The Payment Systems Regulator (PSR) has published its first independent review of the UK's authorised push payment (APP) scam reimbursement rules, and the headline is encouraging: fraud losses are falling, and the large majority of victims are getting their money back. The report, released on 1 July 2026, matters to any UK business that sends or receives bank transfers, because APP fraud does not only hit consumers. It hits companies too, and the way these rules evolve over the next year will shape how much protection your business can rely on.

What the first-year review found

The APP scam reimbursement requirement took effect in October 2024. It forces the sending and receiving payment firms to split the cost of repaying most victims of push-payment scams made over Faster Payments. One year on, the PSR commissioned an independent third-party assessment, which concluded the regime has delivered net benefits in its first year. The PSR's own data sits behind that verdict:

  • Losses are falling: APP fraud losses sent over Faster Payments dropped by around 21% in the first year, a reduction of roughly £73 million according to figures reported when the independent review was published.
  • Most victims are repaid: reimbursement rates rose to about 88% of money lost and claimed, up from 66% for the same period a year earlier.
  • Claims are settled quickly: firms resolved 84% of claims within five days and 97% within 35 days.
  • Awareness is still low: nearly half of victims never attempt to claim, and around 71% say they are unaware the policy exists.

UK payment firms paid roughly £173 million in reimbursement across the first full year of the mandatory regime. That is the cost of protection working, but it also frames the harder question the PSR now has to answer.

Why this is a business issue, not just a consumer one

It is easy to read APP fraud as a purely consumer problem, but businesses are squarely in the firing line. Invoice redirection fraud, mandate fraud and so-called "CEO fraud", where a scammer impersonates a supplier or a director and asks finance to change bank details or push through an urgent transfer, are all forms of authorised push payment fraud. The money leaves your account because someone in your business was tricked into authorising it, which is exactly the scenario the reimbursement rules were built around.

The important nuance is who qualifies for reimbursement. The scheme protects consumers, charities and microenterprises, broadly businesses with fewer than ten staff and under £2 million in turnover. Many UK SMEs fall inside that definition and can claim; larger firms fall outside it and carry the loss themselves. Either way, prevention beats a claim, because reimbursement is never guaranteed and the disruption of a redirected supplier payment lands long before any money is returned.

The unresolved question: who should pay

The review was broadly positive, but it did not settle the argument that has followed this regime since day one. At present the payments sector bears the entire reimbursement cost, even though most scams begin on telecoms networks, social media and messaging platforms that pay nothing toward the bill. Critics, including parts of the industry, argue this treats the symptoms while leaving the source untouched. The PSR has signalled it will engage stakeholders over the summer of 2026 ahead of a formal consultation in December, and this all plays out as the PSR's functions fold into the FCA. For merchants the takeaway is simple: the protections are real today, but the funding model and the finer rules are still moving, so it is worth keeping an eye on how a business claim would be handled.

What UK merchants should do this week

You do not need a regulator to reduce your exposure. The most effective controls against authorised push payment fraud are procedural and cost nothing to introduce:

  • Verify every change of bank details: if a supplier emails new account details, confirm them by phone using a number you already hold, never one from the email itself.
  • Use Confirmation of Payee: check that the account name matches before you send, and treat any "no match" or "close match" result as a stop sign rather than a formality.
  • Require dual authorisation: for payments above a set threshold, insist a second person approves the transfer, which defeats most urgency-based scams.
  • Train the people who move money: finance and admin staff should know that pressure, secrecy and last-minute changes are the classic hallmarks of a scam.

These habits matter more as account-to-account payments grow. UK businesses are increasingly accepting open banking and Pay by Bank alongside cards, and while those rails are fast and low-cost, they settle in real time, so getting the payee right the first time is everything. Card payments carry their own fraud tooling such as 3-D Secure 2, but bank transfers rely far more on your internal discipline.

How Monek fits in

Monek is FCA-authorised in our own right (FRN 920628), and we help UK merchants take payments across cards, our Virtual Terminal, Pay by Link and account-to-account rails, with next-day settlement, blended pricing from 0.99% and a free WooCommerce payment gateway plugin as standard. We are happy to talk through how each payment method handles fraud and settlement, so you can accept money in the way that best fits your business without inheriting risk you did not expect. If you would like a straightforward conversation about your payment mix and a no-obligation rate comparison, our team will run the numbers and tell you candidly where you stand.