figma guide
Designing breach settlement check positive pay and anti-fraud controls UI in Figma: PPAY-*, CHK-FRAUD-*, and stale-check holds
Design breach settlement check positive pay UI in Figma with PPAY-* issue files, CHK-FRAUD-* exception queues, positive pay match rules, and claimant-safe check status without exposing MICR.
- Published
- Updated
- Sep 28, 2026
- Read time
- 5 min
- Level
- Intermediate
Quick answer
Positive pay UI is how settlement programs stop forged or altered checks before the bank pays them—not optional once you mail thousands of CHK- payments.* Design PPAY- issue files* exported with each print batch, CHK-FRAUD- exception queues* when the bank reports amount or payee mismatches, and stale-date / stop-pay linkage so treasury does not fight fraud and stop payment in separate spreadsheets. Positive pay sits between check disbursement (CHK-PRINT-, CHK-MAIL-) and bank confirmation (match type = check cleared). Claimants should see “Check issued” and “Check deposited” without check numbers or MICR in the portal—those fields are admin-only and feed PPAY-* rows. Pair controls with duplicate claim fraud, payee correction, and post-disbursement QA. Start from the Figma guides hub and use tables, badges, and Dev Mode handoff.
Who this is for
- Product designers where mail-house CSV exports exist but positive pay is “the bank’s problem.”
- Treasury reconciling CHK-CASH-* against PPAY-PAID-* and hunting CHK-FRAUD-* before fund reconciliation closes.
- Fraud ops tying check exceptions to identity re-verification when payee names drift from eligibility records.
PPAY-* positive pay issue file workspace
PositivePayIssue — PPAY-992-701 · batch_id: CHK-PRINT-992-044
├── Source rows (from [check disbursement](/designing-breach-settlement-wire-and-check-fallback-disbursement-ui-in-figma/)):
│ ├── chk_id (CHK-*) · pay_id · amount_cents · payee_name_legal
│ ├── check_number (internal) · issue_date · stale_date
│ ├── mail_to_address_id (hash only in export—no full PII in bank file if policy requires)
│ └── program_id · escrow account on check stock
├── Export states:
│ ├── draft → validated → exported → bank_ack → exceptions_open | clean
│ ├── PPAY-EXP-* file id · checksum · row_count
│ └── Block export if CHK-* row missing counsel flag when amount > threshold
├── Validation ([pre-export patterns](/designing-breach-settlement-pre-export-payment-validation-and-exception-queue-ui-in-figma/)):
│ ├── Duplicate check_number in batch
│ ├── Amount ≠ [award restatement](/designing-breach-settlement-award-restatement-and-fin-awd-version-history-ui-in-figma/) FIN-AWD-* current
│ ├── Payee mismatch vs BENE-* after [payee correction](/designing-breach-settlement-payee-correction-and-beneficiary-update-ui-in-figma/)
│ └── Stop flag CHK-STOP-* or [void/recall](/designing-breach-settlement-stop-payment-void-and-in-flight-recall-ui-in-figma/) active
└── Audit:
├── LOG-PPAY-* who exported · IP allowlist optional ([network restrictions](/designing-ip-allowlist-and-network-restrictions-ui-in-figma/))
└── Link [idempotency](/designing-breach-settlement-payment-idempotency-and-duplicate-submission-prevention-ui-in-figma/)—re-export same batch needs new PPAY-EXP-* id
| Export field | Bank needs | Portal shows |
|---|---|---|
| Check number | Yes | No |
| Amount | Yes | “Payment amount” only after proof |
| Payee legal name | Yes | Masked last name optional |
| Issue date | Yes | “Check mailed {date}” from CHK-MAIL-* |
Verdict: Treat PPAY- as a payment submission* parallel to NACHA export—same seriousness, different file format.
CHK-FRAUD-* exception queue
CheckFraudException — CHK-FRAUD-992-033 · bank_alert_id
├── Exception types (bank feed or manual):
│ ├── amount_mismatch · payee_mismatch · unknown_check · stale_paid
│ ├── duplicate_presentment · altered_micr (internal code)
│ └── positive_pay_no_match · issue_file_late
├── Triage workspace ([tables + side panel](/figma-tables-and-data-ui-rows-columns-and-handoff/)):
│ ├── Match to CHK-* / pay_id via check_number (admin only)
│ ├── Side-by-side: PPAY row vs bank presentment
│ ├── Actions: pay · reject · refer_fraud · link [clawback](/designing-breach-settlement-clawback-and-overpayment-recovery-ui-in-figma/)
│ └── SLA badge · assignee · [audit log](/designing-audit-log-and-security-activity-ui-in-figma/) note required
├── Outcomes:
│ ├── approve_pay → CHK-CASH-* with fraud_review_cleared flag
│ ├── reject → CHK-STOP-* + claimant comms via [timeline](/designing-breach-settlement-hold-release-notifications-and-claimant-payment-timeline-ui-in-figma/)
│ └── escalate → [counsel review](/designing-breach-settlement-counsel-review-and-payout-approval-ui-in-figma/) if amount > policy
└── QA sampling:
└── Feed [post-disbursement QA](/designing-breach-settlement-post-disbursement-qa-and-audit-sampling-ui-in-figma/) FIND-* when pattern cluster
Fraud exceptions are not the same as returned ACH—use distinct copy and queue filters so call center agents do not apply ACH scripts to check forgery.
