Payment Fraud: Britain's Bank-Refund Rule Works
The first independent evaluation of the UK’s mandatory payment fraud reimbursement scheme is in and it validates the case EFRI has made for years. Forcing banks to refund scam victims cut authorised push payment (APP) fraud on the covered rails by around a fifth, lifted victim reimbursement to a clear majority, and triggered none of the disasters the industry predicted. It is important evidence for the EU’s PSD3 and Payment Services Regulation (PSR) debate and a verdict on the far weaker deal Brussels agreed in November 2025.
The UK made payment fraud reimbursement mandatory — and measured it
Since 7 October 2024, the United Kingdom has run one of the world’s most far-reaching consumer-protection rules in payments. If you are deceived into authorising a bank transfer to a criminal, a form of fraud known as authorised push payment, or APP-fraud, your bank must generally reimburse you up to £85,000. The cost is split 50/50 between the sending and the receiving institution. The rule was designed by the Payment Systems Regulator (PSR).
The rule covers eligible domestic UK bank transfers made through Faster Payments and CHAPS. It generally does not cover the full loss where the initial transfer is made to another account controlled by the victim — including the victim’s own account at a crypto exchange — and the funds are only subsequently transferred to the fraudster. In such cases, the actual loss may occur outside the payment systems and legal definition covered by the scheme. As a result, many crypto-investment losses remain outside its protection.
Before it took effect, the industry’s warnings were loud and unanimous. Mandatory reimbursement would create “moral hazard,” making consumers reckless. Smaller payment firms would buckle. Instant payments would grind to a halt. Providers would quit the market.
In July 2026, the PSR published the first full independent evaluation carried out by consultancy Frontier Economics. The headline, in the words of Forbes contributor Zennon Kapron: the sky did not fall.
What payment fraud reimbursement actually delivered
On the rails the rule covers, the effect is measurable. Frontier estimated that annual APP fraud losses over Faster Payments were around £73 million lower than they would otherwise have been, representing a reduction of approximately 21% attributable to the policy. Frontier also attributed nearly 35,000 fewer APP scam payments a year to the reimbursement policy.
Victims are also being made whole far more often. The share of APP scam losses reimbursed rose from 54% before the policy to 65% after — an estimated £39 million a year going back to victims who would previously have borne the loss. For claims falling within the mandatory scheme, the PSR reports that firms are now reimbursing 97%. The £85,000 cap is generous enough to cover more than 99% of claims and more than 95% of the value at stake.
According to UK Finance, banks returned £354.3 million to APP fraud victims in 2025, 61% of all APP losses. UK Finance’s data covers a broader range of payments and account types than the mandatory PSR scheme, so that figure should not be treated as the amount paid solely under the new reimbursement rule.
And the predicted catastrophes never arrived. Even on the numbers, they collapse: claims rejected because the customer ignored a warning account for just around 3% of APP scam value (4% by volume), and confirmed first-party (self-)fraud for 0.5% of value and 0.2% by volume. The “moral hazard” that dominated the pre-launch debate is, empirically, a rounding error. No evidence emerged of consumers behaving recklessly, and after prevention and compliance costs of £44–56 million a year, the scheme still delivered a net short-term benefit of £17–29 million.
UK fraud is still rising — which makes the result matter more, not less
Here is the context that turns this from a niche regulatory story into a warning for Europe. Total payment fraud in Britain is not falling, it is climbing. UK Finance reported total fraud losses of £1.28 billion in 2025 (up 4%) across 3.81 million cases (up 11%). Overall APP fraud losses rose 19% to £576.4 million, driven above all by investment fraud, up a startling 40% to £221.5 million.
Artificial intelligence is likely to be an important accelerant of that development, although the available figures do not justify attributing the entire increase in APP fraud to AI alone. AI-generated deepfakes, synthetic content and automated social engineering make scams cheaper to scale and harder to distinguish from legitimate communications. Together with the continuing abuse of social-media platforms, telecommunications and increasingly sophisticated criminal networks, these technologies are industrialising fraud at a scale that traditional controls struggle to contain.
