# Payment Fraud: Who Refunds the Customer — PSD2, Verification of Payee and UK APP Reimbursement

> Who bears the loss when a payment is fraudulent: PSD2 refunds and the €50 cap, gross negligence, euro Verification of Payee and UK APP reimbursement.

Author: Gordey Bolotko — Partner, Corporate & Commercial (https://wiki.private.law/en/authors/bolotko)
Last modified: 2026-09-25T08:14:00.000Z
Canonical: https://wiki.private.law/en/payment-fraud-liability
Publisher: wiki.private.law (https://wiki.private.law)
Version: 77212842e9391601d3c467cf9cebfc7b554c760c5e0630eae429eb9d72a8e64d
Cite as: Payment Fraud: Who Refunds the Customer — PSD2, Verification of Payee and UK APP Reimbursement. wiki.private.law. https://wiki.private.law/en/payment-fraud-liability. Version 77212842e9391601d3c467cf9cebfc7b554c760c5e0630eae429eb9d72a8e64d.
Topics: banking
Jurisdictions: eu, uk, bulgaria
Product tags: compliance, banking, license-emi-eu
Semantic tags: compliance, banking, license-emi-eu

---

When money leaves an account through fraud, European payment law starts with one narrow question: did the account holder authorise the payment? If not, [PSD2](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) puts the loss on the payer's bank or e-money institution (EMI), which must refund by the end of the next business day. If the holder authorised it after being deceived, EU law treats the transfer as correctly executed; its answer is prevention, through Verification of Payee (VoP), a name check before the payment. The United Kingdom handles the second case differently: since 7 October 2024 its payment firms have had to [reimburse authorised push payment (APP) scams](https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf) up to £85,000 per claim.

## Who carries the loss: authorised or unauthorised

### Why the law splits fraud in two

Under [PSD2 Art. 64](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) a payment is authorised only if the payer consented in the form agreed with its payment service provider (PSP); consent may also be given through the payee or a payment initiation service. Without that consent the transaction is unauthorised, and [Art. 73](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) obliges the payer's PSP to refund it immediately and in any event by the end of the following business day.

The split follows control of the risk. When the payer never consented, the failure lies in authentication, a process the PSP designs and records, so [Art. 72](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) makes the PSP prove that the payment was authenticated and correctly recorded. When the payer confirmed the transfer, the PSP executed the instruction it was given: under [Art. 88](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) a payment executed in accordance with the IBAN supplied is deemed correctly executed as regards the payee.

That second branch is where most money is now lost. According to the [joint EBA-ECB report of December 2025](https://www.ecb.europa.eu/press/pr/date/2025/html/ecb.pr251215~e133d9d683.en.html), payment fraud in the EEA reached €4.2 billion in 2024, up from €3.5 billion in 2023; fraud losses on credit transfers were €2.2 billion. For credit transfers, users bore about 85% of the losses, mainly because scams tricked them into initiating the payments themselves.

### What distinguishes the regimes

Three features decide most outcomes.

**All or nothing on authorisation**

The same phishing story can fall on either side. If the fraudster uses stolen credentials to send the payment, it is unauthorised and the PSP refunds. If the customer confirms the transfer on the fraudster's instructions, it is authorised, and in the EU the loss stays with the customer.

**A warning that moves liability**

Verification of Payee tells the payer whether the name matches the IBAN, but it may not stop the payment. A PSP that ran the check correctly is not liable when a warned customer pays anyway; a PSP that failed to run it refunds where that failure led to the misdirected payment.

**Reimbursement with a cap**

In the UK the sending PSP reimburses up to £85,000 per claim and may deduct an excess of up to £100. The receiving PSP pays half, and only first-party fraud or gross negligence defeats the claim.

Two further features cut across all three. Business clients receive less protection: [PSD2 Art. 61](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) lets a PSP agree with a non-consumer that the burden-of-proof and payer-liability rules do not apply, and the UK reimbursement scheme covers only consumers, microenterprises and charities. And gross negligence is where disputes concentrate: it is the ground, besides the payer's own fraud or intentional breach, on which a payer loses the whole of an unauthorised payment, and the PSP has to prove it.

> 🍓 EU law protects the authorisation; UK rules insure the outcome. In the EU the payer's PSP pays when consent, authentication or the payee check fails, but not when a properly warned customer sends money to a fraudster. The UK moves that residual loss onto the sending and receiving PSPs, which is why the same scam can be refunded in London and not in Sofia or Vilnius.

