Feature Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Table of Contents
A consumer bank customer sends a $3,200 FedNow payment to what they believe is their property management company. It’s a spoofed invoice. The money arrives in a fraudster’s account in seconds and is immediately withdrawn via ATM in another state. Three hours later, the consumer calls your fraud line to report the fraud.
By the time the investigation starts, the funds are gone and irrecoverable.
The customer expects their bank to refund the money. Your Reg E error resolution procedures say the institution must complete an investigation within 10 business days or provisionally credit the account. But your error resolution procedures were written for ACH — where you could initiate a return within two business days. For instant payments, the ACH playbook doesn’t translate.
This is the error resolution gap that most institutions haven’t fixed yet.
TL;DR
- Regulation E error resolution requirements apply to FedNow and RTP consumer transactions — the same 10-business-day provisional credit and 45-calendar-day investigation timelines apply
- Instant payment irrevocability means the fraud controls must be pre-payment; Reg E’s investigation obligations still apply post-payment, even when recovery is impossible
- Authorized push payment (APP) fraud — where the consumer authorized the transfer — may fall outside Reg E’s unauthorized transfer protections; your procedures need to document both scenarios
- Most error resolution procedures written for ACH don’t account for instant payment characteristics, creating documented compliance gaps
- FedNow’s payment recall mechanism exists but is advisory — receiving institutions can decline; your investigation documentation should reflect recall attempts and outcomes
- CFPB examiners are checking whether Reg E disclosures and procedures have been updated for instant payments
Why Your ACH Error Resolution Playbook Doesn’t Work for FedNow
Traditional ACH error resolution worked because ACH had return codes. If a consumer reported an unauthorized ACH debit, the sending institution could initiate an ACH return within two business days. The return is settled through the same network that processed the original debit. The consumer gets their money back through a defined, bilateral mechanism.
Instant payments don’t work that way.
When a FedNow or RTP payment settles, the transfer is final. The receiving institution has no obligation to return the funds. FedNow introduced a Request for Payment Recall (RPRQ) message type — a mechanism for asking the receiving institution to send the money back — but accepting the recall is at the receiving institution’s discretion. There is no mandatory return window. If the account has been emptied, the recall will be denied and the funds are gone.
This creates a structural problem for error resolution: Reg E imposes obligations that assume the institution can do something about the disputed transaction. For unauthorized instant payments where the recipient account has already been emptied, the “investigation” is largely documenting why recovery failed — not reversing the transaction.
Financial institutions that copied their ACH Reg E procedures and relabeled them for FedNow have a documented compliance gap. The procedures don’t address the different recovery environment, the different consumer disclosure requirements, and the different basis for provisional credit decisions.
Reg E Error Resolution: What the Regulation Actually Requires
Under 12 CFR 1005.11, a financial institution that receives an error notice from a consumer must:
Within 10 business days of receiving the error notice:
- Complete the investigation and report the results to the consumer, or
- Provisionally credit the consumer’s account for the amount of the alleged error and notify the consumer of the provisional credit
If provisional credit is issued:
- Complete the investigation within 45 calendar days (standard) or 90 calendar days (new accounts, POS transactions outside the US, or foreign-initiated transactions)
- Determine whether an error occurred and report the results to the consumer within 1 business day of completing the investigation
- Correct the error within 1 business day if an error is confirmed
- Reverse provisional credit within 5 business days if no error is found
Provisional credit details:
- The institution may withhold up to $50 from the provisional credit if it reasonably believes the consumer was negligent
- The consumer has full use of provisional funds during the investigation
- If the institution requires written confirmation of an oral error notice and does not receive it within 10 business days, provisional credit is not required
These timelines are the same for FedNow, RTP, and ACH consumer transactions. The difference is not the legal obligation — it is what the institution can actually do during the investigation.
The Unauthorized vs. Authorized Transfer Distinction
This is the compliance fork that determines everything else about how an instant payment dispute is handled.
