TL;DR: PSR and PSD3 will reshape fraud prevention, liability, and strong customer authentication across European payments, with PSPs expected to add verification of payee, behavioural monitoring, fraud data sharing, and broader SCA options, according to OneSpan. The regulatory shift moves security decisions closer to transaction context, not just user authentication.
At a glance
What this is: This is OneSpan’s analysis of the EU’s PSR and PSD3 political agreement, which tightens fraud controls, liability allocation, and strong customer authentication for payment flows.
Why it matters: It matters because payment-security and IAM teams will need to treat authentication, transaction monitoring, and fraud decisioning as a single governance problem rather than separate controls.
Context
The central governance gap is no longer just whether a user authenticated correctly, but whether the payment context itself is trustworthy enough to permit execution. PSR and PSD3 push European payment providers toward stronger fraud detection, verification of payee, and liability-backed control decisions in digital banking.
For identity and access teams, that matters because strong customer authentication is only one layer in the control stack. The article shows a regulatory move toward combining login assurance with behavioural and environmental signals, which changes how organisations should think about payment authorisation, step-up checks, and fraud containment.
Key questions
Q: What breaks when verification of payee is not in place for credit transfers?
A: Without verification of payee, the payer’s PSP has no structured control to compare the stated beneficiary name with the IBAN before execution. That leaves social engineering fraud much easier to complete because the warning happens too late or not at all. In regulated payment flows, the control gap becomes both a fraud exposure and a liability issue for the provider.
Q: Why do behavioural and device signals matter more as fraud becomes more automated?
A: Behavioural and device signals matter because automated attacks can mimic static credentials but struggle to reproduce real interaction patterns, device characteristics, and network behaviour consistently. When organisations rely only on one-time codes or basic checks, they leave gaps that agentic AI driven fraud can exploit. Continuous signal analysis makes impersonation harder and improves detection across the session.
Q: What are the signs that a payment fraud monitoring model is too weak?
A: Common warning signs are excessive false positives, missed suspicious transfers, overreliance on authentication events, and alerts that are so frequent users ignore them. If the model cannot explain why it blocked or allowed a transaction, it will be difficult to defend operationally or regulatorily.
Q: Who is accountable when a PSP fails to stop authorised fraud?
A: Under the article’s summary of PSR and PSD3, accountability can shift to the PSP when it fails to use VoP properly, fails to monitor transactions, or does not block suspicious activity. If the provider’s controls were not applied correctly, liability is no longer just a customer issue.
Technical breakdown
Verification of payee as a control on transaction intent
Verification of payee, or VoP, compares the beneficiary name and IBAN before a credit transfer is executed. In the model described by the article, that control is designed to catch social engineering and beneficiary substitution before funds move. It does not stop every fraud attempt, because a victim can still override a warning or ignore repeated alerts. The architectural point is that VoP introduces a second trust check at the transaction layer, separate from the authentication layer, so payment risk is evaluated against the stated recipient, not just the logged-in account.
Practical implication: treat VoP as transaction-level authorisation support, not a substitute for authentication or customer education.
Behavioural and environmental signals in fraud monitoring
The article says PSPs are expected to expand transaction monitoring with environmental and behavioural intelligence. Environmental signals include device state, malware presence, remote-access tools, and whether a device is active during a banking session. Behavioural signals cover typing cadence, screen-touch patterns, and operation speed, which can reveal coercion or abnormal interaction. This is not the same as classic login telemetry. The model shifts from proving who authenticated to judging whether the session behaviour matches the normal payer pattern and whether the device environment suggests manipulation.
Practical implication: integrate device and behaviour telemetry into fraud models before relying on block or step-up decisions.
How PSR changes fraud liability and control accountability
The liability model in the article is as important as the technical controls. If fraud occurs and the PSP failed to use VoP correctly, failed to monitor transactions, or failed to block a suspicious transaction, liability can shift to the PSP. That creates a governance loop between control quality and financial exposure. In practice, this means monitoring accuracy, warning logic, and false-positive thresholds are not just operational metrics. They become part of an evidentiary trail showing whether the provider used the controls the regulation expects.
Practical implication: align fraud monitoring evidence, alert handling, and exception review with liability attribution and audit readiness.
Breaches seen in the wild
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
PSR and PSD3 move fraud governance out of the authentication silo. The article shows that payment risk can no longer be managed by strong customer authentication alone, because APP fraud succeeds after legitimate login through social engineering and manipulation. That means transaction context, beneficiary validation, and session behaviour become part of the identity decision. For practitioners, the control boundary is now the full payment journey, not the sign-in event.
