Vulnerability and the APP Reimbursement Regime: The Exception That Should Be Doing More Work


The mandatory reimbursement requirement is mostly discussed through its exceptions. The consumer standard of caution carries the commercial weight, because it is the route by which a firm may decline an otherwise valid claim where the customer's conduct fell a very long way short of what could reasonably be expected. Inside it sits the exception to the exception: the standard does not apply where the consumer was vulnerable at the time the payment was made.
That clause carries more weight than its length suggests. It accepts that a uniform standard of reasonable behaviour would fall hardest on the people least able to meet it, who are precisely the people fraudsters select and cultivate. It turns a question about conduct into a question about circumstance, and obliges a firm to know something its claims function has rarely been organised to establish.
This post covers how firms identify and record vulnerability, the difference between a permanent characteristic and a transient circumstance, what an evidenced assessment looks like in a claim file, how Consumer Duty expectations bear on reimbursement decisioning, and how the claims function has to be designed for the provision to work. The framing throughout is that this clause exists to protect people. A firm that treats it as a leakage problem has misread it.
Regulatory and Market Context
The Payment Systems Regulator's reimbursement requirement makes the consumer standard of caution unavailable where the consumer was vulnerable at the relevant time, and does not define vulnerability afresh. The reference point most firms use is the Financial Conduct Authority's guidance on the fair treatment of vulnerable customers, which describes vulnerability as arising where personal circumstances make someone especially susceptible to harm, particularly where a firm is not acting with an appropriate level of care, and sets out four drivers: health, life events, resilience and capability. That is a framework rather than a register of conditions, and explicit that vulnerability is a spectrum and often temporary.
Two further things shape how the provision behaves. The Consumer Duty applies to claims handling as much as to sales, and its outcomes monitoring expectations ask firms to understand how customers with characteristics of vulnerability fare against everybody else; a firm that cannot describe the distribution of its reimbursement decisions has a Duty gap as well as a reimbursement one. The Financial Ombudsman Service, meanwhile, has long considered the individual customer's circumstances rather than an abstract reasonable person, and has been unwilling to hold people to a standard their circumstances made unattainable. The structural tension is plain: the firm assessing vulnerability also bears part of the cost of the answer.
What the Data Is Showing
TrustSphere's own engagement data, drawn from reviews of authorised push payment claims handling, vulnerability frameworks and call quality at UK banks, building societies and electronic money institutions across 2026 and 2027, shows a consistent pattern. Almost every firm had a vulnerability policy, a training programme and a customer indicator. Very few had connected any of it to the reimbursement decision. Vulnerability information sat in three disconnected places: a structured flag on the customer master, unstructured contact notes, and a separate complaints or bereavement system. The handler making the standard of caution decision could reliably see only the first, which is the sparsest and most out of date of the three.
The second finding concerns what gets captured. Long-running characteristics were recorded reasonably well: a declared condition, a registered power of attorney, an accessibility preference. Transient circumstances were close to invisible. Bereavement, a recent diagnosis, redundancy, relationship breakdown, a new caring responsibility: these appeared in narrative notes if at all, and were almost never surfaced when a claim was assessed. That matters disproportionately, because the transient category is where most of this harm sits. A sustained romance or investment scam also manufactures a vulnerability of its own, a state of secrecy and impaired judgement built over weeks by someone the customer believes they trust. Several firms held the evidence already, in a correspondence address changed to a care setting or a bereavement notified elsewhere in the group, and never joined it to the claim.
The third finding is the quality of the assessment itself. Where a decline rested on the standard of caution, only a minority of files recorded what the firm had considered on vulnerability, what it asked, what it found and why it concluded the exception did not apply. The commonest artefact was a single tick against a field. The second commonest was a note observing that no flag was present, treating the absence of a record as evidence of the absence of a circumstance. In calibration exercises with claims teams, handlers given identical anonymised fact patterns reached materially different conclusions, which tells you the decision rested on disposition rather than method.
