(10 min read)
PSD3 and the PSR will overhaul the current PSD2 framework, redefining how payment institutions, electronic money institutions, banks and other PSPs operate across the EU. Senior management, legal, compliance and operations teams need to understand the new authorisation, safeguarding, fraud, strong customer authentication and open banking requirements, as well as the implications for SEPA access and UK–EU regulatory alignment. In this article we explore the key changes and implications for banks, payment institutions, e-money institutions, and the wider payments ecosystem and how these developments compare to the payments regulatory landscape in the UK. UK PSPs should consider whether there are any aspects of PSD3 which might inform their own policy positions for UK payments regulatory reform and to understand where alignment may become necessary.
On 23 April 2026 the agreed text of the Payment Services Directive 3 (PSD3) and Payment Services Regulation (PSR) was published. Together these replace the current PSD2 framework and repeal the second Electronic Money Directive, consolidating the regulatory regime applicable to payments and electronic money institutions across the European Union. This is the first significant overhaul of payments regulation in the EU since PSD2 and will result in a material shift in obligations for EU-based payment service providers across the areas of fraud, strong customer authentication and open banking, to name just a few of the new requirements addressed through the new regime.
The PSD3 regime should also be of interest to UK payment service providers, both in terms of the opportunity it presents for the UK to consider its approach going forwards under HMT’s programme for Modernising Payment Services Regulation and whether to harmonise with the EU, and also to help understand where alignment with the new regime may be necessary in order to ensure the UK’s continued membership of the SEPA payment schemes.
In this article we explore the key changes and implications for banks, payment institutions (PIs), e-money institutions (EMIs), and the wider payments ecosystem and how these developments compare to the payments regulatory landscape in the UK.
The timeline to implementation
PSD3 and the PSR are expected to be published in the Official Journal at the end of Q4 2026. From then on, the timeline to the full application of the new regime will likely extend well into 2028 and beyond, with the core provisions in PSD3 taking effect after a 21-month implementation period. The EBA and European Commission are due to publish a series of regulatory technical standards, implementing technical standards and guidelines covering the more detailed requirements underpinning fraud, SCA and open banking.
The new EU payments regulatory landscape
PSD2 will be replaced with two separate instruments. PSD3, as a directive, retains prudential, licensing and supervisory rules and requires national transposition. Material variation between member states will therefore persist.
The PSR, as a regulation, applies the conduct of business rules directly across the European Union, with substantive rules largely the same in every jurisdiction except that enforcement (sanctions, competent authorities, procedural choices etc) will remain a national matter.
For cross-border firms, this means navigating uniform substantive rules (via the PSR) but potentially divergent enforcement and licensing regimes (via PSD3).
Further, e-money institutions (EMIs) as a separate authorisation will cease to exist and instead will become a sub-category of a payment institution, with the regulated activity being the issuance of e-money. Existing EMIs must transition into the new framework through the transitional regime.
The transitional regime
The timetable for the transitional regime for existing market participants runs in three stages from PSD3 entry into force:
- 21 months – the cut-off for qualifying under the transitional regime;
- 27 months – the deadline by which the firm must have submitted the necessary information and demonstrated compliance with PSD3;
- Up to 30 months – an extension for showing compliance where the firm submitted on time but the supervisor could not process in time.
Until the 27-month deadline, a firm continues to operate under its existing PSD2 or EMD2 authorisation. If a firm misses the 27-month deadline for demonstrating compliance with the new framework then its authorisation will be suspended until it can demonstrate compliance and the supervisor verifies it.
PIs and EMIs can follow two procedural routes in the transitional regime. First, they can submit information to the supervisor who verifies it. This is the default expectation. Alternatively, these firms could seek automatic authorisation without submission where the supervisor already holds evidence of compliance. Supervisors will assess information on firms’ initial capital, safeguarding, governance and internal controls, security incident handling, business continuity, the new EU jurisdictions overview, and the new winding-up plan.
Exclusions
The PSR has made changes to some of the existing PSD2 exclusions and has introduced new ones. Firms which currently benefit from any of the PSD2 exclusions should consider these changes.
See our table for highlights >
Safeguarding
PSD3 introduces new safeguarding requirements. Of particular importance to EMIs, funds will need to be safeguarded by no later than the end of the business day (i.e. D+1) following the day when the funds have been received after the issuance of e-money, in contrast to the five days after the issuance of electronic money required in the EMD2 framework. This aligns with the D+1 requirement in PSD2, but EMIs in the UK will still be subject to the maximum of five business days after the date on which the e-money was issued to safeguard relevant funds.
PSD3 further tightens the safeguarding requirements in three ways:
- The depositary credit institution must be authorised in a Member State;
- Firms using the segregation method must endeavour not to safeguard all client funds with a single credit institution;
- Funds received in exchange for electronic money tokens should instead be safeguarded in accordance with Article 54 of MiCA.
The requirement for the depositary credit institution to be authorised in a Member State is a significant change. In the UK, firms can safeguard relevant funds with foreign credit institutions that meet certain criteria. This is particularly significant for UK credit institutions that will no longer be able to safeguard funds for EU payment institutions unless the credit institution is or becomes authorised in an EU member state.
Otherwise, the obligation on firms to avoid concentration risk of safeguarded customer funds broadly aligns with the UK approach in CASS 15.6.1R(2) which requires firms to consider the need for diversification of the third parties with which it deposits relevant funds it is required to safeguard.
Fraud, liability and reimbursement
The new framework substantially expands mandatory fraud prevention obligations and shifts liability towards PSPs in several specific scenarios:
- Verification of Payee (VOP): Article 50 PSR expands the verification of payee requirements to all credit transfers (beyond the current “VOP” requirements under the EU’s SEPA Regulation which currently only apply to SEPA Instant Credit Transfers). This means that, before authorising a credit transfer, the payer’s PSP must offer and apply a name and unique identifier matching checking service against information held by the payee’s PSP.
