Feature Operational Risk
Your FedNow Send Function Goes Live Next Quarter. Here's What Your Fraud Controls and Operational Risk Program Need Before the First Transaction.
With 1,700+ FedNow participants and $271 billion processed in Q1 2026, instant payments are production infrastructure. But irrevocable, 24/7 settlement with a seconds-long authorization window breaks fraud programs built for ACH. Here's what your operational risk program needs to say about instant payments before you enable send.
Table of Contents
TL;DR
- FedNow hit 1,700+ participating institutions and $271 billion in Q1 2026 — this is production infrastructure at $3 billion per day, not a pilot program
- Irrevocable, 24/7 payments break fraud programs designed for ACH: the seconds-long authorization window eliminates the T+2 buffer most fraud detection depends on
- 2026 NACHA rule changes require all ACH stakeholders to actively monitor and manage fraud — the regulatory direction for all payment rails is clear
- Your operational risk program needs to address fraud governance, 24/7 coverage, credit exposure recalibration, and third-party concentration before your first instant payment exam finding
Here’s how you find out your fraud program wasn’t ready for FedNow: a customer calls Thursday night about a $45,000 payment they didn’t authorize. Your fraud team is off-shift. The payment settled three hours ago. The funds are gone.
That’s not a hypothetical. It’s the operational reality of enabling instant payment send with fraud controls designed for ACH batch processing. FedNow’s irrevocability and 24/7 availability aren’t product features you can turn off when your team goes home — they’re structural characteristics that require your fraud and operational risk program to be rebuilt around them, not adapted from what worked for next-day ACH.
The numbers are past the “we’re still evaluating” stage. The Federal Reserve’s FedNow two-year growth report shows over 1,700 participating financial institutions as of mid-2026, ranging from under $500 million to over $3 trillion in assets. The Federal Reserve is targeting eventual connectivity for roughly 8,000 of the nation’s banks and credit unions. In Q1 2026, FedNow processed 2.73 million payments totaling $271 billion. The average payment is approximately $99,000. This is not consumer P2P — it’s high-value business transactions settling in seconds at $3 billion per day.
The Core Operational Risk Problem
ACH built its fraud model around time. A T+2 settlement window means a suspicious debit has 48 hours to be flagged, verified, and returned before money actually changes hands at the institution level. Transaction monitoring systems, human review queues, and fraud alert workflows were designed for that window.
FedNow and RTP close that window to seconds. Some participants report effective authorization windows of approximately six seconds between payment initiation and irrevocable settlement. Fraud detection logic tuned for a 48-hour cycle is now running against a six-second clock.
Irrevocability makes the stakes explicit: a returned ACH item is operational friction. A settled FedNow payment can’t be reversed through the payment system — recovery depends on the recipient’s cooperation, civil remedies, or law enforcement. None of those move faster than the fraud itself. The Federal Reserve’s fraud-at-a-glance resource for FedNow participants is candid about this: instant payment fraud is qualitatively different from ACH fraud, and the controls have to be designed accordingly.
What the Fraud Threat Landscape Actually Looks Like
The fraud types hitting instant payment rails aren’t new — they’re existing schemes that have been modified to exploit instant, irrevocable settlement:
Business Email Compromise (BEC) with vendor impersonation. An attacker impersonates a known vendor or executive, sends updated wire instructions, and the payment settles before anyone verifies the change. On ACH, the two-day window often allows a verification call before funds actually move. On FedNow, the payment is done.
Authorized Push Payment (APP) fraud. The customer initiates the transfer themselves after being socially engineered into believing the payment is legitimate — a phishing call, a fake invoice, a spoofed bank alert. Under Reg E, banks aren’t automatically liable for authorized transactions. But the customer dispute process, reputational exposure, and pressure from the CFPB’s APP fraud guidance all create operational cost even when liability is clear.
Payroll diversion attacks. An attacker gains access to an employee’s payroll portal and redirects direct deposit to a new account via instant transfer. The employer’s return request arrives after the funds have cleared and been withdrawn.