### Loss allocation at a glance

The regimes below differ on who pays first, how much the payer keeps at risk and whether the rule is already law.

| Scenario | Who pays | Payer's share | Basis and status |
| --- | --- | --- | --- |
| Unauthorised payment, EU | payer's PSP, refund by the end of the next business day | up to €50; everything if fraud, intent or gross negligence | PSD2 Arts 73–74, in force |
| APP scam, EU, payee check run correctly | payer; the PSP must try to recover the funds | the full amount | PSD2 Art. 88; Reg. 260/2012 Art. 5c(8), in force |
| APP scam, EU, PSP failed the payee check | payer's PSP, refund without delay | none, where the PSP's failure led to the misdirected payment | Reg. 260/2012 Art. 5c(8); euro area since 9 October 2025 (date open to interpretation for EMIs and payment institutions) |
| APP scam, UK, Faster Payments or CHAPS | sending PSP reimburses; receiving PSP pays half | excess of up to £100; anything above £85,000 | Payment Systems Regulator requirement, since 7 October 2024 |
| Scam by someone posing as bank staff, EU | PSP, in full, if the customer reports to the police and the PSP | none, as announced | Payment Services Regulation, agreed, not adopted |

The table shows why the authorised/unauthorised question is decisive: in the EU it separates a refund within one business day from a loss the payer keeps, while in the UK both branches end with the PSP paying, subject to caps and exceptions.

## Unauthorised payments under PSD2

### The refund comes first

Once the payer's PSP notes or is told of an unauthorised transaction, [Art. 73(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) requires it to refund the amount immediately, and no later than the end of the following business day, restoring the account with a value date no later than the debit date.

The only exception is where the PSP has reasonable grounds for suspecting fraud and communicates those grounds in writing to the relevant national authority. Where a [payment initiation service provider](https://wiki.private.law/en/open-banking-aisp-pisp) started the payment, the account-servicing PSP still refunds, and the initiation provider compensates it if liable (Art. 73(2)).

The payer has duties of its own. Under [Arts 69 and 71](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) it must use the instrument as agreed, take all reasonable steps to keep its personalised security credentials safe, and report loss, theft or unauthorised use without undue delay, and in any case within 13 months of the debit date. The 13-month limit does not run if the PSP failed to provide the transaction information PSD2 requires. The issuing PSP, for its part, must keep a free notification channel open at all times and, on request, provide proof of a notification for 18 months (Art. 70).

### How much the payer can lose

[Art. 74](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) grades the payer's exposure by what went wrong:

| Situation | Payer's exposure | Provision |
| --- | --- | --- |
| Lost, stolen or misappropriated payment instrument | up to €50 | Art. 74(1), first subparagraph |
| Loss not detectable by the payer before the payment, or caused by the PSP's employee, agent, branch or outsourcee | nothing; in the first case, unless the payer acted fraudulently | Art. 74(1), second subparagraph |
| Payer acted fraudulently or breached its duties with intent or gross negligence | all losses | Art. 74(1), third subparagraph |
| The PSP did not require strong customer authentication | nothing, unless the payer acted fraudulently | Art. 74(2) |
| Use after the payer notified the PSP, or no means to notify | nothing, unless the payer acted fraudulently | Art. 74(3) |

The €50 figure is therefore a ceiling for the cases in the first row, not a charge the PSP may apply to every unauthorised payment. Member states may reduce the payer's liability further where it neither acted fraudulently nor breached its duties intentionally. A payee or payee's PSP that fails to accept strong customer authentication (SCA) must refund the financial damage it causes to the payer's PSP.

### Gross negligence and the burden of proof

When a user denies authorising a payment, [Art. 72](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) makes the PSP prove that it was authenticated, accurately recorded and not affected by a technical breakdown. The recorded use of the instrument is not in itself necessarily sufficient to prove authorisation, fraud or gross negligence, and the PSP must provide supporting evidence of the payer's fraud or gross negligence. In practice the dispute turns on what the PSP's systems logged and what the customer was shown.

