Authorised Push Payment fraud happens when someone deceives another person into transferring money away from their own account, and into an account controlled by the fraudster.
It can happen to individuals or businesses. For example, in the case of World Proteins Kft v Persons Unknown [2019] EWHC 1146 (QB), the company received two genuine invoices and a string of genuine emails about outstanding payments. The email account of the supplier was hacked, and fraudulent emails were sent to the company claiming that the bank details had been updated. The company was tricked into sending the money into the fraudsters account. See our article about the case here.
This type of scam is not uncommon, and businesses should always make enquiries if a supplier or a regular contact claims to have updated their bank details.
Another example from an individual’s perspective, is the case of Philipp v Barclays Bank UK PLC [2023] UKSC 25, which went all the way to the Supreme Court. The fraudsters said they were helping an investigation into fraud at Dr Philipp’s bank, and their money would be safe if they transferred it away. The Philipps lost £700,000 by following the instructions and unwittingly transferring their funds to the fraudster’s bank.
With this type of fraud becoming more widespread, banks and financial institutions have been under pressure to find more effective ways of preventing it.
New scheme now in effect
Back in 2019-2020, there was a voluntary code for banks to follow. Read our article about it here. However, as it was only voluntary, payment service providers were not obliged to follow it. There were inconsistencies between the ways that different banks applied the code, which led to some uncertainty and unfairness for consumers.
Since 7 October 2024, the Payment Systems Regulator has introduced a new scheme of mandatory reimbursement. The details of the scheme were set out in the Financial Conduct Authority’s open letter to banks and building societies about their expectations on APP fraud reimbursement. This letter is known as the ‘Dear CEO’ letter, and can be found here.
Payment service providers must now refund these types of APP frauds within five days. The maximum compensation is £85,000, so there’s no guarantee of recovering compensation for stolen funds above that threshold. But it is expected that this limit will cover the majority of APP frauds.
If a consumer has lost more than £85,000, then there is an additional route available to recovery. They can lodge a claim with the Financial Ombudsman Service (FOS), who may be able to provide compensation. The FOS’s limit is £430,000.
What it means for payment service providers
The new requirement for reimbursing victims of APP fraud applies to all participants in the Faster Payments Scheme that provide ‘relevant accounts’ to customers in the UK. ‘Relevant accounts’ are those operated by a payment service provider in the UK, which can send or receive payments using the Faster Payments scheme. Notably, accounts provided by Credit Unions, Municipal Banks, and National Savings Banks are excluded.
The majority of APP fraud happens within the Faster Payments scheme, but there are also increased protections around CHAPS payments.
Under the new rules, payment service providers must reimburse victims of most APP fraud in transactions between banks, unless the client has helped to commit the scam, or the client acted with gross negligence.
Any refund must be paid within five days. Once it has provided the refund, the payment service provider can claim half of the money back from the financial institution that the fraudster used to receive the stolen money. That way, the sending and receiving firms split the cost of reimbursing victims in a 50/50 division.
While the victim should receive reimbursement within five days, there are ‘stop the clock’ provisions, if the sending payment service provider requests more information. Time can be extended slightly in this way so that the payment service provider has all the information it needs to make an informed decision.
Practical application for payment service providers
In practical terms, payment service providers must make sure that they (i) are taking action to prevent accounts from being used to receive proceeds of fraud or financial crime and (ii) have notified their customers of their rights.
Payment service providers should be completing the following tasks:
- Update your terms and conditions
Incorporate a clause that states that you will reimburse customers in line with the reimbursement requirements and rules. - Notify existing customers of their rights under the reimbursement requirements
This should have been done by 7 October 2024. - Improve onboarding processes
Apply rigorous identity checks and stringent Customer Due Diligence to new customers. - Monitor transactions
For any unusual activity.
What it means for victims of APP fraud
The mandatory reimbursement requirement means that consumers and small businesses will have greater protections. They will have a straightforward route to recovering funds that have been duped away from their accounts. This is a positive step to protect cashflow.
However, customers have some responsibility to act reasonably and they are subject to an express standard of care. Consumers are not entitled to mandatory reimbursement if they have acted fraudulently, or acted with gross negligence (unless the customer is vulnerable).
The Payment Systems Regulator has published guidance on this, which essentially comprises four key points:
- Consumers must adhere to any intervention by the payment service provider.
- Consumers must report the fraud promptly (no later than 13 months after the last payment was authorised.
- Consumers must respond to requests for information from their payment service provider and co-operate with the investigation.
- Consumers must consent to the payment service provider sharing their details with the police.
Payment service providers also have the option of applying a claim excess of up to £100 in order to encourage customer vigilance.
Opinion
The mandatory reimbursement requirement offers enhanced protection to consumers and victims of APP fraud. The requirement also balances the risk between payment services providers and consumers. Consumers must act reasonably, and payment service providers split the reimbursement between sending and receiving banks.
There has been some criticism of the cap being too low, and previously it was expected to be at £415,000. However, the head of PSR, David Geele, says that the £85,000 cap will cover 99% of claims.
Overall, the regulations should bring a welcome consistency to the way payment service providers handle instances of authorised push payment fraud. It encourages the payment service providers to tighten up their systems and controls to reduce the risk of fraud, and makes the financial system more savvy to catching fraudsters.
