Reg E dispute management comes down to four numbers: 10, 45, 3, and 1. Once a financial institution receives a valid notice of error under 12 CFR §1005.11, it must complete its investigation within 10 business days (or extend to 45 calendar days under specific conditions), report results to the consumer within 3 business days of finishing that investigation, and correct any confirmed error within 1 business day of the determination. Every operational decision in your error-resolution program flows from that sequence.
The statutory anchor is §1005.11 (Regulation E) and its companion §205.11 cross-reference, both tied to liability limits under §1005.6. Miss a deadline or shortcut the investigation, and you are looking at an examiner finding, not just an unhappy accountholder.
A compliant Reg E program has three moving parts: accept the notice (oral or written, within 60 days of the relevant periodic statement), investigate without delay (never pending a merchant or police report), and provisionally credit the account when the 45-day extension applies, unless a specific exception excuses it.
Here is the operational floor every institution needs in place:
- Accept error notices by phone, in person, or in writing. Do not require a signed form before the clock starts.
- Begin the investigation the same day the notice is received. Waiting on a merchant response or police report is a documented violation, not a gray area.
- Provisionally credit the account within 10 business days if you invoke the 45-day extension, unless the $50 withholding exception or another listed exception applies.
| Deadline | Trigger | Action Required |
|---|---|---|
| 10 business days | Notice of error received | Complete investigation or begin 45-day extension with provisional credit |
| 45 calendar days | Extension invoked | Finish investigation and provisional credit already posted |
| 3 business days | Investigation completed | Report findings in writing to the consumer |
| 1 business day | Error confirmed | Correct the account, including interest and fees |
Key Takeaways
Effective Reg E dispute management requires meeting the 10/45/3/1-day timeline, conducting a fact-specific investigation of internal records, and documenting every decision as if an examiner will read it.
| Point | Details |
|---|---|
| Follow the four deadlines | Complete investigations in 10 business days (or 45 with provisional credit), report in 3 days, correct in 1 day. |
| Classify errors correctly at intake | Unauthorized transfers, incorrect amounts, and omitted transfers each trigger the same statutory clock. |
| Investigate your own records first | Reviewing merchant history alone, without transaction-specific data, is the top examiner finding. |
| Document extensions and denials | Every extension past 10 or 45 days needs a written, fact-based justification. |
| Pair automation with human review | Bitecode builds modular case-management systems that automate deadline alerts and evidence collection while keeping human checkpoints for final decisions. |
Reg E Dispute Resolution: What Counts as an Error
Not every complaint is an “error” under Regulation E, and misclassifying one at intake is how institutions lose track of a deadline before they even know it started. The regulation defines an error narrowly but broadly enough to cover most of what shows up in a dispute queue: unauthorized electronic fund transfers, incorrect transfers to or from the account, an EFT the institution omitted from a periodic statement, a computational or bookkeeping error the institution itself made, an ATM that dispensed the wrong amount, an EFT that appears on a statement without enough information to identify it, and a consumer request for documentation or clarification about a transfer, according to the official Regulation E text.
Mapped to real cases, that means:
- A card used fraudulently after a phishing attempt (unauthorized EFT).
- A merchant that captures a purchase twice for the same transaction (incorrect transfer amount).
- An ACH credit the consumer expected but never appears on the statement (omitted transfer).
- A refund the merchant processed but the ledger never reflected (institutional computational error).
- A point-of-sale terminal that posts $45.00 instead of $4.50 (incorrect transfer amount, often tied to merchant system errors rather than fraud).
Every one of these categories triggers the same statutory clock, regardless of dollar amount or whether fraud is suspected.
Some inquiries don’t qualify, and routing them as Reg E errors just burns investigative bandwidth. A routine balance inquiry is not an error. A request for a duplicate statement copy for tax purposes is not an error, even though it involves the same periodic statement that governs your 60-day notice window. Recognizing the difference at first contact keeps your dispute log clean and your metrics honest when an examiner asks how many notices you received versus how many you actually investigated under §1005.11.
Consumer Notice Requirements: Timing and Content
The 60-day clock is the single most consequential date in the entire process, and it starts running the day the institution sends the periodic statement reflecting the disputed transaction, not the day the transaction occurred. A notice received within that 60-day window is timely even if the consumer calls it in rather than writing it down. Oral notice is fully valid under Regulation E, though the institution may require written confirmation within 10 business days of the oral notice as a condition of provisional credit.