Behavioural monitoring is becoming a governance signal, not just a detection signal. The regulatory direction described here ties device intelligence and payer behaviour to fraud decisions. That is material because it turns telemetry quality into a control question: if the data are noisy, stale, or easy to evade, the monitoring control becomes hard to defend. Practitioners should treat behavioural signals as policy inputs with evidentiary value, not as soft analytics.
Verification of payee creates a new friction point between customer protection and user experience. The article makes clear that warning fatigue can erode VoP effectiveness if alerts fire too often or are easy to dismiss. That means fraud teams must govern the warning threshold, not just enable the feature. In practice, the important question is whether the control changes user behaviour at the moment of risk.
Liability is now part of the control design conversation. Once a PSP can be held liable for failing to use VoP, monitor transactions, or block suspicious payments, control coverage becomes financially material. That changes prioritisation across fraud, IAM, compliance, and operations because weak control calibration is no longer just a security issue. It is an exposure model that can be measured, challenged, and litigated.
Named concept: transaction-context identity assurance. PSR and PSD3 push identity governance toward a model where authentication proves access, but transaction controls prove legitimacy. That distinction matters across payments, banking apps, and other regulated digital services because authorisation decisions now need to incorporate recipient validation and behavioural evidence. Practitioners should design around the transaction, not around the login alone.
From our research library:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
What this signals
Transaction-context identity assurance: PSR and PSD3 push payment governance beyond sign-in checks and into the conditions surrounding each transfer. That shift matters because fraud can succeed after authentication, so the decisive question becomes whether the beneficiary, device, and session all still look legitimate at the moment of payment.
Fraud controls will increasingly need to balance warning quality with user behaviour. If alerts become too noisy, customers will ignore them, which turns a control into background noise and weakens both prevention and accountability.
For regulated payment providers, the practical challenge is to prove that monitoring, warning, and blocking decisions were applied consistently enough to stand up to dispute and liability review.
For practitioners
- Strengthen verification of payee governance Map every credit-transfer journey to where name and IBAN matching is performed, how discrepancies are surfaced, and who can override the warning.
- Incorporate device and behaviour telemetry Feed remote-access tools, malware indicators, typing cadence, touch patterns, and session timing into fraud detection models so they can distinguish normal use from manipulated activity.
- Reassess false-positive thresholds for blocking Review the conditions under which suspicious payments are blocked so the model is defensible, actionable, and aligned to the liability exposure described in the regulation.
- Align fraud evidence with accountability records Preserve monitoring outcomes, VoP warnings, and exception decisions in a way that supports audit review and liability attribution if a payment is challenged.
Key takeaways
- PSR and PSD3 expand fraud governance beyond login security by tying payment authorisation to transaction context, beneficiary validation, and session behaviour.
- The article shows that providers may face liability when VoP, monitoring, or blocking controls are misapplied or absent, making control quality financially material.
- Payment teams should treat fraud telemetry, customer warnings, and exception handling as part of a single governable control chain rather than isolated functions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | The article discusses strong customer authentication and biometric elements. |
| Recommendation — Apply SP 800-63B to align authentication assurance with payment risk and step-up decisions. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | VoP and fraud controls govern whether a payment should be authorised. |
| Recommendation — Map payment authorisation rules to PR.AA-05 so transaction decisions reflect verified entitlements. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article links fraud outcomes to how identity and access controls are used in payment journeys. |
| Recommendation — Review account and access handling under CIS-5 to reduce fraud exposure in payment workflows. | ||
| GDPR | Art.32 — Security of Processing | Fraud monitoring uses behavioural and device data that must be protected as processing security material. |
| Recommendation — Use Article 32 to govern the security, integrity, and confidentiality of fraud-monitoring data. | ||
Key terms
- Verification Of Payee: Verification of payee is a control that checks whether the recipient name and account number supplied in a payment instruction match. It is designed to interrupt authorised fraud by exposing destination mismatches before money leaves the payer’s account, but it still depends on alert quality and user response.
- Authorised Fraud: Authorised fraud happens when a victim is manipulated into approving a payment themselves. The transaction is legitimate from an authentication standpoint, which is why detection depends on context, behaviour, and payment validation rather than login controls alone.
- Behavioral Intelligence: Behavioral intelligence is the use of session patterns to judge whether an action looks normal for a specific user. In banking, it compares cadence, navigation, pauses, and correction patterns against prior sessions to detect coercion, guidance, or automation that authentication alone cannot reveal.
- Environmental intelligence: Environmental intelligence is the local information that changes what a vulnerability means inside a specific organisation, including network exposure, asset ownership, compensating controls, and the identities or secrets involved. It turns a generic score into a decision that reflects the actual attack surface.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org