Skip to content

FinTech and the office of the CFO

Subscribe

Liability for authorised push payment fraud, by market

Compare authorised push payment fraud liability across major markets, including who reimburses victims and how responsibility is allocated.

Liability for authorised push payment fraud, by market

One market has a hard reimbursement rule. The rest have frameworks, proposals and litigation. The differences are large enough to change where you launch.

Position as at 30 July 2026. Note that Singapore's framework covers a defined scope of phishing scams rather than authorised push payment fraud generally.

Authorised push payment fraud is the category where the payment is genuine. The customer initiated it, the authentication succeeded, and the money went where the customer told it to go. Everything about the transaction is correct except the reason for it. That is why controls designed to detect unauthorised transactions perform poorly against it, and it is why the question of who bears the loss has had to be answered by regulation rather than by contract.

Six markets have now answered it, or started to, and they have not converged. If you operate across them, the liability position is not a single policy.

United Kingdom: the only hard rule, and the first evidence on whether it worked

The Payment Systems Regulator's mandatory reimbursement requirement took effect on 7 October 2024 for Faster Payments and CHAPS. The maximum reimbursement is GBP 85,000 per claim, confirmed in policy statement PS24/7. The cost is split 50/50 between the sending and receiving payment service provider. Firms may apply an excess of up to GBP 100, which cannot be applied to vulnerable customers, and reimbursement is due within five business days of a claim.

On 1 July 2026 the PSR published an independent evaluation by Frontier Economics, and it is the first real evidence in this area rather than argument. Losses to authorised push payment fraud are estimated to have fallen by GBP 73 million a year, with scam volumes down by nearly 35,000. The reimbursement rate across all claims rose from 54 to 65 per cent, and for in-scope claims firms now reimburse 97 per cent. The short-term net benefit is put at GBP 17 million to GBP 29 million a year, which Frontier describes as conservative.

The evaluation found no evidence of the two consequences the industry warned about most loudly: no market exits, and no measurable increase in reckless consumer behaviour.

Two UK datasets are routinely compared and should not be. Frontier measures by scam transaction date. UK Finance measures by claim closure date and covers all authorised push payment losses, including those outside the reimbursement scope.

One institutional change is worth tracking. HM Treasury confirmed in April 2026 that the PSR will be folded into the Financial Conduct Authority, with the Financial Services and Markets Bill 2026-27 introduced on 19 May 2026. The PSR retains full statutory powers until that legislation passes, and a consultation on consistency of application is expected before the end of 2026.

European Union: agreed, and not yet law

PSD3 and the Payment Services Regulation reached provisional political agreement between Parliament and Council on 27 November 2025, and the Council published final compromise texts in April 2026. As at 30 July 2026 neither instrument has been adopted or published in the Official Journal. Formal adoption is expected in the second half of 2026.

On the reported timing mechanics, PSD3 transposition runs twenty-one months from entry into force, and the Payment Services Regulation applies directly from the same date, except the verification of payee articles, which apply at twenty-seven months.

As proposed in the compromise texts, where a fraudster impersonates the payment service provider and the customer promptly reports to the police and to the provider, the provider must refund in full with no upper cap. Liability attaches where the provider failed to implement verification of payee, failed to monitor, or failed to block a suspicious payment. Online platforms become liable to refunding banks where the platform was notified of fraudulent content and did not remove it.

That last provision is the structurally novel one, because it is the first attempt to place part of the cost on the channel where most of these scams begin rather than on the rail where they end. It should be described as proposed until the text is in the Official Journal.

Australia: preventive duties, not a reimbursement percentage

The Scams Prevention Framework Act 2025 commenced on 21 February 2025, but it is a framework and obligations bite through sector designations, rules and codes. The designation instrument covering banking, telecommunications and specified digital platform services was registered on 28 May 2026, along with an external dispute resolution authorisation. Treasury released draft rules and sector codes the same day.

The commencement point matters and is widely misreported. The codes commence on the later of 31 March 2027 and the day after registration, with the rules proposed to commence on 1 September 2026. Several secondary sources have said banks must comply by mid-2026. The registered instruments do not support that.

Australia's model is preventive obligations plus external dispute resolution, enforced by the ACCC generally and ASIC for banks, with reported civil penalties of up to A$50 million per contravention and a private right of action. It does not create a UK-style reimbursement percentage or cap.

Singapore: a waterfall, and a narrower scope than usually described

The Shared Responsibility Framework was implemented on 16 December 2024. Its scope is a defined set of phishing scams, meaning unauthorised transactions where a scammer impersonates an entity. It is not a general authorised push payment reimbursement regime, and describing it as one is a factual error that appears frequently.

Within that scope the allocation is a waterfall. The financial institution bears the loss if it breached its duties. If the institution complied, the telecommunications operator bears it if the telco breached its duties. If both complied, the consumer bears the loss and no payout is due under the framework, though the consumer retains recourse to the dispute resolution centre and the courts. There is no cap, and the regulators confirmed they would not introduce one.

