Fraud has always been the shadow lurking at the edges of digital payments, but the Payment Services Directive II (“PSD 2”)’s introduction of strong customer authentication seemed, at first, to have turned the corner. Yet reality proved less tidy. Authorised push payment (“APP”) fraud continued to rise, exploiting the gap between formal authorisation and genuine consent. Under PSD2, consumers were frequently left to shoulder the loss, a solution that satisfied legal logic but strained notions of fairness and consumer trust. The European Commission recognised that treating fraud as a problem of user behaviour rather than institutional responsibility was no longer tenable.
PSD III reframes the narrative entirely. Fraud is now seen as a systemic challenge, one that institutions must actively prevent and absorb rather than shift onto unsuspecting customers. A mandatory reimbursement regime for victims of APP fraud makes clear that liability rests primarily with the payment service provider, except in cases of gross negligence or deceit by the customer. This recalibration has profound implications for Maltese Payment Services Providers (“PSPs”), who must now view fraud risk not as an operational inconvenience but as a core financial, reputational, and strategic concern.
Meeting these obligations requires more than upgraded systems; it demands a reconsideration of governance philosophy. Real-time transaction monitoring, behavioural analytics, and IBAN-name verification become not just best practices but central pillars of compliance. Even outsourcing arrangements must be scrutinised for their ability to uphold the institution’s responsibility under PSD III, aligning with broader EU standards such as the Digital Operational Resilience Act (“DORA”) and Anti-Money Laundering/Countering the Financing of Terrorism (“AML/CFT”) obligations. Policies, procedures, and staff training must be more than boxes to tick, they must reflect a culture of accountability that can withstand both regulatory inspection and the glare of public scrutiny.
For Maltese PSPs, the implications of PSD III on APP fraud are not abstract and they translate directly into decisions about governance, technology, and customer interaction. Institutions should begin by reviewing and updating all fraud prevention policies and procedures, ensuring they reflect the directive’s mandatory reimbursement obligations. This includes evaluating transaction monitoring systems, implementing IBAN-name verification, and embedding behavioural analytics capable of flagging suspicious activity in real time. Staff training and awareness programs must reinforce a culture of accountability, so that all employees understand their role in preventing and responding to fraud. Institutions should also assess outsourcing and third-party arrangements to verify that service providers can meet PSD III obligations, and that contractual safeguards are robust enough to withstand regulatory scrutiny. Finally, board-level oversight must extend to fraud risk, linking operational controls to strategic decision-making and demonstrating to the MFSA, and to clients, that the institution treats fraud as a core legal and reputational responsibility, not merely an operational inconvenience.
PSD III is not merely a regulatory update, but it is a call to reimagine the responsibilities of payment institutions in the digital era. Fraud is a central legal and strategic concern and not a mere peripheral operational challenge. Maltese PSPs that respond proactively, embedding compliance, governance, and risk management at the heart of their operations, will not only mitigate liability but also enhance credibility, client confidence, and long-term market positioning. With expert legal guidance, institutions can approach PSD III as an opportunity to lead in an increasingly regulated, interconnected, and fraud-conscious payments landscape.
