SardineCon SF/2026

Learn More
Detection & metrics4 min de lectura

¿Qué es Regulation E?

SUBSCRIBE

Regulation E is the US rule covering electronic fund transfers and consumer liability for unauthorized transactions. It sets error-resolution timeframes and pushes most unauthorized-transaction losses onto the institution rather than the customer, which shapes your dispute operations and where fraud losses land.

What is Regulation E, in plain English?

Regulation E is the US consumer-protection rule for electronic fund transfers: debit-card transactions, ACH, ATM withdrawals, and similar movements out of a consumer account. Its core promise is that when a transaction is unauthorized, the consumer is largely protected, and most of the loss falls on the financial institution, not the customer, as long as the customer reports it within set timeframes.

It also lays out an error-resolution process: how quickly an institution must investigate a reported error, when it must issue provisional credit, and how the case must be resolved. These timeframes are not optional, and they drive a large part of how a bank's dispute operations are built.

For a fraud or AML team, Regulation E is not abstract compliance; it directly shapes your dispute workflows, your provisional-credit timing, and, crucially, where a given fraud loss ultimately sits. Get the process right and losses land where the rule intends; get it wrong and you create both compliance and accounting problems.

Unauthorized versus authorized scam payments

The pivotal distinction under Regulation E is whether the consumer authorized the payment. That single question changes who bears the loss.

What changes

Unauthorized transaction

Authorized scam payment

What happened

Someone else moved the money

The customer was tricked into sending it

Consumer authorized it?

No

Yes, under deception

Reg E protection

Generally covered

Often falls outside

Where loss tends to land

The institution

Often the consumer

A recurring nuance is scam payments the customer was tricked into authorizing themselves. These often fall outside the unauthorized-transaction protections, so they are handled differently, which is exactly where misclassification does damage.

What it looks like in practice

In practice

A customer calls to report that money left their account and they did not make the transfer. The dispute team logs it as an unauthorized transaction, starts the Regulation E clock, and issues provisional credit within the required window.

On investigation, the story is different: the customer was talked into approving the transfer themselves by a convincing impersonation scam. It was authorized, under deception, which typically falls outside the unauthorized-transaction protections. The case had been booked in the wrong bucket, which both mishandled the customer's claim and attributed the loss to the wrong place. Correctly classifying it as an authorized scam payment changes the handling, the liability, and where the loss sits, even though on the surface both started as "I did not want this money to leave."

Why classification matters as much as deadlines

Meeting Regulation E's deadlines is only half the job. The other half is classifying the dispute correctly, because unauthorized transactions and authorized scam payments are handled under different rules, carry different liability, and land the loss in different places. Calling an authorized scam payment unauthorized, or the reverse, creates both compliance exposure and wrong loss attribution, which quietly distorts your fraud numbers.

That is why fraud, dispute, and compliance teams have to work from the same definitions. The timeframes force speed, but speed on a miscategorized case just gets you to the wrong answer faster. Getting the classification right is what keeps the institution compliant, treats the customer fairly, and books the loss where it truly belongs so the reporting reflects reality.

What to watch in the data

  • Misclassified disputes. Authorized scam payments logged as unauthorized, or vice versa, create compliance risk and wrong loss attribution; audit the categorization.
  • Timeframe compliance. Track whether investigations and provisional credits hit the required windows; missed deadlines are a direct compliance problem.
  • Scam-pattern claims. A rise in "I authorized it but was tricked" cases signals scam activity that needs different handling than classic unauthorized fraud.
  • Provisional-credit reversals. High reversal rates can point to dispute abuse or miscategorization upstream.
  • Loss attribution drift. If losses are landing in unexpected buckets, classification errors may be distorting your fraud reporting.

Quick questions

What does Regulation E cover?

Electronic fund transfers from consumer accounts, such as debit-card transactions, ACH, and ATM withdrawals. It sets consumer liability limits for unauthorized transactions and the error-resolution process institutions must follow.

Who bears the loss on an unauthorized transaction?

Generally the institution, as long as the consumer reports within the required timeframes. The rule is designed to protect consumers from most unauthorized-transaction losses rather than leaving them out of pocket.

Are scam payments covered?

Often not in the same way. When a customer is tricked into authorizing the payment themselves, it typically falls outside the unauthorized-transaction protections, so it is handled differently and the loss frequently lands on the consumer.

Why is classification so important?

Because unauthorized and authorized-scam cases carry different handling, liability, and loss attribution. Mislabeling one as the other creates compliance problems and books the loss in the wrong place, distorting your numbers.

How does Regulation E relate to provisional credit?

The rule's error-resolution timeframes are what often require provisional credit while a dispute is investigated. So Regulation E directly drives the timing and mechanics of provisional-credit issuance.

Go deeper

Qué saber junto con Regulation E