This episode of Follow the Money looks at the UK’s mandatory reimbursement rules for Authorised Push Payment (APP) fraud — introduced in October 2024 — and what the EU can learn as it builds its own reimbursement and intelligence-sharing framework. Host Dr Nicola Harding is joined by Kate Frankish, who led the UK’s Confirmation of Payee rollout as Chief Business Development Officer at Pay.UK, and Barnabás Ferenczi, Head of Growth at Salv, who works with banks and bank associations across Europe on cross-institutional intelligence sharing.

Scaling Confirmation of Payee: from 70 banks to 550

Nicola: Kate, before we get to the reimbursement rules themselves, can you give people a sense of scale? You took Confirmation of Payee from around 70 banks and PSPs to 550 in a single year. What does a jump like that actually take, and why did it matter for fraud prevention?

Kate: First, let me explain my role at that point. In 2022, 2023 and 2024 I was Chief Business Development Officer of Pay.UK, the payment scheme operator for all the non-card payment types in the UK. Part of that role was fraud prevention, and helping the participants of the schemes collaborate so we could get better fraud prevention wherever possible.

Confirmation of Payee was actually born six years ago, and it was first put in place for “fat fingers” — to stop misdirected payments, which was a large problem for banks. With real-time payments like Faster Payments, once you’ve sent the money, the person who’s received it isn’t obliged to give it back, even if they’re not a fraudster.

That was the main reason for Confirmation of Payee initially. But we discovered it helped with several types of APP fraud too — for example, where someone had changed a bank account detail to impersonate somebody else, and people were sending money to them. The biggest thing it does is add another step to setting up a payment. It makes the consumer stop and think, and puts a bit of grit in the system. Most APP fraud happens when fraudsters put consumers under stress and ask them to act quickly, so a moment of friction at the point of setting up a new payee matters.

Taking it from 70 banks and PSPs to 550 mattered because although 70 covered 97% of Faster Payments volume, the remaining 3% — the long tail of smaller organisations — had less money to invest in fraud controls, both AML and onboarding. Ensuring there was a standard everyone followed meant every bank in the UK could say: when you set up a new payment, we’ll do this check. It’s become a hygiene factor. If you don’t get the check, you notice something’s wrong — people won’t send money unless there’s a check in the process.

What changed on the Monday after reimbursement went live

Nicola: We moved on from that check to the actual reimbursement rules changing at the end of 2024. It didn’t go through uneventfully — there was pushback in the industry about potential unintended consequences. For anyone who only knows the headline: what actually changed the day it came in, and what was different for a bank on the Monday versus the Friday before?

Kate: This was a policy born out of the PSR — the Payment Systems Regulator. What they were trying to do was make sure everybody in the payment chain has skin in the game: the sending bank, and the receiving bank, which is often where the fraudster sits to disperse the money quickly. So the crux of the regulation was twofold — make sure both sides had liability, because that makes you act differently, and make sure victims were consistently reimbursed. In 2021, APP fraud in the UK hit £490 million, the first time non-card fraud exceeded card fraud.

Barnabás: And you already had instant payments at that time, right? In 2021?

Kate: Instant payments for 17 or 18 years in the UK — a long time. Starting at a policy level is fine, putting something down on paper is fine, but the practicality of putting it in place is far different. Pay.UK were given the challenge of turning those policy rules into the Faster Payments rules — the operational, practical rules to run a payment scheme. That was tricky for every participant.

The difference between the Friday and the Monday was significant, and the operational uplift was the hardest part. The policy had clarity: £85,000 is the limit that can be paid back, split 50-50 between sending and receiving bank. There are five days to solve the case — 35 if you stop the clock, but 35 is the absolute end game — and you can keep back up to £100 of every claim. Those were the key rules. But operationally: if I sit in a tiny bank, how do I know Bob from the fraud team at Barclays, his phone number, who I deal with, how we communicate quickly enough to deal with the case?

UK Finance, who represent most UK banks, already had a system for the voluntary scheme that existed before the regulation. Pay.UK also set up a communication and workflow system so every bank and PSP — even non-UK-Finance members — could use it. Participants had to pay for the build and for Pay.UK’s new regulatory reporting regime. Even large organisations with big fraud teams had to retrain staff and rebuild internal workflows. Some of the bigger banks who were already in the voluntary scheme found it was sometimes a cost saving, because the receiving bank was now paying 50% back. But getting everybody to collaborate was probably the hardest thing to do — and Europe will be in exactly the same position. Definitely a learning from Pay.UK: get everybody looking at operational processes upfront, and get experts from the banks themselves to lead some of the workstreams, because they deal with it day in, day out.

