PSR Data Shows Over 300,000 APP Fraud Claims Reimbursed Since Mandatory Rules Began

Payment Systems Regulator data for the first quarter of 2026 shows claim volumes under the UK's mandatory authorised push payment fraud reimbursement scheme have stayed steady, with most claims resolved within five business days.

PSR Data Shows Over 300,000 APP Fraud Claims Reimbursed Since Mandatory Rules Began

The Payment Systems Regulator's (PSR) latest reimbursement dashboard shows 86,500 authorised push payment (APP) fraud claims fell within the scope of the UK's mandatory reimbursement rules in the first quarter of 2026, of which around 58,400 were reimbursable. Since the regime began on 7 October 2024, total in-scope claims have reached 438,000, with just over 301,000 of those reimbursed. The PSR published the figures as part of its ongoing quarterly reporting on how the scheme is performing across UK payment service providers.

How the reimbursement rules work

Under rules the PSR and the Bank of England introduced on 7 October 2024, payment service providers must reimburse most victims of APP fraud sent over Faster Payments or CHAPS, up to a maximum of £85,000 per claim. The cost is split 50/50 between the sending firm and the receiving firm, a structure the PSR designed specifically so that both ends of a fraudulent payment carry a financial incentive to prevent it, rather than leaving the burden entirely on the bank the victim happened to use. Firms are required to resolve claims within five business days unless they can show the customer acted with gross negligence, and victims have up to 13 months from the date of the last relevant payment to submit a claim.

The PSR's Q1 2026 data shows 82% of claims were closed within that five-day window, a rate the regulator says has stayed broadly stable over the past twelve months, aside from a dip recorded in the third quarter of 2025. Claim volumes themselves rose during the first 13 months after the rules took effect before levelling off, according to the regulator, which it interprets as the scheme reaching a steady state rather than continuing to climb as awareness spread. Not every claim that falls within scope ends up reimbursed — the PSR's compliance data reporting standards list several grounds for rejection, including cases the regulator classifies as civil disputes rather than fraud.

An independent review is under way

The PSR published the results of a separate 2025 APP fraud survey on 18 November 2025, which concluded that the reimbursement requirement is having a positive effect, with a consistently high proportion of victims reimbursed across a wider range of payment providers than before the rules took effect. The regulator noted that shared liability between sending and receiving firms appears to be encouraging more collaboration between institutions on fraud prevention, rather than each firm treating it purely as the other side's problem. Alongside that survey, the PSR commissioned an independent review of the reimbursement requirement's overall effectiveness, with a report expected by the second quarter of 2026.

In May 2025, the PSR had already published an interim "snapshot" covering the first several months of the policy, describing how payment providers had adjusted their systems and processes and what impact those changes were having on victims. The consolidated policy statement that followed, PS25/5, addressed a range of frequently asked questions from firms implementing the rules, covering areas such as how claims interact with existing fraud-prevention obligations and how firms should handle disputed cases. Firms operating Faster Payments and CHAPS remain subject to the same core structure — the £85,000 cap, the 50/50 cost split, and the five-day resolution target — regardless of what the ongoing independent review eventually concludes.

What falls outside the scheme

The reimbursement requirement applies specifically to Faster Payments and CHAPS transactions; it does not extend to fraud involving international transfers, card payments or cash. It also does not cover every Faster Payments transaction automatically — claims must meet the PSR's definition of an authorised push payment scam, meaning the victim was deceived into authorising the payment themselves, as opposed to cases where a fraudster gained unauthorised access to an account and moved funds without the victim's knowledge, which fall under separate unauthorised-fraud protections instead. That distinction has been one of the more contested aspects of the scheme among consumer groups since the rules were first proposed, since establishing which category a given loss falls into is not always straightforward from the victim's side of the transaction.

The £100 excess, and who is exempt from it

Sending firms are permitted to apply an excess of up to £100 to a reimbursable claim, a mechanism the PSR confirmed in its December 2023 policy statement and described as a way to encourage customers to stay cautious when making payments, reducing the risk that reimbursement removes any incentive to be careful. A firm can choose to apply the full £100, a lower amount, or waive the excess altogether — but if it applies less than the maximum, it cannot recover the shortfall from the receiving firm as part of the 50/50 cost split. Any future change to the £100 figure requires a separate PSR review; it does not rise automatically with inflation.

Vulnerable customers are exempt from the excess entirely, and the PSR has been explicit that this is not a blanket category assigned by age or a fixed checklist. Firms are expected to make a case-by-case assessment of whether a customer's particular circumstances, whether temporary or ongoing, contributed to them being defrauded, rather than applying a single definition of vulnerability across every claim. The same case-by-case approach applies to a related part of the framework, the consumer standard of caution, which sets out threshold levels of caution a customer is expected to have exercised — falling short of that standard can be grounds for a firm to deny reimbursement, but the exception does not apply where a customer is assessed as vulnerable.