
On 7 October 2024, the Payment Systems Regulator's mandatory APP fraud reimbursement requirement came into force. For the first time, both sending and receiving payment service providers became legally liable to reimburse victims of authorised push payment fraud up to £85,000 per claim, split 50:50 between both firms. For fraud and risk leaders, this was not a consumer protection update. It was a fundamental change to the financial consequences of a fraud detection failure. What was previously a reputational and operational cost became a direct balance sheet liabilit shared equally between the institution that sent the payment and the institution that received it.
Before October 2024: reimbursement was voluntary. Sending PSPs bore most of the cost. Receiving PSPs carried no mandatory obligation.
From October 2024: reimbursement is mandatory. Sending and receiving PSPs each bear 50% of the £85,000 cap per claim. Both firms now have a direct financial incentive to prevent APP fraud not just detect it after the fact.
The PSR's consolidated policy statement PS25/5 (May 2025) sets out the full operational requirements for in-scope PSPs. The scheme covers APP fraud on Faster Payments and CHAPS, protecting consumers, micro-enterprises, and charities. The PSR reimbursement dashboard for Q4 2025 shows that over £215 million was reimbursed to APP fraud victims across 2025, with 83% of claims resolved within the required five business day window and 97% of in-scope claims being reimbursed.
The scheme’s scope is deliberately broad. It covers multi-step fraud cases, applies to vulnerable consumers without the gross negligence exception, and gives victims 13 months from the final payment to submit a claim. Receiving PSPs who previously had no mandatory reimbursement obligation must now pay sending PSPs 50% of the reimbursement cost within defined timeframes. For institutions operating mule-prone accounts or embedded in fraud payment chains, this creates a new and direct financial exposure that did not exist before October 2024.
The PSR commissioned an independent evaluation of the scheme’s first year. The findings, published in 2025, confirmed that APP fraud losses fell by an estimated £73 million per year and the number of APP scams fell by nearly 35,000 as a direct result of the policy. Reimbursement rates rose from 54% to 65% for all claims. The PSR's own assessment was unambiguous: “The evidence is clear APP reimbursement is working.”
However, the UK Finance Annual Fraud Report 2026 published in June 2026 reveals the limits of that progress. APP fraud losses rose sharply in 2025 to £576.4 million, a 19% increase year-on-year with 248,070 cases recorded. Investment fraud accounted for £221.5 million of that total, up 40% year-on-year. The reimbursement scheme reduced fraud loss in year one. But fraud volumes rebounded sharply in year two, driven by increasingly sophisticated social engineering operations that the scheme incentivises institutions to prevent but does not in itself defeat.
The scheme was explicitly designed to create a financial incentive for PSPs to invest in fraud prevention. When reimbursement is mandatory and shared equally, every APP fraud that completes costs both sending and receiving PSPs money they cannot recover from the customer. The PSR's independent review confirmed this mechanism is working the biggest improvements were seen at firms that had the highest APP fraud levels before the policy came into force. The scheme is changing institutional behaviour. But it cannot change fraud volumes alone.
The PSR scheme changes the financial architecture of APP fraud in two directions simultaneously and fraud technology strategy needs to reflect both.
For sending PSPs: the liability exposure now covers every Faster Payments APP fraud claim submitted within 13 months. Outbound payment journeys that rely on static rule checks or manual review at high transaction volumes create a reimbursement tail that accumulates with every missed detection. The architecture implication is direct: real-time, pre-payment behavioural monitoring not post-payment review is the only control that eliminates the liability before it is created. A detection failure that was previously an operational problem is now a balance sheet event.
For receiving PSPs: the scheme created a liability that did not exist before October 2024. Receiving institutions that onboard accounts subsequently used as mule accounts now bear 50% of the reimbursement cost for every APP fraud claim those accounts receive. This makes mule account detection at onboarding and during the account lifecycle, a direct financial risk control, not a reputational one. Institutions that have not invested in inbound payment monitoring and mule network detection are accumulating an exposure that compounds with every claim cycle.
With £576.4 million in APP fraud losses in 2025 and reimbursement now mandatory at 97% of in-scope claims, the question is no longer whether to invest in fraud prevention. The question is whether the current detection architecture prevents fraud before settlement because post-settlement detection on an instant payment rail means the reimbursement liability has already been created. Prevention is not a feature. Under the PSR scheme, it is the primary financial control.
Under the PSR scheme, a fraud detection gap is no longer just an operational problem, it is a reimbursement liability that accumulates with every payment cycle.
Vericent's real-time fraud monitoring platform evaluates every outbound payment before settlement and flags inbound mule account risk at onboarding and throughout the account lifecycle directly addressing both sides of the PSR liability exposure. Request a walkthrough of our APP fraud prevention architecture.