
A larger-than-usual wave of payment regulation is arriving. Here is what PSD3 and the UK reforms are, why the acronyms collide, and what they change for accounts payable.
UK finance teams are used to payment rules shifting, but the next wave is broader than most. Two parallel programmes are in motion: the European Union's third Payment Services Directive, PSD3, and its companion Payment Services Regulation, alongside the United Kingdom's own reform of its payments framework. They point in a similar direction, stronger fraud protection and wider data sharing, but they are separate regimes, and conflating them leads to bad planning.
Start with the acronyms, because they trip people up. In the EU, 'PSR' means the Payment Services Regulation, the directly applicable rulebook proposed alongside PSD3. In the UK, 'PSR' means the Payment Systems Regulator, the body overseeing payment systems. Same three letters, different things. When a vendor or article mentions 'the PSR', check which one they mean before you act on it.
What PSD3 and the EU Payment Services Regulation change
The EU proposals, published by the European Commission and working through the legislative process, tighten several things that matter to anyone paying suppliers across borders. They strengthen obligations around fraud, including wider use of payee verification akin to Confirmation of Payee, extend liability where verification fails, and push open banking towards a broader open finance model with more reliable data access. For a UK business with EU suppliers or EU operations, these rules will shape how your counterparties are paid and verified, even though they do not bind your UK entity directly.
The UK's own path
The UK is not adopting PSD3. After leaving the EU it is reforming its own Payment Services Regulations and setting direction through work such as the government's payments review and National Payments Vision, with the FCA and the Payment Systems Regulator leading delivery. The practical themes overlap with the EU: reducing authorised push payment fraud, expanding open banking towards open finance and smart data, and enabling Variable Recurring Payments for commercial use. The mandatory reimbursement rules for APP fraud, already in force, are the clearest sign of the UK's intent to put more responsibility on the payments industry to prevent fraud before it happens.
Timelines on both sides move, so treat any specific date as provisional and confirm the current position before committing a roadmap. The direction, though, is stable and worth planning around.
What this means for accounts payable
Three implications stand out. First, verification is becoming a regulatory expectation, not just good practice. The trend across both regimes is towards checking that you are paying the right party before money moves, which makes robust supplier verification a compliance asset rather than an overhead. Second, data access is widening. As open banking extends towards open finance, finance teams will be able to draw on richer, consented data about suppliers and payments, provided their systems can use it. Third, fraud liability is shifting towards prevention, so the controls you run at onboarding and before payment carry more weight than they used to.
The common thread is that the regulation rewards businesses that already know who their suppliers are and can see how payments actually behave. A connected accounts payable network is built around exactly that: verified counterparties and visible payment behaviour data, kept current rather than captured once. See how the network keeps supplier data verified as the rules tighten.
A practical stance for the next 18 months
You do not need to track every clause of every proposal. You need to be ready for the direction. Get your supplier master verified and deduplicated, make payment behaviour visible, and ensure your processes can evidence who you checked and when. Do that, and each regulatory change becomes a confirmation of work you have already done rather than a scramble to catch up. As ever, where a specific obligation could apply to your business, take regulated advice; this is an overview, not compliance guidance.
.jpg)