How Regulation E Limits Consumer Liability for Unauthorized Electronic Fund Transfers
Regulation E caps consumer liability for unauthorized electronic fund transfers at the lesser of $50 or the actual unauthorized amount, up to $500, or potentially unlimited amounts, depending almost entirely on timing.
Lose a debit card and don't notice for a few days, and the money you're on the hook for can jump fast — from the lesser of $50 or the actual unauthorized amount, up to the lesser of $500 or a two-part sum, and in some cases to an unlimited amount. Regulation E, the federal rule that governs electronic fund transfers, sets these limits based almost entirely on timing. Here's how the three tiers work, with a lost-card example to show what they mean in dollars.
The three liability tiers, in plain terms
Regulation E's official interpretation of 12 CFR §1005.6(b) breaks consumer liability for unauthorized electronic fund transfers into three possible tiers: up to $50, up to $500, or an unlimited amount, with the applicable tier depending on how quickly you report the loss or theft. These tiers aren't mutually exclusive — because each one corresponds to a different, sometimes overlapping, time period, more than one can apply to the same incident depending on when different unauthorized transfers happened. In practice, this means your total liability can be a sum of pieces from more than one tier, not just a single flat number. Before any of these caps apply, though, the bank has to have done its part first.
The fine print: when the bank can even hold you liable
None of the liability tiers kick in automatically. Regulation E only lets a financial institution hold you liable for an unauthorized transfer if it already gave you the disclosures required under §1005.7(b)(1), (2) and (3). If the unauthorized transfer involved something like a debit card, that card also has to be an
accepted access device, and the bank must have had a way to identify you as the person it was issued to. If either of those conditions is missing, Regulation E does not let the bank hold you liable under the tiers described below at all. Assuming they do apply, the two-business-day window for the $50 cap runs from when you learn your card is lost or stolen, not from when you notify the bank.
Tier one: report within two business days, liability caps at $50
If you notify your bank within two business days after learning your debit card or other access device was lost or stolen, your liability cannot exceed the lesser of $50 or the actual amount of unauthorized transfers that happened before you gave notice. CFPB's consumer-facing guidance on a lost or stolen debit card describes this same rule in plain language: report within two business days and the bank can't hold you responsible for more than $50, or the actual unauthorized amount if that's smaller — a different, generally stricter, standard can apply if only your PIN or security code was stolen, or if no lost or stolen card was involved at all. The cap is a ceiling, not a flat fee, since you only owe the smaller of the two figures.
Tier two: miss the two-day window, liability can rise to $500
Once you miss the two-business-day window, the cap rises to the lesser of $500 or a two-part sum: a $50 (or smaller) portion for unauthorized transfers within those first two days, plus whatever unauthorized transfers happened afterward, up until you finally notified the bank — provided the bank can show those later transfers wouldn't have happened if you'd notified them sooner. CFPB's plain-language guidance confirms the practical outcome: notify the bank after two business days and you could be responsible for up to $500 in unauthorized transactions. CFPB's own worked example shows how the pieces add up: a $100 unauthorized transfer happens within the two-day window and a $600 transfer happens after it but before notice, and the consumer ends up owing $50 of the first amount plus $450 of the second — $500 total, matching the overall cap.
Worked example: a lost card reported after two business days
Imagine your debit card goes missing, $1,200 in unauthorized purchases run up before anyone catches it, and you notify the bank on day five — past the two-business-day window but still well inside the 60-day statement deadline. Because you missed the two-day window, Regulation E raises the cap to the lesser of $500 or a two-part sum: a $50 (or smaller) portion for whatever unauthorized transfers happened within the first two days, plus the unauthorized transfers that happened afterward, up until you notified the bank, provided the bank can establish that those later transfers would not have occurred had you notified it sooner. In a case like this one, where the loss happened after the two-business-day window closed, $1,200 is more than $500, so your liability is capped at $500 — the lesser of the two amounts the rule requires, not the full $1,200 you actually lost.
- day1 capped liability: 50
- total cap: 500
- Formula: day1 capped liability + (total cap - day1 capped liability)
- Result: 500
CFPB's official example: a $100 transfer within the two-day window plus a $600 transfer after it, capped at $500 total.
Worked example
Because the $1,200 loss exceeds the $500 ceiling, your liability is capped at $500, the lesser-of amount the rule requires, not the full $1,200 you actually lost. Had those transfers instead happened entirely within the first two business days, the cap would drop to $50, since the $500 figure is itself a ceiling on the combined two-part sum — a $50 portion for the first two days plus later transfers before notice — not a separate amount that only applies once that window closes.
