Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Operational Risk

Instant Payments Fraud Controls: The Operational Risk Framework Financial Institutions Need for FedNow and RTP

FedNow and RTP are irrevocable, 24/7, and settling in seconds — and your fraud controls were built for ACH and wire. Here's the operational risk framework that bridges the gap before the fraud arrives.

By Rebecca Leung · June 13, 2026 ·
Table of Contents

In the summer of 2023, the Federal Reserve launched FedNow — positioning it as the infrastructure that would finally give every American access to instant, 24/7 payments. Three years and 1,500 participating institutions later, the service has delivered exactly that: instant and irrevocable.

The irrevocable part is where most risk programs haven’t caught up.

TL;DR

  • FedNow has 1,500 participating institutions and settling 40% of US demand deposit accounts; RTP reaches a similar footprint — both are now mainstream payments infrastructure
  • Instant payments are irrevocable: once sent, there is no return window, no ACH reversal mechanism, and no SWIFT recall pathway
  • Reg E covers unauthorized transactions; authorized push payment fraud — where a fraudster tricks someone into sending money voluntarily — has no mandatory federal reimbursement framework
  • The Faster Payments Council published 11 guiding principles for fraud dispute resolution in May 2026; they’re voluntary, not regulatory
  • Financial institutions that enabled FedNow send capabilities without updating fraud controls, transaction limits, and real-time scoring are operating with an unpriced operational risk

The Infrastructure Has Outpaced the Controls

FedNow’s adoption curve has been steep. The Federal Reserve reported a 1,200% year-over-year increase in transaction volume — from 97,424 settled payments in Q1 2024 to over 1.3 million in Q1 2025. The Clearing House’s RTP network, which launched earlier and covers a largely overlapping footprint, adds additional volume on a parallel rail.

Both rails share the same core operational characteristic: payment finality upon posting. There is no ACH-style return window. There is no wire recall mechanism. When a payment clears FedNow or RTP, the funds are at the receiving institution and accessible immediately.

For fraud, this creates a fundamentally different control environment than anything most US financial institutions have managed before. ACH gave risk teams days to identify and return suspicious entries. Wires had a recall option — imperfect and unreliable, but it existed. Instant payments give risk teams seconds.

Some institutions report a six-second window to authorize a transaction before it clears. If your fraud scoring takes longer than that, you’re making authorization decisions without it.

The Fraud Landscape: What’s Coming

FedNow fraud rates have been low since launch — the Federal Reserve reports that participating institutions have seen very little fraud on the network to date, a fact that’s partly a function of current transaction mix (business-to-business and bill pay dominate early FedNow volumes) and partly good industry hygiene.

That will change as consumer adoption accelerates and the fraud industry turns its attention to the rail.

The UK is the instructive precedent. Faster Payments launched in the UK in 2008. Within a decade, regulators were reporting that 96% of all “sender-authorized” fraud involved a faster payment. The UK Payment Systems Regulator’s mandatory APP fraud reimbursement rule — which took effect in October 2024 and requires banks to reimburse victims of authorized push payment scams up to £85,000 — was a direct response to that exposure.

The US is roughly where the UK was in 2014: a faster payments network in wide deployment, consumer adoption beginning to ramp, and fraud controls still being calibrated. The difference is that no US mandatory reimbursement requirement exists, which means consumer loss and trust damage — not regulatory fines — will be the forcing function.

Meanwhile, fraudulent activity in financial services rose 21% between 2024 and 2025, driven primarily by identity and social engineering schemes. Authorized push payment scams — where a fraudster impersonates a bank, a vendor, a government agency, or a trusted individual to get the victim to send money — are the most operationally difficult category to prevent because the consumer is doing exactly what the fraud controls expect them to do.

The Regulatory Gap: Reg E Doesn’t Protect Authorized Payments

This distinction matters enormously for liability analysis.

The Electronic Fund Transfer Act and Regulation E protect consumers against unauthorized electronic fund transfers — transactions the consumer did not initiate or did not authorize. If someone steals credentials and initiates a FedNow transfer, that’s an unauthorized transfer and Reg E’s error resolution process applies. The institution typically bears liability.