A compliant notice does not need a specific form, but it does need enough substance for your team to act:
- The consumer’s name and account number.
- An explanation of why the consumer believes an error occurred.
- The type, date, and amount of the error, to the extent the consumer can provide it.
Frontline staff should capture all three fields at first contact, even if the consumer’s explanation is vague. A consumer who says “there’s a charge I don’t recognize” has still triggered your obligation to investigate, even without a merchant name or exact date.
Pro Tip: Build a mandatory intake script for call center and branch staff that captures the exact date and channel of first contact, whether the notice was oral or written, and whether you requested written confirmation. This single record often becomes the deciding factor in whether an examiner agrees your 10-day clock started when you say it did.
If you require written confirmation of an oral notice, document the request date and the consumer’s response date separately from the original notice date. The 10-business-day rule for investigation timing runs from the original oral notice, not from when the written confirmation arrives, and conflating the two dates is a common source of self-inflicted timeline violations.
Reg E Dispute Management Timelines and Provisional Credit Rules
The 10-business-day rule is the default. A financial institution must determine whether an error occurred within 10 business days of receiving the notice. If it can’t finish that fast, most institutions extend the investigation to 45 calendar days, but that extension comes with a price: provisional credit must post to the consumer’s account within 10 business days of the original notice, including any interest the account would have earned.
Once the investigation concludes, whether at day 10 or day 45, two more deadlines apply. The institution must report results to the consumer within 3 business days after completing the investigation, and if it finds an error, it must correct the account within 1 business day of that determination, according to the CFPB’s error-resolution rule. Certain circumstances, including new accounts or foreign-initiated transactions, allow the 10-day and 45-day windows to stretch to 20 business days and 90 calendar days respectively, but the extension must be documented with a specific, fact-based justification. Examiners routinely flag extensions that lack a written rationale.
| Scenario | Investigation Window | Provisional Credit Required? |
|---|---|---|
| Standard dispute | 10 business days | No, if resolved within 10 days |
| Extended investigation | 45 calendar days | Yes, within 10 business days |
| New account (30 days or less) | Up to 20 business days / 90 calendar days | Yes, if extended |
| Reasonable basis for unauthorized EFT | 45 calendar days | Yes, minus up to $50 withholding |
The $50 withholding exception is narrow. An institution may withhold up to $50 of the provisional credit only if it has a reasonable basis to believe the transfer was unauthorized and it meets the notice and liability-limit requirements of §1005.6(a). “Reasonable basis” means documented, transaction-specific evidence, not a general policy of withholding $50 from every extended case.
Provisional credit is not required in a handful of listed situations, most notably when the institution has requested written confirmation of an oral notice and the consumer fails to provide it within 10 business days.
Consider a practical example. A consumer disputes a $600 unauthorized ACH withdrawal on day 1. Your team cannot complete the investigation within 10 business days, so you extend to 45 days. By day 10, you must credit $550 to the account ($600 minus the $50 withholding, assuming you have documented reasonable suspicion of unauthorized activity) plus any interest the funds would have earned. If your investigation later confirms the transfer was unauthorized, you owe the remaining $50 and must notify the consumer of the final resolution within 3 business days of completing the investigation.
How to Conduct a Reasonable Investigation Under Regulation E
Examiners consistently flag “reasonable investigation” as the weakest link in Reg E dispute resolution programs, and the reason is almost always the same: institutions review too little of their own data before reaching a conclusion. Consumer Compliance Outlook points to supervisory testing that has caught institutions denying claims based on nothing more than the consumer’s prior transaction history with a merchant, without ever pulling the specific transaction records at issue.
A defensible investigation follows a consistent sequence, especially important in the context of regulated digital banking.
- Verify intake completeness. Confirm the notice includes enough information to investigate; if not, follow up immediately rather than letting the clock run on an incomplete file.
- Triage by error type. Unauthorized transfer, incorrect amount, and omitted transfer each call for a different evidence trail, so classify the claim before pulling records.