The UK’s head start on continental Europe

Barnabás: I wanted to express my admiration for what we’re discussing here — UK and continental Europe. The UK story was always a few years ahead. Fast payments came, as you said Kate, more than probably 14 or 15 years before it became mandatory in the EU last October. Then fraud exploded in the UK, and Confirmation of Payee followed. It’s the same story again and again — introducing fast payments without upping the defences, country by country. UK, but also Brazil, India, where it’s used for all kinds of payments every day. Now Europe is facing the same situation as instant payments becomes more typical, whether retail or B2B. It’s like building a very fast motorway without guardrails, and then trying to put them up after the fact.

Kate: There’s one country that’s actually learned the lesson — Payments Canada. I did some consulting for them last year. Their real-time rail isn’t quite live yet, but as they were building it, they built in a version of Confirmation of Payee and real-time transaction monitoring at the centre from the start. The whole point of what we’re discussing today is the benefit of data sharing — you can’t understand the patterns unless you see the full picture, and then you can’t stop more fraud.

Barnabás: And by the way, that’s also a nice side effect of Confirmation of Payee in the UK — it created a kind of communication between the two parties of a transaction that wasn’t there before. That’s not the full scale of data-sharing-based joint action, but it’s a step in the right direction: two banks having a system that checks both sides of the transaction.

Who absorbs the cost — and who doesn’t

Nicola: Any regime like this is costly, and we often talk about the burden falling on payment providers — the 50-50 split — but the transformation needed within a bank or PSP is huge. Rather than telcos and social media platforms, where a lot of the fraud originates, how do you think the industry feels about financial services taking the weight of this problem?

Kate: Pretty angry, generally — and quite rightly. It’s a hard problem, because not many countries are taking Meta to court, or bringing in strict regulation for the tech giants. That does need to change. In the UK, government is more involved now — there are ministers who look after fraud and financial crime, and more groups collaborating than ever before. There are more solutions looking at downstream signals from telcos and social media. I’m an optimist, but this will have to change, because fraudsters are very organised, global businesses. You’re never going to get in front of them, but even to keep up, you need the knowledge and the signals — and those come from data shared carefully, because everyone worries about privacy. My vision was always: imagine if all the payment system operators globally linked up so fraud could be traced and stopped, because fraud doesn’t stick to one jurisdiction.

Barnabás: That’s very much in line with the EU’s vision. The European Payments Council has a pragmatic view: let country-based information-sharing initiatives start or continue — some are already operational — and let Europe create an overarching layer that connects them without destroying what’s already there. The global vision will take longer, but it’s step by step. I wanted to ask you too, Kate, because you also advocate this should be cross-sectoral. There’s a notion on the continental side that we start with banks, because they’re so heavily and concretely regulated, and then broaden out. Do you follow that logic — should a country starting fresh begin with banks, then take on social platforms and others?

Kate: Yes. When it comes to the nitty-gritty of how that’s structured, it gets hard, but there’s definitely willingness to collaborate. We should learn from the card schemes — they have network-wide fraud detection capability globally, and they’re good at making sure data doesn’t leak. With any innovation, you should look at what’s already there and apply it to a new use case.

Barnabás: Absolutely. I spent some years in card payments before joining the crime fighters, and you’re right. A challenge is that instant payments in most countries is inherently a national, domestic initiative — in the EU you can call the Eurozone one domestic payment area. That’s why we start with the same market or jurisdiction covered by instant payments, with the long-term vision that eventually there’s not just cross-border within a market like the EU, but cross-regional too. One of the key corridors for that is EU-UK — and at Salv we’re already operating UK-EU cross-border data sharing at PII level, which is valuable given how much of a payments innovation powerhouse the UK is, which brings its own risks. For the EU, the EU-UK corridor should be the priority once we’ve got our own act together.

Kate: There’s a parallel — lots of global payment schemes are already setting up connections. Nexus in Asia, with Singapore, Malaysia and others joining their payment schemes so cross-border payments are cheaper and quicker. I can only see that growing across the globe. And it’s exactly the same kind of connections you’d want from a financial crime and fraud perspective.