> ⚙️ The evidence a PSP relies on comes from two sources. Strong customer authentication under [PSD2 Art. 97](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) must dynamically link a remote payment to its amount and payee. Transaction monitoring under [Delegated Regulation 2018/389 Art. 2](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912), applicable since 14 September 2019, must weigh compromised credentials, the amount, known fraud scenarios, signs of malware and, where the PSP supplied the device or software, abnormal use.

### Business clients, e-money and pull payments

Three variations change the default. For non-consumers, [Art. 61](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) allows the contract to exclude, in whole or in part, Arts 72, 74, 76, 77, 80 and 89 among others, and to set notification periods other than those of Art. 71; member states may treat microenterprises as consumers. The refund duty of Art. 73 is not on that list.

For electronic money, Arts 73 and 74 apply unless the PSP cannot freeze the account holding the e-money or block the instrument ([Art. 63(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117)). For low-value instruments, used for single payments of up to €30 or with a spending limit or stored funds of up to €150, PSPs may agree reduced protection (Art. 63(1)).

Pull payments follow a separate logic. A payer may ask for a refund of an authorised payment initiated by or through the payee within eight weeks, where the amount was not specified and exceeded what the payer could reasonably expect; for SEPA direct debits that right is unconditional; the PSP must refund or justify a refusal within ten business days ([Arts 76–77](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117)). Card disputes run through [scheme chargeback rules](https://wiki.private.law/en/card-scheme-rules), and consent given through software acting for the payer raises the questions set out in [agentic payments](https://wiki.private.law/en/agentic-payments).

### Case law: 4 rulings and opinions

The Court of Justice has interpreted the notification, refund and execution rules mostly under PSD1 (Directive 2007/64), whose provisions PSD2 carried over with the same structure.

| Case | Status | What it says |
| --- | --- | --- |
| [C-245/18 Tecnoservice](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62018CJ0245) | judgment of 21 March 2019 (PSD1) | execution on the unique identifier is correct even if it does not match the payee name given; the payee's PSP is shielded too |
| [C-337/20](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62020CJ0337) | judgment of 2 September 2021 (PSD1) | a user who reported an unauthorised payment too late cannot sue the PSP under general contract law instead; the user's guarantor can |
| [C-665/23 Veracash](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62023CJ0665) | judgment of 1 August 2025 (PSD1) | late reporting in principle defeats the claim even within 13 months; for a lost, stolen or misappropriated instrument, only intentional or grossly negligent delay does |
| [C-70/25](https://curia.europa.eu/site/upload/docs/application/pdf/2026-03/cp260031en.pdf) | Advocate General's opinion of 5 March 2026; no judgment as of 24 September 2026 | a bank may not withhold the Art. 73 refund by alleging gross negligence; it may later recover the loss by proving it |

In Veracash the Court added that for successive payments with a lost or stolen instrument only those reported late through intent or gross negligence are lost. The opinion in C-70/25, a Polish phishing case, is not binding; the Court may decide differently.

## Scams the payer authorised: the EU approach

### Correct execution under Art. 88

An APP scam leaves an authorised payment behind. [PSD2 Art. 88](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) deems a payment executed in accordance with the unique identifier correctly executed as regards the payee, and where the identifier supplied was wrong, the PSP is not liable for defective execution. In Tecnoservice (C-245/18) the Court of Justice held, under the equivalent PSD1 provision (Art. 74(2)), that this applies even where the identifier does not match the payee name the payer gave, and that it protects the payee's PSP as well. Art. 88 itself requires no name check; Verification of Payee adds one.

What remains is a duty of effort: the payer's PSP must make reasonable efforts to recover the funds, the payee's PSP must cooperate, and if recovery fails the payer can obtain, on written request, the information it needs to sue. The PSP may charge for recovery if the framework contract says so. How recalls and blocked payments work between banks is covered in [correspondent banking and client-money protection](https://wiki.private.law/en/correspondent-banking-safeguarding).

Strong customer authentication does not close this gap. The [EBA-ECB report](https://www.ecb.europa.eu/press/pr/date/2025/html/ecb.pr251215~e133d9d683.en.html) finds it effective against the fraud it was designed for, especially card fraud, with a less clear effect on credit transfers, and names manipulation of payers as a rising fraud type. Card fraud was 17 times higher when the payee was outside the EEA, where SCA is not legally required. A customer who authenticates a payment to a fraudster passes every SCA check.

