2.2 Regulation E: Error Notices and Unauthorized Transfer Liability
Key Takeaways
An oral error notice can trigger an EFT investigation without a written affidavit.
Unauthorized-transfer liability depends on the access-device and statement-notice timelines.
Negligence alone does not enlarge the consumer’s liability beyond Regulation E limits.
Annual Error Resolution Notice Options
Depository institutions must deliver error resolution notices to consumers on an ongoing basis using one of two permissible compliance methods under 12 CFR § 1005.8(b):
- Annual Long-Form Method: Mailing or delivering the full error resolution notice (substantially similar to Model Form A-3) at least once per calendar year; or
- Periodic Short-Form Method: Including the abbreviated summary error notice (substantially similar to Model Form A-4) on or with each monthly or quarterly periodic statement.
Periodic Statements (12 CFR § 1005.9)
Periodic account statements provide consumers with documentation necessary to track account activity, reconcile ledger balances, and identify unauthorized transactions within regulatory reporting deadlines.
Delivery Frequency Rules
- Monthly Statements: An institution must deliver a periodic statement for each monthly cycle in which one or more electronic fund transfers occur.
- Quarterly Statements: If no electronic fund transfers occur during a statement cycle, the institution must provide a periodic statement at least once every three months (quarterly).
Mandatory Periodic Statement Disclosures
Under 12 CFR § 1005.9(b), periodic statements must disclose:
- Transaction Posting Date: The calendar date on which each electronic fund transfer posted to the account.
- Transfer Amount: The net dollar amount of each transfer, including any separately disclosed ATM surcharge fees.
- Transfer Type and Account Affected: The classification of the transfer (e.g., ATM cash withdrawal, point-of-sale purchase, preauthorized ACH debit) and the specific consumer account debited or credited.
- Terminal Identification: For transfers initiated at an electronic terminal (ATM or POS terminal), the physical location including street address, city, and state, or an established unique terminal code.
- Account Identifier: The consumer's account number or truncated access device identifier.
- Itemized EFT Fees: An itemization of all fees assessed for EFT transactions during the statement period.
- Beginning and Ending Balances: The starting balance and closing balance for the statement cycle.
- Error Resolution Contact: The dedicated postal address and telephone number designated for receiving consumer error inquiries.
- Preauthorized Credit Verification: A telephone number that consumers can call to verify whether preauthorized electronic deposits (such as payroll or government benefits) have posted, if the bank does not provide positive notice.
Consumer Liability Tiers for Unauthorized Transfers (12 CFR § 1005.6)
Regulation E balances consumer protection against the requirement that account holders exercise reasonable diligence in safeguarding access devices. The regulation establishes a three-tiered liability structure for unauthorized transfers involving lost or stolen access devices, as well as distinct rules for compromises not involving access devices.
Statutory Conditions for Imposing Consumer Liability
A financial institution may hold a consumer legally liable for an unauthorized electronic transfer only if three conditions are satisfied under 12 CFR § 1005.6(a):
- The access device was an accepted access device (the consumer requested and received it, or signed/used it, or received a renewal/substitute);
- The institution provided complete initial disclosures (§ 1005.7), including liability rules and contact information; and
- The institution provided a validated means of identification, such as a Personal Identification Number (PIN), biometric verification, signature verification, or chip authentication.
The Three-Tier Liability Structure for Lost or Stolen Access Devices
When an unauthorized transfer involves a lost or stolen access device (such as a debit card or ATM card), liability is governed by strict statutory windows:
| Liability Tier | Consumer Reporting Timeline | Maximum Consumer Liability Limit |
|---|---|---|
| Tier 1: Timely Notice | Consumer notifies institution within 2 business days after learning of the loss or theft of the access device. | Lesser of $50 OR the actual total of unauthorized transfers occurring prior to notice. |
| Tier 2: Delayed Notice | Consumer notifies institution after 2 business days of learning of loss/theft, but within 60 calendar days after transmittal of the periodic statement showing unauthorized EFTs. | Lesser of $500 OR the sum of: (1) $50 or unauthorized transfers in first 2 business days, PLUS (2) unauthorized transfers occurring after 2 business days up to 60 calendar days that the bank proves would not have occurred with timely notice. |
| Tier 3: Extended Inaction | Consumer fails to notify institution within 60 calendar days after transmittal of the periodic statement showing the unauthorized EFTs. | Unlimited liability for unauthorized transfers occurring after the close of the 60-day period until notice is given, PLUS applicable earlier-tier liability. The institution must establish that later transfers would have been prevented by timely notice. |
Unauthorized Transfers Not Involving an Access Device
When an unauthorized electronic fund transfer occurs without the loss or theft of a physical access device (such as when an an unauthorized ACH debit occurs without loss or theft of an access device; a stolen code or PIN can itself be an access device):
- Within 60 Calendar Days: The consumer has $0 liability for any unauthorized transfers occurring within 60 calendar days following the transmittal of the periodic statement showing the unauthorized transfer.
- After 60 Calendar Days: The consumer faces unlimited liability for unauthorized transfers occurring after the 60 calendar day window until notice is provided, provided the financial institution proves that the subsequent transfers would have been prevented had the consumer provided timely notice within the 60-day timeframe.
Extenuating Circumstances and State Law Preemption
- Extenuating Circumstances: If the consumer's delay in notifying the financial institution was caused by circumstances beyond their control (e.g., extended international travel, hospitalization, incapacitation, or active military deployment), the institution must extend the notification deadlines to a reasonable period.
- State Laws and Network Rules: More protective state liability rules are preserved by Regulation E; they do not replace the federal investigation duties. Similarly, payment card network rules (such as Visa or Mastercard Zero Liability policies) operate contractually to eliminate consumer liability for unauthorized card transactions, though Regulation E remains the mandatory federal regulatory benchmark during compliance examinations.
A consumer learns on Friday that a debit card was stolen. Assume the bank carries on substantially all business functions Monday through Friday, with no holidays. Unauthorized withdrawals total $120 on Saturday, $200 on Tuesday, and $300 on Wednesday. The consumer reports the theft Thursday. The bank proves the Wednesday loss would have been prevented by timely notice and satisfies all conditions for imposing liability. What is the maximum federal liability?
$350: the lesser of $500 and $50 plus the preventable $300 after the two-business-day period.
$500 automatically whenever notice is late.
$620 because all transfers preceded notice.
$0 because no statement had yet been sent.
Sections you finish are checked off in the contents.