- Pull internal records first. Authorization logs, access-device history, ACH trace numbers, POS transaction data, and any customer service notes tied to the account.
- Contact the merchant or processor only as a supplement. Never as a substitute for your own system review, and never as a reason to pause the clock.
- Document the decision with specific facts. Cite the exact record that supports your conclusion, not a general statement that “the transaction appears valid.”
The types of internal evidence that matter most:
| Record Type | Why It Matters |
|---|---|
| Transaction and authorization logs | Establish whether the cardholder or device authenticated the transfer |
| Access-device history | Shows PIN, biometric, or token use tied to the disputed transaction |
| Switch or processor messages | Confirm what data the merchant terminal actually transmitted |
| Dispute and reason codes | Indicate how the network classified the transaction at the time |
| Reconciliation reports | Reveal whether the institution’s own ledger matches the consumer’s statement |

Documentation standards matter as much as the investigation itself. Every case file should include a chronological log of investigator actions, copies of the internal records reviewed, any merchant or processor communications, the provisional-credit calculation if one applied, and a final written explanation that cites the specific regulatory basis for the decision. Consumer Compliance Outlook describes this kind of examiner-ready packet as one built around a clear index and a fact-specific narrative, not a checklist with boxes checked and no supporting detail.
On the decision itself, the burden sits with the institution to show its investigation was reasonable, not with the consumer to prove the transaction was fraudulent. When the evidence is ambiguous, that ambiguity typically favors provisional credit rather than denial. When you do deny a claim, the file should show exactly which record contradicted the consumer’s account, not a generic reference to “account history” or “similar past disputes.”
Pro Tip: Train investigators to write their denial rationale as if an examiner will read it cold, with no context. A denial that says “prior EFTs to this merchant were authorized by the consumer” is a red flag; a denial that says “the disputed transaction used the same device fingerprint and IP address as three prior authorized transactions, per authorization log entry #4471” is defensible. A modular case-management workflow can help standardize that level of documentation across an entire investigations team.
When No Error or a Different Error Is Found
If the investigation concludes that no error occurred, or that a different error occurred than the one the consumer described, the institution owes the consumer a written explanation, and that explanation needs substance behind it. The consumer also has the right to request copies of the documents the institution relied on in reaching its decision, and the institution must provide those copies in a form the consumer can actually read, converting legacy formats where necessary, per the governing regulation.
Debiting a provisional credit after a negative finding is not automatic. The institution may debit the account, but it must first give the consumer at least five business days’ notice, along with the date the debit will occur.
Practically, that notice should include the exact debit date, the dollar amount, and a plain-language reason tied to your written explanation. Vague debit notices generate a disproportionate share of follow-up complaints and reassertions, simply because the consumer doesn’t understand why money is disappearing from an account they thought was resolved.
Once you’ve completed a compliant investigation and sent the required written explanation, your obligations under that specific notice are generally satisfied. The narrow exception: if the consumer requests the underlying documents and those documents reveal something the original investigation missed, the consumer can reassert the claim, and you need a process for reopening the file rather than treating a reassertion as a duplicate notice to be dismissed.
Common Reg E Violations Examiners Cite
The same handful of failures shows up again and again in supervisory findings, and most of them trace back to shortcuts under time pressure rather than a misunderstanding of the rule itself.
- Delaying investigations pending merchant or police reports. Regulation E does not permit this, and examiners treat it as a straightforward timeline violation, not a judgment call.
- Summary denials with no internal record review. Denying a claim based on merchant reputation or prior consumer behavior, without pulling transaction-specific data, is the most frequently cited failure of the “reasonable investigation” standard.
- Missing provisional credit on extended investigations. Institutions that invoke the 45-day window but forget the 10-day credit deadline create a compounding violation.
- Misapplying the $50 withholding exception. Withholding $50 by default, rather than case by case with documented reasonable basis, does not satisfy §1005.6(a).
- Thin documentation of decision rationale. A file that lacks fact-specific reasoning is difficult to defend in an exam, even when the underlying decision was correct.
A remediation program should include periodic sampling of closed cases, specifically the denials, to test whether staff are actually reviewing internal records or defaulting to templated language. Testing previously denied notices is one of the more effective corrective controls institutions have adopted, paired with refresher training whenever sampling reveals a pattern of thin justifications.