### Verification of Payee

Since 2025 the EU has answered with a check before the payment. [Regulation (EU) 2024/886](https://eur-lex.europa.eu/eli/reg/2024/886/oj), the Instant Payments Regulation of 13 March 2024, inserted Art. 5c into Regulation 260/2012. The payer's PSP must offer verification of the payee for euro credit transfers, instant and standard alike, whatever the channel used to place the order.

The mechanics are fixed by [Art. 5c(1)](https://eur-lex.europa.eu/eli/reg/2024/886/oj). When the payer enters an IBAN and a name, the payer's PSP asks the payee's PSP, before the payer can authorise, whether they match. For a legal-person payee, a fiscal number, European unique identifier or LEI may be matched instead of the name. The service must be free of charge, and non-consumers submitting payments in bulk may opt out and opt back in at any time (Arts 5b(2) and 5c(6)).

Between PSPs the check runs on the [European Payments Council's VOP scheme](https://www.europeanpaymentscouncil.eu/what-we-do/other-schemes/verification-payee), which returns one of four answers:

| Response | Shown to payer | If payer proceeds |
| --- | --- | --- |
| Match | the name matches the account | ordinary execution under PSD2 |
| Close match | the name actually associated with the IBAN | a PSP that complied is not liable under Art. 88 |
| No match | authorising may send the funds to an account not held by the intended payee | a PSP that complied is not liable under Art. 88 |
| Check not possible | that the check could not be completed | if a PSP's failure to comply caused a defective payment, the payer's PSP refunds |

The scheme rules are an industry standard: rulebook version 1.1 took effect on 20 September 2026; as of September 2026, publication of version 2.0 was scheduled for the end of November 2026.

> ⚠️ A no-match warning does not stop the payment. [Art. 5c(5)](https://eur-lex.europa.eu/eli/reg/2024/886/oj) requires that verification must not prevent the payer from authorising the transfer, and under Art. 5c(8) a PSP that met the requirements is not liable for executing a transfer to an unintended payee. A customer who confirms after a warning keeps the loss, and PSPs must explain those consequences in advance (Art. 5c(7)).

The liability shift runs the other way when the PSP fails. If the payer's PSP, or a payment initiation provider, does not comply and a defectively executed transaction results, the payer's PSP must refund the payer without delay; a payee's PSP or initiation provider whose failure caused the problem compensates the payer's PSP ([Art. 5c(8)](https://eur-lex.europa.eu/eli/reg/2024/886/oj)).

### Who must offer it, and from when

[Art. 5c(9)](https://eur-lex.europa.eu/eli/reg/2024/886/oj) sets the dates by where the PSP is located, and draws no distinction between banks and non-bank PSPs:

| PSPs located in | VoP applies | Legal basis |
| --- | --- | --- |
| a euro-area member state | since 9 October 2025; for EMIs and payment institutions, open to interpretation | Reg. 260/2012 Art. 5c(9) |
| Bulgaria, in the euro area since 1 January 2026 | by 1 January 2027 at the latest | Reg. 260/2012 Art. 16(9) |
| a member state outside the euro area | by 9 July 2027 | Reg. 260/2012 Art. 5c(9) |

For EMIs and payment institutions the date is less settled than the operative text suggests. The Commission services' [Q&A on the Regulation](https://finance.ec.europa.eu/document/download/f597b1a5-2a7b-481d-882c-80fb1c5cc3d5_en?filename=instant-payments-implementation-questions-answers_en.pdf) confirms that the duty binds them when the payer is their customer (Q98). Their instant-payment timetable, however, runs later than banks': euro-area EMIs and payment institutions must offer sending and receiving instant euro transfers only by 9 April 2027 under [Art. 5a(8)](https://eur-lex.europa.eu/eli/reg/2024/886/oj). Recital 28 says verification should apply from the same time as the obligation to send instant transfers, and the same Q&A (Q87) reads the Art. 5c(9) date as applying to non-bank PSPs that already provide instant euro transfers.

An EMI or payment institution that already sends instant euro transfers has therefore had to verify payees since 9 October 2025. For one that does not yet send them, the date is a question of interpretation: Art. 5c(9) itself points to 9 October 2025, while the recital and the Q&A point to its own instant-sending deadline. The Q&A is not binding and is without prejudice to the Court of Justice's interpretation.

