What irrevocability actually covers
An instant payment is a push credit initiated by the payer, settled in seconds, and final at the moment of settlement. No subsequent message can reverse it. The payee has the funds as soon as they are credited, and the payer keeps no claim on the money transferred. Finality is a design choice: the rail was built to give the recipient funds with no strings attached. The merchant receives final funds in its bank account, with the interbank leg settled in central bank money and no risk of clawback, something neither cards nor direct debits offer.
The technical term is finality: the point in processing after which a transaction can no longer be canceled, even if both banks agree. On Pix, finality occurs at settlement in the SPI, the Banco Central do Brasil infrastructure that went live in November 2020. On SCT Inst, it occurs at settlement in TIPS or RT1. On The Clearing House’s RTP network, launched in 2017, it occurs on the system’s prefunded accounts. After that point, only one option remains: getting the payee to return the funds, or compelling the payee’s bank to do so.
| Instrument | Return mechanism | Initiated by | Settlement time |
|---|---|---|---|
| Card | Chargeback, handled through the card network under a reason code | The cardholder, through their issuer | 45 to 540 days, depending on the reason code and the scheme |
| SEPA Direct Debit Core | Unconditional refund right, no reason required | The payer, through their bank | Eight weeks; 13 months if the mandate is disputed |
| Standard SEPA credit transfer | Interbank recall, then voluntary return of funds | The payer’s bank | No guaranteed outcome, whatever the timeframe |
| Instant credit transfer | No reversal; only a request for return | No one can force it on the payee | Not applicable: the transaction is final |
Four distinct operations determine what happens to a payment already sent, and a poorly wired integration confuses them. Cancellation does not exist after finality. The request for return, camt.056 in ISO 20022, asks the payee to give the money back without obliging them to. The return itself, pacs.004, is a voluntary act by the payee’s bank and requires the payee’s consent. Finally, the refund is a new outgoing payment issued by the merchant, and it is itself irrevocable. Routing all four cases down a single path creates duplicate payments that no one recovers.
Where fraud has moved
Fraud displacement is the shift from fraud that targets the payment instrument to fraud that targets the payer. As long as cards dominated, fraudsters needed data: the card number, the security code, an authentication code. The industry spent two decades hardening that chain with EMV chips, tokenization, 3-D Secure, and strong customer authentication. Instant payments make that effort irrelevant, because the fraudster no longer needs to steal credentials. All it takes is getting the account holder to push the payment.
This category has a name coined in the UK, which has run an instant rail longer than anyone else: authorised push payment fraud, or APP fraud. It covers payments that account holders make themselves, under manipulation, to an account the fraudster controls. Technically, the payment is legitimate: authenticated, compliant, and executed by a genuine customer from their own device. No instrument-level check distinguishes it from an ordinary transfer, so filters that look at whether a payment order is valid let it through.
The second shift is on the receiving side. An instant rail needs a destination account that is open and can be funded and emptied within seconds. Mule accounts are therefore the fraudster’s scarcest asset, and onboarding quality is the decisive control. Brazil distinguishes three types in the fraud statistics of its alias directory, the DICT. Falsidade ideológica is an account opened with someone else’s documents, while conta laranja is an account opened legitimately and then lent out. The third category covers accounts in the fraudster’s own name.
- Fake bank advisor: an inbound call from a spoofed number, and the customer transfers money to a “safe account” that does not exist.
- Fake seller: peer-to-peer listings, marketplaces, ticketing; the free, instant rail is the requested payment method.
- Swapped QR code: a sticker placed over the real one in store, or a code altered on an invoice; the payer scans a payee who is not the merchant.
- Fake supplier: bank details changed in an email thread; this is the business version, with large ticket sizes.
- Physical coercion: in Brazil, sequestro relâmpago (express kidnapping) means forcing a victim to make transfers while being held, and this is what led to the nighttime limits.
- Fake investment offers: the most lucrative scam type in the UK in 2025, at £221.5 million on its own (UK Finance, 2026).
Checking the name before paying: CoP, VoP, and their equivalents
Confirmation of Payee, operated by Pay.UK, checks the name the payer enters against the actual holder of the destination account before the payment is executed. Launched in the UK, it was the first industry-wide countermeasure against APP fraud. The Payment Systems Regulator imposed it on the six largest banking groups through Specific Direction 10, with a March 31, 2020, deadline. Specific Direction 17 then extended it to some 400 additional providers, with deadlines of October 31, 2023, and October 31, 2024. Five years of operation have exposed where the system breaks down.
