Feature Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Table of Contents
A $340,000 wire transfer happened in early 2026 at a mid-market manufacturer. The AP manager got a video call that looked and sounded exactly like the CFO — same face, same voice, same communication style — requesting an urgent payment to a new vendor account. The funds moved. The CFO had been traveling and found out from the bank’s fraud team.
That’s a deepfake-enabled authorized push payment fraud. The attacker needed three seconds of audio and a few photos to build the clone. They needed one compliant employee and one company with inadequate pre-authorization controls to collect.
Most authorized push payment fraud is less sophisticated than that — a convincing email, a spoofed vendor invoice, a social engineering call that hits an employee at exactly the right moment. What makes instant payments dangerous for all of it is the same thing: once the payment leaves your institution over FedNow, it’s gone. There’s no ACH return window. There’s no card chargeback mechanism. The fraud controls have to work before the payment is sent.
On April 28, 2026, the Federal Reserve Financial Services launched the FedNow Network Intelligence API — a tool that gives participating institutions pre-payment access to receiver account behavioral data derived from activity across the entire FedNow network. It’s the kind of signal no single institution could generate internally, and it changes what fraud risk programs for instant payments can do.
Most institutions haven’t updated their programs to reflect it.
TL;DR
- The FedNow Network Intelligence API launched April 28, 2026, giving participating institutions pre-payment receiver account risk signals derived from historical FedNow network data
- Authorized push payment (APP) fraud is the defining risk for instant payments — once a FedNow payment is sent, funds are typically irrevocable
- The API complements existing internal controls; it doesn’t replace them, and it isn’t a compliance safe harbor
- Payee Name Verification — a feature that would confirm the payee name matches the receiving account before payment — is under development but not yet live
- Fraud policies, procedures, and KRIs written for ACH or card fraud don’t translate directly to instant payments; you need specific instant payment fraud controls
What Changed on April 28, 2026
Before the Network Intelligence API, a FedNow participant’s fraud controls operated entirely on internal data. You knew your customer’s behavior, their account history, their device fingerprint. You didn’t know anything about the receiver account — whether it was newly opened, whether it had been receiving unusual volumes from multiple senders, whether it was exhibiting the behavioral patterns seen in mule accounts.
That’s a significant gap for instant payment fraud. The most sophisticated fraud schemes route funds through accounts specifically chosen because no single sending institution has enough transaction history to flag them.
The Network Intelligence API gives participating institutions a network-level view. The Federal Reserve has visibility across all FedNow participants and can aggregate behavioral patterns at the receiver account level — how long an account has been active on FedNow, whether incoming payment patterns deviate from historical norms, signals that indicate anomalous or high-risk activity that a single institution’s internal controls would miss.
According to the Federal Reserve Financial Services, the API “delivers instant, network-level data insights that complement participants’ existing risk management capabilities” and provides “instant, pre-transaction insights derived from system-wide behavioral trends.” The data enriches over time as the FedNow network accumulates more transaction history.
In practical terms: before you send a $50,000 FedNow payment to an account your institution has never transacted with, you can now query the API and receive a risk signal based on what the entire FedNow network knows about that receiving account.
The Fraud Risk Architecture for Instant Payments
Instant payment fraud risk requires a different mental model than ACH or card fraud risk. The architecture has to be front-loaded.
Layer 1: Sender Authentication and Anomaly Detection
Your first line of defense is knowing the customer sending the payment is who they say they are. This means:
- Strong multi-factor authentication on payment initiation, especially for high-value transactions
- Behavioral analytics to flag deviations from established payment patterns (new payee, unusual amount, unusual time, new device)
- Out-of-band confirmation procedures for high-dollar transfers — phone call to a verified number, not a number provided in the payment request
This layer is mature in most institutions but often hasn’t been tuned for instant payment risk specifically. The risk profile of a customer initiating a $50,000 FedNow credit transfer to a new account is meaningfully different from the same customer paying a utility bill through bill pay.
