Ceety Systems

Platforms

FedNow and RTP readiness for credit unions and banks

A readiness plan for credit unions and community banks joining FedNow or RTP: receive-only vs send, ISO 20022, 24x7 operations, fraud tools and core work.

By the Ceety Systems teamUpdated 7 min read

Key takeaways

  • FedNow (Federal Reserve) and RTP (The Clearing House) both settle instantly, run 24x7x365 and use ISO 20022 messages.
  • Receive-only is the usual first step; sending adds fraud, liquidity and customer-experience work that deserves its own phase.
  • As of September 2026, both networks allow payments up to $10 million, and each institution sets its own lower limits.
  • Your core processor and middleware decide most of your timeline, so start there.
  • A small credit union and a larger bank follow the same steps; what changes is who runs them and how much is built in-house.

FedNow and RTP readiness means being able to receive, and later send, instant payments at any hour, with ISO 20022 messages flowing through your core, fraud controls that work in seconds and staff who can handle exceptions on a Sunday night. For most credit unions and community banks, the path is to go live as receive-only first, then add sending once limits, fraud rules and liquidity monitoring are in place.

This article covers what the two networks are, what participation options exist, and a readiness plan sized for a small institution and for a larger bank.

What are FedNow and RTP?

Both are US instant payment networks: a credit transfer clears and settles in seconds, and the receiving customer can use the funds right away.

Some institutions connect to both, because a payment can only move instantly between two institutions on the same network.

How do the two networks compare?

FedNowRTP
OperatorFederal Reserve BanksThe Clearing House
Hours24x7x36524x7x365
MessagingISO 20022ISO 20022
Network limit per payment (as of September 2026)$10 million, effective November 12, 2025$10 million, effective February 9, 2025
Receive-only optionYesYes
Request for paymentYesYes
AccessDirectly, or through a correspondent or service providerDirectly, or through third-party service providers and funding agents

The FedNow limit comes from the Federal Reserve's November 2025 network limit notice, which also notes that participants may set lower limits. The RTP limit and access models come from The Clearing House.

Should we start receive-only or send and receive?

The FedNow operating procedures define separate participation types, including customer credit transfer receive-only, send and receive, and send and receive with request for payment. The Clearing House describes a credit union that joined RTP receive-only before adding sending.

Receive-only means your members or customers can get instant credits, such as payroll, insurance claims or transfers from their own accounts elsewhere. You still need to post the credit in real time, respond to the network within its timeout, and handle returns and exceptions. You do not yet carry outbound fraud exposure.

Send adds the harder work: authenticating the customer, checking limits and fraud rules before release, confirming the payee, managing liquidity overnight, and explaining to customers that an instant payment generally cannot be recalled like a card transaction.

For most smaller institutions, receive-only first is the lower-risk sequence. A larger bank with commercial treasury clients may need send capability early, because those clients will ask for it.

What does ISO 20022 change?

Both networks use ISO 20022, a structured message standard. Instead of a flat file, each payment carries tagged fields for parties, accounts and remittance information. On FedNow, for example, a customer credit transfer is a pacs.008 message, a return is a pacs.004, and a request for payment is a pain.013.

What that means in practice:

  • Your core has to read and write these messages, or a middleware layer has to translate them in real time.
  • Richer remittance data is useful to business customers, but only if your online banking and statements can show it.
  • Data quality matters more. Name and account fields feed fraud screening and sanctions checks, so truncated or mismatched data creates false positives at 3 a.m.

What does 24x7x365 mean for operations?

Instant payments do not wait for business hours, and your systems have to answer the network in seconds. The FedNow operating procedures (September 2025 version) set a 20-second timeout clock for a transaction to settle or be rejected, and they require participants that receive payments to sign off through the service before planned downtime.

Plan for:

  1. Real-time posting. Batch-oriented cores need a memo-post or real-time ledger so the customer sees funds immediately and the balance is right for the next transaction.
  2. Maintenance windows. Core upgrades, end-of-day processing and failovers must either keep the payment path up or sign off from the network cleanly.
  3. Liquidity. Settlement happens on weekends and holidays. Someone needs to watch the master account or correspondent position, and send limits must reflect what you can fund.
  4. Staffing. Decide who handles a suspected fraud case or a stuck payment at 11 p.m. on a holiday, and write it down.
  5. Monitoring. Alert on message rejects, timeouts and sign-off status, not just server health.

What fraud controls does FedNow provide?

FedNow's fraud tools sit alongside, not in place of, your own fraud program. As described in the FedNow Service operating procedures and the Federal Reserve's June 2025 announcement, the service offers:

  • Transaction limits. Each participant sets its own maximum per payment, up to the network limit.
  • Participant negative list. An optional list that rejects payments coming from or going to specific accounts.
  • Account activity thresholds. Value and velocity thresholds by customer segment, so you can, for example, set a higher cumulative threshold for business customers than for new consumer accounts. The service populates default cumulative value thresholds for send-enabled participants, which you can change.
  • Correspondent net send limits. A correspondent can cap the net sending of the institutions it settles for.

Your own controls still carry most of the load: strong authentication for sending (passkeys or other phishing-resistant methods where your digital banking platform supports them), first-time payee and new-device risk scoring, velocity rules, confirmation screens that name the recipient, and a clear process for customer-reported scams.

Which dependencies decide the timeline?

The network itself is often not the constraint. These usually are:

  • Core processor. Does your core, or your core provider's instant payments module, support FedNow, RTP or both, receive-only and send? What release and contract changes are needed?
  • Middleware or payment hub. Many institutions use a hub to translate ISO 20022, apply fraud rules, and route between FedNow, RTP, ACH and wires. Confirm it can post in real time to your core.
  • Digital banking. Sending requires new screens, limits, payee confirmation and alerts in online and mobile banking.
  • Fraud and sanctions screening. These must run inside the timeout window, around the clock.
  • Settlement. Decide whether you settle in your own master account or through a correspondent, and how liquidity will be moved outside Fedwire hours.
  • Testing and certification. Both networks require testing before production; budget time for it.

A readiness plan for a small institution vs a larger bank

The steps are the same. What changes is who does the work.

Small credit union or community bank

  1. Ask your core provider first. Confirm which network, which participation types and what it costs. Your core provider may already be a certified FedNow service provider or RTP technology provider.
  2. Go receive-only. Configure real-time posting, returns handling and customer notifications. Train member service staff on what customers will see.
  3. Write the after-hours runbook. Who is on call, how to sign off for maintenance and how to escalate a suspected fraud case.
  4. Plan the send phase. Set conservative per-payment limits, enable the network fraud tools, and add sending for existing, authenticated customers before new accounts.
  5. Review after 90 days of live traffic: volumes, rejects, exceptions and member feedback.

Larger community or regional bank

  1. Decide the network strategy. FedNow, RTP or both, and whether a payment hub routes between them and ACH and wires.
  2. Map treasury use cases. Commercial clients may want request for payment, higher limits and rich remittance data.
  3. Build real-time fraud, sanctions and liquidity monitoring as shared services, with segmented thresholds for consumer, business and government accounts.
  4. Integrate operations. Tie exception queues, case management and reconciliation into existing tools, and staff a 24x7 payments desk or define on-call coverage.
  5. Phase the rollout: receive-only, then send for consumer, then commercial and request for payment, with a control review at each step.

For institutions working through core and payment platform changes, our financial services page explains how we approach modernization with audit evidence built in. This article is general information, not legal or regulatory advice; confirm requirements with the network operators and your regulator.

Frequently asked questions

Do we have to join both FedNow and RTP?

No. Neither network is mandatory. An instant payment only moves between institutions on the same network, so the choice depends on where your customers' counterparties are and what your core provider supports.

Can a small credit union join without its own Federal Reserve master account?

It depends on the network. On FedNow, a participant can settle through a single correspondent's master account and can use a service provider as its agent. On RTP, institutions can connect through third-party service providers and funding agents.

What is the maximum FedNow payment?

As of September 2026, the FedNow network limit for customer credit transfers is $10 million, effective November 12, 2025. Each institution can set a lower limit to match its risk appetite.

How long does FedNow or RTP readiness take?

It depends mostly on your core processor and middleware. If your core provider already supports the network, receive-only can be relatively quick; sending takes longer because of fraud controls, digital banking changes and testing.

Is receive-only really risk-free?

No. Receive-only removes outbound payment risk, but you can still receive funds from fraud or scams, and you must post in real time, respond within the network timeout and handle returns. It is a lower-risk first phase, not a no-risk one.

Tell us about your business.

Book a free consultation: a conversation about what you have and what you want. We’ll tell you honestly what you don’t need. Free, with no obligation.