WHO KNEW? Issue 2 | June 2026 | New RTP® Fraud Codes and Reporting Timelines
Welcome to WHO KNEW?, a new monthly series from NEACH that examines a single, significant development in payments — the kind of shift that warrants a closer look. Each issue follows a consistent structure: one key development, context to help make sense of it, and practical next steps for your institution. This month’s topic: New RTP Fraud Codes and Reporting Timelines
THE “WHO KNEW?” MOMENT
The increase in fraud, including credit-push fraud, has driven changes in how payments are reviewed and processed.
Most recently, The Clearing House recently updated rules on how financial institutions must report fraud within the RTP Network, with two new RTP reason codes—UAPA and UPAY—coming into effect on March 31, 2026. The UAPA code now outlines reporting requirements for RTP-native payments sent by a Sender who was deceived through impersonation, social engineering, or other fraudulent tactics. The UPAY code outlines reporting requirements for RTP-native payments that meet Request for Payment warranty claims, as described in the Request for Payment Warranty Claims Procedures.
In addition, effective March 1, 2027, a mandatory two-business-day reporting clock goes into effect when the Participant (i) determines that the RTP-native payment was unauthorized, fraudulently induced, or meets the requirements for a Request for Payment warranty claim; or (ii) the Sender or Initiating Customer reports an OBO Payment Fraud Determination (defined below in Section (d) to the Sending Participant.
RTP-participating financial institutions that have not yet updated fraud procedures to reflect these changes should prioritize doing so, ensuring compliance with the March 2026 requirements and preparing for those to go into effect in March 2027.
Q1: Our institution already submits a camt.056, an IS0 20022 message to request a return of funds, with FRAD, the code used on the RTP Network to request a return of funds, for unauthorized RTP payments. What is changing?
These two codes—camt.056 and FRAD—are no longer sufficient to capture the full range of fraudulent RTP activity.
Effective March 31, 2026, The Clearing House introduced a dedicated reason code—UAPA—for payments where the customer/member authorized the transaction but was deceived into doing so through impersonation, romance scams, business email compromise, or other forms of social engineering. Previously, these authorized but fraudulent transactions lacked a dedicated code, leaving a gap in system-level visibility into fraud.
UPAY, applies when a fraudulently induced payment also meets the requirements for a Request for Payment warranty claim. UPAY serves a dual purpose: it reports the fraud and initiates the warranty claim in a single message.
The distinction between these codes matters. Examiners, product teams, and The Clearing House fraud-monitoring systems rely on distinguishing authorized-but-fraudulent payments from true unauthorized transactions to assess risk accurately and drive appropriate responses.
Q2: What does the March 1, 2027, rule mean for institutions that originate RTP payments on behalf of business customers/members?
Institutions that send RTP payments on behalf of corporate originators, payment processors, or fintech companies operating under a sponsor bank arrangement will need to update their customer/member agreements before the March 1, 2027, effective date.
Under the new rule, when an OBO (on-behalf-of) customer/member determines that a payment was unauthorized or fraudulently induced, the customer must notify the originating institution no later than the calendar day after the determination. The institution then has two business days to report the transaction to The Clearing House using the appropriate reason code—FRAD for unauthorized payments and UAPA for fraudulently induced payments.
Notably, the rule does not require business customers to initiate a fraud investigation. However, once a determination is made—regardless of whether it arises from a regulatory, contractual, or other obligation—both the OBO customer’s/member’s notification to the institution and the institution’s report to The Clearing House are required. Institutions are encouraged to review existing OBO customer/member agreements and add appropriate fraud-reporting language before the deadline.
Q3: Do the RTP fraud alert obligations from The Clearing House require new technology infrastructure?
No technical changes are required. The Clearing House issues two categories of fraud alerts: system-level bulletins distributed to all network participants, and participant-level alerts directed to individual institutions regarding specific customers/members or anomalous activity patterns.
A documented internal process is required. At a minimum, The Clearing House expects each RTP Network participant to designate either a staff member or an automated workflow to review incoming alerts and determine whether additional action is warranted. The appropriate depth of response may scale with an institution’s size, risk profile, and product mix. However, the absence of any documented process is not considered an acceptable posture.
Institutions should ensure that, in the event of an examiner inquiry, they can clearly identify who reviews RTP fraud alerts, the review timeline, and the follow-up procedures.
Additional Resources and Recommended Action Items
The full rules interpretation was issued on October 29, 2025, and is available directly from The Clearing House . Institutions are encouraged to prioritize the following action items:
• Review OBO customer agreements and incorporate fraud-reporting language ahead of the March 1, 2027, deadline.
• Document the institution’s internal process for reviewing The Clearing House fraud alerts, including the party responsible and the steps taken upon receipt.
NEACH members should contact the NEACH hotline with questions about implementation. These changes are expected to appear in examinations, and preparedness documentation should be in place well before the applicable deadlines.
Want to Go Deeper?
Interested in understanding the RTP Operating Rules in greater depth? NEACH invites you to explore our two on-demand sessions:
• What You Need to Know about the RTP Operating Rules—Part 1
• What You Need to Know about the RTP Operating Rules—Part 2
Sign up today to gain valuable insights and stay ahead in your knowledge of RTP Operating Rules!
---
Source: RTP Rules Interpretation: Fraud Reporting and Acting on Alerts, RTP Operating Rule II.G. Accessed online at https://www.theclearinghouse.org/-/media/New/TCH/Documents/Payment-Systems/Fraud-Reporting-and-Acting-on-Alerts-Rules-Interpretation----issued-10292025.pdf?rev=1b234954f9bf4f7a835e247398ebe924&hash=7E2A9C9916E294195DC6CE2AB933F21E on April 28, 2026.
Ibid.
Ibid.