Breaking

PSD3 uncaps APP fraud liability as the UK stops at £85,000

PSD3 uncaps APP fraud liability as the UK stops at £85,000

Three major payment regulators have now settled on three incompatible liability architectures for authorised push payment (APP) fraud: the European Union is moving to uncapped reimbursement for impersonation scams under the Payment Services Regulation (PSR), the United Kingdom caps reimbursement at £85,000, and Singapore guarantees nothing at all. Firms operating across all three will need three separate reimbursement engines by 2028.

The EU’s payments package cleared its final trilogue hurdle in 2026, with the European Parliament and Council reaching provisional political agreement on the third Payment Services Directive (PSD3) and the PSR on November 27, 2025, and legislators settling final texts in April 2026. Under the agreed framework, where a fraudster impersonates a payment service provider (PSP), the transaction is treated as unauthorised and, per Norton Rose Fulbright’s analysis of the agreed text, triggers “full reimbursement by the PSP provided the user reports the fraud to the police and notifies their PSP” — with no monetary ceiling. This analysis walks through the three liability models now in force or in train, the divergence they create, the enforcement backdrop, and what compliance teams must build before the EU clock runs out.

Key facts

  • EU provisional political agreement: November 27, 2025, between the European Parliament and the Council; final texts agreed April 2026 (European Parliament Legislative Train).
  • PSR application: 18 months after entry into force; the payee-name/IBAN verification liability provisions apply at 24 months, giving firms a staggered build (Norton Rose Fulbright).
  • PSD3 transposition deadline: 18 months after entry into force, with practical applicability targeted at Q2–Q3 2028.
  • UK mandatory reimbursement: live since October 7, 2024, capped at £85,000 per claim, with cost split 50:50 between sending and receiving PSP (Payment Systems Regulator).
  • UK coverage estimate: the PSR calculates that 99.8% of APP fraud cases fall below the £85,000 cap, and roughly 90% of total APP fraud value is reimbursed.
  • Singapore Shared Responsibility Framework (SRF): effective December 16, 2024, covering digitally-enabled phishing scams, structured as a duty-based waterfall rather than guaranteed reimbursement (Monetary Authority of Singapore).
  • UK enforcement backdrop: Nationwide Building Society was fined £44 million in December 2025 for financial crime systems and controls weaknesses; total Financial Conduct Authority (FCA) fines published for 2026 stood at £16,842,723 (FCA).

Methodology and sources

This analysis draws on primary and near-primary material across three jurisdictions in the period from October 2024 to July 2026. For the EU, it relies on the European Parliament’s Legislative Train record for the payment services file and on published law-firm analyses of the agreed PSD3/PSR texts, since the consolidated instruments had not yet appeared in the Official Journal of the European Union at the time of writing. For the UK, it uses the Payment Systems Regulator’s published reimbursement policy and the FCA’s finalised guidance FG24/6 on a risk-based approach to payments, together with the FCA’s own published fines register. For Singapore, it uses the MAS Guidelines on the Shared Responsibility Framework. Where article and recital numbers of the PSR are not yet fixed in a published consolidated text, this piece names the obligation rather than citing a provisional article number. Figures are stated as published by the named regulator on the date given.

What the EU rule actually does to liability

The PSR’s fraud provisions attack the problem from two directions at once, and it is the second that changes the economics for payment firms.

The first is preventative. PSPs must verify that the payee name supplied by the payer matches the unique identifier — in practice the International Bank Account Number (IBAN) — before a credit transfer executes, and must warn the payer where a discrepancy appears. This is a confirmation-of-payee duty of the kind UK banks have run for several years, extended across the single market. The enforcement teeth sit in the consequence: failure to give that warning shifts liability for the misdirected funds onto the payer’s own PSP. A control failure becomes a balance-sheet item automatically, without any finding of fault by a supervisor.

