What Changed
The UK government is dissolving the Payment Systems Regulator (PSR) and transferring its functions to the Financial Conduct Authority (FCA). This move aims to streamline oversight and reduce compliance costs by eliminating the three-regulator structure of the PSR, FCA, and Prudential Regulatory Authority. While the PSR has operated as an FCA subsidiary, this consolidation removes a specialized regulator at a time when payment system resilience and fraud risk management are under intense scrutiny.
Key Findings
The APP fraud refund system is now in limbo. The PSR introduced mandatory reimbursement for authorized push payment fraud in October 2024, initially proposing a cap of £415,000 per claim. After objections from smaller banks, the cap was reduced to £85,000, split between sending and receiving payment service providers. With only 10 claims processed in the first month, the system's future governance now falls to the FCA, which lacks experience in managing reimbursement infrastructure or setting liability splits between PSPs.
Payment rail oversight loses a dedicated voice. Recently, the PSR criticized Visa and Mastercard for fee increases and market dominance, citing a £170 million annual cost impact on UK businesses. Such direct challenges to card networks require focused institutional attention. The FCA, overseeing a broad range of financial sectors, may not prioritize payment rail issues as the PSR did.
Fraud prevention accountability becomes diffuse. The PSR had a clear mandate to protect payment system users and promote competition, with fraud risk as a central concern. The FCA's broader mandate may dilute focus on specialized initiatives like the APP refund system, risking them becoming more about compliance than effective enforcement.
What This Means for Your Team
If you're managing fraud controls at a UK bank, PSP, or fintech, you're now under a regulator with less institutional knowledge of payment-specific fraud patterns. The FCA is experienced in conduct risk and consumer protection but lacks the PSR's decade of data on payment rail vulnerabilities and fraud typologies.
Expect slower guidance updates on emerging fraud schemes. The PSR could quickly address payment-specific threats, while the FCA will need time to develop this capability. In the meantime, expect more reliance on industry working groups and less direct regulatory intervention.
Your APP fraud reporting and reimbursement workflows may change unexpectedly. The £85,000 cap and 50/50 liability split were PSR constructs. The FCA could revise these thresholds, shift the burden, or deprioritize enforcement if political pressure mounts. Document your assumptions and prepare contingency workflows.
If you operate cross-border, you now face regulatory arbitrage risk. The European Banking Authority and national regulators in the EU maintain dedicated payment oversight. If your firm processes payments in both jurisdictions, you'll navigate mismatched expectations: specialized oversight in the EU, generalist oversight in the UK. This gap creates compliance complexity and potential blind spots in your fraud detection logic.
Action Items by Priority
Immediate (next 30 days):
Review your APP fraud case documentation. Ensure compliance with the current £85,000 reimbursement cap and 50/50 liability split. If the FCA revises these parameters, you'll need a baseline to measure impact. Tag cases by fraud typology, claim value, and reimbursement timing. Build a dashboard showing your exposure under different cap scenarios (e.g., £50,000, £100,000, no cap).
Identify payment rail dependencies in your fraud detection rules. If you rely on network-level data feeds, interchange fee structures, or scheme rules to flag suspicious patterns, map those dependencies. The PSR's oversight of Visa and Mastercard may weaken under the FCA, and fee structures could shift. Your detection logic needs to remain accurate regardless of upstream changes.
Short-term (next 90 days):
Establish direct communication channels with FCA contacts responsible for payment oversight. Don't assume your PSR relationships transfer automatically. Request clarity on APP fraud reporting timelines, reimbursement claim adjudication, and any planned revisions to the liability framework. If you get vague answers, escalate internally and prepare your board for regulatory uncertainty.
Audit your Suspicious Activity Report (SAR) workflows for payment fraud. The FCA already receives SARs under the Bank Secrecy Act equivalent (Proceeds of Crime Act 2002 and Money Laundering Regulations). Confirm that your SAR triggers for APP fraud, mule account activity, and payment rail abuse align with FCA expectations, not just legacy PSR guidance.
Medium-term (next 6 months):
Scenario-test your fraud controls under reduced regulatory pressure. If the FCA deprioritizes payment-specific enforcement, your fraud prevention program becomes more self-directed. Run tabletop exercises: What happens if reimbursement caps drop to £50,000? What if liability shifts 70/30 to sending PSPs? What if the FCA stops publishing payment fraud statistics? Build contingency playbooks for each scenario.
Engage industry working groups on payment fraud. With the PSR gone, collective defense matters more. Join UK Finance working groups, participate in fraud intelligence sharing, and push for standardized fraud typology taxonomies. The FCA won't build that infrastructure alone.
FCA Payment Systems Oversight