- cap 500: 500
- unauthorized amount: 1200
- Formula: cap 500
- Result: 500
Tier three: miss the 60-day statement deadline, liability can become unlimited
The third tier is triggered by a periodic statement showing an unauthorized debit card transfer rather than by when the card itself went missing. If a periodic statement shows an unauthorized debit card transfer, you have 60 calendar days after that statement was sent to notify the bank; miss that deadline and you face unlimited liability for all unauthorized transfers made after the 60-day period ends. The regulation's exact mechanics require the bank to show that earlier notice from you would have stopped those later transfers, and your exposure runs from the close of the 60 days until you finally notify the institution. CFPB's plain-language guidance confirms the same practical bottom line: wait more than 60 days after the statement and you could owe the full amount of transactions that happened after that 60-day mark and before you spoke up. Continuing the earlier example, say the bank mailed a statement on day one showing the earlier unauthorized activity, you never reported it, and a new $3,000 unauthorized transfer hits the account on day 65 — five days after the 60-day deadline expired. That transfer would fall into the unlimited-liability window described above, provided the bank can show the earlier notice would have stopped it.
How the three tiers compare
| Tier | Trigger | Liability cap |
|---|---|---|
| Tier 1 | Notify bank within two business days of learning of loss or theft | Lesser of $50 or actual unauthorized amount before notice |
| Tier 2 | Notify bank after two business days but before the 60-day statement deadline | Lesser of $500 or a $50 component plus later transfers before notice |
| Tier 3 | Fail to notify within 60 days after the statement showing the unauthorized transfer is sent | Unlimited for transfers after the 60-day period until notice is given |
Comparing the three Regulation E liability tiers for a lost or stolen debit card.
What to do the moment you notice a card is missing
- Check the time. Liability caps under Regulation E depend on how many business days have passed since you learned the card was lost or stolen.
- Call your bank right away. Notifying within two business days keeps your liability capped at the lesser of $50 or the actual unauthorized amount.
- If you're past two business days, still report immediately. The cap rises to $500 but stops growing once you notify the bank.
- Read every statement as soon as it arrives. You have 60 days from when the bank sends a statement showing an unauthorized transfer to report it before unlimited liability can apply.
- Confirm the bank gave you Regulation E disclosures. Liability limits only apply if the bank met its disclosure obligations and the device qualifies as an accepted access device.
Key takeaways
- Regulation E sets three liability tiers for unauthorized electronic fund transfers — $50, $500, or unlimited — based on how quickly you report a loss or theft.
- Reporting within two business days keeps you capped at the lesser of $50 or the actual unauthorized amount.
- Reporting after two business days but before your statement's 60-day deadline raises the cap to the lesser of $500 or a combined formula.
- Missing the 60-day statement deadline can expose you to unlimited liability for transfers after that period.
- These caps only apply if the bank gave required disclosures and, for card-based transfers, the device was an accepted access device traceable to you.
Frequently asked questions
What counts as "two business days" for reporting a lost card?
Regulation E measures the two-day window from when you learn of the loss or theft, and notifying within that window keeps your liability capped at the lesser of $50 or the actual unauthorized amount before notice.
Can I still owe money even if I never lost my card?
Yes — the 60-day statement rule applies to any unauthorized transfer appearing on a periodic statement, and if you miss that 60-day deadline, your liability is limited to unauthorized transfers occurring after the deadline and before you notify the bank, and only for transfers the bank can show would not have happened had you notified it in time.
Is the $500 cap a flat fee I always owe once I miss two days?
No, it's a ceiling, not a flat charge; the rule caps liability at the lesser of $500 or the sum of a $50 portion for the first two days plus later unauthorized transfers before notice, provided the bank can show those later transfers would not have happened had you notified it within the two-day window, so if your actual losses were smaller, you'd owe less.
Does it matter if the bank never sent me required disclosures?
Yes — Regulation E only allows the bank to hold you liable at all if it already provided the disclosures required under §1005.7(b)(1)-(3), and for access-device transfers the device must be an accepted one traceable to you.
What happens if unauthorized transfers occur both before and after I report the loss?
More than one tier can apply to the same incident because the tiers correspond to different, sometimes overlapping, time periods, so transfers before your report can fall under the $50 or $500 tiers while later transfers can be governed by the 60-day statement tier instead.
Sources
Liked this read?
Subscribe to The Weekly Rate Floor — every Monday, the top three rates worth your time, the one to skip, and the loan window we think is closing.