The euro area adopted the same principle and broadened it. Article 5c of the SEPA Regulation, inserted by the Instant Payments Regulation, Regulation (EU) 2024/886, has required every payment service provider in the area to offer a Verification of Payee service since October 9, 2025. The service is free. It applies to all credit transfers, instant or not, on every initiation channel. The European Payments Council standardizes the interbank messaging through a rulebook that took effect on October 5, 2025.
| Response | What the payer sees | What the provider does | Who bears the risk |
|---|---|---|---|
| Match | No flag | Lets the payment flow continue | Normal case |
| Close match | The name actually on file at the payee’s bank | Shows that name and lets the payer decide | The payer, who decides with full information |
| No match | An explicit warning before approval | Warns without blocking: execution cannot be refused on that ground | The payer, who has been warned and owns the decision |
| Verification not possible | A notice that the check could not be completed | Proceeds: no answer within 5 seconds, provider unreachable or outside the scheme | Gray area: no useful information was produced |
Other markets achieved the same effect through rail design, without dedicated legislation. In Australia, PayID, the alias service of the New Payments Platform launched in 2018 by Australian Payments Plus, shows the payee’s name before approval, so the check is part of the user flow rather than a legal requirement. In Brazil, resolving a chave in the DICT returns the holder’s name, partially masked. In India, the UPI virtual payment address displays the payee’s registered name. The principle is converging across markets even though its basis differs: regulation in some, rail design in others.
- This is not an honesty check. Verification confirms that the identifier belongs to that name, not that the payee is legitimate. A fake seller collecting under their real name gets a Match.
- The IBAN remains the legal identifier in the euro area: a Match does not fix a mistyped identifier.
- Non-consumers can opt out of verification for their bulk payment files and opt back in at any time (Art. 5c(6)).
- An identification code (VAT number, legal entity identifier) returns only Match or No match, never Close match.
- The payee’s bank owns the verdict it returns: it decides what counts as a match, not the payer’s bank.
Built-in friction: limits, time windows, and waiting periods
Built-in friction means the amount limits, time windows, and waiting periods that a regulator, or the rail operator itself, imposes on instant payments. These limits cap how much a fraudster can extract per unit of time, the only variable left once a payment cannot be undone. Several central banks have capped their rails for this reason. The values are standardized, binding rules: merchants cannot negotiate them with their provider, and they cut off payments at times the merchant does not choose.
Brazil has turned this into a full regime. Instrução Normativa BCB nº 512 of August 30, 2024, sets a nighttime period from 8 p.m. to 6 a.m., which users can ask to move to 10 p.m. During that window, the limit is R$1,000 when the payee is an individual (art. 3º, § 7º). Contactless payments are capped at R$500 per transaction (art. 16-A, § 1º). Lowering a limit takes effect immediately; raising one takes 24 to 48 hours.
| Market and rail | Drawback | Legal basis and year |
|---|---|---|
| Brazil (Pix), Banco Central do Brasil | R$1,000 between 8 p.m. and 6 a.m. when the payee is an individual | Instrução Normativa BCB nº 512, August 30, 2024, art. 3º § 7º |
| Brazil (Pix por Aproximação) | R$500 per transaction, on top of the other limits | Instrução Normativa BCB nº 512, art. 16-A § 1º |
| India (UPI), National Payments Corporation of India | ₹5,000 for the first 24 hours after a new ID is created or an account is linked | NPCI rail rules, 2025 |
| India (UPI Lite) | ₹1,000 per transaction, maximum on-device balance of ₹5,000 | NPCI, 2025; does not count toward the main limit |
| UAE (Aani), Al Etihad Payments | AED 50,000 per transfer | Central Bank of the UAE / Al Etihad Payments, 2023–2025 |
| US (RTP network and FedNow Service) | $10M per transaction | The Clearing House and the Federal Reserve; limit raised in 2025 |
India chose a different kind of friction, also time-based, but tied to the age of the relationship rather than the time of day. A new UPI ID, or a newly linked account, is capped at ₹5,000 for 24 hours. The cap works like an airlock: a fraudster who has just enrolled a mule account cannot drain it for the next 24 hours. In its 2025–26 annual report, the Reserve Bank of India says it is considering deliberately adding more friction, along with a universal mechanism to immediately block all debits from an account.
Recovering funds after finality: MED, camt.056, and returns
After finality, three families of tools remain, each with a different legal force and a different target. A voluntary return is decided by the payee. A request for return asks the payee’s bank without being able to compel it, whereas regulated restitution requires a participant to freeze and then return the funds. Only regulated restitution guarantees a result, and only for funds still in the targeted account.
| Rail | Instrument | Legal force | Key takeaway for integrators |
|---|---|---|---|
| Pix (Banco Central do Brasil, 2020) | MED (Mecanismo Especial de Devolução), mandatory since 2021 | Binding on the receiving participant | Recovers only funds still in the targeted account |
| Pix | Voluntary devolução via the API, pacs.004 message with reason code MD06 | Voluntary act by the payee | Called on the ID of the Pix received, with an idempotent refund ID |
| RTP network, FedNow Service | camt.056 request for return of funds | None: the request does not compel anything | The payee is not required to return the funds; risk allocation is negotiated by contract |
| UPI (NPCI, 2016) | URCS, with automatic acceptance or rejection | Automatic, based on the response from the payee’s bank | Since NPCI circular UPI-OC-No-213-FY-2024-25 of February 10, 2025, slow reconciliation on the receiving side results in automatic losses |
The workaround was easy, and it was widely exploited. Fraudsters move the funds to a second and then a third account within a minute of receiving them. The Banco Central do Brasil responded with MED 2.0, mandatory since February 2026, which extends the precautionary freeze beyond the first receiving account and along the chain of destination accounts. A collector that receives disputed funds now risks having its account frozen, even when it is second in line.
