search

Real-Time Payments: FedNow, RTP, and the Impact on Community Banks

7/25/2026

Instant payments differ from everything else in a bank's payment stack in one property that drives every other consequence: the funds are final when they arrive, and they arrive in seconds.

Not "available." Final. There is no settlement window in which to reconsider, no return reason code, no chargeback. A payment sent in error or induced by fraud can be recovered only if the receiving institution cooperates and the funds are still there. Every operational, fraud, and liquidity implication of real-time payments follows from that single fact.

Two Networks, Not One

The United States has two instant payment rails, and they are separate systems.

RTP, operated by The Clearing House, launched first and has the longer operating history.

FedNow, operated by the Federal Reserve, launched more recently and is available to institutions with a Federal Reserve master account.

They are not interoperable. An institution on one cannot reach a customer whose bank is only on the other, which means full reach requires participation in both — a fact that surprises banks who assumed joining one solved the problem. Most institutions of any size end up on both, and the sequencing is a real decision rather than a formality.

Both share the defining characteristics: credit push only (the sender initiates; nobody pulls funds), immediate and final settlement, 24 hours a day, every day, with a confirmation returned to the sender in seconds.

How This Differs From What the Bank Already Has

Worth stating precisely, because staff conflate these constantly.

ACH is batch-based, settles on a schedule, supports both debits and credits, and has a return mechanism with defined reason codes and timeframes. Same-day ACH compressed the timing and did not change the model. Our post on ACH fraud covers its risk profile.

Wires settle in real time with finality and operate during business hours, at meaningful cost, typically for larger amounts.

Instant payments combine wire-like finality with 24/7 availability at low cost and small-payment economics. That combination is genuinely new, and it is why the fraud and liquidity implications are not simply the wire playbook applied more often.

The comparison that matters for risk: instant payments have wire-like irrevocability with retail-like volume and no business-hours constraint. Institutions that staffed and controlled wires as a low-volume, high-attention, business-hours function cannot extend that model to a channel that operates at three in the morning on a Sunday.

Fraud: The Central Problem

Irrevocability moves the entire fraud burden to the front of the transaction. There is no recovery process to rely on, which means prevention is the only control that works.

The typology that dominates is not account takeover. It is authorized push payment fraud — the customer is deceived and sends the money themselves. Romance and investment scams, impersonation of the bank or a government agency, invoice redirection in business payments, and the "your account is compromised, move your money to a safe account" script. In every case the sender is genuinely authorized, which is exactly what makes the payment final and the loss hard to reverse.

The framework consequence: under the electronic fund transfer rules, an unauthorized transfer carries the institution's error resolution and liability obligations, while a transfer the consumer was induced to make is generally treated as authorized. That boundary has drawn substantial regulatory attention and should be confirmed against current requirements — and as our post on mobile banking security notes, the reputational and unfair-practice dimensions do not follow the legal line.

What actually reduces losses:

Friction at the right moments. A first payment to a new payee, an unusual amount, a payment shortly after a contact information change, or a rapid escalating sequence should not proceed silently. A confirmation step, a short hold, or a lower limit at those moments is the highest-value control available.

Scam-specific warnings at the moment of payment, matched to the pattern the transaction suggests rather than a generic notice.

Limits that differ by customer tenure, channel, and payee history, rather than one institutional limit applied to everyone.

Payee verification where available, so a customer sending to a name they believe they recognize learns before the money moves.

Front-line authority to slow a payment down, with training for the conversation — because a customer being coached by a scammer will insist, and will have a prepared explanation.

Inbound monitoring. The institution is also a receiving bank, and receiving fraud proceeds creates a mule account problem, a suspicious activity reporting obligation, and a reputational exposure. Monitoring inbound instant credits for mule patterns — a dormant account suddenly receiving and immediately forwarding funds — is as important as monitoring outbound, and it is more often neglected.

A defined recovery process, exercised in minutes rather than days, since the only window in which funds may still be recoverable is short. Knowing who contacts the receiving institution, through what channel, with what information, at 11 p.m. on a Saturday is the difference between a recovery attempt and a report.

Liquidity and Operations at 24/7

The operational consequences are larger than most institutions anticipate, and they are not primarily technological.

Settlement account management outside business hours. Payments settle continuously, including when the institution's staff are not working and when its own funding mechanisms are not conventionally available. The institution needs a way to maintain adequate balances across weekends and holidays, and to know what happens if a balance is insufficient at two in the morning. Both networks provide mechanisms addressing this; the institution has to understand and configure them rather than assume.

Liquidity forecasting changes shape. Outflows can occur at any time with no cutoff, which affects the intraday liquidity discipline covered in our liquidity risk post. This is a modest effect at current volumes for most community banks and a growing one.

Exception handling has no business hours. Someone must be reachable for fraud escalation, a failed payment, an operational issue, or a recovery request. For a community bank the realistic answers are an on-call rotation, a service arrangement with the core provider, or accepting a defined response delay with limits set accordingly — the important thing being that it is a decision rather than an oversight.

Reconciliation becomes continuous rather than a daily cycle, which changes the operational rhythm and the reporting.

