Who Pays When the Customer Pressed Send? APP Fraud Reimbursement and the New Scam Defence
The UK's mandatory reimbursement regime moved the cost of authorized push payment scams onto payment firms. Other markets are watching, and fraud teams everywhere are rethinking what prevention means.
£85,000
Maximum mandatory reimbursement per APP scam claim under the UK regime from October 2024
50 : 50
Default split of reimbursement cost between sending and receiving payment firms in the UK
13 months
Window after the final payment within which UK victims can make a reimbursement claim
Most payment fraud involves a transaction the account holder did not make. Authorized push payment (APP) fraud is different. The victim makes the payment themselves, having been deceived. A caller claiming to be from the bank's fraud team persuades them to move savings to a "safe account". A fake investment platform shows impressive returns. A romance develops over months before a request for money. In each case, the customer presses send.
Because the payment is authorized, traditional protections for unauthorized transactions often do not apply. And because many scams run over instant payment rails, the money can be moved onward through mule accounts within minutes. For years, victims in many markets had little recourse.
The UK model
The UK became a test case. After a voluntary code produced inconsistent outcomes, the Payment Systems Regulator introduced mandatory reimbursement for APP scams over Faster Payments from 7 October 2024, with parallel arrangements for CHAPS. The core features are:
- Reimbursement of eligible victims up to £85,000 per claim.
- Cost split by default 50:50 between the sending and receiving payment firm, giving the receiving side, which hosts the mule account, a direct financial incentive to act.
- A consumer standard of caution, under which firms may decline claims where the customer was grossly negligent, with protections for vulnerable customers.
- An optional excess, capped at £100, that firms may apply, but not to vulnerable customers.
- A claim window of 13 months from the final payment, and a requirement to reimburse quickly, typically within five business days, with limited scope to extend when more information is needed.
The regime's cap was set lower than earlier proposals, reflecting concerns about moral hazard and costs for smaller firms. Its governance is also changing: the UK government announced in 2025 that the Payment Systems Regulator would be consolidated into the Financial Conduct Authority, and readers should check how that transition affects supervision of the regime.
What changed inside banks
When the cost of a scam moves from the customer to the payment firm, the economics of prevention change. Several shifts are visible.
- Receiving-side scrutiny: firms that previously focused on outbound payments now monitor inbound flows for mule behavior, such as new accounts receiving from many unrelated senders and paying out rapidly.
- Targeted friction: generic warnings are being replaced by specific interventions based on scam type, along with cooling-off delays and call-backs for high-risk payments.
- Data sharing: because scams cross institutions, consortium intelligence on mule accounts and scam patterns has become more valuable.
- Name checks: the UK's Confirmation of Payee service, in place since 2020, provides a pre-payment name check similar to the EU's Verification of Payee.
A reimbursement rule does not stop a single scam by itself. What it does is make every payment firm care about the scams it used to be able to ignore.
Other markets
Other jurisdictions are taking different approaches. In the EU, the proposed Payment Services Regulation includes provisions on fraud liability, notably around impersonation of a payment provider's own staff, and the legislative process considered the role of online platforms and telecoms in facilitating scams; final texts determine what applies. Australia passed legislation in 2025 establishing a Scams Prevention Framework that assigns obligations to banks, telecoms and digital platforms. Other markets have introduced codes of practice or are consulting on reimbursement rules.
A common theme is that payment firms are not the only actors in a scam. Fraudsters reach victims through phone networks, social media, online marketplaces and search advertising. Many in the banking industry argue that reimbursement should be shared with those sectors; regulators have so far moved more slowly on that front.
Building a scam defence
Whatever the liability framework, effective scam defence tends to combine several layers.
- Session signals: behavioral patterns that suggest coaching, remote-access software or an active call during a banking session.
- Payee risk: the age, history and inbound patterns of the receiving account.
- Payment context: new payees, unusual amounts and payments that empty an account.
- Tailored interventions: warnings that reference the likely scam type and ask the customer to engage, rather than a generic click-through.
- Victim support: rapid handling of claims and recovery attempts, since funds are sometimes still traceable in the first hours.
Unresolved questions
The debate is far from settled. Some worry that generous reimbursement weakens individual vigilance, although evidence on this is contested. Others point to first-party fraud, in which customers falsely claim to have been scammed, as a growing cost. Smaller firms argue that compliance and reimbursement burdens fall disproportionately on them.
What is clear is that the era in which banks could treat APP scams as the customer's problem is ending in several major markets. As instant payments become the default across Europe and elsewhere, the question of who pays when the customer pressed send will only become more pressing.
Found this useful? Pass it on.
Companies working on this
Cobalt Canopy
Compliance-as-a-service for sponsor banks and their fintech partners.
Ferrous Pay
Full-stack acquiring with network tokens and 3DS2 on by default.
Lodestar Signals
Real-time scam and mule detection for instant payments.
Read next
Stablecoins in Cross-Border B2B Settlement: Beyond the Hype, Into the Treasury