Stale date, escheat, and stop-pay coordination
StaleCheckPolicy — STALE-992-010 · program_config
├── stale_days_after_issue (e.g. 90/180)
├── States on CHK-*:
│ ├── active → stale_warning → stale_hold → escheat_candidate | reissued
│ ├── STALE-HOLD-* blocks secondary CHK-REISS-* without [UCF review](/designing-breach-settlement-unclaimed-funds-and-escheatment-ui-in-figma/)
│ └── Portal: “Check not deposited—contact us before {stale_date}”
├── Positive pay interaction:
│ ├── Bank may reject stale at presentment—maps to CHK-FRAUD-stale_paid
│ └── PPAY re-issue requires new check_number row—never reuse in issue file
└── Link [wind-down](/designing-breach-settlement-program-wind-down-and-portal-closure-ui-in-figma/) when print stock retired
Comparison table: control layers for check programs
| Layer | ID prefix | Prevents | Owner |
|---|---|---|---|
| Address validation | VAL-ADDR-* | Mail fraud | Ops |
| Positive pay issue | PPAY-* | Wrong check paid | Treasury |
| Exception triage | CHK-FRAUD-* | Forgery losses | Fraud |
| Stop / void | CHK-STOP-* | Double pay | Treasury |
| QA sampling | FIND-* | Process drift | Compliance |
Best for: Programs with >500 checks per wave—positive pay ROI appears quickly; smaller pilots can still spec PPAY-* for bank onboarding lead time.
Claimant-facing status (safe fields)
Use status portal events:
EVT-CHK-ISSUE-*— “Check prepared” (internal: linked to PPAY export, not shown)EVT-CHK-MAIL-*— from check disbursementEVT-CHK-CASH-*— “Payment completed” when cleared and fraud queue empty
Never expose check_number in claimant API responses—support looks up via authenticated where-is-my-payment with step-up.
Handoff checklist (Dev Mode)
- PositivePayIssue — ppay_id (PPAY-*), batch_id, export_state_enum, file_checksum, row_count, exported_at.
- PositivePayRow — ppay_row_id, chk_id, check_number_internal, amount_cents, payee_name, issue_date, stale_date.
- CheckFraudException — fraud_id (CHK-FRAUD-*), bank_alert_id, exception_type_enum, chk_id optional, state_enum, resolved_at.
- StaleCheckPolicy — config_id (STALE-*), stale_days, warning_days, program_id.
- CheckClearingEvent — evt_id (CHK-CASH-*), chk_id, cleared_at, fraud_cleared_bool.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Export PPAY after mail without validation | Wrong amount in bank | Pre-export queue |
| Reuse check numbers on reissue | Positive pay chaos | New CHK-* id per reissue |
| Show MICR in portal | Counterfeit aid | Admin-only fields |
| Merge fraud queue with ACH returns | Wrong scripts | Separate CHK-FRAUD-* |
| No bank ack state on PPAY | Silent non-protection | bank_ack required |
| Skip QA on fraud clusters | Repeat forgery | FIND-* from CHK-FRAUD-* |
| Ignore stale holds in escheat | Double liability | STALE-HOLD-* gates |
Recommended workflow
- Add PPAY- export* to the same treasury nav as NACHA preview.
- Design CHK-FRAUD- triage* with bank presentment side-by-side.
- Wire stale policy to portal warnings before escheat workflows.
- Sample cleared checks in post-disbursement QA including fraud_cleared flag.
- Document stop-pay interaction in void/recall UI for checks only.
FAQ
Required if we only use wire fallback for a few claimants?
If any CHK- mails, spec PPAY- for that volume**—banks often require it for settlement accounts regardless of count.
Relation to duplicate claim detection?
Duplicate claim is intake fraud; CHK-FRAUD- is presentment fraud*—cross-link pay_id but keep queues separate.
Minor claimant checks?
PPAY payee_name must match guardian BENE-*— block export on mismatch like counsel approval thresholds.
Positive pay and proof of payment?
Issue proof only after CHK-CASH- and fraud queue clear*—not at PPAY export.
Escheat after stale?
Follow UCF— positive pay stale rejection is not the same as escheat filing.
Next steps
- Design breach settlement wire and check fallback disbursement UI in Figma — CHK-* lifecycle
- Design breach settlement stop payment, void, and in-flight recall UI in Figma — CHK-STOP-*
- Design breach settlement bank confirmation and trace matching UI in Figma — cleared check matching
- Design breach settlement post-disbursement QA and audit sampling UI in Figma — FIND-* sampling
- Design breach settlement unclaimed funds and escheatment UI in Figma — stale → UCF
§ Keep reading