Feature Operational Risk
Instant Payments Fraud Controls: The Operational Risk Framework Financial Institutions Need for FedNow and RTP
FedNow and RTP are irrevocable, 24/7, and settling in seconds — and your fraud controls were built for ACH and wire. Here's the operational risk framework that bridges the gap before the fraud arrives.
Table of Contents
In the summer of 2023, the Federal Reserve launched FedNow — positioning it as the infrastructure that would finally give every American access to instant, 24/7 payments. Three years and 1,500 participating institutions later, the service has delivered exactly that: instant and irrevocable.
The irrevocable part is where most risk programs haven’t caught up.
TL;DR
- FedNow has 1,500 participating institutions and settling 40% of US demand deposit accounts; RTP reaches a similar footprint — both are now mainstream payments infrastructure
- Instant payments are irrevocable: once sent, there is no return window, no ACH reversal mechanism, and no SWIFT recall pathway
- Reg E covers unauthorized transactions; authorized push payment fraud — where a fraudster tricks someone into sending money voluntarily — has no mandatory federal reimbursement framework
- The Faster Payments Council published 11 guiding principles for fraud dispute resolution in May 2026; they’re voluntary, not regulatory
- Financial institutions that enabled FedNow send capabilities without updating fraud controls, transaction limits, and real-time scoring are operating with an unpriced operational risk
The Infrastructure Has Outpaced the Controls
FedNow’s adoption curve has been steep. The Federal Reserve reported a 1,200% year-over-year increase in transaction volume — from 97,424 settled payments in Q1 2024 to over 1.3 million in Q1 2025. The Clearing House’s RTP network, which launched earlier and covers a largely overlapping footprint, adds additional volume on a parallel rail.
Both rails share the same core operational characteristic: payment finality upon posting. There is no ACH-style return window. There is no wire recall mechanism. When a payment clears FedNow or RTP, the funds are at the receiving institution and accessible immediately.
For fraud, this creates a fundamentally different control environment than anything most US financial institutions have managed before. ACH gave risk teams days to identify and return suspicious entries. Wires had a recall option — imperfect and unreliable, but it existed. Instant payments give risk teams seconds.
Some institutions report a six-second window to authorize a transaction before it clears. If your fraud scoring takes longer than that, you’re making authorization decisions without it.
The Fraud Landscape: What’s Coming
FedNow fraud rates have been low since launch — the Federal Reserve reports that participating institutions have seen very little fraud on the network to date, a fact that’s partly a function of current transaction mix (business-to-business and bill pay dominate early FedNow volumes) and partly good industry hygiene.
That will change as consumer adoption accelerates and the fraud industry turns its attention to the rail.
The UK is the instructive precedent. Faster Payments launched in the UK in 2008. Within a decade, regulators were reporting that 96% of all “sender-authorized” fraud involved a faster payment. The UK Payment Systems Regulator’s mandatory APP fraud reimbursement rule — which took effect in October 2024 and requires banks to reimburse victims of authorized push payment scams up to £85,000 — was a direct response to that exposure.
The US is roughly where the UK was in 2014: a faster payments network in wide deployment, consumer adoption beginning to ramp, and fraud controls still being calibrated. The difference is that no US mandatory reimbursement requirement exists, which means consumer loss and trust damage — not regulatory fines — will be the forcing function.
Meanwhile, fraudulent activity in financial services rose 21% between 2024 and 2025, driven primarily by identity and social engineering schemes. Authorized push payment scams — where a fraudster impersonates a bank, a vendor, a government agency, or a trusted individual to get the victim to send money — are the most operationally difficult category to prevent because the consumer is doing exactly what the fraud controls expect them to do.
The Regulatory Gap: Reg E Doesn’t Protect Authorized Payments
This distinction matters enormously for liability analysis.
The Electronic Fund Transfer Act and Regulation E protect consumers against unauthorized electronic fund transfers — transactions the consumer did not initiate or did not authorize. If someone steals credentials and initiates a FedNow transfer, that’s an unauthorized transfer and Reg E’s error resolution process applies. The institution typically bears liability.
But authorized push payment fraud works differently. The consumer receives a convincing call from someone posing as their bank’s fraud department. They’re told a suspicious transfer has been initiated on their account and need to move their money to a “safe account” immediately. They initiate the FedNow transfer themselves. They authorized it. The bank executed it correctly.
That payment is not an unauthorized transfer under Reg E. The error resolution framework doesn’t apply. The consumer has no federal right to reimbursement.
The National Consumer Law Center has advocated explicitly for extending Reg E to cover authorized push payment scams. The Federal Reserve Board has expressed interest in examining Reg E as a potential tool for improving instant payments consumer protection. But as of June 2026, no such requirement has been enacted.
