Jan 2026 : APP fraud & reimbursement pressure

Picture of Zakir Karim

Zakir Karim

Inside this issue

January reinforces a simple message: regulators want firms to prove control, not just describe it. Safeguarding disruption, AI oversight, and open banking all point to higher expectations on governance, evidence, and customer outcomes. 

Supervision & safeguarding: FCA restrictions highlight how safeguarding disruptions and AML/control weaknesses can escalate quickly. 

Future focus areas: advanced AI and open banking/cVRPs progress, with pricing uncertainty under review.

APP fraud & reimbursement pressure

What Happened

In December, HM Treasury published an independent review of the Payment and Electronic Money Institution Insolvency Regulations 2021 (PESAR). The review concludes the regime is a meaningful step forward, but it’s not consistently delivering on what the reviewer describes as the core goal in real failures: Objective 3 (enabling a transfer/continuity outcome where that better protects customers), largely because delays and operational complexity still slow down outcomes for customers.

FAC Response:

On 17 December 2025 the FCA issued a First Supervisory Notice varying BeAccount’s authorisation under the EMRs by imposing immediate requirements, effectively stopping it from carrying out e-money/payment services without FCA consent (including onboarding new customers or accepting new relevant funds), requiring it to return relevant funds (subject to agreed timing), notify customers, publish prominent notices across channels (including a register link), confirm compliance, and preserve UK-held records.

Open banking pricing: regulators give “comfort” to keep commercial VRPs moving

In a joint January statement, the FCA and the Payment Systems Regulator gave clarity on how they are approaching open banking pricing models, particularly as the market develops commercial Variable Recurring Payments (cVRPs). The point wasn’t to set a permanent tariff, but to reduce uncertainty so the ecosystem can progress while regulators keep options open for the longer-term framework — effectively signalling “keep building” while competition and consumer outcomes remain in view.

Parliament pushes back on “wait and see” AI regulation

A UK Treasury Committee report warned that the current approach to AI in financial services risks serious consumer and system harm, calling for clearer guidance on how existing consumer protection rules apply to AI and what level of understanding senior managers should have over AI systems they oversee. The practical impact is less about new rules tomorrow and more about pressure to evidence accountability: model oversight, data traceability, control testing, and decision explainability, especially where AI influences customer outcomes like credit, fraud, onboarding, or pricing.

FCA review on advanced AI in retail finance

In late January, the FCA launched the Mills Review to examine how advanced AI (including more autonomous/agentic systems) could reshape retail financial services out to 2030 and beyond, covering impacts on firms/competition, consumer behaviour and expectations, and what regulators may need to change. The FCA is gathering stakeholder feedback (deadline 24 Feb 2026) and expects recommendations to the FCA Board in summer 2026, while reiterating it does not plan to introduce AI-specific rules (leaning instead on its principles-based framework, incl. Consumer Duty).

Our Thoughts

Show your workings is the new baseline: MI, testing evidence, and audit trails matter as much as policies. 

Safeguarding incidents escalate quickly: customer access issues can rapidly become a governance and control assessment. 

AI will be judged through outcomes: treat it as Consumer Duty + SM&CR accountability, even before AI-specific rules. 

Operational resilience is converging with conduct: incident readiness, customer comms, and remediation pace are becoming as important as the underlying controls.