This is governed by your state's Uniform Commercial Code and the "reasonable commercial standards" of your online security monitoring and strength of login processes as well as your agreement with the commercial customer. You should have your legal department review your contract and state law as well as review the
FFIEC Supplemental Guidance and
2005 FFIEC Guidance on the topic and determine if your authentication and monitoring processes are sufficient.
Regardless of the measures that you have in place, that may not stop your customer from suing you.
_________________________
Sola Gratia, Sola Fides, Sola Scriptura, Solus Christus, Soli Deo Gloria!
www.tcaregs.com