Reference🧭 Global overviewsIntermediate⏱ 20 min read

⚠️ Irrevocability and instant payment fraud

What finality prevents you from undoing, where fraud moved once chargebacks disappeared, and how each market responded: Confirmation of Payee, Verification of Payee, Brazil’s nighttime limits, MED, the UK’s mandatory reimbursement, and Singapore’s shared responsibility

What irrevocability actually covers

An instant payment is a push credit initiated by the payer, settled in seconds, and final at the moment of settlement. No subsequent message can reverse it. The payee has the funds as soon as they are credited, and the payer keeps no claim on the money transferred. Finality is a design choice: the rail was built to give the recipient funds with no strings attached. The merchant receives final funds in its bank account, with the interbank leg settled in central bank money and no risk of clawback, something neither cards nor direct debits offer.

The technical term is finality: the point in processing after which a transaction can no longer be canceled, even if both banks agree. On Pix, finality occurs at settlement in the SPI, the Banco Central do Brasil infrastructure that went live in November 2020. On SCT Inst, it occurs at settlement in TIPS or RT1. On The Clearing House’s RTP network, launched in 2017, it occurs on the system’s prefunded accounts. After that point, only one option remains: getting the payee to return the funds, or compelling the payee’s bank to do so.

InstrumentReturn mechanismInitiated bySettlement time
CardChargeback, handled through the card network under a reason codeThe cardholder, through their issuer45 to 540 days, depending on the reason code and the scheme
SEPA Direct Debit CoreUnconditional refund right, no reason requiredThe payer, through their bankEight weeks; 13 months if the mandate is disputed
Standard SEPA credit transferInterbank recall, then voluntary return of fundsThe payer’s bankNo guaranteed outcome, whatever the timeframe
Instant credit transferNo reversal; only a request for returnNo one can force it on the payeeNot applicable: the transaction is final
How reversible the major payment instruments are

Four distinct operations determine what happens to a payment already sent, and a poorly wired integration confuses them. Cancellation does not exist after finality. The request for return, camt.056 in ISO 20022, asks the payee to give the money back without obliging them to. The return itself, pacs.004, is a voluntary act by the payee’s bank and requires the payee’s consent. Finally, the refund is a new outgoing payment issued by the merchant, and it is itself irrevocable. Routing all four cases down a single path creates duplicate payments that no one recovers.

An instant payment, second by second, and the point of no return
Payer
Enters an alias and an amount, and authenticates the payment order
Pix key (chave), PromptPay mobile number, UPI VPA, Australian PayID, IBAN in the euro area
Payer’s bank
Verifies the payee, debits the account, and forwards the payment
Alias resolution, name/identifier check where the market requires it, fraud scoring within a few hundred milliseconds
Settlement infrastructure
Settles and notifies both banks
SPI in Brazil, TIPS or RT1 in the euro area, prefunded RTP network accounts in the US
Point of finality
The transaction becomes final
No one can undo it unilaterally anymore: not the payer, not the payer’s bank, not the system operator
Payee’s bank
Credits the account and notifies
The payee has the funds and can move them elsewhere a second later
🔑
The benefit and the drawback are the same feature
An instant payment carries no chargeback risk, so in sectors with high dispute rates, the cost gap with cards is substantial. The flip side is how refunds work. A merchant that wants to issue a refund has to send an outgoing payment, which draws on its cash, is subject to the rail’s limits, fails if the customer’s account is closed, and in turn becomes final. The risk of loss has not gone away: it has shifted from the issuer to the payer, and from the network to the merchant.

Where fraud has moved

Fraud displacement is the shift from fraud that targets the payment instrument to fraud that targets the payer. As long as cards dominated, fraudsters needed data: the card number, the security code, an authentication code. The industry spent two decades hardening that chain with EMV chips, tokenization, 3-D Secure, and strong customer authentication. Instant payments make that effort irrelevant, because the fraudster no longer needs to steal credentials. All it takes is getting the account holder to push the payment.

