Insights

Instant Payments Compress the Fraud Window to Zero

A practical weekly article for community bank and credit union boards and senior leaders on instant payments governance, covering the collapse of the overnight fraud and recover...

Most boards approve an instant payments participation decision the way they approve a new channel. A vendor connection. A product expansion. A competitive response.

That framing misses the real change.

Instant payments do not just move money faster. They compress the fraud, exception, and recovery window from overnight to seconds. That is an operating model change, not a technology project. And it belongs in front of the board before the institution goes live, not after the first loss lands.

If your institution is joining FedNow, expanding participation in RTP, or building real-time capabilities into a digital wallet or fintech partnership, the governance conversation should start with one honest question.

Is the institution ready to detect, stop, and absorb fraud in real time, or is it carrying next-day controls into an instant world?

The window that used to save you is gone

For decades, community banks and credit unions relied on a simple structural protection. ACH and wire workflows gave institutions hours, sometimes overnight, to catch suspicious activity before funds became truly unreachable.

A bad transfer initiated at 4 p.m. could be reviewed, reversed, or flagged before the receiving institution released the money the next morning. Fraud teams had time. Operations had time. Compliance had time.

Instant payments remove that buffer. The Federal Reserve launched the FedNow Service in July 2023 to enable financial institutions of every size to settle payments in seconds, around the clock, every day of the year. The Clearing House RTP network, launched in 2017, operates on the same premise. Once a payment is sent and accepted, it is final.

That changes the control problem. The institution is no longer choosing whether to move money fast. It is choosing whether its fraud, exception, and recovery controls can operate at the same speed as the payment rail.

For most community institutions, the honest answer is: not yet.

The governance gap shows up when the first loss does

Boards rarely see the control timing problem in the approval packet. They see the business case. Faster payments. Better member experience. Competitive parity with larger institutions. New revenue from commercial clients who expect real-time settlement.

All true. All incomplete.

What the packet usually does not show clearly enough is what happens when a fraudulent or erroneous instant payment is initiated at 9:47 p.m. on a Saturday.

Who monitors the alerts in real time, not just during business hours?

What automated decisioning is in place to decline or hold a suspicious transaction before it settles?

What is the institution's appetite for absorbing a loss that cannot be reversed, and how is that appetite documented?

What exception workflow catches a funds transfer the moment it is authorized, rather than the next morning when someone reviews a report?

If those answers live in a slide instead of the operating model, the institution is governing the marketing of instant payments, not the risk of them.

Example one: the UK made the liability shift explicit

The clearest preview of what instant payments do to governance is not in the United States. It is in the United Kingdom.

In October 2024, the UK Payment Systems Regulator's mandatory reimbursement framework for authorized push payment fraud took effect. Under those rules, sending and receiving payment firms must reimburse victims of APP fraud, with liability split 50/50 between the two institutions. The reimbursement cap was set at 85,000 pounds per claim.

The framework exists because UK faster payments, running since 2008, made it painfully clear that real-time settlement shifts the fraud burden. When money moves in seconds and cannot be clawed back, somebody has to decide who eats the loss. The regulator answered that question by forcing both sides of the transaction to share it.

Community banks and credit unions in the United States should pay attention, even if the regulatory architecture is different. The structural lesson is the same. Instant payments change who absorbs fraud risk and how fast they have to absorb it.

A US institution joining FedNow does not currently face a UK-style mandatory reimbursement regime for most consumer fraud. But the operating pressure is similar. Customers and members who lose money through an instant payment will expect the institution to respond. Regulators are watching how institutions handle that expectation. And the window to catch the fraud before it becomes a loss has already closed by the time someone picks up the phone to report it.

Example two: Zelle showed what happens when speed outruns governance

The Zelle experience is the closest domestic warning.

Zelle, the bank-owned real-time P2P network, grew rapidly after its 2017 launch. By 2022, federal lawmakers and regulators were publicly pressing Zelle operators over fraud and scam reimbursement. In 2023, the network's operator, Early Warning Services, expanded reimbursement for certain scam victims under pressure from scrutiny by Senator Elizabeth Warren and others. Public reporting documented that consumers lost hundreds of millions of dollars to Zelle scams in prior years.

