Skip to content

United Kingdom

The UK’s APP-fraud reimbursement regime: what mandatory scam refunds mean for payment firms

Since 7 October 2024, UK payment firms have been required to reimburse victims of authorised push payment (APP) fraud up to £85,000 per claim, with the cost split 50/50 between the sending and the receiving firm — so every impersonation scam that starts on an uncaught lookalike domain is now a direct reimbursement cost as well as a brand problem.

Last reviewed: July 20, 2026

£85,000
maximum reimbursement per APP-fraud claim under the mandatory regime
Source: PSR / FCA
50/50
the reimbursement cost is split between the sending and the receiving payment firm
Source: PSR reimbursement rules
88%
of claimed losses returned to victims — with losses cut by roughly £73m a year — in the regime’s July 2026 independent review
Source: Independent review of the regime, 2026

The mandatory reimbursement regime was introduced by the Payment Systems Regulator (PSR), whose functions are now being folded into the FCA. It applies to FCA-regulated payment and e-money institutions, and it changed the economics of impersonation overnight: impersonation and purchase scams — routinely delivered through lookalike domains and cloned pages — are among the largest categories of APP fraud. The July 2026 independent review found the regime is working, cutting losses by roughly £73 million a year and returning 88% of claimed losses to victims, and the FCA has issued Dear-CEO letters setting out its expectations of payment and e-money firms. For a payment firm, the practical question is no longer whether to watch for impersonation, but how quickly you find the clone before it drives claims.

What the reimbursement regime requires

Since 7 October 2024, in-scope payment service providers must reimburse victims of authorised push payment fraud up to £85,000 per claim. The cost is split 50/50 between the sending and the receiving firm, so a firm can carry liability on either side of a scam payment. The regime was created by the Payment Systems Regulator and is moving into the FCA as the PSR’s functions are absorbed — with Dear-CEO letters to payment and e-money institutions already setting out what the FCA expects.

Why lookalike domains show up on your P&L

Impersonation and purchase scams are among the largest APP-fraud categories, and they are routinely delivered through lookalike domains and cloned pages: a fake version of your login page, a spoofed payments brand, a "support" site that walks a customer into an authorised transfer. Before October 2024 that was a trust problem. Under mandatory reimbursement, every scam that a convincing clone of your brand facilitates can translate directly into claims your firm pays.

What the July 2026 review changed

An independent review published in July 2026 found the regime cut fraud losses by roughly £73 million a year and returned 88% of claimed losses to victims. The direction of travel is more regulatory attention, not less: the PSR is being abolished and its functions moved into the FCA, which has written to payment and e-money firms about its expectations on APP fraud. Firms that can show proactive detection of the impersonation infrastructure behind claims are in a materially better position.

How impersona.io helps

impersona.io generates 180+ permutations of your domain and checks each against live DNS and registration data, captures takedown-ready evidence, and alerts you when a new lookalike or certificate appears — so the clone that would drive APP claims is found in minutes, not after the first reimbursement. It is self-serve, transparently priced, and needs no sales call to start.

Frequently asked questions

What is the UK APP-fraud reimbursement regime?

It is the mandatory reimbursement regime for authorised push payment fraud, in force since 7 October 2024. Payment firms must reimburse victims up to £85,000 per claim, with the cost split 50/50 between the sending and the receiving firm. It was introduced by the Payment Systems Regulator, whose functions are moving into the FCA.

Who does it apply to?

FCA-regulated payment service providers — including payment institutions and e-money institutions — on both sides of an in-scope payment. UK fintech brands are squarely in scope, and the FCA has issued Dear-CEO letters setting out its expectations of payment and e-money firms.

Does the regime require brand monitoring?

Not in so many words — it mandates reimbursement, not specific controls. But because impersonation scams delivered through lookalike domains are a top APP-fraud category, every uncaught clone converts directly into reimbursable claims. Continuous detection is how firms reduce the exposure the regime now prices in.

Does the ECCTA "failure to prevent fraud" offence cover brand impersonation?

No. That offence covers fraud committed by a firm’s associated persons — employees, agents, subsidiaries — for the firm’s benefit. Fraud where your firm is the victim, which is what third-party brand impersonation is, sits outside its scope. Some vendors stretch that claim; we would rather tell you plainly that the UK driver for monitoring is the reimbursement regime, not ECCTA.

impersona.io is EU-hosted — does that matter for a UK firm?

For most UK buyers it is a non-issue. Data is stored and processed in the EU (Frankfurt), encrypted in transit and at rest. If your organisation requires in-region hosting for a regulated use case, ask us — we will be straight about current limits rather than overpromise.

Do I have to talk to sales?

No. impersona.io is fully self-serve with transparent pricing — you can pay in your local currency at checkout — and your first brand check is free, no demo call required.

Other regions

See your own exposure first

Your first brand check is free. It generates roughly 160 permutations of your domain and checks them against live DNS and domain registration data.