells Fargo's page presents ACH fraud filters separately from its check services, underscoring that different payment channels need different mechanisms. [3]
The economics are loss prevention plus operating discipline
Assume a hypothetical monthly service charge of $100, ten hours of staff work at $40 per hour and $50 of ancillary processing expense. Total monthly operating cost is $550, or $6,600 a year. If management estimates that the service and process reduce annual expected unrecovered losses from $12,000 to $4,000, the modeled loss reduction is $8,000 and the net annual benefit is $1,400. These invented inputs are a decision framework, not bank pricing or an empirical fraud-loss forecast.
Expected loss is uncertain and can be dominated by rare events. A year with no incidents does not prove the service was unnecessary, and one incident does not establish that it never works. Management should also measure false exceptions, decision timeliness, missing issue records and the cost of legitimate payments returned in error. These operating indicators can reveal deteriorating control quality before a sufficiently large loss sample exists to support statistical conclusions.
Liability and the limits of the promise
Liability depends on applicable law, the deposit and service agreements, the facts of the item and the parties' conduct. Enrollment should not be described as an insurance policy. Nor should declining a service be summarized as an automatic waiver of every legal protection. The specific agreement deserves review, particularly its decision deadlines, permitted reliance on customer instructions, reporting obligations and treatment of unavailable or inaccurate data.
The strongest practical claim is narrower: accurate issued-check information, the right matching features and timely informed decisions can help prevent certain unwanted check payments. The service remains a joint operational process. A business that knows which fields are checked, confirms file acceptance and staffs exception review has purchased a usable control. A business that merely recognizes the product name has not yet established that the control is operating as intended.
Sources
- OCC, Check Fraud: A Guide to Avoiding Losses; historical background, not present-day service termsOfficial source · PDFBack to text: ↑
- Chase Digital Services Agreement; last updated June 2026, Fraud Protection Services addendum, Positive Pay and Reverse Positive Pay sectionsSource · PDFBack to text: ↑1↑2↑3
- Wells Fargo, Payments Fraud; check and ACH service distinctions checked October 4, 2026SourceBack to text: ↑1↑2
- Chase Connect, Getting started with Check Fraud Protection Services and ACH Debit Block; First Republic-transition enrollment guidance, payee-name verification on PDF page 4Source · PDFBack to text: ↑