But authorized push payment fraud works differently. The consumer receives a convincing call from someone posing as their bank’s fraud department. They’re told a suspicious transfer has been initiated on their account and need to move their money to a “safe account” immediately. They initiate the FedNow transfer themselves. They authorized it. The bank executed it correctly.

That payment is not an unauthorized transfer under Reg E. The error resolution framework doesn’t apply. The consumer has no federal right to reimbursement.

The National Consumer Law Center has advocated explicitly for extending Reg E to cover authorized push payment scams. The Federal Reserve Board has expressed interest in examining Reg E as a potential tool for improving instant payments consumer protection. But as of June 2026, no such requirement has been enacted.

This creates a specific operational risk for institutions: consumer losses from authorized push payment scams generate disputes, chargebacks, and reputational damage that institutions absorb differently from unauthorized transaction losses. The absence of a mandatory reimbursement framework is also the absence of a shared industry standard for how to handle those disputes — which creates inconsistency and friction.

The Faster Payments Council Guiding Principles

On May 15, 2026, the U.S. Faster Payments Council released Instant Payments Fraud Dispute Resolution: Guiding Principles for the U.S. — 11 flexible principles developed by its Fraud and Scam Mitigation work group.

The principles aren’t a regulatory requirement, but they represent industry consensus on what a defensible dispute resolution framework looks like. Financial institutions implementing these principles ahead of any regulatory mandate are building infrastructure that will survive both the fraud exposure and any future regulatory response. The key principles include:

Pre-authorization controls: Risk-based fraud scoring should happen before the payment is authorized, not as a post-settlement audit. Institutions need real-time screening capabilities that can make a risk decision within the authorization window.

Standardized messaging: Sending and receiving institutions need a communication channel for fraud dispute coordination. The FPC principles call for standardized messaging capabilities — essentially, a way for a sending institution to contact the receiving institution quickly when it suspects a fraudulent payment has been received.

Clear role delineation: Both sending and receiving institutions have fraud prevention responsibilities. Sending institutions are responsible for pre-authorization controls and customer education. Receiving institutions are responsible for cooperating with legitimate fraud recalls and not facilitating fraudulent withdrawals.

Consumer communication standards: Institutions should provide pre-transaction education about common scams, particularly for first-time send users and high-value transactions.

Building the Operational Risk Framework

The controls gap between legacy payment rails and instant payments isn’t a technology problem — it’s an operational risk framework problem. Most institutions enabled FedNow receive capabilities first (lower fraud risk) and are now expanding to send. The send side is where the fraud exposure sits.

Pre-Authorization Fraud Scoring

Every FedNow send transaction should be scored against a real-time risk model before authorization. The model should incorporate:

  • Behavioral signals: Is this transaction consistent with the customer’s established payment patterns? First-time send, unusual amount, unusual time of day, and unusual recipient are all signals.
  • Device and session risk: Was the transaction initiated from a recognized device? Was the session flagged for unusual behavior (multiple failed logins, rapid navigation to the payment screen, IP anomalies)?
  • Velocity: How many FedNow sends has this customer initiated in the past 24 hours? What’s the total dollar amount?
  • Recipient risk: Is the receiving account associated with known fraud patterns? Has the receiving routing/account combination appeared in fraud alerts?

Institutions that can’t score in under six seconds need transaction holds with customer friction — a confirmation step, a call-back requirement, or a brief delay for high-risk transactions.

Transaction Limits and Controls

Blanket per-transaction and daily limits are table stakes, but limit design matters:

Customer SegmentRecommended Control Approach
New customers (< 90 days)Lower initial limit with gradual increase; manual review above threshold
High-value send requestsStep-up authentication before authorization
Recipient mismatch (payee name ≠ account name)Warning screen with explicit acknowledgment; potential hold
Unverified send requests (no prior payment relationship)Enhanced friction, limit cap

The UK’s Confirmation of Payee controls — which prompt consumers before completing a payment when the account name doesn’t match the beneficiary name — cut authorized push payment fraud by approximately 35% after introduction. US instant payment rails don’t yet mandate equivalent controls, but institutions can implement similar name-matching verification unilaterally.

