Strong Customer Authentication worked. That is the uncomfortable starting point for anyone reading the Payment Services Regulation (PSR) as a verdict on the second Payment Services Directive (PSD2). Put PSD2 vs PSR side by side and the interesting question is not why authentication failed, but why it was never going to be enough on its own.
The European Commission’s own impact assessment found that SCA stripped out most of the card fraud where the customer never approved the payment. The problem is what replaced it. In a scam, the customer is tricked first and authenticates second. The check passes, because the right person really did approve the payment. The deception is complete before authentication begins.
On EBA data, credit transfers carried the lowest fraud rate of any payment instrument and the highest aggregate fraud value – and 43% of that value came from manipulating the payer into authorising the payment themselves. That is a prevention problem wearing the clothes of an authorisation problem.
The PSR legislates prevention. Here is what changes.
One rulebook instead of many implementations
PSD2 and the second E-Money Directive are both repealed. Their successor is deliberately split in two.
PSD3 is a directive. It recasts licensing and prudential rules and folds e-money institutions into the payment-institution regime. Because it is a directive, it still gets transposed into national law and can vary at the edges.
The Payment Services Regulation is the new instrument for conduct of business: SCA, open banking, fraud prevention and, for the first time in harmonised form, an authorised-fraud reimbursement framework. A regulation applies directly and identically in every member state. There is no transposition to wait for.
It is worth being precise about why this matters, because the usual shorthand is wrong. Whether a text harmonises minimally or fully is set by its own wording, not by whether it is a directive or a regulation. PSD2 was itself largely maximum-harmonisation in its core conduct rules. The weakness was structural rather than definitional: as a directive it had to be transposed into national law in every member state, and the discretions it left, compounded by divergent implementation, fragmented the single market and opened room for regulatory arbitrage.
The PSR removes the transposition layer. Member state discretion is confined to areas the regulation narrowly specifies.
PSD2 vs PSR: four shifts, not a list of new controls
The fraud provisions are best read as four changes of philosophy. Each moves fraud prevention earlier, wider, and closer to the perpetrator.

Figure 1. The four shifts the PSR introduces, compared with the PSD2 position.
These are cumulative, not independent. Redrawing reimbursement supports a stronger preventive model. Prevention becomes more effective through coordinated action across the chain. That broader ecosystem creates points of convergence with AML.
Shift 1 – Reimbursement is redrawn
Under PSD2, reimbursement was designed around transactions the customer never approved. The PSR keeps that protection and adds something new: Article 59 creates a harmonised right to a full refund where a consumer was manipulated by someone impersonating their own PSP.
The conditions are cumulative and narrow. It is not enough that a fraudster claimed to represent the bank. The deception must run through a communication channel attributed to the PSP, such as a spoofed caller ID, an existing bank SMS thread, or an email appearing to come from the PSP’s domain. The victim must be a consumer. And they must notify the PSP without undue delay and report the fraud to police.
Once both preconditions are met, the PSP has fifteen business days to refund in full or give a reasoned refusal. Refusal is only permitted where there are objectively justified grounds to suspect the consumer acted fraudulently or with gross negligence, and the burden of establishing that rests with the PSP.
Article 59 is not the whole picture. Articles 57 and 83 attach their own refund consequences to failures of Verification of Payee and transaction monitoring. Liability under the PSR is no longer determined solely by whether a transaction was authorised. It increasingly turns on whether the PSP complied with its statutory prevention duties across the payment lifecycle.
Shift 2 – Prevention becomes a lifecycle
SCA remains, but it now sits inside a sequence of controls operating before, during and after execution.

Figure 2. PSD2 concentrated prevention at one control. The PSR distributes controls across the payment lifecycle, on both sides of the transaction.
The cool-off on limits is worth dwelling on, because its logic is behavioural rather than technical. An increase requested by the user does not take effect immediately; the previous, lower limit continues to apply for a waiting period. The design borrows from Dutch market practice, where increases take effect after four hours. A customer being coached in real time by a fraudster cannot raise their own ceiling and pay within the same session.
