UK Independent. Sourced. Primary. · Est. 2024
Home Regulations Bank Fraud Liability: Your Rights Under Payment Services Regulations
Regulations

Bank Fraud Liability: Your Rights Under Payment Services Regulations

Banks must refund unauthorised fraud in 1 business day. APP fraud reimbursement up to PS415,000 mandatory from October 2024. Gross negligence rules and FOS rights.

CT
Chandraketu Tripathi
Finance Editor, Kaeltripton
Published 14 Jun 2026
Last reviewed 14 Jun 2026
✓ Fact-checked
Bank Fraud Liability: Your Rights Under Payment Services Regulations
Advertisement
CT

Chandraketu Tripathi

Finance Editor, Kael Tripton Ltd - LBS MBA - Verified against FCA Handbook: 14 June 2026

Primary source verified

Quick answer

Under the Payment Services Regulations 2017, banks must refund unauthorised transactions within 1 business day unless you were grossly negligent. For APP fraud (being tricked into authorising a payment), mandatory reimbursement of up to PS415,000 applies from October 2024 under PSR rules. Gross negligence does not mean being deceived by a sophisticated scam.

Max APP fraud reimbursement PS415,000
Verified June 2026
1 business dayUnauthorised fraud refund deadlinePS415,000Max APP fraud reimbursementPS35Max liability before reporting lossOct 2024Mandatory APP rules effective

Are You Liable for Fraud on Your Bank Account?

Direct answer

Am I liable for fraud on my bank account and what must my bank do?

Under the Payment Services Regulations 2017, you are not liable for unauthorised transactions unless you acted fraudulently or with gross negligence. Banks must refund unauthorised fraud within 1 business day. For APP fraud (being tricked into authorising a payment), mandatory reimbursement up to PS415,000 per claim applies from October 2024. Being deceived by a sophisticated scam is not gross negligence.

FCA Handbook - PSR 2017 Reg 77 - Verbatim Rule Text Source: handbook.fca.org.uk

Where an unauthorised payment transaction has been executed, the payer's payment service provider shall immediately refund the payer the amount of the unauthorised payment transaction and, where applicable, restore the debited payment account to the state it would have been in had the unauthorised payment not taken place.

1

Report to your bank immediately

Call the fraud number on the back of your card. Banks must freeze the account and attempt to recall the payment.

2

Report to Action Fraud

actionfraud.police.uk or 0300 123 2040. Get a crime reference number.

3

For APP fraud -- request reimbursement under PSR rules

Write to your bank citing the PSR mandatory reimbursement scheme (from October 2024). Banks must reimburse within 5 business days unless investigating.

4

Challenge a gross negligence finding

If your bank claims you were grossly negligent, challenge this in writing. Being deceived by a sophisticated scam is not gross negligence.

5

Escalate to the FOS if refused

The FOS handles fraud liability disputes and has consistently found against banks that apply gross negligence too broadly.

Fraud typeLiabilityBank obligationDeadline
Unauthorised (card lost/stolen -- reported promptly)Maximum PS35Must refund immediately1 business day
Unauthorised (card fraud -- not your fault)Zero if not negligentMust refund in full1 business day
APP fraud (tricked into authorising payment)Zero if not grossly negligentMust reimburse up to PS415,0005 business days (or 35 to investigate)
Gross negligence (shared PIN etc)Full loss possibleNo obligation to refundN/A
Disclaimer: Kael Tripton Ltd (ICO ZC135439) is an independent editorial publisher. This page explains UK financial regulations for information only and does not constitute legal or financial advice. Always verify current rules at handbook.fca.org.uk.

Frequently Asked Questions

Am I liable for fraud on my bank account?

Your liability for unauthorised transactions depends on the Payment Services Regulations 2017 (PSRs 2017). Under Regulation 77, you are only liable for unauthorised transactions if you acted fraudulently or with gross negligence. For standard fraud where you did not authorise the transaction and were not negligent, the bank must refund you. The bank must refund within 1 business day of you reporting the fraud. Your maximum liability for transactions made before you reported the loss of your card is PS35, unless you acted with gross negligence.

What is the Contingent Reimbursement Model for authorised push payment fraud?

Authorised Push Payment (APP) fraud is where you are tricked into authorising a payment yourself -- for example, a scammer impersonates your bank or solicitor and persuades you to transfer money. The Contingent Reimbursement Model (CRM) Code is a voluntary industry code (now replaced by mandatory PSR rules from October 2024) requiring banks to reimburse victims of APP fraud unless the victim was grossly negligent. From October 2024, the Payment Systems Regulator (PSR) mandated that banks must reimburse APP fraud victims up to PS415,000 per claim.

What is the APP fraud mandatory reimbursement rule?

From 7 October 2024, the Payment Systems Regulator (PSR) requires all banks and payment firms participating in the Faster Payments scheme to reimburse victims of authorised push payment (APP) fraud up to PS415,000 per claim, unless the victim was grossly negligent or acted dishonestly. The sending bank and the receiving bank share the cost of reimbursement 50/50. This is the strongest APP fraud protection in any major economy.

What counts as gross negligence in bank fraud?

Gross negligence in the context of bank fraud means a serious failure to take basic precautions that any reasonable person would take. Examples: sharing your PIN or passwords with a third party, ignoring clear fraud warnings from your bank before making a payment, or making a payment after being explicitly warned by your bank that the payment may be fraudulent. Standard carelessness or being deceived by a sophisticated scam does not typically constitute gross negligence.

What should I do if I am a victim of bank fraud?

Report to your bank immediately -- banks must freeze the account and attempt to recall the payment where possible. Report to Action Fraud (actionfraud.police.uk, 0300 123 2040). For APP fraud, your bank must reimburse you within 5 business days under the PSR mandatory scheme (from October 2024) unless they need more time to investigate (maximum 35 business days). If the bank refuses reimbursement, escalate to the FOS.

Primary sources

    Kael Tripton Ltd is registered with the Information Commissioner's Office under registration number ZC135439.

    Advertisement

    Editorial Disclaimer

    The content on Kaeltripton.com is for informational and educational purposes only and does not constitute financial, investment, tax, legal or regulatory advice. Kaeltripton.com is not authorised or regulated by the Financial Conduct Authority (FCA) and is not a financial adviser, mortgage broker, insurance intermediary or investment firm. Nothing on this site should be construed as a personal recommendation. Rates, figures and product details are indicative only, subject to change without notice, and should always be verified directly with the relevant provider, HMRC, the FCA register, the Bank of England, Ofgem or other appropriate authority before any financial decision is made. Past performance is not a reliable indicator of future results. If you require regulated financial advice, please consult a qualified adviser authorised by the FCA.

    CT
    Chandraketu Tripathi
    Finance Editor · Kaeltripton.com
    Chandraketu (CK) Tripathi, founder and lead editor of Kael Tripton. 22 years in finance and marketing across 23 markets. Writes on UK personal finance, tax, mortgages, insurance, energy, and investing. Sources: HMRC, FCA, Ofgem, BoE, ONS.

    Stay ahead of your money

    Free UK finance guides, rate changes and money-saving tips — straight to your inbox. No spam, unsubscribe anytime.

    Read More

    Get Kael Tripton in your Google feed

    ⭐ Add as Preferred Source on Google