Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
The UK’s anti-fraud system is a stack of private controls, shared utilities, payment rules, digital-identity standards, regulators and law enforcement. No single database or identity check can stop a crime that may begin on a social platform, use stolen credentials, move through mule accounts and end overseas. UK Finance members reported £1.28 billion stolen through payment fraud in 2025, up 4%; authorised push payment fraud rose 19% to £576.4 million even as unauthorised losses declined. Banks prevented £1.68 billion of attempted unauthorised fraud. Since October 2024, in-scope Faster Payments and CHAPS APP claims have generally carried mandatory reimbursement up to £85,000, normally within five business days, with defined exceptions and an optional excess. By the end of 2025, 89%—£243 million—of loss in reimbursable claims under the new regime had been returned. Prevention includes Confirmation of Payee, behavioural and transaction analytics, sanctions and customer checks, Cifas’s National Fraud Database and money-mule tracing. The identity layer is changing too: Companies House verification became a legal requirement from 18 November 2025 with a 12-month transition, while the Data (Use and Access) Act 2025 placed a voluntary certified digital-verification market on a statutory footing. As of July 2026, OfDIA listed 46 providers offering 64 certified services. Better identity and data sharing can reduce fraud, but false positives, privacy, exclusion and liability must be designed into the system.

Fraud is a network business, so the defence must also be a network. A criminal can acquire identity data from a breach, contact a victim through telecoms or social media, open or take over accounts, persuade the victim to authorise a payment and disperse funds through mules before one institution sees the complete story. Authentication at login is only one control in that chain.

This guide maps the UK infrastructure from onboarding to recovery and explains which layers are compulsory, voluntary or still developing. It should be read with Kurums’ UK payment-rails guide, open-banking system map and regulatory perimeter. It is operational analysis, not legal advice on a particular case.

Editorial scope: This is business education, not personal financial, legal or investment advice. Rules, permissions and protection depend on the specific regulated entity and product.
Key Takeaways

Where does payment fraud begin?
Often outside finance: UK Finance said 66% of APP fraud in 2025 began online and another 17% through telecommunications.

What changed with APP reimbursement?
Sending and receiving payment firms now share stronger financial incentives to prevent and reimburse qualifying Faster Payments and CHAPS scams.

Is digital identity one national ID system?
No. The UK framework certifies voluntary digital-verification services against common rules and maintains a public register; it is an ecosystem, not one database.

The UK Fraud-Prevention and Response LoopIdentityVerify & authenticatePaymentWarn & monitorNetworkShare signalsResponseBlock & reimburseLearning from confirmed cases must feed back into onboarding and transaction controls without creating unchecked blacklists.
Learning from confirmed cases must feed back into onboarding and transaction controls without creating unchecked blacklists.

What belongs in the UK financial-crime infrastructure?

The stack begins inside each firm: customer due diligence, sanctions screening, device and behavioural signals, transaction monitoring, case management and suspicious-activity reporting. Shared services add account-name checks, fraud databases and network tracing. Payment-system rules allocate responsibilities, regulators supervise firms, and police and the National Crime Agency investigate and disrupt criminal networks.

Digital identity, company-register reform, telecoms and online-platform controls sit around that core. They determine whether an identity or business can be trusted before a payment firm sees a transaction. The system is fragmented by design because organisations hold different data and legal powers. The operating challenge is to connect signals fast enough while preserving purpose limitation, accuracy, redress and security.

How large is UK payment fraud?

UK Finance’s 2026 Annual Fraud Report recorded £1.28 billion stolen through payment fraud in 2025, 4% more than in 2024. Members prevented £1.68 billion of attempted unauthorised fraud—about 70p in every £1 of attempted loss. The data cover member-reported card, remote-banking, cheque and authorised-payment fraud, not every economic-crime loss in the country.

The mix matters more than the total. Unauthorised losses resumed a decline, while APP losses rose 19% to £576.4 million and cases rose 7%. Purchase, investment and romance scams reached record loss levels even as several impersonation and redirection categories improved. Criminals adapt to controls, shifting from credential theft toward manipulating a legitimate customer into passing authentication and sending the money.

