The prepaid account rules in subpart B of Regulation E were written for a market that no longer looks like reloadable plastic on a drugstore rack. As drafted, they reach payroll cards, government benefit cards, general-purpose reloadable cards, and — importantly for fintech — digital wallets and app balances that can be loaded with funds and spent at multiple unaffiliated merchants or used for person-to-person transfers.
Three obligations sit at the center: a standardized two-part fee disclosure that must appear before the consumer acquires the account, full error-resolution and unauthorized-transfer protections once the consumer's identity is verified, and a set of requirements that make attaching a credit feature to a prepaid account deliberately difficult. If you run a balance product and have not tested it against these rules, coverage is the first question to answer, not the last.
Start with coverage, not compliance
The rule's definition of a prepaid account is functional. It captures accounts that are issued on a prepaid basis in a specified amount or capable of being loaded with funds, whose primary function is to conduct transactions with multiple unaffiliated merchants, at ATMs, or for person-to-person transfers, and that are not checking or share draft accounts. It also expressly names payroll card accounts and government benefit accounts.
That framing catches many products whose builders never thought of themselves as prepaid issuers. A neobank balance held for the consumer at a partner bank, a peer-to-peer transfer app that stores value between transfers, a gig-worker instant-payout wallet — all of these need the analysis. Conversely, some products fall outside: gift cards subject to the separate gift-card rules, accounts loaded only with loan proceeds in narrow circumstances, and balances usable only at a single merchant or affiliated group.
Watch out: "we're just a technology company, the bank holds the funds" does not resolve coverage. The rule allocates duties across the parties in the program, and the program manager typically performs the disclosure, servicing, and error-resolution functions in practice. The bank partnership agreement decides who does the work and who pays for failures — the allocation problem described in our guide to embedded finance compliance risk.
The disclosure package, and why its format is prescribed
Prepaid disclosure is unusually formalistic because the rule uses standardized layouts so consumers can compare products at a glance. Two documents do the work.
The short form
A compact, prescribed-format box shown before acquisition. It surfaces the headline fees — periodic fee, per-purchase fee, ATM withdrawal and balance-inquiry fees, cash reload fee, customer-service fee, inactivity fee — plus a statement of how many additional fee types exist, and directions to where the full schedule and the registration information can be found. For products sold in retail packaging, the disclosure has to be visible on or through the packaging.
The long form
The complete fee schedule with conditions for each fee, along with statements about the account's regulatory and insurance status and how to reach the CFPB. Programs must also make key disclosures available before acquisition through a website, telephone number, and, for retail products, in written form on request.
Account agreements
Issuers must post their prepaid account agreements publicly and submit them to the CFPB, which publishes them. That transparency requirement means competitors, plaintiffs' lawyers, and examiners can all read your terms without asking you for them — a good reason for the posted agreement to match what your servicing team actually does.
Error resolution, unauthorized transfers, and provisional credit
Once a consumer has successfully completed identity verification, the account gets Regulation E's error-resolution machinery. The rule does not require issuers to resolve errors on accounts where the verification process has not been completed, but it does require issuers to disclose that limitation, and the practical answer for most programs is to fix real errors regardless rather than defend the distinction to an examiner.
- Did the consumer give timely notice? The general rule is notice within 60 days after the institution sends the periodic statement or makes the electronic history available showing the alleged error. Because many prepaid programs do not mail statements, the trigger is usually the electronic history the rule requires you to provide.
- Is it an "error" as defined? Unauthorized transfers, incorrect amounts, missing transfers, computational mistakes, and requests for documentation all count. General dissatisfaction with a merchant does not.
- Can you finish the investigation quickly? The regulation gives a short investigation window measured in business days, with a longer window available if provisional credit is issued. Extended timeframes apply to new accounts, point-of-sale transactions, and transfers initiated outside the United States.
- Did you notify in writing? Findings must be reported, and if you conclude there was no error, the consumer is entitled to the documents you relied on upon request.
- Is liability correctly capped? Consumer liability for unauthorized transfers is tiered and rises with delay in reporting — but many programs voluntarily promise more protection through network zero-liability policies, and a voluntary promise is enforceable as a contract term.
