top of page

Folding the PSR into the FCA: What Consolidation Means for Fraud Supervision

Writer: TrustSphere Network
TrustSphere Network
3 hours ago
8 min read

The Payment Systems Regulator was created to do something no other United Kingdom regulator was doing: to look at payment systems as infrastructure, ask whether they served the people using them, and compel change where they did not. It was given economic regulation objectives, concurrent competition powers, and direct authority over the operators of designated payment systems and the participants in them. It then spent much of its life known for something rather different, the mandatory reimbursement requirement for authorised push payment fraud, which is the most consequential consumer protection intervention in United Kingdom payments in a generation.


Consolidating that body into the Financial Conduct Authority is therefore not a tidy merger of two overlapping supervisors. It is the absorption of an economic regulator holding infrastructure powers into a conduct regulator with a very different toolkit, objectives and supervisory culture. The two organisations have been converging operationally for some time, through shared leadership and joint working, and to a firm on the receiving end the practical distinction has already blurred. The legal distinction has not.


This post separates three things that internal briefings routinely run together: what is settled and in force, what has been announced or drafted but is not yet binding, and what remains speculation. That distinction matters more here than in most regulatory change work, because a firm that assumes the PSR's powers have already moved may misread who can direct it to do what, and a firm that assumes nothing has changed may be surprised by how quickly the supervisory posture around fraud has shifted.


What Is Changing


Start with the architecture, because the difference in instruments is the substance of the change. The Payment Systems Regulator operates under the Financial Services (Banking Reform) Act 2013. Its objectives are competition, innovation and the interests of service users, which is an economic regulation framing rather than a conduct one. Its principal tools are directions, which may be general and apply to a class of participants, or specific and apply to a named operator or participant, and requirements imposed on participants in designated payment systems. It can conduct market reviews, it holds concurrent competition powers, and its jurisdiction attaches to designated payment systems and to the operators, infrastructure providers and participants within them.


The Financial Conduct Authority operates under the Financial Services and Markets Act 2000 as amended, with consumer protection, market integrity and competition objectives. Its instruments are Handbook rules, guidance, the Principles for Businesses including the Consumer Duty, individual requirements on authorised firms, supervisory tools and enforcement. Those instruments attach to authorised firms and to individuals, not to payment systems as such. This is the crux of the consolidation question. A direction to the operator of a payment system, or a requirement binding every participant in a scheme, is not the same legal object as a Handbook rule applying to authorised persons. Transferring the function is straightforward in principle. Deciding which instrument the successor body reaches for is not.


For fraud specifically, three inheritances matter. The first is the mandatory reimbursement requirement itself, which reallocated the cost of authorised push payment fraud between sending and receiving payment service providers, set a consumer standard of caution exception, protected customers in vulnerable circumstances from that exception, and was implemented through scheme rule changes alongside regulatory direction. The second is data publication. The PSR's practice of publishing firm level performance on authorised push payment fraud, including reimbursement outcomes and the relative position of sending and receiving institutions, changed behaviour in a way no private supervisory letter achieved, because it put comparative performance in front of boards, journalists and customers at the same time. The third is the receiving side. The PSR's willingness to treat the receiving payment service provider as a party with obligations, rather than as a bystander, is the single most important supervisory idea in United Kingdom fraud policy, and it sits awkwardly with a conduct framework historically organised around a firm's duties to its own customers.


Timelines and What Is Still Uncertain


What is settled can be stated shortly. The government's intention to consolidate the Payment Systems Regulator's functions within the Financial Conduct Authority has been announced, and operational integration between the two bodies has been underway, including shared leadership arrangements and joint working on payments policy. The mandatory reimbursement requirement is in force and continues to bind firms. The Financial Services (Banking Reform) Act 2013 remains the statutory basis for the PSR's powers until Parliament changes it, which means that as at February 2028 the directions and requirements made under it remain live obligations regardless of which building the people administering them work in. The Consumer Duty applies in parallel and always has. The National Payments Vision and the delivery arrangements that followed it continue to set the strategic frame for payments infrastructure, retail payments infrastructure renewal and the treatment of fraud within it.


What is not settled is most of the detail a firm would want. Primary legislation is required to abolish the PSR and transfer or repeal its functions, and legislative timetables slip. Whether the successor body retains the general and specific directions power in its current form, or converts the reimbursement regime into Handbook rules of general application, is a genuinely open design question with different consequences for scope, for appeal rights and for how quickly the regime can be amended. Whether firm level fraud performance publication continues, and in what form, has not been resolved, and there is a reasonable argument in both directions given the conduct regulator's different traditions around naming firms. Whether the economic regulation objectives survive as objectives, as considerations, or not at all will shape how card scheme fee work and infrastructure competition questions are pursued. Whether the reimbursement maximum, the consumer standard of caution and the allocation between sending and receiving firms are revisited under new ownership is speculation, informed speculation, but speculation. Anyone offering a firm date for the completion of this transition is selling confidence rather than analysis. The defensible planning assumption is that supervisory expectations converge on the conduct regulator's posture well before the statutory position is tidied up.


