{"id":5119,"date":"2026-04-08T11:52:04","date_gmt":"2026-04-08T09:52:04","guid":{"rendered":"https:\/\/relycomply.com\/?p=5119"},"modified":"2026-04-08T11:56:14","modified_gmt":"2026-04-08T09:56:14","slug":"authorised-push-payments-app-fraud","status":"publish","type":"post","link":"https:\/\/relycomply.com\/en-gb\/authorised-push-payments-app-fraud\/","title":{"rendered":"Assessing the pressing risk of authorised push payments (APP) fraud for UK firms"},"content":{"rendered":"\n<p id=\"block-86de6002-97e1-456f-a27c-3841802f55d9\">There\u2019s no dismissing the fact that all UK payments will soon need to be instant. This is not a rising need limited to the British Isles either, considering the EU\u2019s Instant Payment scheme and the fact that <a href=\"https:\/\/www.bis.org\/publ\/qtrpdf\/r_qt2403c.htm\" target=\"_blank\" rel=\"noreferrer noopener\">more than 100 jurisdictions<\/a> have access to fast payments systems. The low costs, speed, and safety of account-to-account (A2A) transfers are already proclaimed (and <a href=\"https:\/\/www.swift.com\/payments\/instant-payments\" target=\"_blank\" rel=\"noreferrer noopener\">used in over 80 economies<\/a>), with open banking fund flows also on the rise. But it\u2019s not all happy news; fraudsters will always find a way to bend digitalised financial methods to their whims. In particular, the rise of instant payments has increased the risk of authorised push payments (APP) fraud, making vigilance essential for UK firms.<\/p>\n\n\n\n<p id=\"block-314057b9-855a-47ca-b5a1-35bfd6f5781c\">Authorised push payments help businesses and their consumers transact easily in legitimate circumstances, but APP-based criminals have created a wealth of hazards &#8211; utilising multiple accounts and cross-border tactics to tempt money mules through romance and investment scams, and even <a href=\"https:\/\/www.bbc.co.uk\/news\/uk-england-manchester-67933333\" target=\"_blank\" rel=\"noreferrer noopener\">lost pet ransom schemes<\/a>. They\u2019re so successful that authorised push payments (APP) fraud is now the <a href=\"https:\/\/www.forbes.com\/advisor\/uk\/personal-finance\/what-is-app-fraud\/\" target=\"_blank\" rel=\"noreferrer noopener\">UK\u2019s most common financial scam<\/a>.<\/p>\n\n\n\n<p id=\"block-782917a7-a79e-4b9e-b448-4a97cf56cd4a\">What does it mean for banks, fintechs, and payment providers? A lot of the buck for identifying scams (and recuperating funds lost to it) lies with them. And with authorised push payments (APP) fraud fuelling laundering and other heinous organised crime activity, its actors must be found and prosecuted using a steadfast AML strategy &#8211; with the same breakneck speed expected to keep international money movements flowing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-c00b9698-b7bd-4295-86ea-d9fb408328d0\">Exposing the hidden criminality in instant payments<\/h2>\n\n\n\n<p id=\"block-47df82b0-3205-4d4f-976a-1f05d1cb79e0\">Payment infrastructures have evolved plenty in recent decades to accommodate new payment rails, digital assets, online banking, and APIs: all hallmarks of A2A transactions that save processing fees, and connect financial institutions for real-time payments to reach their destinations. In the dark reaches of the web however, scammers target vulnerable people and SMEs with lax data security or platforms that fail to meet the sophistication of the modern payments world.<\/p>\n\n\n\n<p id=\"block-980e9b39-8548-4237-a6d5-ad01f50dbf1c\">A common trope of authorised push payments (APP) fraud involves criminals posing as a bank or legitimate organisation to demand sensitive information, often very quickly, luring the victim to transfer money to different accounts. In romance or investment scams, repeated exploitation is a growing concern, with victims groomed as mules to transfer funds on criminals\u2019 behalf. This activity is extremely tough to spot, even in advanced AML systems.<\/p>\n\n\n\n<p id=\"block-c91fdb6d-17cb-4c3b-a40d-c293031cbf33\">Given that fraudsters and financial institutions represent two warring factions trying to exploit the others vulnerabilities\u2019, those acting on the consumers\u2019 side now have to be aware of their shortcomings to bolster themselves against real-time payment risk:<\/p>\n\n\n\n<ul id=\"block-5eaa88a7-ea31-4385-8b21-f4e01d725f92\" class=\"wp-block-list\">\n<li>Instant payments grant less time for detection and response, which is near impossible for traditional rules-based interventions. This delays transactions and allows launderers to proliferate,&nbsp;with layering often taking place in minutes.<\/li>\n\n\n\n<li>When the proceeds of fraud can be smurfed and processed through multiple accounts and regions at once, the fraud chain becomes more opaque, lowering the launderers\u2019 detection rate profusely.&nbsp;<\/li>\n\n\n\n<li>Open banking and ultra-fast payments rely on cross-platform AML to be up to scratch; if one institutions\u2019 verification and review protocols are insubstantial, the end-to-end visibility of the A2A payment is lessened.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/Placement-8-1024x536.png\" alt=\"Authorised push payments (APP) fraud in the UK\" class=\"wp-image-5126\" style=\"aspect-ratio:1.9105722852300873;width:719px;height:auto\" srcset=\"https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/Placement-8-1024x536.png 1024w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/Placement-8-300x157.png 300w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/Placement-8-768x402.png 768w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/Placement-8-1536x804.png 1536w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/Placement-8-2048x1072.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-cc09d9ad-1b6a-446e-9de2-9e47b3e41d27\">The pressure of industry-wide compliance<\/h2>\n\n\n\n<p id=\"block-4e4b9c70-a23b-4b04-8118-58b4bbed42fd\">Clearly, today\u2019s payment services providers (PSPs), banks, and fintechs must be able to verify and authenticate their users\u2019 transfers, made more voluminous due to the nature of the interconnected world. What\u2019s also troubling is the scrutiny of UK regulations. Firms are mandated to protect victims of the fraud typologies that they try to mitigate, and expectations from savvy digital users and regulatory bodies are getting ever stricter.<\/p>\n\n\n\n<p id=\"block-2651192b-7db8-4cd7-b0ba-57e6f40bee8c\">Already many institutions are regulated by the Payment Systems Regulator (PSR) to increase interbank activity, and must facilitate e-payment transfers via Pay.UK\u2019s Faster Payment System (FPS) rail. In 2024, the PSR also introduced a rule requiring PSPs to refund victims of authorised push payments (APP) fraud \u2013&nbsp;where the levels of transparency surrounding reimbursements from the largest banking groups can be identified <a href=\"https:\/\/www.psr.org.uk\/information-for-consumers\/app-fraud-performance-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">on their website<\/a> \u2013&nbsp;which is, evidently, a wide spectrum.<\/p>\n\n\n\n<p id=\"block-168f03aa-303a-4532-ad42-35f31ff5e761\">The PSR will soon be consolidated by the UK\u2019s leading regulator the FCA. The watchdogs\u2019 expectations to adapt payment infrastructure are seemingly exacerbating the current compliance culture that deems AML too costly, complex, and shifting too quickly. Fraudsters know this, however, <a href=\"https:\/\/www.ukfinance.org.uk\/news-and-insight\/blog\/open-banking-navigating-new-fraud-risks\" target=\"_blank\" rel=\"noreferrer noopener\">exploiting lax fraud awareness<\/a> and defenses (particularly at third-party providers) to compromise the sensitive data of UK customers. This highlights a severe roadblock for plans to roll out open banking risk-free.<\/p>\n\n\n\n<p id=\"block-0cba28e3-506d-403c-adae-c3db7550670a\">If authorised push payments (APP) fraud is still treated as an inconvenient customer service issue and not a high-risk typology, that\u2019s an open door to other implications \u2013 further manipulation, coercion and organised crime \u2013&nbsp;integrity across the financial world will be lost and hard to recover. This ultimately lets the scammers and their international overlords win, when legitimate customers should be able to conduct swift cross-border payments without delay.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-eaf03ba5-c94d-4c4a-82e2-2287b70d8010\">Quick paths to instant payment AML<\/h2>\n\n\n\n<p id=\"block-4d8c85c0-be98-4739-b7ea-0d23642ed808\">It\u2019s not all doom and gloom. Payment digitalisation is fast, but so too is the rate with which regulatory technology can enhance existing AML workflows. Real-time biometric verification and advanced fincrime detection methods can achieve the inter-institution collaboration encouraged by the PSR and the instant payment scheme.<\/p>\n\n\n\n<p id=\"block-968e406e-b777-46ed-a06c-b2caa0929523\">Such processes have traditionally been siloed, wherein lies the difficulty for institutions to audit transactions according to entities\u2019 specific risk profiles. Instead, a single source of truth draws together fraud and AML teams to detect any high risk activity (including small, repeated transactions, and muling activity such as KYC evasion), as well as build accurately tracked reports for actionable financial crime investigations by the National Crime Agency (NCA).<\/p>\n\n\n\n<p id=\"block-3e45ece3-c99d-459a-8447-495eb9cd8a51\"><a href=\"https:\/\/relycomply.com\/en-gb\/aml-transaction-monitoring\/\">AI-driven transaction monitoring<\/a> does not rely on fixed risk thresholds, but identifies and raises any anomalies in customers\u2019 normal payment behaviours for enhanced due diligence. Elsewhere, risk scoring can adjust in line with any new fraud patterns that emerge in a business\u2019 data &#8211; something that teams under cost and time pressures cannot account for manually, resulting in fewer false positives and raised efficiency.&nbsp;<\/p>\n\n\n\n<p id=\"block-0907ce6a-9f4c-482d-9422-5a521e334afd\">While there may be greater transactional data available, the goal of a strategic RegTech partnership is to bolster AML systems that produce meaningful alerts now, and for the future. AML and fraud teams can be better aligned to intervene in authorised push payments (APP) fraud signals earlier and focus on only the riskiest payments, allowing genuine customer payments to be processed swiftly and safely.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/RelyComply_APP_Fraud_Blog_article_image2-1024x536.jpg\" alt=\"The four pillars of RegTech defence that help prevent authorised push payments (APP) fraud\" class=\"wp-image-5123\" style=\"width:719px;height:auto\" srcset=\"https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/RelyComply_APP_Fraud_Blog_article_image2-1024x536.jpg 1024w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/RelyComply_APP_Fraud_Blog_article_image2-300x157.jpg 300w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/RelyComply_APP_Fraud_Blog_article_image2-768x402.jpg 768w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/RelyComply_APP_Fraud_Blog_article_image2-1536x804.jpg 1536w, https:\/\/relycomply.com\/wp-content\/uploads\/2026\/04\/RelyComply_APP_Fraud_Blog_article_image2-2048x1072.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-25c01eaf-e29d-4d03-ace6-2c99b70aa211\">The time to evolve AML frameworks is now<\/h2>\n\n\n\n<p id=\"block-cfd77c76-a355-4426-9d47-9b6c7bc45dc8\">Authorised push payments (APP) fraud has already had such a damaging effect on UK financial crime that it cannot be avoided. Its coupling with instant payment regulation may feel like a cruel double-header, but with AML systems and workflows attuned to the verifiable risk of real-time payments, PSPs, banks and fintechs can operate with real-time monitoring in an environment that demands it.<\/p>\n\n\n\n<p id=\"block-995c850c-5aa9-4b12-ac57-1d14acc21ac0\">Investing in adaptive compliance technology is a strategy that\u2019s fit for the future. With greater uptake, it can enable the entire UK market of innovative financial companies to appeal to new customers as trusted, secure institutions that facilitate A2A across borders, quickly, and without the hassle. Authorised push payments (APP) fraud is no mere side issue, but a key evolution within digital finance that, when detected in line with other serious crime, can limit criminal opportunity and provide a bright outlook for firms on the right side of UK regulation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There\u2019s no dismissing the fact that all UK payments will soon need to be instant. This is not a rising need limited to the British Isles either, considering the EU\u2019s Instant Payment scheme and the fact that more than 100 jurisdictions have access to fast payments systems. The low costs, speed, and safety of account-to-account &hellip; <a href=\"https:\/\/relycomply.com\/en-gb\/authorised-push-payments-app-fraud\/\">Continued<\/a><\/p>\n","protected":false},"author":13,"featured_media":5120,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[53],"tags":[],"class_list":["post-5119","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized-en-gb"],"acf":[],"_links":{"self":[{"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/posts\/5119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/comments?post=5119"}],"version-history":[{"count":7,"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/posts\/5119\/revisions"}],"predecessor-version":[{"id":5136,"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/posts\/5119\/revisions\/5136"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/media\/5120"}],"wp:attachment":[{"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/media?parent=5119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/categories?post=5119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/relycomply.com\/en-gb\/wp-json\/wp\/v2\/tags?post=5119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}