Payment Fraud: The PSR’s Layered Liability

This post is also available in: Français (French) Nederlands (Dutch)

Current payments law rests on a single question. Was the transaction authorised by the payer?

If it was, the provider owes nothing. If it was not, the provider refunds, unless the user acted with gross negligence or fraudulently.

This architecture has structured all phishing and spoofing litigation since PSD2 was transposed in 2018. It explains why the debates turn on consent, on strong customer authentication and on how gross negligence is characterised. It also explains why Belgian decisions diverge: the question asked is binary, but fraud situations are not.

The Payment Services Regulation (PSR), which comes with the third Payment Services Directive (PSD3), abandons this model.

Where does the Payment Services Regulation stand?

The European Parliament and the Council reached a provisional political agreement on PSD3 and the PSR on 27 November 2025. On 23 April 2026, the Council published the final compromise texts and submitted them to the Committee of Permanent Representatives with a view to a second-reading agreement with Parliament. Parliament’s ECON committee approved them on 5 May 2026.

Publication in the Official Journal is still awaited. The regulation will apply twenty-one months after its entry into force. The obligations relating to verification of the payee will apply only after twenty-seven months.

The text is therefore not yet applicable. Its substance is, however, settled. Positions taken today in cases that will be decided in 2028 or 2029 must take it into account.

What regime for disputed payment transactions under the new Regulation?

The regulation keeps the category of unauthorised transactions, together with its refund regime.

It adds a second one: authorised but refundable transactions.

Three main scenarios fall within this second category.

The first is fraud through impersonation of the provider. The consumer did give consent, but gave it because a third party posed as their bank using communication channels attributed to that bank: a telephone number, an e-mail address or a message thread that appear to be the bank’s. On the compromise text, a call from an unrelated number by someone claiming to be a bank employee is not enough.

The second is a failure of the verification of payee service. The provider did not flag to the payer the mismatch between the payee’s name and the account identifier, although it was required to do so.

The third is a failure of transaction monitoring. The regulation requires the payer’s provider to monitor the transaction before executing it, and the payee’s provider to monitor it before making the funds available. A provider that did not carry out this monitoring is liable for the fraudulent transaction.

Proving that a payment was authorised will no longer be enough

The practical consequence is this. Establishing that a transaction was authorised no longer ends the discussion.

Under PSD2, proving the payer’s consent, backed by strong customer authentication, in principle exhausts the defence. The court then examines the user’s negligence.

Under the PSR, that same proof opens a second question: did the provider’s prevention mechanism work as it should have?

This question is of a different nature. It no longer concerns the user’s conduct but the provider’s internal organisation. It calls for different evidence: documentation of detection scenarios, alert logs, suspension procedures, traceability of decisions.

Providers should anticipate that these items will be requested in disclosure. They have every interest in checking now that they are retained, time-stamped and usable.

The payee’s bank comes into play

The second shift is more structural still.

The PSR turns the payee’s provider into a prevention actor. It must monitor incoming transactions and hold the funds where a transaction is suspicious.

Today, the payee’s provider is a third party to the dispute. The payer sues its own bank. That bank does have a right of recourse against the provider to which liability is attributable (Article 92 PSD2, transposed into the Belgian Code of Economic Law). But that recourse was not designed for fraud by manipulation of the payer and, in practice, it goes unused in this litigation.

Tomorrow, a failure by the payee’s provider is an identified breach, both for verification of the payee and for transaction monitoring. This opens two prospects: the question of a direct action by the victim, and above all a recourse between providers.

This inter-institution litigation has no equivalent in Belgian or European case law. The terms of the recourse, its characterisation, its limitation period and its interaction with interbank settlement rules remain to be built.

What stays: the payment service user’s gross negligence

The user’s gross negligence remains available as a defence. The PSR does not create an unconditional right to a refund.

Strong customer authentication remains required, with its evidentiary regime. The burden of demonstrating the authentication, the recording and the accounting of the transaction continues to rest on the provider. The use of the payment instrument or the completion of strong customer authentication is not, of itself, sufficient to establish that the transaction was authorised or that the payer was grossly negligent. PSD2 already said so. The PSR keeps it.

The refund for impersonation fraud is subject to its own conditions. It is reserved for consumers. The consumer must report the fraud to the police and notify their provider without undue delay. The provider then has fifteen business days to refund or to give reasons for refusing. It may refuse only if it establishes fraud or gross negligence on the consumer’s part, and it bears the burden of proof. These conditions warrant a careful reading of the published text, as the compromise version may still undergo drafting adjustments during the legal-linguistic revision.

Open questions and assessment

The first concerns the applicable standard. At what point is a monitoring mechanism deemed to have failed? The regulation sets no threshold. The technical standards expected from the European Banking Authority will specify part of it, but the court’s review will bear on largely factual matters.

The second concerns the interaction with pending cases. A dispute brought today will be judged under PSD2. A dispute over facts arising after the date of application will fall under the PSR. Between the two, the lines of argument are not transposable, and the precedent value of decisions rendered under the current regime will decline rapidly on the points the regulation changes.

This is the English version of an article originally published in French on bankinglaw.be.

Leave a Reply

Up ↑

Discover more from Banking and Finance law in Belgium

Subscribe now to keep reading and get access to the full archive.

Continue reading