APP Fraud Reimbursement: Evidencing Every Claim Decision
In short
DATS is the AI consulting system from DILR.AI that helps UK payments firms make APP fraud reimbursement decisions consistent and evidenced: how to record a stop-the-clock pause, how to support a consumer standard of caution rejection, how vulnerability affects the excess and the receiving firm's contribution, and what a claim file needs before the PSR's December 2026 consultation.
DE
Dilr.ai EngineeringEngineering team
Published Oct 11, 2026Read 16 min
Since 7 October 2024, UK payment firms directed under the PSR's rules have had to decide authorised push payment (APP) scam claims against a regulator's timetable. On the headline measure the first eighteen months have gone well. The PSR's Q1 2026 reimbursement dashboard reports that 88% of the money lost to APP scams, £316m, was reimbursed to victims between 7 October 2024 and 31 March 2026, measured on claims within the policy, and that 82% of claims were closed within five business days.
The harder number sits underneath. Consumers reported around 438,300 claims over those eighteen months, and 301,500 of them were in scope for reimbursement. Each claim that closes ends in a decision somebody has to be able to explain: reimburse in full, reimburse less an excess, or refuse under an exception, often after the clock has been paused along the way. In July 2026 the regulator said plainly that outcomes still vary depending on who a consumer banks with, and it has scheduled a consultation on consistency for December 2026. For a Head of Compliance the question has moved from whether the firm is fast enough to whether its decisions would survive being laid next to every other firm's. That is a placement question as much as a policy one, which is why it sits inside our enterprise AI consulting guide as well as here.
This guide covers that decision and the evidence behind it: how stop-the-clock pauses are used and recorded, the consumer standard of caution exception (which the PSR's consumer guidance frames as gross negligence), vulnerability, the excess and the 50:50 split. It deliberately cedes two neighbouring frames. Clock speed and the case for automating evidence gathering are covered in our UK fintech AI guide, and capturing bank details and Confirmation of Payee on a call is covered in our post on sort code and account number capture.
This guide is shipped by the team behind DATS, the five-stage AI consulting system DILR.AI runs for enterprises, delivered by senior practitioners who ship code, not decks. Or see AI operating model design, which covers governance, RACI and lifecycle, audit-ready by design.
What does a sending firm actually decide on an APP fraud claim?
A sending payment service provider decides, for every authorised push payment scam claim, whether the payment is reimbursable, how much to repay and whether an exception applies. Under the PSR's direction, a reimbursable payment is one where the consumer standard of caution exception does not apply, the victim was not party to the fraud, and the claim arrived within the time limit. That duty sits with the payment firm, not the customer.
The definition comes from Specific Direction 20, which directs payment service providers in the Faster Payments Scheme to reimburse in-scope APP scam payments and to comply with the reimbursement rules. The PSR's APP scams policy page confirms the scope covers Faster Payments and CHAPS between UK accounts, and that sending and receiving firms split the cost of reimbursement 50:50. In our reading, they turn one claim into four separate determinations, with a vulnerability assessment running alongside them, and a firm that records them as one outcome code loses the ability to show its reasoning later.
The four determinations are, in order. First, scope: was this a UK-to-UK Faster Payment or CHAPS payment, and did the customer report it within the window? The PSR's consumer protections page tells victims to report within 13 months of making the fraudulent payment. Second, eligibility: is the claimant the victim, or a party to the fraud? The PSR's policy clarifications state that a consumer who is party to the fraud, including first party fraud, is ineligible. Third, exception: does the consumer standard of caution exception apply? Fourth, amount: what is repaid, net of any excess and within the cap?
Each determination has a different evidence base and often a different owner. Scope is usually a payments operations fact. Eligibility can lean on financial crime intelligence, sometimes the same data a KYC review team already holds. The exception and vulnerability questions are conduct judgements. The amount is arithmetic that finance will reconcile against the receiving firm's contribution. A decision record that does not separate the four will not survive a second reader, which is the standard the rest of this guide works towards. Separating facts from judgement is part of what an AI operating model covers through governance, RACI and lifecycle.
When can a payments firm stop the five-day reimbursement clock?
A payments firm can stop the five-day reimbursement clock only in the limited circumstances that the PSR places in Section 5 of its Faster Payments reimbursement rules, typically to gather information it needs, such as evidence about a customer's vulnerability. Even with the clock stopped, the firm must arrive at an outcome within 35 business days, so every pause deserves a recorded reason and a dated request trail.
The policy clarifications page points firms to Section 5 of Specific Requirement 1 for the time limits and for the limited circumstances in which the sending firm may pause. The consumer-facing explanation is plainer: victims can expect reimbursement within five business days, firms can stop the clock where they need more time to gather information, and the firm must arrive at an outcome within 35 business days.
