Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Operational Risk

FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.

On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.

By Rebecca Leung · July 21, 2026 ·
Table of Contents

A $340,000 wire transfer happened in early 2026 at a mid-market manufacturer. The AP manager got a video call that looked and sounded exactly like the CFO — same face, same voice, same communication style — requesting an urgent payment to a new vendor account. The funds moved. The CFO had been traveling and found out from the bank’s fraud team.

That’s a deepfake-enabled authorized push payment fraud. The attacker needed three seconds of audio and a few photos to build the clone. They needed one compliant employee and one company with inadequate pre-authorization controls to collect.

Most authorized push payment fraud is less sophisticated than that — a convincing email, a spoofed vendor invoice, a social engineering call that hits an employee at exactly the right moment. What makes instant payments dangerous for all of it is the same thing: once the payment leaves your institution over FedNow, it’s gone. There’s no ACH return window. There’s no card chargeback mechanism. The fraud controls have to work before the payment is sent.

On April 28, 2026, the Federal Reserve Financial Services launched the FedNow Network Intelligence API — a tool that gives participating institutions pre-payment access to receiver account behavioral data derived from activity across the entire FedNow network. It’s the kind of signal no single institution could generate internally, and it changes what fraud risk programs for instant payments can do.

Most institutions haven’t updated their programs to reflect it.

TL;DR

  • The FedNow Network Intelligence API launched April 28, 2026, giving participating institutions pre-payment receiver account risk signals derived from historical FedNow network data
  • Authorized push payment (APP) fraud is the defining risk for instant payments — once a FedNow payment is sent, funds are typically irrevocable
  • The API complements existing internal controls; it doesn’t replace them, and it isn’t a compliance safe harbor
  • Payee Name Verification — a feature that would confirm the payee name matches the receiving account before payment — is under development but not yet live
  • Fraud policies, procedures, and KRIs written for ACH or card fraud don’t translate directly to instant payments; you need specific instant payment fraud controls

What Changed on April 28, 2026

Before the Network Intelligence API, a FedNow participant’s fraud controls operated entirely on internal data. You knew your customer’s behavior, their account history, their device fingerprint. You didn’t know anything about the receiver account — whether it was newly opened, whether it had been receiving unusual volumes from multiple senders, whether it was exhibiting the behavioral patterns seen in mule accounts.

That’s a significant gap for instant payment fraud. The most sophisticated fraud schemes route funds through accounts specifically chosen because no single sending institution has enough transaction history to flag them.

The Network Intelligence API gives participating institutions a network-level view. The Federal Reserve has visibility across all FedNow participants and can aggregate behavioral patterns at the receiver account level — how long an account has been active on FedNow, whether incoming payment patterns deviate from historical norms, signals that indicate anomalous or high-risk activity that a single institution’s internal controls would miss.

According to the Federal Reserve Financial Services, the API “delivers instant, network-level data insights that complement participants’ existing risk management capabilities” and provides “instant, pre-transaction insights derived from system-wide behavioral trends.” The data enriches over time as the FedNow network accumulates more transaction history.

In practical terms: before you send a $50,000 FedNow payment to an account your institution has never transacted with, you can now query the API and receive a risk signal based on what the entire FedNow network knows about that receiving account.


The Fraud Risk Architecture for Instant Payments

Instant payment fraud risk requires a different mental model than ACH or card fraud risk. The architecture has to be front-loaded.

Layer 1: Sender Authentication and Anomaly Detection

Your first line of defense is knowing the customer sending the payment is who they say they are. This means:

  • Strong multi-factor authentication on payment initiation, especially for high-value transactions
  • Behavioral analytics to flag deviations from established payment patterns (new payee, unusual amount, unusual time, new device)
  • Out-of-band confirmation procedures for high-dollar transfers — phone call to a verified number, not a number provided in the payment request

This layer is mature in most institutions but often hasn’t been tuned for instant payment risk specifically. The risk profile of a customer initiating a $50,000 FedNow credit transfer to a new account is meaningfully different from the same customer paying a utility bill through bill pay.

Layer 2: Transaction Screening and Network Intelligence

This is where the API plugs in. Before the payment is authorized:

  • Screen the receiving routing number and account against your internal database of known fraud accounts
  • Query the FedNow Network Intelligence API for receiver account risk signals
  • Cross-reference the payment against your own institution’s FedNow transaction history for that receiver account
  • Check for patterns consistent with business email compromise: last-minute changes to payee account details, payments redirected to newly registered accounts, instructions delivered by email only with no follow-up call

The API query happens in milliseconds. FedNow payment processing happens in seconds. The API was designed to operate at instant payment speed — a slow API that introduces friction defeats the purpose.

