Skip to content
RiskTemplates · The Daily Brief Monday, September 21, 2026
Wire Nodus Bank CEO Sentenced: The Control Failures Behind a $24.9M Fraud and Sanctions Scheme SEP 20

Feature Operational Risk

Your FedNow Send Function Goes Live Next Quarter. Here's What Your Fraud Controls and Operational Risk Program Need Before the First Transaction.

With 1,700+ FedNow participants and $271 billion processed in Q1 2026, instant payments are production infrastructure. But irrevocable, 24/7 settlement with a seconds-long authorization window breaks fraud programs built for ACH. Here's what your operational risk program needs to say about instant payments before you enable send.

By Rebecca Leung · September 20, 2026 ·
Table of Contents

TL;DR

  • FedNow hit 1,700+ participating institutions and $271 billion in Q1 2026 — this is production infrastructure at $3 billion per day, not a pilot program
  • Irrevocable, 24/7 payments break fraud programs designed for ACH: the seconds-long authorization window eliminates the T+2 buffer most fraud detection depends on
  • 2026 NACHA rule changes require all ACH stakeholders to actively monitor and manage fraud — the regulatory direction for all payment rails is clear
  • Your operational risk program needs to address fraud governance, 24/7 coverage, credit exposure recalibration, and third-party concentration before your first instant payment exam finding

Here’s how you find out your fraud program wasn’t ready for FedNow: a customer calls Thursday night about a $45,000 payment they didn’t authorize. Your fraud team is off-shift. The payment settled three hours ago. The funds are gone.

That’s not a hypothetical. It’s the operational reality of enabling instant payment send with fraud controls designed for ACH batch processing. FedNow’s irrevocability and 24/7 availability aren’t product features you can turn off when your team goes home — they’re structural characteristics that require your fraud and operational risk program to be rebuilt around them, not adapted from what worked for next-day ACH.

The numbers are past the “we’re still evaluating” stage. The Federal Reserve’s FedNow two-year growth report shows over 1,700 participating financial institutions as of mid-2026, ranging from under $500 million to over $3 trillion in assets. The Federal Reserve is targeting eventual connectivity for roughly 8,000 of the nation’s banks and credit unions. In Q1 2026, FedNow processed 2.73 million payments totaling $271 billion. The average payment is approximately $99,000. This is not consumer P2P — it’s high-value business transactions settling in seconds at $3 billion per day.

The Core Operational Risk Problem

ACH built its fraud model around time. A T+2 settlement window means a suspicious debit has 48 hours to be flagged, verified, and returned before money actually changes hands at the institution level. Transaction monitoring systems, human review queues, and fraud alert workflows were designed for that window.

FedNow and RTP close that window to seconds. Some participants report effective authorization windows of approximately six seconds between payment initiation and irrevocable settlement. Fraud detection logic tuned for a 48-hour cycle is now running against a six-second clock.

Irrevocability makes the stakes explicit: a returned ACH item is operational friction. A settled FedNow payment can’t be reversed through the payment system — recovery depends on the recipient’s cooperation, civil remedies, or law enforcement. None of those move faster than the fraud itself. The Federal Reserve’s fraud-at-a-glance resource for FedNow participants is candid about this: instant payment fraud is qualitatively different from ACH fraud, and the controls have to be designed accordingly.

What the Fraud Threat Landscape Actually Looks Like

The fraud types hitting instant payment rails aren’t new — they’re existing schemes that have been modified to exploit instant, irrevocable settlement:

Business Email Compromise (BEC) with vendor impersonation. An attacker impersonates a known vendor or executive, sends updated wire instructions, and the payment settles before anyone verifies the change. On ACH, the two-day window often allows a verification call before funds actually move. On FedNow, the payment is done.

Authorized Push Payment (APP) fraud. The customer initiates the transfer themselves after being socially engineered into believing the payment is legitimate — a phishing call, a fake invoice, a spoofed bank alert. Under Reg E, banks aren’t automatically liable for authorized transactions. But the customer dispute process, reputational exposure, and pressure from the CFPB’s APP fraud guidance all create operational cost even when liability is clear.

Payroll diversion attacks. An attacker gains access to an employee’s payroll portal and redirects direct deposit to a new account via instant transfer. The employer’s return request arrives after the funds have cleared and been withdrawn.

Request for Payment (RFP) fraud. Fraudsters send fake RFP requests that mimic legitimate billing — invoices for routine services, requests from apparent business partners. The customer approves the payment thinking it’s a routine transaction. This is a FedNow-specific attack vector that doesn’t map to ACH fraud categories and often isn’t covered in legacy fraud detection rule sets.