This category has a name coined in the UK, which has run an instant rail longer than anyone else: authorised push payment fraud, or APP fraud. It covers payments that account holders make themselves, under manipulation, to an account the fraudster controls. Technically, the payment is legitimate: authenticated, compliant, and executed by a genuine customer from their own device. No instrument-level check distinguishes it from an ordinary transfer, so filters that look at whether a payment order is valid let it through.

£576.4M
APP fraud losses in the UK in 2025, up 19%
UK Finance, Annual Fraud Report 2026
248 070
APP fraud cases recorded in the UK in 2025
UK Finance, Annual Fraud Report 2026
£221.5M
losses from investment fraud alone, up 40% year over year
UK Finance, Annual Fraud Report 2026
₹48,021 crore
value of fraud reported by Indian banks in fiscal 2025–26, across 10,114 cases
Reserve Bank of India, Annual Report 2025-26, May 2026

The second shift is on the receiving side. An instant rail needs a destination account that is open and can be funded and emptied within seconds. Mule accounts are therefore the fraudster’s scarcest asset, and onboarding quality is the decisive control. Brazil distinguishes three types in the fraud statistics of its alias directory, the DICT. Falsidade ideológica is an account opened with someone else’s documents, while conta laranja is an account opened legitimately and then lent out. The third category covers accounts in the fraudster’s own name.

  • Fake bank advisor: an inbound call from a spoofed number, and the customer transfers money to a “safe account” that does not exist.
  • Fake seller: peer-to-peer listings, marketplaces, ticketing; the free, instant rail is the requested payment method.
  • Swapped QR code: a sticker placed over the real one in store, or a code altered on an invoice; the payer scans a payee who is not the merchant.
  • Fake supplier: bank details changed in an email thread; this is the business version, with large ticket sizes.
  • Physical coercion: in Brazil, sequestro relâmpago (express kidnapping) means forcing a victim to make transfers while being held, and this is what led to the nighttime limits.
  • Fake investment offers: the most lucrative scam type in the UK in 2025, at £221.5 million on its own (UK Finance, 2026).
⚠️
Strong authentication does not protect against this risk
Strong authentication proves that the payer is the account holder. It does not prove that the payer knows where the money is really going. In APP fraud, authentication always succeeds, because the victim approves the payment. A security model built around “something I know, something I have” contains no check that can tell this scenario apart from an ordinary transfer. Useful countermeasures work elsewhere: payee name verification, time-based limits, and behavioral detection on the receiving side.

Checking the name before paying: CoP, VoP, and their equivalents

Confirmation of Payee, operated by Pay.UK, checks the name the payer enters against the actual holder of the destination account before the payment is executed. Launched in the UK, it was the first industry-wide countermeasure against APP fraud. The Payment Systems Regulator imposed it on the six largest banking groups through Specific Direction 10, with a March 31, 2020, deadline. Specific Direction 17 then extended it to some 400 additional providers, with deadlines of October 31, 2023, and October 31, 2024. Five years of operation have exposed where the system breaks down.

The euro area adopted the same principle and broadened it. Article 5c of the SEPA Regulation, inserted by the Instant Payments Regulation, Regulation (EU) 2024/886, has required every payment service provider in the area to offer a Verification of Payee service since October 9, 2025. The service is free. It applies to all credit transfers, instant or not, on every initiation channel. The European Payments Council standardizes the interbank messaging through a rulebook that took effect on October 5, 2025.