Request for Payment (RFP) fraud. Fraudsters send fake RFP requests that mimic legitimate billing — invoices for routine services, requests from apparent business partners. The customer approves the payment thinking it’s a routine transaction. This is a FedNow-specific attack vector that doesn’t map to ACH fraud categories and often isn’t covered in legacy fraud detection rule sets.
Deepfake-enabled social engineering is accelerating all of these. Voice synthesis can now replicate a known vendor or executive with enough fidelity to pass a phone verification. The social engineering layer that fraud programs historically treated as “the customer’s problem” is increasingly arriving in channels your institution directly manages — and settling before your team realizes what happened.
What NACHA’s 2026 Changes Signal
The NACHA same-day ACH rule changes that took effect in 2026 require all ACH stakeholders — except consumers — to actively monitor and manage fraud risks. This includes maintaining mechanisms to delay or return suspicious payments and standardizing transaction descriptions for anomaly detection.
That’s an ACH rule. But the regulatory direction it signals applies to every payment rail. The interagency third-party risk management proposed guidance that landed in September 2026, the OCC’s continuing focus on payment system operational resilience, and the Federal Reserve’s own FedNow governance framework all point the same direction: passive fraud controls built around batch processing don’t meet current expectations.
Financial institutions enabling FedNow send should plan for the same evolution in instant payment fraud obligations that ACH underwent over the past decade. The question isn’t whether standards will develop — it’s whether you’re building your fraud program ahead of that standard or behind it.
What Your Operational Risk Program Needs to Say
Most operational risk programs address payment fraud generically: fraud is listed as a risk category, there’s a policy, there are controls. That’s not sufficient for instant payments. The specific operational risk dimensions that FedNow and RTP create require explicit coverage:
Fraud Governance for Instant Payments Specifically
Who owns fraud risk for the FedNow send function? What’s the escalation path when a suspicious transaction is flagged outside business hours? Who has the authority to suspend the send function for a specific customer segment? These decisions need to be documented before an incident creates them under pressure.
For most small fintechs, this means an explicit policy section on instant payment fraud governance, an on-call contact chain with defined response SLAs, and documented authority levels for account restrictions and send suspensions.
24/7 Operational Coverage
FedNow processes payments at 3am on New Year’s Day. Your fraud monitoring needs to match that availability — not just business-hours coverage with an on-call number for emergencies. The OCC’s 2026 cybersecurity resilience report found that institutions document their intent to test operational resilience but frequently lack evidence that the testing actually occurred. Instant payment fraud monitoring is an operational resilience issue, not just a fraud control issue.
Options for 24/7 coverage: internal staffing, a managed fraud detection service with after-hours response capability, or fully automated real-time decisioning with defined auto-decline thresholds configured by customer segment and transaction type. FedNow’s account activity threshold functionality allows participants to customize velocity and value limits by customer segment — that configuration is a fraud control that needs to be documented, tested, and reviewed when your fraud patterns change.
Credit and Liquidity Risk Recalibration
Irrevocable instant settlement changes your real-time exposure position. On ACH, unsettled items are receivables — you can return them. On FedNow, the settlement is final. Your credit risk and treasury teams need to assess whether instant payment send creates intraday exposure that isn’t captured in your current credit risk monitoring, particularly for larger business customers with high-value payment volume.
This is especially relevant for fintechs operating as agent lenders, BaaS partners, or payroll processors where the volume and value of instant payment send activity could be significant relative to your capital position.
Third-Party Concentration Risk for Instant Payment Infrastructure
Many financial institutions — particularly smaller banks and credit unions — connect to FedNow through a core banking provider or payment processing vendor. That vendor’s operational resilience is directly tied to your instant payment availability. If the vendor goes down, your FedNow connectivity goes down.
The OCC and the proposed interagency TPRM guidance have both emphasized concentration risk in critical technology providers. FedNow connectivity is a critical service. Your TPRM program needs to address it explicitly: RTO expectations for connectivity restoration, tested failover procedures, and documentation that you’ve evaluated the vendor’s own resilience posture against FFIEC BCM expectations.
