Access Devices Under the EFTA: Liability Caps and Error Resolution

Under the Electronic Fund Transfer Act, an access device is any card, code, or other means of account access that a consumer can use to initiate an electronic fund transfer from a personal account. That single classification is what unlocks the federal protections most people associate with debit cards: capped liability for unauthorized charges, a formal error-resolution process, provisional credit during investigations, and rules about how banks may put a card in your hands in the first place. Access devices under the EFTA are defined broadly on purpose, and the breadth is doing real work as payment technology keeps changing.

What the Regulation Actually Says

Regulation E, the rule that implements the EFTA, defines an access device as a card, code, or other means of access to a consumer’s account that the consumer can use to initiate an electronic fund transfer.1eCFR. 12 CFR 1005.2 – Definitions Two pieces of that sentence do most of the work. First, “other means of access” is intentionally open-ended, which is how a rule written for magnetic-stripe cards still applies to tools that didn’t exist when it was drafted. Second, the device has to actually let you move money. A tool that only shows a balance or displays transaction history is not an access device.

The account itself also has to qualify. Regulation E covers accounts established primarily for personal, family, or household purposes.2eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E) Internal bank equipment used to process transfers behind the scenes is excluded, and so are paper checks or drafts captured to create a one-time ACH debit.3Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – Definitions

What Counts as an Access Device

Debit cards are the everyday example. When a debit card is paired with a PIN, the card and the code are treated as two separate access devices working together. A PIN also stands on its own when you use it without any physical card, for example when you authorize a transfer through an automated phone system. Telephone transfer codes used to move money between accounts through a bank’s automated line qualify by themselves as well.3Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – Definitions

Digital wallets sit less comfortably in the text but generally fall within it. Regulation E doesn’t mention them by name, but a wallet that stores your debit card credentials and lets you tap to pay is functioning as a path to your funds in exactly the way the definition describes. A wallet that only stores credentials for other accounts and cannot hold funds itself is not treated as its own prepaid account.3Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – Definitions

Biometrics are the closest current edge case. When your fingerprint or face scan initiates a transfer, the biometric input arguably falls within “other means of access.” The regulation doesn’t address biometrics by name, and coverage depends on whether the biometric actually initiates the transfer or merely unlocks a separate credential that does. In practice, banks generally handle biometric-authorized transactions under Regulation E, but the regulatory text hasn’t been formally updated on the point.

Accepted vs. Unaccepted Devices

A device only triggers the full protections once it becomes an “accepted” access device. Acceptance happens when you request and receive it, when you actually use it to transfer money, or when you receive a renewed or replacement version of a device you previously authorized. Until one of those steps happens, the item is inert in the eyes of the EFTA. The practical payoff: a bank cannot hold you liable for unauthorized transfers on a device you never accepted.

What Doesn’t Count

Two familiar payment tools are governed by other laws, not by the EFTA. Paper checks fall under the Uniform Commercial Code. Credit cards are covered by the Truth in Lending Act, and if you use a credit card at an ATM for a cash advance, the credit card rules apply to that transaction rather than the EFTA.

Business accounts are also outside this framework. Because Regulation E only reaches accounts established primarily for personal, family, or household purposes, unauthorized transfers from a commercial account don’t get the EFTA’s liability caps or investigation timelines.2eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E) Business electronic transfers instead fall under UCC Article 4A, which asks whether the bank followed a commercially reasonable security procedure rather than applying fixed dollar caps. If the procedure was reasonable, an account holder can be stuck with an unauthorized transfer, and the main defense is showing the fraud wasn’t caused by anyone entrusted with payment duties or account access.4Legal Information Institute (Cornell Law School). U.C.C. – Article 4A – Funds Transfer

Why the Classification Matters: Liability Caps

The reason the definition is worth caring about is what it triggers. On a covered access device, your exposure to unauthorized transfers is capped, and the caps depend on how quickly you report.

  • Report within 2 business days of learning about the loss or theft: liability is capped at the lesser of $50 or the total unauthorized transfers before you notified the bank.
  • Report after 2 business days but within 60 days of the statement showing the problem: liability can climb to $500, but only for transfers the bank can prove would have been prevented by earlier notice. The $50 cap still applies to what happened in the first two days.
  • Fail to report within 60 days of that statement: you become liable, without a dollar cap, for unauthorized transfers that occur after the 60-day window closes and before you finally notify the bank, if the bank can show they wouldn’t have happened with timely notice.
5eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers

The third tier is the dangerous one. In theory you could lose everything in the account plus any linked overdraft credit line. The statute is explicit that when an unauthorized transfer involves both an electronic fund transfer and an overdraft credit extension, the EFTA’s rules govern the whole thing, so the tiered structure applies to the credit portion too.6Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability

A business day is any day your bank is open to the public for carrying out substantially all of its business, so the two-day and 60-day clocks skip weekends and closures. If you were hospitalized, traveling, or otherwise unable to contact the bank, the reporting period must be extended for a reasonable time, and someone acting on your behalf can give the notice, though the bank may ask for documentation of that person’s authority.7Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – Liability of Consumer for Unauthorized Transfers

Why the Classification Matters: Error Resolution

Once a transaction runs through an access device, the EFTA also gives you a formal way to dispute it. When you notify the bank of a suspected error, it must investigate promptly, reach a conclusion within 10 business days of receiving your notice, report the results within three business days after that, and correct any confirmed error within one business day.8eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors

Investigations often need more time. The bank can extend to 45 days, but only if it provisionally credits your account within the first 10 business days for the full disputed amount plus any interest, and tells you within two business days how much was credited and when. You have full use of those funds while the investigation continues. If the bank has a reasonable basis to believe the transfer was unauthorized and has met the liability requirements, it may withhold up to $50 from the provisional credit.8eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors

Certain transactions get more time on both clocks. The 10-business-day provisional credit window stretches to 20 for transfers on a new account (within 30 days of the first deposit). The overall investigation window extends from 45 to 90 days for international transfers, point-of-sale debit card transactions, and new-account transfers. If the bank concludes there was no error, or that the error was different from what you described, it must send a written explanation and let you know you can request copies of the documents it relied on. If provisional credit was already applied, the bank can reverse it, but must notify you at least three business days before debiting the funds back.

How Banks May Issue an Access Device

The definition also shapes how a card or code can lawfully reach you. Under Regulation E, a bank may only issue an access device in response to a written or oral request, or as a renewal or replacement for a device you already accepted.9eCFR. 12 CFR 1005.5 – Issuance of Access Devices

Unsolicited issuance is allowed only under narrow conditions. The device must arrive unvalidated, meaning the bank hasn’t completed the steps that would let you actually use it. The mailing must include a clear explanation that the device isn’t active, instructions for disposing of it if you don’t want it, and a full set of disclosures about your rights and potential liabilities. The bank can only activate it after you specifically ask and it verifies your identity.9eCFR. 12 CFR 1005.5 – Issuance of Access Devices The result is that you cannot end up liable for a card you never asked for.

Prepaid cards, including gift cards, reloadable general-purpose cards, and government benefit cards, are treated as access devices through a separate set of rules. You’re considered to have requested one when you buy it at a store or apply for it online or by phone, and the protections attach at that point with some modifications tailored to how prepaid accounts work.10Consumer Financial Protection Bureau. Requirements for Financial Institutions Offering Prepaid Accounts