Unauthorized transfer (Reg E applies in full): The consumer did not initiate the transaction. Someone else accessed their account and sent money without their knowledge or consent — account takeover, stolen credentials, unauthorized access. Reg E’s error resolution requirements apply: 10-business-day provisional credit timeline, 45-day investigation window, full consumer liability protections under 12 CFR 1005.6.
Authorized transfer (different framework): The consumer initiated the transaction and authorized it. The consumer was deceived about where the money was going — APP fraud, invoice fraud, romance scam, impersonation fraud — but the transaction itself was authorized. This is technically not an “error” under the EFTA definition. The consumer authorized the electronic fund transfer; the problem is that they were deceived about the recipient’s identity.
The authorized transfer distinction is where most consumers expect protection and where Reg E’s coverage is narrowest. The consumer’s liability under 12 CFR 1005.6 is limited for unauthorized transfers, but there is no equivalent liability cap for authorized transfers to a fraudster.
This doesn’t mean institutions have no obligation when APP fraud occurs. UDAAP, your account agreement representations, and state consumer protection laws may create additional obligations. But the specific Reg E error resolution timelines and provisional credit requirements are designed for unauthorized transfers — and your procedures need to clearly explain both scenarios and the different consumer outcomes in each.
What Your Instant Payment Error Resolution Procedures Need to Say
Most ACH-era Reg E procedures contain some version of this:
“If you believe your account has been debited without your authorization, contact us within 60 days of the statement date. We will investigate and respond within 10 business days.”
That’s incomplete for instant payments. Here’s what the procedures need to address:
1. Scope Clarity: Which Transaction Types Are Covered
Your procedures should explicitly include FedNow and RTP in the list of covered electronic fund transfer types. Procedures that list “ACH transfers, wire transfers, and debit card transactions” without mentioning instant payments leave an ambiguity that CFPB examiners will flag.
2. How “Error” Is Defined for Instant Payments
12 CFR 1005.11(a) defines error categories. For instant payments, the most relevant are:
- An unauthorized electronic fund transfer
- An incorrect electronic fund transfer — wrong amount, wrong account, wrong date
- Failure to properly identify in a statement an EFT that was made
Your procedures need to walk through which categories apply to FedNow/RTP transactions — including the distinction between unauthorized transactions (Reg E fully applies) and authorized-but-disputed transactions (different framework).
3. Recovery Attempt Documentation
For unauthorized instant payment claims, document your recall attempt process:
| Step | Timeline | Documentation |
|---|---|---|
| Initiate RPRQ recall via FedNow | Same business day as error report | Recall request ID, timestamp |
| Receive recall outcome from receiving institution | Per FedNow operating rules | Acceptance or denial response |
| If denied: document funds availability status | Before closing investigation | Evidence of denial, account status if obtainable |
| Escalate to FedNow network exception process | If applicable | Exception case number |
| Document final recovery determination | Before investigation deadline | Recovery amount (if any) or zero recovery with reason |
The recall attempt — and its outcome — is part of your investigation record. If you didn’t attempt a recall, document why not.
4. Provisional Credit Decision Criteria for Instant Payments
Your procedures should specify the basis on which provisional credit is issued for instant payment claims. The 10-business-day clock is the same regardless of irrevocability — you can’t extend the timeline because the payment was instant and the funds are gone.
Consider whether your procedures address:
- The criteria for issuing provisional credit before the investigation is complete
- How the $50 withholding provision applies to instant payment claims
- Whether provisional credit is appropriate for authorized-push-payment fraud claims (this is a separate decision from unauthorized transfer claims)
5. Consumer Notification Language
Your initial error notice disclosures and the notifications you send during the investigation must accurately describe what happens in the instant payment error resolution process. If your standard Reg E disclosure says “if an error occurred, we will reverse the transaction and restore your funds within X days,” that may be inaccurate for instant payments where reversal is not possible. Inaccurate disclosures are a UDAAP risk on top of the Reg E compliance issue.
The FedNow Recall Mechanism: What It Is and What It Isn’t
FedNow’s Request for Payment Recall (RPRQ) is the operational tool that sending institutions can use to attempt recovery of unauthorized instant payments after settlement. Understanding what it actually does is important for setting both consumer expectations and your own investigation process.
