Liability allocation
When it fails, who pays?
Every failure comes with a bill, and laws, network rules and contracts decide who gets it. Liability shapes pricing, risk appetite and which features a company is willing to build.
What it is
Liability allocation is the set of rules that decides who absorbs the cost when something goes wrong: the customer, the platform, a network or an insurer. It is set by law, by network rules and by contracts, and it often shifts depending on what each party did or didn't do.
Follow the liability and you'll understand why a company says yes to some features and no to others.
Where you'll see it
| Industry | Who pays when it fails |
|---|---|
| Payments | Fraud liability shifts to the card issuer when a payment was properly authenticated |
| Telco | Fines for non-compliant messages; who pays for fraudulent traffic |
| Healthcare | Who absorbs a denied claim or a billing error |
| Payroll | Penalties for late or wrong tax filings |
| SaaS | Service credits when uptime targets are missed |
Questions to ask in week one
- For each major failure, who pays today?
- What would shift that cost to someone else?
- Where do our contracts cap liability, or pass it through?
- Which failures are insured, and which come straight out of margin?
- What has the company paid for before, and what changed afterwards?
The trap
Treating liability as a legal footnote. Liability sets the decision culture: the more a failure costs, the slower and more careful every team around it becomes. Know why before you try to speed them up.
In the Field Guides
B2B payments: order to cash
Two rules of thumb. On payments, loss follows initiation: the payer usually eats a bad push, the seller a bad pull. On credit, the seller eats the loss unless it moved it beforehand, to an insurer, a factor, a guarantor or a secured position.
| Failure | Who absorbs it | Mechanism |
|---|---|---|
| Payer tricked into paying a fraudster (BEC) | The payer, if its bank followed the agreed security procedure | UCC 4A-202; Studco v. 1st Advantage (4th Cir., 2025) |
| The seller's invoice in that case | Still legally unpaid, unless contract says otherwise | In practice a negotiation |
| Unauthorized ACH debit from a business account | The seller | The originating bank warrants the authorization; the seller indemnifies it |
| Card-absent fraud | The seller, unless authenticated (3-D Secure) or covered by Visa's compelling-evidence rules | Network rules |
| Returned check, Canadian business PAD claim, surcharge violation | The seller | Provisional credit reversed; debited back; fines through the acquirer |
| Customer can't pay | The seller, unless insured or sold without recourse | Insurers cover up to 90% (EDC) or 90% to 95% (EXIM); the seller keeps the rest, losses above the limit and the waiting period |
| Invalid deduction | The seller, unless it proves otherwise in time | The payer already holds the cash |
| Preference claw-back | The seller returns the cash unless a defense applies | 11 U.S.C. 547 |
| Payer pays the seller after notice that the invoice was sold | The payer still owes the factor | UCC 9-406 |
Sources: UCC 4A-202 and 9-406, Holland & Knight (April 2025), EDC (December 2025), EXIM.
Nacha's 2026 fraud rules leave UCC 4A unchanged; the buyer's controls are in procure to pay. When a payer is tricked into paying a fraudster, the law puts the loss on the payer, the invoice stays open, and your seller is left with a customer who believes it already paid.
Ask an expert: how is that open invoice resolved in practice (seller absorbs, payer repays, split), and when you prove a deduction invalid, how often does cash come back rather than an offset?
B2B payments: procure to pay
In US business payments the sender carries a bad push, and AP sends almost only pushes.
| Failure | Who absorbs it | Mechanism |
|---|---|---|
| Buyer pays a fraudster after a fake bank change | The buyer | UCC 4A-202: if the bank followed the agreed security procedure, the order binds the customer. 4A-207: the receiving bank may rely on the account number |
| The real supplier's invoice | Still owed by the buyer | Pay again, or negotiate |
| Altered or counterfeit check | Banks, under UCC 3 and 4 warranties; the buyer if it declined Positive Pay or missed a cut-off | Deposit agreement |
| Duplicate payment | The buyer, until recovered | Supplier credit balance; recovery-audit fees |
| Late payment | The buyer | Contract fees or interest; Prompt Payment interest for US federal buyers; lost discounts |
| Missing or wrong TIN | The buyer as payer | 24% backup withholding duty; IRS notices |
| Invalid GST/HST number | The buyer | Input tax credit at risk |
| A payment hub fails while holding funds | Buyer and supplier, depending on safeguarding | State permissible-investment rules; RPAA safeguarding |
Sources: UCC 4A-202 and 4A-207 (Cornell LII), IRS, CRA. Positive Pay loss-shifting is bank-agreement practice, not statute.
