Sharing fraud intelligence under the Payment Services Regulation: mind the gap
The EU Payment Services Regulation (PSR) represents a significant improvement in the EU’s response to payment fraud. It moves beyond a model centred mainly on identity and controls on individual payment service providers (PSPs), and recognises that modern fraud prevention requires shared intelligence.
Even so, the PSR leaves two major implementation problems unresolved. The first is internal to the payment sector. The second problem concerns the wider fraud chain.
This analysis argues against both fragmentation and centralisation. The EU does not need a single, mandatory fraud database. It needs interoperability by design, which would entail the following:
- common operational requirements for PSP-to-PSP information sharing;
- a federated FRIDA (fraud information) layer, led by the European Payments Council, to connect national, private and sectoral arrangements across SEPA and EPC payment schemes;
- model protocols for cooperation with non-PSP actors; and
- a first PSR review focused on whether the framework has produced a genuinely interoperable ecosystem of fraud intelligence.
The central claim is that the PSR has opened the legal gateways for fraud intelligence to flow. But its success will depend on whether implementation turns those gateways into a connected, operationally usable and preventive network.
Judith Arnal is Associate Senior Research Fellow at ECRI and CEPS. The author would like to thank Mathilde Bonneau and Iván Burillo for helpful comments to a previous draft.

