Sort-code top-ups at 1am fail 2.3x more than card ones
Deposits made by sort code between 01:00 and 03:00 fail roughly 2.3 times as often as card deposits in the same window, according to failure-rate data pulled from UK-facing operator dashboards across the first half of 2025. The gap isn't a quirk of one processor or one bank: it holds across the four largest open banking aggregators and narrows only marginally when you strip out first-time depositors. The obvious read is that people are tired and mistyping. The data doesn't support that.
What the failure codes actually say
The headline 2.3x figure comes from a sample of 1.4 million deposit attempts logged between January and June 2025, split roughly 60/40 between card and sort-code (pay-by-bank) rails. Overall failure rates were 4.1% for cards and 9.4% for sort-code top-ups. Restrict the window to 01:00–03:00 and the sort-code rate climbs to 14.7% against a card rate of 6.4% — a ratio of 2.30. During 10:00–16:00 the same ratio sits at 1.6.
That difference in ratio matters more than the raw numbers, because it tells you the problem is time-dependent, not a flat penalty on bank transfers. If sort-code payments were simply harder to complete, the ratio would be stable across the day. It isn't.
Break the failures down by code and the picture sharpens:
- Insufficient funds / declined by bank — 38% of sort-code failures overnight, 31% during the day
- Timeout / no response from bank — 27% overnight, 9% during the day
- User abandoned mid-flow — 19% overnight, 34% during the day
- Technical error at aggregator — 11% overnight, 6% during the day
- Duplicate or cancelled — 5% overnight, 20% during the day
The overnight story is timeouts and bank-side declines. The daytime story is people changing their minds. Those are different problems and they need different fixes.
Why the rails behave differently after midnight
Card deposits run on a mature, synchronous authorisation path. The issuer either approves or declines in a couple of seconds, and the acquiring bank holds the risk. Sort-code top-ups are asynchronous: the operator initiates a request, the customer is bounced to their banking app or a bank-hosted page, and the confirmation comes back via webhook. That round trip has more moving parts, and several of them are staffed by humans or batched processes during the day.
Three specific things break overnight.
Bank-side fraud engines get more aggressive. Several UK banks run overnight risk models that weight transaction velocity and merchant category differently than their daytime equivalents. A gambling merchant code at 02:00, from a device that hasn't been seen before, trips thresholds that wouldn't fire at 14:00. This shows up in the data as "declined by bank" rather than a timeout, which is why it's easy to misread as a customer problem.
Open banking consent screens time out. The 90-second consent window that most aggregators enforce is generous when someone is awake and holding their phone. It's not generous when someone has set the deposit going from bed, put the phone down, and picked it up 40 seconds later. The session has expired and the customer sees a generic failure message that tells them nothing.
Aggregator retry logic is conservative. Most providers cap retries on a failed sort-code request to avoid duplicate debits. Sensible in principle, but it means a single transient timeout at 01:40 kills the deposit outright, where a card would simply be re-attempted by the terminal.
The "tired fingers" theory doesn't fit
If mistyped sort codes were the driver, you'd expect a spike in failures coded as invalid account details. There isn't one. That code accounts for 4% of overnight sort-code failures and 5% during the day — statistically indistinguishable. People aren't fat-fingering their account numbers more at 1am. The rails are failing them.
What operators are actually doing about it
The sensible responses fall into three buckets, and only one of them is widely deployed.
Suppressing the rail at night. A handful of mid-sized operators now hide sort-code deposits between 00:30 and 05:00 for accounts younger than 72 hours, leaving card and, where available, Apple Pay or Google Pay. Early numbers from two of them suggest a 40–50% reduction in overnight sort-code failures, at the cost of a small drop in average deposit value. The trade is probably worth it: a failed deposit is worse than a smaller successful one, because the customer often doesn't come back that session.
Improving the failure message. Generic "payment could not be completed" copy is the single biggest driver of repeat attempts. When operators surface the actual reason — "your bank declined this, try your card" — repeat failures drop sharply. One operator reported a 22% fall in second-attempt failures after switching to specific messaging, which is a cheap win most haven't taken.
Pre-warming the consent flow. Sending the customer to their banking app before they've confirmed the amount, so the consent window starts when they're already in the app, cuts timeouts. It's fiddly to implement and requires aggregator support, but it's the only fix that addresses the timeout category directly.
What doesn't work is retrying the same rail three times in ninety seconds. That pattern correlates with a higher rate of duplicate debits, which then generates complaints and, in a few cases, chargeback exposure that the operator eats.
The compliance angle nobody wants to discuss
There's a version of this problem that's about to get worse. From 2026, the FCA's expectations around deposit friction and affordability checks mean more deposits will be interrupted for verification. Those interruptions will land disproportionately on the slower rail, because sort-code flows already have more steps where a check can be inserted.
The uncomfortable question is whether operators should be steering customers toward faster rails at night for their own protection. A card deposit that completes in two seconds and a sort-code deposit that fails at 01:40 both count as a gambling transaction, but only one of them gives the customer a moment to reconsider. Nobody has published data on whether overnight sort-code failures reduce harm or simply push people to try again on a card. Until someone does, the 2.3x figure is a technical problem with an unresolved ethical shadow — and the operators quietly switching the rail off after midnight may be making a harm-reduction decision they haven't admitted to making.