Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Users warrant that any wire instruction submitted through the account in compliance with Mercury's security procedures is effective and binding, even if the actual sender is not the authorized user and even if the account holder did not authorize the specific wire instruction. This provision assigns the risk of unauthorized wire instructions to the user provided the security procedures were technically complied with.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that compliance with security procedures is treated as conclusive authorization for wire instructions, irrespective of whether the account holder actually authorized the specific transfer. This places the risk of social engineering, credential theft, or insider fraud on the account holder rather than on Mercury or its wire services providers, for commercial accounts not subject to Regulation E.
Mercury's updated terms establish detailed rules for how recurring autopay works on invoices. Under the revised language, payers authorize recurring ACH debits through a separate addendum, Mercury will not retry failed payments (except once if caused by a Mercury system issue), and autopay authorization will automatically cancel after two consecutive failures in a series. You can prevent autopay cancellation by ensuring payers have sufficient funds, re-enrolling the payer, or requesting manual payment if the series fails twice.
View change record →The updated terms establish that when customers pay invoices you issue through Mercury Invoicing via ACH debit, Mercury will apply a hold period before crediting the funds to your account. The hold period is determined by Mercury in its sole discretion based on risk factors related to the transaction, payer, and payment history, and may range from 1 to 4 business days from the date the ACH debit is initiated. Mercury will display an estimated funds availability date for each incoming invoice payment in your Invoicing dashboard.
View change record →Under this clause, wire instructions submitted through a Mercury account in compliance with security procedures are deemed effective and binding regardless of whether the actual account holder authorized them, with the authorization warranty provided by the user. Consumer accounts subject to Regulation E may have additional statutory error resolution protections that interact with this provision.
Cross-platform context
See how other platforms handle Security Procedures and Wire Instruction Authorization and similar clauses.
Compare across platforms →Monitoring
Mercury has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"You warrant to us and the International Wire Services Providers that (a) your Administrators and Users are authorized to originate and/or approve Wire Instructions, and (b) any Wire Instructions communicated to us through your Account in compliance with the Security Procedures are effective and binding, irrespective of the actual identity of the sender or whether you authorized the Wire Instructions.Excerpt from Mercury's Terms of Service
1) REGULATORY LANDSCAPE: For consumer accounts, Regulation E provides error resolution rights for unauthorized electronic fund transfers that may supersede this contractual warranty as acknowledged in Section 8 of the agreement. For commercial accounts, Article 4A of the California Uniform Commercial Code governs the enforceability of security procedure agreements and the allocation of loss for unauthorized payment orders, including provisions related to commercially reasonable security procedures. The agreement states that the security procedures represent a commercially reasonable method of providing security, which is a specific legal standard under Article 4A that affects loss allocation. 2) GOVERNANCE EXPOSURE: High. The provision that wire instructions are binding irrespective of actual identity or authorization, provided security procedures are followed, creates significant fraud exposure for commercial account holders. Business email compromise and wire fraud schemes that exploit technical compliance with security procedures while circumventing actual authorization are a recognized threat vector, and this clause allocates the resulting losses to the account holder. 3) JURISDICTION FLAGS: Commercial users in California are subject to Article 4A of the California Uniform Commercial Code, which governs the enforceability and loss allocation consequences of security procedure agreements. The agreement's characterization of its security procedures as commercially reasonable is a legal conclusion that may be subject to challenge under Article 4A if procedures are found inadequate in the context of a specific fraud event. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations processing international wire transfers through Mercury should assess whether Mercury's required security procedures, including multi-factor authentication and security key options, are sufficient to satisfy the commercially reasonable standard under Article 4A and to mitigate business email compromise risk. Organizations should document their implementation of all available security controls, including those referenced in the agreement such as security keys. 5) COMPLIANCE CONSIDERATIONS: Treasury and information security teams should review Mercury's security procedure requirements and implement all available authentication controls, including security keys as referenced in Section 1.3. Organizations should establish internal dual-approval requirements for wire instructions that exceed defined thresholds, as internal controls independent of Mercury's platform security procedures provide an additional layer of fraud mitigation.
This provision establishes that compliance with security procedures is treated as conclusive authorization for wire instructions, irrespective of whether the account holder actually authorized the specific transfer. This places the risk of social engineering, credential theft, or insider fraud on the account holder rather than on Mercury or its wire services providers, for commercial accounts not subject to Regulation E.
Under this clause, wire instructions submitted through a Mercury account in compliance with security procedures are deemed effective and binding regardless of whether the actual account holder authorized them, with the authorization warranty provided by the user. Consumer accounts subject to Regulation E may have additional statutory error resolution protections that interact with this provision.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.