Who reimburses, market by market
Who bears the cost of APP fraud is governed by national rules, and they differ sharply from one market to the next. An operator in four jurisdictions applies four liability regimes that cannot be compared, with different caps, eligible beneficiaries, and avenues of redress. No rule carries over: a reimbursement policy written for London describes no obligation that applies in São Paulo, and vice versa.
| Market | Regime | Who bears the loss | Limit |
|---|---|---|---|
| UK | Mandatory reimbursement for payments executed since October 7, 2024 | Cost split 50/50 between the payer’s and the payee’s providers | £85,000 per claim |
| Singapore | Shared Responsibility Framework, MAS and IMDA, since December 16, 2024 | Cascade: financial institution, then telecom operator, then consumer | No cap; compensation due only if a party breached its duties |
| Australia | Scams Prevention Framework Act 2025, in force since February 21, 2025 | Best-efforts obligations imposed on banks, telecoms, and digital platforms | No compensation schedule; civil penalties up to AUD 50M |
| Brazil | MED, mandatory for all Pix participants since 2021 | The fraudster, up to the funds still in the frozen accounts | Limited to recoverable amounts, not the full loss |
| Euro area | Verification of Payee mandatory since October 9, 2025 | The provider at fault, if it failed to offer verification or performed it incorrectly | Refund of the amount transferred if a breach is established |
| United States | No federal regime specific to APP fraud | Allocated by contract; Regulation E covers only unauthorized transfers | Not applicable |
The UK regime is the most detailed, and the only one that mandates a set payout. It covers payments made over Faster Payments Service and CHAPS between two UK accounts, including when a payment initiation provider triggers them. The payer’s provider handles the claim alone and must decide within five business days, or 35 at most if it requests more information. Claims must be filed within 13 months. An optional excess of up to £100 is allowed, but it cannot be applied to vulnerable customers.
The gap between 88% and 61% is not a contradiction: it reflects what the regime does not cover, namely cards, international payments, other payment systems, and civil disputes. Singapore opted for a framework with no compensation schedule. It assigns specific duties first to financial institutions and then to telecom operators, and compensation is due only if one of them fails in its duties. When every party has met its obligations, the victim bears the loss alone. Australia followed the same logic of sector-specific obligations, with no schedule, and civil penalties of up to AUD 50 million.
Operating on the collecting side
The receiving side means the institution that holds the credited account, together with the merchant or platform that collects through it. A shared liability regime changes the nature of that business: in the UK, the bank that hosts the fraudster’s account pays half of the claim. Fighting mule accounts then stops being a pure compliance issue, and its cost hits the income statement. Brazil is moving the same way, with MED 2.0 exposing second-tier accounts to freezes. Collecting on behalf of third parties therefore carries a financial risk of its own.
- Separate fraud claims from commercial refund requests from the first contact: different contact point, different deadline, different outcome.
- Track the dispute rate by submerchant, not revenue: that is the metric that triggers an account freeze.
- Document onboarding for every receiving account: an unidentifiable payee exposes the institution to restitution claims and penalties.
- Align your payout schedule with the rail’s windows in the market’s local time: 8 p.m. in Brasília, not 8 p.m. at headquarters.
- Reconcile every refund with the original sale, in both directions, using the end-to-end ID provided by the rail.
- Measure the No match rate on your own collections: an upward drift signals a gap between the name given to customers and the name on the account.
How awareness grew, and the blind spots that remain
None of these safeguards was designed before the rail it protects. All were added afterward, under pressure from actual losses. The gap between a rail’s launch date and its first safeguard measures how long it took for losses to become visible enough to justify a rule. A market launching an instant rail today can learn from that experience and put the safeguards in place along with the infrastructure.
Two blind spots remain. The first is timing: outside the euro area, Verification of Payee is required only from July 9, 2027, as is sending instant payments. For two years, the same euro credit transfer will be subject to two different control regimes depending on the sending provider’s country. The second blind spot is the geography of the rails, and no framework covers it yet.
Cross-border links are multiplying. PayNow–PromptPay has connected Singapore and Thailand since 2021, UPI–PayNow India and Singapore since 2023, and PayNow–DuitNow Singapore and Malaysia since 2023. Then there are the QR links of DuitNow QR, operated by PayNet, and QRIS, the Indonesian standard mandated by Bank Indonesia in 2019. No reimbursement regime crosses these borders. A Singaporean victim of fraud sent to a Thai account falls under the Singapore framework with respect to their own institution, but no rule reaches the bank that holds the receiving account.