The mechanics closely track how disputes work on debit cards generally, which is why prepaid servicing teams should also understand the separate private-rulebook process described in our guide to card network chargebacks. The network case and the Regulation E case are not the same proceeding.
Credit features: the part that changes everything
The rule's most consequential design choice concerns overdraft and credit. Rather than banning credit on prepaid accounts, it makes attaching one costly in compliance terms.
| Requirement | Prepaid account alone | Prepaid account with covered credit feature |
|---|---|---|
| Governing rule | Regulation E subpart B | Regulation E plus Regulation Z credit-card-account provisions |
| Underwriting | Not applicable | Ability-to-pay assessment required before opening the credit feature |
| Waiting period | None | The credit feature generally cannot be offered until the prepaid account has been open for a set period |
| Repayment | Not applicable | Limits on automatically sweeping the prepaid balance to repay the credit; consumer choice required |
| Disclosures | Short form and long form | Adds periodic statements and credit-card-style disclosures |
| Fee limits | Fee transparency | Limits on total fees during the first year of the credit plan |
Not every negative balance is a credit feature. Incidental shortfalls the issuer covers without a fee, and force-pay situations arising from settlement timing, are handled differently from a structured line of credit. But products marketed as "get paid early" or "spot me" advances need a careful look at both this rule and the separate analysis in our guide to earned wage access, since similar economics can be structured in very different legal wrappers.
Practical step: before a product team ships a feature that lets a balance go below zero, run the change past compliance as a credit-product launch, not a UX change. The Regulation Z consequences attach to how the feature functions, not to what the marketing calls it.
Where the money sits, and what the states say
Regulation E is a consumer-protection rule; it does not by itself make funds insured. Whether balances are eligible for FDIC pass-through insurance depends on how the accounts are titled and recorded at the insured depository, and on the accuracy of the program's records — the FDIC publishes the requirements. Programs that describe balances as insured without meeting the recordkeeping conditions create both a supervisory problem and a deception problem.
State law adds requirements that vary considerably. Money transmission licensing, permissible-investment rules, gift-card expiration and fee restrictions, and unclaimed-property reporting are all state matters, and states take genuinely different positions on each. No single state's framework is a national standard, and multistate programs typically build to the strictest applicable requirement. Whether the flow of funds itself triggers licensing is a separate analysis, covered in our guide to following the flow of funds.
Quick answers
Does the rule cover digital wallets and app balances?
It can. The definition turns on function, not on whether there is a plastic card. A wallet balance that can be loaded with funds and spent at multiple unaffiliated merchants or sent to another person generally fits the definition. Wallets that merely store card credentials without holding a balance are analyzed differently. Test your specific product against the regulation's text rather than assuming.
Do we have to send monthly paper statements?
No. The rule allows a program to provide electronic account history in place of periodic statements if it makes the required information available — balance by telephone, an electronic history covering a defined lookback period, and written history on request. Choosing that route has consequences: the electronic history availability date becomes the trigger for the 60-day error-notice clock.
Can we deny error claims on unverified accounts?
The rule permits an issuer not to resolve errors on accounts where the consumer has not successfully completed identity verification, provided the limitation is disclosed. It is a narrow allowance, not a general defense, and it does not apply once verification succeeds. Programs that use it aggressively should expect scrutiny of both the disclosure and the verification process itself.
Are payroll cards treated the same as other prepaid accounts?
They get the general prepaid protections plus more. Employers cannot require employees to receive wages on a particular payroll card as the only option; a compulsory-use prohibition applies, and many states have their own wage-payment statutes with additional conditions on electronic payment. Those state rules differ and should be checked wherever employees are located.
A sensible order of operations
Answer coverage first, in writing, against the regulation's actual definition. If covered, build the short-form and long-form disclosures to the prescribed formats and get the pre-acquisition delivery mechanics right, because format failures are visible from outside the company. Then build error resolution with real clocks and provisional credit, and post the account agreement you actually intend to follow.
Treat any credit or negative-balance feature as a separate product launch with its own Regulation Z workstream. Confirm current requirements at consumerfinance.gov and in the text of Regulation Z rather than from secondary summaries. Related product-structuring questions are collected in the banking, payments, and fintech pathway.