PSD3 and PSR
Published on
01/10/2026
Updated on
01/10/2026
Reading time
2 min
As of 1 October 2026
Definition
PSD3 is not a single legal act but a package of two: the PSD3 directive, which governs the authorisation and supervision of payment service providers and has to be transposed by the Member States, and the PSR regulation, which applies directly and holds the conduct rules (fraud liability, verification of payee, open banking).
State of play
Parliament and Council reached a provisional agreement on 27 November 2025, and Parliament’s Committee on Economic and Monetary Affairs endorsed the text on 5 May 2026. What is outstanding is formal adoption and publication in the Official Journal. In substance almost everything is settled; in law, PSD2 continues to apply until then.
The deadlines only start to run from publication: under the compromise text the PSR applies on entry into force, the articles on verification of payee follow 27 months later, and the Member States have 21 months to transpose PSD3. A reliable date will exist only once the text is in the Official Journal.
What changes
One point first, because it is often misrepresented: Verification of Payee is not a project of the PSR but law in force under the Instant Payments Regulation – and for credit transfers generally, not only for instant credit transfers. The PSR captures the payments not covered there and ties refund and compensation claims to the check.
| Topic | today (PSD2 and IPR) | under PSD3 and PSR |
|---|---|---|
| Verification of Payee | mandatory for credit transfers in euro, not only for instant credit transfers | additionally for the payments the IPR does not cover |
| Liability for the check | no rule of its own | refunds and compensation are tied to the check |
| Impersonation fraud | refund only for unauthorised payments | full refund where the fraudster abuses the institution’s own identity |
| Burden of proof | with the customer once they have authorised the order | with the institution, which must prove fraud or gross negligence |
| Open banking | dedicated interface under PSD2 | architecture retained in essence, the boundary between services sharpened |
| Customer support | no rule | access to a human being, not only to a chatbot |
| Legal form | one directive, transposed nationally | a directive for authorisation and supervision, a regulation for everything else |
The genuinely new element is the treatment of impersonation fraud: where a consumer is manipulated into authorising a payment because the fraudster poses as the institution through the institution’s own communication channels, the institution must refund the amount in full (provided the customer reports it without undue delay and files a report with the police). The burden of proving fraud or gross negligence on the customer’s part lies with the institution.
What it means for banks and payment service providers
The effort lies less in new technology than in the shift of liability. Procedures that run today but are poorly parameterised become a refund risk, and in cases of impersonation fraud the institution will have to prove what it could previously dispute. That calls for dependable logging of what was shown to the customer and how they decided – not just of the display itself. On top of that come the parallel deadlines: PSD3 is transposed nationally, the PSR applies directly, and individual obligations only bite years after entry into force.
Sources
- Regulation (EU) 2024/886 – Instant Payments Regulation, in particular Article 5c
- European Parliament – Legislative Train on the revision of the EU payment services rules
- Arthur Cox – PSD3 and PSR: Final compromise texts published
- Linklaters – PSD3 breakthrough: EU legislators agree payments regulation reforms
- Freshfields – PSD3/PSR: What the EU’s new payments rules mean for your business