Layer 2: Transaction Screening and Network Intelligence
This is where the API plugs in. Before the payment is authorized:
- Screen the receiving routing number and account against your internal database of known fraud accounts
- Query the FedNow Network Intelligence API for receiver account risk signals
- Cross-reference the payment against your own institution’s FedNow transaction history for that receiver account
- Check for patterns consistent with business email compromise: last-minute changes to payee account details, payments redirected to newly registered accounts, instructions delivered by email only with no follow-up call
The API query happens in milliseconds. FedNow payment processing happens in seconds. The API was designed to operate at instant payment speed — a slow API that introduces friction defeats the purpose.
Layer 3: Hold and Review Procedures
Not every suspicious transaction should be declined outright. Your procedures need to define:
- Transaction hold criteria: what triggers a manual review rather than automatic approval or rejection?
- Hold duration: how long can you hold an instant payment before you must release or decline it?
- Escalation path: who reviews held transactions and what information do they have access to?
- Customer contact procedures: for high-risk transactions, do you contact the customer to verify intent before sending?
This is where many institutions’ written procedures are weakest. ACH and wire procedures often have hold and review frameworks; instant payment procedures frequently don’t.
Layer 4: Post-Payment Monitoring and Reporting
Because most fraud controls have to happen before the payment, post-payment monitoring serves two purposes: identifying compromised accounts quickly to limit ongoing losses, and building the intelligence that makes pre-payment controls more effective over time.
Post-payment monitoring for instant payments should include:
- Real-time alerts when outbound FedNow volume exceeds defined thresholds
- Monitoring for rapid sequential outbound payments to the same receiver
- Pattern detection for payments that follow known fraud typologies (odd hours, amounts just below review thresholds, payments to accounts opened within the last 30-90 days)
What Your Fraud Policies and Procedures Need to Say
If your institution’s instant payment fraud policy was written when you onboarded to FedNow in 2023 or 2024, it almost certainly doesn’t address the Network Intelligence API. Here’s what the updated documentation should cover:
In your fraud risk policy:
- Explicit acknowledgment that instant payment fraud carries distinct risk characteristics from ACH, wire, and card fraud — particularly the irrevocability of sent payments
- Definition of “authorized push payment fraud” as a fraud typology your program addresses
- Reference to the FedNow Network Intelligence API as a compensating control in your instant payment fraud framework
In your fraud procedures:
- Specific transaction amounts or risk scores that trigger pre-payment review or hold
- Step-by-step process for API query integration into payment authorization workflow
- Employee escalation procedures when API signals return elevated risk
- Customer-facing procedures: when and how your institution contacts customers about potentially fraudulent outbound payments they initiated
In your KRI library:
- FedNow transaction volume vs. fraud loss rate (monthly tracking)
- Percentage of high-value FedNow transactions flagged for review vs. percentage approved without intervention
- Mean time to detect and respond to confirmed instant payment fraud events
- API query hit rate: percentage of queried transactions that return elevated risk signals
The OCC’s Spring 2026 Semiannual Risk Perspective identified fraud risk — including APP fraud — as an elevated concern. Examiners evaluating your fraud risk program in 2026 will be looking at whether your instant payment controls are proportionate to the risk.
Payee Name Verification: The Feature Examiners Will Eventually Ask About
In the UK, a feature called Confirmation of Payee (CoP) — which verifies that a payment recipient’s name matches the account details before a payment is sent — is credited with significantly reducing APP fraud since its implementation. UK payment companies are legally required to implement it.
The Federal Reserve described Payee Name Verification — the FedNow equivalent — as a feature under active development at the April 2026 API launch. No specific launch date has been announced.
When it launches, Payee Name Verification will represent a meaningful upgrade to the fraud controls available to FedNow participants: a customer who has been tricked into sending money to a fraudster’s account will see that the payee name doesn’t match before confirming the payment. For business email compromise schemes that redirect payments to accounts registered under different business names, it’s a direct control.
