Regulation E

Regulation E implements the Electronic Fund Transfer Act for covered U.S. consumer transfers, disclosures, errors, unauthorized transactions, and remittances.

Regulation E is the Consumer Financial Protection Bureau rule at 12 CFR Part 1005 that implements the Electronic Fund Transfer Act. It governs covered electronic fund transfers involving consumer accounts, including disclosures, error resolution, unauthorized-transfer liability, preauthorized transfers, prepaid accounts, and remittance transfers.

Key Takeaways

  • Regulation E protects covered consumer accounts; a business account does not become covered merely because it uses the same payment rail.
  • EFT is a broad category that can include ATM, debit-card, ACH, direct-deposit, and preauthorized transfers.
  • Consumers generally must report an error no later than 60 days after the institution sends the statement on which it first appears to preserve the rule’s standard error-resolution process.
  • An institution generally has 10 business days to investigate or can use an extended period if it meets provisional-credit and notice conditions.
  • The $50, $500, and possible post-60-day liability tiers are conditional, not an automatic allocation of every disputed transfer.
  • State law, account agreements, and network policies can provide greater protection than the federal minimum.

Coverage and Boundaries

Regulation E generally applies to an electronic fund transfer that authorizes a financial institution to debit or credit a consumer’s account. Common examples include:

  • ATM withdrawals and deposits;
  • debit-card purchases;
  • ACH credits and debits;
  • direct deposit;
  • preauthorized recurring transfers; and
  • certain online or telephone-initiated account transfers.

The rule contains exclusions and specialized provisions. Check transactions, some wire or securities transfers, business accounts, prepaid accounts, government-benefit accounts, gift cards, and remittance transfers can follow different parts of the rule or different legal frameworks. Identifying the account and transaction type is the first step.

Error Resolution Process

An error can include an unauthorized EFT, an incorrect EFT, an omitted EFT, certain bookkeeping errors, or a request for required information or clarification. Merely asking whether a transfer posted does not necessarily assert an error.

The standard section 1005.11 process can be summarized as follows:

StepGeneral ruleImportant qualification
Consumer noticeNo later than 60 days after the institution sends the statement first showing the errorNotice should identify the account and explain the type, date, and amount as far as possible
Initial investigationInstitution generally determines whether an error occurred within 10 business daysIt must begin promptly after oral notice and cannot wait for written confirmation to start
Extended investigationUp to 45 days if required provisional credit and notices are providedLonger periods can apply to certain new-account, point-of-sale debit, or foreign-initiated cases
Written confirmationInstitution may request confirmation within 10 business days after oral noticeFailure to provide requested confirmation can affect provisional credit, not the duty to begin investigating
ResultsInstitution reports results and corrects a confirmed error under the ruleDocumentation can be requested in accordance with the rule

This table is an orientation, not a deadline calculator. Prepaid, remittance, service-provider, and other provisions can modify the process.

Unauthorized EFT Liability

Regulation E uses multiple liability tiers. Which tier applies depends on facts such as whether an accepted access device was lost or stolen, when the consumer learned of the loss, when the unauthorized transfer appeared on a statement, and when notice reached the institution.

For a lost or stolen access device, reporting within two business days after learning of the loss generally limits liability to the lesser of $50 or the unauthorized transfers before notice. A later report can permit liability up to $500 under specified conditions. If an unauthorized transfer appears on a periodic statement and is not reported within 60 days after the statement is sent, the consumer may face liability for later transfers occurring after that 60-day period and before notice if the institution proves the required connection.

For an unauthorized transfer made without an access device, the first two liability tiers generally do not apply. A timely report after the statement can therefore produce a different result from a lost-card case. Consumer negligence alone cannot increase liability beyond Regulation E’s permitted limits.

Worked Example: Prompt Lost-Card Report

Assume a consumer discovers on Tuesday that a debit card was lost on Monday. An unauthorized USD 180 debit-card purchase occurred before the consumer notified the institution on Tuesday.

If the transfer meets Regulation E’s unauthorized-EFT definition and the other conditions for liability are satisfied, notice was within two business days after learning of the loss. The federal tier would generally limit liability to the lesser of USD 50 or the unauthorized transfers before notice, so the maximum under that tier would be USD 50 rather than USD 180.

The institution’s agreement, card-network policy, or state law may provide a lower liability amount. Different facts, including a delayed report or a transfer the consumer personally initiated, can change the analysis.

Practical Review Checklist

  1. Identify whether the account is primarily for personal, family, or household purposes.
  2. Determine the actual transfer type and payment rail.
  3. Separate a pending authorization from a posted transfer.
  4. Record when the consumer learned of the event and when each notice was delivered.
  5. Preserve statements, receipts, transaction identifiers, correspondence, and any access-device report.
  6. Distinguish an unauthorized transfer from an incorrect amount, duplicate, missing credit, or merchant dispute.
  7. Check state law and contractual protections in addition to Regulation E.

Common Mistakes and Limitations

  • Saying every EFT error has a 45-day investigation period without mentioning the initial 10-business-day rule and provisional credit.
  • Measuring the 60-day period from the transaction date instead of the statement transmittal specified by the rule.
  • Applying the $50/$500 access-device tiers to every unauthorized account debit.
  • Claiming late notice automatically makes the consumer liable for every disputed transfer.
  • Assuming every scam payment is legally unauthorized; a transfer the consumer initiated can require a different analysis.
  • Applying consumer Regulation E rules to a commercial account without checking coverage.
  • Waiting to report an unfamiliar transfer while trying to resolve it only with the merchant.

Authoritative Sources

FAQs

Does Regulation E apply to every electronic payment?

No. Coverage depends on the account, transaction, provider, and exclusions in the rule. Commercial accounts and some transfer systems follow different rules.

Does reporting within 60 days always limit liability to USD 50?

No. The 60-day statement rule and the two-business-day lost-access-device rule address different parts of the liability framework. The transaction mechanism and timing determine which provisions apply.

This page provides general financial and regulatory education, not legal advice or a conclusion about a specific disputed transfer. Promptly use the institution’s reporting channel and consult current rules for an actual case.

Browse Banking