FRIDA Scheme Rulebook: EPC Opens Fraud Data-Sharing Consultation
On 11 September 2026 the European Payments Council opened a public consultation on version 0.1 of the proposed FRIDA scheme rulebook. The consultation period runs from 11 September to 10 December 2026. FRIDA, the FRaud Information Distribution Arrangement, is the EPC’s proposed scheme for exchanging fraud data between payment service providers on account-to-account transactions across the Single Euro Payments Area. For a payment institution or e-money institution, the consultation is the window to read, and to comment on, the rulebook of a scheme it will have reason to join well before the decade is out.
The reason FRIDA matters now is the incoming EU Payment Services Regulation. The PSR would require PSPs to run transaction monitoring and to share certain fraud data with each other under formal information-sharing arrangements. The EPC has built FRIDA as the industry-standard way to meet that obligation: a single rulebook, common data standards, and a central platform for distributing and managing the life cycle of fraud alerts. The consultation is intended to inform the formal FRIDA rulebook and related technical material. Any publication target or PSR-aligned FRIDA application date remains a planning assumption until confirmed in the live EPC material; the PSR itself has not yet been adopted.
The timeline is tighter than it may appear. A fraud data-sharing scheme touches transaction monitoring systems, data protection governance, customer communications and vendor contracts at once, and the design choices are being fixed in this consultation round. The FRIDA version that participating PSPs would follow when the scheme becomes effective is being drafted now, making the consultation period an opportunity to influence its design.
Related reading: SEPA Instant Payments Regulation
The FRIDA scheme rulebook consultation calendar
Two EPC deadlines run in parallel this autumn, and they serve different audiences.
- 11 September 2026: public consultation on FRIDA scheme rulebook version 0.1 opens.
- A separate EPC Call for Interest concerns fraud data-sharing infrastructure providers; its submission mechanics and deadline should be checked directly against the live EPC notice.
- 10 December 2026: public consultation on the rulebook closes.
- The publication timetable for the formal version 1.0 rulebook and related technical specifications should be taken from the live EPC consultation package.
- The FRIDA effective date should be confirmed against the live EPC consultation material. The current PSR final-compromise text provides that the Regulation will apply 21 months after its entry into force, so the calendar application date remains provisional until adoption and Official Journal publication.
The first deadline is easy to miss because it is not the consultation. The Call for Interest asks organisations that offer, or plan to offer, fraud data-sharing infrastructure to work with the EPC on building the scheme. A compliance team scoping how it will connect to FRIDA has an interest in which providers respond, even if the firm itself does not.
What the scheme covers, and why it is not a supervisory return
FRIDA is a scheme in the EPC sense, the same family as SEPA Credit Transfer, SEPA Instant Credit Transfer and Verification of Payee: a set of inter-PSP rules, practices and standards that participating providers agree to follow. Its subject is fraud data on account-to-account payment transactions processed through the EPC payment schemes and any other account-to-account scheme in scope of the PSR. The EPC describes FRIDA as covering account-to-account payments processed through EPC payment schemes and other account-to-account payment schemes falling within the scope of the PSR in SEPA. The stated aims are automated fraud data sharing, a central platform for distributing and managing fraud alerts, and a common security and data protection baseline.
The confusion worth clearing early is with fraud reporting under PSD2. Today a PSP submits statistical fraud data to its competent authority under Article 96(6) of Directive (EU) 2015/2366 and the applicable EBA Guidelines on fraud reporting under PSD2. EBA/DC/453, as amended, governs the competent authorities’ onward reporting of aggregated payment-fraud data to the EBA. FRIDA is operational inter-PSP fraud-information sharing rather than a supervisory statistical return. The EPC describes it as a standardised framework for secure and automated fraud-information sharing between PSPs. Treating FRIDA as another line in the fraud statistics return misreads the whole design; the two coexist, and the statistical obligation does not disappear.
There is a second boundary. Joining FRIDA is a scheme membership decision. The legal obligation is in the current PSR final-compromise text: Article 83 requires transaction monitoring, while Article 83a(1) requires PSPs to participate in information-sharing arrangements with other PSPs and to exchange the specified fraud data when the Article 83a trigger is met. FRIDA is the EPC’s standardised route to satisfy that obligation, and the rulebook is written to fulfil the legal obligations that the PSR will place on PSPs and payment infrastructures. A firm could in principle meet the PSR through another arrangement, but for most SEPA participants an industry scheme with a shared rulebook and platform will be the path of least resistance.