Layer 3: Hold and Review Procedures

Not every suspicious transaction should be declined outright. Your procedures need to define:

  • Transaction hold criteria: what triggers a manual review rather than automatic approval or rejection?
  • Hold duration: how long can you hold an instant payment before you must release or decline it?
  • Escalation path: who reviews held transactions and what information do they have access to?
  • Customer contact procedures: for high-risk transactions, do you contact the customer to verify intent before sending?

This is where many institutions’ written procedures are weakest. ACH and wire procedures often have hold and review frameworks; instant payment procedures frequently don’t.

Layer 4: Post-Payment Monitoring and Reporting

Because most fraud controls have to happen before the payment, post-payment monitoring serves two purposes: identifying compromised accounts quickly to limit ongoing losses, and building the intelligence that makes pre-payment controls more effective over time.

Post-payment monitoring for instant payments should include:

  • Real-time alerts when outbound FedNow volume exceeds defined thresholds
  • Monitoring for rapid sequential outbound payments to the same receiver
  • Pattern detection for payments that follow known fraud typologies (odd hours, amounts just below review thresholds, payments to accounts opened within the last 30-90 days)

What Your Fraud Policies and Procedures Need to Say

If your institution’s instant payment fraud policy was written when you onboarded to FedNow in 2023 or 2024, it almost certainly doesn’t address the Network Intelligence API. Here’s what the updated documentation should cover:

In your fraud risk policy:

  • Explicit acknowledgment that instant payment fraud carries distinct risk characteristics from ACH, wire, and card fraud — particularly the irrevocability of sent payments
  • Definition of “authorized push payment fraud” as a fraud typology your program addresses
  • Reference to the FedNow Network Intelligence API as a compensating control in your instant payment fraud framework

In your fraud procedures:

  • Specific transaction amounts or risk scores that trigger pre-payment review or hold
  • Step-by-step process for API query integration into payment authorization workflow
  • Employee escalation procedures when API signals return elevated risk
  • Customer-facing procedures: when and how your institution contacts customers about potentially fraudulent outbound payments they initiated

In your KRI library:

  • FedNow transaction volume vs. fraud loss rate (monthly tracking)
  • Percentage of high-value FedNow transactions flagged for review vs. percentage approved without intervention
  • Mean time to detect and respond to confirmed instant payment fraud events
  • API query hit rate: percentage of queried transactions that return elevated risk signals

The OCC’s Spring 2026 Semiannual Risk Perspective identified fraud risk — including APP fraud — as an elevated concern. Examiners evaluating your fraud risk program in 2026 will be looking at whether your instant payment controls are proportionate to the risk.


Payee Name Verification: The Feature Examiners Will Eventually Ask About

In the UK, a feature called Confirmation of Payee (CoP) — which verifies that a payment recipient’s name matches the account details before a payment is sent — is credited with significantly reducing APP fraud since its implementation. UK payment companies are legally required to implement it.

The Federal Reserve described Payee Name Verification — the FedNow equivalent — as a feature under active development at the April 2026 API launch. No specific launch date has been announced.

When it launches, Payee Name Verification will represent a meaningful upgrade to the fraud controls available to FedNow participants: a customer who has been tricked into sending money to a fraudster’s account will see that the payee name doesn’t match before confirming the payment. For business email compromise schemes that redirect payments to accounts registered under different business names, it’s a direct control.

Prudent fraud risk programs should note Payee Name Verification as a planned enhancement and build the expectation of eventual integration into future-state controls documentation. When examiners see a fraud risk program that doesn’t acknowledge the feature’s development, it reads as a program that isn’t tracking the tool landscape.


What Examiners Will Ask

Examiners evaluating instant payment fraud risk in 2026 are looking at this landscape:

  • Is your institution using available risk mitigation tools, including the Network Intelligence API?
  • Are your fraud policies and procedures specific to instant payments, or are they generic templates retrofitted from ACH or wire controls?
  • Have you tested your pre-payment controls against known fraud typologies — business email compromise, romance scam payments, invoice fraud?
  • What are your thresholds for holding an instant payment for manual review, and how were they set?
  • How do you handle high-dollar or high-risk FedNow payments to first-time payees?
  • What do your KRIs look like for instant payment fraud, and how often is the board or senior management seeing them?

The existing controls for instant payment fraud post from June covered the baseline framework. What changed in April is that the pre-payment intelligence layer got a meaningful upgrade — and your program documentation should reflect it.


How FedNow Risk Fits Into Broader Third-Party and Operational Risk

FedNow itself is critical infrastructure for institutions that use it — a third-party relationship with the Federal Reserve Financial Services that deserves treatment as a critical vendor under your third-party risk management program. That means continuity planning for FedNow unavailability, documented SLA expectations, and a process for monitoring Federal Reserve communications about service changes, including the Network Intelligence API.

The April launch was communicated through Federal Reserve Financial Services channels in advance. Institutions that treat their FedNow participant relationship as a static utility connection rather than an active vendor relationship missed the preparation window.

Fourth-party dependencies matter here too. When the FedNow Network Intelligence API draws on network-wide behavioral data, the quality of that intelligence depends on broad participation. Institutions that haven’t queried the API or aren’t active FedNow participants contribute less signal to the network and benefit less from it. The fourth-party risk considerations that emerged from payment network failures apply here in a different way: your fraud intelligence is partially dependent on what the broader participant network is doing.


So What?

The FedNow Network Intelligence API is live. The data is available. The fraud intelligence is there to be used.

Most institutions haven’t updated their fraud risk policies, their procedures, or their KRIs to account for what it changes. The pre-payment intelligence layer for instant payments just got meaningfully better — and fraud programs written in 2023 when FedNow launched don’t reflect that.

Authorized push payment fraud — the kind where your customer is the one initiating the fraudulent payment, not a hacker — is the instant payment fraud risk that existing controls underaddress. It has to be caught before the payment is sent, because once it’s sent, the recovery options are thin.

The API is one tool. Payee Name Verification will be another when it arrives. The fraud policy, the customer authentication controls, the hold and review procedures, and the KRIs are the framework that makes those tools do something beyond generating alerts no one acts on.

If you haven’t reviewed your instant payment fraud program since you onboarded to FedNow, the April 2026 API launch is a reasonable trigger to do it now.


The Federal Reserve Financial Services press release on the Network Intelligence API is publicly available. FinTech Global’s analysis of what the API means for pre-payment risk data provides practitioner context. PYMNTS covered the FedNow security fortification announcement. The Federal Reserve’s FedNow Fraud at a Glance resource describes the FraudClassifier model and other risk mitigation tools available to participants.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the FedNow Network Intelligence API?
The FedNow Network Intelligence API is a fraud risk tool launched April 28, 2026, by the Federal Reserve Financial Services. It gives FedNow participating financial institutions access to pre-transaction risk insights derived from historical, system-wide FedNow network activity. Before approving a payment, a participating institution can query the API to retrieve data about the receiver account's observed behavior across the network — how long the account has been active on FedNow, transaction patterns, and behavioral anomalies. The API is designed to complement — not replace — an institution's internal fraud controls by adding a network-level signal that no single institution could generate on its own.
What data does the FedNow Network Intelligence API actually provide?
The API provides receiver account-level data observed across the FedNow network — specifically, insights derived from historical FedNow activity associated with the recipient account and routing number. This includes behavioral trend information that the Federal Reserve can observe at network scale: account age on the network, payment volume and frequency patterns, and signals of anomalous activity that deviate from typical account behavior. The API does not return detailed transaction records of other institutions; it returns aggregated risk signals. The data enriches over time as FedNow accumulates more network history.
Does using the FedNow Network Intelligence API satisfy fraud program requirements?
No — the API is a risk tool, not a compliance safe harbor. Using the API supplements your existing fraud detection controls but doesn't substitute for written fraud risk policies, employee training, customer authentication controls, or an incident response process. What it does do is provide a signal your institution couldn't generate internally: network-level data across all FedNow participants. Examiners evaluating your instant payment fraud program will ask whether you're using available risk mitigation tools — and the API is now in that category.
What is Payee Name Verification, and when is it coming to FedNow?
Payee Name Verification is a feature the Federal Reserve announced it is exploring for FedNow. It would allow sending institutions to confirm whether the name provided by the sender for a payee actually matches the name associated with the recipient account at the receiving institution — before a payment is sent. This is a standard feature in UK faster payments (Confirmation of Payee) and is credited with significantly reducing authorized push payment fraud there. As of the April 2026 API launch, the Federal Reserve described Payee Name Verification as under development; no specific launch date has been announced.
What is authorized push payment (APP) fraud and why does it matter for FedNow?
Authorized push payment (APP) fraud occurs when a customer is deceived into willingly sending money to a fraudster — business email compromise, romance scams, fake vendor invoices, and grandparent scams are all APP fraud patterns. APP fraud is structurally different from unauthorized payment fraud (card fraud, account takeover) because the customer initiates the transaction. Traditional fraud controls that screen for unauthorized access don't catch APP fraud because the account holder is the one sending the payment. For FedNow, this matters acutely: once a FedNow payment is sent, the funds are typically irrevocable — there is no post-payment recall mechanism equivalent to ACH return windows. The entire fraud program has to be pre-payment.
How does the FedNow Network Intelligence API compare to other payment network fraud tools?
The network intelligence API is FedNow's equivalent to the fraud signals that card networks (Visa, Mastercard) and ACH (Nacha) have provided for years. Card networks use their visibility across billions of transactions to produce real-time fraud scores. FedNow is building equivalent network-level intelligence for instant credit transfers. The key difference from ACH is speed and irrevocability: ACH transactions can be returned within two business days; FedNow payments are final in seconds. The network intelligence API is how the Federal Reserve is addressing the fraud risk asymmetry created by that irrevocability.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.