Skip to main content
Normal View

Crime Prevention

Dáil Éireann Debate, Wednesday - 22 October 2025

Wednesday, 22 October 2025

Questions (36)

Ken O'Flynn

Question:

36. Deputy Ken O'Flynn asked the Minister for Finance if he will consider mandating stronger customer-authentication and fraud-reimbursement obligations similar to those introduced in the United Kingdom under the Payment Systems Regulator’s Contingent Reimbursement Model Code. [57605/25]

View answer

Written answers

The UK’s contingent reimbursement model came into effect in October 2024. The mandatory reimbursement rule in the UK requires financial institutions to reimburse victims of authorised push payment (APP) fraud for UK payments made via Faster Payments or CHAPS payment systems. APP Victims can be reimbursed up to £85,000. The costs for these reimbursements are shared equally between the sending and receiving Payment Service Providers (PSPs).

Payment Service Providers (PSPs) authorised in Ireland and PSPs that operate in Ireland under authorisations in other EU States are subject to the requirements of the Directive 2015/2366/EU on payment services (PSD2). PSD2 is a maximum harmonisation Directive hence Member States shall not maintain or introduce provisions other than those laid down in this directive.

PSPs must apply Strong Customer Authentication (SCA) when a payer: (i) accesses payment accounts online, (ii) initiates an electronic payment, or (iii) carries out any action through a remote channel. PSPs are liable for losses resulting from unauthorised payment fraud but liability for fraud where the payment is authorised via SCA is not provided for.

PSD2 will be repealed and replaced by the proposed Payment Services Regulation (PSR) and its accompanying Payment Services Directive (PSD3), which together aim to increase harmonisation in the area of European payments regulation, including in the areas of authorisation and fighting payment fraud. Both files are currently in Trilogue negotiation under the Danish Council Presidency.

Fighting and addressing fraud is a key element of the draft PSR proposed by the European Commission. This includes strengthening existing strong customer authentication (SCA) measures and the extension of Payment Service Provider (PSP) liability to cases in which the victim is manipulated into authorising a fraudulent payment by a fraudster impersonating their PSP. As well as incorrect application of the matching verification service (IBAN check), and failure to support the application of SCA.

The shifting of liability for such cases onto PSPs aims to incentivise PSPs to develop better solutions to mitigate instances of impersonation / authorised push payment (APP) fraud. This is a departure from the current Payment Services Directive (PSD2), under which PSPs are liable only for losses which are the result of unauthorised transactions.

Liability for impersonation fraud is being considered in the context of ongoing PSR negotiations.

When agreed, PSD3 and the PSR will build on the foundation of PSD2 and further harmonise the European payment services market. It will be important to have a harmonised, pan-European response to fraud to avoid loopholes and protect consumers across the European Union.

This is also a cross-sectoral issue and will need to be addressed through a number of initiatives, including financial literacy programmes, engagement from social media and tech companies, and cooperation between industry and regulators in order to protect and inform consumers.

In Ireland currently several steps to combat fraud are underway, in line with recommendations made by the National Payments Strategy. The BPFI has established a cross sectoral anti-fraud forum with representatives from online platforms, financial services providers, telecommunications services providers and their respective regulators (the Central Bank, ComReg and Coimisiún na Meán) participating. This anti-fraud forum aims to foster cross-sectoral cooperation in fraud prevention through information sharing, coordinated action, and alignment with legislative requirements.

The National Payments Strategy also actioned the Department of Justice, Home Affairs & Migration to work on legislation for a shared fraud database. I am informed by the Department of Justice, Home Affairs & Migration that work on this legislative project is underway.

Share