
Unlike PSD2, which focused much of its attention on SCA and open banking, the new PSR focuses on fraud prevention.
PSD3 and the accompanying PSR regulation are still roughly a year away from formal application. Payment service providers and banks that wait for the regulation to take effect before preparing will be entering a race against time. And that race will be difficult to win.
After the European Parliament and the Council reached a provisional political agreement in November 2025, the final compromise texts were published in April 2026. PSD3 and the accompanying Payment Services Regulation (PSR) are no longer just something to prepare for. Their direction is now clear.
The rules are expected to take effect during 2027. With a transition period of roughly 18 to 21 months, technical and organisational preparations need to start now.
Unlike PSD2, focusing much of its attention on Strong Customer Authentication (SCA) and open banking, PSR puts significantly more emphasis on fraud prevention.
The new framework introduces liability for payment service providers to compensate victims of so-called Authorised Push Payment (APP) fraud where the provider failed to apply the expected fraud detection standards. It also introduces mandatory Verification of Payee, requiring the IBAN and recipient name to be checked for a match, along with clear minimum requirements for real-time transaction monitoring and the exchange of IBAN and payee reputation data between service providers.
This shift in focus is exactly why PSD3 cannot be left to the legal and compliance teams alone.
As a business driver, PSD3 changes the risk profile directly. Liability for APP fraud shifts part of the financial exposure to the institution. Failing to meet fraud detection standards is no longer just a reputational issue. It can become a direct financial cost.
As a technical driver, the regulation requires infrastructure that can process transactions in real time, verify payees, and exchange fraud-related data with other institutions. That goes well beyond what systems designed primarily to verify a second authentication factor were built to do.
And as a security driver, it changes how risk needs to be assessed. The decision can no longer be made in isolation at login. Risk needs to be assessed continuously, throughout the session and across individual transactions. This includes the user’s identity, behaviour, and context.
Most institutions already have identity and authentication systems that successfully meet the requirements of PSD2 and SCA.
The problem is that these systems are typically built around a point-in-time verification model. Confirm who you are when you log in or confirm a transaction, and the job is done.
PSR requires something fundamentally different.
It calls for continuous fraud monitoring, real-time transaction monitoring, information sharing about fraud with other market participants, and risk assessment that does not rely solely on whether the user entered the correct authentication code. The real question is whether the entire transaction is likely to be legitimate at that particular moment.
That gap, between identity as a static verification and identity as a continuous risk signal, is where PSD3 readiness will be decided over the next two years.
Institutions that start building this capability now can prepare deliberately. Those that wait will be pushed into an intensive, expensive, and higher-risk project just before the deadline.
Closing this gap does not require another policy document. It requires extending identity management with the capabilities that PSR effectively demands.
That means fraud monitoring that can identify behavioural and device anomalies associated with a user’s identity.
It means transaction monitoring that tracks transaction patterns in real time and connects them to the authenticated identity behind each transaction.
It means fraud data sharing with other payment service providers, helping institutions identify known fraud patterns and high-risk recipients earlier.
And it means real-time risk assessment that evaluates every transaction before authorisation and decides whether it should proceed, require additional verification, or be blocked.
When these capabilities become part of identity management rather than a collection of disconnected tools, identity becomes a continuous signal throughout the transaction lifecycle.
From login to execution, the institution can use identity, behaviour, and context to make better risk decisions. That helps meet the regulatory requirement while also reducing actual exposure to fraud.
The institutions building this capability today will not meet PSD3 as a deadline they need to catch up with. They will meet it as confirmation that they chose the right direction early.
This article is adapted from the original published on ICT Business.