An unauthorized charge on a checking account is not the account holder’s loss to absorb alone — federal law caps how much a customer can be forced to pay and requires the bank to investigate and, where warranted, refund the money. The protection lives in Regulation E, which implements the Electronic Fund Transfer Act and governs debit-card charges, ATM withdrawals, and other electronic transfers. Its shield is powerful but time-sensitive: the amount a customer is liable for climbs the longer a fraudulent transfer goes unreported, and one deadline in particular can turn a fully recoverable loss into an unlimited one.
How the liability tiers reward fast reporting
Regulation E sorts a customer’s potential liability for unauthorized transfers into tiers set by timing. When a debit card or other access device is lost or stolen, a customer who notifies the bank within two business days of learning of the loss is liable for no more than $50. Waiting longer raises the ceiling: reporting after those two business days, but still within the window tied to the account statement, can expose the customer to as much as $500 of the unauthorized transfers.
The structure is built to reward speed. Each tier assumes the customer could have limited the damage by acting sooner, so the law shifts more of the loss onto an account holder who delays. For fraud that does not involve a lost or stolen card — an unauthorized transfer a thief arranges without ever holding the device — a customer who spots the charge on a statement and reports it promptly generally faces sharply limited liability, provided the report comes inside the key deadline.
The caps have defined edges built into the very definition of an unauthorized transfer. A charge does not count as unauthorized, and the protections do not apply, if the account holder voluntarily handed the card, PIN, or login to another person, unless the bank was told that authority had ended. Transfers a customer makes and later regrets, and plain bank errors, fall outside the rule as well. Regulation E shields genuine fraud, not a transaction the customer set in motion, which is one reason a debit card can leave a holder more exposed than a credit card carrying its own separate protections.
Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.
The 60-day statement deadline and what missing it costs
The pivotal date is 60 days from the day the bank sends the statement showing the unauthorized transfer. A customer who reports within that window keeps the protective liability caps in place. A customer who does not can become liable for the unauthorized transfers that occur after the 60 days close and before the bank is finally notified — amounts the institution can show would not have happened had it been told in time. That later liability is not held to $50 or $500.
The practical lesson is to read statements, because the clock runs from when the bank transmits the statement, not from when the customer happens to open it. A fraudulent transfer buried in an unread statement can quietly consume the 60-day protection while the account holder assumes the money is safe. The deadline turns a routine habit — checking each statement against actual spending — into the difference between a $50 loss and a potentially open-ended one.
What the bank must do once an error is reported
Reporting the charge sets a second set of rules in motion. Under Regulation E’s error-resolution procedures, a bank that receives notice of an unauthorized transfer must generally investigate and resolve the matter within 10 business days. If it needs more time, it may take up to 45 days to finish investigating, but only if it provisionally credits the disputed amount to the account so the customer is not left short while the review runs.
If the investigation confirms an error, the bank must correct it — typically within one business day of that finding — including crediting any interest and refunding fees the error caused. The obligation is not discretionary; the regulation requires the refund once the unauthorized transfer is established. That combination, a capped loss plus a mandated investigation and refund, is what makes a timely report the decisive act. The customer’s leverage is strongest at the beginning, before the 60-day window closes and while the liability ceilings still apply.
The error-resolution clock has a slower version for harder cases. For a newly opened account, a transaction made at a point of sale, or a transfer initiated outside the United States, the bank gets more room — up to 20 business days to issue provisional credit and as long as 90 days to finish investigating, rather than the standard 10 and 45. The provisional-credit condition still holds, so the customer is not meant to be left without the disputed funds while the longer review runs.
The report itself can begin with a phone call, but the bank may require the customer to put it in writing within 10 business days; if that written confirmation never arrives, the institution is not obligated to advance provisional credit. When the review ends, the customer is entitled to the documents the bank relied on, and a bank that finds no error must explain that conclusion in writing before it can pull back any credit it had already advanced.
The whole framework rests on a single behavior it cannot supply: someone has to notice the charge and speak up. Regulation E limits the loss and forces the bank’s hand, but only after a customer flags the transfer inside the deadline. The refund a defrauded account holder can force is real, and it is easiest to secure by treating every unfamiliar line on a statement as worth a phone call before the calendar erodes the protection.
This article was researched and drafted with the assistance of artificial intelligence.
More Financial Reading