The Challenge
In 2025, Open Banking Limited tracked fraud across account providers representing over 60% of UK Open Banking payment volumes. The data highlighted a specific issue: while Open Banking had one fraudulent transaction per 6,000 payments, the wider UK payments industry averaged one per 2,500. By Q1 2026, fraud rose to 0.024% of Open Banking payments, returning to historical levels after an unusually low period.
The main challenge wasn't technological. Authorized Push Payment (APP) fraud made up more than two-thirds of all Open Banking fraud cases. Customers were authorizing payments themselves after falling victim to scams like investment fraud, impersonation, and fake refund schemes. You can't block a transaction the customer genuinely wants to make, even if it's funding a scam.
Understanding the Environment
Open Banking operates under different constraints than traditional card payments. There's no dispute mechanism like Regulation E or chargeback rights. Once a customer authorizes an account-to-account payment, the funds move immediately and often irreversibly.
The fraud landscape is also different. Unlike card-not-present fraud, where you're detecting unauthorized use of stolen credentials, APP fraud exploits the customer's trust. The payment itself is technically legitimate. The customer enters their own credentials, passes strong customer authentication, and initiates the transfer. Your fraud detection system sees a properly authenticated transaction from a recognized device.
This creates a detection problem: how do you identify a scam when every technical indicator suggests the payment is valid? Traditional velocity checks and device fingerprinting won't help if the customer is deliberately sending money to a fraudster.
The Approach Taken
Open Banking Limited's data suggests the ecosystem maintained lower fraud rates through collaborative intelligence rather than isolated controls. The report highlights Transaction Risk Indicators (TRIs) as a mechanism for assessing payment risk before authorization.
TRIs are structured data fields that payment providers exchange during the payment initiation process. When a customer instructs their bank to send money via Open Banking, the receiving institution can share risk signals back to the sending bank. These might include how long the payee account has been open, whether it's received multiple payments from different sources in a short period, and whether the account holder's behavior matches typical patterns for that account type.
This creates a detection layer that doesn't exist in traditional payment rails. Your fraud team isn't just analyzing the customer's behavior in isolation. You're receiving intelligence about the destination account before the payment completes.
The collaborative model extends beyond TRIs. The report emphasizes data sharing between payment providers as essential to maintaining low fraud rates. When fraudsters operate across multiple institutions and payment channels, no single provider has complete visibility. Sharing anonymized fraud patterns, common payee accounts associated with scams, and emerging social engineering techniques creates a network effect in detection capability.
Results and Metrics
Open Banking maintained fraud at one in 6,000 payments during 2025, while the broader UK payments industry recorded one in 2,500. That's a 2.4x difference in fraud rate performance.
By Q1 2026, fraud reached 0.024% of Open Banking payments. While this represents an increase from an unusually low prior quarter, it still demonstrates measurably lower fraud exposure compared to industry benchmarks.
The two-thirds concentration of fraud in APP cases mirrors broader industry trends, but the absolute rate remains lower. This suggests the collaborative intelligence model isn't eliminating APP fraud, but it's reducing the success rate of scam attempts.
What They Would Do Differently
The report identifies a persistent gap: fraud prevention is becoming less about technology alone and more about understanding customer behavior and identifying suspicious payment patterns. This suggests current detection capabilities still miss behavioral signals that precede scam payments.
Investment scams remain one of the largest APP fraud categories by value. These typically involve longer grooming periods where fraudsters build trust before requesting payment. Your transaction monitoring might flag the payment itself, but you've missed weeks of preparatory contact through messaging apps, social media, or phone calls.
The report also notes increasingly complex fraud journeys that blur the distinction between authorized and unauthorized transactions. Fraudsters are combining social engineering with credential theft, creating scenarios where it's unclear whether the customer genuinely intended the payment or was coerced under false pretenses.
A more effective approach would integrate behavioral analytics earlier in the customer journey, not just at payment initiation. If you're only analyzing the transaction when it hits your authorization system, you're detecting too late.
Takeaways for Your Team
Collaborative intelligence scales better than isolated detection. If you're building fraud prevention for account-to-account payments, real-time intelligence sharing with receiving institutions provides detection signals you can't generate internally. Implement structured data exchange that surfaces payee account risk before authorization completes.
APP fraud requires customer-facing intervention, not just backend blocking. When fraud rates concentrate in authorized payments, your detection system needs to trigger warnings the customer will actually heed. Generic "are you sure?" prompts don't work. You need contextual alerts that explain specific risk factors: "This account was opened three days ago and has received 47 payments from different senders."
Fraud rate benchmarking matters for ecosystem trust. Open Banking Limited publishes this data biannually specifically because maintaining measurably lower fraud rates supports adoption. If you operate a payment rail or network, transparent fraud reporting builds confidence among participants and demonstrates that collaborative controls actually work.
Social engineering detection needs to move upstream. If investment scams represent the largest fraud value and involve extended grooming periods, waiting until payment initiation to detect the scam means you're intervening too late. Consider how you might identify customers being targeted before they attempt to send money, whether through unusual account access patterns, repeated small test payments, or sudden changes in typical payment behavior.
The Open Banking model demonstrates that fraud prevention doesn't require sacrificing payment speed or customer experience. One fraudulent transaction per 6,000 payments proves you can maintain strong fraud controls in a real-time, irrevocable payment environment. The key is sharing intelligence across institutional boundaries rather than expecting each provider to detect threats independently.



