The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.
Strengthened obligations for payment service providers
The PSR provides for a significant expansion of the obligations of payment service providers, covering both organisational and technological aspects. Financial institutions will be required to implement both more advanced transaction monitoring mechanisms and systems designed to detect high-risk transactions.
Particular emphasis has been placed on combating fraud involving manipulation, social engineering and the unauthorised impersonation of payment service provider staff. Consequently, banks will be required to continuously improve the security of their communication channels and to respond without delay to any indications that may suggest an attempted fraud.
Liability for unauthorised transactions
Despite the strengthening of user protection standards, the draft PSR does not introduce the principle of strict liability on the part of payment service providers for the consequences of all unauthorised transactions. The final form of the regulation in fact departs from earlier concepts that envisaged a far-reaching transfer of the risk of such transactions to financial institutions.
Whilst the regulation does maintain the principle of prompt reimbursement of the amount of an unauthorised transaction – by the end of the next business day at the latest, following the date on which the transaction is identified or a report is received – it significantly expands the list of exceptions to this rule. Under the proposed provisions, a provider may refuse to refund funds where it has objectively justified grounds to suspect that the user acted intentionally or with gross negligence, in particular with regard to the protection of the payment instrument or authentication credentials. At the same time, the bank is required to justify its refusal and to inform the user of the available means of redress.
This approach to liability reflects a desire to strike a balance between the interests of the consumer and the need to prevent abuse on the part of users as well.
Spoofing – a new basis for liability of payment service providers
The PSR also introduces significant provisions regarding so-called spoofing, i.e. situations involving the impersonation of specific entities and the misleading of a user as to the identity of the sender of a communication.
The draft limits the liability of payment service providers to cases in which the perpetrator directly impersonates a given financial institution. Automatic liability is excluded, however, in situations where the fraudster impersonates other entities operating outside the regulatory scope of the PSR. The right to a refund is available to the consumer only on condition that they promptly report the incident to both the provider and the police, and the provider has 15 business days in which to issue a refund or provide a reasoned refusal.
This solution takes into account the complexity of the modern digital environment, in which fraudulent schemes frequently involve multiple independent communication channels and entities beyond the control of a single payment service provider.
Shared responsibility in the digital ecosystem
A noteworthy development is the expansion of the range of entities involved in combating financial fraud. The PSR provides for an obligation of cooperation between payment service providers, digital platforms and telecommunications service providers. These entities will be required to respond to reports of fraudulent activity and to take measures aimed at eliminating it.
One example of such provisions is the obligation for the payee’s bank to verify, free of charge, that a bank account number (IBAN) matches the payee’s name or business name, and subsequently to inform the payer’s payment service provider of the result of that verification. This information is then passed to the person initiating the transfer by their own provider before that person is offered the opportunity to authorise the transaction. Importantly, this obligation covers all types of transfers, i.e. both standard credit transfers and instant credit transfers.
The extension of the scope of shared responsibility reflects the regulatory direction of building a comprehensive security framework covering the entire digital services ecosystem.
The importance of user due diligence
Despite a significant increase in the level of regulatory protection, the PSR makes clear that the security of payment transactions cannot be ensured solely through the actions of financial institutions. The behaviour of the user and adherence to basic precautionary principles remain of key importance.
The draft Regulation explicitly underlines the importance of education and the raising of awareness regarding the risks associated with the use of payment services. Users should in particular:
- Verify the authenticity of communications and contact channels
- Protect their authentication credentials
- Avoid making decisions under pressure
- Use only reliable communication channels
Failure to exercise due diligence may result in a reduction in the scope of protection afforded by the applicable provisions.
The PSR as part of the new payments market architecture
The PSR forms part of a broader legislative package that also includes the PSD3 Directive, the aim of which is to create a new, more coherent legal framework for the payment services market in the European Union that is adapted to the digital reality.
The new rules will be directly applicable in all Member States, which will contribute to further market harmonisation and to the standardisation of user protection standards.
The PSR should be viewed as an attempt to strike a balance between enhancing security and maintaining user accountability for their own actions. The Regulation strengthens the obligations of financial institutions and expands anti-fraud mechanisms, whilst stopping short of introducing a model of full and unlimited liability on the part of payment service providers.
Questions? Contact us