PSR Articles 83 and 83a: transaction monitoring and fraud data sharing
The PSR remains in the EU legislative procedure. The European Parliament records PE787.675, dated 5 May 2026, as the text agreed during interinstitutional negotiations, while the procedure remains at the stage ‘Awaiting Council’s 1st reading position’. The PSR has therefore not yet been adopted or published in the Official Journal. For current pre-adoption analysis, PE787.675 is the relevant negotiated text; the requirements must be checked again against the adopted act once published.
Article 83 addresses transaction monitoring in the current PSR negotiating framework, while fraud data sharing is addressed separately in Article 83a. The transaction-monitoring data set and mechanics have changed during the negotiations, so firms should use PE787.675 rather than the data set in COM(2023) 367 as the current pre-adoption implementation baseline, and recheck the requirements against the adopted act once published.
Fraud data sharing is addressed separately under Article 83a in the current PSR negotiating framework. The Commission proposal’s Article 83(3) IBAN-only and two-customer formulation should not be used as the implementation baseline: that provision was materially revised during the negotiations. Firms should take the operative sharing trigger, data set, retention requirements and safeguards from PE787.675 and the FRIDA version 0.1 rulebook, and recheck them against the adopted PSR.
The Commission’s 2023 proposal contained retention and competent-authority notification provisions for information-sharing arrangements. Their current wording and location should be checked against Article 83a of PE787.675 before implementation.
How PSPs are expected to connect: Fraud Information Platforms
The EPC is developing a supporting architecture for FRIDA. The September 2026 Call for Interest sets out that the EPC expects PSPs to participate in FRIDA through national, local, intra-group or other fraud data sharing infrastructures, which the EPC refers to as Fraud Information Platforms (FIPs). The version 0.1 rulebook and the current Call for Interest should be used to confirm the role of Fraud Information Platforms and the final connectivity model.
That choice has practical consequences for a compliance and operations team. Whether your firm already sits on a national or group fraud-sharing utility, and whether that utility intends to become a FRIDA FIP, becomes a live procurement and onboarding question. The Call for Interest is the EPC’s mechanism for identifying candidate infrastructures during the build. If the platforms you rely on do not step forward, connectivity stops being something you inherit and becomes something you have to arrange.
For firms already managing operational resilience obligations, the FIP relationship will look familiar as an ICT third-party dependency. The security and continuity of the channel that carries fraud alerts is itself part of the control environment, and the same discipline applied to incident notification pipelines under DORA ICT incident reporting is a reasonable starting point for governing a FIP connection.
The data protection work the rulebook presupposes
Sharing a payee’s IBAN because two customers flagged it as fraudulent is processing of personal data, and the PSR proposal does not wave that away. The Commission’s 2023 proposal required a joint data protection impact assessment under GDPR Article 35 before concluding an information-sharing arrangement and, where applicable, prior consultation under Article 36. The corresponding requirement should be checked against Article 83a of PE787.675 before it is presented as the current negotiated PSR rule. The recitals add that a fresh assessment is not needed when a PSP joins an existing arrangement for which a DPIA has already been done, and that the arrangement should set out the technical and organisational measures and the roles and responsibilities, including any joint-controller relationships.
The PSR proposal is built on the conclusion that sharing is permitted, provided the arrangement carries the DPIA, the safeguards and the role allocation. What the assessment cannot be is an afterthought bolted on once the platform is live, because it is a precondition of concluding the arrangement in the first place.
The proposal also builds in anti-de-risking safeguards, and these change how a receiving PSP may act. Data shared under the arrangement may be used only to enhance transaction monitoring. The Commission’s 2023 proposal contained safeguards against using shared fraud data as an automatic basis for relationship termination or adverse future onboarding. The current safeguard should be verified against PE787.675 before implementation. Recital 105 reinforces the point: an IBAN appearing on a shared list is not, by itself, grounds to withdraw banking services without a detailed investigation, and the expected response is closer to contacting the payer and monitoring the account than to closing it. A firm that wires a shared-identifier hit straight into an account-closure workflow would be reading the scheme against its own stated safeguards. The relationship to AML de-risking is close enough that teams should keep FRIDA distinct from suspicious-activity processes such as Luxembourg’s AML fraud signalements to the CRF, which follow their own legal basis and channel.
