Onfido competitors

PSD3 and the EU Payment Services Regulation: What the New Anti-Fraud Rules Mean for Identity Verification

Table of Contents

Key Takeaways

  • The EU is replacing PSD2 with a two-part package: a directive covering licensing and supervision, and a directly applicable regulation covering conduct, security, and fraud.
  • Parliament and Council reached political agreement in November 2025. Formal adoption looks more likely around 2026, with full application following the transition period around 2028.
  • Verification of Payee becomes mandatory for all credit transfers, free of charge to consumers, extending an obligation that already applies to euro instant transfers.
  • Refund rights expand to cover impersonation and spoofing fraud, shifting liability toward providers and away from customers.
  • Providers gain explicit backing to assess fraud risk earlier in the customer journey using behavioral and contextual signals rather than payment stage challenges alone.

You get a call. The number on the screen belongs to your bank. The caller knows your recent transactions and says suspicious activity has been detected, so the money must move to a safe holding account immediately. You open your banking app and authorize the transfer, passing every authentication step correctly, because you’re the account holder and the process works.

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

The money lands in an account at a different institution. That account was opened five weeks earlier using a document that was never real. Who ends up paying?

Under current rules you, the customer, usually absorb that loss, because the transfer was authorized. The new EU payments package changes that, and in doing so, it changes who carries the cost of weak identity verification. This fraud succeeded because of three failures: the impersonation, the transfer, and the receiving account. The new rules address all three, and the third gets the least attention.

What Are PSD3 and the Payment Services Regulation?

The European Commission proposed replacing PSD2 in June 2023, splitting the framework in two.

The payment services directive 3 governs authorization, licensing, and supervision of payment institutions. As a directive, each member state writes it into national law, which allows limited local variation.

The payment services regulation governs conduct: security requirements, Strong Customer Authentication, fraud prevention duties, and consumer rights. As a regulation it applies directly and identically in every member state with no national transposition, which is the point. Fragmented implementation of PSD2 across 27 markets is exactly what this structure exists to prevent.

Both instruments matter for fraud prevention, but the regulation carries most of the operational obligations. That is the document your fraud and onboarding teams will spend their time on.

What Changes from PSD2 to PSD3

PSD2 dates from 2015, and the market it was written for no longer exists.

  • A single licensing category. Electronic money institutions become a category of payment institution rather than a separate license, with stricter requirements for providers issuing e-money.
  • Access for non-bank providers. Non-bank providers gain clearer rights to access payment systems and bank accounts, with safeguards against unjustified refusals. Member states must implement these provisions within six months of final publication, ahead of the rest of the package.
  • Wider scope. Obligations extend to technical service providers supporting payment services, not only institutions holding the customer relationship.
  • Harmonized enforcement. Penalties for failing to meet fraud prevention standards are standardized across the bloc.
  • Authentication that adapts. SCA rules change to allow both factors from the same category, so a customer without a smartphone or usable biometrics is not locked out. Providers also take on a duty to make authentication accessible to users with disabilities and older users.

That last point reads like a minor accessibility provision. It is not. It signals a regulatory preference for risk assessment that does not depend on challenging the customer at the moment of payment.

The New Anti-Fraud Controls and Their Identity Verification Implications

Four changes carry direct consequences for how customers are verified.

Verification of Payee. A mandatory check that the payee IBAN matches the account name, for all credit transfers, free to consumers, with refund rights where the service fails. The obligation already applies to euro instant credit transfers under the Instant Payments Regulation. It’s worth being precise about what this check actually catches: it confirms that a name matches an account, not that the account was opened with a genuine document in the first place. The operational consequence is narrower but still real. It raises the value of capturing and verifying a customer’s legal name correctly at onboarding, since a wrong or inconsistent name is what surfaces as a mismatch, not the underlying fraud that got the account opened to begin with.

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

Expanded refund rights. Customers losing money to impersonation fraud, where a fraudster poses as bank staff, can reclaim funds from their provider subject to conditions including prompt notification and a police report. Once providers absorb those losses, the economics of the receiving account change. A mule account stops being somebody else’s problem.