## Bulgaria after the euro

Bulgaria transposes PSD2's liability rules in Arts 75–80 of the [Payment Services and Payment Systems Act (ZPUPS)](https://www.bnb.bg/bnbweb/groups/public/documents/bnb_law/laws_payment_services_bg.pdf), and joined the euro area on 1 January 2026. The changeover moved two things: the payer's liability ceiling is now stated in euro, and the timetable for Verification of Payee follows the special rule for new euro-area members.

| Rule | Provision | Content |
| --- | --- | --- |
| Refund of an unauthorised payment | ZPUPS Art. 79(1) | by the end of the following business day, unless the PSP reasonably suspects fraud and notifies the competent authorities |
| Burden of proof | ZPUPS Art. 78(4) | the PSP proves the payer's fraud or gross negligence |
| Payer's ceiling | ZPUPS Art. 80(1) | the amount agreed, at most €50, since 1 January 2026 |
| Verification of Payee | Reg. 260/2012 Art. 16(9) | by 1 January 2027 at the latest |
| Complaints | ZPUPS Art. 174 | written decision within 15 business days, exceptionally 35 |
| Sanction for breaching Reg. 260/2012 | ZPUPS Art. 186(2) | €5,112.92–20,451.68; repeat breach €20,451.68–40,903.35 |

The Verification of Payee date is set by the Regulation itself. Under [Art. 16(9) of Regulation 260/2012](https://eur-lex.europa.eu/eli/reg/2024/886/oj), PSPs in a member state that adopts the euro before 9 April 2027 must comply within one year of adoption and no later than the dates for non-euro PSPs, but are not required to comply earlier than the dates for euro-area PSPs. For Bulgaria that means 1 January 2027 at the latest; a Bulgarian PSP may offer the check earlier.

The Bulgarian National Bank (BNB) supervises compliance with Regulation 260/2012, except its Art. 5d, under [ZPUPS Art. 167(2)](https://www.bnb.bg/bnbweb/groups/public/documents/bnb_law/laws_payment_services_bg.pdf), and since 1 January 2026 the Act lists Regulation 2024/886 among the EU acts it implements. The property sanction in the table is still printed in the Act as BGN 10,000–40,000 (BGN 40,000–80,000 for a repeat breach); Arts 11(2), 12 and 13 of the [Law on the Introduction of the Euro](https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=224950) convert those amounts at the rate of 1.95583.

A customer dissatisfied with the PSP's decision can take the dispute to the Conciliation Commission for Payment Disputes attached to the Commission for Consumer Protection. Under [ZPUPS Art. 175](https://www.bnb.bg/bnbweb/groups/public/documents/bnb_law/laws_payment_services_bg.pdf) it hears national and cross-border disputes between PSPs or e-money issuers, including those licensed under the [Bulgarian EMI and payment institution regime](https://wiki.private.law/en/bulgaria-emi-license), and their users.

## The UK model: mandatory APP reimbursement

[Section 72 of the Financial Services and Markets Act 2023](https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf) required the Payment Systems Regulator (PSR) to impose reimbursement for qualifying APP scams over Faster Payments. The PSR's requirement took effect on 7 October 2024 for Faster Payments and CHAPS, through Specific Requirement 1 and Specific Directions 19 to 21. Which UK firms count as payment service providers in the first place is mapped in the [FCA licence map](https://wiki.private.law/en/uk-fca-license-map).

### Scope

The requirement covers [Faster Payments and CHAPS payments made on or after 7 October 2024](https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf), sent and received by PSPs in the UK, including payments started through a payment initiation service. It protects consumers, microenterprises and charities that were deceived into paying someone other than intended, or for a purpose other than intended. It does not cover earlier payments, international payments, payments over other systems, payments for unlawful purposes or civil disputes with legitimate suppliers.

> ⚠️ The UK reimbursement ends at the border of the domestic rails. A transfer to an account abroad, or money moved onward from a UK account into crypto-assets over another system, falls [outside the scheme](https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf). Customers of UK EMIs who pay across borders therefore rely on the general rules that apply to that payment.

### Sending and receiving PSP

The scheme splits the cost between both ends of the payment.

**Sending PSP**

Reimburses the victim and alone decides whether the claim qualifies. It should process the claim within five business days, may stop the clock only for listed information requests, and must close the claim by the end of the 35th business day after it was reported.

