PSD3 Is Coming: What the EU’s New Payment Rules Mean for Fraud Prevention 

SHARE:

payment services directive 3 and payment services regulation

Payment fraud is becoming more sophisticated, while responsibility for preventing it is shifting toward payment service providers. The proposed PSD3 and Payment Services Regulation respond with stronger fraud prevention, clearer liability rules, and enhanced customer authentication requirements

For banks, fintechs, payment institutions, and electronic money institutions, the reform will affect onboarding, transaction monitoring, identity verification, and open banking processes.  

This article explains the key changes, why trusted digital identity matters, and how businesses can prepare. 

What are PSD3 and the PSR? 

The third iteration of the EU’s Payment Services Directive, commonly referred to as the PSD3, is a new legislative framework for payment services proposed by the European Commission in June 2023. The proposed third directive and an upcoming Payment Services Regulation (PSR) aim to replace the currently active PSD2 and the e-Money Directive. 

The PSD3 governs licensing, authorization, and supervision. Like with other directives, each EU member state is responsible for transposition into national law. The PSR, on the other hand, applies uniformly across all member states without national transposition. It governs day-to-day conduct rules, including strong customer authentication (SCA), fraud liability, and open banking. 
 
In November 2025, the European Commission reached a provisional agreement about the change. The text was subsequently approved in May 2026, with publication in the Official Journal expected before the year’s end.  

The proposal includes a generous transition window of 18 to 21 months, so the expected deadline for compliance with the new regulations may be in late 2027 or early 2028. 

What’s new in the PSD3/PSR? 

stack of legal books on regulations

The PSD3 and PSR as a combination are much more than a simple update of the second Payment Services Directive. The proposal comes with lots of changes related to transaction liability, fraud prevention, payment activity monitoring, and more. 

Some of the key changes to address include, among others: 

  • Much stronger focus on fraud prevention frameworks;
  • More centralized checks of payees before each transaction; 
  • Revised rules around SCA with additional guidance on wallets and mobile banking; 
  • Enhanced guidelines for suspicious behavior monitoring and fraud detection; 
  • Clearer rules regarding the allocation of liability.  

The Changes That Matter Most for Business Compliance Teams 

If you are responsible for ensuring your business meets the new legal requirements set out in the PSD3/PSR, here are a few points to pay special attention to. 

Fraud liability shifts toward PSPs 

Payment services providers (PSPs) that fail to implement adequate fraud controls become liable for customer losses. The obligation includes a new reimbursement right for impersonation and spoofing scams. 

Mandatory payee-name/IBAN verification 

PSPs must check that a payee’s name matches their account identifier before processing a transfer. In addition, they must flag mismatches they detect. This rule is already required for SEPA Instant, but the new regulation extends it EU-wide. 

Stronger, more flexible SCA  

According to the new legislation, there will be much tighter verification rules for high-risk transactions. Furthermore, the proposal expands risk-based exemptions and increases real-time fraud monitoring expectations. 

Open banking overhaul 

The PSD3/PSR require mandatory API performance parity with proprietary channels. They call for the elimination of screen-scraping fallbacks and the establishment of permissions dashboards for consumers to see and revoke data access. 

Re-authorization, not automatic carry-over 

Payment institutions (PIs) and electronic money institutions (EMIs) will need to undergo authorization again to remain compliant. Existing organizations will benefit from a transition window of 24-30 months before they are required to prove compliance with the updated PSD3/PSR legislation. 

Identity Verification Sits at the Center of PSD3 Compliance

identity verification on a mobile phone

As you can see from the core changes proposed to the payment regulations, many of the affected processes involve verifying the identities of all parties in the transaction. Virtually all the changes we outlined above depend on being able to prove who is on the other end. 

If your onboarding and authentication processes are not properly secured, they leave room for impersonation and APP fraud. These kinds of issues are what the PSD3 is specifically designed to limit.  

As a result, banks, fintechs, and other PSPs will need to modernize identity verification flows and strong authentication infrastructure. These processes need to be secured before PSD3/PSR comes into force to save on regulatory, operational, and remediation costs later on.  

Moreover, improving identity verification now can bring your business in alignment with the wider European legal framework. Think of compliance with eIDAS and the upcoming rollout of the EUDI wallet. The highly regulated finance industry will be forced to accept the wallet as an identification method. 

Essentially, addressing these processes within your business now can check multiple boxes because the digital trust infrastructure in the EU is converging.  

How Evrotrust Supports PSD3 Readiness 

As an eIDAS-compliant qualified trust services provider (QTSP), Evrotrust has already built the solutions that the identity assurance aspects of the PSD3/PSR will require. 

We offer remote identity verification as a notified eID scheme. This solution can plug directly into customer onboarding flows, supporting payee-name/IBAN matching and KYC obligations. In addition, we offer several tiers of KYC solutions that you can mix and match in your workflows as process sensitivity demands. 

Moreover, Evrotrust offers qualified electronic signatures and seals for authorizing high-risk transactions and satisfying SCA’s “something you are” factor.  

All our solutions are completely audit-ready, with legally recognized verification trails. They meet the stricter supervisory and evidentiary standards under PSD3/PSR. 

Also, as we continue work on our iteration of the EUDI wallet, we help businesses ensure readiness for both the PSD3 and eIDAS through a single coordinated approach. 

What Businesses Should Do Now 

It’s true that the final text of the PSD3 and the PSR is not available yet. Nevertheless, waiting for its publication could cost you in the long run. 

Now is an excellent time to begin a gap analysis against the agreed text, since the substance is largely locked in even if the exact application date isn’t. Audit your current authentication and onboarding flows against the proposed upcoming SCA/fraud-liability standards, find areas for improvement, and create a plan today to be ready for compliance tomorrow. 

One of the most important things you can start now is engaging with your compliance, IT, and identity-verification partners. It may still be early, but keep in mind that implementation is a multi-year effort, not a one-time update. The more time you allow for planning, testing, and improving, the better. 

contact sales for PSD3 compliance banner

Frequently Asked Questions About PSD3 and the PSR 

What is the difference between PSD3 and the PSR? 

PSD3 covers the authorization and supervision of payment institutions and electronic money institutions. The PSR sets operational rules for areas such as fraud prevention, liability, strong customer authentication, and open banking. 

When will businesses need to comply? 

The final deadlines will be confirmed after the legislation is formally adopted and published. Businesses should begin reviewing their processes now, as implementation may require significant technical and operational changes. 

How will the new rules affect fraud liability? 

Payment service providers will face stronger obligations to prevent fraud and protect customers. In some cases, providers may be required to reimburse losses if adequate controls were not applied. 

Why is identity verification important? 

Reliable identity verification helps reduce impersonation, account takeover, and fraudulent onboarding. It also strengthens customer authentication and provides evidence that the correct person completed a process. 

How can Evrotrust support PSD3 readiness? 

Evrotrust provides remote identity verification, qualified electronic signatures, and qualified electronic seals. These services can support secure onboarding, legally binding approvals, and auditable digital processes. 

Similar resources

Looking for the best trust services to digitize your business?

Evrotrust’s reliable, well-rounded toolkit will meet all digitization needs your company faces.

Happy office workers