Mercury · Mercury Terms of Service · View original document ↗

Security Procedures and Wire Instruction Authorization

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Mercury changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mercury recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Mercury Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Users warrant that any wire instruction submitted through the account in compliance with Mercury's security procedures is effective and binding, even if the actual sender is not the authorized user and even if the account holder did not authorize the specific wire instruction. This provision assigns the risk of unauthorized wire instructions to the user provided the security procedures were technically complied with.

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that compliance with security procedures is treated as conclusive authorization for wire instructions, irrespective of whether the account holder actually authorized the specific transfer. This places the risk of social engineering, credential theft, or insider fraud on the account holder rather than on Mercury or its wire services providers, for commercial accounts not subject to Regulation E.

Recent Activity

This document changed recently

Medium Jun 26, 2026

Mercury's updated terms establish detailed rules for how recurring autopay works on invoices. Under the revised language, payers authorize recurring ACH debits through a separate addendum, Mercury will not retry failed payments (except once if caused by a Mercury system issue), and autopay authorization will automatically cancel after two consecutive failures in a series. You can prevent autopay cancellation by ensuring payers have sufficient funds, re-enrolling the payer, or requesting manual payment if the series fails twice.

View change record →
Medium May 29, 2026

The updated terms establish that when customers pay invoices you issue through Mercury Invoicing via ACH debit, Mercury will apply a hold period before crediting the funds to your account. The hold period is determined by Mercury in its sole discretion based on risk factors related to the transaction, payer, and payment history, and may range from 1 to 4 business days from the date the ACH debit is initiated. Mercury will display an estimated funds availability date for each incoming invoice payment in your Invoicing dashboard.

View change record →

Consumer impact (what this means for users)

Under this clause, wire instructions submitted through a Mercury account in compliance with security procedures are deemed effective and binding regardless of whether the actual account holder authorized them, with the authorization warranty provided by the user. Consumer accounts subject to Regulation E may have additional statutory error resolution protections that interact with this provision.

Cross-platform context

See how other platforms handle Security Procedures and Wire Instruction Authorization and similar clauses.

Compare across platforms →

Monitoring

Mercury has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You warrant to us and the International Wire Services Providers that (a) your Administrators and Users are authorized to originate and/or approve Wire Instructions, and (b) any Wire Instructions communicated to us through your Account in compliance with the Security Procedures are effective and binding, irrespective of the actual identity of the sender or whether you authorized the Wire Instructions.

Excerpt from Mercury's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: For consumer accounts, Regulation E provides error resolution rights for unauthorized electronic fund transfers that may supersede this contractual warranty as acknowledged in Section 8 of the agreement. For commercial accounts, Article 4A of the California Uniform Commercial Code governs the enforceability of security procedure agreements and the allocation of loss for unauthorized payment orders, including provisions related to commercially reasonable security procedures. The agreement states that the security procedures represent a commercially reasonable method of providing security, which is a specific legal standard under Article 4A that affects loss allocation. 2) GOVERNANCE EXPOSURE: High. The provision that wire instructions are binding irrespective of actual identity or authorization, provided security procedures are followed, creates significant fraud exposure for commercial account holders. Business email compromise and wire fraud schemes that exploit technical compliance with security procedures while circumventing actual authorization are a recognized threat vector, and this clause allocates the resulting losses to the account holder. 3) JURISDICTION FLAGS: Commercial users in California are subject to Article 4A of the California Uniform Commercial Code, which governs the enforceability and loss allocation consequences of security procedure agreements. The agreement's characterization of its security procedures as commercially reasonable is a legal conclusion that may be subject to challenge under Article 4A if procedures are found inadequate in the context of a specific fraud event. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations processing international wire transfers through Mercury should assess whether Mercury's required security procedures, including multi-factor authentication and security key options, are sufficient to satisfy the commercially reasonable standard under Article 4A and to mitigate business email compromise risk. Organizations should document their implementation of all available security controls, including those referenced in the agreement such as security keys. 5) COMPLIANCE CONSIDERATIONS: Treasury and information security teams should review Mercury's security procedure requirements and implement all available authentication controls, including security keys as referenced in Section 1.3. Organizations should establish internal dual-approval requirements for wire instructions that exceed defined thresholds, as internal controls independent of Mercury's platform security procedures provide an additional layer of fraud mitigation.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • CFPB
    The CFPB has authority over unauthorized electronic fund transfer protections under Regulation E for consumer accounts, which the agreement acknowledges supersedes inconsistent terms for consumer wire transfers.
    File a complaint →

Provision details

Document information
Document
Mercury Terms of Service
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014142
Document ID
CA-D-00529
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3ac7ab54812d292da7660282e68a275955e77d625774ffe806d425e9b70bcc72
Analysis generated
July 9, 2026 04:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Terms of Service
Record ID: CA-P-014142
Captured: 2026-07-09 04:51:50 UTC
SHA-256: 3ac7ab54812d292d…
URL: https://conductatlas.com/platform/mercury/mercury-terms-of-service/provision/CA-P-014142/security-procedures-and-wire-instruction-authorization/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Mercury's Security Procedures and Wire Instruction Authorization clause do?

This provision establishes that compliance with security procedures is treated as conclusive authorization for wire instructions, irrespective of whether the account holder actually authorized the specific transfer. This places the risk of social engineering, credential theft, or insider fraud on the account holder rather than on Mercury or its wire services providers, for commercial accounts not subject to Regulation E.

How does this clause affect you?

Under this clause, wire instructions submitted through a Mercury account in compliance with security procedures are deemed effective and binding regardless of whether the actual account holder authorized them, with the authorization warranty provided by the user. Consumer accounts subject to Regulation E may have additional statutory error resolution protections that interact with this provision.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.