**Receiving PSP**

Holds the account the money went to. Once the sending PSP has reimbursed the victim, it can require the receiving PSP to pay 50% of the reimbursement, so the firm that opened the recipient's account shares the cost.

The limits and exceptions are set in [policy statement PS25/5](https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf):

| Parameter | Rule |
| --- | --- |
| Maximum reimbursement | £85,000 per claim; set by the PSR for Faster Payments and by the Bank of England for CHAPS |
| Excess | up to £100 or none; never for vulnerable consumers; no minimum claim value |
| Exceptions | first-party fraud; gross negligence measured against the consumer standard of caution |
| Burden of proof | on the PSP alone; contract terms cannot shift it |
| Vulnerable consumers | no excess and no gross-negligence exception; the cap still applies |
| Late claims | may be refused if made more than 13 months after the final payment |

The cap was fixed in [PS24/7](https://www.psr.org.uk/publications/policy-statements/ps247-faster-payments-app-scams-reimbursement-requirement-confirming-the-maximum-level-of-reimbursement/) in line with the deposit-protection limit of the time, and does not track it: the [FSCS deposit limit](https://www.fscs.org.uk/what-we-cover/banks-building-societies/) rose to £120,000 on 1 December 2025, while the APP cap stayed at £85,000. A consumer unhappy with the outcome can go to the Financial Ombudsman Service. Under [DISP 1.6.2A](https://www.handbook.fca.org.uk/handbook/DISP/1/6.html) a payment or e-money firm must give a final response within 15 business days, exceptionally 35, and under [DISP 2.8](https://www.handbook.fca.org.uk/handbook/DISP/2/8.html) the complaint must generally reach the Ombudsman within six months of that response.

### Unauthorised payments and payment delays in UK law

Unauthorised payments remain under the Payment Services Regulations 2017. [Regulation 77](https://www.legislation.gov.uk/uksi/2017/752/regulation/77) caps the payer's liability for a lost, stolen or misappropriated instrument at £35, removes the cap for fraud or for an intentional or grossly negligent breach, and leaves the payer without liability where strong customer authentication was required but not applied, unless it acted fraudulently.

Under [regulation 76](https://www.legislation.gov.uk/uksi/2017/752/regulation/76) the PSP must refund by the end of the business day after it becomes aware, unless it suspects fraud and makes a notification under section 333A of the Proceeds of Crime Act 2002.

Since 30 October 2024, [regulation 86(2A)–(2D)](https://www.legislation.gov.uk/uksi/2017/752/regulation/86) has let a payer's PSP delay an outgoing payment when it has reasonable grounds to suspect fraud or dishonesty by a third party, for no longer than necessary and at most until the end of the fourth business day, telling the payer why. The name check that precedes the payment, Confirmation of Payee, became mandatory under [Specific Direction 17](https://www.psr.org.uk/our-work/app-scams/confirmation-of-payee/confirmation-of-payee-requirements-under-specific-direction-17/): by 31 October 2023 for Group 1 PSPs and by 31 October 2024 for Group 2.

### Reimbursement since October 2024: PSR data

The [PSR's dashboard for the first quarter of 2026](https://www.psr.org.uk/information-for-consumers/app-scams-reimbursement-dashboard/), published on 30 July 2026, covers Faster Payments from 7 October 2024 to 31 March 2026.

| Measure | Figure |
| --- | --- |
| Share of money lost to in-scope scams that was reimbursed | about 88% (£316 million) |
| Claims reported by consumers | about 438,300 |
| Claims in scope | about 301,500 |
| Claims closed within five business days | 82% |
| Claims closed within 35 business days | 98% |
| Claims rejected for insufficient consumer care | about 3% |

The institution running the scheme may change. The [Financial Services and Markets Bill](https://bills.parliament.uk/bills/4129), introduced in the House of Lords on 19 May 2026, would abolish the PSR and transfer its functions to the FCA. In September 2026 it was awaiting second reading in the Commons and is not law, so the PSR still runs the scheme. As of September 2026, the PSR planned a formal consultation in December 2026 on policy parameters such as claims left unresolved after 35 business days and how “returns from investment” are treated under the policy. The wider reshaping of UK payments supervision is followed in [the UK safeguarding and crypto regime](https://wiki.private.law/en/uk-safeguarding-crypto-regime).