ResponseWhat the payer seesWhat the provider doesWho bears the risk
MatchNo flagLets the payment flow continueNormal case
Close matchThe name actually on file at the payee’s bankShows that name and lets the payer decideThe payer, who decides with full information
No matchAn explicit warning before approvalWarns without blocking: execution cannot be refused on that groundThe payer, who has been warned and owns the decision
Verification not possibleA notice that the check could not be completedProceeds: no answer within 5 seconds, provider unreachable or outside the schemeGray area: no useful information was produced
The four possible Verification of Payee responses in the euro area (Regulation (EU) 2024/886, Art. 5c; EPC VoP rulebook)

Other markets achieved the same effect through rail design, without dedicated legislation. In Australia, PayID, the alias service of the New Payments Platform launched in 2018 by Australian Payments Plus, shows the payee’s name before approval, so the check is part of the user flow rather than a legal requirement. In Brazil, resolving a chave in the DICT returns the holder’s name, partially masked. In India, the UPI virtual payment address displays the payee’s registered name. The principle is converging across markets even though its basis differs: regulation in some, rail design in others.

  • This is not an honesty check. Verification confirms that the identifier belongs to that name, not that the payee is legitimate. A fake seller collecting under their real name gets a Match.
  • The IBAN remains the legal identifier in the euro area: a Match does not fix a mistyped identifier.
  • Non-consumers can opt out of verification for their bulk payment files and opt back in at any time (Art. 5c(6)).
  • An identification code (VAT number, legal entity identifier) returns only Match or No match, never Close match.
  • The payee’s bank owns the verdict it returns: it decides what counts as a match, not the payer’s bank.
⚠️
The collection account name is an operational setting
The name on a collection account must match the name customers type in, or the name the payment page pre-fills. A company that collects under a trading name different from its legal name will trigger a string of No match results. Customers then abandon checkout, and support fields the calls without anyone tracing them back to the account name. Confirm the registered name with the account-holding bank before opening a collection channel. Name checks have applied in the UK since 2020 and in the euro area since October 9, 2025.

Built-in friction: limits, time windows, and waiting periods

Built-in friction means the amount limits, time windows, and waiting periods that a regulator, or the rail operator itself, imposes on instant payments. These limits cap how much a fraudster can extract per unit of time, the only variable left once a payment cannot be undone. Several central banks have capped their rails for this reason. The values are standardized, binding rules: merchants cannot negotiate them with their provider, and they cut off payments at times the merchant does not choose.

Brazil has turned this into a full regime. Instrução Normativa BCB nº 512 of August 30, 2024, sets a nighttime period from 8 p.m. to 6 a.m., which users can ask to move to 10 p.m. During that window, the limit is R$1,000 when the payee is an individual (art. 3º, § 7º). Contactless payments are capped at R$500 per transaction (art. 16-A, § 1º). Lowering a limit takes effect immediately; raising one takes 24 to 48 hours.

Market and railDrawbackLegal basis and year
Brazil (Pix), Banco Central do BrasilR$1,000 between 8 p.m. and 6 a.m. when the payee is an individualInstrução Normativa BCB nº 512, August 30, 2024, art. 3º § 7º
Brazil (Pix por Aproximação)R$500 per transaction, on top of the other limitsInstrução Normativa BCB nº 512, art. 16-A § 1º
India (UPI), National Payments Corporation of India₹5,000 for the first 24 hours after a new ID is created or an account is linkedNPCI rail rules, 2025
India (UPI Lite)₹1,000 per transaction, maximum on-device balance of ₹5,000NPCI, 2025; does not count toward the main limit
UAE (Aani), Al Etihad PaymentsAED 50,000 per transferCentral Bank of the UAE / Al Etihad Payments, 2023–2025
US (RTP network and FedNow Service)$10M per transactionThe Clearing House and the Federal Reserve; limit raised in 2025
Limits and windows that decide for the merchant

India chose a different kind of friction, also time-based, but tied to the age of the relationship rather than the time of day. A new UPI ID, or a newly linked account, is capped at ₹5,000 for 24 hours. The cap works like an airlock: a fraudster who has just enrolled a mule account cannot drain it for the next 24 hours. In its 2025–26 annual report, the Reserve Bank of India says it is considering deliberately adding more friction, along with a universal mechanism to immediately block all debits from an account.

