When a Direct Deposit Goes to the Wrong Account,the Proof Decides Who Fixes It

A direct deposit that lands in the wrong account looks like a payroll failure from the outside. The employee did not get paid, rent is due, and the first call goes to whoever runs payroll. The more useful question is not who to blame. It is what record exists of how that account number entered the system. An Ernst & Young survey put the share of U.S. payrolls containing an error at one in five, with direct deposit errors running to 159 per 1,000 employees a year and a correction cost of about $45,000 per 1,000 employees. Most of that cost is reconstruction: hours spent working out what happened, often without a single document showing who submitted what.

Stop typing data by hand — let AI read it for you
Upload an image or PDF — structured spreadsheet data in 10 seconds
Try It Now →
Title 'Wrong Direct Deposit Account: Who Can Prove What Was Submitted?' with three icons below: Submission Recorded, Numbers Read Not Typed, Traceable to Source

Key Takeaways

  1. Payroll gets the first blame call when a deposit lands in the wrong account, even though the number was entered earlier in the chain.
  2. A prenote looks like a safeguard, but it only proves the account exists, never that it belongs to the employee.
  3. Capture the submitted voided check or bank letter, and the next dispute becomes a document lookup instead of a memory test.

A Wrong Account Number Is a Records Problem Before It Is a Kindness Problem

Comparison of reversal attempt with red X and $250 lost versus recorded submission with green check and proof traceable weeks later

The instinct when a check disappears is to fix it fast and absorb the cost, but the money is frequently gone before anyone notices. Under the NACHA Operating Rules, an ACH entry is irrevocable once it has been sent for processing. A reversal is permitted only for a narrow set of reasons, among them a wrong account number, and it must be sent within five banking days of the original entry and within 24 hours of discovering the error (Nacha). The receiving bank is under no obligation to return the funds if the account is overdrawn or closed, which is exactly the situation a wrong deposit creates.

That sequence is what payroll professionals describe in the moment. A thread on r/Payroll titled "I hate how payroll is the first to be blamed" is about that reflex rather than the money. A related r/Payroll discussion is blunter: a payroll administrator sent $250 to an account that was three digits off, tried to reverse it, and found the balance already spent, which left the question of a second payment open in the replies. One commenter summed up the whole problem: "Make sure they provide backup like voided check to avoid this. If you entered it wrong, you will be responsible. If they entered it wrong, there responsible."

The work that protects a payroll team is not reissuing a payment. It is being able to answer, weeks later, who submitted the account number and which document they submitted it on.

How a Bank Change Is Supposed to Work

Four-step flow: Employee Submits, HR Verifies, Employer Transmits, Bank Posts, with arrows between nodes

Most direct deposit mistakes trace back to a short sequence that passes through three hands. The employee submits new bank details, either on a paper authorization form or through a payroll portal. HR or payroll verifies the details and enters them into the payroll system. The employer, acting as the ACH originator, transmits a payment file to its bank, and the receiving bank posts the funds to the account number in that file. Nowhere in that sequence does a bank confirm that the account number belongs to the person named on it.

Two requirements sit underneath that flow. Most states require the employee's written consent before wages move electronically, and an unsigned authorization is not a valid ACH authorization. Nacha rules also place the burden of keeping that authorization on the originator, meaning the employer. The signed form is not paperwork for its own sake. It is the document that ties a specific employee to a specific instruction, and it is the first thing a dispute will ask for. If bank details move through the wider new-hire packet, our guide to pulling onboarding form data into an employee database covers that consolidation.

Where the Chain Loses Its Memory

List of 4 ways a wrong account number reaches payroll: Self-Service Typo, Transcription Error, Platform Migration, Split Deposit Error

There are four common ways a wrong account number reaches payroll, and three of them leave no trace of who was responsible.

