PSD3 and PSR: Navigating the Future of European Payments Regulation

[[Translate to
[[Translate to "English"]]
  • 09/29/2026
  • Reading time 6 Minutes

The next wave of EU payments regulation is taking shape. Here is what financial institutions need to know - and do - now.

The Third Payment Services Directive (PSD3) and Payment Services Regulation (PSR) build on PSD2 but materially sharpen existing requirements. For institutions, this is not a wholesale regulatory reset; it is a logical evolution. Many elements - including strong customer authentication (SCA) and third-party interfaces (APIs) - are already established. 

The real challenge lies in the level of detail. Whereas PSD2 required SCA only in general terms, PSR will specify which account actions trigger it - such as logging in, setting up a new payee or changing a device. 

Directive and Regulation: The New Regulatory Framework 

The reform has two components. PSD3 will be transposed into national law as a directive and will govern institutional aspects of licensing, authorisation and supervision. It will repeal and replace the existing E-Money Directive (EMD2), consolidating its provisions into the new framework: e-money institutions will become a subcategory of payment institutions and must reapply for authorisation under stricter requirements for own funds and outsourcing management. 

PSR, by contrast, will be directly applicable as an EU regulation and uniform across all Member States. It contains core operational requirements, including fraud-prevention measures: the recipient’s name must be checked against the IBAN before each transfer. 

This combination has practical consequences for institutions. While directives leave room for national transposition, PSR creates uniform and directly binding requirements in many areas. Banks and payment service providers can therefore plan for PSR now - for example, by preparing technical measures for IBAN/name matching and adapting SCA processes to the new, broader trigger events. 

Regulatory Timeline: When Will PSD3 Enter into Force? 

PSD1 entered into force in 2007, followed by PSD2 in 2016. The final drafts of PSD3 and PSR, representing the Directive’s third version and further development, were published in April 2026. Formal adoption is expected in late 2026. The texts will then be published in the Official Journal of the EU and will enter into force 20 days after publication. The new framework is therefore likely to apply in the first half of 2028 (H1 2028), depending on formal adoption and publication in the Official Journal. 

PSD3 and PSR are in the final stages of the legislative process, awaiting formal adoption by the Council and Parliament, but institutions should not wait for the process to conclude. Otherwise, the lead time for the substantial infrastructure changes required will be too short. 

From PSD2 to PSD3/PSR: What’s New for Financial Services Providers? 

Fraud prevention is a major focus of the new requirements. Alongside traditional payment fraud, the scope will now expressly include social engineering, identity fraud and authorised push payment (APP) fraud. 

Fraud Prevention 

In these cases, the customer authorises the payment but is induced to do so by deception. Fraud-monitoring systems must therefore evolve, including through the use of new technologies such as artificial intelligence (AI) where suitable for risk detection. Liability will shift to institutions that fail to discharge their warning and verification duties properly - for example, by failing to complete the recipient check - when a transfer has been induced through social engineering. 

Strong Customer Authentication (SCA) 

SCA will remain a central focus. The core concept is preserved but tightened. PSD3/PSR raise the bar for both security and user-friendliness and require more accessible procedures. 

Payment service providers will therefore have to offer customer groups with particular needs - such as customers without a smartphone - other suitable authentication options free of charge. Institutions should revisit existing authentication journeys with both the customer experience and the range of available solutions in mind. 

Consent and Access Management Dashboard 

In open banking, the performance and standardisation of interfaces will become even more important. The framework will also require customer-friendly consent and access management. Institutions will have to provide a central permissions dashboard showing customers, at a glance, which third parties have access - and what access each has been granted - while allowing them to revoke individual permissions at any time. 

Verification of Payee 

Another implementation driver is Verification of Payee. Before certain payments are executed, the system must check whether the recipient’s name matches the IBAN. Since October 2025, the Instant Payments Regulation has made this mandatory only for instant euro payments. The PSR will extend the requirement to practically all transfers - without limiting it to instant payments and including transfers outside the euro area and outside the Single Euro Payments Area (SEPA). 

For consumers, this should reduce misdirected payments and improve the chances of detecting fraud. For institutions, it will require further development, particularly of payment systems and customer interfaces. 

Where Are Banks Most Affected? 

Banks wear several hats in payments: they act as account-servicing payment service providers (ASPSPs), API operators and payment initiators at the same time. The key question is therefore how extensively existing PSD2 processes - particularly fraud management and SCA - must be adapted to the new PSD3 and PSR requirements. 

The analysis should not stop there. PSD3/PSR intersect with a range of other regimes - from the Digital Operational Resilience Act (DORA) and the General Data Protection Regulation (GDPR) to MaRisk (Minimum Requirements for Risk Management) and the future Financial Data Access Regulation (FiDA). Banks should therefore take an integrated approach to data management and digital compliance. This is also an opportunity to consolidate compliance efforts and streamline processes, rather than launch multiple parallel implementation projects. 

The period between publication and application is likely to be relatively short. Where IT systems and customer interfaces are affected, an early impact assessment will help institutions manage implementation effort later. 

Our Recommendation: From Assessment and Gap Analysis to a Roadmap 

The Baker Tilly Financial Services Team helps financial institutions assess the impact of PSD3 and PSR early, identify required actions through a preliminary assessment and conduct a regulatory gap analysis. 

We review existing fraud-detection processes, authentication methods and related controls, then turn the findings into a prioritised implementation roadmap. 

Our interdisciplinary team combines regulatory, IT and digital expertise to translate legal requirements into workable technical changes and embed them in existing structures, linking regulatory certainty with operational efficiency. 

Conclusion: PSD3/PSR as the Framework for Robust Payment Processes 

At its core, PSD3/PSR builds on PSD2 and represents a logical evolution of payment services regulation. That is precisely why institutions should not underestimate the framework. 

Institutions that establish early clarity on their exposure and required changes can implement PSD3 and PSR with regulatory certainty while using the transition to unlock operational efficiency gains in fraud detection and payments.