Trends & Research

Trends & Research

Access the power of data and objective insight. Data from various sources, including NEACH surveys and member interviews, is compiled and made available as white papers, case studies, articles, benchmarking, and industry reports to provide a snapshot of both the current and future payments landscape. 

Published on Wednesday, July 15, 2026

FedNow® Fraud Reporting: Why the Fraud Classifier Lives Inside Your campt.056 Return Request

 

WHO KNEW? Issue #3  |  July 2026  |  FedNow® Fraud Reporting: Why the Fraud Classifier Lives Inside Your campt.056 Return Request

Welcome to WHO KNEW?, a new monthly series from NEACH that examines a single, significant development in payments — the kind of shift that warrants a closer look. Each issue follows a consistent structure: one key development, context to help make sense of it, and practical next steps for your institution. This month’s topic: FedNow® Fraud Reporting: Why the Fraud Classifier Lives Inside Your campt.056 Return Request

 

 

THE “WHO KNEW?” MOMENT

FedNow® handles fraud reporting differently from RTP®, and the distinction hinges on a single, often overlooked element: the “Additional Information” field in your camt.056 (Return Request) message. The Federal Reserve directs Participants to embed a Fraud Classifier code in that field—one that identifies both the type of fraud and the suspicious actor. While many institutions may be familiar with reason codes FR01 (returned or rejected due to fraud) and FRAD (fraudulently originated credit transfer), far fewer populate the classifier detail required by the Fed’s Operating Procedures.

Return requests submitted with WNTB (breach of warranty associated with a payment request) or FRAD reason codes, but without Fraud Classifier detail in the “Additional Information” field, are technically complete under message formatting standards yet provide little analytical value to the Federal Reserve. 

 


Q1: We use FRAD on RTP. Does FedNow work the same way?

While FedNow® and RTP® share similar reason codes, the mechanics of fraud reporting differ between the two rails. On FedNow, a Sender FI that later identifies a fraudulent transaction submits a Return Request (camt.056) with reason code FRAD. A Receiver FI that identifies fraud after initially accepting a transaction, may subsequently submit a Payment Return (pacs.004) with reason code FR01. Both message types satisfy the Federal Reserve’s fraud reporting requirement, and neither is subject to the 60-day response guidelines that govern ordinary return requests.

A key distinction from RTP is that FedNow requires Participants to include Fraud Classifier details in the “Additional Information” field, mapping each transaction to the Federal Reserve’s FraudClassifier(SM) model. This involves identifying whether the payment was unauthorized or authorized but fraudulent, and designating the suspicious actor—the customer, a third party, or an individual impersonating either. RTP’s newer UAPA code incorporates fraudulent inducement directly into the reason code. FedNow, by contrast, keeps the reason code straightforward and places the fraud detail in the message body.

 


Q2: What’s the Fraud Classifier Model, and why does it matter?

The Federal Reserve published the FraudClassifier model in 2020 as an industry-standard framework for categorizing fraud consistently across payment types. The model organizes fraud along two dimensions: whether the payment was authorized by the account holder and who was responsible—an unauthorized third party, an authorized party acting fraudulently, or the account holder themselves.

For FedNow, the Federal Reserve treats the Classifier as a required element rather than optional guidance. The Operating Procedures direct Participants to populate the Classifier detail in the “Additional Information” field when reporting fraud, both for FRAD-coded returns on credit transfers and for WNTB-coded Request for Payment warranty breaches involving fraud. Classifier data enables the Fed to identify patterns, issue meaningful fraud notifications, and share intelligence across the network.

Financial institutions that have not yet mapped their internal fraud codes to the FraudClassifier taxonomy should complete that work prior to their next FedNow fraud report submission.

 

 

Q3: What about FedNow’s fraud mitigation tools — are those separate?

In addition to fraud reporting, FedNow offers Participants two built-in preventive tools, managed through the FedNow interface: a negative list that rejects payments to or from specific RTNs or account parts, and account activity thresholds that reject payments exceeding velocity or cumulative value limits within a defined window. Rejections are communicated to the Sender FI via pacs.002 (FI to FI payment status report) messages with fraud-specific error codes, including F002 (negative list match) and F101 (other fraud control).

These tools supplement but do not replace an institution’s internal fraud program. The FedNow Service also maintains Fraud Notification Contacts on file for every Participant, which the Reserve Banks use to communicate reported fraudulent activity. Maintaining current monitored contacts ensures institutions receive timely alerts when the Federal Reserve needs to reach them.

 

 

Want to Go Deeper? 

This article serves as the FedNow companion to the prior issue’s RTP coverage. While the two rails are converging on fraud reporting requirements, meaningful operational differences remain in how those requirements are met. Institutions are encouraged to confirm that their camt.056 FRAD and pacs.004 FR01 procedures populate the Fraud Classifier detail in the “Additional Information” field, map their internal fraud categorization to the Fraud Classifier model, and verify that their Fraud Notification Contacts on file with the Federal Reserve are current and monitored. The full FedNow Service Operating Procedures (February 2026, Version 3.5) are distributed to Participants through FedLine. 

You may also find these on-demand learning sessions helpful. Once you click on the link and register, you will be redirected to the on-demand learning link.

•    What You Need to Know about the FedNow Operating Procedures—Part 1
•    What You Need to Know about the FedNow Operating Procedures—Part 2

NEACH members can reach out to the hotline with questions on implementation. 

In addition, as you explore ways to mitigate fraud across payment systems, consider joining us for The 2026 Financial Fraud & Compliance Forum, taking place virtually, August 26 and 27 from 9:00 am – 12:30 pm ET. For more information or to register, visit NEACH.org.  


 

Rate this article:
No rating
Comments (0)Number of views (2)
Print