The dashboard shows how close the book runs to those limits. Over eighteen months, 82% of claims closed within five business days and 98% within 35 business days, so about 2% closed later than that. The regulator now wants to look at that tail: its APP scams policy roadmap lists the treatment of claims that cannot be resolved within 35 business days as a policy parameter for the December 2026 consultation.
In practice, a defensible pause record answers five questions: what information was requested, from whom (the victim, the receiving firm, the police), on what date, why the decision could not be made without it, and when it arrived. The failure pattern to design out is the pause used as a queue buffer, where the clock stops because an analyst is busy rather than because a fact is missing. That pattern is invisible in a five-day completion rate and obvious the moment someone samples the request trail. It is one of the first patterns worth checking in any claims operation, because it shows whether the bottleneck is evidence or capacity.
How should a firm evidence a consumer standard of caution rejection?
A firm should evidence a consumer standard of caution rejection by recording what the customer failed to do, what the firm did that the customer disregarded, and why the conduct reaches gross negligence, which the PSR's consumer guidance calls a high bar. The exception does not apply to a vulnerable customer, so a well-built payments firm file shows the vulnerability check came first.
Rejections on this ground are rare, which is exactly why each one draws attention. The dashboard records that 3% of claims over eighteen months were rejected because the customer did not take enough care over the transaction or the claim. In Q1 2026 the figure was around 1,700 claims, or 2%, against an average of around 2,200, or 3%, over the previous four quarters. The PSR reads that as no sign of consumers becoming significantly less careful. A firm whose own rejection rate sits well above that line should be able to explain why.
The consumer protections page sets out what the PSR tells customers to do: paying attention to warnings from the bank, responding promptly to genuine requests for information, and reporting to the police or consenting to the bank doing so. It also states that a customer will not be reimbursed if found complicit or grossly negligent, that gross negligence is a high bar, and that the exception does not apply to vulnerable consumers. In our view a rejection file should therefore hold the warning the firm actually showed, at the moment it showed it, and the customer's response.
The commercial stakes are not limited to the claim. A customer refused under this exception can take the case to the Financial Ombudsman Service, and the same evidence then has to stand up in front of a third party. Firms that already run complaint surges, such as the lenders in our piece on motor finance redress volumes, know how quickly a thin record becomes an expensive one. The roadmap also commits the PSR to consider guidance on applying the consumer standard of caution, so today's reasoning may later be measured against published guidance.
How do vulnerability findings change the decision and each firm's share?
A vulnerability finding changes an APP fraud decision in three ways: the excess cannot be deducted, the consumer standard of caution exception does not apply, and the receiving firm loses its option to reduce its contribution by half the maximum excess. Because two of those turn on it, a payments firm is well advised to settle vulnerability first and record when and how it reached that view.
The protections page sets an optional excess of up to £100 that firms may choose to apply, and states it cannot be applied to vulnerable consumers. The policy clarifications then spell out the knock-on for the split. Under paragraph 5.13 of the reimbursement rules, a receiving firm may deduct 50% of the maximum excess from its contribution where the sending firm chooses not to levy the excess. Where the customer is vulnerable within paragraph 5.17, the sending firm has no such choice, paragraph 5.13 does not apply, and the receiving firm may not make the deduction.
That clarification turns a conduct judgement into a cash item between two regulated firms. The receiving firm has a direct interest in the vulnerability finding, because it determines what it owes. The sending firm has a direct interest in recording it well, because a vulnerability finding made late, or made only after an exception was considered, is the hardest kind of decision to defend. Sequence matters as much as substance.
The cap sits alongside this. The protections page sets a maximum claim of £85,000, which the PSR says covers over 99% of claims, and notes that individual firms may choose to reimburse more. The same page states that the Financial Ombudsman Service has a compensation limit of £430,000, so a case above the cap is not closed simply because the reimbursement rules stop there. Teams that already think about document extraction for onboarding evidence will recognise the pattern: the hard part is not reading one file, it is producing the same reading for the thousandth.
Why is consistency of claim decisions now the regulator's focus?
Consistency of APP claim decisions is now the regulator's focus because the regulator's own independent evaluation found the policy works overall while outcomes still vary depending on who a consumer banks with. The PSR has published a roadmap with a formal consultation in December 2026 and a decision with revised legal directions in May 2027, so payments firms have a short window to tidy their decision logic.
The evaluation, by Frontier Economics and summarised in the PSR's 1 July 2026 release, found that APP fraud losses have fallen by an estimated £73 million a year and that the number of APP scams has fallen by nearly 35,000 because of the policy. It put the short-term net benefit at £17m to £29m after the increased costs to payment firms, which Frontier considers a conservative assessment. Frontier measures reimbursement on a different basis from the dashboard, so its rates below are not directly comparable with the dashboard's 88%.
