PSR welcomes APP scam voluntary code

The Payment Systems Regulator (PSR) has welcomed a new voluntary industry code of good practice to protect people from Authorise Push Payment (APP) scams which will take effect from 28 May.

APP scams are where a fraudster tricks an individual consumer or micro business to instruct their payment services provider - such as their bank - to send money from their account to an account controlled by that fraudster.

At the beginning of 2018, the PSR set up a dedicated steering group, made up of consumer representatives and the industry, to design and implement a code that would work for everyone.

The development and subsequent implementation of the code follows significant work by the steering group, completed within the ambitious timeframe driven by the PSR. This looked to understand the scale and technicalities of the problem, along with setting out how to prevent these types of scam from happening in the future and reimburse victims if they do nothing wrong.

The regulator said the code reflects its continued strong belief that if somebody has done everything they can reasonably do to protect themselves, they should be reimbursed – so even if blame can’t be attributed to either the consumer or the banks, consumers will be reimbursed.

In a further move, the banks have agreed to fund an initial contribution to reimburse victims in the no-blame scenario as an interim measure, until the final long-term funding arrangements are put in place from January 2020. The PSR promised to keep the progress of this under close review.

PSR managing director Hannah Nixon said: “The code is a testament to the significant work that has gone into protecting people from APP scams, it shows that by bringing together consumer and industry representatives, very positive outcomes can be achieved.

“We’re particularly pleased that the steering group has been able to navigate and agree a way to reimburse victims when neither victim nor bank has done anything wrong – this was a tough issue that rightly involved much discussion, but the banks have done the right thing for their customers in backing this measure.

The final code will be implemented on 28 May, at which point the protections and standards will be implemented by banks and other payment service providers.

    Share Story:

Recent Stories


Sanctions evasion in an era of conflict: Optimising KYC and monitoring to tackle crime
The ongoing war in Ukraine and resulting sanctions on Russia, and the continuing geopolitical tensions have resulted in an unprecedented increase in parties added to sanctions lists.

Achieving operational resilience in the financial sector: Navigating DORA with confidence
Operational resilience has become crucial for financial institutions navigating today's digital landscape riddled with cyber risks and challenges. The EU's Digital Operational Resilience Act (DORA) provides a harmonised framework to address these complexities, but there are key factors that financial institutions must ensure they consider.

Legacy isn’t the enemy: what FSIs can do to keep their systems up and running
In this webinar we will examine some of the steps FSIs have already taken to rigorously monitor and test systems – both manually and with AI-powered automation – while satisfying the concerns of regulators and customers.

Optimising digital banking: Unifying communications for seamless CX
In the digital age, financial institutions risk falling behind their rivals if they fail to unite fragmented communications ecosystems to deliver seamless, personalised customer experiences.

This FStech webinar sponsored by Precisely explores vital strategies to optimise cross-channel messaging through omnichannel orchestration and real-time customer data access.