Earlier risk assessment. The framework supports assessing fraud risk before the point of payment using behavioral analysis and contextual signals such as interaction patterns and typing behavior, rather than relying on step up challenges. This provision most directly rewards continuous monitoring over a single check at account opening.

Customer awareness obligations. Providers must run programs educating customers on fraud risks and safe payment practices.

Together these assume an institution knows who holds each account and can tell when something about a session has changed. Firms treating verification as a gate cleared once at signup will struggle to satisfy that assumption. Our overview of the key components of KYC covers where these obligations already overlap.

The Timeline: What to Expect Through 2026 and Beyond

  • June 2023. The Commission publishes both proposals.
  • April 2024. The European Parliament adopts its position.
  • June 2025. The Council adopts its position, opening trilogue negotiations.
  • November 2025. Parliament and Council reach provisional political agreement.

What remains is formal adoption, publication in the Official Journal, and a transition period before the rules bite. Adoption looks more likely around 2026 than the previously expected 2027, with application following the transition period around 2028. As with much EU legislation moving through trilogue, these dates continue to shift as the process plays out, and even the Commission’s own projections have moved more than once.

With adoption landing around 2026, the two years that follow before application in 2028 are the preparation window, not a compliance deadline in themselves. The obligations taking longest to build, meaning fraud signal infrastructure, onboarding data quality, and continuous rather than periodic account monitoring, are precisely the ones that cannot be assembled in the final quarter before application.

What PSD3 Means for Banks, Fintechs, and IDV Providers

For banks, the liability shift is the headline. Absorbing impersonation losses makes both ends of a transfer a commercial concern rather than just the outbound side. Name matching at scale also exposes weakness in identity data captured at onboarding, since a mismatch only means something if the name on file was verified properly to begin with.

For fintechs and payment institutions, license consolidation and improved system access are genuine upside, arriving alongside conduct obligations previously applied unevenly. Firms that grew under lighter national readings of PSD2 will feel the harmonization most. Standardized penalties also change how a thin onboarding process looks to a supervisor.

For identity verification providers, demand moves from document checking toward continuous risk assessment. A psd3 regulation package that explicitly favors pre-payment behavioral risk scoring favors verification that persists after the account opens. It also raises the bar on accuracy, because mandatory free consumer services do not tolerate high false positive rates.

None of this displaces existing due diligence duties. The eu anti-fraud regulation framework sits alongside anti money laundering obligations rather than replacing them, so firms should map the two together rather than sequentially. Our guide to KYC regulations sets out that baseline.

Book a Demo

Give your business the boost of a fully automated, KYC process. No geographical limits and fast, frictionless onboarding verification processes enhance customer’s experience. 

FAQs

What is the difference between PSD3 and the Payment Services Regulation?

The directive covers licensing, authorization, and supervision of payment institutions, and each member state must transpose it into national law. The regulation covers conduct, security, Strong Customer Authentication, fraud prevention, and consumer rights, and applies directly across the EU without transposition, reducing divergence between markets.

When will PSD3 be fully applicable in EU member states?

Political agreement was reached in November 2025, and formal adoption looks more likely around 2026. A transition period reported at roughly 21 months follows adoption, putting full application at around 2028. Access provisions for non-bank providers carry a shorter six month implementation deadline. As with most EU legislative timelines still in process, these dates may continue to shift.

What is Verification of Payee and how does it work?

Verification of Payee checks that the account name a payer enters matches the name registered against the payee IBAN, then warns the payer of any mismatch before the transfer completes. It's a name to account match, not a check on how the receiving account was originally opened. It becomes mandatory for all credit transfers and must be free to consumers, with refund rights where the service fails.

Does PSD3 affect non-EU payment service providers?

The rules cover EU member states and EEA countries and do not automatically extend to the United Kingdom or other third countries. Non-EU providers serving EU customers or operating EU authorized entities will still be affected in practice, and should treat the framework as applying to their European operations.

How does PSD3 relate to AMLA's KYC requirements for payment institutions?

They operate in parallel. The payments package governs fraud prevention, authentication, and consumer liability, while the anti money laundering framework governs customer due diligence and ongoing monitoring. Both rely on the same underlying identity data, so firms benefit from mapping them jointly, as covered in our AMLA RTS KYC benchmark analysis.

You may also like