
BNPL Regulation Raises the Bar. What Does It Mean for Fraud?
For years, Buy Now Pay Later (BNPL) occupied a somewhat unusual position in financial services: widespread adoption but lighter regulation than traditional consumer credit. That era is ending—with direct consequences for fraud prevention.
BNPL has grown enormously in a relatively short time. The UK market expanded more than 200-fold between 2017 and 2024. By May 2024, 10.9 million people—around one in five UK adults—had used BNPL in the previous 12 months. With adoption at this level, the days of relatively light regulation were always numbered.
In the UK, the biggest change arrived on 15 July 2026, when FCA rules for Deferred Payment Credit came into force. Many BNPL providers are now subject to the consumer credit regime, with tougher requirements around affordability, creditworthiness, customer protection, and regulatory oversight.
And this isn’t just a UK story. Across the US, regulators are taking a closer look at BNPL, with New York proposing a licensing framework and other states pursuing their own approaches. The specifics vary, but the broader shift is hard to miss. BNPL is increasingly being treated as what it is: credit.
What Regulators Are Actually Asking For
The FCA’s new regime gives us a clearer picture of what tighter BNPL regulation looks like in practice.
- Authorization: BNPL providers must now be authorized by the FCA (or operate under temporary permissions while transitioning). This brings BNPL firmly within the UK’s regulated consumer credit framework.
- Creditworthiness and Affordability: Providers must assess a customer’s creditworthiness, including whether they can afford the repayments. The FCA requires these checks to be proportionate, with the depth of assessment depending on the circumstances rather than following a one-size-fits-all approach.
- Consumer Duty: Consumer Duty shifts the focus from processes to outcomes. Rather than simply demonstrating compliance, firms are expected to deliver good outcomes for customers—and be able to show that they are doing so.
- Clear Disclosures: Customers must receive clear information about repayment obligations, payment schedules, key risks, and their rights before entering an agreement. Regulators want consumers to understand that BNPL is a form of credit, with responsibilities attached, rather than just another checkout option.
- Complaints: The new framework also strengthens protections when things go wrong. Providers must have clear processes for handling complaints fairly, with customers now able to take eligible complaints to the Financial Ombudsman Service.
BNPL providers are being brought much closer to the standards expected of traditional lenders. But the higher regulatory bar also brings the fraud question into sharper focus. Assessing whether someone can afford to repay is only part of the challenge. Providers also need confidence that the person applying for credit is who they claim to be, that the right person is using the account, and that the transaction itself is legitimate.
What Stronger Regulation Means for BNPL Fraud
BNPL has its own fraud challenges. Providers need to make lending decisions in seconds, often with relatively little information about a new customer, while repayments may stretch over weeks or months. That gives fraud multiple points of entry, from onboarding to long after the purchase is made.
Stronger regulation should make BNPL fraud harder. That’s the point. But it won’t make the fraud disappear. Some of the hardest problems remain: synthetic identities, first-party abuse, and account takeover fraud.
- Synthetic identities become more valuable: The higher the verification bar, the more valuable an identity capable of clearing it becomes. Once a synthetic customer has passed verification and started building a legitimate-looking history, there may be little on the surface to distinguish that account from a genuine one.
- First-party fraud gets harder to separate from credit risk: Not every BNPL loss starts with a fake identity. Some customers may use BNPL to obtain goods with no intention of completing the instalments, while others falsely dispute purchases they genuinely made. As BNPL comes under greater scrutiny around affordability and customers in financial difficulty, separating genuine repayment problems from deliberate abuse becomes increasingly important.
- Account takeover remains a post-onboarding problem: Identity verification only establishes trust at a point in time. Once a BNPL account has built up a payment history and access to credit, that trust has value. A fraudster who takes over the account can use it to make purchases, while the compromise may go unnoticed until a later instalment is charged. Everything checked at onboarding may have been legitimate. The problem is that the person behind the account has changed.