The second is remedial, and it is the significant departure. Where a fraudster impersonates a PSP — the “spoofing” pattern in which a caller or message appears to come from the victim’s own bank — the resulting transaction is treated as an unauthorised transaction rather than an authorised one. That reclassification matters enormously, because unauthorised transactions already carry a strong reimbursement right in EU payments law. The victim must report the fraud to the police and notify their PSP; on doing so, the PSP reimburses in full. No cap is specified in the agreed framework. A €400,000 property-deposit spoofing loss and a €400 one attract the same treatment.

Liability also extends beyond the payments industry for the first time. Under the agreed package, large online platforms and search engines may only advertise financial services to consumers in a member state where the provider is authorised or exempt in that state, and platforms become liable to PSPs that have reimbursed defrauded customers where the platform was notified of fraudulent content and failed to remove it. That is a recovery route the UK regime does not give banks.

How three jurisdictions compare

Jurisdiction / Regulator Effective date Scope Key requirement Liability ceiling
EU (PSD3 / PSR, national competent authorities) PSR applies 18 months after entry into force; payee-verification liability at 24 months; practical applicability Q2–Q3 2028 All PSPs providing credit transfers in the EU; large online platforms and search engines for financial-services advertising Payee-name/IBAN match with warning to payer; PSP-impersonation fraud reclassified as unauthorised, triggering reimbursement on police report plus PSP notification No monetary cap specified in the agreed framework
UK (Payment Systems Regulator, with FCA supervision) October 7, 2024 Faster Payments and CHAPS transfers between UK accounts Mandatory reimbursement of in-scope APP fraud victims, cost split 50:50 between sending and receiving PSP; complaints referable to the Financial Ombudsman Service £85,000 per claim; PSR estimates 99.8% of cases fall below it
Singapore (MAS and Infocomm Media Development Authority) December 16, 2024 Digitally-enabled phishing scams; financial institutions and telecommunications operators Waterfall of specified anti-scam duties across banks then telcos; payouts arise where a duty in the waterfall was breached No guaranteed reimbursement — duty-based, not outcome-based

Sources: European Parliament Legislative Train; Payment Systems Regulator; Monetary Authority of Singapore Guidelines on the Shared Responsibility Framework. Last updated: July 28, 2026.

The three models answer different questions. Singapore’s SRF asks whether the institution did its job; if the bank and the telco each met their duties in the waterfall, the loss can stay with the consumer. The UK asks whether the consumer was defrauded, and reimburses regardless of institutional fault, but bounds the exposure at £85,000 and splits it evenly between the two PSPs in the chain. The EU asks what kind of fraud it was: impersonate the bank and reimbursement is effectively automatic and unbounded; persuade the victim through some other pretext and the outcome is less certain.

That last distinction is where regulatory-arbitrage risk concentrates. A fraud typology that is economically identical to the victim — money moved by deception to a mule account — attracts uncapped reimbursement in the EU if the approach vector was PSP impersonation, a capped payment in the UK, and possibly nothing in Singapore. Fraud rings optimise against exactly this kind of seam. Firms with pan-European and UK operations should expect impersonation-pattern attacks to concentrate in the jurisdiction where the reimbursement right is strongest and the mule-account controls weakest.

“Today’s deal is a win for the Parliament by establishing a liability provision for online platforms where fraud started.”

René Repasi, Member of the European Parliament and rapporteur for the Payment Services Regulation (Linklaters Financial Regulation)

Enforcement context: the controls bill arrives first

Reimbursement liability is the visible cost. The supervisory cost lands earlier and is already being charged.

In December 2025 the FCA fined Nationwide Building Society £44 million for serious weaknesses in financial crime systems and controls, including customer due diligence and transaction monitoring. The case is instructive for payments firms because none of the failings were reimbursement failings — they were detection and monitoring failings, exactly the capability the PSR’s payee-verification duty and the SRF’s waterfall both assume is already working. A firm that cannot evidence effective monitoring has both an enforcement exposure and, under the EU model, an automatic civil liability whenever a warning is not raised.