The core processor determines much of this. For most community banks, instant payment capability arrives through the core or a payments provider, and what the institution can offer, what limits it can set, what fraud controls it can apply, and what visibility it has are functions of that provider's implementation. The questions worth asking in writing: which networks, send and receive or receive only, what fraud tooling is included, what limits are configurable, what reporting exists, what the after-hours support model is, and what the roadmap dates are.

Receive-Only Is a Legitimate Strategy

Institutions do not have to launch send capability to participate, and for many the right sequence is receive first.

Receiving is lower risk and immediately valuable. Customers receive payroll, gig earnings, insurance settlements, and business payments faster. The institution takes on the mule-account monitoring obligation and very little else.

Sending is where the fraud exposure lives, and it requires the controls, the limits, the after-hours model, and the recovery process described above.

Starting with receive gives the institution operating experience, satisfies a real share of customer expectation, and buys time to build the send-side controls properly. The one thing worth avoiding is treating receive-only as a permanent answer, because customer expectation is moving and a bank that cannot send will eventually be compared unfavorably to one that can.

Structured coverage is available through Payments and Settlements, the Certificate in Deposit Compliance, the Certificate in Fraud Prevention, and Financial Risk Management: Liquidity Risk.

Where the Business Case Actually Is

Instant payments are rarely a revenue line for a community bank. The value is in specific use cases and in retention.

Request for payment is the capability with the most commercial potential and the least attention. Rather than the payer initiating from scratch, the payee sends a request the payer approves — which brings the biller's precision to a credit-push rail. For business customers this addresses invoice payment, and it reduces the misdirected-payment problem because the account details come from the requester rather than being typed by the payer.

Disbursements are the clearest business case: insurance claims, loan proceeds, real estate and title disbursements, refunds, and payroll adjustments. A business customer who can pay contractors instantly has a reason to hold its operating account where that is possible.

Account-to-account funding, including instant funding of new accounts, which connects directly to the digital account opening experience.

Deposit retention, or its opposite. This is the honest strategic point: instant payments make money more mobile in both directions. A customer can move balances to a competitor in seconds. Institutions weighing whether to participate should recognize that abstaining does not prevent the outflow — customers will move money using whatever rail is available — it only removes the institution's ability to be on the receiving side.

Where Institutions Get This Wrong

Extending the wire control model to a 24/7 retail-volume channel.

No after-hours coverage for fraud escalation or recovery, so the only window for recovery is missed by default.

Inbound monitoring neglected, leaving the institution a comfortable destination for fraud proceeds and creating suspicious activity reporting exposure.

One institutional limit for everyone, rather than limits varying by tenure, channel, and payee history.

Generic warnings instead of scam-specific messaging at the moment of payment.

Assuming one network provides full reach.

Settlement balance management outside business hours not configured or understood.

No recovery playbook, so the request to the receiving institution is improvised.

Front-line staff without authority to pause a payment they believe is a scam.

The summary for a board considering this: instant payments are not a product decision so much as an operating model decision. The institutions that have implemented them well treated finality as the design constraint — building prevention rather than recovery, limits rather than uniformity, and coverage rather than business hours. The ones that treated it as another payment type on the menu discovered the difference the first time a customer sent fifty thousand dollars to a scammer on a Sunday afternoon.

Frequently Asked Questions

What makes instant payments different from wires and ACH?

Finality combined with 24/7 availability and small-payment economics. ACH is batch-based with a return mechanism; wires settle with finality during business hours at meaningful cost. Instant payments are credit-push only, immediately and irrevocably settled, available every hour of every day, and cheap — which means wire-like irrevocability at retail volume with no business-hours constraint.

Are FedNow and RTP interoperable?

No. They are separate networks, and an institution on one cannot reach a customer whose institution is only on the other. Full reach requires participation in both, which surprises banks that assumed joining one network solved the problem.

What is the main fraud risk in real-time payments?

Authorized push payment fraud — the customer is deceived and sends the money themselves, through romance and investment scams, impersonation of the bank or a government agency, invoice redirection, or the "move your money to a safe account" script. Because the sender genuinely authorized it, the payment is final and recovery depends entirely on the receiving institution's cooperation.

Can a community bank participate without sending payments?

Yes, and receive-only is a sensible first step. Receiving is lower risk and immediately valuable to customers who get payroll, gig earnings, and business payments faster; the institution takes on mule-account monitoring and little else. Sending is where the fraud exposure, limits, after-hours coverage, and recovery process become necessary.

What operational changes does 24/7 settlement require?

Settlement balance management across weekends and holidays, an answer for insufficient balances outside business hours, after-hours coverage for fraud escalation and recovery, continuous rather than daily reconciliation, and liquidity forecasting that accounts for outflows with no cutoff. Most of this is configuration and staffing rather than technology.

What is request for payment and why does it matter?

A capability in which the payee sends a payment request the payer approves, rather than the payer initiating from scratch. It brings billing precision to a credit-push rail, addresses business invoice payment, and reduces misdirected payments because the account details come from the requester rather than being typed by the payer. It is the instant payment feature with the most commercial potential and the least attention.

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026