Search
Contact
Symbolbild zu
19.01.2026 | KPMG Law Insights

PSD3 and PSR: New payment regulation for payment service providers and banks

On April 23, 2026, the EU Parliament, Council and European Commission agreed on final versions of PSD3 (Payment Services Directive 3) and the PSR (Payment Services Regulation). This paves the way for a fundamental reform of European payments law.

For credit institutions, e-money institutions and payment service providers (PSPs), this means that they should review their compliance structures, contractual regulations and IT architecture at an early stage and adapt them where necessary.

The accompanying Open Finance Initiative (Financial Data Access, FIDA), which was initially launched in parallel, was largely “on hold”; however, following the recent resumption of compromise efforts in the Council, progress in negotiations can also be expected in this area in the near future.

An overview of the key changes according to the final drafts

Existing licenses: (Re-)authorization and grandfathering for existing institutions

Existing payment institutions and e-Money institutions must actively review their license and have them reconfirmed. In principle, there is an obligation to submit a (re)confirmation within the transitional periods provided for. 

However, automatic authorizations and register entries will be made as a rule. This requires evidence to be submitted to the supervisory authority that the institution also meets the stricter requirements (e.g. with regard to resolution plans, including ensuring outsourcing continuity).

Fraud prevention

The requirements for fraud prevention will be significantly expanded. Payment service providers must further develop their monitoring systems and explicitly use new technologies such as artificial intelligence, provided this is suitable for risk detection. At the same time, liability risks are increasing: Deficits in monitoring may lead to greater claims for reimbursement in future.

The exchange of data to combat fraud is made easier, but remains subject to strict data protection requirements, such as purpose limitation or data protection impact assessments.

Obligations to cooperate are also new: Providers of electronic communication services and very large online platforms or search engines must be more involved in fraud prevention.

A central instrument is the Verification of Payee. The content of this is being significantly sharpened:

  • Extension to all credit transfers, even outside SEPA,
  • Narrowly limited opt-out options in the B2B area,
  • clearly regulated liability and recourse relationships between the payment service providers involved.

Strong customer authentication

The specifications for strong customer authentication (SCA) will be further developed and harmonized.

What is new in this respect is a clear perspective of inclusion: payment service providers must offer suitable authentication solutions free of charge to user groups with special needs – for example, without a smartphone.

Another component is the mandatory authorization dashboard. Payment service providers must provide a central overview in their customer interface where users can manage the access they have granted to third-party providers – including transparency regarding the purpose, scope and duration of consent as well as clearly regulated revocation and logging functions.

The regulations also introduce new obligations and liability rules for technical service providers, particularly in the context of outsourcing. Liability risks are generally limited to direct damage. It remains unclear whether this will also apply in the case of European Digital Identity Wallets that are to be recognized as mandatory in the future and offered by the member states qualify as SCA under eIDAS.

Open Finance

Access to payment accounts and payment systems will be regulated more precisely. In future, account-holding institutions may only refuse or withdraw access for third-party providers under narrowly defined conditions, for example in the event of demonstrably “serious” risks – particularly in connection with money laundering prevention.

The aim is to create a level playing field between banks and non-bank payment service providers.

Originally, this regime was to be supplemented by the proposal for a Financial Data Access Framework (FiDA). As things stand, movement is expected in the trilogue negotiations from summer 2026.

Protection of customer funds

The requirements for safeguarding customer funds will be standardized and at the same time tightened. Particularly for E-money institutions, in future, a much stricter deadline for securing incoming funds will apply for the T+1 logic.

There are also new specific requirements for managing concentration risks, for example for custodians or hedging instruments. In addition, payment service providers will have to report significant changes to their hedging measures in advance.

The new framework also clarifies the handling of funds in connection with e-money token sand dovetails the requirements with the Markets in Crypto-Assets Regulation (MiCA).

Alignment with the MiCA framework

In order to avoid double regulation, the package contains specific delimitations to the MiCA Regulation. Payment service providers with PSD3 -MiCA license holders can provide certain crypto-related services in connection with e-money tokens without additionally requiring a separate MiCA license.

However, they must fulfill the corresponding notification and information obligations and comply with certain lead times.

Exemption regime

The existing exceptions will be revised and clarified.

One focus is on the Europe-wide harmonization of the commercial agent exemption, which has so far been interpreted differently.

The legislator also clarifies the conditions under which the “limited network” exemption applies. The aim is to reduce regulatory gray areas and sharpen the distinction between regulated and unregulated business models.

Background to the reform of payment law

PSD3 and PSR are intended to harmonize regulation

By transferring central behavior-related regulations to the PSR, the legislator is pursuing the goal of reducing national implementation leeway and thus regulatory fragmentation. This increases legal and planning certainty, but also leads to more uniform and stricter enforcement of the regulations with less room for national interpretation.

