Search
Contact
Symbolbild zu
19.01.2026 | KPMG Law Insights

PSD3 and PSR: New payment regulation for payment service providers and banks

On April 23, 2026, the EU Parliament, Council and European Commission agreed on final versions of PSD3 (Payment Services Directive 3) and the PSR (Payment Services Regulation). This paves the way for a fundamental reform of European payments law.

For credit institutions, e-money institutions and payment service providers (PSPs), this means that they should review their compliance structures, contractual regulations and IT architecture at an early stage and adapt them where necessary.

The accompanying Open Finance Initiative (Financial Data Access, FIDA), which was initially launched in parallel, was largely “on hold”; however, following the recent resumption of compromise efforts in the Council, progress in negotiations can also be expected in this area in the near future.

An overview of the key changes according to the final drafts

Existing licenses: (Re-)authorization and grandfathering for existing institutions

Existing payment institutions and e-Money institutions must actively review their license and have them reconfirmed. In principle, there is an obligation to submit a (re)confirmation within the transitional periods provided for. 

However, automatic authorizations and register entries will be made as a rule. This requires evidence to be submitted to the supervisory authority that the institution also meets the stricter requirements (e.g. with regard to resolution plans, including ensuring outsourcing continuity).

Fraud prevention

The requirements for fraud prevention will be significantly expanded. Payment service providers must further develop their monitoring systems and explicitly use new technologies such as artificial intelligence, provided this is suitable for risk detection. At the same time, liability risks are increasing: Deficits in monitoring may lead to greater claims for reimbursement in future.

The exchange of data to combat fraud is made easier, but remains subject to strict data protection requirements, such as purpose limitation or data protection impact assessments.

Obligations to cooperate are also new: Providers of electronic communication services and very large online platforms or search engines must be more involved in fraud prevention.

A central instrument is the Verification of Payee. The content of this is being significantly sharpened:

  • Extension to all credit transfers, even outside SEPA,
  • Narrowly limited opt-out options in the B2B area,
  • clearly regulated liability and recourse relationships between the payment service providers involved.

Strong customer authentication

The specifications for strong customer authentication (SCA) will be further developed and harmonized.

What is new in this respect is a clear perspective of inclusion: payment service providers must offer suitable authentication solutions free of charge to user groups with special needs – for example, without a smartphone.

Another component is the mandatory authorization dashboard. Payment service providers must provide a central overview in their customer interface where users can manage the access they have granted to third-party providers – including transparency regarding the purpose, scope and duration of consent as well as clearly regulated revocation and logging functions.

The regulations also introduce new obligations and liability rules for technical service providers, particularly in the context of outsourcing. Liability risks are generally limited to direct damage. It remains unclear whether this will also apply in the case of European Digital Identity Wallets that are to be recognized as mandatory in the future and offered by the member states qualify as SCA under eIDAS.

Open Finance

Access to payment accounts and payment systems will be regulated more precisely. In future, account-holding institutions may only refuse or withdraw access for third-party providers under narrowly defined conditions, for example in the event of demonstrably “serious” risks – particularly in connection with money laundering prevention.

The aim is to create a level playing field between banks and non-bank payment service providers.

Originally, this regime was to be supplemented by the proposal for a Financial Data Access Framework (FiDA). As things stand, movement is expected in the trilogue negotiations from summer 2026.

Protection of customer funds

The requirements for safeguarding customer funds will be standardized and at the same time tightened. Particularly for E-money institutions, in future, a much stricter deadline for securing incoming funds will apply for the T+1 logic.

There are also new specific requirements for managing concentration risks, for example for custodians or hedging instruments. In addition, payment service providers will have to report significant changes to their hedging measures in advance.

The new framework also clarifies the handling of funds in connection with e-money token sand dovetails the requirements with the Markets in Crypto-Assets Regulation (MiCA).

Alignment with the MiCA framework

In order to avoid double regulation, the package contains specific delimitations to the MiCA Regulation. Payment service providers with PSD3 -MiCA license holders can provide certain crypto-related services in connection with e-money tokens without additionally requiring a separate MiCA license.

However, they must fulfill the corresponding notification and information obligations and comply with certain lead times.

Exemption regime

The existing exceptions will be revised and clarified.

One focus is on the Europe-wide harmonization of the commercial agent exemption, which has so far been interpreted differently.

The legislator also clarifies the conditions under which the “limited network” exemption applies. The aim is to reduce regulatory gray areas and sharpen the distinction between regulated and unregulated business models.

Background to the reform of payment law

PSD3 and PSR are intended to harmonize regulation

By transferring central behavior-related regulations to the PSR, the legislator is pursuing the goal of reducing national implementation leeway and thus regulatory fragmentation. This increases legal and planning certainty, but also leads to more uniform and stricter enforcement of the regulations with less room for national interpretation.

