This article describes Paynetics' implementation of the UK Payment Systems Regulator (PSR) APP Scam requirements for partners offering outbound GBP Faster Payments. Phase I focuses on payment pre-vetting using Confirmation of Payee (CoP) results.
Prerequisite: APP Scam Phase I is built entirely on top of the Confirmation of Payee (CoP) integration. You must have CoP implemented before rolling out APP Scam compliance. See Confirmation of Payee (UK).
What are APP Scam Regulations?
Authorised Push Payment (APP) scams occur when a person is tricked into authorising a bank transfer to a fraudster — for example, through impersonation of a bank, supplier, or romantic partner. The UK PSR has issued specific directions requiring payment service providers to:
- Apply additional warnings and acknowledgements before sending payments
- Pause or decline suspicious transactions
- Treat all customers as potentially vulnerable (Phase I)
- Reimburse victims of APP fraud (subject to eligibility)
How Phase I Works
Phase I logic is entirely UI/frontend-driven. The decision whether a payment proceeds or is blocked is based on the CoP check result and the end customer's actions within the app. Paynetics' backend does not yet make autonomous blocking decisions in Phase I.
Three flows are triggered based on the CoP response code:
1. Full Match Flow (CoP code: N/A)
The only flow where the end customer can proceed with the payment. Even in a full match, additional acknowledgements are required: - Confirm recipient (if new beneficiary) — customer confirms they know the recipient - Payment purpose (if new beneficiary) — customer selects from a list including: Friends & family, Cryptocurrency, Investments, Paying a business, Large purchase, Online purchase, Online dating, Unexpected request - Important: Online