Reimbursement makes victims whole. It doesn’t stop the harm.

Nicola: Starting with financial institutions means starting at the end of the problem. Before we move further upstream to data sharing, I want to spend a moment on reimbursement, because that became the big headline — the 50-50 split. It let us put a figure on the cost of fraud, without really examining the value of prevention. Reimbursement makes the victim whole — good — but it doesn’t stop the fraud, and it still leaves money moving from the system into criminals’ pockets. Given rules always create displacement — money mule accounts being one example — what did adaptation look like in practice? Was there a worry the rules had created their own workaround?

Kate: The biggest concern the UK industry had before the regulation went live was unintended consequences. If a consumer knows they’ll get their money back, and someone down the pub says “send this money to me, tell your bank it’s fraud, you’ll get it back, and I’ll give you 10% on top” — not everybody would do that, but there are people struggling financially for whom that looks like a victimless crime, because everyone thinks banks have the biggest pockets in the world. What people don’t realise is the cost comes back to them — it’s a cost to the country — and it’s normally funding other, genuinely horrific crime. New types of fraud are always emerging; fraud adapts to whatever the easiest route to money is in the shortest time. So the rules and the policy aren’t bulletproof — they’re part of the solution, not the full solution.

What really stuck with me: we had Action Fraud, run by the police, come and speak to the team developing fraud tools at Pay.UK. They explained the calls they get from victims and the lasting mental health harm — for romance fraud, you feel doubly duped, you’ve lost your savings, but you also believed you were in love with someone real, and you feel massively stupid and heartbroken at the same time. Whatever can be done further up the chain to stop the crime happening in the first place is where we need to get to. What can be done at the point where cashing out happens, so banks can stop more fraud and let real payments through without unnecessary friction — but further up the chain there needs to be more activity too, for a better solution overall.

Nicola: It’s a fully layered approach that’s needed — including the cultural awareness point. We can learn from card payment providers and schemes, who face chargebacks at a similar or growing level, sometimes dubbed “friendly fraud” — culturally, “I haven’t had a refund in a while, maybe I won’t pay for that takeaway, I’ll just say it was fraud.” Less so in the UK, but an emerging problem, especially where it’s made easy — in the US you can press a button in your banking app and get a chargeback done quickly. Wherever there’s a will there’s a way, and it’s not just about what fraudsters might do, it’s about what’s culturally acceptable and what isn’t. That spectrum runs right through to whether we reimburse victims or not.

Kate: There is, and there’s an education piece for consumers — lots of organisations are doing that well. But even as a savvy person, some of the ways APP fraud is committed today, like deepfakes, would catch you out. If I got a phone call from my daughter — thinking it was her — saying “I’ve been in a car crash, I’m using someone else’s phone, can you send me money, I’m stuck,” I’d do it, because I’d be worried about her.

Barnabás: There’s a scam for each of us, even for professionals. The EU is going to follow the reimbursement logic in a more constrained way, carved into the PSR from 2028 onwards. My assumption is that it will create a business case for investment in fincrime fighting — upping transaction monitoring, and for many countries, starting bank-to-bank, peer-to-peer data sharing and joint investigations for the first time. Do you already see that effect — beyond banks understandably complaining about the risk of reimbursement schemes — a wave of extra investment and attention to fraud mitigation?

The investment case, debanking risk, and collective intelligence

Kate: Yes — for the couple of years leading up to 2024 there was a lot of investment, because of the spike in fraud and the knowledge the regulation was coming. One challenge — and I see this now, working with a fintech — is making sure that when you’re onboarding a customer you’ve got strong AML and fraud checks at the start, without discriminating against consumers who don’t have six months of salary slips or an established financial footprint.

Barnabás: This is debanking.

Kate: Debanked people, yes. How do you balance that, so people can take part in a digital society — which everyone has to do to send and receive payments — without banking criminals? There’s appetite to invest in different tools; the challenge is getting to the right people in an organisation to explain it. There’s appetite not just for a one-off tool, but for something that learns and moves with the fraudsters, the way AI and machine learning do today, without needing heavy new integration every time.

