Back to Glossary

Entry · Banking

Authorized Transaction

A payment or account transaction that the account holder has approved or that falls within authority they granted. The account holder is responsible for it under the account's terms. Everything outside that authority is unauthorized and treated very differently by consumer protection law.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

The line between authorized and unauthorized transactions decides who pays when something goes wrong. An authorized transaction is one the account holder initiated, approved, or empowered someone else to make, and everything else is unauthorized.

Consumer protection law treats the two categories very differently. Authorization comes in many forms.

Signing a receipt, entering a PIN, tapping a card, approving an app prompt, or giving a merchant standing permission to debit an account all create authorized transactions, and once given, the account holder generally bears the transaction, subject to billing-error rights. Digital wallets added a wrinkle, since biometric approval on a phone is itself strong evidence of authorization, making a wallet-confirmed purchase much harder to dispute than a magstripe swipe.

Regulation E in the United States draws the boundary for electronic fund transfers. An unauthorized transfer is one initiated by someone without authority and from which the consumer receives no benefit, and transfers by a person the account holder equipped with access, even if the person misuses it, are generally not unauthorized under the rule.

That definition produces the hard cases: a family member given a card who overspends is usually the account holder's problem, because the access itself was authorized, while a thief who skims the card is the bank's problem, subject to the consumer's prompt reporting, because the law protects against outsiders, not against misplaced trust. Reporting timelines allocate the losses.

Consumers who report unauthorized transfers quickly face limited liability tiers, and delays raise their exposure up to the point where some accounts and timeframes remove protection, while issuers must investigate reported errors within set periods and provisionally credit in many cases. Account holders should also treat access as authorization, since handing over credentials, one-time codes, or cards converts future misuse into authorized transactions under most terms, which is why banks warn that sharing codes defeats the protections entirely.

For businesses, authorization is a control design question. Every payment rail offers tools to keep transactions inside granted authority, such as dual approvals, spending limits, merchant category blocks, and positive pay for checks, and an authorized transaction made within sloppy controls is still the company's loss.

Corporate card programs turn the principle into policy, with spending rules that define which transactions are authorized by category and amount, so violations become discipline issues rather than fraud claims. For non-finance managers, the discipline is documentation.

Keep the approval trail for who may spend what, review statements promptly, and revoke access the day roles change, because disputes are won with records of what was authorized and what was not. The concept extends beyond cards to direct debits, standing instructions, and corporate payment approvals, all of which rest on documented authority that auditors test existed before the transaction occurred.

In practice

Real-world examples.

1

Example

A cardholder taps for groceries; the signed authorization record defeats a later "I never shopped there" claim. The merchant produces the terminal log showing a chip-and-contactless approval and the store camera footage. The issuer rejects the dispute because the cardholder's own device completed the payment.

2

Example

A consumer reports a skimmed card's ATM withdrawals within two days, limiting liability under Regulation E. The bank investigates and provisionally credits the account while it reviews the claim. The consumer receives a replacement card and keeps the money.

3

Example

A firm's dual-approval rule stops a wire that one compromised account tried to send alone. The payment sat in the queue waiting for a second approver, who noticed the beneficiary was new and rejected it. The firm's controls turned a potential loss into an incident report.

Formula

Calculation

This is liability logic, not a formula: if authority existed and the account holder benefited, the transaction is the holder's; if there was no authority and no benefit, it is unauthorized and protected. Example: a skimmed-card purchase reported within two days costs the holder at most a small statutory tier. Now apply it to a card statement of five transactions totalling $1,000. Three purchases by the holder come to $300, one purchase of $150 was made by an office manager who was given the card, and one purchase of $550 was made by a thief. The holder bears $300 + $150 = $450, because access was granted for the office manager's purchase. The $550 is unauthorized and protected, subject to prompt reporting.

Case study

Seen in the real world.

This is a fictional example. Miran gives his office manager a company card for supplies. She books a personal holiday on it, and the bank declines his unauthorized-use claim because he granted access. The company's recourse is against the employee, not the issuer, and Miran tightens card controls the same week.

The holiday cost $2,400. Miran recovers part through payroll deductions agreed with the employee and a settlement, and then sets a monthly limit of $500 on each card, blocks travel and entertainment merchant categories, and reviews statements every week. The authority he gave was real, so only better controls could have prevented the loss.

Watch out

Common mistakes.

  • Assuming any transaction you dislike is unauthorized, when misuse by someone you equipped with access is legally your responsibility. Authority, not approval of each purchase, is the test.
  • Sharing cards, PINs, or one-time codes, which converts theft into authorized use under most account terms. Access shared is protection surrendered.
  • Delaying reports of genuinely unauthorized activity, which raises liability tiers and can eliminate protection entirely. Statement review is a control, not a chore.

Questions

People also ask.

What makes a transaction unauthorized?

Under Regulation E, it must be initiated by someone without authority and give the account holder no benefit. Misuse by someone you granted access usually fails that test.

What should I do about an unauthorized charge?

Report it to the issuer immediately; federal rules cap liability in tiers based on how quickly you report, and issuers must investigate within set periods.

Can an authorized transaction still be disputed?

Yes, on other grounds such as wrong amount, non-delivery, or services not as described, through billing-error and chargeback processes separate from fraud claims.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.