Crypto authorisation: why financial crime evidence will matter more than policy
Crypto authorisation: why financial crime evidence will matter more than policy, Start with the transaction flow, not the policy suite.
08 Oct 2026 7 min read

On 7 October, the UK’s mandatory reimbursement regime for authorised push payment (APP) fraud was two years old.
When the rules were introduced, much of the debate focused on who should bear the cost of fraud, whether reimbursement could weaken customer caution and how payment firms would manage the operational burden. Two years on, there is now enough evidence to move that conversation forward.
The independent evaluation carried out by Frontier Economics for the Payment Systems Regulator (PSR) found that APP scam losses sent over Faster Payments fell by around 21% following the introduction of the reimbursement requirement, equivalent to approximately £73 million a year. It also found that the new requirements strengthened incentives for payment service providers to invest in fraud prevention.
Consumer outcomes have improved too. In the first 18 months of the regime, 88% (£316 million) of money lost through reimbursable APP scams was returned to victims, while 82% of claims were closed within five business days. The PSR has also reported no indication that consumers have become significantly less cautious as a result of the reimbursement arrangements.
Reimbursement was never intended simply to create a better process for dealing with fraud after it happened. By changing the economics for sending and receiving payment firms, it was also intended to strengthen the incentive to prevent the fraud in the first place.
Many traditional fraud controls are concentrated around the payment itself or what happens afterwards: customer warnings, transaction monitoring, investigation, account freezing and reimbursement.
The problem is speed; by the time suspicious activity has generated an alert and reached an investigator, the funds may already have passed through several accounts.
The Government’s 2026 Fraud Strategy sets a clear direction towards earlier disruption of fraud and greater use of shared intelligence. The Financial Conduct Authority is moving in the same direction: its 2026/27 work programme says it will continue integrating multiple datasets to identify financial crime earlier and intervene more quickly.
For payment firms, that means asking where the earliest reliable indicators appear, i.e. when a customer is onboarded, when a device or account behaviour changes, when a new beneficiary is created or during payment initiation. An unusual payment may look materially different when combined with a newly registered device, an unfamiliar beneficiary, previous scam indicators or connections to accounts already associated with suspicious activity.
The objective should not be to stop more legitimate payments, it is to use the information already available across the customer journey to make a better decision before the payment is released.
That creates a different design question: what is the earliest point at which the firm has enough confidence to intervene, and what is the proportionate intervention at that point?
Sometimes that will mean stopping a payment, but more often it may mean additional authentication, a targeted customer warning, further confirmation of the beneficiary or a short delay while higher-risk activity is reviewed.
APP fraud is also difficult to address if firms continue to treat each scam as an isolated payment. Fraud proceeds commonly move through mule accounts and networks of connected beneficiaries. Individual transactions may look relatively unremarkable, but the relationships between accounts can tell a different story.
The reimbursement regime deliberately changed the incentives for both sending and receiving firms, and the independent evaluation found that firms responded by strengthening prevention activity.
That means connecting information that has traditionally been considered separately: customers, accounts, devices, IP addresses, beneficiaries, companies and transaction patterns. Where several apparently unrelated customers share the same device, repeatedly pay the same beneficiaries or form part of the same flow of funds, investigating each alert separately can obscure the wider pattern.
For some firms, the biggest improvement in fraud prevention may therefore come not from another payment rule, but from better entity resolution and network detection.
There is also a limit to what payment firms can achieve alone. The Government’s Fraud Strategy notes that 53% of reported APP fraud cases in 2023 involved social media, messaging and call platforms, while other cases involved online marketplaces and telecommunications platforms. By the time the payment firm sees the transaction, the victim may already have been interacting with the criminal for days or weeks.
The Strategy’s creation of an Online Crime Centre is intended to improve collaboration and intelligence sharing across government, law enforcement and industry, including the technology and financial-services sectors.
For firms, the practical question is whether external intelligence can reach their controls quickly enough to change an outcome.
If another institution identifies a suspected mule account, how quickly does that information alter the treatment of connected accounts? If a phone number, website or online account is linked to an active scam campaign, can that signal influence a payment decision while it still matters?
The reimbursement regime has also created much better information about claims and consumer outcomes. Firms now need the same discipline when assessing fraud prevention.
Traditional measures such as alert volumes, investigation times and the number of customer warnings are useful operational indicators. They do not, on their own, tell management whether fraud controls are working.
There is no perfect measure of the proportion of fraud a firm prevents because the total population of attempted or undetected fraud is not observable. Firms can, however, build a much stronger picture by combining several forms of evidence.
Confirmed fraud and mule populations can be back-tested to establish which controls identified them and when. Cases discovered through one route can be used to identify false negatives in another control. Firms can track whether detection is moving earlier in the journey, examine activity immediately below important thresholds and test whether new controls perform better against known typologies.
The useful questions become more specific:
The two-year anniversary is a useful point for firms to step back from reimbursement operations and test whether their fraud framework is actually becoming more preventive, with a focus on five key areas:
This does not necessarily require wholesale replacement of the fraud-control environment. In many cases, targeted changes to existing data, thresholds, decision points or investigation processes may materially improve prevention. The practical challenge is to identify where the current framework is still too reactive and where investment will genuinely move intervention earlier.
The reimbursement regime has improved the safety net. The next phase should be about needing it less often.
Crypto authorisation: why financial crime evidence will matter more than policy, Start with the transaction flow, not the policy suite.