
Two Years to Reimbursement, and Most Banks Aren’t Ready
ThreatMark’s Fraud Readiness Benchmark 2026 revealed that almost 70% of financial institutions expect banking regulation mandating reimbursement for authorized push payment fraud within the next two years. Yet most are still far from ready.
Banks aren’t expecting reimbursement mandates to emerge out of nowhere. Developments across key markets suggest the liability shift is already underway.
In the United Kingdom, reimbursement requirements for APP fraud have been in effect since 2024. In Europe, upcoming PSR rules are set to expand liability and strengthen consumer protections. The tide is turning in the United States as well, where cases involving Zelle and Cash App are increasingly testing where responsibility lies when customers authorize payments after being deceived.
Together, these changes point to a broader shift in responsibility, with banks increasingly expected to absorb losses from authorized fraud.
Download the Full Report

The Clock Is Ticking, but Readiness Remains Low
Yet knowing change is coming and being ready for it are two very different things. While banks largely expect reimbursement mandates and the operational demands they will bring, most are not prepared to meet them.
In North America, only 31% of financial institutions consider themselves currently prepared to comply with a regulatory requirement to reimburse APP fraud victims. In other words, if reimbursement became mandatory tomorrow, roughly two out of three banks would be caught on the back foot.
Why are so many institutions unprepared? Part of the answer lies in the uncertainty surrounding upcoming banking regulations. Many banks are reluctant to make major investments before the rules are finalized, preferring to wait and tailor their response to the exact requirements.
Competing priorities also help explain the gap. Banks are balancing no shortage of regulatory and technology initiatives, and until recently, APP fraud reimbursement was widely viewed as a UK or European problem. For many institutions, it simply wasn’t high on the agenda.
Why Waiting Is a Risky Bet
Given the investment that fraud prevention transformation requires, this wait-and-see approach might seem reasonable.
But with a timeline of two years or less, it is becoming an increasingly risky bet. By shifting financial responsibility for a growing category of scams directly onto banks, APP fraud reimbursement requirements will demand significant changes to fraud operations, customer journeys, and detection capabilities. And those changes cannot be made overnight.
Preparing for reimbursement is about more than setting aside funds to compensate victims. As banking regulations evolve, institutions must also build the processes, controls, and governance needed to identify qualifying cases, handle claims consistently, maintain documentation, and demonstrate compliance.
In an ideal world, APP fraud reimbursement becomes as routine as handling unauthorized fraud is today. For many institutions, however, the foundations for that operational model are still being put in place.
The Financial Reality of Reimbursement
If banks are hoping reimbursement costs will ease with time, markets that have already made the liability shift offer an important reality check. In those European markets, around 80% of institutions reported that reimbursement volumes either increased or remained unchanged over the past year. Only a small minority saw them decline.
In other words, reimbursement costs are not declining for nearly four out of five banks. Once reimbursement obligations take hold, the financial impact does not simply fade into the background.
Now let’s look at what those volumes mean in practice. Among the European institutions surveyed, all operating under established reimbursement rules, 73% had to reimburse 500 or more fraud cases in the past 12 months, and one in five handled more than 10,000 cases during that period. The latter figure translates to around 200 fraudulent incidents every week.
Managing fraud at this scale is not only an operational challenge but also a financial one. High case volumes can turn reimbursement into a persistent cost that banks must absorb year after year.
Three Lessons from Markets Already Living with Reimbursement
For banks still preparing for reimbursement, there is already a roadmap. The experience of institutions operating under reimbursement requirements offers several lessons worth paying attention to.
1. Reimbursement Alone Does Not Reduce Fraud
Markets where reimbursement is already established offer an important lesson: compensating victims does not, by itself, reduce fraud. While reimbursement strengthens consumer protection, it does little to address the tactics and manipulation behind APP scams. As a result, institutions can continue to face high fraud volumes while shouldering the financial cost of making customers whole.
2. Operational Readiness Matters as Much as Regulation
Every reimbursed case sets a chain of processes in motion, from confirming the fraud and recovering or writing off funds to maintaining records and communicating with customers. As reimbursement volumes grow, these tasks become a significant operational burden. In markets where institutions handle hundreds or even thousands of cases each year, reimbursement becomes a routine process that must function efficiently, consistently, and at scale.
3. The Cost of Waiting Grows Over Time
Many institutions can already see the liability shift on the horizon, yet significant preparation still lies ahead. Building the systems, processes, and cross-functional coordination needed to support reimbursement is not a last-minute exercise. The institutions furthest ahead are already turning expectation into execution. For everyone else, the takeaway is simple: the time to prepare is now.
Breaking the Reimbursement Cycle
The picture that emerges from regulated markets is hard to ignore. Reimbursement is becoming a permanent operational and financial burden for many institutions, with some handling hundreds or even thousands of cases every year.
Faced with volumes on this scale, adding more staff or expanding claims-processing capacity can help manage the workload. But it does not change the underlying problem. It scales the response to fraud, not the reduction of fraud itself.
This is why more institutions are shifting their focus upstream. Rather than concentrating solely on what happens after a scam has occurred, they are looking for ways to intervene while the customer is still engaged in the payment journey. The goal is simple: stop the fraudulent transaction before the money leaves the account and before reimbursement becomes necessary.
Why APP Fraud Prevention Matters More Than Ever
Reimbursement changes the equation of fraud prevention because every prevented scam represents more than a fraud loss avoided. It is also a reimbursement case that never has to be investigated, processed, documented, or refunded.
Preventing APP fraud, however, requires a different approach than preventing unauthorized fraud. Customers are often using their own devices, authenticating successfully, and willingly initiating the transaction. From a traditional fraud-control perspective, everything can appear legitimate.
The warning signs emerge much earlier in the customer journey. Long before a payment is submitted, customers may exhibit behavioral patterns associated with social engineering, coercion, or remote manipulation. Detecting those signals requires visibility beyond the transaction itself and into the context surrounding it.
This is why many institutions are moving detection further upstream and turning to behavioral intelligence. Rather than focusing exclusively on whether a payment looks suspicious, they are looking for contextual indicators that a scam may already be unfolding: behavioral anomalies, signs of remote access, unusual customer interactions, and other signals can help identify risk before an irreversible payment is authorized.
The earlier banks can identify manipulation and intervene, the greater their chances of stopping losses before they occur and preventing a reimbursement case from being created in the first place.
The message from regulated markets is clear: as reimbursement becomes the norm, preventing scams before they happen is no longer just a fraud objective. It is a business imperative.
See how in-session detection cuts reimbursement exposure. Book a ThreatMark walkthrough.