Pro Tip: Track your extension rate over time. A sudden jump in 45-day extensions, without a corresponding jump in complexity, often signals a staffing or training gap rather than a genuine increase in difficult cases.
Balancing Automation With Human Judgment in Dispute Investigations
Automated flagging tools are useful for triage, but a workflow that denies claims automatically based on a fraud score or a merchant blocklist runs headlong into the reasonable-investigation standard. The risk isn’t automation itself, it’s automation that skips the fact-specific review examiners expect to see in every file, confirmed or denied.
The better model pairs automated routing with mandatory human checkpoints. Let automation flag high-risk patterns, pull the relevant records, and calculate provisional-credit amounts, but require a human investigator to review and document the specific evidence before any denial goes out. Set thresholds, dollar amount, transaction type, or prior dispute history, that force a case into deeper manual review rather than letting a system close it unattended. That structure gets you speed on the routine cases without losing the judgment that a compliant investigation requires. Institutions building out automated fraud triage should treat the automation as an intake and evidence-assembly tool, not a decision-maker.

Reducing Reg E Risk With Modular Case Management
Manual dispute tracking in spreadsheets or generic ticketing tools is where most timeline violations start, not from a lack of policy knowledge but from missed alerts and scattered evidence. Bitecode builds modular case-management systems specifically for compliance workflows like Reg E investigations, starting with a substantial portion of the core system already built, so your team gets a working intake, timeline, and documentation platform without a multi-year development cycle.

A well-built system configures intake forms to capture every required notice field automatically, triggers alerts ahead of the 10, 45, 3, and 1-day deadlines, and generates evidence-collection templates that match what examiners expect to see in a case file. When an investigation closes, the export becomes examiner-ready on its own, without a separate scramble to assemble documentation after the fact. Bitecode also builds the automated audit-trail and workflow layer that connects dispute intake to your broader fraud detection and reconciliation systems, so a flagged transaction doesn’t sit in a silo separate from your case file.
None of this replaces legal review for novel or high-risk cases, but it removes the operational friction that turns a defensible investigation into a missed deadline. If your current process depends on manual tracking and institutional memory, start a compliance workflow assessment with Bitecode to see where a modular system would close the gap fastest.
Primary Sources for Reg E Compliance
Start with the regulation itself, then move to supervisory guidance for how examiners interpret it in practice.
- 12 CFR §1005.11 / §205.11, the core error-resolution procedures, via the CFPB.
- The full Regulation E text through govinfo.gov.
- The e-CFR version via Cornell’s Legal Information Institute, useful for cross-referencing §1005.6.
- CFPB compliance FAQs for plain-language summaries of obligations.
For novel fact patterns, cross-border transfers, or cases touching multiple regulations, loop in counsel or your primary federal regulator before finalizing a decision.
Frequently Asked Questions About Reg E Dispute Management
What is the deadline for a consumer to report an error under Regulation E? A consumer has 60 days from the date the institution sends the periodic statement reflecting the disputed transaction to submit a notice of error, whether oral or written.
Can an institution require written confirmation of an oral error notice? Yes. The institution may require written confirmation within 10 business days of the oral notice, but this cannot be used to delay the start of the investigation itself.
How much can an institution withhold from provisional credit? Up to $50, and only if the institution has a documented reasonable basis to believe the transfer was unauthorized and meets the requirements of §1005.6(a).
What happens if an institution misses the 10-business-day investigation deadline? It must extend to 45 calendar days and provisionally credit the account within 10 business days of the original notice, unless a specific listed exception applies.
Is delaying an investigation to wait for a merchant’s response allowed? No. Regulation E requires institutions to begin investigating promptly upon receiving notice, and waiting on merchant or police input is a commonly cited examiner violation.
What must a written explanation include when no error is found? It must explain the basis for the decision and inform the consumer of their right to request copies of the documents the institution relied on during the investigation.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- § 1005.11 Procedures for resolving errors. | Consumer Financial Protection Bureau
- Govinfo
- 12 CFR § 1005.11 - Procedures for resolving errors. | Electronic Code of Federal Regulations (e-CFR) | LII / Legal Information Institute
- Electronic Fund Transfers FAQs | Consumer Financial Protection Bureau
