APP Fraud Reimbursement: A UK CFO's 2026 Action Checklist | INFORMD Executive Briefing

APP Fraud Reimbursement: A UK CFO’s 2026 Action Checklist

UK CFOs should treat Authorised Push Payment (APP) fraud reimbursement as a treasury and compliance priority in 2026, not a payments-team issue: the Payment Systems Regulator’s (PSR) mandatory reimbursement rules, combined with its planned consolidation into the FCA, are reshaping who carries liability when push payment fraud hits your business.

Since October 2024, PSPs have had to reimburse eligible APP scam victims up to £85,000 within five business days of a claim, funded through shared liability between sending and receiving banks. That regime is now under independent review, HM Treasury has confirmed the PSR will be folded into the FCA through primary legislation in the 2026/27 parliamentary session, and the fraud numbers driving all of this are still moving in the wrong direction for businesses. CFOs who treat this as “the bank’s problem” are exposed on two fronts: as a fraud victim with only partial reimbursement protection, and as a regulated or soon-to-be-regulated payment entity if their business touches payment services at all.

What is the UK’s APP fraud reimbursement regime, and why does it reach beyond the payments team?

The PSR’s mandatory reimbursement requirement replaced the voluntary Contingent Reimbursement Model Code, making refunds compulsory for in-scope payment service providers rather than discretionary. Liability is now split roughly 50/50 between the sending and receiving PSP, which has forced banks to tighten fraud controls, delay high-risk payments, and, in some cases, push friction back onto corporate customers through additional verification steps. According to UK Finance’s Annual Fraud Report 2026, APP fraud losses rose 19% year-on-year to £576.4 million in 2025, with £75.6 million of that in business losses — money typically not covered by the consumer-focused reimbursement cap. For finance functions running high volumes of supplier payments, payroll, or treasury transfers, that gap is the exposure that matters.

Executive Action:

  • Confirm with your banking and payments providers whether your business accounts fall inside or outside the reimbursement scheme’s consumer protections.
  • Quantify last year’s push payment fraud losses (invoice fraud, CEO fraud, supplier redirection) as a baseline for board reporting.
  • Route findings through your existing risk register rather than treating this as a standalone payments issue.

Is your business protected the same way as consumers under the reimbursement rules?

No — and this is the point most finance teams miss. The PSR’s reimbursement requirement was designed primarily around consumer and micro-enterprise protection, with the £85,000 cap and standard excess provisions calibrated for retail scam victims. Larger corporates sending high-value supplier or payroll payments sit in a greyer zone, often relying on contractual terms with their bank rather than a statutory guarantee. That matters because purchase scams and invoice redirection fraud — the categories most likely to hit a finance function — accounted for 71% of all APP fraud cases in 2025, with losses up 20% to £118.1 million. A CFO who assumes the bank will simply refund a diverted supplier payment is making a costly assumption.

Executive Action:

  • Ask your relationship bank directly, in writing, what reimbursement terms apply to your specific account tier.
  • Review supplier bank detail change processes — callback verification should be mandatory, not best-practice guidance.
  • Check whether cyber or crime insurance cover has been updated to reflect the new reimbursement landscape, rather than pre-2024 assumptions.

How does the PSR’s move into the FCA change compliance obligations in 2026?

HM Treasury’s April 2026 package confirmed that payment services and e-money regulation will be integrated into the FCA’s FSMA 2000 framework, with the PSR’s core functions absorbed rather than run as a standalone regulator. For CFOs of fintechs, e-money institutions, or any business holding a payment services licence, this means a single supervisory relationship, a single rulebook direction, and — in the transition period — genuine uncertainty about which guidance takes precedence. For everyone else, it signals that fraud and payments risk is being pulled more tightly into mainstream financial regulation, which typically means more scrutiny, not less, over time. Firms that treat this as a legal-team footnote will be reacting in 2027 instead of preparing now.

Executive Action:

  • If regulated by the PSR, map current obligations against known FCA supervisory expectations to identify gaps early.
  • Assign one senior owner (typically CFO or CRO) for tracking the consolidation legislation through the 2026/27 parliamentary session.
  • Brief the audit or risk committee now — do not wait for the primary legislation to land before raising it at board level.

What should CFOs put in place before the 2026/27 reimbursement review reports?

The PSR’s independent review of the reimbursement regime, launched in October 2025, is due to report findings during the 2026/27 annual plan year. Early signals are mixed: reimbursement has changed bank behaviour on the Faster Payments rail specifically, but overall APP losses across all channels are still climbing, driven largely by investment fraud, which rose 40% year-on-year to £221.5 million in losses. That divergence — narrower losses where reimbursement bites, wider losses everywhere else — is likely to shape whatever changes follow the review, including possible extensions of protection or adjusted excess thresholds. CFOs who build monitoring now will not be caught flat-footed by a rule change mid-year.

Executive Action:

  • Set a quarterly fraud-loss and near-miss tracking cadence, distinct from general cyber incident reporting.
  • Pressure-test payment authorisation controls against investment-fraud and impersonation scam patterns, not just invoice fraud.
  • Calendar the PSR review’s expected reporting window and pre-brief the board on likely scenarios rather than waiting for the outcome.

None of this requires a new department or a large budget line. It requires the CFO to own a risk that currently sits, uncomfortably, between the payments team, the bank relationship, and the risk committee — and to make sure it does not fall through the gaps between them. INFORMD’s executive self-assessment tools and capital and technology review templates can help structure that first conversation with the board. For context on the treasury side of this shift, see our earlier briefing on digital treasury and programmable payments.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).

Frequently Asked Questions

What is APP fraud reimbursement in the UK?

It is the Payment Systems Regulator’s mandatory requirement, in force since October 2024, for payment service providers to reimburse eligible Authorised Push Payment scam victims up to £85,000, with liability split between sending and receiving providers.

Does APP fraud reimbursement cover business bank accounts?

Coverage varies. The scheme was built primarily around consumer and micro-enterprise protection. Larger businesses often depend on contractual terms with their bank rather than a guaranteed statutory reimbursement, so CFOs should confirm terms directly with their provider.

Is the Payment Systems Regulator being abolished?

Its core functions are being consolidated into the FCA under HM Treasury’s April 2026 package, integrating payment services and e-money regulation into the FSMA 2000 framework. This will proceed through primary legislation in the 2026/27 parliamentary session.

How much has APP fraud cost UK businesses?

According to UK Finance’s Annual Fraud Report 2026, APP fraud losses reached £576.4 million in 2025, up 19% year-on-year, with £75.6 million of that in business losses across 248,070 recorded cases.

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.

Similar Posts