Use cases

Banking requests between agents

How a person's agent could lock or replace a card or share data with a bank's agent, under Regulation E, the CFPB data rule and Canada's reforms.

Banking requests range from the harmless to the dangerous. Locking a lost card lowers risk for everyone. Changing the mailing address and ordering a new card is how accounts get taken over. A person’s agent could handle many of these with the bank’s agent directly, but only if the bank can match the proof it demands to the risk of each request.

How it works today

People use the bank’s app, call the number on the back of the card, or visit a branch. The app handles common requests: lock a card, order a replacement, report a charge, set a travel note. Phone agents authenticate callers with security questions, one-time codes or voice checks.

Authentication expectations. The FFIEC’s 2021 guidance on authentication and access, which replaced its 2005 and 2011 internet banking guidance, gives examples of risk-based authentication for customers, employees and third parties, and discusses multi-factor authentication or controls of equal strength against compromised credentials.

The liability clock. Timing decides who pays for fraud. Under Regulation E (12 CFR 1005.6), a consumer who reports a lost or stolen debit card within two business days of learning of it is liable for at most $50; after that, up to $500. For credit cards, Regulation Z (12 CFR 1026.12(b)) caps liability for unauthorized use at $50. Disputes over specific charges follow separate rules, covered in billing disputes.

Data access in the US. The CFPB’s Personal Financial Data Rights rule (12 CFR Part 1033), published 18 November 2024, requires covered institutions to make consumer data available to consumers and authorized third parties through reliable interfaces. On 8 January 2025 the CFPB recognized Financial Data Exchange (FDX) as a standard setter under the rule. The rule’s status has since changed: the CFPB published an advance notice to reconsider it on 22 August 2025, covering who may act as the consumer’s representative, fees, security and privacy. Compliance dates were stayed, the rule is being challenged in Forcht Bank, N.A. v. CFPB (E.D. Ky.), and the CFPB’s regulatory agenda of 14 August 2026 lists a rulemaking to reconsider parts of it. As of 2026-09-26, no revised rule has been published.

Canada. Bill C-15, the Budget Implementation Act, 2025, No. 1, received Royal Assent in March 2026. It includes anti-fraud measures requiring banks to have policies to detect and prevent consumer-targeted fraud, to let consumers disable certain account features, and to let them adjust maximum transaction amounts. On 26 June 2026 the government pre-published proposed regulations in Canada Gazette Part I, covering those fraud measures and the Consumer-Driven Banking Regulations. The Bank of Canada would oversee compliance with the Consumer-Driven Banking Act, starting with accreditation of participants. These regulations were proposals when we checked on 2026-09-26. Complaints follow the Financial Consumer Protection Framework, in force since 30 June 2022: banks have 56 days to deal with a complaint before it can go to the Ombudsman for Banking Services and Investments.

The agent-to-agent version

Illustrative. A person tells their agent they lost their debit card on the train an hour ago.

  1. The agent sends the bank’s agent a lost-card report with the time of loss and the time the person noticed.
  2. The bank’s agent locks the card immediately and returns a confirmation with the time it received the report.
  3. For the replacement, the bank’s agent moves the task to TASK_STATE_AUTH_REQUIRED: sending a new card is lower risk to the address on file, higher to any other.
  4. With the person’s approval, the replacement ships to the address on file. The task completes with the lock time, the new card’s expected arrival, and a list of recent transactions to review.

Step 1:

{
  "jsonrpc": "2.0",
  "id": "req-card-1",
  "method": "SendMessage",
  "params": {
    "message": {
      "messageId": "msg-card-01",
      "role": "ROLE_USER",
      "parts": [
        { "text": "Report a lost debit card and lock it now. Send a replacement to the address on file." },
        {
          "data": {
            "cardRef": "card-token-91d0",
            "event": "lost",
            "lostAt": "2026-09-26T12:30:00-04:00",
            "noticedAt": "2026-09-26T13:15:00-04:00",
            "replacement": { "deliverTo": "address_on_file" }
          },
          "mediaType": "application/json"
        }
      ]
    }
  }
}

The bank’s receipt time for step 1 is what starts the Regulation E two-business-day window, so it belongs in the confirmation.

