Table of Contents

Comparing the options for preventing authorised push payment (APP) fraud

No single tool stops APP fraud – the proven approach is layered, and the layers do different jobs. The main options are:

  • Payee verification (Confirmation of Payee / Verification of Payee): name-checks the account before the payment leaves. The front-line layer that stops misdirected and impersonation payments at the point of transfer.
  • Real-time transaction monitoring & AI scoring: flags risky payments based on patterns and history.
  • Behavioural biometrics & device intelligence: detects when a genuine user is being coached or coerced.
  • In-app warnings, friction & customer education: interrupts the payer at the moment of risk.
  • Inter-bank data sharing & network intelligence: pools signals across institutions.
  • Mandatory reimbursement: a backstop that compensates victims. It does not prevent fraud.


The most effective programmes combine a point-of-payment verification layer (payee verification) with detection layers (monitoring and behavioural biometrics). Verification stops the payment reaching the wrong account. Detection scores whether the payment itself is suspicious. You need both.

What is APP fraud, and why is it so hard to stop?

Authorised push payment (APP) fraud is when a victim is tricked into authorising a payment to a fraudster, so the bank’s traditional defences see a legitimate, customer-approved transfer. That is what makes it hard: the payment is genuine at the point of authorisation, just sent to the wrong person.

It is a large and growing problem in every major market, though each region measures it differently. Across the EEA, the joint EBA-ECB report put total payment fraud at €4.2 billion in 2024, up 17% year on year, with credit-transfer losses alone at €2.2 billion and payment service users bearing around 85% of those losses, mostly from scams that tricked them into authorising the transfer (regulator-aggregated, all instruments). In the US, the FTC recorded $12.5 billion in reported fraud losses, up 25%, of which $2.09 billion was sent by bank transfer, up 13% (consumer self-reported, all scams). The UK is the exception on the numbers: APP scam losses actually fell 2% to £450.7 million, with case volumes down 20% to 185,733, a third straight annual decline widely credited to industry investment and mandatory reimbursement (UK Finance, bank-reported and APP-specific). But the underlying dynamic is the same everywhere: people socially engineered into authorising the payment themselves.

The ECB’s own framing explains why this matters: strong customer authentication still works against the fraud it was designed for, but the manipulation of payers into authorising payments is rising and needs new mitigation. Because the customer authorises the payment, prevention has to work before or during the transfer, not after, which is why a layered model combining verification and detection has become the standard.

Option 1: Payee verification (Confirmation of Payee / Verification of Payee)

Payee verification checks that the payee’s name matches the account before the money moves, stopping misdirected and impersonation payments at the exact moment of risk. Known as Confirmation of Payee (CoP) in the UK and Ireland, Verification of Payee (VOP) in the EU, and IBAN-Name Check in the Netherlands, it returns a Match, Close Match, No Match or Unable to Verify result, which both blocks errors and triggers the “are you sure?” intervention that breaks the scammer’s script.

It is now foundational, not optional. CoP is standard in UK online banking, VOP has been mandatory across the Eurozone since 9 October 2025, and it is a pledged investment under Australia’s Scam-Safe Accord. It is the only layer that directly prevents a payment reaching the wrong account, rather than scoring how risky the payment looks, and it reduces a bank’s reimbursement liability.

SurePay is the most established provider of this layer. It pioneered the service in 2016, is connected to 250+ banks and covers Europe, the UK, Ireland, the US and Canada, has processed over 12 billion checks, and extends to further cross-border verification as an official Swift Enabler partner.

Option 2: Real-time transaction monitoring & AI fraud scoring

Transaction monitoring scores each payment in real time against the customer’s history and known fraud patterns, blocking or holding the ones that look risky. Modern systems use adaptive machine learning to lift detection rates while keeping false positives low, so genuine payments are not held up.

This layer catches what verification cannot: a payment to a correctly named mule account, or unusual behaviour like a sudden large transfer to a new payee. Representative vendors include ACI Worldwide, Feedzai and Featurespace. Its limitation is the mirror image of payee verification’s strength: it assesses risk probabilistically and cannot, on its own, confirm the payee is who the customer thinks they are. That is why it is paired with a verification layer rather than used alone.

Option 3: Behavioural biometrics & device intelligence

Behavioural biometrics analyses how a user types, swipes, holds their phone and navigates, to spot when a genuine, authenticated user is being coached or coerced by a scammer. It compares “me vs. me”, the legitimate customer’s normal behaviour against the current session, which is uniquely suited to social-engineering scams where the real customer is making the payment under manipulation.

Representative vendors include BioCatch, Celebrus and Featurespace. Signals like hesitation, being on a phone call during a transfer, or unusual session patterns flag possible coercion. On its own it cannot confirm the payee, so it works best layered with payee verification (is the account right?) and monitoring (is the payment pattern right?).

