What the service does, how the four variants differ, and where the liability sits when a fraudulent check gets paid. Convert your bank statement here and paid check numbers, dates, and amounts come back in columns, which is how you prove the checks your bank paid match the file you sent. Start free, no credit card.
Upload your bank statement
Drop file here or click to upload
PDF, JPG, PNG, BMP, HEIC, TIFF, MT940
Uploading...
Positive pay is a bank fraud control for business accounts. You send your bank a list of the checks you issued, and when a check is presented the bank compares the account number, serial number, amount, and date against that list. Matching items pay normally. Anything that does not match becomes an exception you have to pay or return, usually by a cutoff the same business day. Three variants exist alongside it: payee positive pay also reads the payee name off the check image, reverse positive pay sends you a daily list of presented checks to review instead of matching against a file you sent, and ACH positive pay does the same job for incoming ACH debits rather than checks. Banks price it as a treasury service, commonly in the range of $25 to $100 a month depending on the bank and account volume. Last updated August 2026.
Checks are the most attacked payment method US businesses use, and most of them are not going away.
In the 2026 AFP Payments Fraud and Control Survey, 76 percent of organizations reported attempted or actual payments fraud during 2025, and 58 percent said checks were subject to fraud. Nothing else in the payment mix attracts that share of attempts.
The same survey found 72 percent of organizations that write checks intend to keep writing them, and 68 percent pointed to vendor requirements as the reason. You cannot fix the exposure by switching everything to ACH, because the counterparty controls that choice.
When an item does not match, the bank posts an exception with a cutoff that is often mid morning the next business day. Miss it and the default decision in your service agreement applies, which at many banks means the item pays.
Positive pay only works if a person opens the exception queue every business day. On reverse positive pay that duty is heavier, because the entire presented check list is yours to review rather than a short list the bank pre filtered.
The Uniform Commercial Code allocates check fraud loss using an ordinary care standard, and UCC 4-406 expects a customer to examine statements and report unauthorized items promptly. Declining an offered fraud control, or enrolling and then not reviewing, weakens the position badly.
To confirm the bank actually paid what you issued, you need paid check numbers and amounts you can sort and join against your issue file. A statement PDF read line by line is not that.
The paid side of the control. The issue file comes from your accounting system, and the exception queue lives at your bank. This is the verification layer between them.
Every check the bank actually paid comes back with its date, check number, description, amount, and the running balance, so the paid side of positive pay stops being a document you read by eye.
Serial numbers arrive as a real field rather than text buried inside a description string, which is what makes a lookup against your issued check list actually work.
When the bank flags a check you cannot place, you need to know whether that serial cleared before, whether the amount drifted, and what else posted that day. On a cutoff clock, that has to be a filter, not a search through pages.
Two checks paid on one serial number is a standard exception reason. Sorting a converted year of statements by check number surfaces the reuse in seconds.
An .xlsx workbook for the working paper, or a CSV you can reshape into whatever column order your bank spec asks for.
Nothing connects to your bank or your treasury portal. You upload a statement you already have and download a spreadsheet.
The cycle repeats every check run, and the timing is what most programs get wrong.
Send the bank your issued check list the same day you print checks: serial number, issue date, amount, account, and payee name if you are on payee positive pay. A check that clears before its issue record reaches the bank becomes a false exception.
Tip: Upload voids too, so cancelled items drop off the outstanding list.
Each business day the bank posts items that did not match, with a check image and a reason. Decide pay or return on each one before the cutoff, which is frequently around mid morning. Know what your agreement does when nobody responds.
Tip: Name a backup reviewer. Vacations are when defaults get applied.
After the month closes, convert the bank statement here and match paid serial numbers and amounts against the issue files you uploaded. Anything paid that you never issued, or issued at a different amount, is something the control should have caught.
Tip: Run this monthly, not only when an exception appears.
Finance teams at US businesses that still write checks, which is most of them.
Choose the variant, sign the service agreement, and answer for any exception that paid by default because nobody decided in time.
Upload an issue file after every check run and work the exception queue each morning, which is the part that quietly stops happening when the team is short staffed.
Run the control for clients whose accounting system will not produce a bank ready file, which means building it in a spreadsheet each time.
Test whether the issued check list actually agrees to the checks that cleared, which requires paid check data in a form you can join on.
Positive pay is a fraud control your bank sells as a treasury service. You transmit a list of every check your business has issued, and the bank holds each presented check against that list before paying it. When the account number, check serial number, amount, and date all agree, the check pays with no involvement from you. When any of them disagree, or the check is not on the list at all, the bank stops it and posts an exception for you to decide.
The word positive refers to affirmatively identifying the items you authorized, rather than trying to spot bad ones after the fact. That is the whole design: the bank does not have to judge whether a check looks forged, because it only has to check whether it appears on a list you already sent.
