Skip to content
Digital, Innovation, Payments

PSD3 and PSR: one European payments market needs one rulebook

Published on 30 September 2026

Europe’s new payments framework is about more than updating the rules. It reflects a broader shift towards a more integrated European financial market, but also a new understanding of how risks such as fraud need to be addressed. At a conference organised by the ABBL and A&O Shearman, policymakers, supervisors, legal experts and market participants discussed what has already been achieved and what still needs to be done to make the new framework work in practice.

Summary

    At a conference organised by the ABBL and A&O Shearman, policymakers, supervisors, legal experts and market participants came together to assess where PSD3 and the Payment Services Regulation now stand, what has already been achieved through the Level 1 negotiations, and what still needs to happen to make the framework work in practice.

    The discussion highlighted two priorities that will shape the next phase: turning greater legal harmonisation into genuinely consistent implementation across Europe, and treating fraud as an ecosystem challenge that requires cooperation beyond the financial sector alone.

    More than another payments reform

    PSD3 and the Payment Services Regulation (PSR) mark the next stage in the development of Europe’s payments framework.

    PSD1 established the foundations of a European payments market in 2007, combining greater competition with protection for payment service users. PSD2 subsequently adapted that framework to an increasingly digital economy and supported the development of open banking.

    PSD3 and the PSR now take this evolution further.

    The importance of the package goes beyond another regulatory update. Payments infrastructure is part of the backbone of modern economies, while the environment in which it operates is being transformed by technology, new market participants and increasingly sophisticated forms of fraud.

    The new framework also introduces an important architectural change. PSD3 will focus in particular on the authorisation and supervision of payment institutions, while the PSR will make a substantial part of the operational rulebook directly applicable across the European Union.

    With the Level 1 framework largely settled, attention is therefore already shifting towards implementation and the substantial body of Level 2 measures still to come.

    Advocacy has already moved the dial

    For the ABBL, this next phase builds on more than three years of advocacy.

    Since the European Commission presented its proposals in June 2023, the ABBL has brought together its members through a dedicated task force and represented their priorities towards the Luxembourg Ministry of Finance, through the European Banking Federation and directly at EU level.

    The final compromise reflects progress on several priorities raised by the industry.

    Liability for authorised fraud has become more targeted. The framework provides a clearer basis for payment service providers to exchange fraud-related information, places greater emphasis on prevention and increasingly recognises that responsibility for fraud cannot rest with payment service providers alone.

    This is particularly significant because fraud rarely happens within the boundaries of a single institution.

    A scam may begin with an advertisement on social media, continue through a message or a spoofed telephone call, and only end with a payment. The payment service provider controls only one part of that chain.

    Extending responsibilities to telecommunications providers and online platforms therefore brings the regulatory framework closer to the reality of how fraud occurs.

    The objective should be to prevent fraud, rather than merely determine who pays once fraud has occurred.

    Ananda Kautz

    Member of the Management Board of the ABBL

    One market, fewer regulatory borders

    Another fundamental shift concerns harmonisation.

    Speaking at the conference, Ward Möhlmann, Head of Unit for Retail Financial Services and Payments at the European Commission, explained that moving towards directly applicable regulations forms part of a broader European policy orientation.

    Different national transpositions and interpretations can ultimately become barriers within the Single Market. If financial services providers are to scale across borders, they need to be able to rely increasingly on the same rules and concepts across Member States.

    This direction was also welcomed from the supervisory side.

    Suzanne Weber, Deputy Head of Department Innovation, Payments, Market Infrastructures and Governance at the CSSF, stressed that a harmonised framework should foster greater convergence and help address the fragmentation that successive European payments frameworks have sought to overcome.

    The ABBL shares this objective.

    Moving operational rules into a regulation is a genuine step towards harmonisation. But Level 1 is only part of the story. Level 2 standards and, ultimately, supervisory practices will determine whether a single European rulebook also becomes a single rulebook in practice.

    Fighting fraud also means breaking down institutional silos

    Extending responsibility across the fraud chain creates another challenge: regulation itself has to cross traditional institutional boundaries.

    As Ward Möhlmann pointed out, the different actors involved fall within the remit of different parts of the European Commission. DG FISMA approaches the issue from the financial-services and payments perspective, DG CONNECT from the perspective of platforms and digital services, and DG HOME from that of fraud and crime.

    If the regulatory framework asks the private sector to approach fraud as an ecosystem, policymakers need to do the same.

    This means bringing these different perspectives together and avoiding policy silos. Market participants also have an important role to play by highlighting situations where different regulatory channels result in inconsistent approaches.

    The same logic applies at national level.

    The ABBL is advocating for stronger cooperation between payment providers, telecommunications operators, online platforms and public authorities. Regulation can distribute responsibilities across the chain, but effective fraud prevention requires the actors along that chain to cooperate.

    From Level 1 to Level 2: the market reality check

    If policymakers and supervisors set out the direction of travel, the second panel brought the discussion down to operational reality.

    Representatives from PayPal, Convera and BGL BNP Paribas brought three different perspectives to the table: a global payments platform operating across multiple regulatory jurisdictions, a B2B cross-border payments provider, and a universal bank translating the new requirements into processes, systems and customer interactions.

    Their assessment of the direction of travel was broadly positive.

    Greater harmonisation can reduce the complexity of operating across European markets, improve transparency and create a more level playing field. But the benefits will depend heavily on how the Level 1 principles are translated into technical standards and supervisory practice.

    Several priorities emerged.

    Harmonisation must survive implementation.

    A directly applicable European regulation will only deliver its full value if common rules are accompanied by sufficiently consistent interpretation and supervision. Otherwise, fragmentation risks reappearing through national requirements and supervisory practices, precisely what the move towards a regulation is intended to reduce.

    Information sharing must work across the entire fraud chain.

    Allowing payment service providers to exchange fraud data is an important step, but effective prevention increasingly requires information to move across the wider ecosystem. PayPal notably highlighted the need to involve data-protection authorities too, so that firms have sufficient legal certainty to share the information needed to prevent fraud.

    Proportionality will matter.

    Convera highlighted the particular reality of corporate payments. Requirements primarily designed around retail fraud do not necessarily translate seamlessly into high-value or automated B2B transactions. Real-time transaction monitoring can generate false positives for businesses making large or less predictable payments, with potentially significant consequences if a time-sensitive payment misses its value date.

    Greater security must not unnecessarily undermine the fluidity of payments.

    BGL BNP Paribas illustrated the practical dilemma: more sophisticated fraud detection may require institutions to stop transactions, contact customers and perform additional checks. Particularly during the initial implementation phase, stronger protection could therefore create additional friction.

    The market’s message was therefore not to reopen the Level 1 compromise, but to make the next phase work: clear standards, proportionality, legal certainty and genuinely harmonised implementation.

    The next advocacy chapter starts now

    That is also where the ABBL’s work moves next.

    As the regulatory debate shifts from Level 1 to Level 2, the association will continue to bring together banks, payment institutions and other market participants to identify practical implementation issues and feed them into the dialogue with Luxembourg authorities and European institutions.

    The timing matters.

    As Suzanne Weber stressed, institutions should not wait for the application date. Gap analyses, governance involvement and the allocation of adequate human and technical resources need to start well before the rules become applicable.

    For the ABBL, the collective work that helped shape the Level 1 compromise now needs to continue into implementation.

    As Ananda Kautz told participants, member input has allowed the association to speak with one voice throughout the negotiations. The same collective intelligence will be needed when the Level 2 measures are developed.

    The stakes go beyond compliance.

    PSD3 and the PSR are ultimately a test of two broader European ambitions: whether one market can operate with one genuinely consistent rulebook, and whether an increasingly interconnected fraud ecosystem can be addressed through equally interconnected regulation and cooperation.

    By the time the new framework applies, institutions should no longer be debating what the rules mean. They should be competing on how well they implement them: securely, efficiently and with the level of trust their clients expect.

    Arnaud Clément

    Arnaud Clément

    Head of Payments and Innovation, ABBL

    Published on 30 September 2026