United Kingdom flagIndependent UK business banking research
UK Business Banking Research · BanksGB
Business typesCards & expensesCash flowSecurityDigital bankingMerchant servicesFX & tradeInsightsAll topics
BanksGB · Security

Unauthorised business payments: when the bank transfer or card payment was not yours

A practical UK guide to unauthorised business payments covering Payment Services Regulations, refund timing, evidence, reporting deadlines, gross negligence and larger corporate terms.

An unauthorised payment is different from an APP scam. In an APP scam, an authorised person is deceived into sending the money. In an unauthorised-payment case, the business says it never consented to the transaction at all. That distinction changes the legal starting point and the evidence the bank needs to examine.

Separate a payment you did not authorise from a payment you were tricked into making

The Financial Ombudsman distinguishes unauthorised transactions from authorised push payment fraud. If a criminal steals online-banking credentials and sends a transfer without the company's consent, that is an unauthorised-payment issue. If a finance employee is deceived by a fake supplier email but personally approves the transfer, the payment was authorised even though it was induced by fraud.

This distinction matters because different reimbursement rules can apply. Start the incident file by recording who approved the payment, what authentication was used and whether any authorised user actually intended the transaction. Do not describe every fraud loss simply as "unauthorised" if an employee genuinely clicked approve.

The Payment Services Regulations set a strong starting point for unauthorised transactions

Regulation 76 of the Payment Services Regulations 2017 says that, subject to the surrounding rules, a payment service provider must refund an unauthorised transaction and restore the payment account to the position it would have been in if the transaction had not occurred. The regulation also says the refund should normally be made as soon as practicable and no later than the end of the following business day after the provider becomes aware of the unauthorised transaction.

There are exceptions and evidential issues. For example, the next-business-day refund requirement does not apply in the same way where the provider has reasonable grounds to suspect fraudulent behaviour by the payment service user and follows the required reporting process. The business should therefore report the transaction promptly and ask the bank to state clearly whether it regards the payment as authorised or unauthorised.

Authentication records are important, but authentication alone does not automatically prove consent

Regulation 75 says that where a payment user denies authorising a transaction, the provider normally has to prove that the payment was authenticated, accurately recorded and not affected by a technical failure. It also says that the recorded use of a payment instrument is not necessarily enough by itself to prove that the payer authorised the transaction or acted fraudulently or with gross negligence.

That is why the investigation should look beyond a statement such as "the correct password was used". Relevant evidence can include device registration, IP data, one-time passcodes, biometrics, card-and-PIN records, call recordings and online-banking logs. The Financial Ombudsman specifically asks financial firms for this type of audit trail when resolving disputed unauthorised transactions.

Report the transaction immediately and preserve the internal evidence

Freeze affected cards or users, change compromised credentials and contact the bank using an official channel. Record the disputed amount, time, beneficiary or merchant and the first moment the business became aware of the transaction. Preserve email, mobile-device and login evidence before systems are reset.

The default Payment Services Regulations framework says users should notify the provider without undue delay and generally no later than 13 months after the debit date to obtain redress for an unauthorised or incorrectly executed transaction. That long-stop period is not a reason to wait. Fast reporting can stop additional payments and gives the bank a better chance to trace what happened.

Larger corporate customers should check the contract because some protections can be modified

The Payment Services Regulations allow a provider and a customer that is not a consumer, micro-enterprise or charity to agree that certain Part 7 provisions do not apply and to agree a different notification period for disputed payments. This makes the account terms especially important for larger companies.

Do not assume a large company has exactly the same evidential or notification position as a microenterprise. Check the corporate banking agreement, security procedures and reporting window. If the bank rejects the claim, ask which contractual clause and regulatory provision it relies on. Eligible SMEs may also be able to take a complaint to the Financial Ombudsman even where mandatory APP reimbursement rules are not relevant.

After the claim, fix the route that allowed the transaction to occur

Identify whether the compromise came from a stolen device, reused credential, social engineering, malware, shared login or excessive user permissions. Remove unnecessary access, reset recovery methods and review device registrations. If one compromised user could both create a new beneficiary and release a high-value payment, tighten the permission structure.

Also check whether alerts were ignored or sent to the wrong person. A £30,000 unauthorised transfer should not wait until month-end reconciliation to be noticed. Real-time or same-day alerts on high-risk activity can reduce the size of the loss even when the payment itself cannot be stopped.

Editorial Verdict

Unauthorised-payment claims begin with consent. If nobody authorised the transaction, the Payment Services Regulations provide an important refund framework, but the facts, authentication trail and business's contractual status still matter.

Report immediately, preserve evidence and ask the bank to explain whether it says the transaction was authorised, unauthorised or excluded under the contract. Larger companies should pay particular attention to negotiated corporate terms. After the incident, fix the credential, device or user-control weakness that allowed the payment to leave.

Sources

Keep the banking structure tied to the business model

Use the provider directory, comparisons and practical guides to narrow the questions before choosing products.

Start comparison