Note also that these controls do different jobs and should not be conflated. Limits do not detect fraud; they constrain how much can leave before detection matters. VoP does not authenticate; it tests where the money is going. Monitoring does not decide the payment; it produces the assessment on which intervention is based.
Shift 3 – Responsibility widens to the ecosystem
Effective prevention depends on coordinated action across the payment chain. The PSR extends monitoring duties to the payee’s PSP, creates a separate intervention point on the receiving side under Article 69, and establishes a right of recourse under Article 78 for a PSP that has reimbursed a payer to recover from another PSP or intermediary whose failure contributed.
Article 78 reaches beyond payments firms. It extends recourse to certain hosting service providers whose failure to meet their Digital Services Act obligations facilitated the fraud.
The redistribution is largely invisible to the customer, who is reimbursed by their own PSP while responsibility is settled behind the scenes.
This matters most in an instant-payment environment. Once funds move in seconds, prevention cannot depend on the sending institution catching everything before execution. The receiving PSP may be the next, and last, point at which the money can still be stopped.
Shift 4 – Fraud and AML stop being strangers
Fraud has always been capable of generating criminal proceeds. What changes is that payment-services regulation now recognises the operational consequences.
Article 69 expressly connects intervention on the payee side with the PSP’s obligation to refrain from executing a suspicious transaction under Article 71 of the AMLR. The two regimes reach for the same lever, hold the payment, but point it at opposite outcomes. Fraud rules aim to restore the payer. AML rules aim to preserve the assets for the authorities.
Reading the two as one control, or confusing which has been triggered, is where liability now sits.
When does this actually bite?
Here the honest answer is: partly already, and 2028 is a poor planning anchor.
The PSR had not been published in the Official Journal at the time of writing. Political agreement was reached in late 2025 and the final compromise text was settled in April 2026. Under that text the Regulation would generally apply 21 months after entry into force, with the Verification of Payee requirements in Article 50 and the corresponding liability regime in Article 57 following six months later.
But the Verification of Payee clock has already run. The Instant Payments Regulation has required euro-area PSPs to offer verification of payee on every SEPA credit transfer, instant or not, since 9 October 2025. PSPs outside the euro area follow on 9 July 2027.
One consequential piece is still to come. Under Article 89, the EBA must submit draft regulatory technical standards on authentication, communication and the technical requirements for transaction monitoring within one year of entry into force.
National legislators are also moving ahead. Lithuania has proposed fraud-prevention requirements including intervention where fraudulently obtained funds reach the payee’s account. And supervision does not wait for new liability rules: competent authorities already have tools under payment security, governance, operational-risk and AML/CFT frameworks to examine whether an institution understands its fraud exposure.
What this means in practice
The practical consequence is a change in what a PSP has to be able to prove. It is no longer sufficient to show that a transaction was authorised. Liability increasingly turns on demonstrating that the whole prevention framework was in place and operating.
That has an architectural implication worth raising now, while technology decisions are still being made. Institutions reviewing fraud or AML monitoring platforms can ask a different procurement question: not whether the engine handles one regulatory workflow, but whether the architecture supports payer- and payee-side monitoring, behavioural and transactional analysis, external fraud intelligence, case management, decision logging, information sharing, and appropriate interaction with AML controls.
This does not mean one vendor or one system for everything. It means avoiding technical architecture that recreates the regulatory silos the PSR is beginning to dismantle.
—
This is part 1 of a four-part series on the PSR and payment fraud.
Next: Verification of Payee: what PSPs must have in place
The full analysis is in our white paper Fraud, redrawn – 23 pages on how the PSR turns fraud prevention from a control into a lifecycle, by Eglė Kontautaitė, former Head of the Money Laundering Prevention Division at the Bank of Lithuania.
→ Download the full white paper here