Deepfake-enabled social engineering is accelerating all of these. Voice synthesis can now replicate a known vendor or executive with enough fidelity to pass a phone verification. The social engineering layer that fraud programs historically treated as “the customer’s problem” is increasingly arriving in channels your institution directly manages — and settling before your team realizes what happened.

What NACHA’s 2026 Changes Signal

The NACHA same-day ACH rule changes that took effect in 2026 require all ACH stakeholders — except consumers — to actively monitor and manage fraud risks. This includes maintaining mechanisms to delay or return suspicious payments and standardizing transaction descriptions for anomaly detection.

That’s an ACH rule. But the regulatory direction it signals applies to every payment rail. The interagency third-party risk management proposed guidance that landed in September 2026, the OCC’s continuing focus on payment system operational resilience, and the Federal Reserve’s own FedNow governance framework all point the same direction: passive fraud controls built around batch processing don’t meet current expectations.

Financial institutions enabling FedNow send should plan for the same evolution in instant payment fraud obligations that ACH underwent over the past decade. The question isn’t whether standards will develop — it’s whether you’re building your fraud program ahead of that standard or behind it.

What Your Operational Risk Program Needs to Say

Most operational risk programs address payment fraud generically: fraud is listed as a risk category, there’s a policy, there are controls. That’s not sufficient for instant payments. The specific operational risk dimensions that FedNow and RTP create require explicit coverage:

Fraud Governance for Instant Payments Specifically

Who owns fraud risk for the FedNow send function? What’s the escalation path when a suspicious transaction is flagged outside business hours? Who has the authority to suspend the send function for a specific customer segment? These decisions need to be documented before an incident creates them under pressure.

For most small fintechs, this means an explicit policy section on instant payment fraud governance, an on-call contact chain with defined response SLAs, and documented authority levels for account restrictions and send suspensions.

24/7 Operational Coverage

FedNow processes payments at 3am on New Year’s Day. Your fraud monitoring needs to match that availability — not just business-hours coverage with an on-call number for emergencies. The OCC’s 2026 cybersecurity resilience report found that institutions document their intent to test operational resilience but frequently lack evidence that the testing actually occurred. Instant payment fraud monitoring is an operational resilience issue, not just a fraud control issue.

Options for 24/7 coverage: internal staffing, a managed fraud detection service with after-hours response capability, or fully automated real-time decisioning with defined auto-decline thresholds configured by customer segment and transaction type. FedNow’s account activity threshold functionality allows participants to customize velocity and value limits by customer segment — that configuration is a fraud control that needs to be documented, tested, and reviewed when your fraud patterns change.

Credit and Liquidity Risk Recalibration

Irrevocable instant settlement changes your real-time exposure position. On ACH, unsettled items are receivables — you can return them. On FedNow, the settlement is final. Your credit risk and treasury teams need to assess whether instant payment send creates intraday exposure that isn’t captured in your current credit risk monitoring, particularly for larger business customers with high-value payment volume.

This is especially relevant for fintechs operating as agent lenders, BaaS partners, or payroll processors where the volume and value of instant payment send activity could be significant relative to your capital position.

Third-Party Concentration Risk for Instant Payment Infrastructure

Many financial institutions — particularly smaller banks and credit unions — connect to FedNow through a core banking provider or payment processing vendor. That vendor’s operational resilience is directly tied to your instant payment availability. If the vendor goes down, your FedNow connectivity goes down.

The OCC and the proposed interagency TPRM guidance have both emphasized concentration risk in critical technology providers. FedNow connectivity is a critical service. Your TPRM program needs to address it explicitly: RTO expectations for connectivity restoration, tested failover procedures, and documentation that you’ve evaluated the vendor’s own resilience posture against FFIEC BCM expectations.

Before You Enable Send: Operational Readiness Checklist

ItemWhat to Verify
Fraud detection recalibrationDetection logic runs against real-time decisioning, not adapted from batch ACH parameters
24/7 monitoring coverageCoverage model documented: internal staffing, managed service, or automated decisioning with escalation path
Velocity and value thresholdsConfigured by customer segment; reviewed and approved as a fraud control
APP fraud proceduresCustomer notification, account freeze process, re-authorization workflow documented
RFP fraud controlsNew-payee confirmation requirements and RFP whitelist configuration documented
Credit exposure documentationIntraday exposure calculation updated to reflect irrevocable settlement
BCP for instant payment outageRecovery procedure and RTO for FedNow connectivity documented and tested
Third-party resilience assessmentFedNow connectivity vendor RTO documented; vendor resilience reviewed in last 12 months
Fraud trainingFraud team and customer service trained on instant-payment-specific scenarios
Loss event documentationProcess for capturing, categorizing, and reporting instant payment fraud losses established

Loss Event Documentation From the Start

When instant payment fraud does occur, how you document it determines whether you learn from it or repeat it. Most operational risk programs treat fraud loss documentation as an afterthought — something that gets reconstructed months later for an audit or examiner request.