ℹ️
Limits are the leading cause of rejections in production
A team running a payment funnel without the current limit schedule will blame its own checkout for drop-offs caused by the rail. Brazil is the most instructive case, because the nighttime limit applies to individual payees, not businesses. The flows actually exposed are therefore outgoing payments: marketplace disbursements to individual sellers, winnings, refunds, freelancer pay. A payout run scheduled for 9 p.m. Brasília time hits a limit even though the merchant is not the one receiving the funds. The fix is scheduling: run outgoing payments before 8 p.m.

Recovering funds after finality: MED, camt.056, and returns

After finality, three families of tools remain, each with a different legal force and a different target. A voluntary return is decided by the payee. A request for return asks the payee’s bank without being able to compel it, whereas regulated restitution requires a participant to freeze and then return the funds. Only regulated restitution guarantees a result, and only for funds still in the targeted account.

RailInstrumentLegal forceKey takeaway for integrators
Pix (Banco Central do Brasil, 2020)MED (Mecanismo Especial de Devolução), mandatory since 2021Binding on the receiving participantRecovers only funds still in the targeted account
PixVoluntary devolução via the API, pacs.004 message with reason code MD06Voluntary act by the payeeCalled on the ID of the Pix received, with an idempotent refund ID
RTP network, FedNow Servicecamt.056 request for return of fundsNone: the request does not compel anythingThe payee is not required to return the funds; risk allocation is negotiated by contract
UPI (NPCI, 2016)URCS, with automatic acceptance or rejectionAutomatic, based on the response from the payee’s bankSince NPCI circular UPI-OC-No-213-FY-2024-25 of February 10, 2025, slow reconciliation on the receiving side results in automatic losses
Recovery tools by rail
How a MED claim works in Brazil (Guia MED, Banco Central do Brasil)
Victim
Reports the fraud to their own bank
Claims accepted up to 80 days after the transaction
Payer’s bank
Reviews the report
Seven days to assess the case (proven fraud or operational failure, never a commercial dispute)
Payer’s bank
Sends the restitution request to the receiving participant
72 hours to file it
Payee’s bank
Freezes and returns the available funds
Six hours to execute; anything that has already left the account is out of reach of the original mechanism

The workaround was easy, and it was widely exploited. Fraudsters move the funds to a second and then a third account within a minute of receiving them. The Banco Central do Brasil responded with MED 2.0, mandatory since February 2026, which extends the precautionary freeze beyond the first receiving account and along the chain of destination accounts. A collector that receives disputed funds now risks having its account frozen, even when it is second in line.

⚠️
MED is not a chargeback, and confusing the two is costly
The Banco Central do Brasil states unambiguously that MED covers fraud and operational failures, not commercial disputes. A customer unhappy with a delivery does not dispute the Pix; they ask the merchant for a refund, which the merchant issues through the API. A customer service team that sends these customers to their bank generates inadmissible claims, processing delays, and frustration. The same line between fraud and civil disputes runs through every regime discussed below.

Who reimburses, market by market

Who bears the cost of APP fraud is governed by national rules, and they differ sharply from one market to the next. An operator in four jurisdictions applies four liability regimes that cannot be compared, with different caps, eligible beneficiaries, and avenues of redress. No rule carries over: a reimbursement policy written for London describes no obligation that applies in São Paulo, and vice versa.

MarketRegimeWho bears the lossLimit
UKMandatory reimbursement for payments executed since October 7, 2024Cost split 50/50 between the payer’s and the payee’s providers£85,000 per claim
SingaporeShared Responsibility Framework, MAS and IMDA, since December 16, 2024Cascade: financial institution, then telecom operator, then consumerNo cap; compensation due only if a party breached its duties
AustraliaScams Prevention Framework Act 2025, in force since February 21, 2025Best-efforts obligations imposed on banks, telecoms, and digital platformsNo compensation schedule; civil penalties up to AUD 50M
BrazilMED, mandatory for all Pix participants since 2021The fraudster, up to the funds still in the frozen accountsLimited to recoverable amounts, not the full loss
Euro areaVerification of Payee mandatory since October 9, 2025The provider at fault, if it failed to offer verification or performed it incorrectlyRefund of the amount transferred if a breach is established
United StatesNo federal regime specific to APP fraudAllocated by contract; Regulation E covers only unauthorized transfersNot applicable
Liability regimes for APP fraud

