APP Fraud Liability Shift: What the UK's PSR Reimbursement Rules Mean for Fraud Architecture in 2026

APP Fraud Liability Shift: What the UK's PSR Reimbursement Rules Mean for Fraud Architecture in 2026
The PSR's mandatory APP fraud reimbursement scheme has changed who pays when fraud succeeds. Here is what the liability shift means for fraud architecture in 2026.

On 7 October 2024, the Payment Systems Regulator's mandatory APP fraud reimbursement requirement came into force. For the first time, both sending and receiving payment service providers became legally liable to reimburse victims of authorised push payment fraud up to £85,000 per claim, split 50:50 between both firms. For fraud and risk leaders, this was not a consumer protection update. It was a fundamental change to the financial consequences of a fraud detection failure. What was previously a reputational and operational cost became a direct balance sheet liabilit shared equally between the institution that sent the payment and the institution that received it.


THE LIABILITY SHIFT IN BRIEF

Before October 2024: reimbursement was voluntary. Sending PSPs bore most of the cost. Receiving PSPs carried no mandatory obligation.

From October 2024: reimbursement is mandatory. Sending and receiving PSPs each bear 50% of the £85,000 cap per claim. Both firms now have a direct financial incentive to prevent APP fraud not just detect it after the fact.


What the PSR Reimbursement Scheme Actually Requires

The PSR's consolidated policy statement PS25/5 (May 2025) sets out the full operational requirements for in-scope PSPs. The scheme covers APP fraud on Faster Payments and CHAPS, protecting consumers, micro-enterprises, and charities. The PSR reimbursement dashboard for Q4 2025 shows that over £215 million was reimbursed to APP fraud victims across 2025, with 83% of claims resolved within the required five business day window and 97% of in-scope claims being reimbursed.

The scheme’s scope is deliberately broad. It covers multi-step fraud cases, applies to vulnerable consumers without the gross negligence exception, and gives victims 13 months from the final payment to submit a claim. Receiving PSPs who previously had no mandatory reimbursement obligation must now pay sending PSPs 50% of the reimbursement cost within defined timeframes. For institutions operating mule-prone accounts or embedded in fraud payment chains, this creates a new and direct financial exposure that did not exist before October 2024.


What the Data Shows One Year Into the Scheme

The PSR commissioned an independent evaluation of the scheme’s first year. The findings, published in 2025, confirmed that APP fraud losses fell by an estimated £73 million per year and the number of APP scams fell by nearly 35,000 as a direct result of the policy. Reimbursement rates rose from 54% to 65% for all claims. The PSR's own assessment was unambiguous: “The evidence is clear APP reimbursement is working.”

However, the UK Finance Annual Fraud Report 2026 published in June 2026 reveals the limits of that progress. APP fraud losses rose sharply in 2025 to £576.4 million, a 19% increase year-on-year with 248,070 cases recorded. Investment fraud accounted for £221.5 million of that total, up 40% year-on-year. The reimbursement scheme reduced fraud loss in year one. But fraud volumes rebounded sharply in year two, driven by increasingly sophisticated social engineering operations that the scheme incentivises institutions to prevent but does not in itself defeat.


THE INCENTIVE STRUCTURE THE PSR DESIGNED

The scheme was explicitly designed to create a financial incentive for PSPs to invest in fraud prevention. When reimbursement is mandatory and shared equally, every APP fraud that completes costs both sending and receiving PSPs money they cannot recover from the customer. The PSR's independent review confirmed this mechanism is working the biggest improvements were seen at firms that had the highest APP fraud levels before the policy came into force. The scheme is changing institutional behaviour. But it cannot change fraud volumes alone.


What the Liability Shift Means for Fraud Architecture

The PSR scheme changes the financial architecture of APP fraud in two directions simultaneously and fraud technology strategy needs to reflect both.

For sending PSPs: the liability exposure now covers every Faster Payments APP fraud claim submitted within 13 months. Outbound payment journeys that rely on static rule checks or manual review at high transaction volumes create a reimbursement tail that accumulates with every missed detection. The architecture implication is direct: real-time, pre-payment behavioural monitoring not post-payment review is the only control that eliminates the liability before it is created. A detection failure that was previously an operational problem is now a balance sheet event.

For receiving PSPs: the scheme created a liability that did not exist before October 2024. Receiving institutions that onboard accounts subsequently used as mule accounts now bear 50% of the reimbursement cost for every APP fraud claim those accounts receive. This makes mule account detection at onboarding and during the account lifecycle, a direct financial risk control, not a reputational one. Institutions that have not invested in inbound payment monitoring and mule network detection are accumulating an exposure that compounds with every claim cycle.


THE ARCHITECTURE QUESTION THE PSR SCHEME CREATES

With £576.4 million in APP fraud losses in 2025 and reimbursement now mandatory at 97% of in-scope claims, the question is no longer whether to invest in fraud prevention. The question is whether the current detection architecture prevents fraud before settlement because post-settlement detection on an instant payment rail means the reimbursement liability has already been created. Prevention is not a feature. Under the PSR scheme, it is the primary financial control.


Key Takeaways

  • The PSR’s mandatory APP fraud reimbursement scheme (live October 2024) made both sending and receiving PSPs jointly liable for up to £85,000 per claim a fundamental change to the financial consequence of a fraud detection failure..
  • The PSR’s independent review confirmed the scheme reduced APP fraud losses by £73 million and cut scam volumes by nearly 35,000 in year one but UK Finance’s 2026 report shows APP losses rebounded to £576.4 million in 2025, up 19%.
  • For sending PSPs, every missed APP fraud detection is now a direct balance sheet liability of up to £42,500 per claim. Pre-payment behavioural monitoring is the only control that eliminates the exposure before it is created.
  • For receiving PSPs, mule account onboarding and lifecycle monitoring are now direct financial risk controls. Every mule account that receives APP fraud funds creates a 50% reimbursement liability.
  • £215 million was reimbursed to APP fraud victims across 2025. With fraud volumes rising and the scheme’s incentive structure now embedded, institutions that have not invested in pre-settlement detection are accumulating a liability that compounds each quarter.

Under the PSR scheme, a fraud detection gap is no longer just an operational problem, it is a reimbursement liability that accumulates with every payment cycle.

Vericent's real-time fraud monitoring platform evaluates every outbound payment before settlement and flags inbound mule account risk at onboarding and throughout the account lifecycle directly addressing both sides of the PSR liability exposure. Request a walkthrough of our APP fraud prevention architecture.