Banks Benefit from Digitalisation. Consumers Should Not Be Left to Insure Its Risks.
EFRI Briefing | Response to Simon Landuyt’s advisory opinion of 11 August 2026 to the Committee on Economy, Consumer Protection and Digitalisation of the Belgian Chamber of Representatives on bills DOC 56 1592/001, amendment DOC 56 1592/002 and DOC 56 0542/001 | Published 6th October 2026
Banks and their advisers still underestimate the scale of online fraud, and the threat it poses to society and to the financial sector itself. Treating fraud mainly as a question of how much financial pain consumers must bear to stay vigilant misses the larger problem: payment systems must be designed to withstand predictable human vulnerability.
Simon Landuyt (KU Leuven/UGent, Alba Advisors) has submitted a law-and-economics opinion to the Belgian Parliament on two bills that would strengthen bank liability for unauthorised payment transactions after phishing. One of them, the bill by Jeroen Soete (DOC 56 1592/001), would place the burden of proof on the bank and stop banks from relying on gross negligence to delay refunds. Landuyt’s opinion starts from a legitimate premise: liability should encourage effective fraud prevention. But his emphasis on consumer responsibility, his objections to unconditional immediate reimbursement and his proposal for mandatory account-linked insurance point policy in the wrong direction.
EFRI’s position is straightforward. Institutions that design payment services, control their safeguards and benefit from their efficiency should bear strong responsibility for preventing fraud and protecting victims. Consumer vigilance has a role. It cannot replace professional fraud prevention.
What Landuyt proposes
Landuyt’s opinion makes three arguments.
First, liability is a prevention tool, not a way to spread losses. He argues that hifting losses to a bank does not shift them to “the bank” but to its shareholders, employees and customers. Liability rules therefore redistribute imprecisely: the person who ends up paying may be the lowest-paid employee who is laid off, a young family facing a dearer mortgage or a pensioner earning less interest. Spreading losses, in his view, should be done through a separate instrument: insurance that is mandatory and automatically linked to every payment account. He suggests a cap of, for example, €100,000, aligned with deposit protection; cover that includes gross negligence, because ruin is no less serious when the victim was careless; and, for gross negligence, a deductible higher than the €50 in Article VII.44 of the Belgian Code of Economic Law (WER). An insurer, handling claims in series, could also enforce valid claims against banks more effectively than individual victims.
Second, liability should lie with the “cheapest cost avoider”. Sometimes this is the bank, which can roll out strong authentication, transaction monitoring and the IBAN-name check once for all customers. Sometimes it is the account holder, for example when they disclose their codes over the phone and the bank sees only a correctly authenticated transaction. Sometimes it is neither: where a fraudster spoofs the bank’s phone number, the telecom operator may be best placed to spot an external call carrying a Belgian number. The line of gross negligence and the specific prevention duties should follow this criterion, not the question of who can best bear the loss.
Third, “pay first, argue later” buys prevention at too high a price. Article VII.43 WER requires banks to refund unauthorised transactions immediately. Landuyt accepts that this removes the cost of claiming for victims and restores the bank’s prevention incentive. But it also removes a filter: under ordinary law, people with weak claims do not sue. He proposes alternatives: public enforcement of banks’ prevention duties, an accessible ombudsman that decides disputes up to a certain amount with binding effect, and a duty on banks to explain, in every rejection, how their fraud detection worked in that case.
Landuyt does not propose abolishing bank liability. He recognises the banks’ advantage in implementing security measures, supports a role for telecom operators and wants insurance to protect consumers even in cases of gross negligence. These are important qualifications, and several of his alternatives (binding ombudsman decisions, reasoned refusals) are proposals EFRI supports. Our disagreement concerns where his model places responsibility, costs and the burden of obtaining redress.
Digitalisation’s benefits and its risks belong together
Banks pursue digitalisation partly because it reduces operating costs and improves profitability. Automated processing and digital self-service reduce the need for branches and manual work. The European Banking Authority reports that automation, digitalisation and outsourcing are gaining traction as key cost-cutting strategies, as banks shift from income generation to expense management. In the same report, it ranks fraud, amplified by the use of AI in financial crime, as the second most significant operational risk for banks. Speaking in Amsterdam on 22 September 2026, Claudia Buch, Chair of the ECB’s Supervisory Board, noted that more than 80% of banks supervised by the ECB identify process automation as an important way of reducing costs, and that digital innovation also introduces new sources of risk, including fraud . Supervisors thus see both sides of the same development. Consumers gain convenience too, but that does not justify separating the providers’ commercial benefits from responsibility for security.
A payment service cannot be judged only by how cheaply and quickly it moves money. Its ability to prevent foreseeable misuse belongs in the calculation. Where fraud losses stay with victims, part of the service’s apparent efficiency may simply reflect costs borne outside the provider’s accounts.
Landuyt’s point that a bank is a “legal fiction” whose costs end up with employees and customers applies equally to his own proposal. A mandatory insurance premium attached to every payment account would also be paid by the low-income account holder, the young family and the pensioner, plus the insurer’s administration costs and profit margin.
The cheapest cost avoider is usually not the person making the last click
Landuyt’s own criterion, placing responsibility with whoever can prevent the harm at the lowest cost, requires a much fuller examination of the imbalance between institutions and individuals.
A customer has no visibility of a recipient account’s transaction history. They cannot identify suspicious patterns across thousands of accounts, investigate links between beneficiaries or redesign a bank’s authentication and payment processes. Banks and payment providers have, or can develop, capabilities that individuals cannot replicate. Their information is not unlimited, but their structural advantage is substantial.
The relevant comparison is therefore not between an alert customer and a bank observing an apparently authenticated payment. It is between the customer’s limited options and the preventive measures available across the whole payment chain.
The victim’s final click is not the beginning of the fraud. By the time a victim approves a transfer or discloses a code, other chances to stop the loss may already have been missed. The receiving account may have warranted scrutiny. The payment may depart from the customer’s normal behaviour. Multiple transactions may reveal a pattern invisible to the individual victim.
Landuyt’s analysis confines itself to the two parties that payment law places opposite each other: the payer’s bank and the account holder. The institution that opened and runs the receiving account is missing. In EFRI’s casework, that is often where the cheapest prevention lies. Money mules, shell companies and payment intermediaries need accounts, and only the receiving institution sees who opened them, how they are funded and where the money goes next. A framework that asks only whether the payer or the payer’s bank could have stopped the fraud leaves out the party with the best view of the fraud’s infrastructure.
None of this means a bank could have stopped every fraud. It means that identifying a mistake by the victim does not establish that the victim was the most efficient fraud preventer. That conclusion requires evidence about the entire sequence of events, including the receiving institution’s role.
Landuyt himself acknowledges that the empirical data needed to allocate responsibility accurately are usually missing: it is not known what share of fraudulent transactions banks could have stopped at reasonable cost, or what share account holders could have avoided with reasonable care. He also acknowledges that his method may underweight fairness, protection of the weaker party and trust in the financial sector. Those admissions should limit the confidence placed in assumptions about what consumers could reasonably have prevented.
The authorised-payment gap
Landuyt’s opinion deals mainly with unauthorised transactions. He accepts that the legal line between authorised and unauthorised payments says little about who could have prevented the fraud, but finds a rough economic logic in it: whoever made the payment was, on average, better placed to stop it, especially now that banks must check the payee’s name against the IBAN before a transfer is executed.
For investment fraud, that logic does not hold. EFRI’s research covering 1,750 victims of investment fraud in 20 countries, with documented losses of €62.5 million, shows how these victims are manipulated over weeks or months before they pay (Sixt, Restoring Trust in European Payment Rails, SSRN 2025). Name checks rarely help, because the networks use correctly named accounts held by mules, shell companies or payment intermediaries. In one case documented by EFRI, payments went to virtual IBANs opened in the victim’s own name: every name check returned a positive match, and each transfer looked like a payment to the victim’s own account
Under current law, these victims bear their losses in full. If the authorised/unauthorised distinction is economically weak, as Landuyt himself suggests, the larger problem is not that unauthorised-payment victims are refunded too easily. It is that authorised-payment victims are not refunded at all.
What the UK evidence shows
The UK experience deserves particular attention. In its initial assessment of the reimbursement requirement, the Payment Systems Regulator reported no evidence of increased first-party fraud, that is, fraud committed by claimants themselves. Its monitoring covering the period to 31 March 2026 found no indication that consumers had become significantly less cautious; in the first quarter of 2026, around 2% of claims were rejected for lack of caution, the lowest share since the policy began. These findings do not establish that abuse never occurs. They do challenge the assumption that stronger reimbursement protection inevitably produces careless customers.
The British framework concerns authorised push payment (APP) scams and is not identical to the unauthorised-payment rules Landuyt mainly examines. It also contains limits and exceptions. It should therefore not be presented as proof that every form of unconditional reimbursement will succeed. It is nevertheless directly relevant to his broader concerns about consumer behaviour.
The independent evaluation commissioned by the PSR adds a further challenge. Frontier Economics reports that APP fraud losses sent over Faster Payments fell by around 21%, an estimated £73 million a year, after the reimbursement requirement took effect, and that reimbursement rates rose from 54% to 65%. Payment providers strengthened controls on both outgoing and incoming payments. The evaluation concluded that benefits likely exceeded costs in the first year, while noting uneven consumer outcomes across providers, the risk of fraud moving to channels outside the requirement, and uncertainty about longer-term effects . EFRI analysed these results in Payment Fraud: Britain’s Bank-Refund Rule Works.
That evidence supports a central argument for liability: making fraud financially consequential for providers encourages investment in prevention, including on the receiving side.
Mandatory insurance: who pays?
Landuyt proposes automatic insurance linked to payment accounts, potentially covering losses up to €100,000, including gross negligence but with a higher deductible. An insurer could also pursue valid claims against banks more effectively than an individual victim.
Those features may improve protection. They do not settle whether this is the right way to finance it.
In Landuyt’s model, the premium is meant to reflect the risks the account holder chooses to take, so customers would fund it. They would pay to cover losses allocated to them by the liability rules, plus insurance administration costs and profit margins. Deductibles would leave part of the loss with the victim. Landuyt himself acknowledges that these additional costs could make insurance more expensive overall than spreading losses through bank liability.
Before imposing such a scheme, policymakers should require evidence that it improves both prevention and protection compared with stronger provider responsibility. Insurance can supplement an effective liability framework. It should not become a reason to weaken one, or require customers to buy protection against risks they have little ability to control.
The argument that banks pass liability costs on through prices does not resolve this. Passing on costs does not remove the incentive to reduce them: a provider that prevents fraud reduces its exposure. Nor should complete pass-through be treated as inevitable without considering competition, pricing and the scope for better prevention.
The cost of claiming is not a neutral filter
Landuyt recognises that the cost of pursuing a claim prevents some victims from enforcing valid rights. He also treats that cost as a useful filter against unfounded claims.
For victims, the same filter excludes people who lack the money, information or resilience to contest a bank’s refusal. A right too costly to enforce offers little practical protection. Accessible dispute resolution and properly reasoned bank decisions are valuable proposals. Their existence does not, by itself, establish that victims should finance the loss while liability is disputed.
There is also a legal constraint that Landuyt deliberately leaves aside. Article VII.43 WER transposes the immediate-refund obligation in Article 73 of the Payment Services Directive (PSD2). In Case C-70/25 (Tukowiecka), Advocate General Rantos concluded on 5 March 2026 that a bank may not suspend the refund by alleging gross negligence; it must refund first and may then seek recovery if it can prove gross negligence or fraud. The Court’s judgment is pending. A national legislator that wants to replace “pay first, argue later” would have to reckon with that framework.
The full cost of fraud
The assessment must also extend beyond the amount transferred. Fraud undermines financial security, disrupts families and damages trust in digital services and democracy. A payment system that leaves victims financially exposed weakens the trust on which its continued use depends. These effects belong in the economic assessment, even when they are hard to quantify.
Our Assessment
Landuyt’s opinion is a serious contribution, and it shares more with EFRI’s position than its headline proposals suggest: telecom operators should carry responsibility where they enable fraud, banks should explain their refusals, and disputes should be resolved quickly and cheaply. But the model it builds on rests on three assumptions that do not survive contact with the fraud EFRI sees every day.
First, it treats the payment as a two-party relationship between the payer and the payer’s bank. In investment fraud, the decisive failures usually occur on the receiving side, at the institutions that open, run and fail to monitor the accounts into which victims’ money flows. Any serious cheapest-cost-avoider analysis has to include them. That is the core of EFRI’s work: the intermediary is the pressure point.
Second, it assumes that the account holder who makes a payment was, on average, better placed to stop it. For victims who have been groomed for months, paying into correctly named accounts or into accounts opened in their own name, the opposite is true. Payee name checks give these victims false reassurance, not protection.
Third, it treats mandatory insurance as a neutral way to spread losses. In practice it would ask consumers to pay premiums, deductibles and insurers’ margins for risks that are created and controlled further up the payment chain, while weakening pressure on the institutions best placed to prevent them.
EFRI therefore advocates strong provider incentives to prevent fraud, responsibility shared across the payment chain including receiving institutions, accessible redress with binding dispute resolution, and prompt reimbursement within a clearly defined framework, including for authorised payments induced by fraud. Telecommunications companies and online platforms should also be responsible where their conduct or controls contribute to fraud. Allocating responsibility among professional actors is their task; it should not leave victims navigating a maze of institutions to recover their money.
Banks cannot sustainably capture the benefits of digitalisation while treating its foreseeable fraud risks primarily as a consumer problem. Secure payments must be part of the service.
Elfriede Sixt, EFRI







