Preparing for a New Era of Fraud Accountability

1-888-216-3544

             
Contact Us

PSD3: Are You Ready?

PSD3 and PSR signal a shift toward real-time fraud prevention, stronger consumer protections and greater accountability across the payments ecosystem.
Since its introduction, PSD2 has helped modernise European payments through Open Banking and Strong Customer Authentication (SCA), increasing security, competition and digital innovation across the payments ecosystem.

But fraud evolved alongside it. Scams became more sophisticated, fraud losses continued to rise and differing interpretations of PSD2 created inconsistencies across member states, prompting regulators to introduce the Payment Services Directive 3 (PSD3) and the Payment Services Regulation (PSR) to establish a more consistent framework centered on fraud prevention, accountability and consumer protection across the EU.

The result is a significant shift in how banks, payment service providers (PSPs) and fintechs will need to think about fraud risk in the years ahead.

Get a concise overview of the proposed regulations, key fraud-related changes and what they mean for your business.

Explore implementation considerations, fraud accountability and best practices for organisational readiness.


What are PSD3 and PSR?

PSD3 (Payment Services Directive 3) and the Payment Services Regulation (PSR) work together to form the EU's future framework of digital and electronic payments.

PSD3 focuses on the licensing, supervision and governance of payment institutions, while PSR establishes the operational rules that govern payment execution, fraud controls and consumer protection.

Together, they are designed to address gaps identified under PSD2 by creating a more consistent, real-time and accountability-driven approach to fraud prevention across the EU.

Why Are PSD3 and PSR Being Introduced?

PSD3 and PSR are being introduced in response to a changing payments and fraud landscape. While PSD2 significantly improved security and enabled innovation through Open Banking, fraud continued to evolve, scams became increasingly sophisticated, and implementation varied across member states. The reforms aim to address these challenges by creating a more consistent framework that better reflects today's fraud and risk environment.
Call Us

How Is PSD3 Different From PSD2?

PSD3 is best viewed as an evolution rather than a revolution. While PSD2 focused on access, authentication and enabling Open Banking, PSD3 and PSR expand that vision toward Open Finance while introducing stronger requirements around fraud prevention, consumer reimbursement and operational accountability.

The most significant shift is the move from fragmented compliance and reactive controls toward standardised, real-time fraud prevention and clearer accountability across the payments ecosystem.

What Is the Timeline for PSD3 and PSR?

While the final legislative process is still underway, the direction is clear. PSD3 and PSR have progressed through several years of review, consultation and negotiation, with formal adoption expected to be followed by a phased implementation period across the EU.

The proposed timeline currently points to implementation beginning in 2028, with Verification of Payee (VoP) requirements likely following shortly after. Importantly, organisations are not expected to become compliant overnight. The framework includes transition periods that give institutions time to assess gaps, implement new controls and modernise fraud prevention strategies.

For many payment providers, the real question is no longer when PSD3 arrives, but whether they are using the time available to prepare effectively.

Who Will Be Impacted by PSD3?

PSD3 and PSR will affect a broad range of financial services organisations, including banks, payment service providers (PSPs), fintechs and Open Banking providers.

While requirements will vary by organisation type, virtually any institution involved in initiating, processing or facilitating payments will need to evaluate the potential impact of the reforms.

How Will PSD3 Change Fraud Prevention?

The most significant change introduced by PSD3 and PSR is the elevation of fraud prevention from an operational function to a strategic business priority.

Historically, many fraud programmes focused on detecting and investigating fraud after suspicious activity occurred. Under PSD3, the focus shifts toward identifying risk before funds leave an account.

A key driver behind these reforms is the rise of impersonation scams and other forms of Authorised Push Payment (APP) fraud. In these scams, fraudsters often pose as trusted organisations, such as banks, law enforcement agencies or government bodies, and persuade customers to authorise payments to fraudulent accounts. Because the customer initiates the payment themselves, traditional authentication controls alone are often insufficient to prevent the fraud.

