Fraud reporting
Each instant payment network has specific requirements for reporting suspected fraud, with its own criteria for what qualifies as reportable fraud.
You must notify Cross River about any suspected fraudulent transaction.
Reporting procedure
For all instant payment networks, if an activity meets the network's definition of a fraudulent payment (outlined below in Reporting requirements), you must notify Cross River as follows:
Send an email to [email protected] with at least the following information, per payment network:
FedNow | RTP | CRNow |
|---|---|---|
A notice that a Reportable Transfer occurred over FedNow | A notice that an unauthorized transaction occurred over RTP | A notice that a fraudulent payment occurred over CRNow |
Date of transaction | Date of transaction | Date of transaction |
Payment ID or COS reference ID | Payment ID or COS reference ID | Payment ID or COS reference ID |
Amount | Amount | Amount |
Customer name | Customer name | CRNow customer name payment was sent to/from |
Other financial institution that is party to the transaction | Receiving financial institution | |
| | |
Party associated with the Reportable Transfer. Valid values are:
| | |
If warrented according to the outlined incident report submission thresholds, send an incident report to [email protected]. Use the incident report form template.
Incident report submission
Incident reporting thresholds
Partners must escalate the following unusual activity to Cross River Bank (CRB) via an Incident Report (IR):
- Criminal violations involving insider abuse of any amount.
- Criminal violations of $5,000 or more when a suspect can be identified.
- Criminal violations of $25,000 or more, regardless of whether a suspect is identified.
- Transactions aggregating $5,000 or more, if the Partner knows, suspects, or has reason to suspect that the transaction:
- May involve money laundering or other illegal activity.
- Is designed to evade the BSA or its regulations.
- Lacks a clear business purpose or is inconsistent with the customer’s expected activity, with no reasonable explanation after reviewing available facts.
Incident reporting process
- As a partner, maintain a documented incident reporting process to notify Cross River of potentially unusual or suspicious activity.
- Escalate any unusual activity within 5 days of detection by submitting a CRB Incident Report to [email protected].
- Include any relevant supporting documentation in your report.
Timely reporting is critical to ensure compliance and mitigate financial crime risks.
Incident report template
Download our MS Word incident report template as an example:
Network reporting requirements
Each instant payments network has explicit reporting requirements.
FedNow
Summary
If a funds transfer made through the FedNow network is later identified as potentially fraudulent, you as a Cross River partner must report it to Cross River, enabling us to notify FedNow.
The FedNow Service requires participants to report Reportable Transfers sent over the network. A Reportable Transfer is defined as:
“Any funds transfer completed, in part, through the FedNow Service based on a payment order sent or received by a FedNow Participant that was authorized by the sender at the time of submission but was later determined to potentially involve fraudulent activity. The FedNow Participant must have a good-faith belief that the transaction resulted from fraudulent activity.” |
|---|
You must ensure compliance with this requirement by reporting any Reportable Transfers to Cross River, regardless of whether you are the sender or receiver of the transfer.
The Clearing House (RTP)
Summary
You as a Cross River partner must report to Cross River any funds transfer using the RTP network that a network user learns afterwards was not authorized by the sender, so we can notify The Clearing House.
We will request that the funds receiver return the funds, flagging the request as due to suspected fraudulent activity.
Under The Clearing House (TCH) RTP Operating Rule II.G.2, Participants must report fraudulent activity involving the RTP System to TCH and the other Participant involved, following the RTP Technical Specifications and Risk Management and Fraud Control Requirements.
Section 5 of the Risk Management and Fraud Control Requirements states:
“A Participant must report any instance of fraudulent activity or suspected fraudulent activity to TCH subject to and in accordance with the RTP Operating Rules and other procedures established by TCH from time to time.” |
|---|
A fraudulent RTP Payment is a payment the Sending Participant determines was unauthorized by the Sender ("Unauthorized Payment") based on an investigation of how it was initiated.
A payment authorized by the Sender but induced under false pretenses does not qualify as an Unauthorized Payment under this rule.
You must report any suspected unauthorized RTP Payments to Cross River. We take the necessary steps, including notifying the Receiving Participant and submitting a Request for Return of Funds message with the "FRAD" reason code to request a return.
Your timely reporting ensures compliance with TCH rules and facilitates an efficient fraud response.
CRNow (Cross River Partner network transfers)
Summary
You as a Cross River partner must report any funds transfer made through Cross River's CRNow network that is identified as fraudulent or unauthorized.
Cross River’s procedures require participants to report fraudulent activity involving the CRNow system.
A fraudulent CRNow payment is defined as:
“Any funds transfer completed through the CRNow Service, based on any Payment sent or received by a CRNow Participant, that resulted from fraudulent or unauthorized activity.” |
|---|
You must ensure timely reporting of such transactions to Cross River.