What a recall does: It sends a message to the receiving institution requesting that they return the funds. The receiving institution receives the request, reviews it, and decides whether to comply.
What a recall doesn’t do: It doesn’t freeze the recipient account. It doesn’t compel the receiving institution to return the funds. If the account has been emptied and the money withdrawn, the receiving institution has nothing to return even if they want to cooperate.
Timeline: FedNow operating rules govern how quickly a receiving institution must respond to a recall request. The sending institution’s investigation documentation should track the recall response timeline.
Outcome documentation: Whether the recall succeeds or fails, the outcome is relevant to your investigation. A successful recall changes the consumer’s outcome. A denied recall documents why funds were not recovered. An unanswered recall or a lack of funds at the receiving account after a reasonable period is evidence for your investigation record.
For institutions routing instant payments through a middleware provider or banking-as-a-service platform, confirm whether your platform initiates recall requests on your behalf and how that is documented in your investigation records.
Where CFPB Examiners Are Finding the Gaps
CFPB examination activity in 2026 has focused on whether institutions’ Reg E programs have been updated for instant payment characteristics. The most commonly cited gaps:
Written procedures that reference ACH-specific processes: Procedures that walk through ACH return codes, R10 authorization disputes, and ACH-specific timelines without any mention of FedNow or RTP. Examiners cite this as evidence that the institution hasn’t meaningfully addressed instant payment error resolution.
Disclosures that mismatch instant payment reality: Consumer-facing disclosures that describe “reversing” or “canceling” a payment when the institution knows the payment is irrevocable. Describing instant payment dispute outcomes in language that implies reversal when recovery isn’t possible is a UDAAP concern.
No documentation of recall attempts: Institutions closing unauthorized FedNow payment investigations without evidence that a recall was attempted. Even a denied recall needs to be in the file.
APP fraud claims handled without a documented framework: Institutions receiving APP fraud reports and improvising case-by-case responses without a documented process for how authorized-but-disputed instant payment transfers are handled, what the consumer is told, and what recovery efforts (if any) the institution makes.
Provisional credit decisions lacking a documented basis: Investigation files where the institution issued (or denied) provisional credit on an instant payment claim without documentation of what criteria informed the decision.
The Zelle Precedent You Should Know
Zelle — the bank-operated instant payment network backed by Early Warning Services — provides useful reference points for how regulators approach authorized push payment fraud in faster payment contexts, even though Zelle operates under a different network structure than FedNow and RTP.
In 2022 and 2023, the Senate Permanent Subcommittee on Investigations documented widespread Zelle APP fraud, with participating banks recovering less than 50% of disputed authorized transfers. The CFPB initiated supervisory activity against Zelle participants, citing concerns about how banks handled consumer complaints about authorized-but-disputed Zelle transfers.
The practical lessons for FedNow and RTP programs:
- Consumer-facing materials should accurately describe what protections exist for authorized transfers — and what protections don’t exist
- Having a documented process for reviewing APP fraud claims demonstrates you’re applying consistent criteria — rather than making case-by-case decisions that regulators can characterize as arbitrary
- Reimbursement policies for APP fraud, if you have them, need to be clearly documented and consistently applied
The Zelle experience also accelerated industry discussions about whether banks should voluntarily reimburse certain APP fraud losses — discussions that have shaped what examiners expect to see documented, even if no mandatory reimbursement requirement currently applies to FedNow and RTP.
So What?
The FedNow Network Intelligence API launched in April gave institutions a new tool to prevent instant payment fraud before it happens. The fraud risk controls post from July 22 covered the pre-payment side of that picture.
But the error resolution obligations are the post-payment side — and they apply regardless of how sophisticated your pre-payment controls are. When a fraud gets through, Reg E has something to say about how quickly you must act, what you must provisionally credit, and what you must document.
