top of page

Authorised Push Payment Scams in 2026: Reimbursement, Reform, and the Last-Mile Battle

  • Writer: TrustSphere Network
    TrustSphere Network
  • 1 day ago
  • 5 min read

Authorised Push Payment fraud has cemented itself as the dominant consumer fraud typology in real-time payment markets, overtaking card fraud in losses across the United Kingdom and increasingly being identified as a systemic concern in the European Union, the United States, Australia and Singapore. The combination of instant settlement, limited recall windows, and the social-engineering sophistication of modern scam playbooks has created a fraud category that traditional rules-based detection was never designed to catch. For Tier 1 banks and challenger banks alike, APP fraud now sits at the intersection of consumer protection, prudential conduct risk, and financial crime compliance.


The UK Payment Systems Regulator introduced mandatory reimbursement for APP fraud in October 2024, splitting liability fifty-fifty between the sending and receiving payment service providers up to a £415,000 cap. The reform has had two consequences industry leaders are still digesting: it has materially shifted the economics of APP fraud, and it has forced a new operating model in which fraud and AML teams must collaborate, share data, and intervene on the receiving leg of every suspicious payment.


Beyond the United Kingdom, regulators in Australia under the proposed Scams Prevention Framework, Singapore under the MAS Shared Responsibility Framework, and the European Union under the Payment Services Regulation review are watching the UK experience closely. The implication is clear: shared-liability reimbursement is no longer a theoretical regulatory option — it is the emerging international norm, and it is reshaping how banks must invest in detection, intervention, and inter-bank intelligence sharing.


Regulatory and Market Context


The PSR's APP reimbursement requirement applies to all payment service providers participating in Faster Payments and CHAPS, with a tightly defined consumer-standard test that places the burden firmly on banks to demonstrate that warnings, education, and detection were proportionate. The Financial Ombudsman Service has provided early case law indicating that defences will be applied narrowly, and that institutions relying on generic friction screens will struggle to discharge the standard. UK Finance reporting shows total APP losses stabilised at £459.7 million in 2023, but with a growing share moving to purchase scams, romance, and impersonation typologies that are harder to detect at the point of payment.


In parallel, the European Union's Payment Services Regulation introduces an obligation for confirmation-of-payee checks across SEPA Instant payments, intended to reduce misdirected and impersonation losses. Combined with the European Banking Authority's emerging fraud-monitoring guidelines, the message to firms is consistent: pre-execution detection, real-time intervention, and post-event recovery must operate as a single discipline rather than as separate functional silos.


What the Data Is Showing


Cross-industry data from Pay.UK, FICO, and the PSR's own published metrics shows that APP fraud is shifting in shape, not in size. The proportion of cases linked to investment scams and impersonation of trusted brands has risen sharply, while bank-impersonation has declined as institutions have improved authentication and customer-side warnings. The mule-account leg of the typology has not improved at the same pace; receiving-bank detection of inbound mule activity remains the single largest control gap exposed by the new reimbursement regime.


Behavioural-biometrics and session-intelligence vendors are reporting that more than 60% of APP losses now exhibit a detectable change in user behaviour during the scam interaction — pause patterns, hesitation on payment confirmation, switching between apps, and unusual ATM withdrawal patterns ahead of payments. The implication is that the data needed to intervene is overwhelmingly already available; the bottleneck is integrating it with the payment authorisation flow in real time.


Implications for Financial Institutions


Banks that have responded most effectively to the new regime have invested in three capabilities simultaneously: behavioural analytics on the sending leg to disrupt scams before authorisation, enhanced mule-account screening on the receiving leg using device, network, and inbound-payment graph signals, and the operational ability to recall, freeze, or hold funds within minutes of the originating customer reporting a loss. Institutions that have under-invested are seeing reimbursement costs run into tens of millions of pounds annualised in mid-tier UK banks alone.


Equally important is the shift in data sharing. The 2024 reform has forced sending and receiving banks to share information at speed and scale that previously required formal subject-access processes. Cifas, Pay.UK and several private-sector consortia are now operating real-time mule-intelligence feeds, and the institutions that will see the greatest reduction in net APP losses are those that contribute and consume this intelligence as a core part of their fraud and AML operating model.


Conclusion


APP fraud reform marks a generational shift in how consumer fraud risk is allocated, detected, and remediated. Institutions that treat reimbursement as a compliance line item — rather than as a strategic signal to redesign detection, mule screening and inter-bank intelligence — will find their cost base growing faster than their capability to respond. Those that integrate fraud, AML and customer-experience teams around the payment flow will not only meet the regulatory standard but materially reduce loss.


Suggested Next Steps


  • Review your APP detection architecture end-to-end: behavioural analytics on the sending leg, mule screening on the receiving leg, and post-event recall capability — quantifying the loss-reduction impact of each layer separately so investment cases are evidence-based.

  • Establish or strengthen real-time data-sharing arrangements with peer institutions through Pay.UK, Cifas, or sector consortia; these feeds are now an essential control, not a value-added option.

  • Run a dedicated mule-account programme that integrates KYC, transaction monitoring and fraud signals — explicitly measuring the time from inbound suspicious payment to account intervention as a board-level KPI.

  • Stress-test your reimbursement decisioning process against the Financial Ombudsman Service's emerging case law, with particular focus on the consumer-standard test and the documentation required to defend a denied claim.


Sources: UK Payment Systems Regulator APP Fraud Policy Statement; UK Finance Annual Fraud Report 2024; Financial Ombudsman Service Published Decisions 2024 to 2026; European Banking Authority Fraud Reporting Guidelines; Monetary Authority of Singapore Shared Responsibility Framework; Cifas Mule Account Statistics 2024.


TrustSphere Risk Index — Vendor Spotlight


The TrustSphere Risk Index is our independent assessment of the global fraud, financial crime and identity vendor landscape. The March 2026 edition covers 221 vendors across eight functional categories — Risk Orchestration, Enterprise FRAML & Decisioning, Identity / eKYC / KYB Onboarding, Behavioural & Device Intelligence, AML Data, Screening & Regulatory Intelligence, FRAML Technology Stack, Deepfake Detection, and adjacent specialist categories — each scored across eleven capability dimensions including fraud detection, transaction monitoring, identity verification, watchlist screening, and regulatory intelligence.


This week's vendor spotlight is NICE Actimize, which scored 62% on the TrustSphere Risk Index — placing it in the top decile of the Enterprise FRAML & Decisioning Platforms category. NICE Actimize is a global leader in unified financial crime, risk and compliance, with a deep suite spanning enterprise fraud management, AML, market surveillance and case management. For institutions building APP-fraud reimbursement defences, the platform's strengths in real-time transaction monitoring, payment-graph analytics and integrated case management make it one of the most credible options for Tier 1 banks managing both sending- and receiving-leg risk under the new liability regime.


If you would like a comprehensive vendor suitability assessment for your institution — mapped to your specific use cases, regulatory footprint, and target architecture — please contact TrustSphere directly. The full Risk Index, peer benchmarks and tailored shortlist work is available on request.


TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai

Comments


Recommended by TrustSphere

© 2024 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page