TL;DR: PSR and PSD3 will reshape fraud prevention, liability, and strong customer authentication across European payments, with PSPs expected to add verification of payee, behavioural monitoring, fraud data sharing, and broader SCA options, according to OneSpan. The regulatory shift moves security decisions closer to transaction context, not just user authentication.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “PSD3: Habemus Pactum”.
Key questions
Q: What breaks when verification of payee is not in place for credit transfers?
A: Without verification of payee, the payer’s PSP has no structured control to compare the stated beneficiary name with the IBAN before execution.
Q: Why do behavioural and device signals matter more as fraud becomes more automated?
A: Behavioural and device signals matter because automated attacks can mimic static credentials but struggle to reproduce real interaction patterns, device characteristics, and network behaviour consistently.
Q: What are the signs that a payment fraud monitoring model is too weak?
A: Common warning signs are excessive false positives, missed suspicious transfers, overreliance on authentication events, and alerts that are so frequent users ignore them.
Practitioner guidance
- Strengthen verification of payee governance Map every credit-transfer journey to where name and IBAN matching is performed, how discrepancies are surfaced, and who can override the warning.
- Incorporate device and behaviour telemetry Feed remote-access tools, malware indicators, typing cadence, touch patterns, and session timing into fraud detection models so they can distinguish normal use from manipulated activity.
- Reassess false-positive thresholds for blocking Review the conditions under which suspicious payments are blocked so the model is defensible, actionable, and aligned to the liability exposure described in the regulation.
Bottom line: PSR and PSD3 expand fraud governance beyond login security by tying payment authorisation to transaction context, beneficiary validation, and session behaviour.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
PSR and PSD3 move fraud governance out of the authentication silo. The article shows that payment risk can no longer be managed by strong customer authentication alone, because APP fraud succeeds after legitimate login through social engineering and manipulation. That means transaction context, beneficiary validation, and session behaviour become part of the identity decision. For practitioners, the control boundary is now the full payment journey, not the sign-in event.
A few things that frame the scale:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
A question worth separating out:
Q: Who is accountable when a PSP fails to stop authorised fraud?
A: Under the article’s summary of PSR and PSD3, accountability can shift to the PSP when it fails to use VoP properly, fails to monitor transactions, or does not block suspicious activity. If the provider’s controls were not applied correctly, liability is no longer just a customer issue.
👉 Read our full editorial: PSR and PSD3 change fraud controls, liability, and SCA