More security and fraud prevention

The new features place even greater emphasis on security and fraud prevention. Strong Customer Authentication (SCA), improved transaction monitoring and (re)introduction of the IBAN name matching are intended to reduce risks and strengthen trust in digital payments. The tightening of liability and reimbursement in cases of fraud is also operationally challenging: Similar to the UK and Singapore, PSPs will have to reimburse losses incurred by bank customers in certain constellations of fraud. At the same time, it will become easier – and in some cases mandatory – to exchange fraud data. There will be limited possibilities for recourse against telecommunications companies whose infrastructure has been used by fraudsters.

The regulatory framework for open banking is also being further developed. Dedicated, secure interfaces and clear rules on interface governance are intended to increase availability and quality; customers are to be given more transparency and control over data access, for example via authorization dashboards.

Strengthening consumer protection and transparency

The information obligations towards customers will be specified, in particular with regard to currency conversion fees and the blocking of funds. As a result, many institutions will have to revise the content and editing of their general terms and conditions, customer information and product-related documents.

How companies should prepare for PSD3 and the PSR

Credit institutions, payment institutions, e-money institutions and AIS/PIS providers should (have) an integrated legal and operational gap analysis carried out at an early stage so that the requirements of PSD3/PSR are translated into processes, controls, IT and contracts in a verifiable manner.

The most efficient approach is one in which legal departments and second-line managers work closely together and translate the regulatory interpretation directly into an actionable operating model – especially for GRC, third-party/outsourcing governance, contracting, SCA/fraud controls and API/interface governance.

 

 

We regularly work in close cooperation with the implementation experts at KPMG AG Wirtschaftsprüfungsgesellschaft, who deal with corresponding implementation issues here, among other things.

 

 

Explore #more

19.08.2026 | In the media

KPMG Law Interview in HAUFE: Even If AI Makes a Mistake, the Board of Directors Is Still Liable

AI analyzes, makes recommendations, and helps make decisions. But who bears the consequences if it makes a mistake? KPMG Law experts Vincent Manthey and Sabrina

19.08.2026 | In the media

KPMG Law Article in Bloomberg Tax: Germany’s Tax Crime Action Plan Pushes the Boundaries of the Constitution

The new 26-point action plan against tax and financial crime, issued by Germany’s finance and justice ministries, signals a shift toward tougher sanctions, closer interagency…

13.08.2026 | KPMG Law Insights

Federal Ministry of Finance Presents Draft Bill on Mandatory Use of Electronic Cash Registers and Combating Tax Evasion

In July 2026, the Federal Ministry of Finance (BMF) and the Federal Ministry of Justice (BMJV) presented an action plan to combat tax and financial

11.08.2026 | In the media

Guest article in *Versicherungsmonitor* on the topic of cyber claims regulation

Cyberattacks—particularly ransomware campaigns—pose challenges for insurers when it comes to claims settlement. When entire IT infrastructures at insured companies come to a standstill and the…

11.08.2026 | KPMG Law Insights

Transparency Requirements Under Article 50 of the AI Act: Companies Should Address These Questions Now

The transparency requirements of the EU AI Act have been in effect since August 2, 2026. These obligations apply to chatbots, AI assistants, avatars, synthetic…

10.08.2026 | In the media

Op-Ed on the Procurement Acceleration Act and Sustainable Public Procurement

On April 23, 2026, the Bundestag passed the Act on Accelerating the Award of Public Contracts. After the Act was published in the Federal Law…

05.08.2026 | Deal Notifications

KPMG Law and KPMG Advise NMP Germany on the Acquisition of Klöckner Desma Elastomertechnik GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised NMP Germany GmbH on the legal, tax, and financial aspects of the transaction…

04.08.2026 | In the media

Portrait of Mathias Oberndörfer in the *Börsen-Zeitung*

Mathias Oberndörfer has been with KPMG for more than 20 years—reason enough for an in-depth profile in the *Börsen-Zeitung*. The Börsen-Zeitung traces his career path…

03.08.2026 | Unkategorisiert

KPMG Law und KPMG beraten NMP Germany beim Erwerb der Klöckner Desma Elastomertechnik GmbH

Die KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) und die KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) haben die NMP Germany GmbH beim Erwerb der Klöckner Desma Elastomertechnik Gruppe…

03.08.2026 | In the media

Statement by KPMG Law experts on the EU Packaging Regulation in the business magazine *impulse*

Starting January 1, 2030, packaging must consist of at least 70 percent recyclable materials. Starting August 1, 2030, so-called “deceptive packaging” will also be banned.…

Contact

Marc Pussar

Partner

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49 69 951195-062
mpussar@kpmg-law.com

Jonas Sturies

Manager

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49 69 951195 199
jsturies@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll