Request Demo
← All posts

The 10/45/90-Day Problem: Reg E Error Resolution at Understaffed Scale

TL;DR

Regulation E gives financial institutions fixed clocks for electronic fund transfer disputes: generally 10 business days to investigate and determine, extendable to 45 calendar days (or 90 for point-of-sale, foreign-initiated, and new-account transactions) only if provisional credit is issued on time. The clocks start when the consumer alleges an error, not when your queue has capacity, and they do not toll for backlogs, turnover, or fraud spikes. Most institutions are resolving the tension between volume and deadlines by quietly thinning investigations — which trades a visible timeliness problem for an invisible quality problem that surfaces at examination. The way out is not more overtime. It is making thorough investigation cheap.

The clocks, briefly

Under Reg E’s error-resolution provisions (12 CFR §1005.11), a consumer has 60 days from the periodic statement to report an alleged error — an unauthorized transfer, a wrong amount, a missing credit. From receipt of that notice, the institution must investigate and determine whether an error occurred within 10 business days (20 for new accounts). It can take up to 45 calendar days — 90 for POS, foreign-initiated, or new-account transactions — but only if it provisionally credits the consumer within the initial 10 business days and gives the required notices. Results must be reported promptly, corrections made promptly after finding an error, and if the claim is denied, the consumer gets a written explanation and the right to the documents the institution relied on.

Two properties make this regime unforgiving. The deadlines are consumer-triggered and absolute — there is no “reasonable time” standard to argue about later. And the obligation is not to answer within the deadline; it is to investigate within it. A timely denial without a real investigation underneath is its own violation.

Why queues break now

The math has moved against dispute teams from both directions. Volume is up — P2P payment fraud, card-not-present fraud, and scam-driven claims have pushed dispute intake to levels the function was never staffed for, and every fraud wave arrives as a Reg E spike with the clock already running. Capacity is flat or down — investigation is experienced, detail-heavy work; teams are small, turnover is high, and training a competent investigator takes months. A mid-size credit union might run a handful of investigators against thousands of claims a year, each claim requiring transaction pulls, authentication review, pattern analysis, provisional credit decisions, and regulation-correct notices — under a deadline that started before anyone looked at the file.

Institutions resolve this pressure in one of three ways. Some pay the claim — auto-approving small disputes because investigating costs more than the loss, which trains fraudsters on exactly where the threshold sits. Some thin the investigation — a glance at the authentication log, a template denial — which keeps the timeliness metrics green while hollowing out the substance. Some miss deadlines outright, which at least has the virtue of being visible. The second failure mode is the dangerous one, because nothing in the ordinary course of business surfaces it. It waits for the examiner.

What the examiner actually reads

Consumer compliance examiners do not audit your average handling time. They pull files. And a defensible Reg E file answers, with evidence, a specific chain of questions: What did the consumer allege, and when was notice received? What information was gathered — transaction records, authentication data, device and location signals, account history — and what did each item show? What did the investigation consider and rule out? On what basis was the determination made, and is that basis consistent with how similar claims were decided? Were provisional credit, notices, and corrections executed on the right dates? If denied — the file that matters most — does the written explanation reflect the actual investigation, and could the institution hand over “the documents relied upon” without embarrassment?

Notice what this list is. It is not a demand for a particular outcome; examiners accept that some claims are properly denied. It is a demand for a documented reasoning process — evidence in, analysis visible, conclusion supported, treatment consistent across like cases. Which is precisely what gets thinned first when a team is underwater, because prose documentation of reasoning is the most expensive part of the work and the least visible when skipped.

Making thoroughness cheap

The standard objection to automating dispute investigation is that the determination is too consequential to hand to a model. That objection is correct about ungoverned models and irrelevant to governed ones. The investigation workflow is, in fact, unusually well-suited to structured reasoning: the evidence sources are enumerable, the regulatory tests are explicit, the deadlines are computable, and the required output — a determination with a documented basis — is exactly what a reasoning graph produces as a side effect of running. Evidence-gathering nodes pull and normalize the transaction and authentication record. Analysis nodes apply the unauthorized-transfer tests. Verification gates check that every element of the claim was addressed before a determination node can fire. Deadline logic rides alongside: provisional-credit triggers, notice dates, extension eligibility. A human investigator reviews a structured case file with the reasoning laid out — and overrides it where judgment says otherwise — instead of assembling one from scratch.

The output is the point: every claim, including the routine ones, closes with an examiner-ready artifact — what was alleged, what was gathered, what was considered, why it was decided, when each clock obligation was met. Consistency across like cases stops depending on which investigator caught the file. And the economics invert: when a thorough investigation costs minutes of review instead of hours of assembly, the auto-pay threshold drops, the thin-file temptation disappears, and the team’s scarce experience goes to the genuinely hard cases. The clocks don’t get longer. The work fits inside them.

Reg E’s deadlines were written on the assumption that investigation is expensive and must be rationed. The institutions that make investigation cheap — without making it hollow — are the ones for whom the 10/45/90 problem stops being a problem.