Will Davis
Financial Institutions Banks Leader
-
United Kingdom
The UK Payment Systems Regulator (PSR) is introducing a mandatory reimbursement requirement for victims of authorised push payment (APP) fraud. The scheme, due to come into force from October 7, aims to hold payment service providers (PSPs) to greater account for fraudulent transactions suffered by customers. It is critical that all PSPs operating in the UK understand the requirements of this scheme and consider the risk and insurance ramifications it poses to their business.
In 2023, APP fraud losses within the UK totalled £459.7 million — with personal losses constituting the majority. Typically, APP fraud involves criminals using social engineering techniques to convince victims to send funds. Fraudsters may pose as people in positions of authority or imitate friends and relatives to request money via phone calls, emails, text messaging, or social media.
Incidents of APP fraud are increasing in the UK — in 2023 the recorded number of APP fraud cases rose by 12%. APP fraud seeks to take advantage of the enhanced speed of direct electronic payments offered by the faster payment service (FPS); in 2021 FPS was used in 97% of fraudulent APP payments.
The PSR has acknowledged these concerns and, in response, developed the FPS APP scams reimbursement requirement. This scheme aims to offer more robust protection from APP fraud to customers, while enabling victims a clearer route to recovery.
The reimbursement requirement is an industry-wide legal requirement for UK FPS transactions involving PSPs, which can include banks, building societies, and fintechs.
Initially, the PSR intended to impose a maximum reimbursement, beyond a £100 excess, of £415,000 — to be split equally between the offending PSPs. This figure aligned with the maximum award from the Financial Ombudsman Service (FOS) to limit the number of fraud cases being referred to the FOS for resolution. However, in response to lobbying from various lenders, fintechs, and politicians, the PSR has indicated it may elect to reduce the maximum reimbursement figure to £85,000.
Any funds the receiving PSP recovers from APP fraud must be split equally with the sending PSP. This equal split is to encourage PSPs on either side of the transaction to carry out due diligence and help reduce fraud within the industry. Potentially, any evidence of systemic failures and repeat offences from PSPs could open the door to wider regulatory scrutiny.
However, customers may fail to secure a reimbursement under the new legislation if they are found to have acted carelessly in respect to the ‘consumer standard of caution’. The burden of proof for customers acting with ‘gross negligence’ rests with the PSP. To protect customers and ensure they are acting with sufficient caution, PSPs can improve fraud prevention controls and adopt interventions, such as ‘confirmation of payee’ to prevent fraudulent transactions.
Customers may have failed to act with the ‘consumer standard of caution’, if they have:
Marsh’s financial institutions (FI) claims report 2023 revealed that one-fifth of notifications made by banks related to crime insurance policies — with third-party fraud and cyber/telephonic crime amounting to 27% of all crime related matters.
It is critical that PSPs consider the insurance and risk issues that the reimbursement requirement introduces. Risks need to be quantified and modelled against, along with the possible losses they may entail.
The scale of APP fraud is significant, and bad actors have the opportunity to defraud customers from data leaks and possibly use developments in artificial intelligence to deceive customers.
Specific insurance and risk issues PSPs must consider, include:
It is essential that all organisations handling FPS payments are aware of the risks and liabilities that the APP fraud reimbursement requirement introduces. All PSPs should review their existing processes and controls to mitigate risk and ensure compliance before the reimbursement requirement’s introduction on October 7.
For further advice and discussion on topics raised above, contact your Marsh representative.
Financial Institutions Banks Leader
United Kingdom
Product Executive, UK Financial and Professional Lines
United Kingdom