Regulation E is the rule that decides who absorbs a loss when money leaves a consumer's account without authorization. That single function makes it one of the most operationally consequential consumer regulations a bank administers, and one of the most frequently violated — not through misunderstanding of the standard, but through missed deadlines.
Regulation E implements the Electronic Fund Transfer Act. It applies to electronic fund transfers that authorize a financial institution to debit or credit a consumer's account.
Covered transfers include ATM transactions, point-of-sale debit card transactions, ACH debits and credits, telephone-initiated transfers under a plan, online banking transfers, and preauthorized recurring transfers.
Two boundaries matter constantly. Business accounts are not covered — an unauthorized ACH debit against a business account is governed by the Nacha Rules and the deposit agreement, not by Reg E, which is why the outcome for a business customer can differ sharply from that for a consumer on identical facts. And wire transfers are excluded, falling under UCC Article 4A instead. Checks are also outside Reg E, though a check converted to an ACH entry becomes an EFT.
An unauthorized transfer is one initiated by a person other than the consumer without actual authority, from which the consumer receives no benefit. Liability depends entirely on how quickly the consumer reports it:
|
Consumer reports |
Maximum consumer liability |
|
Within 2 business days of learning of loss or theft of the access device |
$50 |
|
After 2 business days but within 60 days of the statement |
$500 |
|
More than 60 days after the statement transmittal |
Unlimited for transfers after the 60-day period |
Three points that drive real disputes.
These are ceilings, not defaults. Many institutions choose to absorb losses more generously than the regulation requires, and card network rules frequently impose stricter zero-liability standards on top of Reg E. What an institution may not do is impose more liability than the tiers permit.
A transfer induced by fraud is generally not "unauthorized." If the consumer was tricked into initiating the transfer themselves, it was authorized in the regulatory sense. This is the central fact in most scam disputes, and it is genuinely difficult to explain to a customer who has lost money.
Timeframes for extended travel or hospitalization must be extended to a reasonable period, which is easy to overlook when applying the tiers mechanically.
The consumer must notify the institution of an error within 60 days of the transmittal of the periodic statement showing it. Notice may be oral or written, and the institution may require written confirmation — but may not withhold investigation while waiting for it.
Once notified, the institution must:
Investigate and determine within 10 business days. If it cannot, it may take up to 45 calendar days provided it gives provisional credit for the amount in question within 10 business days and notifies the consumer of the credit.
Report results within 3 business days of completing the investigation, and if no error is found, provide a written explanation and notice that the consumer may request the documents relied upon.
Extended periods apply in specific situations: 20 business days for determination and 90 calendar days for the extended investigation where the notice concerns a transfer at a new account, a point-of-sale debit card transaction, or a transfer initiated outside the United States.
The single most common violation in this area is a missed provisional credit deadline. An institution that decides to take the full 45 days but does not fund provisional credit within 10 business days has violated the rule regardless of whether its eventual conclusion was correct. Institutions that automate the provisional credit trigger stop having this problem; institutions that rely on analyst diligence do not.
A note on debiting provisional credit: if the investigation finds no error, the institution may reverse the provisional credit, but must notify the consumer of the date and amount and honor items for five business days as if the credit remained.
Reg E requires initial disclosures at account opening covering consumer liability, the telephone number and address for reporting unauthorized transfers, the business days of the institution, the types and limitations of transfers available, applicable fees, the right to receive documentation, stop payment rights for preauthorized transfers, the institution's liability, and the error resolution procedures.
Change-in-terms notice is generally required 21 days in advance for changes that would increase fees or liability or limit transfers.
Receipts must be provided at electronic terminals, and periodic statements must be provided for accounts with EFT activity.
For recurring debits, the consumer must have authorized the transfer in writing or in a similarly authenticated electronic form, and must receive a copy.
The consumer may stop payment by notifying the institution at least three business days before the scheduled date. The institution may require written confirmation within 14 days of an oral notice, provided it told the consumer of that requirement at the time.
Where the amount of a preauthorized transfer varies from the previous one, the payee generally must notify the consumer at least 10 days in advance, unless the consumer elected a range or threshold arrangement.
The rule requires affirmative consumer consent — opt-in — before an institution may assess an overdraft fee on an ATM or one-time debit card transaction. The consent must follow a segregated disclosure describing the service and its fees, and the consumer must be given the option to decline.
Recurring debit card transactions and check or ACH items are outside the opt-in requirement, which produces the counterintuitive result that a consumer who declined can still incur overdraft fees on other transaction types.
This area carries elevated UDAAP risk in addition to Reg E risk. Enforcement has focused on opt-in processes that were not genuinely optional, disclosures that misdescribed which balance authorizations were measured against, and fee sequencing that made overdrafts unpredictable.
International consumer money transfers above a threshold are covered by a separate subpart requiring prepayment and receipt disclosures with the exchange rate, fees and taxes, the amount to be received, the date of availability, and error resolution and cancellation rights — generally a 30-minute cancellation window. Institutions offering international transfers should treat this as a distinct compliance area rather than an extension of the domestic rules.
