PSD3 and PSR: Why the new EU payments framework is a transformation programme, not just a compliance exercise

The European payments industry is entering one of its most significant regulatory transformations since the introduction of PSD2 in 2018. With the proposed Payment Services Directive (PSD3) and the Payment Services Regulation (PSR), the European Union is not merely updating an existing regulatory framework. It is fundamentally reshaping how payment services are governed, delivered, secured, and supervised across the Single Market.

For banks, payment institutions, electronic money institutions, fintechs, and other payment service providers (PSPs), the challenge goes far beyond regulatory compliance. PSD3 and PSR together represent a strategic transformation programme that will impact governance, risk management, customer experience, fraud prevention, technology architecture, open banking capabilities, data management, and operating models.

From PSD2 to PSD3 and PSR: Why change was needed

PSD2 delivered significant progress in the European payments’ ecosystem. It introduced Strong Customer Authentication (SCA), enabled open banking through Payment Initiation Services (PIS) and Account Information Services (AIS), and increased competition in the payments market.

However, the European Commission's review identified several shortcomings:

  • Different interpretations and implementations across Member States.
  • Persistent obstacles to open banking.
  • Growing levels of payment fraud, particularly social engineering and impersonation scams.
  • Inconsistent supervision across Europe.
  • Increasing complexity introduced by digital wallets, instant payments, and crypto-assets.

To address these challenges, the EU decided to split the framework into two complementary legislative instruments:

  • PSD3 focuses on authorisation, prudential requirements, governance, and supervision of payment institutions.
  • PSR establishes directly applicable operational, conduct, consumer protection, fraud prevention, and open banking rules throughout the European Union.

 

More than compliance: A strategic transformation programme

Many organisations view PSD3 and PSR as regulatory projects. In reality, they should be approached as enterprise-wide transformation initiatives.

The breadth of impacted domains is remarkable:

1. Governance and operating model need to be thought again

PSD3 introduces strengthened governance obligations, enhanced risk management frameworks, stricter internal controls, updated authorisation requirements, and enhanced supervisory expectations for payment institutions and electronic money institutions. New requirements around safeguarding, winding-up plans, and ICT governance (frameworks, that manages how organizations optimize their use of IT) require senior management attention and board-level sponsorship.

2. Fraud prevention: The area experiencing the most significant transformation

PSR introduces enhanced transaction monitoring obligations, stronger anti-fraud controls, new reimbursement frameworks, mandatory fraud prevention measures, and specific provisions addressing social engineering fraud and payment service provider impersonation scams. The regulation aims to create a much more proactive and intelligence-driven fraud management framework.
Institutions will need to reassess fraud operating models, monitoring tools, investigation processes, customer communication channels, and incident response frameworks. Fraud capabilities will increasingly become a strategic differentiator rather than a purely compliance-driven function.

3. Open banking: The age of maturity

PSD2 introduced open banking, while the PSR is designed to make it work more effectively in practice. The new framework strengthens requirements relating to API availability and performance, the provision of dedicated interfaces, data parity between customer-facing channels and Open Banking interfaces, business continuity arrangements, consent management, and the removal of obstacles that could hinder third-party providers from accessing services.
One of the most visible changes will be the introduction of consent dashboards, enabling customers to manage, monitor, withdraw, and reinstate data access permissions in a transparent and user-friendly manner. This will require substantial investment in API management platforms, customer journeys, data governance mechanisms, and API monitoring capabilities.

4. Customer enhanced protection and experience while strengthening compliance duties.

PSR significantly enhances consumer protection by introducing expanded reimbursement rights, greater transparency on fees and charges, enhanced fraud protection mechanisms, Verification of Payee controls, and improved information disclosure requirements. As a result, customer experience, digital channels, operations, and front-office teams will all be impacted. Financial institutions must ensure that compliance enhancements do not negatively affect customer journeys while simultaneously strengthening security and building customer trust.

5. Verification of Payee: A Game-Changing requirement

One of the most important innovations introduced through the new framework is Verification of Payee (VoP). The objective is straightforward: before a credit transfer is executed, the payer receives confirmation that the beneficiary account matches the intended recipient. This measure directly addresses one of the fastest-growing fraud categories in Europe: authorised push payment (APP) fraud.

Operationally, Verification of Payee requires:

  • New data matching capabilities.
  • Real-time customer notifications.
  • Integration with payment initiation processes.
  • Additional exception handling and dispute management processes.

Many institutions underestimate the complexity of implementing these capabilities across multiple channels and payment infrastructures. In reality, Verification of Payee often affects payment engines, customer channels, fraud systems, operational processes, customer support functions, and third-party providers.

 

The Technology dimension are extensive.

PSR significantly enhances consumer protection by strengthening the rights and safeguards available to payment service users. Under the new framework, customers will benefit from broader reimbursement rights, increased transparency regarding fees and charges, stronger fraud prevention measures, Verification of Payee controls, and more comprehensive information disclosures. These changes are intended to improve confidence in digital payments while providing greater protection against errors and fraud.

Consequently, customer experience, digital channels, operations, and front-office teams will all be impacted. Financial institutions must ensure that compliance enhancements are implemented in a way that preserves seamless customer journeys while simultaneously strengthening security and fostering greater trust in payment services.

 

Key dates to remember

Although the legislative process is approaching its final stages, institutions should already be preparing. The latest Council compromise texts were published in April 2026. Both PSD3 and PSR are expected to enter into force following their final adoption and publication in the Official Journal.

The current framework foresees:

  • Entry into force: 20 days after publication in the Official Journal à S2 2026
  • General application of PSR: 21 months after entry into force à ~2028
  • Verification of Payee and certain fraud-related provisions: 27 months after entry into force.
  • PSD3 transitional arrangements: existing payment institutions and electronic money institutions will generally have up to 27 months to comply with the new framework.

These timelines may appear comfortable, but the implementation effort should not be underestimated. Large financial institutions will need significant lead times to redesign operating models, perform gap analyses, develop technology capabilities, update governance arrangements, and manage regulatory interactions.

 

Executive Management should act now

The organisations that will be most successful in adapting to PSD3 and PSR will be those that start their transformation programmes early rather than waiting for the final implementation deadlines. Achieving compliance requires more than a regulatory review; it involves assessing the impact of the new requirements, defining a target operating model, reviewing fraud prevention strategies, developing an Open Banking transformation roadmap, and evaluating technology and architectural capabilities. Organisations will also need to enhance their API capabilities, redesign customer journeys, update governance and risk frameworks, and align PSD3/PSR initiatives with other key regulatory programmes such as DORA and FIDA.

Importantly, PSD3 and PSR should not be viewed as compliance-only initiatives. A successful transformation programme requires close collaboration across Payments, Operations, Technology, Fraud, Security, Legal, Risk, Data, and Customer Experience functions to ensure that regulatory compliance is achieved while delivering operational efficiency, resilience, security, and an improved customer experience.

 

Conclusion

PSD3 and PSR represent much more than the next generation of European payment regulation. Together, they signal the beginning of a new era for payments, characterised by stronger customer protection, enhanced fraud prevention, greater harmonisation, more mature Open Banking capabilities, and increased operational resilience.

For financial institutions, the question is no longer whether compliance will be required. The real challenge is how to leverage this regulatory change as an opportunity to modernise payment infrastructures, improve customer trust, strengthen resilience, and create long-term competitive advantage.

The institutions that treat PSD3 and PSR as strategic transformation programmes rather than compliance exercises will be best positioned to thrive in the future European payments’ ecosystem.

Want to know more?