Prudent fraud risk programs should note Payee Name Verification as a planned enhancement and build the expectation of eventual integration into future-state controls documentation. When examiners see a fraud risk program that doesn’t acknowledge the feature’s development, it reads as a program that isn’t tracking the tool landscape.
What Examiners Will Ask
Examiners evaluating instant payment fraud risk in 2026 are looking at this landscape:
- Is your institution using available risk mitigation tools, including the Network Intelligence API?
- Are your fraud policies and procedures specific to instant payments, or are they generic templates retrofitted from ACH or wire controls?
- Have you tested your pre-payment controls against known fraud typologies — business email compromise, romance scam payments, invoice fraud?
- What are your thresholds for holding an instant payment for manual review, and how were they set?
- How do you handle high-dollar or high-risk FedNow payments to first-time payees?
- What do your KRIs look like for instant payment fraud, and how often is the board or senior management seeing them?
The existing controls for instant payment fraud post from June covered the baseline framework. What changed in April is that the pre-payment intelligence layer got a meaningful upgrade — and your program documentation should reflect it.
How FedNow Risk Fits Into Broader Third-Party and Operational Risk
FedNow itself is critical infrastructure for institutions that use it — a third-party relationship with the Federal Reserve Financial Services that deserves treatment as a critical vendor under your third-party risk management program. That means continuity planning for FedNow unavailability, documented SLA expectations, and a process for monitoring Federal Reserve communications about service changes, including the Network Intelligence API.
The April launch was communicated through Federal Reserve Financial Services channels in advance. Institutions that treat their FedNow participant relationship as a static utility connection rather than an active vendor relationship missed the preparation window.
Fourth-party dependencies matter here too. When the FedNow Network Intelligence API draws on network-wide behavioral data, the quality of that intelligence depends on broad participation. Institutions that haven’t queried the API or aren’t active FedNow participants contribute less signal to the network and benefit less from it. The fourth-party risk considerations that emerged from payment network failures apply here in a different way: your fraud intelligence is partially dependent on what the broader participant network is doing.
So What?
The FedNow Network Intelligence API is live. The data is available. The fraud intelligence is there to be used.
Most institutions haven’t updated their fraud risk policies, their procedures, or their KRIs to account for what it changes. The pre-payment intelligence layer for instant payments just got meaningfully better — and fraud programs written in 2023 when FedNow launched don’t reflect that.
Authorized push payment fraud — the kind where your customer is the one initiating the fraudulent payment, not a hacker — is the instant payment fraud risk that existing controls underaddress. It has to be caught before the payment is sent, because once it’s sent, the recovery options are thin.
The API is one tool. Payee Name Verification will be another when it arrives. The fraud policy, the customer authentication controls, the hold and review procedures, and the KRIs are the framework that makes those tools do something beyond generating alerts no one acts on.
If you haven’t reviewed your instant payment fraud program since you onboarded to FedNow, the April 2026 API launch is a reasonable trigger to do it now.
The Federal Reserve Financial Services press release on the Network Intelligence API is publicly available. FinTech Global’s analysis of what the API means for pre-payment risk data provides practitioner context. PYMNTS covered the FedNow security fortification announcement. The Federal Reserve’s FedNow Fraud at a Glance resource describes the FraudClassifier model and other risk mitigation tools available to participants.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the FedNow Network Intelligence API?
What data does the FedNow Network Intelligence API actually provide?
Does using the FedNow Network Intelligence API satisfy fraud program requirements?
What is Payee Name Verification, and when is it coming to FedNow?
What is authorized push payment (APP) fraud and why does it matter for FedNow?
How does the FedNow Network Intelligence API compare to other payment network fraud tools?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026
Operational Risk
AI-Enhanced Fraud Is Now the OCC's Top Operational Risk Concern. Here's What That Means for Your Fraud Risk Program.
The OCC's Spring 2026 Risk Perspective named fraud the primary driver of operational losses. But having a fraud operations team isn't a fraud risk program — examiners want second-line oversight, documented loss events, and KRIs that signal emerging exposure.
Jul 15, 2026