figma guide

Designing breach settlement check positive pay and anti-fraud controls UI in Figma: PPAY-*, CHK-FRAUD-*, and stale-check holds

Design breach settlement check positive pay UI in Figma with PPAY-* issue files, CHK-FRAUD-* exception queues, positive pay match rules, and claimant-safe check status without exposing MICR.

Published
Updated
Sep 28, 2026
Read time
5 min
Level
Intermediate

Quick answer

Positive pay UI is how settlement programs stop forged or altered checks before the bank pays them—not optional once you mail thousands of CHK- payments.* Design PPAY- issue files* exported with each print batch, CHK-FRAUD- exception queues* when the bank reports amount or payee mismatches, and stale-date / stop-pay linkage so treasury does not fight fraud and stop payment in separate spreadsheets. Positive pay sits between check disbursement (CHK-PRINT-, CHK-MAIL-) and bank confirmation (match type = check cleared). Claimants should see “Check issued” and “Check deposited” without check numbers or MICR in the portal—those fields are admin-only and feed PPAY-* rows. Pair controls with duplicate claim fraud, payee correction, and post-disbursement QA. Start from the Figma guides hub and use tables, badges, and Dev Mode handoff.


Who this is for

  • Product designers where mail-house CSV exports exist but positive pay is “the bank’s problem.”
  • Treasury reconciling CHK-CASH-* against PPAY-PAID-* and hunting CHK-FRAUD-* before fund reconciliation closes.
  • Fraud ops tying check exceptions to identity re-verification when payee names drift from eligibility records.

PPAY-* positive pay issue file workspace

PositivePayIssue — PPAY-992-701 · batch_id: CHK-PRINT-992-044
├── Source rows (from [check disbursement](/designing-breach-settlement-wire-and-check-fallback-disbursement-ui-in-figma/)):
│   ├── chk_id (CHK-*) · pay_id · amount_cents · payee_name_legal
│   ├── check_number (internal) · issue_date · stale_date
│   ├── mail_to_address_id (hash only in export—no full PII in bank file if policy requires)
│   └── program_id · escrow account on check stock
├── Export states:
│   ├── draft → validated → exported → bank_ack → exceptions_open | clean
│   ├── PPAY-EXP-* file id · checksum · row_count
│   └── Block export if CHK-* row missing counsel flag when amount > threshold
├── Validation ([pre-export patterns](/designing-breach-settlement-pre-export-payment-validation-and-exception-queue-ui-in-figma/)):
│   ├── Duplicate check_number in batch
│   ├── Amount ≠ [award restatement](/designing-breach-settlement-award-restatement-and-fin-awd-version-history-ui-in-figma/) FIN-AWD-* current
│   ├── Payee mismatch vs BENE-* after [payee correction](/designing-breach-settlement-payee-correction-and-beneficiary-update-ui-in-figma/)
│   └── Stop flag CHK-STOP-* or [void/recall](/designing-breach-settlement-stop-payment-void-and-in-flight-recall-ui-in-figma/) active
└── Audit:
    ├── LOG-PPAY-* who exported · IP allowlist optional ([network restrictions](/designing-ip-allowlist-and-network-restrictions-ui-in-figma/))
    └── Link [idempotency](/designing-breach-settlement-payment-idempotency-and-duplicate-submission-prevention-ui-in-figma/)—re-export same batch needs new PPAY-EXP-* id
Export fieldBank needsPortal shows
Check numberYesNo
AmountYes“Payment amount” only after proof
Payee legal nameYesMasked last name optional
Issue dateYes“Check mailed {date}” from CHK-MAIL-*

Verdict: Treat PPAY- as a payment submission* parallel to NACHA export—same seriousness, different file format.


CHK-FRAUD-* exception queue

CheckFraudException — CHK-FRAUD-992-033 · bank_alert_id
├── Exception types (bank feed or manual):
│   ├── amount_mismatch · payee_mismatch · unknown_check · stale_paid
│   ├── duplicate_presentment · altered_micr (internal code)
│   └── positive_pay_no_match · issue_file_late
├── Triage workspace ([tables + side panel](/figma-tables-and-data-ui-rows-columns-and-handoff/)):
│   ├── Match to CHK-* / pay_id via check_number (admin only)
│   ├── Side-by-side: PPAY row vs bank presentment
│   ├── Actions: pay · reject · refer_fraud · link [clawback](/designing-breach-settlement-clawback-and-overpayment-recovery-ui-in-figma/)
│   └── SLA badge · assignee · [audit log](/designing-audit-log-and-security-activity-ui-in-figma/) note required
├── Outcomes:
│   ├── approve_pay → CHK-CASH-* with fraud_review_cleared flag
│   ├── reject → CHK-STOP-* + claimant comms via [timeline](/designing-breach-settlement-hold-release-notifications-and-claimant-payment-timeline-ui-in-figma/)
│   └── escalate → [counsel review](/designing-breach-settlement-counsel-review-and-payout-approval-ui-in-figma/) if amount > policy
└── QA sampling:
    └── Feed [post-disbursement QA](/designing-breach-settlement-post-disbursement-qa-and-audit-sampling-ui-in-figma/) FIND-* when pattern cluster

Fraud exceptions are not the same as returned ACH—use distinct copy and queue filters so call center agents do not apply ACH scripts to check forgery.