Barnabás: That’s a great example with onboarding and debanking risk, because if tools get smarter — not just more powerful — banks can use collective intelligence when assessing riskiness at onboarding. That’s exactly one of the use cases we’ve run for years in our core North European market, where one bank can query whether a person being onboarded, or an existing customer under repeat due diligence, was already flagged by another bank as suspicious for money laundering or fraud — more than 200,000 queries so far. That’s smart defence: it likely increases the chances of catching bad actors without increasing the debanking problem for certain socio-economic groups. Defences need to be not just more powerful — more AI, more of everything — but smarter, using collective intelligence.

Nicola: Particularly with data sharing, we tend to think of it only at the point of payment, but ongoing or dynamic KYC is a really good moment too — those routine checks that should be happening anyway, shared with potentially linked accounts at other banks. Being able to share that intelligence at a random KYC check is really valuable, because of account takeovers and other MOs. I’ve always advocated for switching things up — making checks as random as possible, which is difficult in a rules-based environment, but that’s almost what you need to outstep the fraudsters. We can’t quite get there, but where that randomness exists, sharing it is a valuable source.

Barnabás: Our own statistics confirm the need for that kind of smart, collective action in the markets where we run joint screening — it puts banks in a difficult position if they’re fighting alone. That’s a clear learning from the markets where Salv operates.

The 2024 proof of concept: 50% more fraud detected

Nicola: Kate, I wanted to ask about the 2024 proof of concept — seven UK banks, three fraud prevention vendors, 13 months of Faster Payments data analysed in a three-month window, with almost a 50% uplift in detection. What can we learn from that, and what still stands nearly two years later?

Kate: We were trying to prove the hypothesis that more data means more fraud found. Realistically we knew that was true — it’s analytically the case — but you have to prove things. The hardest part was getting the data out of Vocalink, who operate the infrastructure behind Pay.UK, and safely to the vendors to test, under very strict rules the participating banks rightly wanted in place, because it’s their customers’ data. It did prove out: we used the data plus fraud flags the banks had applied, and the vendors ran their models and found around 50% more fraud than the banks’ current systems had detected. It’s a case that shows data sharing is needed to identify and stop more fraud.

The trouble with putting it into production was agreement on who could actually do that — what kind of company could all the UK’s payment providers trust to hold that much data securely. Masking PII has moved on significantly since then — I think Salv has solutions in that space — but what we were asking at the time was whether every UK participant would jump into one system that shared data centrally with a fraud prevention provider, passing signals back to add accuracy on top of what banks already had. The banks weren’t ready at that point. That’s not to say it hasn’t changed — there’ll be a solution that works that way. Visa and Mastercard have some real-time payment solutions for the market, and there are other interesting solutions, but in the UK nothing has taken off for the majority yet. Everyone’s buying their own.

Barnabás: In our experience, what helps solve that situation — where everyone agrees strategically but can’t move operationally, because it’s essentially a coordination problem, who connects all the players — is having an industry-level consortium builder or coordination agent. On the continental side it’s often the bank association that brings banks together, maybe not all of them at first, but the ones responsible for the majority of transactions, with a mandate from member banks to embark on the journey and select a platform. Most importantly, they develop the playbook and the consortium-level governance together with the platform partner and the banks — because I don’t see it as a technical challenge any more. The security layer, pseudo-anonymisation, these techniques have fulfilled GDPR’s data privacy requirements for years, if — and only if — the governance layer is designed the right way. It works most effectively with central coordination — not bottom-up, and I wouldn’t call it top-down either, but there’s a governance structure around it. We work with a number of European bank associations this way, and most of our discussions are around governance: how to use a standard fraud typology, how to implement data minimisation and retention constraints so GDPR requirements are met. The technical implementation, after that, is relatively straightforward.

From “data swamp” to infrastructure

Nicola: I remember being in rooms, more than once, talking about data sharing and proofs of concept, where the term used was “data swamp” — not a very attractive term, the idea that all our data sits in a swamp people can just pull from. It sounds messy and disorganised.

Barnabás: And very likely not GDPR-conformant on the EU side.

Nicola: Exactly. I think that’s the difference between how data sharing is talked about and imagined by the people in a position to make it happen. Terms like “data swamp” make it sound risky, something we don’t want to do. But flip it and think about data sharing as infrastructure — that’s how we secure things, with strong, robust frameworks, the way we think about critical infrastructure generally. “Data swamp” conjures an image; “infrastructure” means: how does it actually work? I think that’s the shift I’ve seen over the last year or two — from “we just can’t do this, it’s dangerous, it’s lurking in the shadows” to “okay, what does this actually look like.” Barnabás, walk us through intelligence sharing and how it can minimise data, and where it can’t. If we think of data sharing as infrastructure, and you can screen against real identifiers like IBANs — isn’t an IBAN personal data? — how do you make sure that infrastructure is safe?

