Regulation E, at 12 CFR 1005.11, requires an institution to investigate a consumer's report of an unauthorized electronic fund transfer within ten business days — or complete the investigation within one business day after provisionally crediting the disputed amount and take up to 45 days (90 in defined cases) to conclude — and its consumer-liability ladder caps losses at $50 or $500 depending on promptness, facts that have decided thousands of peer-to-peer fraud disputes since payment apps made "unauthorized" the contested word of the decade. The CFPB's December 2024 complaint against the Zelle network banks put the category on the record: the allegations describe screening and response failures, and whatever the enforcement outcome, the Regulation E duties themselves never moved.
3G Times publishes information, not legal advice; error-resolution questions are account-specific and belong with the institution and, where needed, counsel.
What counts as an "error" and an "unauthorized EFT"?
The regulation's error definition is broad: an incorrect transfer, an unauthorized one, a computation error, a missing documentation delivery, or a consumer's belief that a transfer was made in error — and the institution must investigate the category, not merely the subcategory the consumer happened to name. "Unauthorized" means initiated without actual authority and not ratified by the consumer; the P2P difficulty is the inducement case, where the consumer authenticated the payment under a fraudster's instruction. The interface between the definition's text and social-engineering facts is where most disputes live, and where supervisory expectations have pressed institutions toward outcomes the liability ladder alone does not dictate: staff trained to classify correctly, evidence standards proportionate to the claim, and the consumer informed of results with reasons.
How do the clocks run?
Three timelines govern. The consumer's window: report within 60 days of the statement showing the error, to preserve the full protection — late reports can narrow remedies. The investigation clock: conclude within ten business days of notice, or — the standard large-institution path — provisionally credit within ten business days, confirm the credit in writing, and extend the investigation to 45 days (90 for accounts under 30 days old, point-of-sale or foreign-initiated transfers). The determination: written notice of the outcome, with the correction and interest if an error occurred, or the statement of the investigation's basis and the consumer's right to request the documents. Every step is dated correspondence; the exam finding writes itself from an undocumented step.
| Clock | Trigger | Deadline | Extension |
|---|---|---|---|
| Consumer report | Statement showing error | 60 days | None (remedies narrow) |
| Investigation — no credit | Notice of error | 10 business days | None |
| Investigation — with provisional credit | Notice of error | 10 business days to credit | 45 days (90 defined cases) |
| Determination notice | Conclusion | Prompt; with documents on request | — |
What does provisional credit actually require?
The credit must restore the disputed amount with interest, be confirmed in writing, and be unconditional in form: the institution may reverse it only after the investigation concludes no error occurred, with written notice explaining the basis and the documents available on request, and the reversal cannot overdraw-rescind fees already incurred. The operational failures are consistent: credits posted late under the deadline's pressure, confirmations never sent, reversals executed with a form letter that explains nothing. Each is a compliance finding independent of the dispute's merits — which is why mature programs treat the correspondence package as the product, not the investigation's byproduct.
How does the P2P fraud pattern strain the frame?
The regulation assumed the consumer's account being debited by a third party; app-era fraud often has the consumer's own authenticated device sending the money. Institutions' classifications — unauthorized versus authorized-but-induced — determine outcomes, and the divergence produced both consumer harm and supervisory attention: the Bureau's 2024 complaint alleged the network's banks lacked reasonable dispute processes, and regardless of that matter's course, examiners now read P2P dispute files against the same regulation with modernized expectations. The durable compliance posture: classification standards written down, applied consistently across the fraud typology spectrum, staff trained on the inducement cases, and outcomes reported upward so the fair-treatment question is answered with data rather than anecdote.
What does this mean in practice?
- Log the notice date, not the intake date. The clocks run from the consumer's report however it arrives; the app's "report a problem" screen starts the ten-day count as surely as a branch visit.
- Template the correspondence. Provisional-credit confirmation, determination with reasons, document availability — the regulation names the letters; a missing letter is a missing control.
- Write the classification standard for induced payments. Consistency is both the fairness answer and the exam answer; inconsistency is the finding that predates the merits.
- Reconcile reversals against fees. The reversal's collateral consequences — overdraft cascades — are where remediation failures compound.
Regulation E's machinery predates the apps, but its discipline — dated steps, stated reasons, restored funds — is exactly what the P2P era asks institutions to prove. The dispute that documents itself wins; the dispute reconstructed from memories pays twice.
The correspondence archive rewards discipline beyond the rule's minimum: disputes resolved in the consumer's favor are natural inputs to fraud-pattern analytics, and the error-resolution file — properly tagged — becomes the dataset that answers the next supervisory question about typology and outcomes. Programs that treat the archive as a byproduct leave its second life on the table.
How do network rules interact with Regulation E?
They run in parallel and cannot contract around the regulation: network zero-liability programs may exceed the federal floor but never undercut it, and dispute files built to network timelines satisfy the rule only if the federal clocks and letters are separately documented. Programs that merge the two tracks into one network report discover the missing federal artifacts at exam.
What does a mature program measure?
Clock compliance by stage (notice-to-investigation start, credit timing, determination lag), provisional-credit reversal rates with reasons, and dispute outcomes by fraud typology — the three dashboards that turn the correspondence discipline into management information and answer the supervisory questions before they are asked.
Frequently asked questions
Does Regulation E cover all P2P payments?
It covers transfers from consumer accounts through electronic means — which reaches most P2P flows — with the induced-authorization boundary contested in specific fact patterns. Non-consumer accounts and certain account types sit outside; coverage analysis is account-by-account.
Reporting channels are part of the compliance surface too: the regulation runs from however the consumer reports, so every supported channel — app, phone, branch, mail — needs the same intake discipline and the same clock start. The unmonitored inbox that collects disputes is the classic aged-claim origin story.
Can the institution require a police report first?
Conditioning investigation on a police report is inconsistent with the regulation's own mechanics: the institution investigates on notice, and its affidavit path is a defined, limited step — a blanket precondition delays the clock it cannot extend.
Staffing consistency is the last mile: the ten-day clock does not pause for weekends-as-workflow-gaps, seasonal volume, or the specialist's queue. Institutions that staff dispute intake to notice-volume, not case-count, keep the clocks honest; the ones that discover backlog through aged-provisional-credit reports have already converted an operational fact into a compliance finding.
What if the consumer delays reporting for months?
The 60-day statement window preserves the full error-resolution rights; later reports leave the institution's obligations to its contract, network rules, and discretion — which is why late-reported-fraud policies exist as written programs rather than improvisation.
For more context, read ECOA Adverse Action Notices When AI Influences Credit Decisions: Circular 2022-03 in Practice.
For more context, read e-sign act consumer consent.
For more context, read ftc safeguards rule requirements.