Reading version 0.1 and shaping version 1.0
The consultation is on version 0.1, an explicitly draft rulebook, and the EPC has framed it as seeking feedback from relevant stakeholders before it settles version 1.0. Responses are due by 10 December 2026. Use the live EPC consultation page for the response method and any exact cut-off time. The scheme change here is not yet fixed, which is the opposite of most items that reach a reporting desk, where the rules are set and the task is implementation. For once the drafting is still open.
Worth testing against your own operations: the Article 83a fraud-sharing trigger and how it maps onto your fraud case management; the data fields and formats the technical specifications will carry, and whether they align with your existing fraud taxonomy; the FIP connectivity model and whether it fits the utilities you already use; and the notification, retention and safeguard mechanics that the rulebook will need to make workable. The EPC manages its schemes through iterative rulebook versions, and the pattern of scheme change is visible in how it has handled other adjustments such as the SEPA structured address migration timeline. Feedback lodged now is cheaper than a change request against version 1.0.
Where payment institutions and EMIs should start
FRIDA lands on the same teams that already carry the heaviest payments-reporting load, and payment institutions and e-money institutions supervised under the national PI and EMI regimes are squarely in the frame. The first task is a mapping exercise: which of your outbound and inbound flows are account-to-account transactions in scope of the PSR, where your current transaction monitoring sits against the Article 83 data set in the current negotiated PSR text, and who owns the joint DPIA when the time comes to conclude an arrangement. Firms that already track CSSF-style PI and EMI reporting through channels such as the CSSF eDesk prudential reporting route will recognise the coordination problem: several obligations, several owners, one calendar.
The concrete next step is small. Read version 0.1 against your fraud operations, decide whether to respond by 10 December 2026, and open the conversation with whichever fraud data-sharing infrastructure you expect to become your FIP. Everything after that depends on the rulebook the consultation produces.
Frequently Asked Questions
Does the PSR require my firm to join FRIDA specifically?
No. The current PSR final-compromise text requires PSPs to run transaction monitoring and, under Article 83a(1), to participate in information-sharing arrangements with other PSPs and exchange specified fraud data when the statutory trigger is met. It does not require participation in FRIDA specifically.
We are a small payment institution. Are we in scope of the sharing obligation?
The obligation applies to payment service providers, with the overall reach of the PSR set by its scope provisions, and FRIDA maps its own scope to account-to-account schemes covered by the PSR in SEPA. There is no size carve-out visible in the current negotiating text. Confirm your status and the final scope against the adopted PSR text before assuming a small-firm exemption exists.
Is FRIDA the same as our PSD2 fraud reporting to the regulator?
No. PSD2 fraud reporting under Article 96(6) of Directive (EU) 2015/2366 and the applicable EBA Guidelines is a statistical return from PSPs to their competent authorities; EBA/DC/453, as amended, governs the competent authorities’ onward reporting of aggregated data to the EBA. FRIDA is operational inter-PSP data sharing aimed at stopping individual transactions. They have different purposes, directions and data, and the statistical return continues in parallel.
How can we share a customer’s IBAN under the GDPR?
The PSR proposal treats this as lawful processing subject to conditions. The Commission’s 2023 proposal required PSPs to jointly carry out a data protection impact assessment under Article 35 of the GDPR before concluding an information-sharing arrangement and, where applicable, to consult the data protection authority under Article 36. A firm joining an arrangement that already has a completed DPIA does not need a fresh one. The arrangement itself must set out the safeguards, retention limits and controller responsibilities. The current requirements should be checked against Article 83a of PE787.675 and the adopted PSR once published.
What exactly can be shared, and when is the threshold met?
The operative sharing trigger and data set should be taken from Article 83a of the current negotiated PSR text and the FRIDA version 0.1 rulebook. The Commission proposal’s IBAN-only and two-customer formulation should not be used as the current implementation baseline for case-tagging.
If an IBAN we hold is shared as potentially fraudulent, can we close that account?