Consumer Education

Authorized push payment fraud works because consumers don’t recognize the scam in progress. Fraud controls that put a friction moment in front of the consumer — a clear warning message before they complete a send — materially reduce loss rates.

Effective consumer education for instant payments includes:

  • Pre-authorization warnings for new recipients: “Once sent, this payment cannot be reversed.”
  • Scam identification reminders triggered by high-risk patterns: “Banks, government agencies, and utilities will never ask you to transfer money to a ‘safe account.’”
  • Post-authentication confirmations for high-value sends: Step-up authentication with a specific reason-for-payment prompt.

Recall and Recovery Protocols

When a consumer reports a fraudulent outbound send, institutions need a documented recall protocol:

  1. Immediate hold request: Contact the receiving institution’s fraud line immediately. FedNow does not have a built-in recall mechanism, but receiving institutions may cooperate with voluntary hold requests if contacted quickly.
  2. FinCEN notification: For losses meeting materiality thresholds, coordinate with FinCEN’s Financial Fraud Kill Chain for potential recovery assistance.
  3. Law enforcement referral: CISA and FBI’s Internet Crime Complaint Center (IC3) maintain relationships with financial institutions for rapid-response fraud recovery. Losses above institutional thresholds warrant IC3 reporting.
  4. SAR filing: Coordinated fraud events — particularly those involving multiple victims or institutions — typically require SAR filing regardless of whether a recall succeeds.

For comparison, the wire transfer fraud incident response playbook covers the UCC 4A liability framework for wire fraud; instant payments operate outside that framework but can use similar rapid-response protocols.

Fraud KRIs for Instant Payments

Most existing fraud monitoring programs track ACH return rates, debit card fraud rates, and wire fraud losses. None of those metrics capture instant payments fraud exposure.

Institutions that have enabled FedNow or RTP send capabilities need instant payments-specific KRIs:

KRIMeasurementThreshold Signal
APP fraud loss rateFraud losses per $1M settledRising trend against baseline
First-time send rate% of sends to new recipientsSpike above established range
High-risk send rate% flagged by pre-authorization scoringTrend up (increasing fraud attempt volume)
Dispute rateCustomer disputes per 1,000 sends> 0.5% warrants investigation
Recall cooperation rate% of requests where receiving FI cooperates< 50% signals process gaps
Consumer education completion% of first-time send users completing education< 80% is a control gap

These metrics should feed into your existing operational risk monitoring program. The fraud KRI examples for fintech and banking teams covers threshold calibration methodology — the core principle is that KRI thresholds calibrated at today’s volume may be meaningless as instant payments volume grows.

For institutions building out a KRI program, the KRI Library (132 Key Risk Indicators) includes payment-specific fraud metrics with pre-calibrated green/amber/red thresholds across operational, compliance, and financial risk domains.

Connecting Instant Payments to Your Operational Loss Program

Instant payments fraud losses need to flow into your operational loss event database — they’re not just fraud department statistics. BCBS 356 loss event categories cover external fraud, and FedNow-related losses belong in your operational risk data set for RCSA and capital modeling purposes.

For institutions with a formal operational loss database, classify instant payments fraud losses under External Fraud — Payments/Transfers, with a note on authorization status (authorized vs. unauthorized). Track separately from card fraud and ACH fraud to understand the rail-specific exposure. The operational loss data collection framework covers the database requirements that support this classification.

Institutions that lump all fraud losses into a single bucket will have difficulty defending their instant payments risk assessment to an examiner — particularly if the FDIC or OCC starts treating instant payments fraud as a named examination priority, which the FDIC’s 2026 Risk Review language suggests is coming.

What Examiners Will Ask

The FFIEC Retail Payment Systems Booklet (updated most recently for cloud-era risk) explicitly covers operational risk assessment requirements for new payment services. Examiners following this booklet will ask:

  • Did the institution conduct a formal risk assessment before enabling FedNow send capabilities?
  • Does the institution have documented transaction limits with documented rationale for those limits?
  • Is there a real-time fraud scoring capability for instant payment transactions?
  • How does the institution handle consumer-reported authorized push payment scams?
  • Has the institution reviewed and responded to the FPC’s fraud dispute resolution guiding principles?