FedNow FraudClassifer model type codes
Fraud type code | Code name | Fraud type | Description | Notes/examples |
|---|---|---|---|---|
FC00 | Transaction is not fraudulent | None | If a Reportable Transfer was previously reported and is later determined not to be the result of fraudulent activity, use FC00 to indicate Not Fraud. | N/A |
FC01 | Authorized party was manipulated | Product and Services Fraud | A situation involving a transfer of funds in exchange for a product or service, irrespective of the nature of the relationship between the two parties, whereby the receiver of the funds does not deliver the product or service or delivers a grossly inferior product or service than advertised or promised. | Examples include rental scams, travel scams, lottery scams, tech support scams, home repair scams, home alarm scams, free trial scams, brain booster scams, gold coin scams, etc. Example: Paul has been wanting a puppy and found a great deal online. For $75, he can get a chocolate lab puppy, including delivery. He needs to send $75 to the information provided in the ad. Excited about this great deal, he sends the money but never received the puppy. |
FC02 | Authorized party was manipulated | Relationship and Trust Fraud | A situation involving a transfer of funds to a trusted party or an imposter acting as a trusted or authorized party, where there is no expectation or promise of goods or services in exchange for the transferred funds; the seemingly trustworthy party can be an existing or emerging relationship or a party pretending to be an authority or reputable company. | Examples include IRS imposter scams, Social Security imposter scams, sheriff’s office scams (jury duty), romance scams, grandparent scams, utility scams, fake debt collections, duplicate payment scams, etc. Example: Joan developed a relationship with Fred online. A day before the first meeting in person, Fred asked Joan to send him $10,000 to get out of serious trouble. Joan sent the money to Fred. Fred does not show up for their meeting and Joan never hears from him again. |
FC03 | Authorized party acted fraudulently | Embezzlement | Theft or misuse of funds legally placed in one’s trust or belonging to one’s employer. | This would include situations involving agents acting for others. Example: Tina, the Treasurer, had the ability to initiate payments at her company. Tina instructs the company’s FIs account to her personal account. |
FC04 | Authorized party acted fraudulently | Synthetic Identity Fraud (SIF) | The use of a combination of personally identifiable information (PII) to fabricate a person or entity to commit a dishonest act for personal or financial gain. | Use of a false identification to create an account with the intent to commit fraud. Example: Fred opens a deposit account under a fabricated identity. Fred uses the account to collect payments from his fraudulent scheme, wires the amount to an offshore account, and leaves the account dormant. |
FC05 | Authorized party acted fraudulently | False claim | An intentional lie or deception to receive a payment or avoid a payment obligation. | Informing a consumer of a false situation to obtain funds (e.g., overdue utility bill/disconnect; child/grandchild in prison). Example: Betsy orders online and makes the payment electronically. Days after she received the goods, she calls her bank, reports the purchases as fraudulent, and seeks a refund. |
FC06 | Unauthorized party took over account | Compromised Credentials | Account login information, intended only for an authorized party is obtained by an unauthorized party. | Account login information (e.g., ID/password) allows one to access an account and is not specific to personal information, contact information, etc. Access to personal information, contact information, etc. would be classified under Impersonated Authorized Party. Example: Using Greg's login ID and password, Frank gains full access to Greg’s online bank account. Frank then proceeds to initiate several transfers through Greg’s bank and the FedNow Service from Greg's account to an account at different bank. |
FC07 | Unauthorized party modified payment information | Compromised Credentials | Unauthorized Party has obtained access to a payment instruction “in process” and modified it to redirect funds to an account they have access to. | Account login information (e.g., ID/password) allows one to access an account and is not specific to personal information, contact information, etc. Access to personal information, contact information etc. would be classified under Impersonated Authorized Party Example: Steve set up an online recurring bill payment from his bank account while his roommate was nearby. His roommate later authenticated into Steve’s account using Steve's ID/password and modified the recurring payment. Upon processing of the payment, funds were redirected to an account under the roommate’s control |
FC08 | Unauthorized party modified payment information | Impersonated Authorized Party | A person or organization who does not have authorized credentials but has enough information to authenticate as the Authorized Party. | Authorized credentials in this context include account login information (e.g., ID/password) that allows one to access an account and is not specific to personal information, contact information, etc. Example: Jim scheduled an online bill payment. A day later, Jake represented himself as Jim by successfully answering verification questions asked by the call center associate. Jake (as Jim) then instructed the call center associate to modify the scheduled payment, redirecting it to an account in his control. Upon receipt of the payment, Jake withdrew the funds |