For instant payments, that approach is especially problematic. The speed and irrevocability of the loss means the incident timeline is compressed — the gap between initiation, settlement, and discovery can be hours or days rather than the days or weeks an ACH return might allow. Capturing root cause, control failure point, and detection gap at the time of the event is the only way to get accurate data for control improvement.

The Loss Monitoring & Event Tracking Kit is built for this: capturing loss events with root cause, control failure analysis, trend reporting, and the escalation documentation your operational risk committee needs to see. Examiners reviewing your instant payment operational risk program will want to see that you’re tracking loss events, analyzing root causes, and adjusting controls in response — not just that controls exist on paper.

So What?

Enabling FedNow or RTP send is a product decision with a compliance tail. Your fraud controls, operational coverage model, credit exposure calculations, and third-party resilience documentation all need to be updated to reflect the structural differences between instant payments and ACH. The regulatory direction — from NACHA, the OCC, and the Federal Reserve’s own FedNow governance framework — is clear: passive, batch-era fraud programs aren’t enough.

The time to build instant payment operational risk controls is before your first examiner asks for them and before your first significant fraud loss. FedNow’s 1,700+ participants are not a future state — they’re current infrastructure operating at $3 billion per day. If you’re planning to enable send, build the operational risk program around it first. The six-second authorization window doesn’t extend to give you time to figure this out after you’ve turned it on.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What makes FedNow and RTP operationally riskier than ACH?
Three structural differences: irrevocability (once sent, funds can't be recalled through the payment system), speed (settlement in seconds vs. two business days), and 24/7/365 availability (no business day cutoffs, no settlement windows to catch errors before funds move). ACH's T+2 settlement window is a de facto fraud buffer — flagged transactions can be returned before funds actually change hands. FedNow and RTP eliminate that buffer entirely.
What fraud types are increasing on instant payment rails?
The highest-volume fraud vectors on instant payment rails are business email compromise (BEC) with vendor impersonation, authorized push payment (APP) fraud where customers are socially engineered into initiating the transfer, payroll diversion attacks, and Request for Payment (RFP) fraud where fraudulent payment requests mimic legitimate billing. Deepfake-enabled social engineering is accelerating all of these — voice and video can now be synthesized to impersonate known vendors or executives in real time.
What does NACHA's 2026 rule change require for fraud monitoring?
NACHA's 2026 ACH rule updates require all ACH stakeholders — except consumers — to actively monitor and manage fraud risks, including the ability to delay or return suspicious payments and to standardize transaction descriptions for anomaly detection. While these rules apply to ACH directly, they signal the regulatory direction for all payment rails: passive fraud controls are no longer acceptable.
What is the authorization window for FedNow transactions?
Some FedNow and RTP participants report effective authorization windows of approximately six seconds between payment initiation and irrevocable settlement. That's the window your fraud detection has to flag a suspicious transaction before funds are gone. ACH fraud detection is typically designed for a T+2 review cycle — legacy fraud systems running on instant payment rails without recalibration will miss the transactions they were designed to catch.
What should our operational risk program say about instant payments?
Your ORM program needs to address four specific dimensions: (1) fraud governance — who owns fraud risk for instant payments, what their escalation path is, and how decisions to suspend the send function are made; (2) 24/7 operational coverage — instant payments don't stop at 5pm, and your fraud monitoring needs to reflect that; (3) credit and liquidity risk — irrevocable settlement changes your real-time exposure calculations; and (4) third-party concentration — if your FedNow connection runs through a single vendor, their operational resilience is your operational risk.
What should we do before enabling the FedNow send function?
Four things: First, verify your fraud detection system has been recalibrated for real-time decisioning, not adapted from an ACH batch model. Second, confirm you have 24/7 fraud monitoring coverage, not just business-hours staffing. Third, run a customer communication and escalation scenario for a suspected APP fraud event — know how fast you can freeze a customer account and what your re-authorization process looks like. Fourth, document your instant payment operational risk framework before your first exam asks for it — the time to build it is before you have loss events, not after.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Loss Monitoring & Event Tracking Kit

Basel-aligned operational loss event tracking and root cause analysis for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.