Zero Liability Is a Card Network Policy, Not a Law

Visa and Mastercard advertise zero liability for unauthorized charges. It is a contractual policy with conditions and exclusions — separate from, and revocable unlike, your statutory protections.

Two protections, easily confused

If you have an unauthorized charge, two separate things may protect you, and they are not the same kind of thing.

Federal law sets a floor. Regulation E caps liability for unauthorized electronic transfers on a sliding scale tied to how quickly you report. Regulation Z caps liability for unauthorized credit card use at $50.

Zero liability is a policy offered by Visa and Mastercard, sitting on top of that floor. It typically promises you pay nothing for unauthorized transactions, which is more generous than the statute.

The distinction is not academic. A statutory floor is a right you can enforce. A network policy is a contractual commitment with conditions and exclusions, and it is the card networks and your issuer — not Congress — who set them.

What the conditions usually look like

Exact terms differ by network, by issuer and by card product, and your cardholder agreement is the governing document. Across policies, the recurring themes are:

  • Prompt reporting. Delay is the most common route to a declined claim, and it undercuts your statutory position simultaneously.
  • Transactions processed over the network. Some PIN-based and ATM transactions may fall outside the policy, because they do not travel the same rails.
  • Card type. Commercial, business and certain anonymous prepaid cards are often excluded or treated differently.
  • Account standing. Some policies condition coverage on the account being in good standing.
  • Cardholder conduct. Negligence — sharing a PIN, handing over the card — is a common carve-out.

Read the policy your card actually carries. "Zero liability" is a marketing phrase across the industry; the operative terms are in your agreement.

Why this matters most on debit

On a credit card the two protections point the same way: the statutory cap is $50 and most issuers waive it anyway, so a zero-liability decline still leaves you with a low, fixed exposure.

On a debit card they diverge sharply. Regulation E's cap escalates with delay — $50, then $500, then potentially unlimited for transfers after the 60-day window. Zero liability may cover you regardless; but if your claim falls into an exclusion, you fall back onto whichever statutory tier your reporting timeline has earned you. The person who noticed a fraudulent debit charge months later, on a card whose policy excludes their transaction type, is in a genuinely difficult position.

That is the argument for reporting fast even when you are confident zero liability applies. Speed protects you under both regimes at once; delay weakens both.

What zero liability does not cover

It addresses unauthorized transactions — someone else using your card without permission. It does not address:

  • A charge you made where the goods never arrived
  • A subscription you forgot to cancel
  • A free trial that converted as its terms said it would
  • A merchant who billed a different amount than you expected
  • A charge you simply do not recognize *yet*

That last one matters, because it is the largest category by far. In our own lookup data, roughly half of the charges people cannot recognize cannot be confidently traced to a merchant on the descriptor alone — and a large share of those resolve to a business the account holder recognises immediately once the processor prefix is stripped away. Reporting a legitimate charge as fraud is not free: it can close your card, cancel your recurring payments, and leave you re-establishing a payment you actually wanted.

Reading your own cardholder agreement

The agreement is the governing document, and it is short enough to skim for the four things that matter. Search the PDF or the online terms for:

"Zero liability" or "unauthorized" — the clause itself, and immediately after it, the conditions.

"Promptly" or a stated number of days — how quickly the policy requires you to report. This is usually the first thing an issuer relies on to decline.

"Negligence" or "unreasonable" — the conduct carve-out. Sharing a PIN or leaving a card accessible is the standard example.

"Business", "commercial" or "prepaid" — whether your specific card product is in scope at all. Business cards frequently are not.

Fifteen minutes now is considerably better than reading it for the first time while arguing about a declined claim.

If zero liability is declined

A decline under the policy is not the end of the matter, because the statutory floor is still there underneath it.

  1. Ask which exclusion applies, in writing. A policy decline should be attributable to a specific term, and asking often surfaces that the decline was procedural rather than substantive.
  2. Assert the statutory position explicitly. Name the framework — Regulation E for a debit or prepaid account, Regulation Z for a credit card — and state the liability cap you say applies given your reporting timeline.
  3. Pin down the reporting date. Your liability tier under Regulation E turns on when you reported relative to learning of the loss, so establish that date on the record early.
  4. Request the documents relied on. Whatever the framework, a determination against you should be explicable, and the evidence is frequently answerable.

The distinction matters most here. A policy can be applied narrowly; the statutory cap cannot be waived away by an issuer's own terms.

What to do with this

  1. Identify the charge first. Unrecognized is not the same as unauthorized.
  2. If it is genuinely unauthorized, report immediately. This maximises both protections simultaneously.
  3. Claim under the policy, but know your floor. If zero liability is declined, ask which exclusion applies and in writing, then assert your statutory position explicitly.
  4. Read your cardholder agreement once, now. It is the document that governs, and reading it under pressure is worse.

Sources

  1. Visa Zero Liability Policy — Visa
  2. Mastercard Zero Liability Protection — Mastercard
  3. Regulation E § 1005.6 — Liability of consumer for unauthorized transfers — Consumer Financial Protection Bureau
  4. Regulation Z § 1026.12 — Special credit card provisions — Consumer Financial Protection Bureau
  5. Using Credit Cards and Disputing Charges — Federal Trade Commission

Frequently Asked Questions

So is zero liability worthless?

Not at all — for most people most of the time it is more generous than the statute, particularly on debit cards where the statutory cap escalates with delay. The point is that it is a policy with conditions rather than a floor you can rely on. Know your statutory position as well, because that is the part that cannot be withdrawn.

What typically falls outside a zero liability policy?

Policies commonly carve out transactions not processed over the network (some PIN and ATM transactions), certain commercial and anonymous prepaid cards, and cases where the cardholder was negligent or delayed reporting. Some also condition it on the account being in good standing. The specific exclusions live in your cardholder agreement, which is the document that actually governs.

Does zero liability cover a merchant dispute?

No. Zero liability addresses transactions you did not authorize. A charge you did make, where the goods never arrived or were not as described, is a different claim — on a credit card, the claims-and-defenses route under Regulation Z is the relevant one.

Have an unrecognized charge? Look it up now →