## What an operator has to build

For a bank, EMI or payment institution, the licence types mapped in the [fintech hub](https://wiki.private.law/en/fintech-hub), the liability rules translate into a small set of controls, each with a legal source and a direct effect on who ends up paying:

| Control | Legal basis | Effect on loss |
| --- | --- | --- |
| Strong customer authentication and transaction monitoring | PSD2 Art. 97; Reg. 2018/389 Art. 2 | without SCA the payer bears nothing unless fraudulent (Art. 74(2)) |
| Free notification channel, open at all times | PSD2 Art. 70 | without it the payer is not liable (Art. 74(3)) |
| Refund workflow for unauthorised payments | PSD2 Art. 73; ZPUPS Art. 79 | refund by the next business day; only a fraud suspicion notified to the authority delays it |
| Payee check as requester and responder | Reg. 260/2012 Art. 5c | compliance removes Art. 88 liability; failure means refunding the payer |
| Complaint handling within 15 business days, exceptionally 35 | PSD2 Art. 101; FCA DISP; ZPUPS Art. 174 | unresolved disputes go to ADR or the Ombudsman; the user must be told of an ADR body |
| UK claim handling and receiving-side contributions | PSR Specific Directions 19–21 | reimbursement within the deadlines; 50% contribution as receiving PSP |

Fraud data also feed supervision. [PSD2 Art. 96(6)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) requires PSPs to send statistical fraud data to their competent authority at least annually. The [EBA fraud-reporting guidelines](https://www.eba.europa.eu/sites/default/files/document_library/Final%20Report%20on%20EBA%20Guidelines%20on%20fraud%20reporting%20-%20Consolidated%20version.pdf) (EBA/GL/2018/05, as amended by EBA/GL/2020/01) require reporting every six months, or annually with a half-year breakdown for exempted small institutions. The data cover both unauthorised transactions and transactions resulting from manipulation of the payer. The contractual side matters too: the opt-outs Art. 61 allows for business clients only apply if the framework contract uses them.

> 🧭 The rail decides the regime. A euro credit transfer, standard or instant, falls under PSD2 and the Verification of Payee duty. A UK Faster Payments or CHAPS transfer falls under the Payment Services Regulations 2017 and, if authorised under deception, the PSR reimbursement scheme. A card payment follows PSD2 Arts 73–74 when unauthorised and scheme chargeback rules otherwise.

These controls sit inside a payment firm's wider [compliance stack](https://wiki.private.law/en/compliance-stack), next to [sanctions screening](https://wiki.private.law/en/sanctions-screening) of payers and payees, which is a separate control.

## What changes next (not in force)

The EU is moving towards partial reimbursement, but only by legislation that has not yet been adopted. PSD3 (procedure 2023/0209(COD)) and the [Payment Services Regulation](https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2023%2F0210\(COD\)) (2023/0210(COD)) reached a provisional political agreement on 27 November 2025. The ECON committee approved the agreed texts on 5 May 2026, and as of September 2026 the indicative plenary date was 14 December 2026. Neither act is adopted, published or in force; the legislative calendar is followed in [PSD3 and the Payment Services Regulation](https://wiki.private.law/en/psd3-psr).

As announced by the [European Parliament](https://www.europarl.europa.eu/news/en/press-room/20251121IPR31540/payment-services-deal-more-protection-from-online-fraud-and-hidden-fees) and the [Council](https://www.consilium.europa.eu/en/press/press-releases/2025/11/27/payment-services-council-and-parliament-agree-to-step-up-the-fight-against-fraud-and-increase-transparency/), the agreement would:

- require the PSP to refund the full amount when a fraudster posing as its staff tricks a customer into paying, if the customer reports the fraud to the police and informs the PSP;
- make a PSP that fails to implement appropriate fraud-prevention mechanisms liable for its customers' losses;
- make online platforms liable to PSPs that reimbursed defrauded customers, if the platform was told of fraudulent content and did not remove it;
- oblige PSPs to share fraud-related information and to check that the payee's name and unique identifier match; the Parliament's release says a mismatched order would be refused.
The last point would reverse the current rule that a payee check must not prevent the payment. Until the Regulation is adopted and applies, Art. 5c(5) of Regulation 260/2012 governs.

