PSD2 felt like a bombshell piece of legislation when it first came in, with high hopes of open banking transformation. And while the regulation has been successful in some areas, inefficiencies like high fraud rates have also been identified, leading to the introduction of the PSR. The EU’s recent report listed “unharmonized implementation”, “cross-border difficulties” and “disproportionate requirements and costs” as barriers under PSD2. In this article, learn all about PSR and how it will fix those challenges.
Trustpair goes further than European regulation in terms of fraud prevention, by providing ongoing account validation. Contact an expert to learn more!
Key Takeaways
- The Payment Services Regulation (PSR) is a new EU regulation that directly applies across all member states, no national transposition needed.
- It works alongside PSD3 to replace PSD2, addressing fraud, open banking, and consumer protection gaps.
- After a provisional political agreement in November 2025, final texts were published in April 2026. The PSR is expected to apply from mid-to-late 2027, following a 21-month transition period.
- The PSR introduces mandatory IBAN-name verification (Verification of Payee), stronger SCA rules, and enhanced fraud liability frameworks.
- Tools like Trustpair’s account validation platform already deliver the payee verification standard that PSR is mandating, helping businesses stay ahead of compliance requirements.
What is the Payment Services Regulation (PSR)?
- Strengthen fraud prevention, including mandatory payee verification before any transfer
- Expand consumer rights and transparency around fees and charges
- Harmonize open banking rules across the EU
- Level the playing field between banks and non-bank payment service providers (PSPs)
What is the difference between PSR and PSD3?
PSR key obligations
- Accessible financial services: Transparent, non-discriminatory rules for all customer groups, including vulnerable populations
- Fraud prevention: Transaction monitoring, mandatory information-sharing between PSPs, and IBAN-name verification before all transfers
- Open banking data sharing: Standardized API access for third-party providers (PISPs and AISPs)
- SCA upgrades: Refined Strong Customer Authentication, including biometrics and passkeys
PSD3 key obligations
- Harmonized licensing timelines (3-month approval from complete application)
- Consolidated PI and EMI licensing into a single framework
- Consumer data dashboards showing which third parties hold permissions
- Improved cross-border supervision, including “triangular passporting”
- Alignment with DORA (Digital Operational Resilience Act)
What are the main fraud prevention measures in the PSR?
Mandatory IBAN-name verification (Verification of Payee)
Fraud data sharing between PSPs
Enhanced liability rules
Why this matters for companies
What is the PSR and PSD3 implementation timeline?
- June 2023 — European Commission proposes PSD3 and PSR
- 2024–2025 — European Parliament and Council review and negotiate draft texts
- November 2025 — Provisional political agreement reached between Parliament and Council
- April 2026 — Final compromise texts published (Council, 23 April 2026); ECON Committee vote (5 May 2026)
- H2 2026 — Expected publication in the EU Official Journal (June–September 2026 window)
- 2027 — Entry into force; 21-month transition period begins
- Mid-to-late 2027 — PSR begins to apply across all EU member states
- 24 months after entry into force — IBAN-name check (Verification of Payee) obligation and related liability apply
How should businesses prepare for PSR compliance?
- Upgrade payee verification processes — Implement IBAN-name matching before executing any outgoing payment. Trustpair’s platform already automates this continuously, not just at onboarding.
- Review SCA setups — Assess whether current authentication methods meet the updated requirements, including biometric and passkey support.
- Audit your open banking APIs — Ensure third-party data access is consistent, well-documented, and secured to PSR standards.
- Map fraud data sharing obligations — Identify which fraud signals should be shared with other PSPs and establish the operational processes.
- Update outsourcing and vendor contracts — Revisit agreements with technical service providers and SCA vendors to address liability allocation.
- Engage regulators early — Open dialogue with national regulators on transition timelines and re-authorisation expectations (especially for PIs and EMIs under the merged licensing regime).