What is the difference between unauthorised and APP fraud?

In unauthorised fraud, the customer did not consent to the transaction: stolen card details, account takeover or malware may be involved. In authorised push payment fraud, the payer authenticates the transfer but has been deceived about the recipient or purpose. Purchase, investment, romance, invoice and impersonation scams are common APP patterns.

The distinction affects evidence, liability and controls. Strong customer authentication can stop unauthorised access but may be satisfied in an APP scam because the victim genuinely performs the steps. APP defence therefore needs payee verification, contextual warnings, behavioural analytics, receiving-account controls and rapid fund tracing. A technically valid payment can still be economically fraudulent.

💡 Pro Tip: Do not treat successful authentication as proof of intent. In an APP scam, the legitimate customer may complete every security step under deception.

How does identity fraud become a financial account?

A criminal may use stolen identity attributes to apply for credit or open an account, combine real and fabricated data into a synthetic identity, or take over an existing account after compromising email, mobile or device credentials. First-party fraud is different again: the applicant uses their own identity but misrepresents intent or circumstances. Each pattern needs different evidence and response.

Cifas recorded more than 444,000 cases on its National Fraud Database in 2025, including more than 242,000 identity-fraud cases—54% of the total. That database reflects member filings under its standards, not a census of all UK crime. The scale shows why onboarding cannot depend on a photo document alone. Device, contact, account, history and network consistency help distinguish a real person from a safe transaction.

What do KYC, authentication and transaction monitoring each do?

Know-your-customer checks establish and verify identity, understand the relationship and assess risk at onboarding and through its life. Authentication tests whether the current user can access or approve an action. Transaction monitoring examines behaviour and money movement for risk. Passing one layer does not guarantee the next: a genuine, authenticated customer can still be coerced or deceived.

Effective firms connect the layers. A new device, changed contact detail, unusual payee, high-value transfer and inbound funds rapidly sent onward may be weak signals alone but strong together. Models must be supported by rules, investigation and feedback. Excessive alerts overwhelm analysts; overly narrow thresholds miss adaptive criminals. Governance should track detection, false positives, loss, customer friction and displaced fraud.

What is the UK digital-verification-services regime?

Part 2 of the Data (Use and Access) Act 2025 placed the digital-verification-services framework, public register and related oversight on a statutory footing from 1 December 2025. The Office for Digital Identities and Attributes maintains the trust framework. Independent, UKAS-accredited conformity assessment bodies certify services, and eligible providers apply to appear on the government register.

The framework covers governance, security, privacy, technical rules, user experience and inclusion. It does not make a service ‘government approved’ or eliminate a relying firm’s obligations. As of July 2026, the register listed 46 providers offering 64 certified services. Version 1.0 was published in June and was scheduled to take effect from 1 September 2026 or when accreditation readiness was met, whichever was later.

How can reusable digital identity change finance?

A digital-verification service can let a person prove identity or an attribute—such as age or right to work—without repeatedly sending full document copies. Standardised evidence and provenance can shorten onboarding, reduce manual error and make it harder to reuse altered documents. Holder and orchestration services can support credentials and routes among providers and relying organisations.

Reuse also concentrates consequences. A compromised credential or provider could affect several relationships, and an inaccurate attribute can propagate. Revocation, freshness, binding to the user, fraud reporting and recovery are therefore as important as initial proofing. The Act’s future information-sharing power can allow public authorities to provide information to registered services at an individual’s request, subject to commencement and safeguards.

What changed at Companies House?

Identity verification became a legal requirement from 18 November 2025 for new directors and people with significant control, with existing roles phased through a 12-month transition according to their due dates. Individuals can verify directly through GOV.UK One Login or through an Authorised Corporate Service Provider, then use a personal code for relevant company roles.

The reform improves confidence about who creates, runs and controls a company, but it is not a credit, solvency or honesty guarantee. A verified person can still submit misleading commercial information, use nominees or commit fraud after incorporation. Banks and fintechs should treat the register as stronger evidence within due diligence, not outsource beneficial-ownership and business-model assessment to Companies House.