## Q/A

### Unauthorised payments

### **Can the bank always keep €50 of an unauthorised payment?**

No. The €50 applies only where a lost, stolen or misappropriated instrument was used, and it falls to zero if the loss was not detectable, was caused by the PSP's own staff or outsourcee, or occurred after notification or without strong customer authentication (PSD2 Art. 74). The payer bears everything only for fraud, or for an intentional or grossly negligent breach of its duties. Bulgaria applies the same €50 ceiling; the UK equivalent is £35.

### **Can the bank refuse a refund by claiming I was grossly negligent?**

PSD2 Art. 73 allows only one ground for withholding the refund past the next business day: reasonable grounds to suspect fraud, communicated in writing to the national authority. The PSP carries the burden of proving gross negligence (Art. 72). In C-70/25 the Advocate General took the view that the refund comes first and the bank may try to recover the loss later; that opinion is not binding and the Court had not ruled as of 24 September 2026.

### **How long do I have to report an unauthorised payment?**

Without undue delay after becoming aware of it, and no later than 13 months after the debit (PSD2 Art. 71). In Veracash the Court held that late reporting can defeat the claim even inside 13 months; where a lost or stolen instrument was used, only intentional or grossly negligent delay does.

### Scams and Verification of Payee

### **Does Verification of Payee stop a payment to the wrong name?**

No. The payer's PSP must show the result before authorisation, but Art. 5c(5) of Regulation 260/2012 forbids the check from preventing the payer from authorising the transfer. A refusal on mismatch appears only in the pending Payment Services Regulation, as announced.

### **Who pays if I ignore a no-match warning and the payee turns out to be a fraudster?**

Usually the payer. A PSP that complied with Art. 5c is not liable under PSD2 Art. 88, although it must make reasonable efforts to recover the funds and, if that fails, give the payer the information needed for a legal claim. The PSP refunds only if its own failure to run the check led to a defective payment.

### **Do e-money institutions in the euro area already have to verify payees?**

Yes, if they already send instant euro transfers. Art. 5c(9) sets 9 October 2025 for all PSPs located in the euro area and does not distinguish banks from EMIs or payment institutions. The Commission services' non-binding Q&A, read with recital 28, ties that date to PSPs already offering instant euro transfers, so for an EMI not yet sending them the date is open to interpretation; its own instant-sending deadline is 9 April 2027. Bulgarian PSPs must offer the check by 1 January 2027 at the latest.

### UK and cross-border

### **Is an international transfer from a UK account covered by the APP reimbursement rules?**

No. The scheme covers Faster Payments and CHAPS payments sent and received by PSPs in the UK, made on or after 7 October 2024. International payments, and onward transfers over other systems such as crypto-asset platforms, are outside it.

### **Are company accounts protected in the same way?**

Only partly. In the UK the scheme covers microenterprises and charities besides consumers. In the EU, PSD2 Art. 61 allows a PSP and a non-consumer client to exclude the burden-of-proof and liability rules by contract, while the Art. 73 refund duty stays.

### **Will the EU adopt the UK reimbursement model?**

Not as a general rule. The Payment Services Regulation, as announced after the November 2025 agreement, would add a refund for scams by fraudsters posing as bank staff and liability for PSPs without adequate fraud prevention. It is not yet adopted, and until it applies the EU relies on Verification of Payee.

---

## Factual claims

- When money leaves an account through fraud, European payment law starts with one narrow question: did the account holder authorise the payment?
- Under PSD2 Art. 64 a payment is authorised only if the payer consented in the form agreed with its payment service provider (PSP); consent may also be given through the payee or a payment initiation service.
- The regimes below differ on who pays first, how much the payer keeps at risk and whether the rule is already law.
- Art. 74 grades the payer's exposure by what went wrong:
- The €50 figure is therefore a ceiling for the cases in the first row, not a charge the PSP may apply to every unauthorised payment.
- When a user denies authorising a payment, Art. 72 makes the PSP prove that it was authenticated, accurately recorded and not affected by a technical breakdown.
- For electronic money, Arts 73 and 74 apply unless the PSP cannot freeze the account holding the e-money or block the instrument (Art. 63(3)).
- Since 2025 the EU has answered with a check before the payment.

---

Source: wiki.private.law — the private.law legal knowledge base. When quoting, cite the canonical page URL.
Consultation with a lawyer: https://t.me/private_law_bot