The FCA has also been reshaping the payments perimeter directly rather than only through fines: it has cancelled 95 payment service provider authorisations and opened nine enforcement cases in the sector. Its finalised guidance FG24/6 sets out how firms should take a risk-based approach to payments, including delaying outbound payments where there are reasonable grounds to suspect fraud — a power that only works if the underlying monitoring can identify those grounds in near real time. Published FCA fines for 2026 totalled £16,842,723 at the time of writing, a figure that understates supervisory pressure because it excludes censures and voluntary payments, including the CACEIS Bank UK Branch matter, where a Final Notice dated June 19, 2026 was followed by a public censure on June 25, 2026 and acceptance of a £31.7 million voluntary payment in place of a penalty.

The UK’s liability debate is older than it looks. When the FCA introduced rules letting APP fraud victims complain to the receiving PSP, Christopher Woolard, then Executive Director of Strategy and Competition at the FCA, said: “The FCA takes APP fraud and the harm it causes to consumers very seriously. Now victims of APP fraud can make a complaint to the PSP receiving their payment and if they’re not satisfied with the outcome, can refer their complaint to the Financial Ombudsman Service.” That statement, published by the FCA, dates from 2018, against a backdrop of 43,875 APP cases and £236 million of losses in 2017. It took a further six years to reach mandatory reimbursement. The EU, having started later, is arriving at a broader remedy — and firms should not assume the intervening design work has been done for them.

What this means for brokers, PSPs, exchanges and compliance teams

For payment institutions and e-money institutions, the build list is concrete. Payee-name matching must run against every outbound credit transfer in the EU, with a persisted, auditable record of whether a mismatch warning was displayed and what the payer did next. That record is the sole defence when liability is asserted; an unlogged warning is, evidentially, no warning. Because the verification liability lands at 24 months while the rest of the PSR lands at 18, there is a six-month window in which the wider obligations bite before the specific verification liability does — a sequencing detail worth building the project plan around rather than discovering late.

For banks and receiving PSPs, the UK 50:50 split makes inbound mule-account detection a direct profit-and-loss line rather than a reputational one. Receiving-side controls that were historically underfunded relative to sending-side controls now carry half of every in-scope claim.

For brokers, contracts-for-difference providers and crypto-asset service providers taking client money by credit transfer, the exposure is second-order but real: firms that are the unwitting destination of fraud-funded deposits face reimbursement claims from paying PSPs, chargeback-style disputes, and the client-money reconciliation problem of funds that must be returned after they have been traded. Onboarding controls and source-of-funds checks are the mitigation, and both are already supervisory priorities.

For legal and compliance teams, the governing document is the fraud-liability matrix: which entity, in which jurisdiction, bears which loss, under which trigger, subject to which cap. Groups operating in the EU, UK and Singapore need three matrices, not one, and the reimbursement engine has to be configurable per corridor rather than hard-coded. Firms should also revisit intra-group recharge arrangements, because uncapped EU liability sitting in a thinly capitalised subsidiary is a prudential question as well as a conduct one.

What is next: the forward view

The immediate gate is publication in the Official Journal, expected around mid-2026 with some risk of slipping to the autumn. Entry into force follows shortly after publication, and it is that date — not the political agreement date — that starts the 18-month and 24-month clocks. Firms budgeting against a fixed 2028 deadline should treat the quarter of publication as the single most consequential unknown in the plan.

Beyond the timetable, three things remain contested. First, the operational definition of PSP impersonation: the broader the reading, the more fraud typologies collapse into the uncapped unauthorised-transaction bucket, and that boundary will be drawn by national competent authorities and, eventually, litigation. Second, the platform-liability mechanism, which depends on what constitutes valid notice to a platform and how quickly removal must follow; this is the provision Repasi singled out, and it is the one most likely to be tested. Third, the UK’s own settlement is not static — the Payment Systems Regulator is being folded into the FCA, which concentrates reimbursement policy and enforcement in a single supervisor and makes a future revisit of the £85,000 cap more likely, not less.