APP reimbursement rates before and after the policyReimbursement rate for all APP claims before and after the reimbursement policy, and for in-scope claims after it. The third bar uses a narrower base: in-scope claims only. Not directly comparable with the PSR dashboard measure. Source: Frontier Economics evaluation, via PSR release (1 July 2026)
The same release is candid about the gap. It says inconsistent implementation means outcomes can still vary to some degree depending on who consumers bank with, and that the PSR has intervened, and will continue to intervene, where it identifies poor compliance. David Geale, managing director of the Payment Systems Regulator, put it in one line:
There is more to be done to ensure consistency in how consumers are treated
The roadmap puts dates on that intent: stakeholder engagement over the summer, formal consultation in December 2026, then a decision and revised legal directions in May 2027, with implementation within six months of the decision. The institutional setting is moving at the same time. The PSR's 2025/26 annual report records that the Financial Services and Markets Bill was introduced into Parliament on 19 May 2026 with provisions to abolish the PSR and transfer its functions to the FCA, preserving their substance and scope. For now the PSR continues to run the policy, and if the transfer completes, a decision file written today may later be read by the FCA.
What does a decision-grade claim file contain?
A decision-grade claim file contains everything a second reviewer, the receiving firm or the Financial Ombudsman Service would need to reach the same outcome without asking the original handler: the scope and eligibility facts, the vulnerability assessment, every stop-the-clock request with its dates, the exception analysis if one is used, and the amount calculation, including any excess and the 50:50 contribution.
The test is reproducibility. If two experienced handlers given the same file would reach different outcomes, the file is incomplete or the policy is ambiguous, and either one will show up as inconsistency in the regulator's data. The five-part structure below is our framework for a payments firm's claim file, not a PSR template; it simply records the facts each later judgement relies on before that judgement is made.
A decision-grade APP claim fileOur framework: each stage records the facts the next stage depends on, so a second reader can reproduce the outcome.
Most of what goes into those five stages already exists somewhere in the firm: payment data in the core platform, warnings in the app logs, contact notes in the case system, intelligence in the fraud tooling. The cost is in assembling it in the same shape every time, which is where AI earns a place in the process. A drafting layer can pull the facts into the five stages, flag a missing request trail or a vulnerability check recorded after an exception, and propose a reason code. The human still decides; the machine makes it obvious when a decision is missing a leg. Evaluation and observability for production agents is one of our named enterprise AI solutions for the same reason: you cannot claim consistency you do not measure.
Measurement is the second half. A consistency programme samples decisions of the same type each month and compares them: claims with similar facts that ended differently, rejections whose warning evidence is thin, pauses with no recorded request. A firm that runs that sample before the December 2026 consultation will know where its decisions diverge before the regulator's data tells it. Any AI used in drafting or ranking those decisions belongs on the firm's register, the subject of our guide to an AI tool inventory for the FCA and ICO, because a model that shapes conduct outcomes is a governance question in its own right. Where a firm wants that work built rather than advised on, our AI execution office is embedded delivery, with production placements the client owns.
What is the best way for a UK payments firm to run APP claim decisions in 2026?
The best way for a UK payments firm to run APP claim decisions in 2026 depends on volume and on how varied its claims are. A firm with low claim volumes and one experienced team can run well on a case management system and a written decision policy. A firm at higher volume needs reason-coded decisions, monthly sampling and drafting support that keep every handler consistent.
Whichever approach a firm picks, four tests show whether it is working. The table is a buyer's checklist, not a ranking of vendors.
Criterion
What good looks like
How to test it
Reproducibility
Two handlers reach the same outcome from the same file
Blind re-decide a sample of closed claims
Sequence
Vulnerability recorded before any exception
Timestamp check across every rejection
Pause discipline
Every stop-the-clock has a dated request and a reason
Sample pauses against the request log
Split accuracy
Receiving firm contribution matches the excess and vulnerability facts
Reconcile a month of contributions
There are honest alternatives to an outside partner, and for some firms they win. A firm with a mature financial crime operations team, a modern case platform and modest volumes may need nothing more than a rewritten decision policy and an internal quality sample; bringing in consultants would add cost without changing the outcome. At the other end, a group whose change spans several core banking platforms and legal entities may be better served by a large programme partner such as Accenture, Deloitte or PwC for a multi-year platform change. Specialist AI firms such as Faculty sit between those.
DATS is aimed at the middle case: a firm whose decisions are already mostly right, whose data is scattered across several systems, and which wants AI placed into production by practitioners who ship code, not decks. The diagnostic produces a ranked roadmap of where AI belongs in the claim process and where it does not, and our five-stage DATS methodology carries a chosen placement from pilot to production. For the wider industry picture, our UK banking AI guide and the industries category cover the adjacent workflows, from onboarding to complaints.
Does the APP reimbursement duty bind a fintech's partners?
