The Platform PM
Primitive 10

Liability allocation

When it fails, who pays?

Every failure comes with a bill, and laws, network rules and contracts decide who gets it. Liability shapes pricing, risk appetite and which features a company is willing to build.

What it is

Liability allocation is the set of rules that decides who absorbs the cost when something goes wrong: the customer, the platform, a network or an insurer. It is set by law, by network rules and by contracts, and it often shifts depending on what each party did or didn't do.

Follow the liability and you'll understand why a company says yes to some features and no to others.

Where you'll see it

IndustryWho pays when it fails
PaymentsFraud liability shifts to the card issuer when a payment was properly authenticated
TelcoFines for non-compliant messages; who pays for fraudulent traffic
HealthcareWho absorbs a denied claim or a billing error
PayrollPenalties for late or wrong tax filings
SaaSService credits when uptime targets are missed

Questions to ask in week one

  1. For each major failure, who pays today?
  2. What would shift that cost to someone else?
  3. Where do our contracts cap liability, or pass it through?
  4. Which failures are insured, and which come straight out of margin?
  5. What has the company paid for before, and what changed afterwards?

The trap

Treating liability as a legal footnote. Liability sets the decision culture: the more a failure costs, the slower and more careful every team around it becomes. Know why before you try to speed them up.

In the Field Guides

B2B payments: order to cash

Two rules of thumb. On payments, loss follows initiation: the payer usually eats a bad push, the seller a bad pull. On credit, the seller eats the loss unless it moved it beforehand, to an insurer, a factor, a guarantor or a secured position.

FailureWho absorbs itMechanism
Payer tricked into paying a fraudster (BEC)The payer, if its bank followed the agreed security procedureUCC 4A-202; Studco v. 1st Advantage (4th Cir., 2025)
The seller's invoice in that caseStill legally unpaid, unless contract says otherwiseIn practice a negotiation
Unauthorized ACH debit from a business accountThe sellerThe originating bank warrants the authorization; the seller indemnifies it
Card-absent fraudThe seller, unless authenticated (3-D Secure) or covered by Visa's compelling-evidence rulesNetwork rules
Returned check, Canadian business PAD claim, surcharge violationThe sellerProvisional credit reversed; debited back; fines through the acquirer
Customer can't payThe seller, unless insured or sold without recourseInsurers cover up to 90% (EDC) or 90% to 95% (EXIM); the seller keeps the rest, losses above the limit and the waiting period
Invalid deductionThe seller, unless it proves otherwise in timeThe payer already holds the cash
Preference claw-backThe seller returns the cash unless a defense applies11 U.S.C. 547
Payer pays the seller after notice that the invoice was soldThe payer still owes the factorUCC 9-406

Sources: UCC 4A-202 and 9-406, Holland & Knight (April 2025), EDC (December 2025), EXIM.

Nacha's 2026 fraud rules leave UCC 4A unchanged; the buyer's controls are in procure to pay. When a payer is tricked into paying a fraudster, the law puts the loss on the payer, the invoice stays open, and your seller is left with a customer who believes it already paid.

Ask an expert: how is that open invoice resolved in practice (seller absorbs, payer repays, split), and when you prove a deduction invalid, how often does cash come back rather than an offset?

B2B payments: procure to pay

In US business payments the sender carries a bad push, and AP sends almost only pushes.

FailureWho absorbs itMechanism
Buyer pays a fraudster after a fake bank changeThe buyerUCC 4A-202: if the bank followed the agreed security procedure, the order binds the customer. 4A-207: the receiving bank may rely on the account number
The real supplier's invoiceStill owed by the buyerPay again, or negotiate
Altered or counterfeit checkBanks, under UCC 3 and 4 warranties; the buyer if it declined Positive Pay or missed a cut-offDeposit agreement
Duplicate paymentThe buyer, until recoveredSupplier credit balance; recovery-audit fees
Late paymentThe buyerContract fees or interest; Prompt Payment interest for US federal buyers; lost discounts
Missing or wrong TINThe buyer as payer24% backup withholding duty; IRS notices
Invalid GST/HST numberThe buyerInput tax credit at risk
A payment hub fails while holding fundsBuyer and supplier, depending on safeguardingState permissible-investment rules; RPAA safeguarding

Sources: UCC 4A-202 and 4A-207 (Cornell LII), IRS, CRA. Positive Pay loss-shifting is bank-agreement practice, not statute.