Real-time monitoring, proactive intervention and reimbursement accountability therefore become central to the fraud operating model. Institutions are increasingly expected to identify, assess and intervene before fraudulent payments occur, rather than relying primarily on post-event investigation and remediation.

Fraud prevention becomes a frontline control. Institutions are increasingly expected to identify, assess and intervene before fraud occurs rather than relying solely on post-event investigation and remediation.

Organisations that can identify risk earlier and make better decisions in real time will be better positioned to reduce losses while maintaining a positive customer experience.

What Are the Five Key Changes Organisations Should Prepare For?

  1. Real-Time Fraud Monitoring
    Instant payments leave little time for investigation. Organisations will need the ability to assess transaction, device and behavioural signals and make decisions in milliseconds, not minutes.
  2. Verification of Payee Expansion
    Verification of Payee (VoP) will continue to expand the role of account and payee validation in reducing misdirected payments and APP fraud.
  3. Liability and Reimbursement Readiness
    As institutions assume greater responsibility for impersonation scams, reimbursement processes and fraud controls become more closely linked.
  4. Data Sharing and Collaboration
    New proposals encourage broader fraud insights sharing and cooperation across payment providers, creating opportunities for earlier detection of emerging threats and mule activity.
  5. Balancing Security and Customer Experience
    Organisations will need to balance stronger protections with customer expectations for seamless payment experiences.

Why Layered Intelligence Matters

As expectations around fraud prevention, reimbursement and customer protection continue to grow, single-point solutions are unlikely to provide sufficient visibility. Organisations increasingly need a layered approach that combines transaction, identity, device and behavioural intelligence to create a more complete view of risk throughout the payment journey.

What Should Organisations Be Doing Now?

While implementation details continue to take shape, organisations do not need to wait to take meaningful steps toward readiness. Preparation can begin with:

  • Assessing current fraud monitoring capabilities
  • Evaluating Verification of Payee readiness
  • Reviewing reimbursement and liability processes
  • Identifying gaps in behavioural and transaction intelligence
  • Establishing governance and oversight frameworks
  • Understanding how increased fraud accountability may impact operating models and costs
A phased approach allows organisations to build momentum now while maintaining flexibility as the final regulatory framework is formalised.

What Does PSD3 Readiness Look Like?

While every organisation's journey will be different, several capabilities are emerging as foundational to PSD3 readiness:

  • Making real-time fraud decisions before funds are sent
  • Strengthening payee and transaction intelligence
  • Monitoring risk across the full payment lifecycle
  • Detecting behavioural indicators of scams and social engineering
  • Leveraging network intelligence to identify emerging fraud threats
Together, these capabilities can help institutions move beyond compliance and toward a more proactive approach to fraud prevention.

Beyond Compliance: Turning Regulatory Pressure into a Competitive Advantage

The institutions that gain the most value from PSD3 will not simply focus on meeting regulatory requirements. They will use this moment to modernise fraud strategies, improve decisioning and strengthen trust across the customer journey.

Investments in real-time decisioning, risk intelligence, behavioural intelligence and fraud orchestration can help organisations prepare for regulatory change while simultaneously reducing losses, improving operational efficiency and creating better customer experiences.

The same investments that support regulatory readiness can also create competitive advantage.

Looking Ahead

PSD3 and PSR represent more than the next evolution of payments regulation. They signal a broader shift toward real-time fraud prevention, stronger consumer protections and increased accountability across the payments ecosystem.

The organisations that succeed will view PSD3 not simply as a compliance requirement, but as an opportunity to modernise fraud strategies, strengthen customer trust and build long-term resilience.
LexisNexis and the Knowledge Burst logo are registered trademarks of RELX Inc.
Other products or services may be trademarks or registered trademarks of their respective companies.
Copyright © 2026 LexisNexis Risk Solutions.

Contact us to learn how we can help you prevent fraud earlier, make more confident decisions and prepare for PSD3 and PSR with greater confidence.

Products You May Be Interested In