  • Self-service typo. The employee enters the number in a portal and transposes two digits. The system records that an update happened, not what the employee intended.
  • Transcription. A paper form is keyed in by hand, often from a scan where the MICR line is faint. The person typing may be the only one who could have caught it, and they are also the one blamed.
  • Platform migration. The details were correct in the old system and were corrupted during a move to a new payroll platform or a bulk import.
  • Split deposit error. A percentage or fixed amount is assigned to the wrong account among several on file.

A prenote, the zero-dollar test entry some payroll systems run before the first live deposit, sounds like verification but is not. It confirms that the routing number and account number form a valid combination at some institution. It does not confirm that the account belongs to the employee. As one ACH practitioner put it in the same r/Payroll thread, a prenote "does not verify account holder information, just that the routing/ACH number and account number correspond to a valid account combination." A wrong number that belongs to someone else passes that test cleanly.

A prenote checks that the account exists. It does not check whose account it is, which is precisely the mistake that starts the dispute.

By the time an employee reports a missing deposit, the reversal window is often closed, and if the submission arrived as an emailed photo or a paper form that was keyed in and filed loose, no dependable record of the original exists. Accountability at that point becomes a memory test, and memory favors whoever speaks first.

Building a Submission You Can Point To Later

The fix separates two jobs that a payroll inbox normally does at the same time: receiving the employee's proof, and typing the numbers off it. A direct deposit verification workflow handles the first through a channel that records the submission, and the second by reading the document instead of retyping it.

A Collection Link is a shareable URL, generated from an ImageToTable.ai account, that lets someone upload documents directly into your processing queue without creating an account or logging in. The link is paired with a short verification code, so only people given both the link and the code can submit. In practice an HR team creates one link for bank verification, sends it to employees who are setting up or changing direct deposit, and each employee uploads a photo of a voided check, a bank letter, or a screenshot of the routing and account numbers from their banking app. What arrives is not an email that can be lost in a thread. It is a file in a single queue, and the submission itself is the record.

The second half is Custom Column Extraction. Rather than reading the uploaded image and keying the numbers in by hand, you type the column names you need, such as Employee Name, Bank Name, Routing Number, Account Number, and Account Type. The AI reads each uploaded document and returns a row per employee, locating each value by what it means rather than by a fixed spot on the page. The number that reaches payroll is the number printed on the document the employee submitted, and the document stays attached to the process. Both halves fit into a wider collection-to-extraction workflow if the same link also gathers other records.

1
Generate one link and code for bank verification. Create the link from your account and keep the verification code separate, so it can be shared only with the employees who need to submit.
2
Send the link to employees setting up or changing direct deposit. Ask for one of the accepted proofs: a voided check, a bank letter, or a bank app screenshot. The request is the same whether it is a new hire or a mid-year account change.
3
Let submissions land in one queue. Each upload arrives as a file tied to the collection rather than an attachment in someone's inbox, so the record survives the pay period in which it was created.
4
Define the columns once and process the batch. Name your columns, run the batch, and the routing and account numbers come off the submitted documents. Save the column set and reuse it for the next cycle.
JPG/PNG/PDF AI Extraction

Files are processed securely and not stored.

What Counts as Bank Verification Proof

Any captured artifact that shows the routing and account numbers, uploaded through a channel that records the submission, does the job. The paper form itself is not the point, since what payroll actually needs is a source the numbers can be traced to.

Form of proofWhat it showsWhere it fits
Voided checkRouting and account numbers in MICR format, plus the printed account holder nameThe traditional option; a clear photo works
Bank letter on letterheadThe bank's own written statement of the routing and account numbersUseful when the employee has no checkbook
Direct deposit form or banking app screenshotThe numbers as the bank itself displays themCommon for online-only banks
Micro-deposit or account-linking verificationConfirms the account exists and can receive fundsVerifies existence, not ownership in most cases

Nacha, the organization that governs the ACH network, has spent years retiring the assumption that a voided check is required. Its own HR team moved to a secure payroll portal and no longer collects paper checks at all, a change its HR director described publicly (Nacha). The lesson is not to demand a check. It is to make whatever proof an employee submits arrive through a channel that keeps a record of it. A bank letter or an app screenshot uploaded through the same link is worth more than a voided check that was photographed, entered, and then deleted from a phone.

For the extraction side used in payroll reviews, our guide to batch payslip extraction for HR audit covers pulling pay data at year end, and payroll register extraction handles the register itself.

What This Workflow Proves, and What It Does Not

Capturing a submission and extracting from the document solves the transcription and memory problems. It does not turn a collection link into an identity check, and the line is worth stating plainly.

  • Access is not identity. The verification code controls who can upload. It does not, on its own, prove the uploader is the employee. Share the code privately, and rotate it if it spreads further than intended.
  • Extraction reads, it does not validate. The AI reads the number printed on the document. It does not check the routing number checksum or confirm the account belongs to the named employee. For ownership, use a bank-side step such as micro-deposit confirmation or an account-linking service, or call the employee at a number already on file.
  • A typo and a diversion are different threats. A transposed digit is an accuracy problem, and the fix is capturing the source document. A fraudulent change is a security problem, and the fix is controls: multi-factor authentication, a callback to a known number, and an alert on any change to bank details. The FBI's Internet Crime Complaint Center has warned about payroll diversion fraud specifically.
  • No chasing built in. A collection link does not send reminders. If your process depends on following up with people who have not submitted, pair the link with your own follow-up.

Retention matters as much as capture. FLSA regulations require payroll records to be kept at least three years and the records used to compute wages at least two (29 CFR Part 516), while the IRS expects employment tax records to be kept for four years (IRS Publication 15). The signed ACH authorization carries its own expectation, held for as long as the employee uses direct deposit and for a period after. A submission record that is deleted at the end of the pay period is not a record at all.

The same document layer appears on the vendor side, where banking details and certificates of insurance have to be tied to a supplier record, as our guide to supplier onboarding document automation describes. Employees and vendors differ in where the liability lands, but both disputes turn on the same question of what was submitted and when.

Frequently Asked Questions

Is a voided check legally required to set up direct deposit?

No. Nacha has stated that a voided check is not required, and no state mandates one. What matters is an accurate routing and account number with a record of where it came from. A bank letter, a pre-filled direct deposit form, or a screenshot from the bank's app works, provided it is submitted through a channel that captures it.

Can a prenote catch a wrong bank account number?

Only if the number is not a valid account at any institution. A prenote confirms that the routing number and account number match a valid combination. It does not check the account holder's name, so a wrong number that belongs to someone else can pass. That gap is exactly how a wrong deposit becomes a dispute.

Can payroll reverse a direct deposit that went to the wrong account?

Sometimes, and only narrowly. Nacha permits a reversal for a wrong account number but requires it within five banking days of the original entry and within 24 hours of discovering the error. The receiving bank is not obligated to return the funds if the account is overdrawn or closed. Recovery is not something a payroll team should count on after payday.

Does this replace a bank account verification service?

No. Capturing the submitted document and extracting from it removes the transcription step and preserves the source. It does not confirm that the account belongs to the employee. For ownership, keep a bank-side check such as micro-deposit verification or an account-linking service, especially for any mid-year change to bank details.

How long should we keep the signed authorization and the bank proof?

Keep the signed authorization as long as the employee uses direct deposit and for a period after, which is the ACH originator's expectation. Federal rules separately require payroll records for at least three years and wage computation records for at least two, and the IRS expects employment tax records for four years. Retain the uploaded proof on the same schedule.

What if the employee does not have a checkbook?

Accept an alternative through the same link: a bank letter on letterhead, a pre-filled direct deposit form, or a screenshot of the routing and account numbers from the bank's app. The goal is a captured artifact with a timestamp, not a specific piece of paper. Online-only banks make the app screenshot the most practical option for many employees.

None of this makes a wrong account number impossible. It makes the argument about it short. When a deposit goes astray and the submission, the document, and the time it arrived all sit in one place, the conversation stops being about who to blame and becomes about what to correct. That record is the part a payroll team can build before payday instead of reconstructing after it.

📮 contact email: [email protected]