How does Confirmation of Payee prevent misdirection?

Confirmation of Payee is an API-based account-name checking service for UK domestic payments. When a payer sets up or changes a payee, the sending provider can compare the entered name, account number, sort code and relevant secondary reference with the receiving provider’s records. The response can indicate a match, close match, no match or inability to check.

Pay.UK owns the service rules and standards. By mid-2025 it said almost 400 payment providers offered CoP, covering more than 99% of payments across Faster Payments, Bacs and CHAPS and processing more than 70 million checks a month. CoP reduces misdirected payments and some impersonation fraud, but a criminal can use an account whose real name fits the story. A match is assurance about account naming, not transaction legitimacy.

ℹ️ Context: Confirmation of Payee validates account-name data, not the underlying purchase, investment or relationship. It is one control, not a payment guarantee.

How do firms detect and disrupt money mules?

Mule accounts receive and move criminal proceeds, sometimes through customers who are recruited, coerced or unaware of the full scheme. Detection examines rapid pass-through, many unrelated counterparties, device or address links, newly opened accounts and behaviour inconsistent with stated purpose. Receiving firms matter because stopping the destination can protect many sending customers.

The FCA’s 2025 review examined the National Fraud Database and a commercially available money-mule account detection tool across 13 firms. It found positive investigation standards where firms filed to the NFD, but also inconsistent reporting, restrictions and response to alerts. A network tool does not replace case judgement. Firms need timely action, evidential standards, customer communication and review of accounts incorrectly restricted.

What is the Cifas National Fraud Database?

Cifas operates a cross-sector database holding fraud and money-mule records contributed by member organisations. Members include banks, card providers, insurers, telecoms, lenders, retailers and public bodies. A previous confirmed record can help an institution identify patterns that would be invisible in its own data and prevent repeated attacks.

Membership is voluntary and a filing can have serious consequences for access to services. Quality, proportionality and dispute routes are therefore fundamental. A database match should lead to investigation under the relevant standard, not an unexplained automatic conclusion. Firms should monitor submission accuracy, retention, access controls, false positives and whether frontline staff can explain and escalate outcomes.

How does mandatory APP reimbursement work?

From 7 October 2024, qualifying consumers, microenterprises and charities sending in-scope Faster Payments or CHAPS transfers received a mandatory reimbursement framework. Sending providers normally reimburse within five business days, with a stop-the-clock process in defined circumstances. The maximum is £85,000 per claim and a provider can apply an excess up to £100, subject to protections for vulnerable consumers.

Fraudulent claims and gross negligence under the consumer standard of caution are exceptions, and the scope does not cover every payment route, international transfer or civil dispute. Receiving providers generally share 50% of reimbursement cost, strengthening incentives on both ends. In the 15 months to December 2025, PSR data showed 89%—£243 million—of loss in reimbursable claims returned and 82% of claims closed within five business days.

Layer Primary function Important limitation
Digital identity / KYC Establish identity and attributes at onboarding A verified person or company can still act fraudulently
Confirmation of Payee Check account name before a UK payment A name match does not validate the economic purpose
NFD and mule analytics Share confirmed patterns and trace risky networks Evidence, accuracy, explanation and redress remain necessary
APP reimbursement Return qualifying losses and price prevention failures Scope, cap, exceptions and civil disputes require case assessment

How does reimbursement change product economics?

Before mandatory cost sharing, a receiving firm could benefit from fast payments while much of the scam loss and customer relationship sat with the sender. The new allocation puts a direct price on weak onboarding, mule detection and warning design. Payment firms must include reimbursement, operations and prevention investment in unit economics rather than treat fraud solely as a compliance expense.

Incentives can still misfire. Firms may reject more payments, close higher-risk customers or create generic warnings that transfer friction without improving decisions. They may dispute whether a claim is APP fraud or a civil disagreement. Metrics should therefore include prevented loss, reimbursement, rejection reasons, vulnerable-customer outcomes, complaint overturns and time to recover funds—not simply lower approval rates.