Automate the provisional credit clock. This one control eliminates the most common violation.
Do not require a written claim before investigating. Requesting written confirmation is permitted; conditioning investigation on it is not, and this is a frequent finding.
Train the authorized-versus-unauthorized distinction. Front-line staff should not be adjudicating scam claims, but they should recognize that an induced transfer and a stolen-credential transfer are different cases requiring different handling.
Track error resolution timeliness as a metric, by case, with aging. Institutions that report this see violations fall; institutions that measure only outcomes discover breaches at examination.
Reconcile Reg E claims to fraud loss data. A rise in claims of one type is frequently the earliest signal of a new fraud pattern.
Structured coverage sits inside our deposit compliance training and the Certificate in Deposit Compliance, with the wider framework in our bank compliance catalog.
A meaningful share of Reg E disputes escalate not because the institution reached the wrong conclusion but because nobody explained the conclusion in terms the customer could accept. Two conversations are worth scripting in advance.
The first is the induced-transfer conversation. A customer who wired or sent money after being deceived has suffered a real loss, and telling them the transfer was "authorized" sounds like the bank is calling them liable for being defrauded. The explanation that lands is the one that separates the two questions — whether someone else took the money, or whether the customer was persuaded to send it — and then explains what the institution can still attempt, such as a recall request, without overpromising.
The second is the no-error-found conversation. The regulation requires a written explanation and notice of the right to request the documents relied upon, and institutions that lead with that right rather than burying it get fewer escalations. A customer who can see the evidence usually accepts the outcome; a customer who receives a conclusion with no basis rarely does.
Both conversations go better when the front line is not improvising. Providing staff with plain-language explanations, reviewed by compliance, prevents the well-meaning misstatement — "we're required to refund this" or "there's nothing anyone can do" — that turns a routine claim into a complaint to the regulator.
The single sharpest edge in Regulation E is that it protects consumers and not businesses, and the practical consequences of that line are large enough that they belong in the commercial onboarding conversation rather than in a dispute.
A small business owner whose debit card is compromised may reasonably assume the same protections apply that would apply to their personal account. They generally do not. An unauthorized ACH debit against a business account is governed by the Nacha Rules — with a return window measured in two banking days rather than sixty days — and by the deposit agreement. A fraudulent wire is governed by UCC Article 4A, under which a properly authenticated payment order sticks with the customer.
That means the controls a business customer declines are frequently the only protections available to them. Three products carry outsized value for exactly this reason:
ACH positive pay, debit blocks, and filters, which let a business specify which originators may debit the account. Given the two-day return window, prevention is close to the only remedy.
Check positive pay with payee match, which addresses the altered-payee fraud that has become the dominant check fraud pattern.
Dual control and callback verification on outbound payments, which is a procedural control on the customer's side rather than a bank product, but is the one that stops business email compromise.
Framing these as fraud-loss allocation rather than as convenience features changes how they are received. A treasury officer who explains that the bank cannot reverse a wire the customer authorized, and that the callback procedure is what prevents the loss in the first place, is having a more useful conversation than one selling a service. It also puts the institution in a defensible position later: a customer who declined positive pay in writing, having been told what it protects against, is a customer whose eventual loss is a business decision rather than a dispute.
Electronic fund transfers to or from a consumer's account: ATM transactions, point-of-sale debit card transactions, ACH debits and credits, telephone transfers under a plan, online banking transfers, and preauthorized recurring transfers. Business accounts, wire transfers, and checks are outside its scope, though a check converted to ACH becomes a covered transfer.
The consumer generally has 60 days from the statement to report an error. The institution must investigate and determine within 10 business days, or may extend to 45 calendar days if it provides provisional credit within 10 business days and notifies the consumer. Results must be reported within 3 business days of completing the investigation. Extended periods of 20 business days and 90 calendar days apply to new accounts, point-of-sale debit transactions, and transfers initiated outside the United States.
Up to $50 if reported within two business days of learning of the loss or theft of the access device; up to $500 if reported after that but within 60 days of the statement; and potentially unlimited for transfers occurring after a 60-day period during which the consumer did not report. These are maximums — many institutions and card network rules impose lower limits.
Generally no. Reg E protects against unauthorized transfers, meaning those initiated by someone other than the consumer without actual authority. A transfer the consumer initiated, even under deception, is authorized in the regulatory sense — which is why scam losses often fall on the consumer while stolen-credential losses do not.
When the institution cannot complete its investigation within 10 business days and elects to take the extended period. Provisional credit for the disputed amount must be given within 10 business days and the consumer notified. Missing this deadline is the most common Reg E violation, and it stands regardless of whether the final determination was correct.
Institutions may not assess an overdraft fee on an ATM or one-time debit card transaction unless the consumer has affirmatively opted in after receiving a segregated disclosure describing the service and its fees. Recurring debit transactions and check or ACH items are not subject to the opt-in requirement, so a consumer who declined can still incur fees on those.


