READ
News

Fraud under the PSR: a new liability regime

Date:August 25, 2026

1. Introduction

Payment fraud is not a new problem, but the way in which legislators allocate liability between payment service providers and customers is on the verge of a fundamental shift. For payment institutions and banks, this is more than a technical legislative amendment: it directly affects the design of fraud monitoring, customer communications, dispute resolution and the evidence required to rebut liability.

Under the current Payment Services Directive 2 (PSD2), liability largely revolves around whether a transaction was authorised. Under the new Payment Services Regulation (PSR), the liability framework shifts towards the question of whether the payment service provider can demonstrate that the payment was executed with the payment service user's consent, or whether the user acted fraudulently or with gross negligence. This represents a conceptual shift with significant practical consequences, particularly in situations where customers themselves have approved a payment under false pretences. For compliance and risk functions, this means that fraud policies, monitoring and record-keeping will need to be reassessed.

2. The current regime under PSD2/Wft: liability for (un)authorised transactions

Under the current regime, the basic principle is relatively straightforward: if the payer has authorised the transaction, the payer generally bears the risk, except in cases of gross negligence by the PSP in relation to authentication. For unauthorised transactions, the burden of proof lies with the PSP to demonstrate that the transaction was authenticated, accurately recorded and executed, and was not affected by a technical breakdown or any other deficiency in the services provided by the payment service provider.

The more difficult issue arises in the intermediate category: situations in which customers themselves authorise a payment as a result of deception. Consider, for example, a customer who receives a telephone call from someone posing as a bank employee and subsequently approves a bank transfer. Under PSD2, this type of fraud, known as impersonation fraud or ‘authorised push payment’ fraud (APP fraud), largely falls outside the liability provisions from a legal perspective because the transaction is formally authorised.

3. The shift under the PSR: liability where fraud prevention measures fail

Under the PSR, successful authorisation requires the customer to consent to the transaction. Therefore, where a third party has unlawfully obtained the customer's data, there is no consent, even if the payment was executed using information known only to the customer. The PSR states this explicitly: a transaction is not considered authorised where it has been initiated or modified by a third party acting without the user's consent, even where that third party uses fraudulently obtained personalised security credentials.

This has a consequence that can easily be underestimated in practice: where fraud falls within this classification, reimbursement does not take place under the specific regime for impersonation fraud, but under Article 56 PSR, requiring reimbursement by the end of the following business day.

The next question is whether the PSP, using the means that could reasonably be expected of it, could have detected or prevented the fraud. If the PSP cannot demonstrate, on objectively justified grounds, that the customer acted fraudulently or with gross negligence, the PSP must reimburse the customer's losses.

However, this burden of proof is not unlimited. The PSR provides for a number of situations in which the PSP is not required to provide reimbursement, or is not required to reimburse the full amount. If the customer fails to report fraud within the required timeframe, the right to redress lapses (Article 54). In cases involving the loss, theft or misuse of a payment instrument, the payer bears a limited amount of the loss, unless the loss could not have been detected by the payer or is attributable to the PSP (Article 60). In cases of fraud, intentional conduct or gross negligence, the payer bears the full loss and this limited liability does not apply (Article 60). Where there is an objectively justified suspicion of fraud or gross negligence, the PSP may suspend reimbursement, provided that it reimburses the payer within a short period if the payer is found not to be at fault or, where the payer is found to be at fault, the PSP substantiates this conclusion (Article 56).

4. Case study: impersonation fraud and the obligation to provide full reimbursement

The most significant change introduced by the PSR concerns impersonation fraud, also referred to as ‘authorised push payment’ fraud (APP fraud): situations in which a fraudster impersonates a trusted party in order to persuade a customer to authorise a payment.

The scope of the reimbursement obligation is narrower than the term APP fraud might suggest. The provision applies only where the fraudster impersonates the consumer's own payment service provider and uses communication channels attributable to that payment service provider, for example by spoofing its domain name, email address, telephone number, website or app.

Scenario: a customer receives a telephone call from someone posing as an employee of their bank who, under the pretence that ‘your account is about to be hacked’, persuades the customer to transfer money to a ‘safe account’. The customer authorises the transaction themselves, including any required SCA steps. Under PSD2, this constitutes an authorised transaction for which the PSP is, in principle, not liable. Under the PSR, however, if the consumer reports the incident to their PSP without undue delay after becoming aware of the fraud and also reports it to the police, the PSP is required to reimburse the full amount.

Article 59 begins with a preventive obligation that is often overlooked in discussions about reimbursement: the PSP must have adequate preventive measures and robust technical safeguards in place to prevent fraudsters from imitating or misusing its communication channels in order to induce users to make fraudulent transactions.

What exactly constitutes ‘adequate preventive measures and robust technical safeguards’ is already relatively specific in certain respects. Article 83 requires transaction monitoring prior to execution by both the payer's PSP and the payee's PSP, provides an exhaustive list of the data that may be processed for this purpose, and establishes a separate liability and reimbursement rule where such monitoring is absent, with the burden of proof resting on the PSP.

