PSD2 asked whether a payment was authenticated. The Payment Services Regulation asks something harder: who carries the loss when a customer is manipulated into paying? Article 59 puts the reimbursement burden, and the burden of proof, on the PSP. Here is what the final text requires and what PSPs should be doing now.

Finvisor Fintech Partners, May 2026.
Fraud may end up being the most consequential part of the new EU payments package. That might sound odd when much of the market discussion has focused on open banking, access to payment systems, instant payments and the structural split between the Third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR). But the fraud provisions go to something more fundamental: who carries the loss when a customer is manipulated into making a payment?
That question was never fully resolved by PSD2. PSD2 did a great deal. It made Strong Customer Authentication central, improved the legal framework for unauthorised transactions and gave the market a clearer security baseline. But it was designed around a fraud environment where the main regulatory question was whether the customer's credentials had been compromised and whether the payment was properly authenticated. That is no longer where most of the risk sits.
Today, much of payment fraud does not involve a criminal breaking into an account. It involves persuading the customer to make the payment themselves. Fake bank calls, spoofed SMS messages, malicious adverts, investment scams, cloned payment journeys. The fraudster does not always need to defeat authentication. They need to defeat the customer. The European Banking Authority has noted that fraudsters have shifted away from stealing credentials and towards inducing undue payments directly.
The real change is not simply that the PSR introduces new fraud rules. It is that the PSR alters the lens through which fraud claims are assessed. Under PSD2, firms could often begin from the position that if the payment was authenticated and technically executed correctly, the customer faced a difficult path to reimbursement unless the transaction was unauthorised or the PSP had failed a specific obligation. The PSR makes that position considerably less comfortable.
Article 59 is the clearest example. Where a consumer is the victim of impersonation fraud, specifically a fraudster impersonating the PSP itself rather than merely an employee, and this induces the customer to authorise a payment, the PSP is required to refund the full amount. The conditions are that the customer has reported the fraud to the police and notified their PSP without undue delay. The final compromise text settled on impersonation of the PSP as an institution; Parliament's attempt to extend liability to impersonation of any entity, including police or tax authorities, did not survive the trilogue. The PSP has 15 business days from notification and receipt of the police report to refund, or to refuse with reasons where there are objectively justified grounds to suspect fraud or gross negligence by the consumer.
Article 59 also creates a second, distinct liability trigger. Where fraud occurs because the PSP failed to implement verification of payee correctly, did not conduct the required transaction monitoring, or failed to block a payment it had grounds to flag as suspicious, the PSP is liable for the resulting loss. These are failures within the PSP's own control, and the PSR treats them with the same directness as the impersonation scenario.
Taken together, Article 59 positions the PSP close to the centre of the reimbursement framework even where the fraud originated largely outside its systems. A spoofed phone number is not controlled by the PSP. A fake advertisement may sit on a third-party platform. And yet the PSP carries the primary reimbursement obligation. That is a deliberate policy choice. It reflects a view that the PSP is not merely a processor of payment instructions but the trusted interface through which the consumer participates in the payment system.
Recital 82 sets out the framework for assessing gross negligence, and it does so in a way that places the PSP's own conduct squarely within the analysis. Gross negligence requires a significant degree of carelessness. It is not established simply because the customer clicked a link, ignored a general scam warning or authorised the payment. All individual circumstances must be considered. The examples in the final text include acting on guidance from an unfamiliar third party, persuading the PSP to lift a block placed after a fraud alert, keeping credentials beside the payment instrument in an easily detectable form, and giving an unblocked device to a third party. A consumer who has already been reimbursed for impersonation fraud and falls victim to the same fraud type again may, depending on the circumstances, be found to have shown the requisite carelessness.
This is a materially different test from the one many firms have historically applied. Was the warning specific to the payment being made, or a generic pop-up? Was the intervention timed to the actual risk, or buried elsewhere in the customer journey? Was there a vulnerability indicator on the account? There is a significant difference between a warning that says "beware of scams" and one that says "this payment has characteristics consistent with impersonation fraud: your bank will never ask you to move money to a safe account".
The burden of proof sits with the PSP. To refuse reimbursement on the basis of consumer fraud or gross negligence, the PSP must demonstrate it, and must first invite the consumer to provide information about the events leading up to the payment and incorporate that information in the assessment.
It will not be sufficient to produce Strong Customer Authentication logs confirming that the customer approved the payment. Firms will need to reconstruct the wider picture: the risk indicators present at the time, the customer journey, the fraud warning displayed, the timing and nature of any intervention, the customer's response, any vulnerability indicators, the payment pattern, payee risk intelligence and the reasoning behind the reimbursement decision. Fraud decisioning becomes an evidential discipline.
The Instant Payments Regulation adds a further layer. Funds must be available in the payee's account within ten seconds of initiation, and verification of payee is expected to occur before that window begins. Fraud controls therefore cannot rely on a slow, post-event investigation; by the time it concludes, the mule account may already have been emptied. Verification of payee, transaction monitoring, behavioural analytics, channel controls, payment limits, mule-account intelligence, risk-based friction, vulnerability flagging, bespoke warnings and clear audit trails must all move upstream. The PSR increases liability and evidence pressure; the IPR compresses the time available to act on either.
The PSR recognises that PSPs do not control the entire fraud chain. Online platforms are liable to PSPs who have reimbursed defrauded customers where the platform was notified of fraudulent content and failed to remove it, and electronic communications providers carry a cooperation obligation. Both build on the Digital Services Act. That is the right direction, but PSPs should not take too much comfort from it. The PSP remains the party with the primary reimbursement obligation to the consumer. Recourse against a platform or telecoms provider comes after.
On 23 April 2026 the Council of the EU published the final compromise texts for PSD3 and the PSR, recommending COREPER approval with a view to second-reading agreement with the European Parliament. Formal adoption votes, signature and publication in the Official Journal remain outstanding. The PSR will enter into force 20 days after publication and apply directly across all Member States 21 months later, with the verification of payee provisions under Articles 50 and 57 applying at 27 months. PSD3 requires national transposition within 21 months of entry into force. Substantive application lands broadly in 2028. The final legal text is public; implementation planning should be under way.
The work spans fraud governance, customer journey design, payment initiation controls, warning design and timing, reimbursement decision frameworks, fraud typology monitoring, vulnerability processes, complaint handling, evidence retention, management information and board reporting. This is not a compliance project with a narrow deliverable. It is an operating model question. The test is not whether the firm has fraud controls; every PSP has some. It is whether those controls are specific enough, timely enough and evidenced well enough to withstand scrutiny when a customer has been manipulated into authorising a payment and the PSP has to justify why it is not refunding them.
Finvisor works with payment firms, EMIs and crypto-asset businesses on fraud governance frameworks, PSR gap analysis, reimbursement decision frameworks, customer warning design, evidence standards and implementation planning. See how we support payment and e-money firms, or contact Michelle McGuire, Povilas Randis or Simon McFeely at info@finvisor.global.
We use strictly necessary cookies to run this site, and optional analytics cookies (Google Analytics) to understand how it is used. Analytics cookies are only set if you accept them. See our Cookie Policy and Privacy Policy.