Most institutions with strong ACH error resolution programs have a documentation gap for instant payments — not because they’re doing the wrong thing operationally, but because the written procedures, consumer disclosures, and investigation documentation templates weren’t updated when FedNow went live. That’s the gap CFPB examiners are finding.
The fix isn’t complex. Update the procedures to include FedNow and RTP by name. Add a section distinguishing unauthorized vs. authorized transfers. Document the recall attempt process. Confirm your consumer disclosures accurately describe instant payment dispute outcomes. Review and update the investigation file templates to capture recall attempts, their outcomes, and the basis for provisional credit decisions.
The instant payments fraud controls guide from June 2026 covers the control architecture side. The error resolution program is what your examiners will check first when a consumer complaint comes in.
Error Resolution Compliance Checklist for Instant Payments
Use this to assess where your current Reg E program has instant payment gaps:
Procedures and Policies
- Written error resolution procedures explicitly cover FedNow and RTP consumer transactions
- Procedures define “error” for instant payments and distinguish unauthorized from authorized-push-payment transfers
- Procedures specify provisional credit criteria for unauthorized instant payment claims
- APP fraud claims have a documented handling framework separate from unauthorized transfer error resolution
Investigation Documentation
- Standard investigation file template captures recall attempt initiation and outcome
- Basis for provisional credit decisions is documented in each file
- Investigation closure documentation specifies whether and why recovery was not possible
Consumer Disclosures
- Initial error notice disclosures are accurate for instant payment dispute outcomes — no language implying reversal when irrevocability is the norm
- Consumer notifications during investigation reflect instant payment characteristics
- APP fraud disclosure explains what protections apply (and which don’t) when the consumer authorized the transfer
Staff and Training
- Fraud line staff trained on the different handling process for FedNow vs. ACH error reports
- Investigation staff understand when a recall attempt is appropriate and how to document it
- Staff have documented guidance on how to handle APP fraud claims that don’t meet the unauthorized transfer definition
FAQ
Does Regulation E apply to FedNow and RTP transactions?
Yes. The EFTA and Regulation E apply to electronic fund transfers from consumer accounts, including FedNow and RTP credit-push instant payments.
What are the investigation timelines for instant payment error reports?
Same as ACH: report results within 10 business days, or issue provisional credit within 10 business days and complete investigation within 45 calendar days (90 calendar days for new accounts, foreign transactions, or POS transactions).
What is APP fraud and does Reg E protect consumers?
Authorized push payment fraud is where the consumer was deceived into sending a payment to a fraudster. Because the consumer authorized the transaction, it may not qualify as an “error” under Reg E’s unauthorized transfer definition. Reg E’s standard error resolution obligations are designed for unauthorized transfers. APP fraud requires a separate documented handling framework.
Does FedNow have a way to recall payments?
FedNow has a Request for Payment Recall (RPRQ) message type that allows sending institutions to request return of a settled payment. The receiving institution may accept or decline the recall. It is not a mandatory return mechanism.
What should investigation files for instant payment disputes contain?
At minimum: date and manner of error notice; description of the alleged error; recall attempt and outcome; basis for any provisional credit decision; investigation findings; consumer notification dates; and final determination of whether an error occurred.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does Regulation E apply to FedNow and RTP transactions?
What are the Reg E error resolution timelines that apply to instant payment disputes?
What is authorized push payment (APP) fraud, and why does it create a unique problem for Reg E compliance?
What does a compliant Reg E error resolution procedure for instant payments actually need to include?
Are there specific CFPB examination concerns about instant payment error resolution?
What is FedNow's payment recall mechanism, and how does it interact with the Reg E investigation?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
FinCEN Extended 314(b) to Fraud: The Safe Harbor Most Financial Institutions Are Still Ignoring
On June 12, 2026, FinCEN updated its Section 314(b) Fact Sheet to explicitly cover fraud — including pig butchering, romance scams, and mule account activity. Institutions can now share transaction records, device data, IP addresses, and video footage in real time with other registered participants. Here's what changed, what you can and can't share, and why most compliance teams are leaving this tool unused.
Jul 21, 2026