MARKETS, CREDIT & POLICYAbout & methodology
c.The Credit CurrentDAILY INTELLIGENCEWhat matters in Credit
Deep-dive library
Supervisory Cases

U.S. Bank ReliaCard: fraud freezes need a workable route back to funds

The terminated CFPB unemployment-benefit-card order illustrates false-positive harm, identity-verification bottlenecks and the need to preserve error-resolution rights.

5 min read · estimatedAI-generated analysis · Methodology
Current version · 1 version · Publication details

Initial full research article; sources and status reviewed September 27, 2026.

Key takeaways

From this version
Main finding
The terminated CFPB unemployment-benefit-card order illustrates false-positive harm, identity-verification bottlenecks and the need to preserve error-resolution rights.
Practical implication
Recommended intake separates these issue types and identifies the accountable team.
Key limitation
Identity documents may help establish who is contacting the bank, but they do not by themselves resolve whether a disputed electronic transfer was authorized.
In this article

The verified status

The CFPB’s December 19, 2023 order concerned U.S. Bank, National Association’s administration of ReliaCard prepaid cards holding unemployment benefits. The agency required $5.7 million in redress and a $15 million penalty, and addressed access to frozen accounts and error investigations. The CFPB terminated that order on September 22, 2025 and waived alleged noncompliance with it. [1]

The termination document states that the bank fulfilled certain obligations, including the penalty, redress payments and steps to implement conduct provisions. [2] This is a historical case with a terminated CFPB order. The OCC separately announced a $15 million penalty in December 2023; termination of the CFPB order should not be presented as a blanket disposition of every action by every agency. [3]

The control that trapped eligible customers

The CFPB found that, after introducing new fraud-freeze criteria in 2020, U.S. Bank did not provide eligible affected cardholders adequate means to verify identity and regain timely access. Its order describes inconsistent instructions, document-submission difficulties, review delays and repeated freezes after identity verification. It also addresses untimely investigation of notices involving alleged unauthorized transfers. [4]

These findings concern the historical period examined. They do not establish the design or performance of the bank’s current program. Their continuing value is the interaction they reveal between a fraud decision and the service process required to resolve it. Preventing an improper withdrawal and restoring legitimate access must be designed together.

Analysis: a fraud system can look successful when measured only by dollars stopped. That measure does not reveal how many legitimate customers lost access, how long they waited or whether the bank could distinguish an unresolved identity question from a confirmed fraudulent claim. A freeze is an intervention with costs, not a final determination of wrongdoing.

Different questions require different evidence

Benefit eligibility, ownership of the card account, identity verification and authorization of a particular transfer are separate questions. A state may determine eligibility, while the bank operates the payment account and investigates a transfer dispute. A workflow that repeatedly sends a customer between institutions can fail even when each party believes another owns the next step.

Recommended intake separates these issue types and identifies the accountable team. Identity documents may help establish who is contacting the bank, but they do not by themselves resolve whether a disputed electronic transfer was authorized. Likewise, successful authentication does not automatically prove that a consumer understood or authorized a specific transaction.

Regulation E §1005.11 provides the general error-resolution framework, including investigation and applicable timing requirements. [5] A fraud hold should not silently stop the separate error-resolution clock. Staff need a way to record the notice, identify the applicable account provisions and escalate missing evidence without treating every delay as attributable to the customer.

A hypothetical capacity failure

Assume a fraud rule freezes 10,000 accounts in a day and 20% require human review after automated verification. That creates 2,000 cases. If a staffed team can complete 200 cases daily and receives no further work, clearing the initial queue takes ten working days. New freezes, repeat submissions and quality rework extend that period. These figures are illustrative, not U.S. Bank statistics.

The key insight is that a threshold change is also a capacity decision. Before deployment, estimate the legitimate-customer review volume and test whether the recovery path can handle it. A system that reduces fraud loss but creates an unmanageable queue may require a different intervention, such as a narrower restriction or additional verification, where lawful and operationally appropriate.

Measure the entire distribution of time to resolution. A median of one day can coexist with a small but consequential group waiting weeks. Segment failures by document type, device, accessibility need and submission channel. Requiring the same failed upload repeatedly is not a meaningful alternative path.

Make release from a freeze as reliable as the freeze itself

Recommended controls maintain a reason for every hold, the evidence required to resolve it, the responsible team and the next review date. An approved release should propagate to every linked system. Before re-freezing a verified account, determine whether new evidence exists or the original unresolved signal is simply being replayed.

Customer instructions should match the available process. If staff can accept an alternative document or route a case for manual review, that path needs to be visible and executable. Track rejected submissions, reasons for rejection and repeat contacts. A successful screen upload is not the same as a completed review, and a case marked closed is not proof that the customer regained access.

Quality assurance should sample both continued holds and releases. Reviewing only released cases can miss consumers who gave up, while reviewing only suspected fraud can exaggerate apparent precision. Link operational metrics to complaints and eventual confirmed outcomes, with appropriate privacy and access controls.

Tradeoffs and evidence

More generous recovery paths can create opportunities for impersonators; more restrictive paths can exclude legitimate consumers. Evaluate the choices using confirmed fraud loss, wrongful restrictions, time without access and review cost. Do not assume a face-match vendor or a document score independently settles all four measures.

Evidence that would change the operational conclusion includes successful end-to-end recovery tests, stable performance during surges and lower repeat-freeze rates without an offsetting increase in fraud. New public agency documents could change legal status. For now, the lesson of the terminated CFPB matter is clear: a fraud control is incomplete unless eligible customers have a timely, usable and properly governed way to resolve it.

Sources

  1. CFPB, U.S. Bank prepaid-card action, December 19, 2023; updated September 22, 2025Back to text: ↑
  2. CFPB, order terminating U.S. Bank consent order, September 22, 2025Back to text: ↑
  3. OCC, separate U.S. Bank civil money penalty, December 19, 2023Back to text: ↑
  4. CFPB, U.S. Bank consent order 2023-CFPB-0019, December 19, 2023Back to text: ↑
  5. CFPB, Regulation E §1005.11, error resolution; reviewed September 27, 2026Back to text: ↑