More security and fraud prevention

The new features place even greater emphasis on security and fraud prevention. Strong Customer Authentication (SCA), improved transaction monitoring and (re)introduction of the IBAN name matching are intended to reduce risks and strengthen trust in digital payments. The tightening of liability and reimbursement in cases of fraud is also operationally challenging: Similar to the UK and Singapore, PSPs will have to reimburse losses incurred by bank customers in certain constellations of fraud. At the same time, it will become easier – and in some cases mandatory – to exchange fraud data. There will be limited possibilities for recourse against telecommunications companies whose infrastructure has been used by fraudsters.

The regulatory framework for open banking is also being further developed. Dedicated, secure interfaces and clear rules on interface governance are intended to increase availability and quality; customers are to be given more transparency and control over data access, for example via authorization dashboards.

Strengthening consumer protection and transparency

The information obligations towards customers will be specified, in particular with regard to currency conversion fees and the blocking of funds. As a result, many institutions will have to revise the content and editing of their general terms and conditions, customer information and product-related documents.

How companies should prepare for PSD3 and the PSR

Credit institutions, payment institutions, e-money institutions and AIS/PIS providers should (have) an integrated legal and operational gap analysis carried out at an early stage so that the requirements of PSD3/PSR are translated into processes, controls, IT and contracts in a verifiable manner.

The most efficient approach is one in which legal departments and second-line managers work closely together and translate the regulatory interpretation directly into an actionable operating model – especially for GRC, third-party/outsourcing governance, contracting, SCA/fraud controls and API/interface governance.

 

 

We regularly work in close cooperation with the implementation experts at KPMG AG Wirtschaftsprüfungsgesellschaft, who deal with corresponding implementation issues here, among other things.

 

 

Explore #more

11.09.2026 | KPMG Law Insights

The Procurement Acceleration Act and Sustainable Procurement: What Is Permitted and What Is Required?

The Public Procurement Acceleration Act took effect on July 1, 2026. The Act implements the reform of public procurement law that has been under discussion…

08.09.2026 | Deal Notifications

KPMG Law advises the shareholders and management of KODIAK on the sale of shares and the strategic partnership with Bencis

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) advised the shareholders and management of KODIAK GmbH (KODIAK) on the sale of shares to Bencis and the establishment…

07.09.2026 | In the media

KPMG Law advises Bosch Rexroth on the sale of its Active Shuttle product business to Neura Robotics

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) has provided legal counsel to Bosch Rexroth AG (Bosch Rexroth) in the sale of its product business related to…

31.08.2026 | In the media

Op-Ed in the Börsen-Zeitung – Interim Assessment of the European Crypto Regulation MiCAR

A year and a half after MiCAR took effect, it is clear that, despite European guidelines, there are still misunderstandings regarding the requirements. KPMG Law…

19.08.2026 | In the media

KPMG Law Interview in HAUFE: Even If AI Makes a Mistake, the Board of Directors Is Still Liable

AI analyzes, makes recommendations, and helps make decisions. But who bears the consequences if it makes a mistake? KPMG Law experts Vincent Manthey and Sabrina

19.08.2026 | In the media

KPMG Law Article in Bloomberg Tax: Germany’s Tax Crime Action Plan Pushes the Boundaries of the Constitution

The new 26-point action plan against tax and financial crime, issued by Germany’s finance and justice ministries, signals a shift toward tougher sanctions, closer interagency…

13.08.2026 | KPMG Law Insights

Federal Ministry of Finance Presents Draft Bill on Mandatory Use of Electronic Cash Registers and Combating Tax Evasion

In July 2026, the Federal Ministry of Finance (BMF) and the Federal Ministry of Justice (BMJV) presented an action plan to combat tax and financial

11.08.2026 | In the media

Guest article in *Versicherungsmonitor* on the topic of cyber claims regulation

Cyberattacks—particularly ransomware campaigns—pose challenges for insurers when it comes to claims settlement. When entire IT infrastructures at insured companies come to a standstill and the…

11.08.2026 | KPMG Law Insights

Transparency Requirements Under Article 50 of the AI Act: Companies Should Address These Questions Now

The transparency requirements of the EU AI Act have been in effect since August 2, 2026. These obligations apply to chatbots, AI assistants, avatars, synthetic…

10.08.2026 | In the media

Op-Ed on the Procurement Acceleration Act and Sustainable Public Procurement

On April 23, 2026, the Bundestag passed the Act on Accelerating the Award of Public Contracts. After the Act was published in the Federal Law…

Contact

Marc Pussar

Partner

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49 69 951195-062
mpussar@kpmg-law.com

Jonas Sturies

Manager

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49 69 951195 199
jsturies@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll