in

Authorized Push Payment Fraud or Customer Abuse? Managing Disputed Transfers in FinCrime Operations

When Customers Authorize the Payment and Then Deny It: Risks, Red Flags, and Operational Implications for Banks

Authorized Push Payment Fraud or Customer Abuse
Authorized Push Payment Fraud: Managing Disputed Transfers and Abuse

Authorised push payment fraud creates a difficult evidential problem because the payment can be technically valid while the customer’s decision is criminally manipulated. The customer may log in through a recognised device, pass strong customer authentication, create or select a beneficiary and confirm the transfer. Those records establish that the payment instruction travelled through the expected channel. They do not, by themselves, establish that the customer understood the recipient’s true identity, the real purpose of the payment or the deception surrounding the transaction.

The opposite risk also exists. Reimbursement and consumer-protection mechanisms can be targeted through first-party fraud: a customer knowingly makes or participates in a payment and later presents a false scam narrative to recover the funds. Between these positions sit civil disputes, coercion, vulnerability, account sharing, collusion and cases where genuine victims provide incomplete or inconsistent accounts because of embarrassment, trauma or continuing influence from the fraudster.

For FinCrime operations, the task is therefore not to label the customer as either victim or abuser at the beginning of the investigation. It is to reconstruct what happened, determine which regulatory and reimbursement framework applies, and reach an evidence-led, auditable decision.

Key Takeaways

  • Authentication Does Not Equal Informed Consent
  • APP Fraud Can Involve Fully Authorised Payments
  • Customer Abuse and Genuine Victimisation Can Look Similar
  • First-Party Fraud Requires Evidence, Not Suspicion
  • Civil Disputes Must Be Distinguished from APP Scams
  • Customer Intent Is Central to APP Investigations
  • Vulnerability Can Materially Affect Scam Outcomes
  • Device Evidence Is Important but Not Conclusive
  • Receiving-Side Intelligence Can Expose Wider Fraud Networks
  • Accurate Adjudication Matters More Than Approval or Rejection Rates

Listen the podcast

Watch the video

Why disputed authorised payments matter now

Authorised push payment fraud has become one of the central risks in account-to-account payments. UK Finance reported £576.4 million of APP fraud losses across 248,070 cases in 2025, representing a 19% increase in value and a 7% increase in cases compared with 2024. Its data also showed a continued shift towards “malicious payee” scams—including investment, purchase, romance and advance-fee fraud—in which victims pay the intended recipient but are deceived about the legitimacy or purpose of the transaction.

This distinction matters operationally. In a malicious-redirection scam, the customer intends to pay a legitimate party but is given fraudulent account details. In a malicious-payee scam, the customer deliberately pays the identified recipient, but the product, investment, relationship or opportunity has been misrepresented. The second category can be harder to detect because the payment destination and customer intention may appear aligned until the wider deception is understood.

The reimbursement landscape has also changed materially. Since 7 October 2024, in-scope Faster Payments and CHAPS APP scam claims are generally reimbursable, subject to defined limits, exclusions and exceptions. Sending payment service providers ordinarily have five business days to decide a claim, may pause that period only in specified circumstances and must close the claim within 35 business days. The mandatory reimbursement cap is £85,000 per claim, while receiving PSPs generally contribute 50% of the amount reimbursed.

Early data illustrates the operational significance of the regime. During the 15 months to 31 December 2025, the Payment Systems Regulator recorded approximately 352,000 reported claims, of which 243,000 were considered in scope for reimbursement. It reported that 89% of reimbursable losses by value had been returned, 82% of claims were closed within five business days and 98% within 35 business days.

These outcomes strengthen victim protection, but they also increase the importance of correct claim classification, defensible evidence standards and effective controls against deliberate first-party abuse.

The difference between authentication, authorisation and informed intent

A recurring operational error is to treat successful authentication as conclusive evidence that no scam occurred. APP fraud is defined by deception, manipulation or dishonest persuasion—not by the absence of customer participation. In many cases, the customer performs the payment personally and completes every security step requested by the bank.

The decisive questions are different: who did the customer believe they were paying, what purpose did they believe the payment served, and did a fraudulent course of conduct create those beliefs? The PSR directs firms to consider what the consumer understood or knew about the payment’s recipient and purpose at the time it was made.

This is particularly important in bank-impersonation scams. A victim transferring funds to a supposed “safe account” may know that the beneficiary is new and may consciously approve the transaction. However, they may believe they are following instructions from their bank to protect their savings. The authentication is genuine; the decision-making environment is fraudulent.

The same issue appears in investment and romance fraud. A customer may communicate with the recipient for months, make several payments, provide misleading explanations to bank staff or ignore repeated warnings. Those behaviours may appear suspicious, but they can also demonstrate the depth of the manipulation. The FCA has noted that romance-fraud victims may remain emotionally invested and reluctant to accept that they are being defrauded, making effective intervention unusually difficult.

Technical evidence nevertheless remains essential. Authentication logs, device intelligence, session telemetry, beneficiary history and transaction confirmations can show whether the customer controlled the journey, whether another party accessed the account and whether the reported narrative is consistent with the recorded sequence.

The correct conclusion is not that authentication proves informed consent. It is that authentication forms one component of a broader evidential picture.

When a disputed transfer may indicate first-party abuse

First-party fraud is a recognised exception to mandatory reimbursement. The PSR framework excludes cases in which the consumer acted fraudulently or was party to the fraud or dishonesty. Firms therefore have a legitimate basis for rejecting fabricated scam claims, but the decision must be supported by evidence. Suspicion, inconsistency or an unfavourable customer profile is not sufficient.

Indicators requiring closer investigation may include:

  • evidence of a pre-existing undisclosed relationship with the beneficiary;
  • repeated payments followed by selective disputes;
  • funds cycling back to the customer or connected parties;
  • fabricated documents or manipulated communications;
  • device or network links between the payer and receiving account;
  • material contradictions that remain unexplained after proportionate questioning;
  • evidence that the customer retained part of the financial benefit.

These indicators should not be treated as an automatic fraud score. Genuine victims frequently communicate extensively with offenders, move savings between their own accounts before paying and follow instructions designed to defeat bank controls. Fraudsters may tell victims to conceal the true payment purpose, ignore warnings or falsely claim that the transfer is for property, family support or legitimate investment activity.

Victims may also withhold information because the scam involves an intimate relationship, unregulated investment, embarrassment or fear of being blamed. An investigation that begins from an assumption of dishonesty may therefore misclassify genuine victimisation and create conduct, complaint and vulnerability risk.

Civil disputes require a separate assessment. The reimbursement requirement does not cover ordinary disagreements with legitimate suppliers where there was no intent to defraud. The PSR’s guidance recognises that scams and civil disputes can look similar and requires firms to consider each claim on its facts. Relevant factors include the relationship between the parties, the supplier’s trading status, pre-payment communications, representations made to the customer and evidence that the recipient intended to deceive. Non-delivery alone does not automatically establish an APP scam.

What an evidence-led investigation looks like

The first layer is transaction reconstruction. Investigators should build a precise timeline covering internal funding movements, beneficiary creation, payment attempts, interventions, transaction release, customer contact and subsequent movement of the funds. An outbound payment cannot be assessed properly without understanding the events that preceded and followed it.

The second layer is channel and device evidence. Relevant information may include device identifiers, IP addresses, geolocation, session age, authentication method, remote-access indicators, biometric or passcode events and recent changes to contact details. This helps distinguish an APP scam from unauthorised account takeover and may identify customer coaching or third-party control.

A familiar device should not be interpreted as evidence that the customer was acting freely. Many APP scams are executed by victims using their normal phones while speaking to the fraudster.

The third layer is customer interviewing. Questioning should be structured, neutral and sensitive to trauma. Investigators need to establish how contact began, how trust was created, what representations were made, what warnings appeared, why the customer continued and what happened after the payment.

Open questions should normally precede detailed challenge. Genuine victims can provide confused or inconsistent accounts when distressed, while fabricated claims can initially appear organised and persuasive. Credibility should therefore be assessed against independent evidence rather than communication style alone.

The fourth layer is receiving-side intelligence. The receiving PSP may hold information on account opening, device sharing, rapid pass-through transactions, previous scam reports, linked accounts and cash-out routes. Under the reimbursement rules, the sending PSP must notify relevant receiving PSPs and allow them to provide evidence material to the claim. Rapid contact also increases the possibility of freezing and recovering funds.

The fifth layer is vulnerability assessment. Vulnerability is not an administrative addition to the investigation; it may affect both causation and the reimbursement decision. The consumer-standard-of-caution exception and permitted excess cannot be applied where the customer was vulnerable to the specific scam.

Firms should consider how health conditions, bereavement, cognitive impairment, financial distress, limited digital capability, emotional dependence or other circumstances affected the customer’s ability to recognise and resist manipulation.

What a resilient adjudication framework looks like

A mature adjudication framework separates four questions.

First, was the payment technically authorised or unauthorised?

Second, does the reported event meet the definition of an APP scam, or is it a civil dispute or another out-of-scope event?

Third, is there evidence that the customer knowingly participated in fraud or dishonesty?

Fourth, where a genuine APP scam occurred, does any lawful reimbursement exception apply?

This sequence prevents teams from conflating authentication, deception, customer conduct and reimbursement eligibility.

For non-vulnerable consumers, the consumer standard of caution is not a broad customer-negligence test. A PSP must demonstrate gross negligence in relation to specified obligations, including having regard to an effective intervention, reporting the scam promptly, responding to reasonable information requests and, where requested, supporting police reporting. The burden of proof rests on the PSP, and the PSR describes gross negligence as a significant degree of carelessness above ordinary negligence.

A warning should not be treated as effective merely because it appeared on screen. Investigators should consider whether it was specific to the suspected scam, clearly explained the risk and was presented at a point where the customer could reasonably reconsider the payment. Generic warnings repeatedly displayed during legitimate transactions may offer limited evidential value.

Allegations of first-party fraud should require defined evidential thresholds and independent review. Case records should clearly distinguish established facts, customer assertions, reasonable inferences and unresolved gaps. Decisions should explain which evidence was relied upon and how it affected the outcome.

This discipline must extend to customer communications. The FCA has criticised firms for slow complaint handling, unclear final decisions, aggressive or accusatory language and insufficient evidence that customer vulnerability was properly considered.

Quality assurance should test consistency across investigators, typologies, customer groups and payment channels. Relevant management information includes reimbursement outcomes, first-party-fraud referrals, civil-dispute classifications, overturned decisions, recovery rates, processing times, vulnerability findings and Financial Ombudsman outcomes.

A low reimbursement rate is not evidence of strong fraud control, just as a high reimbursement rate does not necessarily indicate weak challenge. The relevant measure is whether decisions are accurate, fair, timely and defensible.

How institutions can use analytics defensively

Analytics can support both payment prevention and claim adjudication when transaction behaviour is connected with customer, device and network context.

Pre-payment models should analyse unusual beneficiaries, transaction value, internal liquidity movements, payment purpose, receiving-account risk, previous scam exposure and deviation from normal customer behaviour. Interventions should be dynamic and typology-specific rather than relying solely on generic warnings.

Post-claim analytics can identify repeated narratives, shared devices, linked beneficiaries, circular movement of funds and clusters of claims connected to common receiving infrastructure. Network analysis can also reveal relationships between disputed payments and known mule accounts that would not be visible through an individual case review.

Natural-language tools can help structure call notes, compare stated timelines with system events and identify inconsistencies for investigator review. They should not autonomously determine that a customer has acted dishonestly. First-party-fraud findings carry serious consequences and require explainable evidence, human judgement and safeguards against bias.

Confirmed claims should feed back into preventive controls. Scam scripts, mule accounts, communication channels, intervention failures and device indicators should be converted into typology updates and detection changes. The FCA has emphasised that fraud intelligence must be acted upon quickly and that receiving PSPs should respond promptly when notified of fraudulent funds.

Authorized Push Payment Fraud or Customer Abuse
Authorized Push Payment Fraud

What this means for financial crime leaders

Disputed authorised transfers are not simply reimbursement cases. They are cross-functional financial-crime events involving fraud prevention, payment operations, AML, complaints, customer vulnerability, legal interpretation, data science and interbank recovery.

The operational model should therefore be built around shared evidence and accountable decision-making rather than sequential hand-offs between isolated teams.

The first strategic mistake is to equate customer action with customer intent. Genuine APP victims often authenticate and execute every stage of the payment themselves. The second is to assume that every post-payment scam narrative is truthful. A resilient institution holds both possibilities open until the available evidence supports a conclusion.

The strongest programmes prevent suspicious payments where possible, investigate disputed transfers without prejudgment, protect vulnerable customers, challenge deliberate abuse and communicate decisions clearly.

In an environment where APP losses are rising and reimbursement has become a central consumer protection, the differentiator will not be how aggressively a firm approves or rejects claims. It will be how accurately the institution can reconstruct the customer’s decision, identify the underlying criminal operating model and reach a fair, timely and defensible outcome.

What Financial Institutions Should Consider

  • Reconstruct the Full Payment Journey
  • Separate Authentication, Authorisation and Customer Intent
  • Establish Clear Evidential Thresholds for First-Party Fraud
  • Use Structured and Neutral Customer Interviews
  • Integrate Device, Behavioural and Transaction Intelligence
  • Assess Customer Vulnerability Throughout the Investigation
  • Strengthen Receiving-Bank Intelligence Sharing
  • Apply Typology-Specific Payment Interventions
  • Use Network Analytics to Identify Mule Connections
  • Introduce Independent Review for High-Risk Decisions
  • Improve Fraud, AML, Complaints and Payments Collaboration
  • Feed Confirmed Scam Intelligence Back Into Preventive Controls
  • Measure Accuracy, Fairness, Timeliness and Defensibilit

Download the briefing

Managing Disputed Transfers: Authorized Push Payment Fraud vs. Customer Abuse

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

One Comment

  1. Authorised push payment fraud investigations sit at the intersection of customer protection, fraud prevention, regulatory compliance and evidential judgement. The central challenge is that a payment may be technically authorised while the customer’s decision has been shaped by deception, coercion or manipulation. At the same time, firms must remain alert to civil disputes, collusive behaviour and deliberate first-party abuse of reimbursement mechanisms.

    Effective adjudication therefore depends on more than authentication records or customer testimony alone. Institutions need to reconstruct the full payment journey, assess the customer’s understanding and vulnerability, analyse device and behavioural evidence, obtain receiving-side intelligence and distinguish clearly between established facts, reasonable inferences and unresolved uncertainty.

    The strongest operating models avoid both extremes: automatically blaming customers because they approved the payment, or reimbursing every disputed transfer without sufficient scrutiny. Instead, they apply consistent evidential standards, proportionate challenge and independent review.

    Ultimately, the quality of a disputed-payment framework should be measured not by how many claims are approved or rejected, but by whether decisions are accurate, fair, timely and defensible. Financial institutions that combine effective prevention, intelligence-led investigation and customer-sensitive adjudication will be better positioned to protect genuine victims, deter abuse and strengthen trust in real-time payment systems.

AI-Driven SAR Drafting in Financial Crime Compliance

AI-Driven SAR Drafting in Financial Crime Compliance: Real Cases, Real Possibilitie