Why must online and telecom platforms be part of the system?

UK Finance said 66% of APP fraud in 2025 originated online and 17% through telecommunications. Criminals buy adverts, create marketplace listings, impersonate institutions, spoof calls and move victims into encrypted conversations before a bank sees a payee. Payment controls act late when the persuasion campaign has already established urgency and trust.

The government’s Fraud Strategy 2026–2029 calls for faster cross-sector data sharing, disruption of overseas networks and stronger obligations where fraud begins. The proposed Online Crime Centre and public-private work are intended to connect signals. Effective accountability needs common definitions and privacy-safe evidence: origin data should identify harmful accounts, adverts or numbers quickly enough to prevent reuse.

What does the ‘failure to prevent fraud’ offence change?

The Economic Crime and Corporate Transparency Act created a corporate offence for a large organisation that fails to prevent specified fraud by an associated person intending to benefit the organisation or, in some circumstances, its clients. The offence came into force on 1 September 2025. A relevant organisation can defend itself by showing reasonable fraud-prevention procedures or that it was reasonable to have none.

Government guidance centres on proportionate risk assessment, top-level commitment, due diligence, communication and training, monitoring and review. This is not limited to a company being the victim of fraud; it targets fraud committed for its benefit. Financial firms must connect product incentives, sales, agents, subsidiaries and third parties to their control framework rather than confine fraud to a loss-prevention team.

Where do privacy, exclusion and false-positive risks arise?

Fraud models process sensitive behavioural, device, identity and network data. More data can improve detection but also expand breach impact and function creep. Lawful basis, purpose, minimisation, retention, access and explanation matter. Shared intelligence can magnify an error across institutions, making correction and propagation of updates part of system design.

People without conventional documents, stable addresses, long credit histories or typical digital behaviour can face disproportionate friction. The OfDIA framework requires inclusion monitoring and encourages evidence options such as vouching. Firms should measure abandonment, manual-review availability and error by customer group. Security that excludes legitimate customers or provides no appeal is not a complete control.

⚠️ Risk: A shared fraud signal can propagate an error as efficiently as a correct match. Every networked control needs evidence thresholds, correction and a usable appeal route.

How should an operator assess the UK fraud stack?

Map controls to the attack journey: identity proofing, account security, payee confirmation, contextual warnings, transaction and network analytics, mule response, reimbursement, reporting and recovery. Assign ownership at each hand-off and test latency. A signal that arrives after funds have crossed several accounts may help investigation but cannot serve as real-time prevention.

Use balanced metrics: attempted and realised loss, prevented fraud, false positives, customer abandonment, alert productivity, funds recovered, reimbursement, complaints, time to decision, confirmed mule removal and repeat victimisation. Then examine partner and model governance. The strongest infrastructure learns across institutions while preserving evidence, privacy, inclusion and redress—turning every confirmed case into a safer next transaction.

Continue the country series: Explore the United Kingdom Finance & Fintech Hub, or compare the underlying concepts in the Fintech & Transfers Hub.

Frequently Asked Questions

What is authorised push payment fraud?

It occurs when a payer is deceived into authorising a transfer to a criminal or for a fraudulent purpose, even though the payment authentication is genuine.

Is every APP scam reimbursed up to £85,000?

No. The payment and claimant must be in scope, and exclusions, the consumer standard, time limits and case facts apply. Firms may reimburse above the cap voluntarily.

Does Confirmation of Payee prove a recipient is trustworthy?

No. It checks whether entered account-name information matches the receiving provider’s records; it does not verify the promised goods, investment or relationship.

Is the UK digital identity framework mandatory for everyone?

No. It creates a statutory regime and voluntary certification for digital-verification services. Specific sectors may separately require identity checks.

When did Companies House identity verification become compulsory?

The legal requirement began on 18 November 2025, with new appointments covered and existing directors and PSCs phased through a 12-month transition.

Primary Sources and Further Reading

This guide prioritises regulators, payment-system operators and company filings. Figures are the latest available at the July 2026 review date.

Last Updated: July 2026 · Reviewed by the Kurums Finance editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading