As of July 2026
Refund and hold policies may share the same fraud signals, but they create different systems. One pays after loss. The other needs enough time and authority to contain money before it leaves the receiving institution.
Policy becomes executable through state, clocks, evidence, and ownership. The legal choice determines the payment architecture.
UK control
Reimburse
qualifying APP scam claims create duties for sending and receiving payment firms.
US direction
Interrupt
the July 2026 House framework emphasized prevention, data sharing, and stopping funds.
Architecture
Stateful hold
suspicion, decision time, release, escalation, and evidence become explicit states.
Reimbursement builds a post-loss operating path
The UK reimbursement model requires intake, eligibility checks, allocation between firms, customer communication, payment, and recovery work. Sending institutions need confirmation-of-payee and scam controls before release. Receiving institutions need mule-account detection and evidence that can support the reimbursement decision after the payment has settled.
Holds build an in-flight decision path
A hold model needs a different state machine. Funds can arrive without becoming available. A suspicion trigger starts a clock. Investigators need a lawful evidence path, release and escalation rules, customer notices, and an auditable reason for every decision. The payment can settle while availability remains suspended.

Refund allocates loss after settlement. Hold architecture tries to preserve recovery value before withdrawal.
The shared dependency is cross-bank signal speed
Neither model works inside one institution. The sending bank sees the customer interaction and authorization pattern. The receiving bank sees account age, inbound concentration, rapid dispersal, and mule indicators. A hold isn’t useful unless the receiving institution receives a credible signal before the funds move again. Reimbursement is fair only if both sides can exchange evidence without turning each claim into a manual document chase.
That makes the event fabric a first-class payment component. The signal needs a common identifier, a reason code, confidence, timestamps, ownership, retention rules, and a closed-loop outcome. Fraud teams can then measure which signals prevented loss, which caused unnecessary holds, and where release decisions missed their clock.
A refund policy allocates the loss. A hold policy buys time. Both fail when the fraud signal arrives after the money has moved again.




