October 2026 will mark two years since the mandatory Authorised Push Payment (APP) reimbursement requirements came into effect. In that time, the industry has had to adapt not only to the financial consequences of fraud, but also to a fundamental shift in how firms think about customer harm, accountability and fraud risk.
Two years on, Boards and C-Suites should be reflecting on whether they have built a genuinely preventative fraud capability, rather than simply an efficient reimbursement operation. Firms will need to demonstrate that the organisation is actually reducing the underlying risk of APP fraud, and evidence that to customers and regulators.
The latest Payment Systems Regulator (PSR) data illustrates the scale of the challenge. In Q1 2026, around 301,500 claims were in scope for reimbursement, with 88% reimbursed to victims and 82% closed within five business days. Firms have built significant capability around the consequences of APP fraud, but operational performance does not necessarily tell the Board whether fraud prevention is becoming more effective.
And for fintechs in particular, the issue is amplified. The same characteristics that create customer value, such as rapid payments, digital onboarding, instant account opening and highly automated journeys, can also create opportunities for fraudsters to exploit speed and scale.
The next stage of maturity therefore needs to be about understanding and reducing the underlying fraud risk, rather than becoming increasingly efficient at managing its consequences.
5 REASONS WHY APP FRAUD BELONGS ON THE BOARD AGENDA.
There are five reasons APP fraud should be treated as a strategic risk, rather than a siloed fraud risk.
- It has a direct financial impact: APP fraud has a direct financial consequence through reimbursement. Where customers become victims of APP fraud, firms may face a direct financial cost through reimbursement (where eligible), alongside investigation, recovery and customer-support costs. For scaling firms, relatively small changes in fraud rates can translate into significant financial exposure.
- It’s a customer trust risk: APP fraud causes significant financial and emotional harm, even when authorised by the customer. Designing customer journeys to detect risk early, simplify reporting, and provide support protects trust. For firms aspiring for growth, effective fraud prevention protects the brand and drives customer retention.
- Growth strategies can also create fraud exposure: Fintech business models are often built around reducing friction: fast payments, digital onboarding, automated account opening and decision-making can make products easier and faster to use. Those characteristics can be fundamental to customer acquisition and growth, but they can also increase the speed at which fraud can occur. Boards need evidence that controls are targeted at meaningful risk, that interventions are proportionate and that the firm understands where additional friction creates value.
- Firms can be exposed on both sides of the transaction: A payment firm can have customers who become victims of APP fraud while simultaneously receiving fraudulent funds into its own accounts. Boards should understand its exposure: how its customers are being targeted, where fraudulent funds are being sent from and to, how quickly those funds move, and how effectively the organisation can identify and disrupt fraudulent activity.
- Regulatory scrutiny is increasingly focused on effectiveness: The FCA has been clear that firms should regularly evaluate the fraud risks to which they and their customers are exposed and ensure that their control frameworks remain fit for purpose; the FCA has also emphasised participation in data sharing networks to help disrupt fraud. More broadly, the PSR is also consulting on Specific Direction 17 with regard to Confirmation of Payee, including proposals to remove the fixed expiry date and expand the scope of firms required to participate. These developments point towards a broader expectation that firms should be able to demonstrate that they are contributing to better outcomes.
THE REAL QUESTION: ARE WE MANAGING FRAUD OR ACTUALLY REDUCING IT?
There’s a natural temptation after two years of the reimbursement regime to measure maturity through operational metrics, such as, claims processed, reimbursement rates, complaints resolved and payments declined. However, these metrics don’t provide the Board with assurance that anti-fraud controls are reducing the underlying incident and impact of APP fraud.
The FCA’s review into anti-fraud controls and complaint handling in firms showed that Management Information (MI) focused primarily on commercial risk appetite and financials, whilst stronger examples included customer-centric measures and demonstrated how those measured informed action to strengthen controls and improve outcomes.
5 EXAMPLE QUESTIONS THE BOARD SHOULD BE ABLE TO ANSWER:
- What has happened to our APP fraud loss rate since October 2024?
- Where in the customer journey are losses occurring?
- How much fraud are we stopping before the payment is authorised?
- Which customer segments are disproportionately exposed?
- What evidence do we have that our interventions actually work?
MEASURING WHAT MATTERS.
MI should show the relationship between fraud exposure, prevention, customer outcomes and commercial impact. Boards should understand:
| Fraud exposure. | This tells the Board the scale and direction of the risk |
|
|---|---|---|
| Prevention effectiveness. | This tells the Board whether controls are changing that fraud exposure |
|
| Customer outcomes. | This informs the Board about customer experience |
|
Customer outcomes are particularly important under the Consumer Duty. The FCA’s APP fraud review emphasises that firms need to put customers first, make it easy for customers to report fraud and provide appropriate support to victims, including customers who may be vulnerable.
WHAT SHOULD THE BOARD DO IN THE NEXT 90-DAYS?
For many firms, the final quarter of 2026 will also be a period of setting priorities and investment for 2027.
This creates a useful opportunity to step back from individual fraud processes and assess whether the overall strategy is delivering the intended reduction in risk.
- Review the Board’s fraud MI – Review whether the current reporting gives the Board a thorough end-to-end view of fraud risk exposure, customer outcomes and effectiveness. Does the data inform the Board of where the risk is changing?
- Conduct an end-to-end APP fraud review – Map the customer’s journey from onboarding through to payment. The review should consider both sides of the payment: customers sending fraudulent payments, and fraudulent funds being received into the organisation. The output should be a clear view of where the material gaps are and where investment could have the greatest impact.
- Stress test the effectiveness of controls – Targeted testing should be used to challenge whether key controls work in practice, and qualify their effectiveness.
- Test the customer experience – The customer journey should be tested just as rigorously as the fraud controls. Measure how quickly a customer can report fraud, how they are treated, how decisions are made, how vulnerable customers are supported, and whether communication is clear throughout.
Two years after the introduction of mandatory APP reimbursement, the true test of organisational maturity is whether the Board and C-Suite can demonstrate a real reduction in underlying risk. Boards must clearly connect the firm’s overarching fraud strategy and investment decisions directly to measurable improvements in fraud exposure, customer outcomes, and commercial risk mitigation.
IS YOUR FRAUD STRATEGY REDUCING RISK, OR JUST MANAGING ITS CONSEQUENCES?
Cosegic and FINTRAIL help fintechs, payment firms and banks move beyond reimbursement to a genuinely preventative approach to APP fraud. From reviewing your Board MI to running an end-to-end APP fraud review and stress testing your controls, our specialists can help you evidence real reductions in fraud risk to your customers and regulators.