What has to be true

Identity. The bank authenticates the person as well as the agent. The agent is a third party in the FFIEC’s sense, and banks apply their own risk-based controls to it.

Authority matched to risk. A useful way to scope an agent’s authority is by what a mistaken or malicious request could do:

Request Effect if abused Proof needed
Lock a card Inconvenience Low
Replace a card to the address on file Delay Moderate
Raise a transaction limit, re-enable a disabled feature Direct loss Strong, often a person
Change address, phone or email Account takeover Strongest, usually a person

Canada’s proposed fraud rules make limit changes and feature switches formal consumer requests, which cuts both ways: an agent can lower a limit quickly, and a compromised agent could try to raise one.

Data versus actions. The US data rights rule concerns access to data by authorized third parties. It does not give an agent authority to act on the account. Those are separate permissions.

Record. Report times, lock times and every change requested, with who approved it. Liability caps, complaint deadlines and fraud investigations all depend on those timestamps.

Where Emissar fits

  • Resolve (in development): a person’s agent often starts from the phone number on the back of the card. Resolve maps that number to the bank’s verified agent endpoint, if one exists.
  • Verify (in development): checks the calling agent’s identity and history before the bank acts.
  • Mandate (spec in progress): tiered, revocable authority, for example “lock and replace cards” without “change contact details”.
  • Ledger (spec in progress): signed, timestamped records of reports and approvals.
  • Front Door (open to design partners): an agent endpoint in front of the bank’s existing card and servicing systems.
  • Handoff (in development): fraud cases and customers who may be under pressure from a scammer go to a person.

Open questions

  • Will US banks treat a consumer’s agent as a representative for data access under whatever the CFPB’s reconsideration produces, and as something different for account actions?
  • When Canada’s consumer-driven banking moves beyond read access, will accredited participants include agents acting for individuals?
  • How should a bank’s agent recognize a person who is being coached by a scammer through their own agent?
  • Can the liability clock start from an agent’s report when the person has not yet confirmed the loss themselves?

Questions

Is the CFPB's open banking rule (Section 1033) in effect?
The final rule was published on 18 November 2024. The CFPB opened a reconsideration with an advance notice on 22 August 2025, the rule's compliance dates were stayed, and it is being challenged in Forcht Bank v. CFPB in the Eastern District of Kentucky. The CFPB's August 2026 agenda lists a rulemaking to reconsider parts of it. Check the CFPB directly before relying on any date (we checked on 2026-09-26).
Why would a bank accept a card lock from an agent but not an address change?
Because the two requests carry opposite risks. Locking a card reduces exposure even if the request is mistaken. Changing an address or phone number is a classic account-takeover step, so it needs much stronger proof that the account holder is behind it.

Sources

  1. Regulation E, 12 CFR 1005.6: Liability of consumer for unauthorized transfers (CFPB) (accessed )
  2. Regulation Z, 12 CFR 1026.12: Special credit card provisions (CFPB) (accessed )
  3. FFIEC: Guidance on Authentication and Access to Financial Institution Services and Systems (11 August 2021) (accessed )
  4. CFPB: Required Rulemaking on Personal Financial Data Rights, final rule (18 November 2024) (accessed )
  5. CFPB: Personal Financial Data Rights Reconsideration, advance notice of proposed rulemaking (22 August 2025) (accessed )
  6. CFPB: Regulatory Agenda (14 August 2026) (accessed )
  7. CFPB: Decision and order recognizing Financial Data Exchange as a standard setter (8 January 2025) (accessed )
  8. Department of Finance Canada: Legislation passes to implement Budget 2025 (March 2026) (accessed )
  9. Department of Finance Canada: Government pre-publishes regulations to prevent fraud and facilitate the next phase of consumer-driven banking (26 June 2026) (accessed )
  10. Department of Finance Canada: Budget 2025, Canada's Consumer-Driven Banking Framework (accessed )
  11. FCAC: The Financial Consumer Protection Framework (accessed )
  12. A2A Protocol Specification (accessed )