The fourth finding is about access. Claims raised through digital channels carried far less vulnerability information than those raised by telephone, which is consequential, because a web form asks closed questions and cannot notice that the person completing it is distressed, confused or being coached. The customers most affected by the exception are often the least able to complete a digital journey or narrate a clean chronology, and shame suppresses disclosure. Few firms could produce decline rates split by recorded vulnerability on request, so few could evidence to a board or a supervisor that the provision was operating fairly.
Implications for Financial Institutions
The first implication is that vulnerability must become a question the firm actively asks in every claim rather than a flag it may consult. The regime does not ask whether the customer was recorded as vulnerable; it asks whether the customer was vulnerable, and only one of those is answered by a database lookup. In practice that means a short, consistent, humane enquiry at intake and again at assessment, framed as understanding what was happening in someone's life rather than as testing eligibility.
The second implication is that capture must distinguish the permanent characteristic from the transient circumstance and treat them differently. A long-term characteristic belongs in a durable, consented record with a defined review cycle. A transient circumstance belongs in a time-stamped entry attached to a period, visible to claims, with an explicit rule that its expiry does not retrospectively erase the circumstance for a payment made while it applied. Much of this is special category data, so lawful basis, consent and retention should be settled deliberately rather than by accident.
The third implication is evidential. A claim file should show the assessment as a short piece of reasoning: what the firm knew, what it asked, what the customer said, what it concluded and how that bore on the outcome. Where the exception applied, record that the standard of caution was therefore not considered further. Where it did not, record why, in language that would read fairly if the customer saw it, because they may.
The fourth implication is the Consumer Duty one, and the tension is sharpest here. The Duty expects firms to monitor the distribution of outcomes for customers with characteristics of vulnerability and to act where it diverges without good reason. That needs management information most claims functions do not produce, and second line looking at the population rather than at individual files. It also needs senior management to answer the conflict created by placing a costly judgement with the party that pays for it, using independent review rather than assurance.
The fifth implication is operational design. This cannot be done well by a handler working to an average handling time target on a queue built for throughput. It needs time, training in how to ask difficult questions, a specialist escalation route, and a rule that no decline resting solely on the standard of caution leaves the department without independent review. It also needs a commitment not to make customers prove vulnerability with documents they cannot reasonably obtain. If a customer says they had just been bereaved, the default should be to believe them.
Conclusion
The vulnerability exception is the humane centre of the reimbursement regime. It accepts that a standard of caution applied without regard to circumstance would penalise the people the regime exists to protect, and it places the responsibility for noticing on the firm rather than the customer. That is the right allocation: the firm holds the data, the training and the process, and the customer has just lost their money to someone who spent weeks earning their trust.
What is missing in most institutions is not policy but plumbing and method: connecting what the organisation already knows to the moment of decision, capturing transient circumstances as carefully as permanent ones, asking the question rather than looking for a flag, and watching outcomes at population level. None of that is expensive against the redress and supervisory attention that follow from getting it wrong, or against the harm done to a customer told they should have known better at the worst moment of their year.
Suggested Next Steps
Make an evidenced vulnerability assessment a mandatory step in every authorised push payment claim, and prohibit reliance on the absence of a flag as a finding.
Separate permanent characteristics from transient circumstances in the customer record, give transient circumstances a time-stamped entry visible to claims handling, and confirm lawful basis, consent and retention before widening capture.
Surface signals already held elsewhere in the group, including bereavement notifications, powers of attorney and correspondence addresses changed to care settings, into the claims decisioning view.
Report reimbursement outcomes monthly by recorded vulnerability, intake channel and handler, and require independent review of any decline resting solely on the standard of caution.
Sources: Payment Systems Regulator, Financial Conduct Authority, Financial Ombudsman Service, Information Commissioner's Office, Pay.UK, UK Finance, TrustSphere Risk Index, April 2026.
Companion vendor assessment: today's TrustSphere Risk Index post assesses Nuance Gatekeeper against this problem. Read it at www.trustsphere.ai
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments