PSR Specific Direction 20: APP Scam Reimbursement Reporting
On 7 October 2024 the reimbursement requirement in PSR Specific Direction 20 became live, and every payment service provider that sends a Faster Payments transaction from a relevant UK account acquired two obligations at once. The first is reimbursement: where an FPS APP scam claim is reimbursable, the sending PSP must reimburse the consumer subject to the £85,000 maximum and the applicable exclusions, exceptions and time limit; any receiving-PSP contribution is calculated separately under SR1. The second is data: collate, retain and report a defined set of compliance metrics to Pay.UK so the payment system operator can check whether the reimbursement rules were actually followed.
The reporting side is where most implementation effort quietly goes. Pay.UK monitors PSP compliance with the FPS reimbursement rules under SD19, while the PSR monitors and enforces compliance with SD20. It directs in-scope firms to comply with reimbursement rules that sit inside the Faster Payments scheme, and it requires those firms to feed Pay.UK the evidence. That evidence flows through the Compliance Data Reporting Standards, the CDRS, and the monthly Reporting Standard A submission that began landing at Pay.UK on 6 January 2025. Miss the field mapping and a firm can reimburse every victim correctly and still fail the monitoring layer.
This guide walks a UK reporting officer through Specific Direction 20 from the reporting seat: the legal scaffolding, who is caught, what the reimbursement rules oblige, and precisely what the CDRS asks firms to record and send. It is written for the person who has to reconcile the claims system against the return, not for the person drafting the fraud policy.
Related reading: the UK payments initiative and the open banking commercial variable recurring payments scheme.
How PSR Specific Direction 20 fits the regulator’s legal toolkit
The direction itself is short. It carries the APP scams reimbursement requirement and instructs in-scope PSPs to comply with the reimbursement rules. The operative detail that a reporting team needs, the metrics, the timing, the claim mechanics, lives elsewhere: in the Faster Payments reimbursement rules that Pay.UK maintains and in the Compliance Data Reporting Standards. Reading SD20 alone and expecting a rulebook is the first mistake teams make.
The PSR gives directions under section 54 of the Financial Services (Banking Reform) Act 2013, its general power to direct participants in a regulated payment system in writing. Separately, the PSR imposed Specific Requirement 1 (SR1) on Pay.UK under its requirement-imposing power, obliging the operator to build the reimbursement requirement into the Faster Payments scheme rules. So there are two instruments doing two jobs: SD20 binds the PSPs, SR1 binds the operator to write and run the rules the PSPs must follow.
Sitting alongside SD20 are two separate instruments. Specific Direction 18 governs the collection and publication of firm-level APP fraud performance information. Specific Direction 19 directs Pay.UK to create and maintain the Faster Payments reimbursement compliance-monitoring regime. The CDRS supports the SD19 monitoring regime and forms part of PSPs’ data obligations under SD20.
One structural point shapes everything downstream. Because SD20 directs compliance with Pay.UK’s rules, Pay.UK is the body that monitors compliance, while enforcement stays with the PSR. A reporting officer therefore has two audiences with one dataset: Pay.UK reads the returns to monitor, and the PSR stands behind Pay.UK with the enforcement powers if something is wrong.
The dates that anchor the SD20 reporting calendar
Deadline pressure is the reason this topic sits on so many 2024 and 2025 project plans, so the calendar deserves to be scannable. These are the operative dates for the reimbursement requirement and its reporting obligations:
- 12 July 2024 – the amended and consolidated SD20 came into force, revoking and replacing the original direction of 19 December 2023. The CDRS was first published in July 2024; the current PSR PDF is labelled ‘updated October 2024’.
- 20 August 2024 – deadline for PSPs already in scope to register with Pay.UK for the FPS Reimbursement Directory. This was a registration deadline, not a deadline requiring every PSP to adopt the full RCMS claims-management product.
- 7 October 2024 – the reimbursement requirement comes into effect; Reporting Standard A applies from this date; sending PSPs capable of sending in-scope payments must tell existing customers about their reimbursement rights.
- 6 January 2025 – first report under Reporting Standard A due to Pay.UK, covering the period from 7 October to 30 November 2024.
- After the first submission, each Reporting Standard A report covers one month and is due by close of business on the last business day of the following month. A nil notification is required where a PSP capable of sending received no claims in the reporting period.
- 9 April 2025 – deadline for directed sending PSPs to update customer terms and conditions to reference the reimbursement obligation.
- 31 March each year is the deadline for indirect access providers to submit their complete prior-calendar-year customer list to the PSR. They must also submit an update by 30 April 2024 and monthly thereafter whenever the list changes; no monthly report is required where there has been no change.
The date that catches people is 6 January 2025. The first Standard A return covers the stub period from go-live to the end of November 2024, a window shorter than a full calendar month. A team that built its extract logic assuming clean monthly windows had to special-case that opening submission.
Related reading: our guide to PSD2 reporting requirements for UK payment and e-money firms.
Who Specific Direction 20 actually captures
SD20 applies to all PSPs participating in the Faster Payments Scheme that provide relevant accounts. A relevant account is one provided to a service user, held in the UK, that can send or receive payments over Faster Payments. The direction is explicit that there are no exemptions based on business or firm type. A payment institution or an electronic money institution that offers a qualifying account is caught on the same terms as a clearing bank.
The perimeter works by exclusion: a broad relevant-account test with a short list of carve-outs. Accounts provided by credit unions, municipal banks and national savings banks fall outside the definition of a relevant account. Everything else that meets the relevant-account test is in. A scoping exercise built around firm labels misses the point, because the test turns on whether the account can move a Faster Payment and says nothing about what the firm calls itself.
Indirect participants matter too. Many smaller PSPs reach Faster Payments through an indirect access provider instead of a direct technical connection. SD20 reaches them through their own relevant accounts, and it separately obliges the access providers to identify them. That second limb is the annual list obligation covered later in this guide, and it is the mechanism the PSR uses to see the long tail of firms that never appear on the direct participant list.
What the reimbursement rules oblige in-scope PSPs to do
The reporting cannot be understood without the underlying rules, because the metrics describe how a firm behaved against them. The Faster Payments reimbursement rules, which SD20 directs firms to follow, set a consistent minimum standard of protection for consumers, microenterprises and charities who fall victim to an in-scope APP scam.
The headline figures are fixed. The maximum a firm has to reimburse is £85,000 per claim, a level the PSR confirmed in its October 2024 policy statement after reducing the previously confirmed £415,000 maximum before the requirement went live. The PSR estimated that £85,000 fully covers 99.8% of Faster Payments APP scams by volume and 90% by value. After reimbursing the victim, the sending PSP may request a contribution from the receiving PSP. Subject to SR1’s exclusions and adjustments, the receiving PSP must pay 50% of the lower of the amount actually reimbursed that is attributable to payments sent to that receiving PSP and the amount the sending PSP was required to reimburse for those payments.
Once a victim reports an FPS APP scam claim, the sending PSP must reimburse any reimbursable payment within five business days. The PSP may stop the clock only while awaiting information requested for one of the circumstances specified in SR1 paragraph 5.4, including assessing whether the claim is reimbursable, assessing vulnerability, investigating evidence of first-party fraud, or verifying that a claims management company is submitting a legitimate claim on the consumer’s behalf. The clock resumes when the response is received, and the claim must be closed before the end of the 35th business day. A claim reported more than 13 months after the final FPS APP scam payment need not be reimbursed.
Two exceptions shape the reporting. A sending PSP may apply a single excess of up to £100 per claim, and it may decline reimbursement where the consumer standard of caution exception applies. The latter requires the PSP to establish gross negligence in the consumer’s failure to meet one or more elements of the standard of caution. The excess and the consumer standard of caution exception are disapplied only where the victim was vulnerable when making the payment and that vulnerability had a material impact on their ability to protect themselves from the scam. Vulnerability alone is not the complete legal test.
The reimbursement requirement and FPS reimbursement rules require reimbursement in most cases. They do not require reimbursement where a payment or claim falls outside the defined scope or an applicable exception or time limit applies. The reporting exists precisely so Pay.UK can see how often, and on what basis, firms are declining.
The CDRS: what PSPs must collate, retain and report
The Compliance Data Reporting Standard turns the reimbursement rules into data and record-keeping obligations. The current PSR PDF is labelled ‘updated October 2024’ and is effective from 7 October 2024 until replaced. It defines the live Reporting Standard A requirements, the future Reporting Standard B scenario and the records that all directed PSPs must maintain.
Reporting Standard A is aggregate monthly reporting by sending PSPs. It reports total volumes and values against the applicable CDRS metrics for claims closed during the reporting period; it is not a transaction-level return. The first report was due by 6 January 2025 for claims closed from 7 October to 30 November 2024. Each subsequent report covers one month and is due by close of business on the last business day of the following month. A directed PSP capable of being a sending PSP must also submit a nil notification for any reporting period in which it received no FPS APP scam claims.
Reporting Standard B is the future, more comprehensive CDRS scenario. It is not currently in force. The latest published PSR timetable said Standard B was intended for adoption by no later than December 2026, subject to consultation. When Standard B takes effect, all directed PSPs will be required to collate and retain the full CDRS dataset.
Underneath both standards sits a record-keeping duty. Directed PSPs must keep accurate records of customer communications and responses; communications with other parties; communications with Pay.UK about reimbursement processes or potential compliance issues; individual claim decisions and their rationale; remediation actions; and relevant first-, second- and third-line reports on APP-scam systems and controls. The information required to be retained under SD20’s record-keeping and retention provisions must be kept securely for at least five years. These records form the audit trail behind the counts: the individual reasoning that each total is built from. When Pay.UK’s monitoring queries a firm’s numbers, the record-keeping is what substantiates them. CDRS metric 3.1 is an aggregate volume-and-value metric for claims closed within five business days, measured from the consumer’s report to reimbursement or claim rejection. Under SR1, a claim cannot be closed until the assessment is complete and any required reimbursement has been paid or the claim has been rejected.
Current-state summary: Standard A is the live monthly aggregate return for sending PSPs. Standard B is a future, more comprehensive regime. While Standard A applies, receiving PSPs do not have to collate or retain Standard A metric data, although all directed PSPs remain subject to the separate CDRS record-keeping duties.
How the data reaches Pay.UK and who reads it
Pay.UK provides two RCMS products. RCMS Core provides access to the reimbursement directory and functionality for submitting Reporting Standard A data, while RCMS Core + Claims adds claims-management functionality. The 20 August 2024 SD20 deadline required existing directed PSPs to register with Pay.UK for the directory; it did not require universal adoption of the full claims-management product. Pay.UK uses RCMS Core as its standard channel for Reporting Standard A submissions. SD20 also permits reporting by a reasonable alternative method, subject to Pay.UK’s assessment, while the PSR has stated that it does not intend to mandate a particular claims-management system for Standard B.
Pay.UK monitors and manages compliance with the FPS reimbursement rules under its compliance-monitoring regime and may take scheme-level action on breaches under that regime. It also reports relevant matters to the PSR. The PSR retains statutory responsibility for monitoring and enforcing compliance with SD20 and may escalate identified non-compliance to regulatory enforcement.
Where a firm’s claim, assessment, reimbursement and customer-contact data sit in different systems, the reporting build must assemble a coherent and reconcilable claim record across those systems. The CDRS is indifferent to a firm’s internal architecture and asks only for a coherent, reconcilable account of each claim. Assembling that from fragmented systems is the real reporting build.
The indirect access provider list, and why it is a separate obligation
Alongside reimbursement and CDRS reporting, SD20 places ongoing reporting obligations on indirect access providers. An IAP, whether directly or indirectly connected to Faster Payments, must give the PSR a complete list of its indirect PSP customers for the previous calendar year by 31 March each year. It must also submit an update by 30 April 2024 and monthly thereafter whenever that list changes; no monthly report is required where there has been no change. The PSR provides an optional template for the annual list.
This obligation exists to solve a visibility problem. The PSR can see direct Faster Payments participants readily; the firms that reach the scheme indirectly are harder to enumerate. The annual IAP list is the mechanism that maps the indirect population so the regulator knows which smaller PSPs are, through their relevant accounts, inside the reimbursement perimeter. A common misreading treats the IAP list as part of the CDRS compliance data. The IAP list is a separate structural return about who accesses the scheme, filed to the PSR as an annual submission and kept distinct from the monthly monitoring data that goes to Pay.UK.
Where reporting teams get the CDRS wrong
The reimbursement policy attracts the attention, but the reporting is where firms accumulate quiet compliance risk. A handful of errors recur.
The first is scope by firm type. Because SD20 exempts no business model, some smaller payment and e-money firms assumed a threshold or a carve-out existed and only checked when a partner bank asked for their scope status. The test is the relevant account, held in the UK and capable of sending or receiving a Faster Payment, with only the credit union, municipal bank and national savings bank exclusions.
The second is to confuse record-keeping with live metric reporting. All directed PSPs, including receiving PSPs, must maintain the records specified in the CDRS record-keeping section. However, while Standard A applies, receiving PSPs do not have to collate or retain Standard A metric data. Receiving-side metric reporting becomes relevant when Standard B is brought into force.
The third is the vulnerability assessment. The relevant legal test is whether the victim was vulnerable when making the payment and whether that vulnerability materially affected their ability to protect themselves from the scam. That determination affects whether the excess or consumer standard of caution exception may be applied and must be supported by the claim record.
The fourth is the metric 3.1 measurement endpoint. CDRS metric 3.1 measures the interval from the consumer’s report to reimbursement or claim rejection. Reporting teams should reconcile the source timestamps used for that calculation before submission.
Recent changes and how the regime consolidated
The reimbursement framework arrived through several instruments across 2023 and 2024, which is why the source trail looks fragmented. The consumer standard of caution guidance was published in December 2023. The maximum level of reimbursement was confirmed at £85,000 in the October 2024 policy statement, replacing the £415,000 maximum that the PSR had confirmed in December 2023 before the requirement went live. In May 2025 the PSR issued a consolidated policy statement that pulls the reimbursement requirement together in one place, which is now the cleaner reference point than reading each earlier document in sequence.
For firms watching the direction of travel, the reporting layer is the part most likely to evolve. The CDRS defines the compliance data collected by Pay.UK. The PSR publishes the APP scams reimbursement dashboard using Standard A data supplied by sending firms through Pay.UK. Firm-level APP fraud performance publication is governed separately under SD18. A reporting team should track updates to the Pay.UK reimbursement rules and any revised CDRS version, and should not treat the July 2024 baseline as static, because the compliance metrics are the instrument most sensitive to operational review. Confirmation-of-payee style name-checking controls, such as the Verification of Payee scheme used across European payment service providers, sit upstream of this regime as a fraud-prevention control, but they do not change what SD20 requires a firm to reimburse or report once a scam has occurred.
One boundary is worth stating so it is not assumed away. SD20 and the CDRS govern Faster Payments. Equivalent protection for CHAPS payments is governed by PSR Specific Direction 21, the CHAPS reimbursement rules made by the Bank of England as CHAPS operator, and the separate CHAPS compliance-data and reporting arrangements. A firm that clears both rails cannot assume a single reporting pipeline covers everything; the Faster Payments obligations in this guide are the SD20 and CDRS obligations specifically. For firms comparing the UK approach with the EU instant-payments trajectory, our note on the SEPA Instant Payments Regulation sets out a different model built around mandatory reachability and verification rather than mandatory reimbursement.
Frequently Asked Questions
Does Specific Direction 20 apply to payment institutions and e-money firms, or only to banks?
It applies to any PSP participating in the Faster Payments Scheme that provides a relevant account, with no exemption based on firm type. A payment institution or electronic money institution offering a UK account that can send or receive Faster Payments is directed on the same terms as a bank. Only accounts from credit unions, municipal banks and national savings banks sit outside the relevant-account definition.
What is the difference between Reporting Standard A and Reporting Standard B?
Reporting Standard A is the live aggregate monthly reporting regime for sending PSPs. Reporting Standard B is the more comprehensive future regime under which all directed PSPs would collate and retain the full CDRS dataset. As of July 2026, Standard B has not been brought into force and the PSR continues to use Standard A data from sending firms.
When was the first CDRS report due and what period did it cover?
The first Reporting Standard A submission was due to Pay.UK by 6 January 2025 and covered the stub period from go-live on 7 October 2024 to 30 November 2024. Every subsequent report is monthly and covers claims closed in the previous calendar month, which is why the opening submission needs its own extract logic.
Who monitors and who enforces compliance?
Pay.UK, as the Faster Payments operator, monitors compliance with the reimbursement rules using the CDRS data. Enforcement of Specific Direction 20 remains with the PSR. The reporting therefore feeds an operator’s monitoring function first and can escalate to the regulator if monitoring surfaces a problem.
How do vulnerable customers change what a firm must report?
The sending PSP cannot apply the £100 excess or the consumer standard of caution exception where the victim was vulnerable when making the payment and that vulnerability had a material impact on their ability to protect themselves from the scam. The claim record must therefore evidence both vulnerability and the required material impact.
Is the indirect access provider list part of the CDRS?
No. The IAP reporting is separate from the CDRS. IAPs must send the PSR a complete prior-calendar-year customer list by 31 March annually and must report changes monthly, with no submission required for a month in which there is no change. These reports go to the PSR rather than forming part of the Standard A data sent to Pay.UK.
Does Specific Direction 20 cover CHAPS payments?
No. SD20 and the Faster Payments CDRS govern Faster Payments. CHAPS reimbursement is governed separately by PSR Specific Direction 21, the Bank of England’s CHAPS reimbursement rules and the separate CHAPS reporting process. A PSP participating in both systems must assess and implement each reporting regime separately.
Related Articles
- UK Payments Initiative and the Open Banking CVRP Scheme – how the account-to-account payments agenda and commercial variable recurring payments interact with the UK retail payments landscape.
- PSD2 Reporting Requirements – the incident, fraud and operational reporting duties that already sit on UK payment and e-money firms.
- Verification of Payee for PSPs – the name-checking control that operates upstream of APP fraud as a prevention measure.
- FCA Financial Crime Speech and AML Reporting for UK Regulated Firms – the wider financial-crime supervisory context in which APP fraud sits.
- SEPA Instant Payments Regulation – the EU model built on mandatory reachability and payee verification, useful as a contrast with the UK reimbursement approach.
Key Takeaways
- Specific Direction 20 carries the APP scams reimbursement requirement and directs in-scope Faster Payments PSPs to comply with Pay.UK’s reimbursement rules; the operative detail lives in those rules and the CDRS, while the direction itself only points to them.
- The regime has applied since 7 October 2024. The maximum reimbursement is £85,000 per claim. A sending PSP must reimburse a reimbursable claim within five business days unless an SR1-permitted information-request pause applies, and the claim must be closed before the end of the 35th business day. A claim reported more than 13 months after the final in-scope payment need not be reimbursed. Receiving-PSP contributions are governed by SR1’s separate calculation and exclusions.
- The £100 excess and the consumer standard of caution exception are disapplied where the victim was vulnerable when making the payment and that vulnerability materially affected their ability to protect themselves from the scam.
- Reporting Standard A is the sending PSP’s monthly submission to Pay.UK, in place since 7 October 2024; the first return was due by 6 January 2025 covering 7 October to 30 November 2024.
- Reporting Standard B is the future comprehensive CDRS regime. As of July 2026 it has not been brought into force; Standard A remains the operative reporting regime.
- Pay.UK monitors and manages compliance using Standard A data and its compliance-monitoring regime. RCMS Core supports Standard A reporting, while full RCMS claims-management functionality is a separate product. The PSR retains statutory enforcement responsibility for SD20.
- Indirect access providers file a separate prior-calendar-year customer list to the PSR by 31 March annually and report changes monthly, with no monthly submission required where the list has not changed. This reporting is not part of the CDRS.
- SD20 and the CDRS apply to Faster Payments only; CHAPS reimbursement runs under the Bank of England’s separate rules and PSR Specific Direction 21.
Sources and References
- PSR, Specific Direction 20: FPS APP scam reimbursement requirement (made and amended 12 July 2024)
- PSR, Amended Specific Direction 20 (July 2024) PDF
- PSR, Amended Specific Requirement 1 (July 2024): FPS APP scam reimbursement rules PDF
- PSR, Specific Direction 18: Publication of APP scams information (revised December 2023)
- PSR, Specific Direction 19: APP scams Faster Payments Operator monitoring
- PSR, Specific Direction 21: CHAPS APP scam reimbursement requirement
- PSR, Faster Payments APP Scams Compliance Data Reporting Standard (CDRS), updated October 2024
- PSR, APP scams reimbursement: Deadlines for firms
- PSR, PS24/7 Faster Payments APP scams reimbursement requirement: Confirming the maximum level of reimbursement (October 2024)
- PSR, PS24/3 Faster Payments APP scams reimbursement: compliance and monitoring (July 2024)
- PSR, PS25/5 APP scams reimbursement requirement: consolidated policy statement (May 2025)
- PSR, The Consumer Standard of Caution Exception: guidance (December 2023)
- PSR, Updating our timings for the APP scams claims management consultation (Standard B timetable)
- Financial Services (Banking Reform) Act 2013, section 54 (PSR direction power)
- PSR, Specific directions (regulatory framework)
- Bank of England, CHAPS APP scam rules
Filing Specific Direction 20 as a reporting problem, not a policy problem
The fraud policy and the customer-facing promise get the headlines, but the durable work of Specific Direction 20 is reconciliation. A firm that reimburses correctly and reports incorrectly still fails Pay.UK’s monitoring, and a firm that treats the receiving side as out of scope has misread the shared-liability design that sits at the centre of the regime. A sound reporting-control framework maps the CDRS fields to source-system timestamps, documents the closure and vulnerability logic, and treats the monthly Standard A return as evidence supporting Pay.UK’s compliance monitoring and the PSR’s oversight.
Last updated: July 2026
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.