
The PSRs 2017 Explained: Payment Authorisation, Liability and Execution Times
One payment traced in six figures: who authorises, who executes by when, and who bears the loss
The Payment Services Regulations 2017 (SI 2017/752) govern who may provide payment services in the UK and what obligations each party to a payment owes the others. Part 7, the conduct-of-business core, decides three questions: whether a payment was authorised, how fast it must be executed, and who bears the loss when it fails. The six figures below explain the PSRs 2017 visually, tracing one payment from consent to credit, first working, then failing, with every duty set out against the party that bears it. An unauthorised payment must be refunded by the end of the next business day; regulation 77 decides what reaches the payer; and a corporate customer can agree to vary much of what surrounds the refund duty, but not the refund itself.
Who is involved in a payment?
Every UK payment involves the same cast, and the PSRs 2017 attach different duties to each role. The payer is the customer whose account is debited. The payee is the merchant or biller being paid. The payer and the payee each have an account provider: the payer’s account servicing payment service provider (ASPSP) holds the account, executes the order and makes any refund, and the payee’s provider receives the funds and credits them. A fifth party, the payment initiation service provider (PISP), can be layered on top: it initiates the payment without holding any account. Each provision that follows either imposes an obligation on one of these parties or sets the conditions on which that obligation applies.
What does a successful payment look like?
The base case has no PISP: the payer instructs its own ASPSP directly. The payer consents to the transaction in the form agreed under regulation 67, with strong customer authentication applied where regulation 100 requires it. The payer’s ASPSP executes: for a sterling payment executed wholly within the United Kingdom, it must ensure the amount is credited to the payee’s payment service provider’s account by the end of the business day following the time of receipt of the payment order, under regulation 86(1). The payee’s provider must then value date and credit the amount to the payee’s account following receipt of the funds under regulation 86(4).
Two standing conditions apply alongside the consent stage. The payer must use the payment instrument in accordance with its terms and notify the provider without undue delay on learning of loss, theft, misappropriation or unauthorised use, and must take all reasonable steps to keep personalised security credentials safe, under regulation 72. The provider, for its part, must make sure appropriate means of notification are available at all times, under regulation 73(1)(c). Both matter only when something goes wrong.
What changes when a PISP initiates the payment?
Open banking adds a fifth party without changing the accounts. A payment initiation service provider initiates the payment at the payer’s request but holds no account; consent to execution may be given via the PISP under regulation 67(2)(c). Three duties change, and each falls on a named party. The PISP carries its own evidential burden: where a transaction initiated through it is disputed, regulation 75(2) requires the PISP to prove that, within its sphere of competence, the transaction was authenticated, accurately recorded and not affected by a technical breakdown or other deficiency linked to its service. The refund route stays with the account: on an unauthorised transaction, regulation 76(5)(a) requires the ASPSP to refund the payer, and regulation 76(5)(b) requires the PISP, where it is liable, to compensate the ASPSP immediately on request. And for non-executed or defective transactions initiated through a PISP, regulation 93 applies the same pattern: the ASPSP refunds the payer, and the PISP compensates the ASPSP where it cannot prove its own leg was sound.
One point matters for business terms: regulation 93 is not in the regulation 63(5) list, so the PISP refund route survives even where a corporate customer has agreed to disapply other provisions.
Where can a payment go wrong?
The PSRs 2017 deal with failure in two families. Either the payer never consented, in which case the transaction is unauthorised and regulations 74 to 77 govern who refunds and who bears the loss; or the payment was authorised but was not executed properly, late, wrong, missing or lawfully held, in which case regulations 86, 91 to 94 and 94A govern. Regulation 74 applies to both families: redress under regulations 76 and 91 to 94 depends on the payer notifying without undue delay and within 13 months of the debit date.
What must be proved when a payment was not authorised?
Regulation 75 places specified evidential obligations on the provider; evidence of authentication or recorded use of a payment instrument does not, without more, establish that the payer authorised the transaction. Where a payment service user denies authorising an executed transaction, or says a transaction was not correctly executed, regulation 75(1) requires the payment service provider to prove that the transaction was authenticated, accurately recorded, entered in its accounts, and not affected by a technical breakdown or other deficiency in its service.
Authentication is not authorisation, and proving the first does not establish the second. Regulation 75(3) makes the point expressly: the recorded use of a payment instrument is not in itself necessarily sufficient to prove either that the payer authorised the transaction or that the payer acted fraudulently or failed with intent or gross negligence to comply with regulation 72. The payment service provider must prove each of the matters in regulation 75(1). A firm that wants to allege fraud or gross negligence must go further still: regulation 75(4) requires it to provide supporting evidence to the payer.
What must be refunded, by whom, and by when?
The payer’s payment service provider must refund by the end of the next business day after it learns of the problem. Where an executed transaction was not authorised in accordance with regulation 67, regulation 76(1) requires the payment service provider to refund the amount to the payer and, where applicable, restore the debited account to the position it would have been in. Regulation 76(4) requires the credit value date to be no later than the date the unauthorised amount was debited, so interest is calculated from that date rather than from the refund.
Regulation 76(2) sets the deadline: as soon as practicable, and in any event no later than the end of the business day following the day on which the firm becomes aware of the unauthorised transaction. The deadline runs from awareness of the unauthorised transaction, not from the conclusion of an investigation. The FCA’s Approach Document (version 8, May 2026) accepts at 8.212 that an investigation may be justified, but requires it to be carried out as quickly as the circumstances allow, forbids its use to discourage a claim, and expects an immediate back-valued refund where the customer is not at fault. It also accepts at 8.210 that a firm which later establishes the customer did authorise the transaction may reverse the refund, on reasonable notice.
There is one statutory carve-out from the deadline. Regulation 76(3) disapplies it where the firm has reasonable grounds to suspect fraudulent behaviour by the payment service user and notifies a person mentioned in section 333A(2) of the Proceeds of Crime Act 2002 in writing. The carve-out depends on the written notification actually being made, not on the suspicion alone.
An amount deducted from a customer’s account by the firm in error is an unauthorised transaction for these purposes, because the customer did not consent to it (Approach Document 8.204). For low value payment instruments used anonymously, where the firm cannot in the nature of the instrument prove authorisation, the FCA’s view at 8.213 is that the provision does not apply.
How is the loss allocated?
Regulation 77 allocates the loss between payer and firm, and the order of its tests matters. Fraud comes first and is the only conduct that survives every protection: under regulation 77(4), except where the payer has acted fraudulently, the payer is not liable at all for losses arising after notification under regulation 72(1)(b), where the firm failed to provide means of notification under regulation 73(1)(c), where regulation 100 required strong customer authentication but the payer’s provider did not require it, or where the instrument was used in connection with a distance contract other than an excepted contract as defined by regulation 77(5). Only where none of those gateways is open does regulation 77(3) put the whole loss on a payer who acted fraudulently or failed with intent or gross negligence to comply with regulation 72. And only then does the cap arise: regulation 77(1) permits, but does not require, the firm to make the payer bear up to £35 where the transaction arose from a lost, stolen or misappropriated instrument, and regulation 77(2) removes even that where the loss was not detectable by the payer before the payment or was caused by the firm’s own employee, agent or branch.
The authentication compensation runs the other way too. Under regulation 77(6), where regulation 100 requires strong customer authentication but the payee or the payee’s payment service provider does not accept it, the payee or the payee’s provider, or both as the case may be, must compensate the payer’s payment service provider for the losses incurred or sums paid in complying with regulation 76(1).
How long does a customer have to notify?
Thirteen months, subject to two qualifications. Regulation 74(1) entitles a payment service user to redress under regulation 76, 91, 92, 93 or 94 only where it notifies the firm without undue delay on becoming aware of the unauthorised or incorrectly executed transaction, and in any event no later than 13 months after the debit date.
The first qualification depends on the firm’s own compliance with Part 6. Under regulation 74(2), where the firm has failed to provide or make available information about the transaction in accordance with Part 6 of the PSRs 2017, the user keeps its right to redress even though it did not notify in time. A firm that does not meet the Part 6 information requirements loses the 13-month limit. The second qualification is contractual: where the customer is not a consumer, a micro-enterprise or a charity, regulation 63(5)(b) permits the parties to agree a different period. A firm may also simply offer better terms than the statute requires: the FCA notes at 8.186 that the Direct Debit Guarantee is not cut down by this provision.
How fast must the money move, and can it be held?
The base-case deadline is regulation 86(1): the payer’s payment service provider must ensure the amount is credited to the payee’s provider’s account by the end of the business day following the time of receipt of the payment order. That deadline is expressly subject to three extensions. A paper-initiated order has until the end of the second business day under regulation 86(2). A transaction falling outside the regulation 85(1) categories and regulation 85(1A) but still executed wholly within the United Kingdom has until the end of the fourth business day under regulation 86(3). And a suspected-fraud hold under regulations 86(2A) to (2D) lawfully extends the deadline: it is a modification of the execution obligation, not a breach of it.
The hold power arises on two conditions in regulation 86(2A): the payer’s provider has established reasonable grounds to suspect the order was placed subsequent to fraud or dishonesty by someone other than the payer, and has established those grounds by the end of the business day following the time of receipt. Regulation 86(2C) bounds the delay twice: no longer than necessary, and in any event no later than the end of the fourth business day following receipt. Regulation 86(2D) requires the payer to be told of the delay, the reasons for it, and anything needed from the payer, as soon as possible and in any event by the end of the business day following receipt, except so far as compliance would be unlawful. Regulation 85(1A) confines the power to transactions authorised in accordance with regulation 67, executed wholly within the United Kingdom in sterling, and not initiated by or through a payee, so direct debits fall outside it.
The hold has a price. Regulation 94A, inserted by the Payment Services (Amendment) Regulations 2024 with effect from 30 October 2024, makes the payment service provider liable to its payment service user for any charges for which the payment service user is responsible, and any interest which the payment service user must pay, as a consequence of a delay to the execution of a payment order in reliance on regulation 86(2B), irrespective of whether the payment order is ultimately executed. The FCA reads this at 8.361 as covering charges levied by a third party for late payment, but as narrowly constructed: it covers interest and charges directly incurred, and not wider losses such as an investment opportunity missed because of the delay. The FCA also expects the Consumer Duty to bear on the decision to delay, noting at 8.300 that a firm will likely need a real-time human interface to support the customer during a hold.
Where an authorised payment is not executed properly outside any lawful hold, regulations 91 to 94 govern: regulation 91 for payer-initiated transactions, regulation 92 for payee-initiated transactions, regulation 93 for transactions initiated through a PISP, and regulation 94 for the consequential charges and interest. Three scope limits apply alongside them: regulation 63(2)(b) disapplies regulations 84 to 88 where both providers are in the United Kingdom but the transaction is in a currency other than sterling or euro; regulation 63(3)(b) disapplies not only regulation 86(1) to (3) but also regulations 91, 92, 94 and 95 on a one-leg transaction, so much of the second family falls away where only one of the two providers is in the United Kingdom; and regulation 85(2) allows the user and the firm to agree that regulations 86 to 88, except regulation 86(3), do not apply to any other payment transaction.
Which of these rules can a corporate customer disapply?
Many of them, where the customer is not a consumer, a micro-enterprise or a charity. Under regulation 63(5), the payment service user and the payment service provider may agree that any or all of a listed set of provisions do not apply, and may agree a different time period for regulation 74(1). The liability provisions in that list are regulation 75, regulation 77, regulation 86(2A) to (2D), regulations 91, 92 and 94, and regulation 94A. The full list is wider, also covering regulations 66(1), 67(3) and (4), 79, 80 and 83 on charges, consent withdrawal, direct debit refunds and revocation; the columns below show the liability subset only. Regulation 76 is not on the list, so the refund duty survives whatever the terms say, and nor is regulation 93, so the PISP refund route survives too.
Always applies
The refund duty itself (reg 76). The next business day refund deadline (reg 76(2)). Credit value dating (reg 76(4)). The ASPSP refunds first and recovers from the PISP after (reg 76(5) and reg 93).
A corporate can agree otherwise
The evidential duty (reg 75). The £35 cap and loss allocation (reg 77). The fraud hold conditions (reg 86(2A) to (2D)). Defective execution and charges (regs 91, 92, 94). The cost of a hold (reg 94A). A different notification period (reg 74(1)).
Figure 6: the corporate opt-out under regulation 63(5), liability subset only.
The FCA describes the third protected category as a charity with an annual income of less than £1 million (Approach Document 8.6). And because the PSRs 2017 permit the agreement to disapply “any or all” of the listed provisions, the FCA’s view at 8.7 is that it must be made clear to the customer which provisions are being disapplied. A general clause reciting that Part 7 does not apply is unlikely to satisfy that expectation, so the opt-out should name each provision it disapplies.
Which other regimes apply to the same transaction?
The statutory carve-out is regulation 64: where a payment transaction consists of the placing, transfer or withdrawal of funds covered by a credit line under a Consumer Credit Act regulated agreement, regulations 76(1) to (4) and 77(1) to (5) do not apply, and regulation 74 is disapplied only as it applies to regulation 76. It is a defined carve-out for credit-line transactions, not a blanket exclusion of credit cards from the PSRs 2017. The FCA’s position at 8.200 and 8.201 is that for CCA regulated credit cards the consumer credit regime applies to unauthorised transactions in place of regulations 74, 76(1) to (4) and 77(1) to (5), although regulation 75 still applies, and that for current accounts with overdrafts the two regimes divide according to whether the customer is in credit or overdrawn, with both applying where a single unauthorised transaction takes the account from one to the other. A firm offering both products needs either two operational processes or one built to the higher of the two standards.
Where a firm has borne a loss that is properly another firm’s, regulation 95 gives a right of recourse and regulation 148 a right of action, and the FCA notes at 8.363 that this includes compensation where a firm has failed to apply strong customer authentication required by regulation 100. Reimbursement for authorised push payment fraud operates as a separate regime again, and the Consumer Duty applies to the design of the claims and support processes a firm uses across all of this. The Safeguarding and Consumer Duty page covers both. Part 6 sets out the disclosure duties that sit behind these rules, and The PSRs 2017 Explained: Information Requirements and Framework Contracts covers what a firm must tell the payer and how it may change those terms.
What does each provision require?
The table indexes each provision: who it binds, what it requires, and the figure that shows it. It is a map, not the rules; the text of each provision governs.
| Provision | Who it binds | What it requires | See figure |
|---|---|---|---|
| Reg 63(5) | No one; it permits | A non-consumer customer and its provider may disapply listed provisions and vary the reg 74(1) period | Figure 6 |
| Reg 64 | Scope rule | For transactions on a credit line under a regulated agreement, disapplies regs 76(1) to (4), 77(1) to (5) and 74 as it applies to 76 | No figure |
| Reg 67 | Payer and its provider | Consent in the agreed form defines whether a transaction is authorised | Figure 1, consent edge |
| Reg 72 | Payer | Use the instrument on its terms, keep credentials safe, notify loss or theft without undue delay | Figure 1, standing conditions |
| Reg 73 | Payer’s provider | Provide means of notification at all times | Figure 1, standing conditions |
| Reg 74 | Payment service user | Notify without undue delay and within 13 months of the debit to keep redress under regs 76 and 91 to 94 | Figure 3, the gate |
| Reg 75 | Payment service provider; PISP for its leg, 75(2) | Prove authentication, accurate recording, entry in accounts and no technical fault | Figures 1 and 2, first family |
| Reg 76 | Account servicing provider | Refund an unauthorised transaction by the next business day, restore the account, back-value the credit; recover from a liable PISP, 76(5) | Figures 1 and 2, refund edges |
| Reg 77 | Allocates between payer and firm | Fraud, the 77(4) gateways, gross negligence, then the conditional £35 cap; the payee or its provider, or both, compensate on SCA failure, 77(6) | Figure 4 |
| Regs 85 and 86 | Payer’s provider | Execution deadlines from receipt of the order, and the conditions and limits of a suspected-fraud hold | Figure 5 |
| Regs 91 to 93 | Providers, by initiation route | Liability for non-executed or defective transactions: payer-initiated, payee-initiated, PISP-initiated | Figure 3, second family |
| Reg 94 | Payment service provider | Charges and interest consequent on non-execution or defective execution | Figure 3, second family |
| Reg 94A | Payer’s provider | Charges and interest the customer incurs from a reg 86(2B) hold, whether or not the order executes | Figure 5, hold costs |
| Reg 100 | Payer’s provider; the payee and its provider on acceptance | Strong customer authentication where required; failure moves the loss, 77(4)(c) and 77(6) | Figures 1 and 4 |
Need advice on payment liability and execution times?
Frequently asked questions about the PSRs 2017
Who has to refund an unauthorised payment transaction?
The payer’s payment service provider. Regulation 76(1) requires it to refund the amount and restore the account, subject to the payer’s limited liability under regulation 77. Where the transaction was initiated through a payment initiation service provider, regulation 76(5) still requires the account servicing provider to make the refund, and it may then recover from the payment initiation service provider.
How quickly must an unauthorised transaction be refunded?
As soon as practicable, and no later than the end of the business day following the day the firm becomes aware of it, under regulation 76(2). The deadline runs from awareness, not from the end of an investigation. It is disapplied only where the firm has reasonable grounds to suspect fraud by the customer and has notified in writing under section 333A(2) of the Proceeds of Crime Act 2002.
Does a firm have to prove the customer authorised the payment?
No. Regulation 75(1) requires it to prove that the transaction was authenticated, accurately recorded, entered in its accounts and unaffected by technical failure. That is not the same as proving authorisation, and regulation 75(3) provides that the recorded use of a payment instrument is not in itself necessarily sufficient to prove either authorisation or gross negligence by the payer.
How much of the loss can a customer be asked to bear?
Up to £35 under regulation 77(1) where the unauthorised transaction arose from a lost, stolen or misappropriated payment instrument. The cap does not apply where the loss was undetectable by the payer or was caused by the firm’s own people. Where the payer acted fraudulently, or failed with intent or gross negligence to comply with regulation 72, the payer bears the loss in full, although except in the case of fraud the regulation 77(4) protections apply first.
Can a firm contract out of these liability rules with a corporate customer?
Largely yes. Regulation 63(5) allows a firm and a payment service user who is not a consumer, a micro-enterprise or a charity to agree that any or all of a listed set of provisions, including regulations 75, 77, 86(2A) to (2D), 91, 92, 94 and 94A, do not apply, and to agree a different notification period for regulation 74(1). The refund duties in regulations 76 and 93 are not in that list. The FCA expects the terms to make clear which provisions are being disapplied.
Is there a time limit for complaining about an unauthorised payment?
Thirteen months from the debit date, with notification also required without undue delay, under regulation 74(1). The limit falls away under regulation 74(2) where the firm has not provided or made available transaction information in accordance with Part 6 of the PSRs 2017. A firm may offer a longer period, and the corporate opt-out in regulation 63(5) allows a different period to be agreed with a non-consumer customer.
How fast must a UK sterling payment be credited?
The payer’s payment service provider must have the amount credited to the payee’s provider by the end of the business day following receipt of the order, under regulation 86(1). Paper-initiated orders have until the end of the second business day. Transactions outside the regulation 85(1) and 85(1A) categories but executed wholly within the United Kingdom have until the end of the fourth business day under regulation 86(3).
Can a payment be held back while a firm investigates suspected fraud?
Yes, within limits. Regulations 86(2A) to (2D), in force from 30 October 2024, permit the payer’s provider to delay where it establishes reasonable grounds to suspect the order followed fraud or dishonesty by someone other than the payer, and does so by the end of the business day following receipt. The delay cannot run past the end of the fourth business day, and the payer must be told of the delay and its reasons.
What does a fraud-check delay cost the firm that imposes it?
Regulation 94A makes the payment service provider liable to its user for any charges the user is responsible for and any interest the user must pay as a consequence of a delay to the execution of a payment order in reliance on regulation 86(2B), irrespective of whether the payment order is ultimately executed. The FCA reads this as including third-party late payment charges but not wider losses such as a missed investment opportunity.
Do these rules apply to credit card transactions?
Not in the same way. Regulation 64 disapplies regulations 76(1) to (4) and 77(1) to (5) where the transaction involves funds covered by a credit line under a Consumer Credit Act regulated agreement, and the consumer credit regime governs instead, although regulation 75 still applies. For current accounts with overdrafts the two regimes divide according to whether the customer is in credit or overdrawn.
What happens if strong customer authentication is not applied?
The loss moves. Where regulation 100 requires strong customer authentication and the payer’s provider does not require it, the payer is not liable under regulation 77(4)(c) unless the payer acted fraudulently. Where the payee or the payee’s provider does not accept strong customer authentication, regulation 77(6) requires the payee or its provider, or both, to compensate the payer’s provider.
Related payments regulation pages
Payment Institution Authorisation and Licensing
Open Banking and Variable Recurring Payments
Safeguarding and Consumer Duty
PSR and Scheme Governance
Operational Resilience and DORA
EMI Authorisation and E-Money Regulation
FCA Investigations and Enforcement
Digital Money and Central Bank Digital Currencies
The PSRs 2017 Explained: Information Requirements and Framework Contracts. Readers wanting the wider context, including which activities and providers fall outside the regime altogether, should read The PSRs 2017 Explained: the Payment Services Perimeter and the Exclusions.