The UK regime is the most detailed, and the only one that mandates a set payout. It covers payments made over Faster Payments Service and CHAPS between two UK accounts, including when a payment initiation provider triggers them. The payer’s provider handles the claim alone and must decide within five business days, or 35 at most if it requests more information. Claims must be filed within 13 months. An optional excess of up to £100 is allowed, but it cannot be applied to vulnerable customers.

£316M
reimbursed under the UK mandatory scheme, out of £358 million in in-scope losses, from October 7, 2024, to March 31, 2026
Payment Systems Regulator
88 %
reimbursement rate within the scope of the UK mandatory scheme only
Payment Systems Regulator, 2026
61 %
reimbursement rate across all APP fraud in the UK in 2025, or £354.3 million
UK Finance, Annual Fraud Report 2026
301 500
claims within the scope of the mandatory scheme, out of 438,300 reported
Payment Systems Regulator

The gap between 88% and 61% is not a contradiction: it reflects what the regime does not cover, namely cards, international payments, other payment systems, and civil disputes. Singapore opted for a framework with no compensation schedule. It assigns specific duties first to financial institutions and then to telecom operators, and compensation is due only if one of them fails in its duties. When every party has met its obligations, the victim bears the loss alone. Australia followed the same logic of sector-specific obligations, with no schedule, and civil penalties of up to AUD 50 million.

🔑
Never promise protection the rail does not provide
Brazil’s MED returns whatever funds are still there, and nothing more, while the UK regime caps reimbursement at £85,000 and applies only to eligible payments. In the US, no federal law requires anyone to reimburse fraud that the customer authorized. Advertising “buyer protection” in a checkout settled by instant payment creates an expectation with no legal basis, and the resulting dispute is resolved at the merchant’s expense. Describing the actual protections, and their limits, always costs less than that litigation.

Operating on the collecting side

The receiving side means the institution that holds the credited account, together with the merchant or platform that collects through it. A shared liability regime changes the nature of that business: in the UK, the bank that hosts the fraudster’s account pays half of the claim. Fighting mule accounts then stops being a pure compliance issue, and its cost hits the income statement. Brazil is moving the same way, with MED 2.0 exposing second-tier accounts to freezes. Collecting on behalf of third parties therefore carries a financial risk of its own.

🪪
Align the account name
The account holder’s exact legal name must appear on invoices, bank details, and payment pages. Nothing else prevents No match results in Verification of Payee, in the euro area or in the UK.
🔍
Use the rail’s signals
In Brazil, the DICT provides fraud statistics by chave and by account holder that can be checked before paying. The operating manual prohibits showing them to end users, because they are meant to inform the participant’s decision, not to be displayed.
⏱️
Meet the regulatory clocks
In the UK, the sending provider notifies receiving providers within two hours of the report. In Brazil, the receiving participant executes a MED restitution within six hours. These deadlines have to be built into systems; they cannot be improvised.
↩️
Treat refunds as payments
Four-eyes approval above a threshold, a daily limit separate from the collection limit, a deterministic refund ID, and tracking of cumulative partial refunds. An API plugged in without these safeguards is an exit door for insider fraud.
  • Separate fraud claims from commercial refund requests from the first contact: different contact point, different deadline, different outcome.
  • Track the dispute rate by submerchant, not revenue: that is the metric that triggers an account freeze.
  • Document onboarding for every receiving account: an unidentifiable payee exposes the institution to restitution claims and penalties.
  • Align your payout schedule with the rail’s windows in the market’s local time: 8 p.m. in Brasília, not 8 p.m. at headquarters.
  • Reconcile every refund with the original sale, in both directions, using the end-to-end ID provided by the rail.
  • Measure the No match rate on your own collections: an upward drift signals a gap between the name given to customers and the name on the account.
⚠️
Silence is the worst kind of failure
An instant payment can fail in four ways: an explicit rejection, an expired request to pay, a limit breach, and silence. The first three tell you what happened to the payment order. Silence leaves the payment’s status unknown. Replaying an unanswered payment order on an irrevocable rail creates a final duplicate payment, which can then be recovered only if the payee agrees to return it. Every initiation must therefore carry an idempotency key, and every unanswered payment order must be checked with the rail before it is replayed, never blindly resent.