- Impersonation fraud: Under Article 59 PSR PSPs must refund the full amount of an authorised payment where a consumer is manipulated by a third party impersonating the consumer’s own PSP. Consumers must report the fraud to police to be eligible for compensation. PSD2 had no equivalent reimbursement obligation for impersonation or authorised push payment fraud. Additionally, all PSPs (whether or not they service consumers) have an obligation to have adequate prevention and technical safeguards in place to prevent this.
- Fraud transaction monitoring: PSD3 introduces new requirements for transaction monitoring, including new requirements to carry out transaction monitoring for inbound payment transactions. Broadly speaking, if the payer’s PSP has objectively justified reasons to suspect that the transaction is fraudulent the PSP must suspend the execution under Article 65 PSR. If the PSP has reasons to suspect fraud and does not suspend the transaction, the payer must not bear any financial losses. The payee’s PSP is subject to similar obligations if they have clear and incontrovertible reasons to suspect a transaction is fraudulent to return the funds to the payer’s PSP and not credit the payee’s account under Article 69 PSR.
Notably, PSD2 had no equivalent reimbursement obligation for impersonation or authorised push payment fraud. While this represents one of the largest shifts of liability in the new EU regulatory framework, UK PSPs will be familiar with similar mandatory reimbursement requirements for APP fraud which have been in force since October 2024.
One point of difference stands out in that users must report the fraud to the police to be eligible for compensation. No such reporting requirement exists in UK legislation. Policy reasons for this may be to add some friction in order to reduce the number of customer claims, as well as help gather intelligence on patterns of criminality. This will likely create additional burden for EU PSPs, as the recitals to PSD3 encourage PSPs to assist vulnerable users in reporting fraud to the police in a timely manner. While we are not aware of any movement towards implementing a similar reporting requirement in the UK, it would be prudent to compare the effectiveness of the EU implementation of the fraud liability changes in case of future changes in the UK.
Strong customer authentication
The PSR retains the requirement that strong customer authentication be based on factors belonging to two different categories from possession, knowledge and inherence. Except that PSPs can implement SCA using two elements only from the inherence category if it can demonstrate to its regulator that the independence of the elements is at all times fully preserved and the authentication procedure ensures at all times a high level of security. The EBA will develop guidelines within 18 months of entry into force on how to assess that the independence of the two inherence elements is fully preserved.
While in the UK PSPs must only use authentication factors from two different categories and cannot justify the use of two “inherence” factors (i.e. something the user is, such as biometric or behavioural characteristics), parallels can be drawn between this change in PSD3 and the general move to a more outcomes-based regime in the UK. If it can be shown in the EU that good outcomes for customers can be preserved by less prescriptive requirements for SCA such as the use of two inherence factors then the FCA may consider a similar change in the UK.
Open banking
The dedicated interface obligation is elevated from the EU RTS-SCA to primary legislation by Article 35 PSR. ASPSPs must put in place at least one dedicated interface within three months of authorisation if they provide payment accounts that are accessible online, and there is no longer the automatic right to put in place a modified customer interface as an alternative. Firms can, however, apply for an exemption from putting in place a dedicated interface at all, or to request permission to put in place a different arrangement altogether.
Article 43 PSR introduces a requirement for ASPSPs to provide the payment service user with a dashboard, integrated into its user interface, to monitor and manage the consents that the user has given for the purpose of AIS and PIS. The dashboard must be able to:
- provide the user with an overview of each ongoing consent (name of AIS or PIS provider, the account to which access has been granted, purpose of consent, period of validity, categories of data shared, the dates on which account data was accessed);
- allow users to withdraw data access for all AIS or PIS providers or for a given provider at any time and free of charge;
- allow the user to re-establish any withdrawn data access within 48 hours of withdrawal of a consent; and
- include a record of data access consents that have been withdrawn or that have expired for a duration of 2 years.
These more prescriptive Open Banking requirements in PSD3 are a result of inconsistent standards and fragmented implementation of PSD2 across member states, whereas UK ASPSPs have been required to put in place dedicated interfaces for many years. Further contrast can be found in the approach to Open Banking and its stage of development across the EU compared to the UK. In the UK, Open Banking is maturing beyond prescriptive requirements to a more industry-led approach exemplified in the Open Banking Payments Commercial Model.
What next?
With publication in the Official Journal expected in late Q4 2026, impacted EU firms should begin preparing for the new regime. Key priorities for PIs and EMIs include:
- Preparing for authorisation in the transitional regime.
- Reviewing and assessing the use of any exclusions.
- Reviewing capital requirements and updating safeguarding arrangements.
- Preparing for operational readiness for new fraud prevention and liability rules.
- Planning for SCA and interface changes.
The PSD3/PSR package marks a significant step in the evolution of EU payments regulation, with significant implications for market participants and consumer protection. Impacted firms should act now to ensure a smooth transition.
For the UK, this package presents an opportunity to consider the future of payments regulation in the UK in the light of our own regulatory reform agenda through HMT’s Modernising Payments Regulation work. In particular, UK PSPs should carefully consider whether there are aspects of the EU regime from which we would like to borrow, or conversely where we clearly disagree with the approach. This will help to inform firms’ own policy positions for UK payments regulatory reform. More generally, UK PSPs will want to closely follow PSD3 developments to understand where alignment may become necessary in order to ensure the UK’s continued access to SEPA payment schemes, which requires the UK to demonstrate it has in place a functionally equivalent legal and regulatory regime for euro payments. A careful balance must be struck between forging our own regulatory path for payments whilst balancing the continuing need to access SEPA payment schemes.