The Liability Shift That Changed Everything
On 7 October 2024, the UK Payment Systems Regulator's mandatory reimbursement framework for Authorised Push Payment (APP) fraud came into force, requiring banks and payment service providers to reimburse victims of scams up to 85,000 GBP per claim — regardless of whether the customer was negligent. Split equally between sending and receiving PSPs, the framework fundamentally altered the economics of fraud in the UK's Faster Payments ecosystem.
One year on, the data tells a mixed story. Reimbursement rates for victims have improved dramatically — from under 60% to above 90% in most cases. But the cost is significant. Industry estimates suggest aggregate payouts exceeded 500 million GBP in the framework's first year. More consequentially, the liability model has exposed a structural weakness in how banks have historically managed APP fraud: the fraud was always the customer's problem until it wasn't.
What Is APP Fraud?
Authorised Push Payment fraud occurs when a legitimate account holder is manipulated into initiating a payment to a criminal-controlled account. The payment is authorised — the customer enters their credentials, confirms the transaction — but under false pretences. Common typologies include:
- Romance scams: Fraudsters build emotional relationships over months before requesting transfers, often to overseas accounts or crypto exchanges.
- Impersonation fraud: Criminals pose as bank fraud teams, HMRC, police, or utility companies to create urgency. Victims are told their account is compromised and directed to move funds to a "safe account."
- Invoice redirect: Fraudsters intercept legitimate B2B payment instructions — often via email compromise — and substitute the payee's account details with their own.
- Investment scams: High-yield investment opportunities, frequently promoted via social media or WhatsApp, lure victims into transferring savings to fraudster-controlled wallets.
The common thread: the bank's authentication systems detect no anomaly. The customer is who they say they are. The fraud is in the social engineering, not the technical exploit.
Real-Time Payments and the Speed-Fraud Paradox
APP fraud has been turbocharged by the global proliferation of instant payment systems. The UK's Faster Payments (since 2008), India's UPI, Brazil's PIX, the EU's SEPA Instant Credit Transfer, and the US Federal Reserve's FedNow (live since July 2023) all share the same fundamental property: irrevocability within seconds.
The paradox is acute. Instant payments are a genuine economic good — they improve cash flow for small businesses, enable real-time payroll, and reduce dependency on costly card networks. But their irrevocability creates a narrow fraud window. By the time a victim realises they have been scammed, the funds have typically been moved to mule accounts and withdrawn or further transferred. Recall mechanisms exist but succeed in fewer than 25% of cases.
Mule account networks are the logistics layer of APP fraud. Accounts recruited or coerced into receiving and forwarding fraudulent proceeds are often young adults, students, or individuals in financial distress who may not fully understand their legal exposure. The networks are highly adaptive: a mule account flagged by one institution's models will be discarded and replaced within hours. Estimating their scale is difficult, but Cifas data suggests the UK alone had over 40,000 confirmed mule account cases in 2024, a figure widely regarded as an undercount.
The UK Framework One Year On: What's Working
Confirmation of Payee Confirmation of Payee (CoP) — the name-matching service that checks whether the recipient's account name matches the bank's records — has been mandatory for major UK banks since 2020 and significantly expanded in scope in 2024. When properly implemented, CoP has demonstrably reduced invoice redirect fraud. Its limitations are real: it cannot detect a legitimate account that has been taken over, and it only matches name to account, not account to identity.
Detection Friction Several UK PSPs have introduced deliberate friction for high-risk payment scenarios — extended confirmation screens, mandatory cooling-off periods for first-time payees, outbound call verification for transactions above thresholds. These interventions are measurably effective but create tension with the user experience expectations that digital banking has established.
Receiving Bank Obligations The most significant structural change from the PSR framework is the shared liability model. Receiving banks — historically passive in fraud prevention — are now financially motivated to implement controls on account opening and mule detection. The shift is producing real investment: enhanced behavioural analytics on new accounts, tighter velocity controls on outbound transfers in the first 30 days, and more aggressive account closure when mule indicators are present.
The US Picture: FedNow, Zelle, and the Regulatory Gap
The US lacks a mandatory reimbursement framework equivalent to the UK's. Zelle — operated by Early Warning Services on behalf of the major bank consortium — processed over 1 trillion USD in payments in 2025, with fraud losses estimated in the billions. The Consumer Financial Protection Bureau under the previous administration had pursued enforcement actions against major Zelle participant banks for inadequate fraud reimbursement, but those actions were substantially curtailed following the administration change in early 2025.
The Electronic Fund Transfer Act (EFTA) technically limits liability for unauthorised transactions but provides no statutory protection for authorised payments made under fraud. Victims of APP fraud in the US currently have no federal reimbursement right.
This gap is increasingly politically visible. Several Congressional proposals would extend EFTA protections to APP fraud victims, and state attorneys general have been active in pursuing enforcement against platforms perceived as facilitating scams. The regulatory trajectory — though uncertain in timing — points toward mandatory reimbursement frameworks within the next legislative cycle.
EU: SEPA Instant and the Instant Payments Regulation
The EU's Instant Payments Regulation, which entered force in 2024, mandates that all payment service providers offering euro credit transfers also offer instant credit transfers by January 2025 (for eurozone PSPs) and July 2025 (for non-eurozone EU PSPs). Critically, the regulation mandates IBAN-name verification (the EU equivalent of CoP) for all instant transfers.
The EU's AML package — including the establishment of AMLA (the Anti-Money Laundering Authority, which began operations in Frankfurt in mid-2025) — is expected to address APP fraud through its payment fraud provisions. AMLA's first supervisory priorities include assessment of payment fraud controls at the largest cross-border PSPs.
Building Controls That Work
Pre-payment friction that's proportionate. Blanket friction damages conversion and trains customers to dismiss warnings. Risk-based friction — triggered by first-time payees, unusual hours, high values, or behavioural anomalies in how the payment was initiated — is substantially more effective and less corrosive to the user experience.
Outbound customer intervention. Scripted outbound calls for high-risk scenarios — especially investment-related transfers or large first-time payees — remain one of the highest-ROI interventions available. The challenge is scaling them without creating a false sense of security.
Cross-industry intelligence sharing. APP fraud thrives on information asymmetry. Intelligence about known mule accounts, scam phone numbers, and fraudulent payees shared across institutions — through platforms like the UK's MACS (Mule Account Data Collaboration Service) or equivalent — dramatically improves detection speed. Institutions that participate in these networks outperform those that rely solely on proprietary data.
Mule account detection at onboarding. The receiving bank's role in the liability framework creates the right incentives. Effective controls include: device fingerprinting matched against known fraud infrastructure, social graph analysis of referrers, and velocity monitoring on accounts less than 90 days old. Mule accounts exhibit distinctive patterns — rapid receipt and forwarding, minimal merchant spend, unusual geographic patterns for cash withdrawal — that are detectable with appropriately tuned models.
Victim recovery and support. Financial and reputational costs of APP fraud extend beyond the direct loss. Institutions that invest in victim communication, rapid freeze capabilities, and proactive outreach to potential victims — flagged by behavioural or network signals before a loss is reported — build genuine trust and reduce total claim costs.
The economics of APP fraud have permanently changed for financial institutions. Shared liability means shared incentive. The institutions that treat this as an engineering and intelligence problem — rather than a claims processing problem — will define what best practice looks like as mandatory frameworks proliferate globally.
