The EU Has Repriced Payment Fraud, and the Bill Lands in the Boardroom

In 2024, payment service users absorbed approximately 85% of credit-transfer fraud losses in the European Economic Area. The figure reflects a persistent challenge in authorized-payment scams: customers can be manipulated into initiating a transfer even when the payment is technically authenticated.

That allocation of loss is now changing. The political agreement on the Payment Services Regulation (PSR) and the Third Payment Services Directive (PSD3), reached by the European Parliament and EU member states on November 27, 2025, shifts more of the fraud risk toward payment service providers in certain circumstances. 

Where a provider fails to implement appropriate fraud-prevention mechanisms, it can be liable for resulting customer losses; the agreement also creates reimbursement protections in specified impersonation-fraud cases and extends potential liability to online platforms that fail to remove notified fraudulent content. The European Parliament’s summary of the agreement sets out those changes.

This is not blanket reimbursement for every authorized payment scam. Nor should it be read as a distant compliance exercise. The agreement points toward a fundamental repricing of fraud: providers’ future exposure will increasingly depend on the prevention controls they implement, the evidence they retain, and their ability to show how they acted when a payment became suspicious.

Why Fraud Has Become a Board Matter

The EBA and ECB recorded €4.2 billion in payment fraud across the EEA in 2024, up from €3.5 billion in 2023 — a 17% increase in one year. Credit-transfer fraud accounted for €2.2 billion, while card fraud accounted for €1.3 billion. The headline number captures direct reported losses; it does not represent the additional operational burden of investigation, customer remediation, dispute handling, recovery efforts, and new control requirements.

Until now, customers have borne a substantial portion of the loss from authorized credit-transfer scams. The new framework starts to move that exposure toward payment providers where statutory reimbursement rules apply or required prevention controls are absent. A growing fraud-loss line, broader refund obligations, and greater scrutiny of prevention effectiveness create an exposure that deserves the same executive attention as other material balance-sheet risks.

That does not mean fraud should be treated the same as credit risk. It does mean boards should give it similarly disciplined governance: a defined risk appetite, transparent loss reporting, stress scenarios, a named accountable executive, and clear evidence that control investments reduce exposure rather than simply satisfy a checklist.

Responsibility may also extend beyond the immediate payment chain. Under the political agreement, online platforms that fail to remove notified fraudulent content can be liable to payment providers that reimburse victims. A bank’s eventual exposure may therefore be shaped in part by how quickly fraudulent ads, impersonation profiles, and scam content are detected, reported, and removed.

The legal and operational implications are substantial. The final texts still require formal adoption, and implementation details will determine the exact standards providers must meet. But the direction is already clear: when a customer dispute arises, firms will need contemporaneous evidence of what their controls saw, what decision they made, and why that decision was reasonable in context. Retrospectively assembled documentation is unlikely to be persuasive in a complaint or dispute.

Where Current Controls Fall Short

Strong customer authentication has achieved much of what it was designed to do. The EBA and ECB found that SCA-authenticated transactions were less susceptible to fraud, particularly in card payments. They also reported that card fraud was 17 times higher when the recipient was outside the EEA, where SCA is not required. For credit transfers, however, the report found the protective effect less conclusive — a critical distinction as scammers increasingly rely on deception rather than stolen credentials. The EBA and ECB’s joint payment-fraud report details the divergence between payment types.

In a coached-payment scam, the payer may successfully complete SCA even though the payment has been induced by deception. The customer’s credentials can be genuine, the device familiar, and the authentication valid. Controls designed primarily to validate whether a customer is initiating a payment are not, on their own, designed to determine whether that customer is being deceived.

The emerging requirements will therefore demand more than authentication alone. Verification of Payee can help prevent misdirected or manipulated transfers by checking whether the payee name matches the IBAN provided by the payer. But the ability to detect or interrupt suspicious inbound transfers before funds settle requires a different operating model — especially as instant payments make the window for intervention extremely short.

For receiving institutions, this elevates the importance of real-time detection of suspicious receiving accounts, including potential money-mule activity. In my years building fraud detection systems, I have often seen receiving-side mule detection treated as someone else’s problem because the immediate loss was elsewhere. The emerging framework makes the allocation of responsibility harder to sustain.

What Good Looks Like

Statutory minimums — including payee verification and powers to delay or freeze suspicious transactions — should be treated as a baseline rather than an end state. Fraud tactics adapt to predictable controls. Firms that focus only on formal compliance may still remain exposed to reimbursement costs, operational expenses and customer harm.

More effective prevention begins before the payment is executed. A provider should assess the context around a transaction, not only whether the customer has completed authentication. A first-time payee, a new device, unusual account behavior, navigation patterns that suggest a customer may be acting under direction, and digital-identity signals associated with a new or higher-risk recipient can each be relevant depending on the institution’s fraud typologies and available data.

No single signal proves a scam. But when firms combine relevant signals in real time, they can support earlier intervention — before money leaves the account. The right intervention will vary by risk level: allowing a routine transaction to proceed, adding a context-specific warning, prompting a confirmation step, delaying the transfer for review, or freezing activity where the facts justify it.

The decisioning layer matters as much as the data. Risk scores must translate into concrete actions inside the payment flow, and each action should have a recorded rationale that can be reviewed in a later complaint, reimbursement decision, or dispute. Properly implemented risk-based controls can target added friction at higher-risk events instead of applying the same burden to every legitimate customer.

Where to Start

Start with exposure, not obligations. Use 2024 and 2025 fraud data to run scenario analyses based on the political agreement: identify which historical cases could have triggered reimbursement, which controls were available at the time, and what the resulting refund and operational bill might have been under different assumptions.

Do not project a single regulatory outcome as if the final technical standards were already fixed. Use a range of scenarios informed by the EBA and ECB’s reported 2023-24 increase in payment fraud, changes in payment volume and mix, historical scam typologies, and the organization’s current control coverage. That analysis is more likely to resonate with a board than a generic compliance roadmap because it ties regulatory readiness to the firm’s own loss exposure.

Then close the gap between batch monitoring and instant settlement. For institutions that still depend on batch scoring, real-time risk assessment should become a foundational program at payment initiation and on inbound flows. That capability will be central to obligations requiring an institution to recognize, delay, or interrupt suspicious activity before funds can be dissipated.

Documentation belongs in the architecture from the start. Firms should be able to reconstruct, for any disputed payment, what information was available at the time, which controls were applied, what decision was reached, and why that outcome was reasonable. Evidence created only after a complaint arrives is inherently less persuasive than a contemporaneous record.

The PSR and PSD3 package still awaits final adoption and publication. Current legal analysis places practical application around 2028, although the operative timetable will depend on the final texts and their publication in the Official Journal. That may sound distant, but large-scale changes to monitoring, decisioning, data architecture and case management processes can take years — particularly for institutions operating across markets, products and legacy technology stacks.

The losses are already rising. Every prevented scam can reduce immediate losses and customer harm today; the same capabilities may also reduce future reimbursement exposure when the new framework takes effect.

The political agreement has made the direction of travel clear: payment providers will bear more of the cost when fraud controls fail and, in some circumstances, when impersonation scams succeed. The remaining question is how much exposure each institution chooses to retain. Firms that treat fraud prevention as a defense of their own income statement — not merely a concession to Brussels — will be better positioned to answer it.

Take the First Step Toward Transformative Fraud Prevention