Why More Friction Isn’t the Answer
The obvious response to a higher regulatory bar is more checks. But for BNPL, that comes with a cost. Speed and simplicity are fundamental to the product, and every additional verification step or challenge risks adding friction for legitimate customers—and ultimately damaging conversion rates.
Plus, more friction doesn’t necessarily stop the fraud that remains. A synthetic identity may clear additional verification, a first-party fraudster is already using their real identity, and an account takeover can happen long after onboarding is complete. More checks can raise the barrier without closing the gaps.
The goal is friction where it’s warranted: identifying when the risk is higher and adding scrutiny then, rather than forcing every customer through the same obstacles.
Read more about smart friction
… But Behavioral Intelligence Is
Knowing when to add scrutiny depends on what you can see. Identity verification establishes whether a customer can clear an identity check. Creditworthiness and affordability assessments address lending risk. But neither tells BNPL providers much about what is happening during the interaction itself.
Behavioral intelligence fills in that missing context. Rather than asking customers for another proof point, it assesses how someone moves through onboarding or checkout, the device they’re using, signs of malware or remote access, changes from their usual behavior, and the circumstances surrounding the transaction.
These signals can distinguish ordinary customer activity from something that warrants a closer look—even when an identity has passed verification, the customer is genuinely who they claim to be, or the account has a legitimate history. And because risk is assessed continuously, that visibility doesn’t end at onboarding.
How ThreatMark Helps with BNPL Fraud
When you can assess risk throughout the customer journey, you don’t have to wait until the transaction takes shape to spot trouble. More than 80% of fraud can be detected before payment creation.
ThreatMark Fraud Disruption Platform brings those signals together. It combines behavioral profiling, device intelligence, transaction risk analysis, and machine learning to continuously assess risk as customers interact with a BNPL provider, giving fraud teams visibility into anomalies that traditional identity and credit checks can miss.
- Spotting synthetic identity signals: A verified identity doesn’t necessarily tell the whole story. Signals from the device, session, and user behavior, from navigation paths and typing cadence to device characteristics and IP, can expose inconsistencies even when the identity presented at onboarding appears legitimate.
- Separating first-party fraud from credit risk: Transaction and behavioral signals add context that credit risk alone cannot provide. Rather than treating every missed repayment or disputed purchase as the same problem, fraud teams can identify behavior that points to deliberate abuse.
- Detecting account takeover after onboarding: Continuous behavioral and device monitoring helps expose the moment a trusted account stops behaving like one. A legitimate history shouldn’t mean automatic trust when the device, behavior, or context suddenly changes.
The point isn’t to add another hurdle, but to make intervention more precise. That’s where ThreatMark fits: alongside the identity, affordability, and credit checks regulators require, helping BNPL providers catch more fraud, reduce false declines, and keep checkout friction low.
Preparing for Audit and Scale: A Practical Checklist
For fraud and compliance leaders, the challenge now is making sure those controls hold up beyond regulation day. A few questions are worth putting to the test:
- Can you reconstruct a decision? Make sure you can show what drove an affordability, credit, or fraud decision, including the signals available and why action was or wasn’t taken.
- Can you separate fraud from financial difficulty? Fraud, credit, and collections teams need to distinguish deliberate first-party abuse from customers genuinely struggling to repay.
- Does risk assessment continue after onboarding? Changes in device, behavior, or transaction context should be able to challenge trust established when the account was opened.
- Can you justify the friction? Know what risk signals trigger additional verification or intervention, rather than applying the same controls to every customer.
- Will your controls hold up at scale? Watch where growing volumes increase manual reviews, false positives, or customer friction, and address those bottlenecks early.
Better risk signals help BNPL providers intervene when it matters, without turning every checkout into an obstacle course. As BNPL becomes more regulated, the answer isn’t to make every customer prove themselves more. It’s to get better at knowing when something isn’t right.