Payment fraud is not a new problem, but the way in which legislators allocate liability between payment service providers and customers is on the verge of a fundamental shift. For payment institutions and banks, this is more than a technical legislative amendment: it directly affects the design of fraud monitoring, customer communications, dispute resolution and the evidence required to rebut liability.
Under the current Payment Services Directive 2 (PSD2), liability largely revolves around whether a transaction was authorised. Under the new Payment Services Regulation (PSR), the liability framework shifts towards the question of whether the payment service provider can demonstrate that the payment was executed with the payment service user's consent, or whether the user acted fraudulently or with gross negligence. This represents a conceptual shift with significant practical consequences, particularly in situations where customers themselves have approved a payment under false pretences. For compliance and risk functions, this means that fraud policies, monitoring and record-keeping will need to be reassessed.
Under the current regime, the basic principle is relatively straightforward: if the payer has authorised the transaction, the payer generally bears the risk, except in cases of gross negligence by the PSP in relation to authentication. For unauthorised transactions, the burden of proof lies with the PSP to demonstrate that the transaction was authenticated, accurately recorded and executed, and was not affected by a technical breakdown or any other deficiency in the services provided by the payment service provider.
The more difficult issue arises in the intermediate category: situations in which customers themselves authorise a payment as a result of deception. Consider, for example, a customer who receives a telephone call from someone posing as a bank employee and subsequently approves a bank transfer. Under PSD2, this type of fraud, known as impersonation fraud or ‘authorised push payment’ fraud (APP fraud), largely falls outside the liability provisions from a legal perspective because the transaction is formally authorised.
Under the PSR, successful authorisation requires the customer to consent to the transaction. Therefore, where a third party has unlawfully obtained the customer's data, there is no consent, even if the payment was executed using information known only to the customer. The PSR states this explicitly: a transaction is not considered authorised where it has been initiated or modified by a third party acting without the user's consent, even where that third party uses fraudulently obtained personalised security credentials.
This has a consequence that can easily be underestimated in practice: where fraud falls within this classification, reimbursement does not take place under the specific regime for impersonation fraud, but under Article 56 PSR, requiring reimbursement by the end of the following business day.
The next question is whether the PSP, using the means that could reasonably be expected of it, could have detected or prevented the fraud. If the PSP cannot demonstrate, on objectively justified grounds, that the customer acted fraudulently or with gross negligence, the PSP must reimburse the customer's losses.
However, this burden of proof is not unlimited. The PSR provides for a number of situations in which the PSP is not required to provide reimbursement, or is not required to reimburse the full amount. If the customer fails to report fraud within the required timeframe, the right to redress lapses (Article 54). In cases involving the loss, theft or misuse of a payment instrument, the payer bears a limited amount of the loss, unless the loss could not have been detected by the payer or is attributable to the PSP (Article 60). In cases of fraud, intentional conduct or gross negligence, the payer bears the full loss and this limited liability does not apply (Article 60). Where there is an objectively justified suspicion of fraud or gross negligence, the PSP may suspend reimbursement, provided that it reimburses the payer within a short period if the payer is found not to be at fault or, where the payer is found to be at fault, the PSP substantiates this conclusion (Article 56).
The most significant change introduced by the PSR concerns impersonation fraud, also referred to as ‘authorised push payment’ fraud (APP fraud): situations in which a fraudster impersonates a trusted party in order to persuade a customer to authorise a payment.
The scope of the reimbursement obligation is narrower than the term APP fraud might suggest. The provision applies only where the fraudster impersonates the consumer's own payment service provider and uses communication channels attributable to that payment service provider, for example by spoofing its domain name, email address, telephone number, website or app.
Scenario: a customer receives a telephone call from someone posing as an employee of their bank who, under the pretence that ‘your account is about to be hacked’, persuades the customer to transfer money to a ‘safe account’. The customer authorises the transaction themselves, including any required SCA steps. Under PSD2, this constitutes an authorised transaction for which the PSP is, in principle, not liable. Under the PSR, however, if the consumer reports the incident to their PSP without undue delay after becoming aware of the fraud and also reports it to the police, the PSP is required to reimburse the full amount.
Article 59 begins with a preventive obligation that is often overlooked in discussions about reimbursement: the PSP must have adequate preventive measures and robust technical safeguards in place to prevent fraudsters from imitating or misusing its communication channels in order to induce users to make fraudulent transactions.
What exactly constitutes ‘adequate preventive measures and robust technical safeguards’ is already relatively specific in certain respects. Article 83 requires transaction monitoring prior to execution by both the payer's PSP and the payee's PSP, provides an exhaustive list of the data that may be processed for this purpose, and establishes a separate liability and reimbursement rule where such monitoring is absent, with the burden of proof resting on the PSP.
Based on the current text and explanations provided by the negotiating parties, a number of elements are nevertheless emerging that PSPs are expected to be able to demonstrate:
This provision deserves particular attention from compliance officers for several reasons:
For internal processes, this means in practical terms that PSPs need a standardised, auditable process for receiving APP fraud reports, assessing them against the statutory requirements and, where the customer has not acted fraudulently or with gross negligence, reimbursing the customer. This process affects the fraud/risk function, customer service and legal teams, and warrants a dedicated section in the fraud policy, separate from the existing complaints procedure for unauthorised transactions.
Translated into the day-to-day work of compliance and risk teams, this shift in liability results in a number of practical considerations that can already be addressed in anticipation of the PSR's formal entry into force:
These points are expressly not exhaustive and will be refined once the EBA publishes further technical standards, but they provide a basis for starting internal preparations now and taking a phased approach.
The shift from authorisation towards prevention and substantiation of fraudulent or negligent conduct as the basis for liability is the most fundamental change that the PSR introduces in relation to fraud. For payment institutions and banks, this means moving from a reactive model to a proactive and demonstrable one, in which the quality and currency of their own prevention policies take centre stage.
The case study discussed above shows that this shift is significant not only from a legal perspective but also operationally: it requires changes to monitoring, customer communications, record-keeping and escalation processes.
It is important to approach these preparations in the right order and with the appropriate caveats. The direction of the changes is sufficiently clear to begin conducting a gap analysis and reviewing fraud policies now. At the same time, important details have yet to be finalised. Preparation is therefore both useful and advisable; however, fully embedding new processes in their definitive form would be premature until the text has been published in the Official Journal.
Want to know what the changing regulatory landscape means for your organisation? Projective Group helps financial institutions navigate complex regulatory requirements and turn them into practical, future-proof solutions. Get in touch with our experts to find out how we can support your organisation.