The governance lesson for community institutions is not about Zelle itself. Many community banks and credit unions participate through partners. The lesson is that when a payment network settles in seconds, fraud losses accumulate faster than the control environment can adapt.

Zelle moved money in real time. Fraud reporting, investigation, and reimbursement processes were still built on the older assumption that the institution would have time to sort it out. The gap between payment speed and control speed became the story.

Any board approving expanded instant payments participation should ask whether the institution is about to repeat that pattern at a different scale. The question is not whether fraud will happen. It will. The question is whether the control, escalation, and recovery model is designed for the speed of the rail or for the speed of the old ACH world.

What I would want in the packet before an instant payments approval

If I were sitting in the boardroom, I would want four things in plain English before management asked the board to approve expanded instant payments participation.

1. The real-time fraud control inventory

Not the policy. The actual controls.

What transaction monitoring runs in real time, not batched overnight? What automated decisioning can hold or decline a suspicious instant payment before settlement? What alerting routes to a human during off-hours, weekends, and holidays, when instant payments still run?

If the answer is "we are working on it," the institution is not ready. It might still proceed. But it should do so knowing the gap.

2. The loss absorption and appetite statement

What is the institution's documented appetite for unrecoverable instant payment losses? How is that appetite reflected in limits, monitoring thresholds, and customer communication?

If the board has not been asked to accept a loss number, management is carrying the risk without governance. That is not sustainable. The board may accept a higher number. But it should be asked.

3. The customer and member communication plan

When an instant payment loss happens, what does the customer or member hear, and when do they hear it?

Institutions that handle this well are direct. We are sorry. Here is what happened. Here is what we are doing. Here is what you should watch for.

Institutions that handle it poorly circle the situation for days, argue about whether the loss is the customer's fault, and let the story get told by social media instead of the institution. The board should know which approach the institution has chosen before the first incident, not after.

4. The off-hours operating model

Instant payments run 24 hours a day, seven days a week. Most community institutions do not staff fraud, operations, and risk functions that way.

What is the actual coverage model during evenings, weekends, and holidays? Who has authority to freeze a transaction, shut down a participant, or escalate to executive leadership when something looks wrong at 2 a.m. on a Sunday?

If that model is informal or depends on one person answering their phone, the institution is carrying an operating risk it has not really designed for.

This is a risk appetite decision, not a product launch

Community banks and credit unions should not avoid instant payments. The competitive direction is clear. Members and commercial clients expect real-time capability. FedNow and RTP are not going away.

But the board's job is not to approve the product. The board's job is to approve the risk posture that makes the product survivable.

That means forcing the fraud timing problem into the packet before the vote. It means naming the loss appetite instead of letting it default to whatever the first incident produces. It means asking whether the operating model matches the speed of the rail or just the speed of the marketing deck.

Instant payments compress the fraud window to zero. The governance question is whether the institution has a control model that can function in that compressed window.

If the answer is yes, proceed with confidence.

If the answer is "we will figure it out," the board is not governing the decision. It is deferring it.

Discussion questions

1. If a fraudulent instant payment were initiated at your institution at 9 p.m. on a Saturday, who would catch it before settlement, and what authority would they have to stop it? 2. What loss number has the board formally accepted for unrecoverable instant payment fraud, and where is that documented? 3. Which of your current fraud, exception, and reconciliation controls still assume overnight processing, and what happens to them when the payment window is measured in seconds?

Sources

  • Federal Reserve Banks, FedNow Service launch announcement, July 2023
  • The Clearing House, RTP network overview and operational documentation
  • UK Payment Systems Regulator, mandatory reimbursement framework for authorized push payment fraud, effective October 7, 2024
  • Early Warning Services, Zelle network reimbursement policy updates and public reporting, 2022 through 2023
  • FFIEC IT Examination Handbook, Architecture, Infrastructure, and Operations booklet
  • U.S. Senate and public reporting on Zelle fraud scrutiny, 2022 through 2023
Talk with FinEdge Back to Insights