The cycle has four steps and repeats with every check run. You issue checks and export the issued check list. You upload that file to the bank, ideally the same day the checks leave the building. Checks get presented over the following days and the bank matches each one. Anything that fails the match lands in an exception queue with a check image and a reason code, and you pay or return it before the daily cutoff.
The timing detail that causes most false exceptions is upload lag. A check handed to a vendor on Monday can be deposited and presented on Tuesday. If your issue file does not reach the bank until Wednesday, a perfectly legitimate check shows up as paid no issue and somebody has to research it under time pressure. Uploading on the same day as the check run removes most of that noise.
Four services get sold under the positive pay heading, and they protect against different things. Banks do not use identical names for them, so match on the description rather than the label when you read a proposal.
| Variant | What it compares | Who reviews | Relative cost |
|---|---|---|---|
| Check positive pay | Account number, serial number, amount, and date on each presented check against your issue file. | Bank matches first, you decide only on exceptions. | Standard |
| Payee positive pay | Everything above, plus the payee name read off the check image. | Bank matches first, you decide only on exceptions. | Higher |
| Reverse positive pay | Nothing. You send no file. The bank sends you a daily list of every check presented. | You review the full list every business day. | Lower, sometimes free |
| ACH positive pay | Incoming ACH debits against a list of originators you authorized to pull from the account. | You decide on debits from parties not on the list. | Separate service |
The distinction people miss most often is the direction of travel. Check and payee positive pay protect money leaving your account by check. ACH positive pay protects money being pulled from your account electronically by somebody else, which is a completely different attack. Enrolling in one does nothing for the other, and a business that writes checks and also publishes its account and routing number on invoices is exposed on both sides.
The difference is who does the matching, and it decides where the work and the risk sit. With standard positive pay the bank compares every presented check against the file you sent, so you only ever see the small number of items that failed. With reverse positive pay you send nothing, the bank posts the full list of presented checks each morning, and you compare that list against your own records.
Reverse costs less and some banks include it at no charge, which is why it appears in small business packages. It also protects less, for a mundane reason: it depends entirely on somebody opening that list every single business day and recognizing an item that does not belong. Skip a day, or review it quickly during a busy close, and a fraudulent check pays on schedule. If your bank offers both and you write more than a handful of checks a month, the file based version is the one that survives a bad week.
An exception is any presented check the bank could not match cleanly. The reason codes vary by bank, but the underlying causes are consistent, and roughly half of what lands in a typical queue is your own housekeeping rather than fraud.
| Exception | What it usually means |
|---|---|
| Paid no issue | A check was presented that is not in your file at all. Either counterfeit, or a legitimate check run that was never uploaded. Check your own upload history before assuming fraud. |
| Amount mismatch | The serial number is on the list but the amount differs. An altered check, or a hand written check the ledger recorded at a different figure. |
| Duplicate presentment | The same serial number came through twice. Often a reused check number after a printer jam, sometimes a genuine duplicate deposit. |
| Payee mismatch | Only on payee positive pay. The name read off the image does not match your file. Frequently a truncation or punctuation difference rather than an altered payee. |
| Stale dated | The check is older than the staleness window on the account, commonly six months. Usually genuine, just very late. |
| Void or stop match | A check you cancelled was presented anyway. Worth investigating regardless of the amount. |
The reason codes your bank prints alongside these are covered in more detail in the guide to positive pay exception codes. Building the upload itself, including the field layouts and the Excel formatting traps that get a batch rejected, is the subject of the positive pay file format reference.
Banks price it as a treasury management service rather than publishing a rate card, so the number in your proposal depends on the bank, the number of accounts enrolled, and your check volume. The range quoted most often for check positive pay at US banks is roughly $25 to $100 per month per account, with payee matching priced above plain check matching and reverse positive pay below it or bundled free into a small business package. Per item fees on top of the monthly charge are common.
Weigh it against a single loss rather than against the monthly line. A business that writes checks in the thousands of dollars recovers a year of the fee on one blocked item, and the AFP survey notes organizations reporting fraudulent checks above $100,000 stopped by the control before funds moved. The harder cost is operational: somebody has to work the queue daily, and that duty is what actually determines whether the service protects anything.
Under the Uniform Commercial Code, check fraud loss is allocated using an ordinary care standard applied to both the bank and the account holder. UCC 4-406 expects a customer to examine bank statements with reasonable promptness and report unauthorized items, and 4-406(e) allows the loss to be split when both sides fell short. Deposit agreements at most US banks then narrow the practical window further, frequently to 30 or 60 days from the statement date.
Positive pay sits inside that framework in a specific way. Being offered a fraud control and declining it, or enrolling and then leaving exceptions to default, is exactly the fact pattern a bank raises when arguing the customer failed to exercise ordinary care. That is why the daily review discipline matters beyond the fraud it catches, and why keeping evidence that you reconciled paid checks against issued checks is worth the effort. This is not legal advice, and the outcome turns on your state's version of the UCC and the deposit agreement you signed.