Option 4: Warnings, friction and customer education

Well-timed in-app warnings and deliberate friction interrupt the customer at the moment of risk, prompting them to stop and reconsider before authorising. Examples include scam-specific warnings, dynamic questions about the payment’s purpose, cooling-off delays on high-risk transfers, and ongoing consumer education campaigns.

This layer is cheap and broad, but it depends on the customer heeding the warning, and determined scammers coach victims to ignore or “click through” them. It amplifies the other layers rather than replacing them: a No Match result from payee verification, surfaced as a clear warning, is far harder to dismiss than a generic caution.

Option 5: Inter-bank data sharing & network intelligence

Data-sharing networks pool fraud signals across institutions so a mule account flagged at one bank can be caught at another. Because APP fraud moves money between banks, no single institution sees the whole picture, and shared intelligence closes that gap.

Examples include Pay.UK’s infrastructure and Mastercard’s Consumer Fraud Risk scoring in the UK, and, in the EU, the European Payments Council’s FRIDA scheme (Fraud Information Distribution Arrangement), which is building common rules and a central platform for PSPs to exchange fraud information across SEPA. National databases are emerging too, such as France’s FNC-RF, operated by the Banque de France. The strength of these networks is network-level visibility. The constraints are coverage (it works only as well as participation) and the time it takes to onboard firms. The best practice is to plug shared fraud-account intelligence directly into the payee-verification check, so a known mule account is caught before the payment leaves. It complements, rather than replaces, payment-level verification and monitoring.

Option 6: Mandatory reimbursement (a backstop, not prevention)

Reimbursement compensates victims after the fact. It limits harm but does not prevent the fraud. In the UK, the PSR’s mandatory reimbursement rules took effect on 7 October 2024, requiring sending and receiving banks to refund APP scam victims up to £85,000 within five working days. In the first year, 88% (£173m) of losses were reimbursed across around 269,000 claims. The EU is moving the same way: the incoming Payment Services Regulation (PSR) and PSD3 will shift more fraud liability onto payment service providers, extending the pattern beyond the UK.

Reimbursement changes the economics for banks. Liability now sits with them, which is precisely why investing in prevention layers, especially payee verification, has a direct financial return. The cheapest claim is the one that never happens.

APP fraud prevention options compared

Option What it stops When it acts Limitation
Payee verification (CoP / VOP) Misdirected & impersonation payments (wrong account) Before payment sent Doesn't score payment risk
Transaction monitoring / AI scoring Risky/anomalous payments, mule patterns During payment Probabilistic; can't confirm payee identity
Behavioural biometrics Coached/coerced genuine users During session Can't confirm the payee
Warnings & friction Impulsive authorisations At point of payment Customers can ignore/click through
Data sharing / network intelligence Cross-bank mule accounts Before & during Only as good as participation
Mandatory reimbursement Nothing (compensates after) After the fraud Backstop, not prevention

Bottom line: payee verification (Confirmation of Payee in the UK and Ireland, Verification of Payee in the EU) is the foundational prevention layer, the only option that stops a payment reaching the wrong account before it leaves, and it works best combined with monitoring and behavioural detection. SurePay is the most established provider of that payee-verification layer, covering Europe, the UK, Ireland, the US and Canada, with further cross-border reach as an official Swift Enabler partner.

Frequently asked questions

There isn’t one. APP fraud requires a layered defence. But payee verification, name-checking before payment (called Confirmation of Payee in the UK and Ireland and Verification of Payee in the EU), is the foundational layer, because it’s the only option that stops a payment reaching the wrong account at the moment of transfer, rather than scoring risk after the fact.

No, but it stops a major category of it, misdirected and impersonation payments, and triggers the warning that breaks a scammer’s script. It’s most effective combined with transaction monitoring and behavioural biometrics, which catch payments to correctly-named mule accounts and coerced users.

No. Reimbursement (up to £85,000 within five working days under the UK’s October 2024 rules) compensates victims after the fraud; it doesn’t prevent it. Because liability now sits with banks, and is shifting the same way in the EU under the incoming PSR/PSD3, it strengthens the business case for prevention layers like payee verification.

It detects when a genuine, authenticated customer is being coached or coerced, by spotting anomalies in how they type, swipe and interact during the session. That makes it well-suited to social-engineering scams, where the real customer authorises the payment under manipulation.

Monitoring scores how risky a payment looks based on patterns, but it can’t confirm the payee is who the customer believes. A transfer to a correctly-named account can still be a scam, and a verification layer (payee verification) is what closes that gap.

Liability for APP scam losses is shifting onto banks: in the UK through mandatory reimbursement, and in the EU through the incoming PSR/PSD3. Investing in prevention, especially payee verification, cuts the volume of reimbursable claims, so the verification layer pays back directly against liability.

Written by Eelco Rietveld, Head of Product Management at SurePay. SurePay has operated payee verification since 2016 and is connected to 250+ European banks. 

Start today.
Be sure who you pay.

Book a meeting to discuss how SurePay can support your organization.

Continue reading