TL;DR

The EU’s PSD3/PSR package, politically agreed on November 27, 2025 with final texts settled in April 2026, reclassifies PSP-impersonation fraud as an unauthorised transaction and requires full reimbursement with no monetary cap, while also making large online platforms liable to PSPs for fraudulent content they fail to remove. The UK has run mandatory APP reimbursement since October 7, 2024 but caps it at £85,000, a level the Payment Systems Regulator says covers 99.8% of cases. Singapore’s Shared Responsibility Framework, effective December 16, 2024, guarantees no reimbursement at all and pays out only where a duty in its waterfall was breached. Cross-border firms will need three reimbursement engines by 2028.

FAQ

When exactly does the EU fraud-liability regime start applying?

The PSR applies 18 months after entry into force, and the payee-name/IBAN verification liability applies at 24 months. Entry into force follows publication in the Official Journal, expected around mid-2026. On that basis, practical applicability lands in the second or third quarter of 2028. PSD3 must additionally be transposed into national law by member states within 18 months of entry into force.

Is EU reimbursement really uncapped?

For the impersonation case, the agreed framework specifies full reimbursement without stating a monetary ceiling, conditional on the user reporting the fraud to the police and notifying their PSP. That is materially different from the UK, which caps each claim at £85,000. Firms should model tail exposure on high-value transfers — property deposits, corporate treasury movements — rather than on average fraud values.

How does the UK’s 50:50 split work?

Since October 7, 2024, the cost of reimbursing an in-scope APP fraud claim is shared equally between the PSP that sent the payment and the PSP that received it. This gives receiving institutions a direct financial incentive to detect and close mule accounts, an area historically funded less generously than outbound fraud controls.

Why does Singapore’s framework produce different outcomes?

The Shared Responsibility Framework, effective December 16, 2024, is duty-based rather than outcome-based. It sets a waterfall of anti-scam duties across financial institutions and then telecommunications operators for digitally-enabled phishing scams. Where each party discharged its duties, the loss can remain with the consumer. Reimbursement is a consequence of breach, not a consumer entitlement.

What does platform liability mean in practice?

Under the agreed EU package, large online platforms and search engines may only advertise financial services in a member state where the provider is authorised or exempt there, and become liable to PSPs that have already reimbursed customers if the platform was notified of fraudulent content and failed to remove it. This gives EU banks a recovery route against the origination channel that UK banks currently lack.

What is the single highest-priority build for a PSP?

An auditable payee-verification log. The EU liability shift turns on whether a mismatch warning was given, so the persisted record of the warning and the payer’s response is the primary evidential defence. Firms should treat the log schema, retention period and retrieval path as in-scope deliverables, not as by-products of the payments flow.

Does any of this apply to crypto-asset firms?

Indirectly but materially. Crypto-asset service providers that accept fiat deposits by credit transfer sit downstream of the fraud and can face reimbursement claims from paying PSPs, plus the client-asset problem of returning funds already deployed. The mitigation is onboarding and source-of-funds control, which is separately a supervisory priority under EU anti-money-laundering reform.

Related coverage on how these frameworks are diverging: the AMLA single rulebook splitting EU anti-money-laundering rules from the US and UK, the FCA’s decision not to copy MiCA, the consolidation of payment orchestration estates, and open-banking credit arriving as FCA rules land.

This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.

Rick Steves has seen business and economics through many lenses. He joined the financial services industry in 2009, and has been a financial journalist since 2011. He holds a degree in Business Administration and has experience producing real-time news, from both buy-side and sell-side, as well as for retail traders, brokers and service providers. Steves' work has appeared in a variety of online publications including FX Street, NewsBTC, FinanceFeeds, and The Industry Spread. Rick has great interest in the dynamics of the trading industry. The never-ending clash between technology, economics, regulation, and more importantly, the people.

Most Read

Related Posts

Imdustry insights

Stay Ahead

Get the latest news, insights, and market updates delivered to your inbox every day.

Enter your email address