Authorised push payment fraud — where you’re tricked into sending money to an account controlled by a fraudster — is the single biggest financial fraud threat to UK small businesses. We’re not talking about a new problem. But what is new is the regulatory regime around it, and many small business owners still don’t fully understand what they’re entitled to when things go wrong.
What APP Fraud Actually Is
You approve the payment. That’s what makes it “authorised.” The fraud happens before the payment, not at the point of the transaction. A supplier’s email account gets compromised, and the fraudster changes the bank details in an upcoming invoice. Or a convincing impersonation of your solicitor tells you to transfer client funds before a property purchase completes. Or your payroll manager receives what looks like a message from you asking for an urgent bank transfer.
The bank processed the payment correctly — the fraud was that you were deceived into authorising it. This is why, until relatively recently, banks often refused to reimburse victims: they argued the payment was authorised.
The PSR’s Mandatory Reimbursement Regime
The Payment Systems Regulator (PSR) introduced mandatory reimbursement requirements for APP fraud on Faster Payments in October 2024. The headline is that banks are required to reimburse victims of APP fraud, with a cap of £85,000 per claim. The paying bank and receiving bank share the cost 50/50, which aligns incentives for both ends to prevent fraud from arriving and from being sent.
Here’s where it gets more complicated for small businesses. The PSR rules distinguish between consumers and businesses. The full mandatory reimbursement protection applies primarily to personal accounts. For business accounts — which most small businesses use — the position depends on your bank’s published policy under the PSR framework. Some banks apply equivalent protections to small business accounts; others don’t.
Check your bank’s APP fraud policy for business accounts. This should be publicly available. If it’s not clear whether your account type is covered, call your business banking team directly and ask. Get the answer in writing.
What “Gross Negligence” Actually Means in Practice
Even where reimbursement applies, banks can decline claims if they determine you were “grossly negligent.” This sounds alarming but in practice the bar is high. Losing money because an email looked convincing is not gross negligence. Transferring money after ignoring multiple explicit fraud warnings from your bank is closer to gross negligence. The FOS (Financial Ombudsman Service) has published a series of determinations clarifying this standard, and the general direction is that banks can’t use gross negligence as a blanket excuse to refuse claims.
What does affect your claim: whether you acted on a “stop” or warning from your bank during the payment process, whether you verified bank detail changes through a genuinely independent channel before paying, and whether the amount was so unusual for your business that due diligence was obviously required.
The Claim Process
If you’ve been defrauded, call your bank’s fraud line immediately — the faster you report it, the higher the chance the receiving bank can freeze the funds before they’re moved on. Report to Action Fraud (actionfraud.police.uk) within 24 hours. Get a crime reference number.
Then make a formal written complaint to your bank, including the chronology of events, all evidence (emails, invoice copies, payment confirmations), and your claim for reimbursement. Banks are required to respond within 15 business days for standard cases, eight weeks at most. If they refuse and you disagree, escalate to the Financial Ombudsman Service (for business accounts with fewer than 10 employees and under £2m turnover, the FOS has jurisdiction).
Keep everything. The claim process is evidence-driven, and your ability to demonstrate the deception — not just the loss — is what matters.
Preventive Controls That Matter for the Claim
One of the things banks assess in APP fraud claims is whether you had reasonable controls in place. This is worth knowing before any fraud occurs, because it directly affects your position if you ever need to claim.
Calling to verify bank detail changes using a number you independently sourced (from the supplier’s website, a previous invoice, or your own records — not the number in the email asking you to change details) is the single most effective control. It’s also one the FOS and PSR treat as a basic reasonable precaution. If you didn’t do it and the amount was significant, that weakens your claim. If you did do it and were still defrauded (because the phone call itself was intercepted or the website was compromised), your position is much stronger.
Dual authorisation for payments above a threshold — requiring two people to approve before any transfer executes — is another control that both reduces your fraud risk and demonstrates reasonable diligence if you do need to claim.
If Your Bank’s Policy Doesn’t Cover You
Small businesses not covered by mandatory reimbursement still have options. The Consumer Rights Act doesn’t apply to business-to-business contracts, but if your bank can be shown to have been negligent — for example, in failing to act on fraud warnings from the receiving bank — you may have a legal claim. This is more complex to pursue but not impossible.
Cyber insurance policies often cover APP fraud losses. Check your policy or speak to your broker. Coverage varies enormously between policies; some exclude social engineering fraud, others cover it explicitly. If you don’t have cover for this, it’s worth reviewing at renewal.
The underlying message is that the PSR regime has improved the position for many fraud victims, but assuming you’re automatically covered without checking your specific account type and bank policy is a mistake. Check now, before you need to make a claim.