PSD3 and the Payment Services Regulation: What Changes for Verification
The EU's payment-law revision puts identity checks closer to the center of fraud prevention and liability. Its most concrete verification measure is an IBAN-to-name check designed to stop misdirected and impersonation-scam payments.

Published September 30, 2026. This is EU lawmaking, not a new US legal obligation. The legislative text and implementation timetable are still moving, so firms should distinguish the Commission proposals and negotiating drafts from final, applicable requirements.
The identity story is clearest in the proposed requirement to verify a payee's name against the account identifier, usually an International Bank Account Number, or IBAN, before a credit transfer is authorised. It is a practical intervention against authorized push-payment fraud, in which a victim is deceived into sending money to a fraudster.
PSD3 and the PSR are two instruments
“PSD3” is often used as shorthand for the entire revision of the EU payment-services framework. That is convenient, but inaccurate. The package has two proposed legal instruments with different jobs and different legal effects.
- The third Payment Services Directive, or PSD3, is a directive. EU countries must transpose it into national law. It principally addresses authorisation, prudential requirements and supervision of payment institutions, including firms that provide payment initiation or account-information services.
- The Payment Services Regulation, or PSR, is a regulation. Once applicable, its conduct rules apply directly across EU member states, subject to the final text and any implementing measures. It is the more important instrument for many day-to-day rules on payment execution, customer information, authentication and fraud.
- Reading a PSR conduct duty as though it were a PSD3 licensing requirement, or the reverse, can lead compliance teams to assign ownership to the wrong function.
The distinction also matters for multinational groups. A US company is not regulated merely because it is American or because it sells technology to a European bank. But payment service providers operating in the EU are in scope of the relevant rules. That can include a non-EU group serving EU customers through an EU-authorised bank, payment institution or other authorised entity. Geography of headquarters is not a reliable exemption.
IBAN name checks are the clearest identity change
The proposed payee-verification rule requires a payment service provider to check whether the name supplied by the payer corresponds with the name held for the destination payment account. Before the payer confirms the transfer, the provider must communicate a match result or warn of a mismatch. The aim is to give a customer a usable warning when the account details point somewhere other than the person or business they believe they are paying.
This is commonly described as an IBAN name check, although the legal and technical details matter. A result need not be a simple yes or no: a service may indicate a close match, a mismatch or that verification cannot be performed. Providers will need controls for name normalisation, joint accounts, trading names, transliteration, privacy and accessibility. A weak or ambiguous warning can be as consequential as no warning if a payer reasonably proceeds.
There is overlap with the EU Instant Payments Regulation, which already introduced verification-of-payee requirements for covered euro credit transfers on a phased timetable. The PSR revision should therefore be read alongside that regulation, rather than treated as the sole source of every IBAN-name-check obligation. The final scope, exceptions and liability consequences remain material points for firms to track.
Strong customer authentication remains, with calibrated friction
Strong customer authentication, or SCA, broadly carries forward from PSD2 into the revised framework with adjustments. SCA requires two or more independent elements drawn from knowledge, possession and inherence: for example, a passcode, a registered device and a biometric characteristic. It is often called two-factor authentication, though the legal test is more specific than a generic two-step login.
The exemption regime also remains central. Low-value payments, certain recurring transactions, trusted beneficiaries and transactions assessed as low risk through transaction-risk analysis can, under defined conditions, avoid a fresh SCA challenge. Exemptions do not eliminate the underlying fraud-control duty, and payment providers, not merchants alone, decide whether an exemption can safely be used.
For a merchant, an exemption can improve conversion by removing an extra authentication screen or banking-app approval at checkout. That reduces abandonment, particularly on mobile and repeat purchases. It is not a guarantee that a payment will be approved, nor a free pass on fraud: the issuer may still require SCA, and the merchant may bear commercial costs through declines, chargebacks or provider rules.
Verification becomes part of the liability position
The policy direction is to shift more of the loss from sophisticated scams and payment fraud toward providers that are better placed to prevent them. Proposed provisions on impersonation fraud, fraud-data sharing, authentication and payee verification make prevention controls relevant to whether a provider must reimburse a customer or can limit its exposure.
That does not mean every failed identity check automatically creates liability. Outcomes will depend on the final allocation rules, the facts of the scam, customer conduct, the warnings given and whether the provider met its authentication and monitoring duties. Still, the revision changes the internal framing of identity work. Account-name matching, device and behavioural signals, beneficiary controls and evidence of a clear warning are no longer only compliance overhead. They can determine a provider's fraud-loss position.
What payment firms should watch
Banks, payment institutions, electronic-money institutions and the technology suppliers supporting them should map obligations by instrument, product and EU entity. They should also avoid promising merchants that an SCA exemption or name-match result guarantees approval or removes liability. The practical test will be whether controls are accurate, understandable to customers and documented well enough to withstand a complaint, supervisory review or reimbursement dispute.


