In short
- UK banks must now reimburse APP scam victims for eligible Faster Payments and CHAPS claims up to £85,000, split 50/50 between sending and receiving providers, within five business days, since October 2024.
- Weak fraud controls are now a conduct issue. Under the FCA Consumer Duty, a customer scammed because of inadequate systems is treated as foreseeable harm — not just an operational loss.
- DORA makes fraud defence a board responsibility. In force since January 2025, it places ultimate accountability for operational resilience on the management body, and it cannot be outsourced to a vendor.
- The EU AI Act does not automatically classify fraud detection AI as high-risk — Fraud detection is explicitly excluded from Annex III’s credit-scoring category — but transparency, explainability and human-oversight obligations obligations still apply.
- The net effect: banking fraud regulation has converged into a governance and personal-accountability problem that demands explainable, auditable decisions at scale.
For most of the last decade, fraud sat on the balance sheet as a managed operational cost, measured against peers and accepted within a defined risk appetite. The teams running fraud always understood how much it mattered, but it rarely demanded much of the board's attention.
That operating model no longer fits the regulatory environment. Four separate regimes, written by different authorities for different reasons and on different timelines, have ended up pointing at the same conclusion: fraud is now something the institution is accountable for, something the board is expected to oversee, and, increasingly, something named executives can be held personally answerable for.
None of these regulations references the others, yet read together, they point to the same conclusion. Fraud is no longer judged solely by how much money a bank loses. It is judged by how well the institution governs the decisions that prevent those losses in the first place.
Are banks now liable for APP fraud losses?
They are now, by statute. For years the customer who authorised a payment to a fraudster generally absorbed the loss, but that premise no longer holds.
In the UK, mandatory reimbursement for Authorised Push Payment (APP) scams has been in force since October 2024. Payment service providers must reimburse victims on Faster Payments and CHAPS up to £85,000 per claim, within five business days, with the cost shared equally between the sending and receiving institution. The regulator was candid about why: the aim was to move the financial consequence onto the firms best placed to prevent the fraud.
The EU is heading the same direction. The emerging PSD3 and Payment Services Regulation framework normalises APP fraud reimbursement and pushes liability further across the ecosystem - from sending and receiving providers, to, in some cases, thecases, the platforms and technical actors that enable the attack.
The commercial impact is immediate: fraud losses that once fell on customers now land directly on the institution.
Do weak fraud controls breach the FCA Consumer Duty?
They can, and that is far harder to manage than a loss you can simply quantify.
Under the FCA Consumer Duty, firms must act to deliver good outcomes and avoid foreseeable harm. Regulators have already drawn the line to fraud directly: a customer falling victim to a scam because a firm's systems and controls were inadequate is treated as foreseeable harm. The reimbursement data firms now report is used to monitor conduct failings and inadequate controls, not just to track payouts.
This changes what fraud performance actually measures. It is no longer judged solely by how much loss a firm managed to recover, but also by whether it did enough to prevent harm — and whether it can demonstrate that it did. It is no longer judged solely by how much loss a firm managed to recover, but also by whether it did enough to prevent harm — and whether it can demonstrate that it did.
Does DORA apply to fraud prevention systems?
It does. DORA, the EU's Digital Operational Resilience Act, has applied since January 2025, setting binding expectations for ICT risk management, incident reporting, resilience testing and third-party risk, while placing ultimate responsibility with the institution's management body.
Boards tend to underestimate that final point. Responsibility for operational resilience cannot be handed to a vendor along with the software; you can buy the technology, but you cannot buy your way out of owning the outcome. Modern fraud is a digitally executed attack on a critical financial service, which means it sits squarely within this perimeter.
Is fraud detection high-risk under the EU AI Act?
No. This is the detail most coverage gets wrong. The EU AI Act explicitly carves AI used to detect financial fraud out of the high-risk creditworthiness category set out in Annex III. Fraud-detection systems are not automatically treated as high-risk.
That carve-out does come with conditions. Transparency, AI-literacy, and human oversight obligations continue to apply, and a system that effectively denies people access to services may still fall within those requirements. The incoming EU anti-money-laundering framework and its new supervisory authority will expect institutions to document the methodology behind any AI used in monitoring and risk scoring. Supervisors have already signalled that financial services will be one of the first sectors they examine closely.
The Digital Omnibus agreement of May 2026 deferred the main Annex III high-risk obligations to December 2027. The delay gives institutions time to strengthen AI governance before those obligations take effect. Waiting for the deadline will leave very little time to adapt operating models, controls and oversight.
The pattern underneath the four
Despite their different origins, these four regimes ask for remarkably similar things. Each one, in its own language, requires the institution to demonstrate the same capabilities: produce good outcomes, avoid foreseeable harm, stay operationally resilient, and explain its automated decisions, while being able to show how those decisions were reached, on demand, to a supervisor or a court.
That makes this a governance challenge before a technology one, with direct consequences for how fraud operations are organised and executed every day.
Why your operating model is the real exposure
The accountability bar has risen sharply, yet the operating model expected to clear it has barely moved. A fraud function built around human investigators simply cannot examine every alert, case, and signal that requires attention. Across the industry, a substantial share of cases that genuinely warrant a full investigation never get one, not because teams are negligent, but because the volume of fraud signals exceeds the investigative capacity available. Many institutions have quietly come to accept this coverage gap as a cost of doing business.
Set that gap against the four regulatory demands, and it becomes much harder to defend. You cannot show that you avoided foreseeable harm on a case no analyst ever opened, and you cannot produce an explainable, auditable decision trail for an investigation that never took place. The greater exposure is not the fraud you detect and still lose to, but the volume of suspicious activity you never reach, and therefore can never account for.
What satisfies all four at once
The operating model that satisfies these regulatory expectations has a recognisable set of characteristics. Every case gets investigated rather than a representative sample; every decision is explainable and auditable, with the underlying reasoning preserved instead of scattered across tickets and the memories of individual analysts; and human accountability stays where the consequences are, on the decisions that carry real weight, while the work itself runs at machine scale.
This is where Autonomous Fraud Operations diverges from conventional automation. Automation helps analysts do what they already do more quickly, which leaves the human as the structural bottleneck and the coverage gap firmly in place. Autonomous Fraud Operations removes that throughput constraint, while keeping the human firmly on the loop, governing outcomes rather than clearing queues.
This operating model is already running in production. Since December 2025, Cleafy has operated Autonomous Fraud Operations at leading European banks. Nyx assesses every event end-to-end in minutes rather than hours, logging and timestamping each recommendation so it can be traced back through the evidence that produced it, and leaving consequential actions to be authorised by a person rather than a black box. Every recommendation is fully traceable, creating an audit trail that supports governance, oversight and regulatory review.
The point regulators were quietly making
None of these regulations asks banks to investigate fewer cases or make slower decisions. What they ask for is the ability to explain those decisions, at the speed and scale at which modern fraud operates. The next test for financial institutions will be whether they can demonstrate, for any individual case, what was decided, why, and by whom. The institutions that treat banking fraud regulation as a reason to redesign how they operate, rather than as simply another compliance deadline to clear, are the ones that will stay ahead of it.
For bank boards, the question is no longer whether fraud operations need to change. It is whether today's operating model can withstand tomorrow's scrutiny.
%20copia%208.png)
.png)
%20(3).png)
%20(1).png)
%20(1)%20copia%203.png)