So the two figures are not in conflict; they are the whole story. Frontier evaluated APP scams on the domestic payment rails covered by the reimbursement policy. UK Finance measures a broader universe of fraud, including scam types and payment routes outside that perimeter. On the domestic Faster Payments rails the rule governs, APP scam losses were around 21% lower than they would otherwise have been. Across channels it does not fully govern, fraud continued to climb.
The reimbursement duty did not stop AI, online platforms or international criminal networks from driving fraud upwards. What it did was act as a brake within its regulatory perimeter. Without the rule, Frontier estimates that covered losses would have been higher and substantially more of the resulting financial damage would have remained with victims.
The scheme does not necessarily recover money from the criminals. It changes who bears the loss when the criminal proceeds can no longer be recovered: the victim or the institutions controlling the payment rails. The tool works exactly where it can reach and exposes, just as clearly, what a bank-only rule cannot.
The proof that fraud simply moves to the rails the rule can't reach
The evaluation puts hard numbers on that gap, and they are among the most important figures in the report for European policymakers. As domestic APP scams on covered rails fell, fraud increasingly appeared on channels outside the scheme’s scope:
- APP scam losses associated with payments to crypto exchanges rose, indicatively, from around £59 million in 2023 to around £153 million in 2025, a near-tripling.
- International APP scams rose from £21 million in 2023 to £60 million in 2025.
The parallel movement is strong evidence of displacement, although the available data cannot establish that every increase outside the scheme was caused by criminals responding to the reimbursement rule. At a minimum, the figures show that fraud is increasingly being structured through routes the domestic scheme cannot fully reach.
The UK rule covers eligible domestic UK bank-to-bank transfers via Faster Payments and CHAPS. It generally does not cover the ultimate loss where a victim first transfers money to an account held in the victim’s own name and only subsequently loses control of the funds outside the covered payment system.
That is the exact route many crypto-investment scams follow. Victims are coached to move money into their own exchange account or wallet before transferring cryptoassets to a wallet controlled by the criminal. The initial bank transfer may therefore be treated as a transfer between accounts controlled by the victim, while the actual loss occurs later, often on-chain.
A rule anchored only at the sending bank cannot follow the money once it leaves the covered banking rails. The criminals have already found the door it leaves open.
Why it works: liability changes prevention incentives
Where the rule does reach, the mechanism is clear. The decisive design choice is the 50/50 split. By making the receiving bank — the institution hosting the criminal “mule” accounts — liable for half the loss, the rule finally gives it a financial reason to detect and shut those accounts. Frontier confirms the logic: the policy “creates a stronger financial incentive for all PSPs to identify and prevent mule activity, as receiving PSPs become liable for a share of reimbursable APP scam losses.” It is the same point EFRI has made repeatedly — that Europe’s core problem is a structural imbalance in liability, with customers bearing the loss in 79% of fraudulent credit-transfer cases. Liability is not only a compensation mechanism; it is the most effective prevention mechanism there is.
The honest limits — and why they prove EFRI's whole-chain case
A serious case does not hide the weaknesses, and Frontier names three. Each validates EFRI’s argument rather than undermining it.
First, an awareness gap: only 24% of consumers know the protection exists, and only about half of APP scam victims ever seek reimbursement. A right the public cannot see delivers a fraction of its value.
Second, a reimbursement lottery: outcomes still depend heavily on which bank the victim banks with. Reimbursement rates ranged from 21% to 94% between payment companies: from 48–94% among payment companies already signed up to the old voluntary code, down to 21–45% among those that were not. Without a common standard and real enforcement, justice is postcode-and-provider dependent.
The mandatory scheme has substantially reduced that disparity, but differences in claim handling, consumer awareness and access to redress remain relevant and require continued supervision.
Third — and most important for Europe — displacement, quantified above: fraud fleeing to crypto, international and first-party routes, and originating upstream on the social-media and search platforms where victims are recruited. This is the heart of EFRI’s evidence base: across 1,750 documented victim cases in 20 countries totalling €62.5 million, the typical target is a 50-to-70-year-old conservative saver, reached through advertising on social media or search engines — the actors a bank-only rule leaves entirely off the hook.