Based on the current text and explanations provided by the negotiating parties, a number of elements are nevertheless emerging that PSPs are expected to be able to demonstrate:

  • Real-time transaction monitoring, aimed at identifying unusual payment behaviour, such as unusual amounts, new beneficiaries and atypical transaction times.
  • Risk scoring for each transaction, whereby the level of risk partly determines whether additional verification or a delay is applied. The EBA is required to develop an RTS for this purpose.
  • Behavioural analysis and device fingerprinting, to detect potential account takeovers by identifying atypical user behaviour.
  • Exchange of fraud indicators between PSPs. Article 83a makes participation in mutual information-sharing arrangements mandatory, while placing strict limits on such exchanges: information may only be shared where there is an objectively justified suspicion of fraudulent behaviour.

This provision deserves particular attention from compliance officers for several reasons:

  • The dual reporting requirement. The reimbursement obligation is linked to reporting the fraud both to the police and to the PSP. The text already provides more guidance on this point than is often assumed: consumers must report the incident without undue delay after becoming aware of the fraud. The 15-business-day period within which the PSP must either reimburse the consumer or provide a reasoned refusal only starts once the consumer has both reported the fraud and submitted the police report.
  • A fraud and gross-negligence assessment, but no excess threshold. Article 59(3) expressly provides that the reimbursement obligation does not apply where the consumer has acted fraudulently or with gross negligence. Article 59(4) places the burden of proof on the PSP and requires the PSP to invite the consumer to explain the circumstances before reaching that conclusion. What the compromise text does not provide for is an excess threshold or an allocation of losses based on the degree of care exercised by the consumer.

For internal processes, this means in practical terms that PSPs need a standardised, auditable process for receiving APP fraud reports, assessing them against the statutory requirements and, where the customer has not acted fraudulently or with gross negligence, reimbursing the customer. This process affects the fraud/risk function, customer service and legal teams, and warrants a dedicated section in the fraud policy, separate from the existing complaints procedure for unauthorised transactions.

5. Practical implications for compliance and risk functions

Translated into the day-to-day work of compliance and risk teams, this shift in liability results in a number of practical considerations that can already be addressed in anticipation of the PSR's formal entry into force:

  • Review the fraud policy as a whole. Many existing fraud policies are primarily written from the perspective of SCA compliance and complaints handling in relation to unauthorised transactions. These policies will need to be expanded to include an explicit section on preventive measures for authorised transactions, including the requirements that will apply to such measures.
  • Establish escalation procedures for APP fraud reports. As described in Section 4, the reimbursement obligation for impersonation fraud requires a dedicated, clearly identifiable process with clear assessment criteria, a defined timeframe and an escalation route between customer service, the fraud/risk function and legal.
  • Align with the name/IBAN verification requirement. For institutions that are not yet subject to the Instant Payments Regulation, this is a good opportunity to explore the technical and operational feasibility of verification across all payment rails in anticipation of the broader PSR requirement.
  • Implement the specific requirements of Articles 51 and 53. These include configurable transaction limits in the framework contract, a four-hour delay for remote increases to those limits and for the remote activation of a mobile app, notification through a second communication channel, and a free reporting channel offering human support in the local language, with customers being able to prove their use of that channel for 18 months afterwards. These are not open-ended standards: they can already be incorporated into the customer journey and framework contract.
  • Treat record-keeping as an ongoing process rather than an incident response. The documentation required to demonstrate that there were objectively justified grounds for suspecting fraud or gross negligence must already be available at the time a report is made. This supports automated, systematic recording of monitoring and risk decisions rather than ad hoc reconstruction following a complaint.
  • Provide training and awareness for the first line. Customer service employees who receive APP fraud reports must be equipped to ask the appropriate questions, such as whether a police report has been filed, when it was filed and under which reference number, in order to facilitate the subsequent assessment process.
  • Coordinate with internal audit and the second line at an early stage. Given the heavier burden of proof, it is advisable to carry out a baseline assessment of the current fraud prevention framework against the expected PSR standards, so that any shortcomings can be identified in good time.

These points are expressly not exhaustive and will be refined once the EBA publishes further technical standards, but they provide a basis for starting internal preparations now and taking a phased approach.

6. Conclusion and key considerations

The shift from authorisation towards prevention and substantiation of fraudulent or negligent conduct as the basis for liability is the most fundamental change that the PSR introduces in relation to fraud. For payment institutions and banks, this means moving from a reactive model to a proactive and demonstrable one, in which the quality and currency of their own prevention policies take centre stage.

The case study discussed above shows that this shift is significant not only from a legal perspective but also operationally: it requires changes to monitoring, customer communications, record-keeping and escalation processes.

It is important to approach these preparations in the right order and with the appropriate caveats. The direction of the changes is sufficiently clear to begin conducting a gap analysis and reviewing fraud policies now. At the same time, important details have yet to be finalised. Preparation is therefore both useful and advisable; however, fully embedding new processes in their definitive form would be premature until the text has been published in the Official Journal.

Projective Group

Want to know what the changing regulatory landscape means for your organisation? Projective Group helps financial institutions navigate complex regulatory requirements and turn them into practical, future-proof solutions. Get in touch with our experts to find out how we can support your organisation.