Courts reinforce it. In Studco v. 1st Advantage (4th Cir., 2025) the receiving bank wasn't liable for a name and account mismatch without an employee's actual knowledge. Nacha's 2026 rules expressly leave UCC 4A unchanged, and the US has no push-fraud reimbursement scheme like the UK's. Recovery is thin: in AFP's 2025 survey (2024 data), 22% of victims recovered more than 75% of lost funds and 20% recovered nothing. When a hub "guarantees" supplier payment, what that covers is a contract question.
The buyer pays for a bad push, so the cheap protection sits before release: verify the change, hold new details, require two people.
Ask an expert: does crime or social-engineering insurance typically cover vendor-impersonation losses, and at what sub-limits?
B2B payments: spend management
Strangers' fraud has a legal cap and a dispute process; your own people's misuse has neither.
| Failure | Who absorbs it | Mechanism |
|---|---|---|
| Stolen card, third-party fraud (credit or charge) | The merchant if the dispute is won; else the company, or an individually liable employee up to $50 | Reg Z; at 10+ cards the contract decides |
| Same, on a prepaid or business debit card | The company or the program manager | No Reg E; Visa's zero liability excludes Corporate and Purchasing |
| Employee misuse | Company, employee or both, by liability model | Not "unauthorized use": the employee had authority |
| Misuse by an employee who has left | Network misuse insurance, if the card was canceled in time | See below |
| Business expense on an individual card, California | The employer | Labor Code 2802 |
| Stand-in approval | The issuer at network level, passed down by contract | Visa Rules |
| Customer can't pay its charge balance | Whoever holds the receivable, often the fintech and its funders | Participation agreements |
| Unsubstantiated charge never repaid | The employee, as wages; the employer owes payroll tax | Treas. Reg. 1.62-2 |
| Late reimbursement | The employer | California interest and fees; New York misdemeanor |
| Purchase made by an AI agent | The cardholder, as if it had made it | Visa rule on agentic payment providers |
The waivers. Visa's US program covers misuse by employees who've left: up to $100,000 per cardholder at five or more cards ($5,000 at one to four), for charges billed up to 75 days before the termination notice or made up to 14 days after, if the card was canceled within two business days, and only one paid claim per person. Mastercard's covers $25,000 per cardholder at two to four cards and $100,000 at five or more, but not one-card companies, lost or stolen cards, or owners and shareholders above 5%. The Visa text I found dates from 2004 to 2007, though bank pages repeat its figures. In Canada, Visa requires misuse insurance of at least CAD 100,000 per cardholder.
Sources: Reg Z 1026.12 and interpretation, Visa Liability Waiver Program (copy hosted by the State of Alaska), Visa Rules, California 2802; Mastercard terms from a US bank's brochure.
The law caps what strangers can cost a company, not what its own employees can, and the waiver covers only leavers cut off within two days.
Ask an expert: on individual-liability programs, who really eats it when a leaver owes the issuer, and does the issuer have recourse to the company?
Telco: numbers and senders
The default answer to "who pays?" is the sender, then whoever has a contract with the sender.
| Failure | Who pays | Mechanism |
|---|---|---|
| Message blocked or filtered | Sender | Blocked messages can still be billed (stated explicitly for unverified toll-free) |
| Non-compliant content | Carrier fines the provider, which passes it down by contract | T-Mobile's Sev-0 fines are reported at $500 to $2,000 per violation since 2024 |
| SMS pumping | Sender, for every message | Fraudsters split termination revenue with a complicit operator; customers who switch off a provider's geographic protections carry the loss explicitly |
| TCPA violation | Sender | Class actions; the reassigned-number safe harbor covers only a caller who proves it checked |
| Miscategorized WhatsApp template | Business | Charged at the category Meta applied at send time |
| RCS replies and fallback | Platform as RCS partner | Owes carriers for billable events, including US replies and STOP taps; fallback SMS is its own cost |
| False attestation or RMD filing | Signing provider | Token revocation, RMD removal, a $10,000 base forfeiture for false RMD information |
| 911 failure | Shared | The NET 911 Act gives VoIP providers liability protection no less than local phone companies get; notice duties stay with the provider; terms push address accuracy onto customers |
| Port-out fraud on mobiles | Wireless carrier | Authentication, notification and lock duties |
Sources: Meta pricing, Google US billing, TransNexus, 47 USC 615a, Hudson Cook; billing, fines and pumping terms from provider pages (secondary).
Every setting that relaxes a protection (geographic permissions, rate limits, consent checks) is also a decision about who absorbs the loss. Write the answer into the spec and the contract.
Ask an expert: when SMS pumping or a carrier fine hits, how often does the platform absorb the cost to keep the customer, and how far does that drift from the contract?
Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.