Before You Enable Send: Operational Readiness Checklist
| Item | What to Verify |
|---|---|
| Fraud detection recalibration | Detection logic runs against real-time decisioning, not adapted from batch ACH parameters |
| 24/7 monitoring coverage | Coverage model documented: internal staffing, managed service, or automated decisioning with escalation path |
| Velocity and value thresholds | Configured by customer segment; reviewed and approved as a fraud control |
| APP fraud procedures | Customer notification, account freeze process, re-authorization workflow documented |
| RFP fraud controls | New-payee confirmation requirements and RFP whitelist configuration documented |
| Credit exposure documentation | Intraday exposure calculation updated to reflect irrevocable settlement |
| BCP for instant payment outage | Recovery procedure and RTO for FedNow connectivity documented and tested |
| Third-party resilience assessment | FedNow connectivity vendor RTO documented; vendor resilience reviewed in last 12 months |
| Fraud training | Fraud team and customer service trained on instant-payment-specific scenarios |
| Loss event documentation | Process for capturing, categorizing, and reporting instant payment fraud losses established |
Loss Event Documentation From the Start
When instant payment fraud does occur, how you document it determines whether you learn from it or repeat it. Most operational risk programs treat fraud loss documentation as an afterthought — something that gets reconstructed months later for an audit or examiner request.
For instant payments, that approach is especially problematic. The speed and irrevocability of the loss means the incident timeline is compressed — the gap between initiation, settlement, and discovery can be hours or days rather than the days or weeks an ACH return might allow. Capturing root cause, control failure point, and detection gap at the time of the event is the only way to get accurate data for control improvement.
The Loss Monitoring & Event Tracking Kit is built for this: capturing loss events with root cause, control failure analysis, trend reporting, and the escalation documentation your operational risk committee needs to see. Examiners reviewing your instant payment operational risk program will want to see that you’re tracking loss events, analyzing root causes, and adjusting controls in response — not just that controls exist on paper.
So What?
Enabling FedNow or RTP send is a product decision with a compliance tail. Your fraud controls, operational coverage model, credit exposure calculations, and third-party resilience documentation all need to be updated to reflect the structural differences between instant payments and ACH. The regulatory direction — from NACHA, the OCC, and the Federal Reserve’s own FedNow governance framework — is clear: passive, batch-era fraud programs aren’t enough.
The time to build instant payment operational risk controls is before your first examiner asks for them and before your first significant fraud loss. FedNow’s 1,700+ participants are not a future state — they’re current infrastructure operating at $3 billion per day. If you’re planning to enable send, build the operational risk program around it first. The six-second authorization window doesn’t extend to give you time to figure this out after you’ve turned it on.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Loss Monitoring & Event Tracking Kit
Basel-aligned operational loss event tracking and root cause analysis for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What makes FedNow and RTP operationally riskier than ACH?
What fraud types are increasing on instant payment rails?
What does NACHA's 2026 rule change require for fraud monitoring?
What is the authorization window for FedNow transactions?
What should our operational risk program say about instant payments?
What should we do before enabling the FedNow send function?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Loss Monitoring & Event Tracking Kit
Basel-aligned operational loss event tracking and root cause analysis for financial services.
◆ Keep reading
Related posts.
Operational Risk
New Silicon Valley Bank Review: The Seven Supervisory Failures Risk Teams Should Fix
The new Silicon Valley Bank review says supervisors saw risks but failed to act. Here is how banks can repair escalation and decision rights.
Sep 19, 2026
Operational Risk
The Basel III Endgame Re-Proposal Slashed Op Risk Capital. Here's What Your Operational Risk Program Still Has to Do.
On March 19, 2026, the Fed, OCC, and FDIC formally rescinded the 2023 Basel III proposal and issued a dramatically different re-proposal that delivers net capital relief after industry feedback identified operational risk as the single largest driver of inflated RWA. Here's what changed, what didn't, and what your op risk program needs to do before 2027 implementation.
Sep 18, 2026
Operational Risk
NACHA Just Approved a $10 Million Same Day ACH Limit. Your Fraud Controls Were Built for $1 Million.
NACHA approved a $10 million per-transaction limit for Same Day ACH in April 2026, effective September 2027. That's a 10x increase from the current $1 million cap. Most financial institution fraud controls, velocity limits, and risk-based monitoring thresholds weren't built for that exposure. Here's what needs to change before the September 2027 effective date.
Sep 13, 2026