The control tells you about items the bank stopped. It does not tell you whether the items it paid were right. That check is on you, and it is a monthly reconciliation rather than a daily one.
The mechanics are simple once the data is in columns. Convert the statement so paid checks arrive with their serial number, date, and amount as separate fields, put your issued check list beside it, and join on serial number. Three things fall out: serials paid that you never issued, serials paid at an amount different from what you issued, and serials still outstanding past their staleness window. The running balance extraction page covers keeping check numbers and balances in their own columns, and bank statement reconciliation covers tying the whole month back to the ledger. For teams whose real problem is that approving and paying invoices is manual before a check is ever printed, accounts payable automation sits a layer above this.
Most businesses that enroll in check positive pay have far more money moving by ACH than by check, and the fraud controls there work differently. ACH positive pay screens inbound debits against an authorization list. On the outbound side, the file you originate follows the NACHA format, and the checks that matter are structural rather than fraud related: control totals, entry hashes, and effective dates. The NACHA file format reference covers the layout, the NACHA file validator checks a file before your bank sees it, and ACH return codes explains what comes back when an entry fails after settlement.
One naming trap is worth flagging. ACH positive pay, ACH debit block, and ACH debit filter are related but not identical. A block refuses all debits on the account. A filter permits only listed originators. ACH positive pay adds a review queue so unlisted debits come to you rather than being refused outright. Ask which one a proposal actually means, because the operational difference is whether a legitimate new vendor gets paid or bounced.
Positive pay is a bank fraud control for business accounts. You send the bank a list of checks you issued, and the bank compares every presented check against it before paying. Matching items clear normally. Items that do not match become exceptions you must pay or return, usually by a cutoff the same business day.
It is a treasury management service banks sell to business customers, not a feature of a consumer account. The bank matches presented checks against your issued check file and refers mismatches back to you. Banks also sell related variants covering payee names and incoming ACH debits.
You upload an issued check file after each check run containing the serial number, issue date, amount, and account. When a check is presented, the bank compares those fields. If they all agree it pays. If any disagree, or the check is absent from your file, the bank holds it and posts an exception with a check image for your decision.
With positive pay you send the bank an issue file in advance and the bank does the matching, so you only see exceptions. With reverse positive pay you send nothing and the bank sends you a daily list of all presented checks to review yourself. Reverse costs less and protects less, because it depends on somebody reviewing that list every business day.
ACH positive pay screens incoming ACH debits against a list of originators you authorized to pull funds from your account. Debits from anyone not on that list come to you for a pay or return decision. It protects the opposite direction from check positive pay, which covers checks leaving your account.
Payee positive pay adds one comparison to standard check positive pay: the bank reads the payee name off the check image and matches it against the payee in your file. It is the version that catches an altered payee name on an otherwise legitimate check, and it makes the payee field mandatory in your upload.
Banks price it per account as a treasury service rather than publishing rates. The range quoted most often for check positive pay at US banks is about $25 to $100 per month per account, often with per item fees on top. Payee matching costs more, and reverse positive pay costs less or is bundled free into small business packages.
Your service agreement contains a default decision that applies when nobody responds by the cutoff. At many banks the default is to pay the item, which means an unreviewed fraudulent check clears. Check what your specific agreement says and name a backup reviewer, because vacations and month end closes are when defaults get applied.
If you write checks regularly, generally yes. The 2026 AFP survey found 58 percent of organizations reported checks subject to fraud, and a single blocked item usually covers more than a year of the fee. The real cost is the daily review duty, so only enroll if somebody will actually work the exception queue.
No to both, and it is worth being clear about that. Positive pay is a service only your bank can provide, and the issue file comes from your accounting system because only that system knows what you wrote. What the converter does is the verification side: it turns your bank statement into spreadsheet rows with check numbers, dates, and amounts so you can prove the checks the bank paid match the file you sent.
The field layouts banks want in the upload itself.
The ACH equivalent, and it does have a national standard.
Check an ACH file before your bank sees it.
Keep check numbers and balances in their own columns.
Test issued checks against checks that cleared.
Cancel anytime from your account settings · refund policy
Get started converting bank statements to spreadsheets.
USD
per month
billed as
$288 yearly
Choose speed vs accuracy when extracting
| Base AI Faster | 2,500 pages |
| Pro AI Best accuracy | 500 pages |
Scale statement conversion across your team with automation.
USD
per month
billed as
$888 yearly
Choose speed vs accuracy when extracting
| Base AI Faster | 10,000 pages |
| Pro AI Best accuracy | 2,000 pages |
Enterprise-grade bank statement conversion and controls.
USD
per month
billed as
$ yearly
Choose speed vs accuracy when extracting
| Base AI Faster | pages |
| Pro AI Best accuracy | pages |