Courts reinforce it. In Studco v. 1st Advantage (4th Cir., 2025) the receiving bank wasn't liable for a name and account mismatch without an employee's actual knowledge. Nacha's 2026 rules expressly leave UCC 4A unchanged, and the US has no push-fraud reimbursement scheme like the UK's. Recovery is thin: in AFP's 2025 survey (2024 data), 22% of victims recovered more than 75% of lost funds and 20% recovered nothing. When a hub "guarantees" supplier payment, what that covers is a contract question.

The buyer pays for a bad push, so the cheap protection sits before release: verify the change, hold new details, require two people.

Ask an expert: does crime or social-engineering insurance typically cover vendor-impersonation losses, and at what sub-limits?

B2B payments: spend management

Strangers' fraud has a legal cap and a dispute process; your own people's misuse has neither.

FailureWho absorbs itMechanism
Stolen card, third-party fraud (credit or charge)The merchant if the dispute is won; else the company, or an individually liable employee up to $50Reg Z; at 10+ cards the contract decides
Same, on a prepaid or business debit cardThe company or the program managerNo Reg E; Visa's zero liability excludes Corporate and Purchasing
Employee misuseCompany, employee or both, by liability modelNot "unauthorized use": the employee had authority
Misuse by an employee who has leftNetwork misuse insurance, if the card was canceled in timeSee below
Business expense on an individual card, CaliforniaThe employerLabor Code 2802
Stand-in approvalThe issuer at network level, passed down by contractVisa Rules
Customer can't pay its charge balanceWhoever holds the receivable, often the fintech and its fundersParticipation agreements
Unsubstantiated charge never repaidThe employee, as wages; the employer owes payroll taxTreas. Reg. 1.62-2
Late reimbursementThe employerCalifornia interest and fees; New York misdemeanor
Purchase made by an AI agentThe cardholder, as if it had made itVisa rule on agentic payment providers

The waivers. Visa's US program covers misuse by employees who've left: up to $100,000 per cardholder at five or more cards ($5,000 at one to four), for charges billed up to 75 days before the termination notice or made up to 14 days after, if the card was canceled within two business days, and only one paid claim per person. Mastercard's covers $25,000 per cardholder at two to four cards and $100,000 at five or more, but not one-card companies, lost or stolen cards, or owners and shareholders above 5%. The Visa text I found dates from 2004 to 2007, though bank pages repeat its figures. In Canada, Visa requires misuse insurance of at least CAD 100,000 per cardholder.

Sources: Reg Z 1026.12 and interpretation, Visa Liability Waiver Program (copy hosted by the State of Alaska), Visa Rules, California 2802; Mastercard terms from a US bank's brochure.

The law caps what strangers can cost a company, not what its own employees can, and the waiver covers only leavers cut off within two days.

Ask an expert: on individual-liability programs, who really eats it when a leaver owes the issuer, and does the issuer have recourse to the company?

Telco: numbers and senders

The default answer to "who pays?" is the sender, then whoever has a contract with the sender.

FailureWho paysMechanism
Message blocked or filteredSenderBlocked messages can still be billed (stated explicitly for unverified toll-free)
Non-compliant contentCarrier fines the provider, which passes it down by contractT-Mobile's Sev-0 fines are reported at $500 to $2,000 per violation since 2024
SMS pumpingSender, for every messageFraudsters split termination revenue with a complicit operator; customers who switch off a provider's geographic protections carry the loss explicitly
TCPA violationSenderClass actions; the reassigned-number safe harbor covers only a caller who proves it checked
Miscategorized WhatsApp templateBusinessCharged at the category Meta applied at send time
RCS replies and fallbackPlatform as RCS partnerOwes carriers for billable events, including US replies and STOP taps; fallback SMS is its own cost
False attestation or RMD filingSigning providerToken revocation, RMD removal, a $10,000 base forfeiture for false RMD information
911 failureSharedThe NET 911 Act gives VoIP providers liability protection no less than local phone companies get; notice duties stay with the provider; terms push address accuracy onto customers
Port-out fraud on mobilesWireless carrierAuthentication, notification and lock duties

Sources: Meta pricing, Google US billing, TransNexus, 47 USC 615a, Hudson Cook; billing, fines and pumping terms from provider pages (secondary).

Every setting that relaxes a protection (geographic permissions, rate limits, consent checks) is also a decision about who absorbs the loss. Write the answer into the spec and the contract.

Ask an expert: when SMS pumping or a carrier fine hits, how often does the platform absorb the cost to keep the customer, and how far does that drift from the contract?

Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.