What It Means Operationally


The first operational consequence is that the supervisory relationship changes character before it changes law. Economic regulation asks whether a market works. Conduct regulation asks whether a firm treated its customers fairly and can evidence it. Those two questions produce different examinations. A firm accustomed to responding to the PSR with scheme level data and reimbursement statistics should expect to be asked, in addition, how its fraud strategy delivers good outcomes for its own customers, how it identifies and treats vulnerability, how its warnings are tested for effectiveness, how it evidences fair claim handling, and what its board sees. Much of that already sits inside the Consumer Duty. Consolidation makes it the primary lens rather than a parallel one.


The second consequence concerns the receiving side and the firms that have quietly benefited from being looked at less. Under a conduct framework, an institution's obligations to a person who is not its customer are less naturally expressed, but the supervisory interest in receiving accounts will not diminish, because the evidence base points squarely at onboarding quality and mule account management. Expect that interest to be pursued through financial crime systems and controls, through business account due diligence, and through senior manager accountability rather than through a payment system direction. Firms that have treated receiving side obligations as a reimbursement cost to be modelled rather than a control weakness to be fixed should assume the framing is about to become less comfortable, not more.


The third consequence is data and reporting, and it has the longest lead time. Whatever the final shape, fraud reporting will not become lighter. Firms should expect continued granular reporting on volumes, values, reimbursement outcomes, claim handling timeliness, vulnerability identification and receiving side performance, capable of comparison across institutions. The practical implication is unglamorous and urgent: the numbers a firm submits must be reproducible from its own systems on demand, reconcilable to the general ledger and complaints data, and consistent between the scam queue, disputes and financial crime reporting. In our review work the most common failure is not a bad control, it is an inability to reproduce last quarter's submitted figure from this quarter's data model. Under a regulator that publishes comparative performance, that is a reputational exposure rather than a housekeeping problem.


The fourth consequence is governance. The Senior Managers and Certification Regime gives the conduct regulator an instrument the PSR never had, the ability to attach a supervisory conversation to a named individual. Firms should confirm that responsibility for fraud, including reimbursement outcomes and receiving side controls, is unambiguously allocated in a statement of responsibilities, that the person holding it has the authority and budget the responsibility implies, and that the board receives fraud management information capable of supporting a challenge rather than a summary of one. Where fraud responsibility is split across payments operations, financial crime, customer service and technology without a single accountable owner, that arrangement is workable under an economic regulator and awkward under a conduct one.


Conclusion


Consolidation is best understood not as the end of payment systems regulation but as a change in the instruments available to conduct it. The mandatory reimbursement requirement is not going away, the interest in receiving side behaviour is not going away, and the appetite for comparative transparency on fraud performance is unlikely to go away either. What changes is the vocabulary in which those expectations are expressed, the legal form they take and the accountability mechanism attached to them: a shift from an economic question about market outcomes to a conduct question about customer outcomes and individual responsibility.


The sensible response is to stop tracking the transition as a legal event and start preparing for the supervisory posture it produces. That means evidencing fraud outcomes in Consumer Duty terms now, treating receiving side controls as a financial crime systems and controls matter rather than a reimbursement cost line, making regulatory fraud data reproducible and internally consistent, and allocating accountability to a named senior manager with the authority to act. None of that depends on a commencement date. All of it will be expected whenever one arrives, and every element of it is defensible work in its own right if the timetable slips again.


Suggested Next Steps


  • Restate the firm's fraud strategy and its reimbursement performance in Consumer Duty terms, covering outcomes, vulnerability, communication effectiveness and fair claim handling, and take that framing to the board before it is requested externally.


  • Reconstruct the last four quarters of submitted fraud data from current systems and reconcile it to complaints, disputes and the general ledger, documenting every discrepancy and the remediation plan for each.


  • Move receiving side controls into the financial crime systems and controls framework, with business account onboarding quality, mule detection performance and account closure timeliness reported as controls rather than as inputs to a loss allocation model.


  • Confirm that a single named senior manager holds documented accountability for fraud including receiving side performance, and test that the management information they receive would support a regulatory conversation about a specific poor outcome.


Sources: Financial Services (Banking Reform) Act 2013 provisions establishing the Payment Systems Regulator, its objectives and its directions and requirements powers; Financial Services and Markets Act 2000 as amended and the Financial Services and Markets Act 2023; HM Treasury announcements on the consolidation of the Payment Systems Regulator into the Financial Conduct Authority and the National Payments Vision; Payment Systems Regulator mandatory reimbursement requirement for authorised push payment scams, including the consumer standard of caution and vulnerability provisions, and its published authorised push payment scam performance reporting; Bank of England approach to reimbursement for CHAPS payments; Pay.UK scheme rules and retail payments infrastructure renewal work; Financial Conduct Authority Consumer Duty, financial crime guide, Senior Managers and Certification Regime and guidance on the fair treatment of vulnerable customers; Prudential Regulation Authority and Bank of England operational resilience policy; Competition Act 1998 and Enterprise Act 2002 concurrent competition arrangements; National Crime Agency assessments of fraud and money laundering; Financial Ombudsman Service published approach to authorised push payment complaints; UK Finance fraud analysis; TrustSphere Risk Index, April 2026.


TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai


 
 
 

Comments


Recommended by TrustSphere

© 2026 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page