The Exception Desk: Wire Callbacks | September 2026

The Exception Desk is a monthly look at one exception process banks still run by hand — what it is, how it actually gets handled today, and what it would take to make it digital. First up: the wire callback.
Every bank has a control that works exactly as designed and still loses money. The wire callback is the clearest example in the payment stack.
The design intent is sound. A payment order arrives through a channel that cannot authenticate the sender, so someone picks up the phone and confirms it out of band. What happens in practice is a manual queue staffed by people making identity judgments over a voice connection, against a clock set by the Federal Reserve, with the consequence of getting it wrong allocated by a statute written in 1989.
The exception is the gap between how a wire is authorized and how it is instructed
"Settlement of funds is immediate, final, and irrevocable," and individual payments can carry any value from $1 to $999,999,999.99. That is the FDIC's own description of the rail in its wire transfer examination module, updated October 2025. No chargeback, no dispute window, no clearing period in which a mistake surfaces on its own.
Against that finality, banks accept payment instructions through channels never built to prove who sent them: email, fax, scanned PDF, a call to a relationship manager, a walk-in at a branch. The same FDIC module asks examiners to document the "range of allowable customer wire transfer initiation channels" and the security procedures used for each — a polite way of noting that most institutions accept more channels than they can authenticate.
The callback closes that gap, and the module treats it as a first-class control, listing callbacks alongside "biometrics, dual controls, IP address registration" and instructing examiners to confirm that wire exception-processing procedures cover activity outside policy. So this is not an edge case the industry forgot to automate. It is a documented, examined, load-bearing control. It is just a manual one.
What actually happens, step by step
Triggers vary, but the common set maps to the configuration options the FDIC expects examiners to review: dollar thresholds, new or changed beneficiary, country-of-beneficiary restrictions, first wire on a new relationship, and any instruction arriving through a channel the bank cannot authenticate.
Here is the handoff chain at a mid-size commercial bank…note the number of touches.
- Instruction arrives: email to the relationship manager, a fax, or a signed form scanned from a branch.
- Wire ops intake: the order is keyed or imported into the wire application.
- Exception fires: the transaction breaks a threshold or beneficiary rule and drops into a verification queue.
- Analyst retrieves the callback number: the step the entire control rests on. The number must come from the system of record, never from the instruction itself. If the number on file is stale, the analyst needs the RM to source a current one, reintroducing the channel the bank was trying to route around.
- Callback attempt: the analyst calls the authorized signer, reaches voicemail, leaves no transaction detail.
- Second and third attempts: spread across the day, because there is no other mechanism. A traveling CFO or a controller in back-to-back meetings turns a five-minute control into a two-day one.
- Verification conversation: the analyst confirms beneficiary, account and routing number, amount, and purpose, authenticating the person with knowledge-based questions and, informally, voice familiarity.
- Documentation: the attempt goes into a log or free-text notes field. This is the artifact that will be produced under examination or in litigation.
- Release and dual approval: a second approver reviews and releases.
Six people-touches, one phone tree, and a documentation artifact whose quality depends on how carefully one analyst typed at 4:40 p.m.
The clock is the part nobody controls
Customer transfers over Fedwire must be submitted by 6:45 p.m. ET, with the service closing at 7:00. Most banks impose internal cutoffs hours earlier. So the callback queue is not just a verification workflow, it is a deadline workflow. An exception that fires at 3:00 p.m. and cannot reach the signer does not fail — it moves. The wire goes tomorrow. For payroll funding, a closing, or a margin call, tomorrow is a customer-impact event, and the operations team knows it.
That pressure produces the two failure modes that actually cost money. The first is the policy override: the callback is waived, or run against a number sourced from the instruction, because the alternative is missing the wire. The second is quieter, a control performed correctly and fast, by someone who has done four hundred of these and learned that the answer is almost always yes.
The control assumes a voice is evidence
Both halves of the verification step rest on assumptions that no longer hold.
Knowledge-based authentication
The questions an analyst asks draw on exactly the information that breached credential sets and infostealer logs have made broadly available. A fraudster who has been reading a compromised mailbox for six weeks can usually answer them better than the signer can.
Voice authentication
The marquee case is well documented: a finance employee at Arup's Hong Kong office, convinced by synthetic colleagues on a video call, executed 15 transfers totaling roughly $25.6 million. Arup later confirmed it was the victim and noted no systems were compromised — social engineering, start to finish. The relevant detail is not the amount. It is that the employee did roughly what a callback asks (confirm with known parties, live, over a synchronous channel) and the channel returned a false positive.
Regulators have said so directly. FinCEN's FIN-2024-Alert004 warns institutions about generative-AI media used specifically to circumvent identity verification and authentication controls. A control whose evidentiary basis is a recognizable voice on a phone line is a control that alert is describing.
Caller ID does not rescue it. Procedure demands an outbound call precisely because inbound caller ID is trivially manipulable, but an outbound call proves only that a number is answered. Calling a known number confirms the line, not the human.
What "taking it digital" actually means
The instinct is to buy a better phone workflow: a dialer, a recorded line, an automated passcode to the number on file. Each improves throughput; none changes what is being proven. A one-time passcode authenticates possession of a device, not a person, which is why SIM-swap remains viable against it.
The digital version replaces the evidentiary basis, not the medium:
Verify the person, not the channel.
The signer completes an identity verification binding a documented human to the authorization (document authentication, biometric match, liveness) rather than answering questions drawn from data already circulating.
Make the authorization the artifact.
The release record becomes a signed authorization tied cryptographically to a verified identity, carrying beneficiary, amount, and timestamp. That converts the bank's good-faith showing from a recollection into a record.
Take the callback off the critical path.
A verification the signer completes in ninety seconds at 4:40 p.m. does not queue against the Fedwire cutoff. Remove the deadline pressure and you remove the override — which is where the losses live.
The test for any replacement: if the fraudster controls the customer's mailbox, their voice, and their caller ID, does the control still fail closed? A callback does not.
Where Proof fits
Proof Identify is built for this step. The signer completes an IAL2-standard verification and the bank receives an identity report that stands as the record of who authorized what. Proof is IAL2 certified by the Kantara Initiative and WebTrust audited, and legitimate users who fail automated verification route to a trained fraud agent rather than dead-ending the payment.
Proof Digital ID changes the economics for repeat originators: the signer verifies once and carries a reusable credential cryptographically bound to them, so a controller authorizing wires weekly completes a fast biometric check instead of a fresh verification each time. Paired with Defend, the same transaction is scored against 150+ behavioral risk signals in the background, including deepfake detection, so the identity check and the anomaly check land in one decision.
The wire callback was built for a world where reaching a known number and hearing a familiar voice was sufficient proof of a person. That world is gone, and the regulators have said so in writing. What is left is a manual control running against an irrevocable rail, on a deadline, with the bank's legal position resting on a free-text note.
The exception does not need a faster phone call. It needs Proof.















































.jpg)





























































.jpg)
