The APP reimbursement duty to the victim sits with the sending payment service provider, and the receiving payment service provider shares the cost 50:50. A fintech that is neither the sending nor the receiving payment service provider is not the party the PSR's direction binds, although its partner bank's decision process may depend on the fintech's customer records being complete.
That dependency is worth writing into the partnership agreement: what customer data the fintech must supply, how fast, and in what form, so the regulated firm can meet its own clock. Our fintech guide covers the wider partner model.
Can a payments firm reimburse more than £85,000?
Yes. The PSR sets a maximum claim of £85,000, which it says covers over 99% of claims, but individual payments firms may choose to reimburse more. Where more than £85,000 is lost and not reimbursed, the customer can take the case to the Financial Ombudsman Service, whose compensation limit is £430,000, so the firm should record why it stopped at the cap.
A firm that sometimes reimburses above the cap should treat that as a policy with criteria, not a goodwill gesture, or it creates exactly the inconsistency the regulator is measuring. If you want to talk through where that line sits for your book, contact our team.
What happens when an APP claim cannot be decided within 35 business days?
The PSR requires the sending payments firm to arrive at an outcome within 35 business days, even where it has stopped the clock, so an APP claim that cannot be decided in that window has missed the deadline the rules set rather than simply running late. The December 2026 consultation will cover how such claims should be treated, which is why each one is worth logging with its cause now.
Logging the cause, whether a slow receiving firm, an unresponsive customer or a police referral, gives the firm its own evidence for the consultation response and a list of the process fixes that would have closed the claim in time.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
app fraud reimbursement clock fintech ukfintechpsr app reimbursement rulesconsumer standard of cautionapp scam claim decisionsapp fraud reimbursement redditbest ai consultancy uk 2026dats
Questions this article answers
What does a sending firm actually decide on an APP fraud claim?
A sending payment service provider decides, for every authorised push payment scam claim, whether the payment is reimbursable, how much to repay and whether an exception applies. Under the PSR's direction, a reimbursable payment is one where the consumer standard of caution exception does not apply, the victim was not party to the fraud, and the claim arrived within the time limit. That duty sits with the payment firm, not the customer.
When can a payments firm stop the five-day reimbursement clock?
A payments firm can stop the five-day reimbursement clock only in the limited circumstances that the PSR places in Section 5 of its Faster Payments reimbursement rules, typically to gather information it needs, such as evidence about a customer's vulnerability. Even with the clock stopped, the firm must arrive at an outcome within 35 business days, so every pause deserves a recorded reason and a dated request trail.
How should a firm evidence a consumer standard of caution rejection?
A firm should evidence a consumer standard of caution rejection by recording what the customer failed to do, what the firm did that the customer disregarded, and why the conduct reaches gross negligence, which the PSR's consumer guidance calls a high bar. The exception does not apply to a vulnerable customer, so a well-built payments firm file shows the vulnerability check came first.
How do vulnerability findings change the decision and each firm's share?
A vulnerability finding changes an APP fraud decision in three ways: the excess cannot be deducted, the consumer standard of caution exception does not apply, and the receiving firm loses its option to reduce its contribution by half the maximum excess. Because two of those turn on it, a payments firm is well advised to settle vulnerability first and record when and how it reached that view.
Why is consistency of claim decisions now the regulator's focus?
Consistency of APP claim decisions is now the regulator's focus because the regulator's own independent evaluation found the policy works overall while outcomes still vary depending on who a consumer banks with. The PSR has published a roadmap with a formal consultation in December 2026 and a decision with revised legal directions in May 2027, so payments firms have a short window to tidy their decision logic.
What does a decision-grade claim file contain?
A decision-grade claim file contains everything a second reviewer, the receiving firm or the Financial Ombudsman Service would need to reach the same outcome without asking the original handler: the scope and eligibility facts, the vulnerability assessment, every stop-the-clock request with its dates, the exception analysis if one is used, and the amount calculation, including any excess and the 50:50 contribution.
What is the best way for a UK payments firm to run APP claim decisions in 2026?
The best way for a UK payments firm to run APP claim decisions in 2026 depends on volume and on how varied its claims are. A firm with low claim volumes and one experienced team can run well on a case management system and a written decision policy. A firm at higher volume needs reason-coded decisions, monthly sampling and drafting support that keep every handler consistent.
Does the APP reimbursement duty bind a fintech's partners?
The APP reimbursement duty to the victim sits with the sending payment service provider, and the receiving payment service provider shares the cost 50:50. A fintech that is neither the sending nor the receiving payment service provider is not the party the PSR's direction binds, although its partner bank's decision process may depend on the fintech's customer records being complete.
DE
Dilr.ai Engineering
Engineering team
Dilr Voice
Voice AI built for your sector
Dilr Voice answers and places calls 24/7 with compliance rules for regulated industries, from clinics and estate agents to financial services.