A real-time fraud surveillance duty took effect on 16 June 2025 after a six-month transition. The trigger is defined precisely: an account rapidly drained of a material sum, where the balance immediately before the unauthorised transaction was SGD 50,000 or more and more than half was transferred out within twenty-four hours. On trigger, the institution must block until it reaches the customer for positive confirmation, or notify and hold for twenty-four hours.

United States: no federal reimbursement right, and the action moved to the states

The Electronic Fund Transfer Act and Regulation E cover unauthorised electronic fund transfers. A transfer the consumer initiated themselves, however they were deceived into it, is authorised, and therefore falls outside the error-resolution and liability-limitation provisions. There is no federal reimbursement right for this category.

The Consumer Financial Protection Bureau sued Early Warning Services and three large banks in December 2024, seeking reimbursement for induced fraud among other relief, and dismissed the suit in March 2025. State enforcement filled the space. On 20 July 2026 the New York Supreme Court allowed the New York Attorney General's suit against Early Warning Services to proceed to trial, with alleged consumer losses exceeding $1 billion.

The practical consequence for a US institution is that the liability position is currently set by state litigation risk and by voluntary policy, not by a federal rule.

India: the current rule covers unauthorised transactions, and a revision is out

The operative instrument is the Reserve Bank of India circular of 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions, which provides zero liability for third-party breach where the customer reports promptly, graded limited liability for delayed reporting, and places the onus on the bank to prove customer negligence. It addresses unauthorised transactions. There is no Indian equivalent of the UK reimbursement requirement for authorised scam payments.

The RBI issued revised instructions for public consultation on 6 March 2026, including a compensation mechanism for small-value fraudulent electronic banking transactions. It is a draft. Alongside it, the Indian Digital Payment Intelligence Corporation was incorporated on 16 October 2025 and the MuleHunter.AI tool is live in 26 banks, which is a supply-side attack on mule accounts rather than a liability rule.

What this means if you operate across markets

  • Your liability exposure is not a single number and cannot be provisioned as one. In the UK it is capped and shared. In Singapore it is uncapped and conditional on your own compliance. In the US it is currently litigation risk.

  • In two markets the determinant is whether you implemented specific controls: payee verification, monitoring, and blocking. Evidence that you did is the asset.

  • Three of the six positions are unsettled. The EU package is agreed but not adopted, Australia's codes commence in 2027, and India's revision is in consultation. Treat none of them as current obligations.

  • Where the framework is preventive rather than compensatory, as in Australia, the cost lands on control build rather than on reimbursement provisions. Both are real costs, and they hit different budget lines.

This is reporting on regulation as it stood at the date of publication. It is not legal or compliance advice, and obligations differ by jurisdiction and change. Take qualified advice on your own circumstances.

References

Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.

  1. Payment Systems Regulator, PS24/7, confirming the maximum level of reimbursement. https://www.psr.org.uk/publications/policy-statements/ps247-faster-payments-app-scams-reimbursement-requirement-confirming-the-maximum-level-of-reimbursement/

  2. Payment Systems Regulator, PS25/5, APP scams reimbursement consolidated policy statement, May 2025. https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf

  3. Payment Systems Regulator, Payment fraud falls by GBP 73m following reimbursement scheme, independent evaluation by Frontier Economics, 1 July 2026. https://www.psr.org.uk/news-and-updates/latest-news/news/payment-fraud-falls-by-73m-following-psr-reimbursement-scheme/

  4. Frontier Economics, APP payment scam policies reducing fraud, 2026. https://www.frontier-economics.com/uk/en/news-and-insights/news/news-article-i22383-app-payment-scam-policies-reducing-fraud/

  5. Council of the European Union, via A&L Goodbody, PSD3 and PSR final compromise texts published, April 2026. https://www.algoodbody.com/insights-publications/psd-3-psr-final-compromise-texts-published

  6. Federal Register of Legislation, Australia, Competition and Consumer (Scams Prevention Framework, Regulated Sectors) Designation 2026, registered 28 May 2026. https://www.legislation.gov.au/F2026L00627/asmade/text

  7. Monetary Authority of Singapore and IMDA, Implementation of the Shared Responsibility Framework from 16 December 2024, 24 October 2024. https://www.mas.gov.sg/news/media-releases/2024/mas-and-imda-announce-implementation-of-shared-responsibility-framework-from-16-december-2024

  8. Monetary Authority of Singapore, Guidelines on the Shared Responsibility Framework. https://www.mas.gov.sg/regulation/guidelines/guidelines-on-shared-responsibility-framework

  9. Reuters, reported via TradingView, Zelle must face New York Attorney General lawsuit, judge rules, 20 July 2026. https://www.tradingview.com/news/reuters.com,2026:newsml_L6N43O10A:0-zelle-must-face-new-york-attorney-general-lawsuit-over-rampant-fraud-judge-rules/

  10. Press Information Bureau, Government of India, Reply on the review of customer liability instructions and the compensation mechanism consultation, 24 March 2026. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2244478

  11. UK Finance, Annual Fraud Report 2026, 15 June 2026. https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2026-press-release

How we work. This article was researched and written by the Financy editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@financyhub.com and tell us what and why.

Filed under Fraud, Risk & Financial Crime · Get The Weekly Brief

The briefing

Keep reading the stack.

One email a week on financial technology and the finance stack.