In late November 2025, EU legislators reached a landmark political agreement on the Payment Services Directive (PSD3) and the Payment Services Regulation (PSR). Since then, the legislative process has advanced significantly, with final compromise texts published in April 2026 and approved at committee level in May 2026, signalling that the reforms are now entering their final adoption phase. This package represents one of the most significant reforms to the EU payments framework since PSD2, driven by accelerating digitalisation, persistent payment fraud risks, and the need for greater regulatory harmonisation across the EU.
At a glance
While PSD3 and the PSR are not yet in force, the legislative process is now largely complete. The exact implementation timeline will depend on:
In practical terms, the next phase involves formal adoption of the final texts by the European Parliament and their publication in the Official Journal of the EU, before they enter into force. Based on the final compromised texts, it is anticipated that:
On this basis, most obligations introduced by PSD3 and the PSR are expected to take effect during 2028.
PSD3 and the PSR introduce obligations that extend beyond traditional payment service providers, affecting every actor involved in providing, supporting, or enabling payment services across the EU. The scope reflects the EU’s ambition to create a harmonised, fraud‑resistant payments environment.
Entities in scope include:
While PSD3 and the PSR will introduce a broad set of new obligations for PSPs, several requirements will stand out because of their direct impact on fraud prevention, liability exposure and customer protection. These changes will be particularly relevant for fraud, compliance and operational teams, as they will fundamentally reshape how fraud risks are expected to be prevented, detected and managed.
Heightened liability for impersonation fraud
PSD3 will explicitly clarify PSPs’ liability where customers are deceived by fraudsters impersonating their bank or payment service provider. In such cases, PSPs will be required to refund their customers (provided the consumer notifies the PSP without undue delay after becoming aware of the fraud and reports the fraud to the police) unless they can demonstrate that the customer acted fraudulently or with gross negligence. This will place greater emphasis on:
Mandatory IBAN-name verification and accountability for failure
PSPs will be required to operate a verification service that matches the unique identifier (e.g., IBAN) with the payee’s name The final compromise text establishes PSP's liability where failures in the Verification of Payee process contribute to customers transferring funds to an unintended or fraudulent beneficiary, reflecting the growing regulatory focus on preventing Authorised Push Payment (APP) fraud before a payment is executed.
This will make clear that technical implementation alone will be insufficient and that PSPs will need to ensure accuracy, seamless integration into payment flows, and reliable audit trails.
Authentication no longer equals legitimacy
Under PSD3, successful authentication or use of a payment instrument alone will no longer be sufficient proof that a transaction was legitimately authorised or that the customer acted fraudulently or with gross negligence. Where fraud or negligence is alleged, the burden of proof will lie with the PSP. This will increase the importance of behavioural monitoring, transaction logs, authentication data and structured investigation processes, both for customer disputes and supervisory assessments.
Refund timelines and investigation efficiency
Unauthorised transactions will generally require immediate refunding no later than the end of the following business day, unless there are reasonable grounds to suspect customer fraud.
Where such suspicion exists, PSPs will have 15 business days to conclude the investigation and either issue the refund or provide a substantiated refusal. These expectations will place pressure on operational efficiency, decision‑making speed and case tracking accuracy.
Transaction monitoring, SCA and information sharing
PSD3 and the PSR will require PSPs to have effective transaction monitoring and fraud‑detection systems capable of identifying suspicious activity at an early stage. The final compromise text introduces direct liability where mandatory transaction monitoring is not properly performed. Transaction monitoring systems will be expected to assess key risk factors such as common fraud scenarios, unusual transaction amounts, compromised or stolen authentication elements, signs of malware, or abnormal use of the device. In addition, PSPs will be required to apply SCA for high‑risk actions like adding new payees or changing account limits, helping prevent account takeover and other remote fraud.
Transaction monitoring obligations are expanded significantly under the PSR. Both payer-side and payee-side PSPs will be expected to monitor outgoing as well as incoming payment transactions, increasing focus on the identification of mule accounts and suspicious fund flows. Additionally, PSPs will have an explicit legal basis to suspend payment transactions where there are objectively justified grounds to suspect fraud, enabling them to contact customers, verify payment instructions and, where appropriate, refuse execution before funds are transferred.
To strengthen fraud and scam prevention, PSPs will also be able to participate in information‑sharing, for example by exchanging payee identifiers where there is sufficient evidence of fraud.
Such information sharing will help other PSPs identify and block emerging fraud patterns earlier, reducing exposure across the ecosystem.
Fraud governance, awareness and accountability
Finally, PSD3 and PSR will significantly strengthen expectations around fraud governance and organisational accountability. PSPs will be required to maintain incident‑management frameworks, conduct regular operational and security risk assessments, report fraud statistics for different payment methods annually to competent authorities and provide mandatory, recurring fraud training to employees.
At the same time, PSPs will be required to actively educate customers on fraud risks, considering specific channels tailored to vulnerable customer groups and ensure that fraud reporting is simple and accessible. Crucially, PSPs will remain responsible for ensuring compliance across employees, agents and outsourced providers, reinforcing that outsourcing does not reduce regulatory accountability.
Although the final text and timelines are still being confirmed, there are several practical actions that firms should already begin preparing for:
As firms prepare for PSD3 and the PSR, strengthening fraud capabilities becomes not only a regulatory requirement but a critical enabler of trust, customer protection and operational resilience. The new standards elevate expectations across real‑time monitoring, SCA controls, behavioural analytics, investigation quality, and customer communications.
At PwC we have developed a PSD3/PSR maturity assessment tool to diagnose your current state against the evolving regulatory requirements around payment fraud. The assessment identifies areas of heightened exposure and enables you to proactively strengthen fraud prevention and transaction monitoring capabilities, clarify liability and refund decision‑making, improve investigation speed, and enhance customer communications. It delivers a practical, prioritized roadmap covering customer protection, fraud investigation & dispute handling, refunds & PSP’s liability, transaction monitoring, fraud detection, prevention, and reporting & management information. The maturity assessment helps PSPs assess whether their operating model, controls, data and management information are sufficient to support increased requirements and tighter refund timelines under PSD3. If you are interested in discussing the topic of PSD3/PSR and what the requirements of the new legislation will mean for your organisation, feel free to get in touch.
[1] In our earlier article, “The 3rd Payment Services Directive is around the corner: Are you ready?”, we outlined how PSD2 strengthened payment security through SCA while unintentionally enabling the rise of APP fraud, impersonation scams and ATO frauds. We also summarised the initial PSD3 key changes proposed at that time. For readers who would like to revisit that background and the original PSD3 change overview, the full article is available here.
[2] Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs)
Disclaimer: The information contained in this article is for general information purposes only and is provided as of the date of publication. It should not be relied upon as legal advice, nor as a basis for determining how applicable laws or regulations may apply to your organisation. Readers should seek appropriate guidance from their legal or regulatory advisors regarding obligations specific to their business and how to ensure compliance. The authors do not accept any liability for actions taken or not taken based on the contents of this publication.
Hledáte experta, který Vám pomůže; chcete poptat naše služby; nebo se zkrátka na něco zeptat? Dejte nám o sobě vědět a my se Vám co nejdříve ozveme zpátky.