Not automatically. Article 83a(5) provides that PSPs must not draw conclusions or take decisions affecting a business relationship, including termination or future onboarding, solely on the basis of information received from other PSPs without first assessing that information; recital 105 adds that shared fraud data should not constitute grounds for withdrawal of banking services without detailed investigation. The expected response is to use the signal for monitoring and, where relevant, to contact the payer, and closure would need its own investigated basis.
What is a Fraud Information Platform and do we need to build one?
A Fraud Information Platform, or FIP, is the fraud data-sharing infrastructure through which a PSP is expected to connect to FRIDA. The September 2026 Call for Interest sets out that the EPC expects PSPs to participate in FRIDA through national, local, intra-group or other fraud data sharing infrastructures. The final connectivity model should be confirmed against the version 0.1 rulebook and the current Call for Interest. Most firms will select or confirm a FIP, not construct one.
Related Articles
- SEPA Instant Payments Regulation: the instant credit transfer and Verification of Payee obligations that sit alongside FRIDA in the EPC and SEPA rulebook stack.
- DORA ICT Incident Reporting: how to govern the resilience and reporting of the ICT channels that a fraud-sharing connection depends on.
- CSSF Prudential Reporting for PIs, EMIs and CASPs: the eDesk reporting environment the same payment-institution teams already manage.
- Luxembourg AML Law and CRF Fraud Signalements: the separate suspicious-activity channel that FRIDA should not be confused with.
- EPC SEPA Structured Address Migration Delay: a recent example of how the EPC manages change across its scheme rulebooks.
Key Takeaways
- The FRIDA scheme rulebook version 0.1 consultation runs to 10 December 2026. Check the live EPC consultation page for the exact closing time and submission mechanics before filing a response.
- A separate EPC Call for Interest concerns fraud data-sharing infrastructure providers; its submission mechanics and deadline should be checked directly against the live EPC notice.
- The EPC targets the formal version 1.0 rulebook and technical specifications by May 2027, with the scheme taking effect alongside the PSR, expected around Q4 2028.
- The current PSR negotiating framework separates transaction monitoring under Article 83 from fraud data sharing under Article 83a; the regulation remains under the legislative procedure and is not yet in force.
- Do not build case-tagging to the Commission proposal’s two-customer presumption; use the sharing trigger and data set in Article 83a of the current negotiated PSR text and the FRIDA version 0.1 rulebook.
- A joint data protection impact assessment under GDPR Article 35 is a precondition of concluding an information-sharing arrangement, with Article 36 consultation where residual risk is high; verify the current requirement against Article 83a of PE787.675.
- Shared IBAN data may be used only to enhance transaction monitoring and cannot by itself justify closing an account or refusing onboarding.
- Plan connectivity through a Fraud Information Platform and confirm whether the utilities you already use intend to become one.
Sources and References
- European Payments Council, EPC launches public consultation on FRIDA scheme rulebook (11 September 2026): europeanpaymentscouncil.eu
- European Payments Council, Call for Interest to Fraud Information Platforms to participate in EPC FRIDA scheme creation: europeanpaymentscouncil.eu
- Proposal for a Regulation on payment services in the internal market (PSR), COM(2023) 367, CELEX 52023PC0367: eur-lex.europa.eu
- European Parliament, PSR agreed text (PE787.675, 5 May 2026), procedure 2023/0210(COD), Legislative Train Schedule: europarl.europa.eu
- Regulation (EU) 2016/679 (GDPR), Articles 35 and 36 on data protection impact assessment and prior consultation: eur-lex.europa.eu
- EBA Guidelines on fraud reporting under PSD2 (EBA/GL/2018/05, as amended): eba.europa.eu
- EBA Decision EBA/DC/453 of 24 June 2022 on reporting of payment fraud data under PSD2, consolidated as amended by EBA/DC/482 of 23 March 2023: eba.europa.eu
Your window on the FRIDA rulebook closes on 10 December
FRIDA is still a draft, and that is the point. The rulebook is still under consultation, and firms should test the Article 83a sharing trigger, the connectivity model and the data-protection mechanics against their operations before the consultation closes on 10 December 2026. Read version 0.1 against your own fraud operations, decide whether to file a response through the EPC consultation page, and identify the Fraud Information Platform you expect to connect through before the version 1.0 text arrives.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
