Facts
- A plumbing and heating company employed an IT contractor who later became its comptroller and received access to the company’s computer systems and bank-account information.
- The comptroller allegedly initiated unauthorized ACH debits from the company’s bank accounts to pay down his personal credit-card balance at the same bank.
- The company claimed only its principals were authorized to direct ACH payments and that the comptroller’s access was limited to monitoring accounts.
- The alleged unauthorized transfers began in 2008, continued after the comptroller’s termination, and were discovered months later.
- The company sued, asserting (among other claims) that the bank, as the originating depository financial institution (ODFI), breached NACHA-related authorization warranties and acted negligently by processing the debits.
Issues
- Whether a commercial account holder whose account was debited is an intended third-party beneficiary who may sue an ODFI directly for breach of NACHA operating-rule warranties.
- Whether the pleadings stated a Pennsylvania negligence claim against the ODFI for failing to prevent or detect unauthorized ACH debits initiated by the customer’s employee.
- Whether the UCC Article 4A/NACHA framework displaces or limits common-law claims that would impose duties beyond the ACH allocation of rights and remedies.
Decision
- The court granted the bank’s Rule 12(b)(6) motion and dismissed the NACHA-based breach-of-warranty claim.
- The court held the plaintiffs were not intended third-party beneficiaries of NACHA interbank warranties; any benefit to account holders was incidental.
- The court dismissed the negligence claim for failure to plead a cognizable duty owed by the ODFI to the debited account holder in this setting.
- The challenged counts against the bank were dismissed; the case continued as to other defendants and claims.
Legal Principles
- NACHA operating rules function as contracts among participating financial institutions; ODFI warranties run to other network participants (e.g., RDFIs and operators), not to customers absent clear intent to confer enforceable rights.
- Under Pennsylvania third-party beneficiary doctrine, incidental benefits from an interbank contractual framework do not confer standing to sue for breach.
- Negligence requires a legally recognized duty; in ACH disputes governed by UCC Article 4A and NACHA rules, courts are reluctant to impose extra-contractual duties on banks that would alter the scheme’s risk allocation.
- Where a comprehensive statutory/contractual regime governs electronic funds transfers, common-law theories that effectively add remedies or obligations inconsistent with that regime may be unavailable.
Conclusion
The court dismissed claims against the bank because NACHA authorization warranties were enforceable only within the ACH interbank framework and the plaintiffs failed to plead an independent common-law duty supporting negligence for employee-initiated unauthorized ACH debits.