This creates a specific operational risk for institutions: consumer losses from authorized push payment scams generate disputes, chargebacks, and reputational damage that institutions absorb differently from unauthorized transaction losses. The absence of a mandatory reimbursement framework is also the absence of a shared industry standard for how to handle those disputes — which creates inconsistency and friction.
The Faster Payments Council Guiding Principles
On May 15, 2026, the U.S. Faster Payments Council released Instant Payments Fraud Dispute Resolution: Guiding Principles for the U.S. — 11 flexible principles developed by its Fraud and Scam Mitigation work group.
The principles aren’t a regulatory requirement, but they represent industry consensus on what a defensible dispute resolution framework looks like. Financial institutions implementing these principles ahead of any regulatory mandate are building infrastructure that will survive both the fraud exposure and any future regulatory response. The key principles include:
Pre-authorization controls: Risk-based fraud scoring should happen before the payment is authorized, not as a post-settlement audit. Institutions need real-time screening capabilities that can make a risk decision within the authorization window.
Standardized messaging: Sending and receiving institutions need a communication channel for fraud dispute coordination. The FPC principles call for standardized messaging capabilities — essentially, a way for a sending institution to contact the receiving institution quickly when it suspects a fraudulent payment has been received.
Clear role delineation: Both sending and receiving institutions have fraud prevention responsibilities. Sending institutions are responsible for pre-authorization controls and customer education. Receiving institutions are responsible for cooperating with legitimate fraud recalls and not facilitating fraudulent withdrawals.
Consumer communication standards: Institutions should provide pre-transaction education about common scams, particularly for first-time send users and high-value transactions.
Building the Operational Risk Framework
The controls gap between legacy payment rails and instant payments isn’t a technology problem — it’s an operational risk framework problem. Most institutions enabled FedNow receive capabilities first (lower fraud risk) and are now expanding to send. The send side is where the fraud exposure sits.
Pre-Authorization Fraud Scoring
Every FedNow send transaction should be scored against a real-time risk model before authorization. The model should incorporate:
- Behavioral signals: Is this transaction consistent with the customer’s established payment patterns? First-time send, unusual amount, unusual time of day, and unusual recipient are all signals.
- Device and session risk: Was the transaction initiated from a recognized device? Was the session flagged for unusual behavior (multiple failed logins, rapid navigation to the payment screen, IP anomalies)?
- Velocity: How many FedNow sends has this customer initiated in the past 24 hours? What’s the total dollar amount?
- Recipient risk: Is the receiving account associated with known fraud patterns? Has the receiving routing/account combination appeared in fraud alerts?
Institutions that can’t score in under six seconds need transaction holds with customer friction — a confirmation step, a call-back requirement, or a brief delay for high-risk transactions.
Transaction Limits and Controls
Blanket per-transaction and daily limits are table stakes, but limit design matters:
| Customer Segment | Recommended Control Approach |
|---|---|
| New customers (< 90 days) | Lower initial limit with gradual increase; manual review above threshold |
| High-value send requests | Step-up authentication before authorization |
| Recipient mismatch (payee name ≠ account name) | Warning screen with explicit acknowledgment; potential hold |
| Unverified send requests (no prior payment relationship) | Enhanced friction, limit cap |
The UK’s Confirmation of Payee controls — which prompt consumers before completing a payment when the account name doesn’t match the beneficiary name — cut authorized push payment fraud by approximately 35% after introduction. US instant payment rails don’t yet mandate equivalent controls, but institutions can implement similar name-matching verification unilaterally.
Consumer Education
Authorized push payment fraud works because consumers don’t recognize the scam in progress. Fraud controls that put a friction moment in front of the consumer — a clear warning message before they complete a send — materially reduce loss rates.
Effective consumer education for instant payments includes:
- Pre-authorization warnings for new recipients: “Once sent, this payment cannot be reversed.”
- Scam identification reminders triggered by high-risk patterns: “Banks, government agencies, and utilities will never ask you to transfer money to a ‘safe account.’”
- Post-authentication confirmations for high-value sends: Step-up authentication with a specific reason-for-payment prompt.
Recall and Recovery Protocols
When a consumer reports a fraudulent outbound send, institutions need a documented recall protocol:
- Immediate hold request: Contact the receiving institution’s fraud line immediately. FedNow does not have a built-in recall mechanism, but receiving institutions may cooperate with voluntary hold requests if contacted quickly.
- FinCEN notification: For losses meeting materiality thresholds, coordinate with FinCEN’s Financial Fraud Kill Chain for potential recovery assistance.
- Law enforcement referral: CISA and FBI’s Internet Crime Complaint Center (IC3) maintain relationships with financial institutions for rapid-response fraud recovery. Losses above institutional thresholds warrant IC3 reporting.