Stale date, escheat, and stop-pay coordination

StaleCheckPolicy — STALE-992-010 · program_config
├── stale_days_after_issue (e.g. 90/180)
├── States on CHK-*:
│   ├── active → stale_warning → stale_hold → escheat_candidate | reissued
│   ├── STALE-HOLD-* blocks secondary CHK-REISS-* without [UCF review](/designing-breach-settlement-unclaimed-funds-and-escheatment-ui-in-figma/)
│   └── Portal: “Check not deposited—contact us before {stale_date}”
├── Positive pay interaction:
│   ├── Bank may reject stale at presentment—maps to CHK-FRAUD-stale_paid
│   └── PPAY re-issue requires new check_number row—never reuse in issue file
└── Link [wind-down](/designing-breach-settlement-program-wind-down-and-portal-closure-ui-in-figma/) when print stock retired

Comparison table: control layers for check programs

LayerID prefixPreventsOwner
Address validationVAL-ADDR-*Mail fraudOps
Positive pay issuePPAY-*Wrong check paidTreasury
Exception triageCHK-FRAUD-*Forgery lossesFraud
Stop / voidCHK-STOP-*Double payTreasury
QA samplingFIND-*Process driftCompliance

Best for: Programs with >500 checks per wave—positive pay ROI appears quickly; smaller pilots can still spec PPAY-* for bank onboarding lead time.


Claimant-facing status (safe fields)

Use status portal events:

  • EVT-CHK-ISSUE-* — “Check prepared” (internal: linked to PPAY export, not shown)
  • EVT-CHK-MAIL-* — from check disbursement
  • EVT-CHK-CASH-* — “Payment completed” when cleared and fraud queue empty

Never expose check_number in claimant API responses—support looks up via authenticated where-is-my-payment with step-up.


Handoff checklist (Dev Mode)

  • PositivePayIssue — ppay_id (PPAY-*), batch_id, export_state_enum, file_checksum, row_count, exported_at.
  • PositivePayRow — ppay_row_id, chk_id, check_number_internal, amount_cents, payee_name, issue_date, stale_date.
  • CheckFraudException — fraud_id (CHK-FRAUD-*), bank_alert_id, exception_type_enum, chk_id optional, state_enum, resolved_at.
  • StaleCheckPolicy — config_id (STALE-*), stale_days, warning_days, program_id.
  • CheckClearingEvent — evt_id (CHK-CASH-*), chk_id, cleared_at, fraud_cleared_bool.

Common mistakes

MistakeWhy it hurtsFix
Export PPAY after mail without validationWrong amount in bankPre-export queue
Reuse check numbers on reissuePositive pay chaosNew CHK-* id per reissue
Show MICR in portalCounterfeit aidAdmin-only fields
Merge fraud queue with ACH returnsWrong scriptsSeparate CHK-FRAUD-*
No bank ack state on PPAYSilent non-protectionbank_ack required
Skip QA on fraud clustersRepeat forgeryFIND-* from CHK-FRAUD-*
Ignore stale holds in escheatDouble liabilitySTALE-HOLD-* gates

  1. Add PPAY- export* to the same treasury nav as NACHA preview.
  2. Design CHK-FRAUD- triage* with bank presentment side-by-side.
  3. Wire stale policy to portal warnings before escheat workflows.
  4. Sample cleared checks in post-disbursement QA including fraud_cleared flag.
  5. Document stop-pay interaction in void/recall UI for checks only.

FAQ

Required if we only use wire fallback for a few claimants?

If any CHK- mails, spec PPAY- for that volume**—banks often require it for settlement accounts regardless of count.

Relation to duplicate claim detection?

Duplicate claim is intake fraud; CHK-FRAUD- is presentment fraud*—cross-link pay_id but keep queues separate.

Minor claimant checks?

PPAY payee_name must match guardian BENE-*— block export on mismatch like counsel approval thresholds.

Positive pay and proof of payment?

Issue proof only after CHK-CASH- and fraud queue clear*—not at PPAY export.

Escheat after stale?

Follow UCF— positive pay stale rejection is not the same as escheat filing.


Next steps

Share on X

§ Keep reading

Related guides.