How awareness grew, and the blind spots that remain

None of these safeguards was designed before the rail it protects. All were added afterward, under pressure from actual losses. The gap between a rail’s launch date and its first safeguard measures how long it took for losses to become visible enough to justify a rule. A market launching an instant rail today can learn from that experience and put the safeguards in place along with the infrastructure.

2008
Faster Payments Service in the UK
The first 24/7 instant rail launched at scale in Europe, under the Pay.UK scheme. It was 17 years ahead of the euro area’s obligation to send instant payments, and of the fraud that comes with them.
2016-2017
The wave in Asia and the US
NPCI launched the Unified Payments Interface in 2016; National ITMX launched PromptPay and the Association of Banks in Singapore launched PayNow in 2017; the RTP network and Zelle went live in the US the same year.
2018
Hong Kong sounds the first warning
A few weeks after the HKMA launched its Faster Payment System, fraud led the monetary authority to suspend wallet top-ups. A regulator can freeze a function of a new rail within days.
March 31, 2020
Confirmation of Payee, first deadline
The Payment Systems Regulator’s Specific Direction 10 requires the six largest UK banking groups to check payee names.
November 2020
Pix launches
Addressing by chave, mandatory EMVCo QR codes, and compulsory participation for every institution with more than 500,000 accounts. No restitution mechanism at launch.
2021
MED goes live
The Banco Central do Brasil adds a freeze-and-return mechanism to Pix, limited to the first receiving account.
October 7, 2024
Mandatory reimbursement in the UK
The Payment Systems Regulator regime applies to payments executed from this date: £85,000 cap, cost shared 50/50.
December 16, 2024
Shared Responsibility Framework in Singapore
MAS and IMDA split the loss among the financial institution, the telecom operator, and the consumer, with no cap but no automatic payout.
October 9, 2025
Verification of Payee in the euro area
Regulation (EU) 2024/886 mandates verification on all SEPA credit transfers, alongside the obligation to send instant payments.
February 2026
MED 2.0 in Brazil
The precautionary freeze now follows the chain of destination accounts, beyond the first recipient.

Two blind spots remain. The first is timing: outside the euro area, Verification of Payee is required only from July 9, 2027, as is sending instant payments. For two years, the same euro credit transfer will be subject to two different control regimes depending on the sending provider’s country. The second blind spot is the geography of the rails, and no framework covers it yet.

Cross-border links are multiplying. PayNow–PromptPay has connected Singapore and Thailand since 2021, UPI–PayNow India and Singapore since 2023, and PayNow–DuitNow Singapore and Malaysia since 2023. Then there are the QR links of DuitNow QR, operated by PayNet, and QRIS, the Indonesian standard mandated by Bank Indonesia in 2019. No reimbursement regime crosses these borders. A Singaporean victim of fraud sent to a Thai account falls under the Singapore framework with respect to their own institution, but no rule reaches the bank that holds the receiving account.

ℹ️
What to watch in a new market
Three factors are enough to gauge the risk of an unfamiliar instant rail. First, whether there is a name check before approval, which a rule may make mandatory or a provider may merely offer. Second, whether there is a restitution mechanism, and how far back along the chain of accounts it reaches. Third, whether there is a reimbursement regime that designates who ultimately pays; without one, the victim bears the loss. Colombia shows the usual sequence: Bre-B, the Banco de la República’s public rail, entered mass operation on October 6, 2025, and passed 617 million transactions in six months. Recourse mechanisms will come later, as they have everywhere else.