- SAR filing: Coordinated fraud events — particularly those involving multiple victims or institutions — typically require SAR filing regardless of whether a recall succeeds.
For comparison, the wire transfer fraud incident response playbook covers the UCC 4A liability framework for wire fraud; instant payments operate outside that framework but can use similar rapid-response protocols.
Fraud KRIs for Instant Payments
Most existing fraud monitoring programs track ACH return rates, debit card fraud rates, and wire fraud losses. None of those metrics capture instant payments fraud exposure.
Institutions that have enabled FedNow or RTP send capabilities need instant payments-specific KRIs:
| KRI | Measurement | Threshold Signal |
|---|---|---|
| APP fraud loss rate | Fraud losses per $1M settled | Rising trend against baseline |
| First-time send rate | % of sends to new recipients | Spike above established range |
| High-risk send rate | % flagged by pre-authorization scoring | Trend up (increasing fraud attempt volume) |
| Dispute rate | Customer disputes per 1,000 sends | > 0.5% warrants investigation |
| Recall cooperation rate | % of requests where receiving FI cooperates | < 50% signals process gaps |
| Consumer education completion | % of first-time send users completing education | < 80% is a control gap |
These metrics should feed into your existing operational risk monitoring program. The fraud KRI examples for fintech and banking teams covers threshold calibration methodology — the core principle is that KRI thresholds calibrated at today’s volume may be meaningless as instant payments volume grows.
For institutions building out a KRI program, the KRI Library (132 Key Risk Indicators) includes payment-specific fraud metrics with pre-calibrated green/amber/red thresholds across operational, compliance, and financial risk domains.
Connecting Instant Payments to Your Operational Loss Program
Instant payments fraud losses need to flow into your operational loss event database — they’re not just fraud department statistics. BCBS 356 loss event categories cover external fraud, and FedNow-related losses belong in your operational risk data set for RCSA and capital modeling purposes.
For institutions with a formal operational loss database, classify instant payments fraud losses under External Fraud — Payments/Transfers, with a note on authorization status (authorized vs. unauthorized). Track separately from card fraud and ACH fraud to understand the rail-specific exposure. The operational loss data collection framework covers the database requirements that support this classification.
Institutions that lump all fraud losses into a single bucket will have difficulty defending their instant payments risk assessment to an examiner — particularly if the FDIC or OCC starts treating instant payments fraud as a named examination priority, which the FDIC’s 2026 Risk Review language suggests is coming.
What Examiners Will Ask
The FFIEC Retail Payment Systems Booklet (updated most recently for cloud-era risk) explicitly covers operational risk assessment requirements for new payment services. Examiners following this booklet will ask:
- Did the institution conduct a formal risk assessment before enabling FedNow send capabilities?
- Does the institution have documented transaction limits with documented rationale for those limits?
- Is there a real-time fraud scoring capability for instant payment transactions?
- How does the institution handle consumer-reported authorized push payment scams?
- Has the institution reviewed and responded to the FPC’s fraud dispute resolution guiding principles?
The Nacha ACH fraud monitoring Phase 2 compliance post describes the kind of documentation regulators expect for payment rail fraud monitoring programs — similar documentation expectations apply to FedNow and RTP, even without the formal Nacha rule structure.
So What?
Instant payments are not optional in 2026. Your customers expect them; your competitors offer them; your bank partners and processors have built infrastructure around them. The question is not whether to offer FedNow or RTP, but whether your operational risk framework has caught up with the payment rails you’ve enabled.
If you enabled FedNow receive before send, you’ve had time to observe the incoming fraud patterns from your network without carrying the liability. If you’ve now enabled send, the liability clock is running. The controls that protect you aren’t the same ones that covered ACH and wire — they need to account for irrevocability, the authorized push payment gap in Reg E, the six-second scoring window, and the FPC dispute resolution principles that the industry is coalescing around.
The institutions that build these controls now — before volume scales and before the fraud industry shifts attention to the rail — are the ones that will be in front of any examiner conversation rather than behind it.
Related reading: Account Takeover Incident Response: The Reg E Liability Playbook covers how Reg E error resolution applies when an account is compromised; the liability analysis for authorized push payment fraud follows a different path but raises similar documentation questions.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does Regulation E protect consumers against authorized push payment fraud on FedNow or RTP?
What is the window for recalling a fraudulent FedNow payment?
What fraud controls does the Faster Payments Council recommend for FedNow and RTP?
How is instant payments fraud different from wire transfer fraud or ACH fraud?
What fraud KRIs should financial institutions track for FedNow and RTP?
Are there regulatory examination expectations for instant payments fraud controls?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026