What the PSR plans next: naming the platforms, not just the banks
The naming-and-shaming approach sits also at the centre of the PSR’s strategy. The regulator publishes payment company-level APP scam performance data that names individual PSPs, ranking which reimburse victims most and least and which host the most mule accounts, and the resulting reputational pressure has pushed weaker performers to improve.
Since December 2024 it has aimed the same transparency at the source of the problem: its first “fraud enabler” report identified where scams begin, linking Meta’s platforms (Facebook, Instagram, WhatsApp) to 54% of scam cases and telecom channels to 12% of cases but 31.5% of the losses. Following the July 2026 evaluation, the PSR (now being consolidated into the Financial Conduct Authority), intends to go further still, publishing fuller platform-level data on where scams originate by the end of 2026 and pushing the liability debate onto the social-media, search and telecom firms themselves.
The EU chose the weakest version of APP fraud reform
EU legislators reached a provisional political agreement on the PSD3 and PSR package on 27 November 2025. The agreement improves some elements of the existing payment-services framework, but its dedicated reimbursement duty covers one exceptionally narrow form of APP fraud: cases in which a criminal impersonates the victim’s own payment service provider.
It leaves out the very fraud types now driving the UK’s numbers: fake investment platforms, boiler rooms, pig-butchering and romance scams. Those payments will generally remain classified as “authorised,” even though the victim’s consent was obtained through deception, and will not benefit from an equivalent outcome-based reimbursement right.
The package contains additional fraud-prevention duties, and PSPs may incur liability where they fail to comply with them. Those provisions are relevant, but they are not a substitute for a general APP-fraud reimbursement right. They require the victim to establish a particular regulatory failure instead of focusing on the fact that the payment was induced by fraud.
Two further weaknesses deepen the gap. The platform-accountability provision is narrowly derivative: it activates only after a PSP has reimbursed the victim and where the platform failed to remove fraudulent content after receiving notice. Where mandatory reimbursement does not apply, the PSP may have no reimbursed loss to recover from the platform. Platform liability will therefore rarely assist victims of investment or romance scams.
The agreed rules on gross negligence also require close scrutiny once the final consolidated text is available. Under PSD2, unauthorised transactions were generally subject to rapid reimbursement unless the PSP had reasonable grounds to suspect fraud, with the evidential burden resting on the PSP. Any new rule allowing reimbursement to be withheld merely on the basis of an untested allegation of gross negligence would risk turning an exceptional defence into a routine mass-rejection mechanism. Suspicion alone must not be enough.
A shared-liability framework for European payment fraud
The alternative is already written. In Restoring Trust in European Payment Rails: A Framework for a Shared Liability Reform (SSRN, September 2025), EFRI chairwoman Elfriede Sixt sets out the model the British data now supports: reclassify deception-induced payments so they are no longer treated as freely “authorised”; establish an outcome-based reimbursement right for all APP fraud, anchored at the payer’s own bank; and extend shared liability across the entire chain, sending and receiving banks, acquirers, telecoms and platforms alike — backed by an EU-wide dispute-resolution body (FIN-NET 2.0), a Union fraud-data framework, and concrete technology duties such as real-time analytics and transaction “kill switches.”
Britain supplies the missing proof. Its numbers show mandatory reimbursement works and pays victims. Its documented weaknesses, the near-tripling of crypto scam losses, the flight to international rails, the platform-borne investment-scam surge, are exactly the gaps Sixt’s whole-chain liability is built to close.
The bottom line for PSD3 and the PSR
The message to European legislators is uncomfortable but firmly evidenced: one of Europe’s most significant real-world tests of mandatory APP fraud reimbursement and the principal warnings examined by the independent evaluation did not materialise.
Payment fraud reimbursement worked where it reached, victims were paid at scale, and Frontier found no evidence of policy-induced market exits, all while fraud continued to evolve and overall APP losses reached record levels.
To confine a dedicated APP-fraud reimbursement right to PSP-impersonation cases, and to leave most crypto and platform-borne scams outside an equivalent protection framework, is not caution. It is a decision to walk away from a proven result and to leave the door identified by the UK standing wide open.
Britain has shown that the sky holds. It is now for Brussels, as the provisional PSD3 and PSR agreement is legally finalised and subsequently implemented, to take the whole step, not half of it.




