Auditors ✓ Lawyers ✓ Tax advisors ✓ and business consultants ✓ : Four perspectives. One solution. Worldwide. Learn …
Auditing and audit-related advice for companies ✓ Experienced auditors ✓ Excellent advice ✓ Tailor-made solutions » …
Our clients entrust us with their most important legal matters. Learn more about our legal services!
Tax laws are complex and dynamic. We face the challenge of tax law together with you - find out more.
Business consulting for companies ✓ Experienced consultants ✓ Excellent advice ✓ Tailor-made solutions » more
Germany’s KRITISDachG Now in Force, Implementing Regulations Still Pending: What Operators Need to Know
Bafin Publishes WpI MaRisk: New Supervisory Framework for Small and Medium Investment Firms
No Unlimited Right to Disclosure: Employer’s Information Claims in Default-of-Acceptance Wage Disputes
EmpCo Directive: New Requirements for Environmental Claims Apply from September
Baker Tilly Advises SEVEST on Acquisition of Majority Stake in IBG HydroTech
E-Invoicing in Germany: Countdown to January 2027
Baker Tilly Strengthens Mid-Market Tax Advisory with Markus Krinninger
ICT risks when using AI: New BaFin guidance
One year of DORA: What's next for financial companies
Survey: Two thirds of German automotive suppliers anticipate a market shakeout
Cross-industry expertise for individual solutions ✓ Our interdisciplinary teams combine expertise & market …
Baker Tilly advises CERTANIA on the Acquisition of InnoDiab
New SGEI Decision: Key Changes at a Glance
SGEI Decision: New Funding Opportunities for Affordable Housing
Risk management ✓ Compliance and controls ✓ Increase and ensure security & conformity ✓ more»
Baker Tilly offers a wide range of individual and innovative consulting services. Find out more!
The next wave of EU payments regulation is taking shape. Here is what financial institutions need to know - and do - now.
The Third Payment Services Directive (PSD3) and Payment Services Regulation (PSR) build on PSD2 but materially sharpen existing requirements. For institutions, this is not a wholesale regulatory reset; it is a logical evolution. Many elements - including strong customer authentication (SCA) and third-party interfaces (APIs) - are already established.
The real challenge lies in the level of detail. Whereas PSD2 required SCA only in general terms, PSR will specify which account actions trigger it - such as logging in, setting up a new payee or changing a device.
The reform has two components. PSD3 will be transposed into national law as a directive and will govern institutional aspects of licensing, authorisation and supervision. It will repeal and replace the existing E-Money Directive (EMD2), consolidating its provisions into the new framework: e-money institutions will become a subcategory of payment institutions and must reapply for authorisation under stricter requirements for own funds and outsourcing management.
PSR, by contrast, will be directly applicable as an EU regulation and uniform across all Member States. It contains core operational requirements, including fraud-prevention measures: the recipient’s name must be checked against the IBAN before each transfer.
This combination has practical consequences for institutions. While directives leave room for national transposition, PSR creates uniform and directly binding requirements in many areas. Banks and payment service providers can therefore plan for PSR now - for example, by preparing technical measures for IBAN/name matching and adapting SCA processes to the new, broader trigger events.
PSD1 entered into force in 2007, followed by PSD2 in 2016. The final drafts of PSD3 and PSR, representing the Directive’s third version and further development, were published in April 2026. Formal adoption is expected in late 2026. The texts will then be published in the Official Journal of the EU and will enter into force 20 days after publication. The new framework is therefore likely to apply in the first half of 2028 (H1 2028), depending on formal adoption and publication in the Official Journal.
PSD3 and PSR are in the final stages of the legislative process, awaiting formal adoption by the Council and Parliament, but institutions should not wait for the process to conclude. Otherwise, the lead time for the substantial infrastructure changes required will be too short.
Fraud prevention is a major focus of the new requirements. Alongside traditional payment fraud, the scope will now expressly include social engineering, identity fraud and authorised push payment (APP) fraud.
In these cases, the customer authorises the payment but is induced to do so by deception. Fraud-monitoring systems must therefore evolve, including through the use of new technologies such as artificial intelligence (AI) where suitable for risk detection. Liability will shift to institutions that fail to discharge their warning and verification duties properly - for example, by failing to complete the recipient check - when a transfer has been induced through social engineering.
SCA will remain a central focus. The core concept is preserved but tightened. PSD3/PSR raise the bar for both security and user-friendliness and require more accessible procedures.
Payment service providers will therefore have to offer customer groups with particular needs - such as customers without a smartphone - other suitable authentication options free of charge. Institutions should revisit existing authentication journeys with both the customer experience and the range of available solutions in mind.
In open banking, the performance and standardisation of interfaces will become even more important. The framework will also require customer-friendly consent and access management. Institutions will have to provide a central permissions dashboard showing customers, at a glance, which third parties have access - and what access each has been granted - while allowing them to revoke individual permissions at any time.
Another implementation driver is Verification of Payee. Before certain payments are executed, the system must check whether the recipient’s name matches the IBAN. Since October 2025, the Instant Payments Regulation has made this mandatory only for instant euro payments. The PSR will extend the requirement to practically all transfers - without limiting it to instant payments and including transfers outside the euro area and outside the Single Euro Payments Area (SEPA).
For consumers, this should reduce misdirected payments and improve the chances of detecting fraud. For institutions, it will require further development, particularly of payment systems and customer interfaces.
Banks wear several hats in payments: they act as account-servicing payment service providers (ASPSPs), API operators and payment initiators at the same time. The key question is therefore how extensively existing PSD2 processes - particularly fraud management and SCA - must be adapted to the new PSD3 and PSR requirements.
The analysis should not stop there. PSD3/PSR intersect with a range of other regimes - from the Digital Operational Resilience Act (DORA) and the General Data Protection Regulation (GDPR) to MaRisk (Minimum Requirements for Risk Management) and the future Financial Data Access Regulation (FiDA). Banks should therefore take an integrated approach to data management and digital compliance. This is also an opportunity to consolidate compliance efforts and streamline processes, rather than launch multiple parallel implementation projects.
The period between publication and application is likely to be relatively short. Where IT systems and customer interfaces are affected, an early impact assessment will help institutions manage implementation effort later.
The Baker Tilly Financial Services Team helps financial institutions assess the impact of PSD3 and PSR early, identify required actions through a preliminary assessment and conduct a regulatory gap analysis.
We review existing fraud-detection processes, authentication methods and related controls, then turn the findings into a prioritised implementation roadmap.
Our interdisciplinary team combines regulatory, IT and digital expertise to translate legal requirements into workable technical changes and embed them in existing structures, linking regulatory certainty with operational efficiency.
At its core, PSD3/PSR builds on PSD2 and represents a logical evolution of payment services regulation. That is precisely why institutions should not underestimate the framework.
Institutions that establish early clarity on their exposure and required changes can implement PSD3 and PSR with regulatory certainty while using the transition to unlock operational efficiency gains in fraud detection and payments.
Simone Yuson
Director
Talk to us. Simply without obligation
Get in touch
View all news