The Nacha ACH fraud monitoring Phase 2 compliance post describes the kind of documentation regulators expect for payment rail fraud monitoring programs — similar documentation expectations apply to FedNow and RTP, even without the formal Nacha rule structure.

So What?

Instant payments are not optional in 2026. Your customers expect them; your competitors offer them; your bank partners and processors have built infrastructure around them. The question is not whether to offer FedNow or RTP, but whether your operational risk framework has caught up with the payment rails you’ve enabled.

If you enabled FedNow receive before send, you’ve had time to observe the incoming fraud patterns from your network without carrying the liability. If you’ve now enabled send, the liability clock is running. The controls that protect you aren’t the same ones that covered ACH and wire — they need to account for irrevocability, the authorized push payment gap in Reg E, the six-second scoring window, and the FPC dispute resolution principles that the industry is coalescing around.

The institutions that build these controls now — before volume scales and before the fraud industry shifts attention to the rail — are the ones that will be in front of any examiner conversation rather than behind it.


Related reading: Account Takeover Incident Response: The Reg E Liability Playbook covers how Reg E error resolution applies when an account is compromised; the liability analysis for authorized push payment fraud follows a different path but raises similar documentation questions.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does Regulation E protect consumers against authorized push payment fraud on FedNow or RTP?
Partially. Reg E covers unauthorized electronic fund transfers — transactions the consumer didn't initiate or authorize. Authorized push payment scams, where a fraudster tricks a consumer into voluntarily sending money, generally fall outside Reg E's error resolution framework. The consumer authorized the payment; the bank executed it. The FPC's May 2026 guiding principles address this gap with voluntary dispute resolution standards, but no federal mandate for reimbursement exists in the US, unlike the UK's mandatory APP fraud reimbursement rule.
What is the window for recalling a fraudulent FedNow payment?
Effectively zero. FedNow settles in seconds and payments are final upon posting. There is no ACH-style return window or SWIFT gpi recall mechanism. Some receiving institutions may voluntarily cooperate with recall requests, but there is no obligation to do so. The FBI's Financial Crimes Enforcement Network (FinCEN) and the Financial Fraud Kill Chain may assist with recovery in coordinated fraud cases, but the practical recovery window is measured in minutes, not hours or days.
What fraud controls does the Faster Payments Council recommend for FedNow and RTP?
The FPC's May 2026 Instant Payments Fraud Dispute Resolution: Guiding Principles for the U.S. includes 11 principles covering: risk-based fraud screening before payment authorization, standardized messaging for fraud dispute communication between sending and receiving institutions, clear delineation of operational responsibilities for each institution, streamlined dispute processes that preserve payment speed and integrity, and consumer education requirements. The principles are voluntary guidance, not regulation.
How is instant payments fraud different from wire transfer fraud or ACH fraud?
Wire transfer fraud is covered by UCC 4A's commercially reasonable security procedure framework — banks that follow commercially reasonable procedures shift liability to the customer. ACH fraud has a return window (typically 2 business days for unauthorized entries). Instant payments combine wire-level finality with consumer-facing Reg E applicability and a 6-second authorization window. The liability framework is materially more complex than either ACH or wire, and controls designed for those rails don't directly translate.
What fraud KRIs should financial institutions track for FedNow and RTP?
The most important instant payments fraud KRIs include: real-time payment fraud loss rate (dollars lost per $1M settled), suspicious transaction flag rate (flags per 1,000 transactions), first-party fraud detection rate by product channel, average time-to-detect for confirmed fraud events, customer dispute rate for instant payment transactions, percentage of transactions cleared without real-time scoring, and Rule 0 payment volume (where institutions waive fraud holds). Each should have green/amber/red thresholds calibrated quarterly as volume grows.
Are there regulatory examination expectations for instant payments fraud controls?
Yes. FFIEC expects financial institutions to assess operational risk before offering new payment services. Examiners applying the Information Technology Booklet and Retail Payment Systems Booklet will evaluate whether the institution conducted a risk assessment before enabling FedNow receive/send capabilities, has documented fraud controls and monitoring procedures, maintains transaction limits calibrated to risk, and conducts testing of fraud detection capabilities. FDIC's 2026 Risk Review flagged payment system fraud as an emerging operational risk area for community banks.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.