Barnabás: Honestly, I don’t even like the phrase “data sharing,” because what ultimately matters is the joint action that banks can take together, or in the relevant pair on two sides of a transaction — data empowers that joint action. What matters is being able to act at the speed the use case demands. For joint screening of persons — flagging someone as suspicious for money muling, say — you need to act within seconds if it’s a digital onboarding process. For IBAN screening, you need to be within the time window of the instant payment transaction — milliseconds. For a joint investigation of a suspicious transaction, it shouldn’t take more than minutes, because after half an hour or an hour, the likelihood the bad guy starts layering the money and moving it further out is much, much higher.

So we set up data sharing to enable exactly these kinds of joint actions — and in our experience it’s possible even within the EU’s strict privacy rules, if you set it up with the right governance structure. Rather than shying away from the GDPR discussion and building expensive, complicated technical solutions that make joint action harder — or impossible — our recommendation is to deal with the GDPR question, but deal with it the right way: privacy designed in, with a governance layer at the level of the consortium of banks that clarifies, concretely, how data minimisation is implemented in the operational use case. For example, we design the fraud typology and interfaces so only the data agreed for a specific fraud scenario is shared — no more, no less. That’s GDPR compliance built in. And we pay attention to why fraud is a legitimate reason for data processing under GDPR — there’s a suspicion behind the joint investigation that triggers the data sharing, which avoids the “data swamp” story that led to a regulatory catastrophe in the Netherlands, where TMNL’s first-generation programme didn’t get the governance structure right and had to be stopped. We’ve run data-sharing-based joint action, like in Latvia and other countries, for five years, and never had a single regulatory backlash, because we designed in privacy from the beginning, and had regulators involved from the beginning.

Kate: Which is a good way to do it — get the regulators in the camp.

What the EU should take from the UK’s head start

Nicola: Kate, coming back to you: banks have to identify where funds went within five days, and the UK Finance fraud scheme is moving into Pay.UK so institutions can collaborate on cases. Is that collaboration infrastructure the real lesson for the EU — that reimbursement only works if you build the rails for banks to work together underneath it?

Kate: Definitely. I don’t see how you can work significant volumes of cases unless you’ve got a tool that lets you quickly and easily identify who to speak to at another organisation, and pass information securely between organisations to work the fraud within the timescales. There has to be some form of directory and workflow capability. If you think about Verification of Payee — VOP — it’s fundamentally a directory for Bank A to speak to Bank B when a customer sets up a payment. It’s the same logic here. Whether it’s regulatory- or rules-driven, there has to be a workflow that lets an operator at Bank A put the right information in to get a case moving quickly, and lets the operator at the other end understand what checks they need to do and what to give back. That’s a key learning — something we probably underestimated in the UK, how hard it would be to do, how much it would cost, and how long it would take. We did manage to hit the timescales, which is why I’ve got so much grey hair now.

Nicola: I’ll ask you both for one thought on the future. Kate, if you could tell the people who designed the UK scheme one thing before they started, what would it be?

Kate: The policy is fine, and the outcomes regulators want to deliver are fine. But unless you bring the operational impact to the front — what it will mean for everyone who has to adhere to the policy — everything ends up back-ended, difficult and problematic. Get experts from a selection of the affected organisations to help you with that work, because they know what it means day to day.

Nicola: And Barnabás — for the EU institution that wants to get ahead of this rather than react to it, what’s the best first move?

Barnabás: Take GDPR, and look properly at what it says about fraud being a legitimate reason for data processing. Get a mentor, an experienced supporter for the journey of enabling joint action, because waiting for the regulation to arrive slows you down, and fraud will keep growing in the meantime. Get ahead of the curve, get ready, and when the regulation lands, you’ll already be compliant from day one.


×
ISO/IEC 27001 logo
Aicpa logo
GDPR compliant logo
OWASP logo

We build security to our products and organisation from the start. We use security best practices (incl. ISO 27001, CIS etc.) to ensure that our security management system meets the highest standards.

Salv has an ISO/IEC 27001: 2022 certificate, as well as ISAE 3000 compliant SOC 2 Type 2 report.