Lesson: When a safety rule only covers part of the system, the risk doesn’t disappear — it relocates
The UK’s mandatory reimbursement regime for authorised push payment fraud has just had its first independent evaluation, and the results teach a principle worth carrying into any business decision involving rules, controls, or compliance boundaries.
The setup. Since October 2024, UK payment providers have been required to reimburse victims of authorised push payment fraud on Faster Payments transfers, with liability shared between the sending and receiving firm. An independent review published on 1 July 2026 found the policy has reduced in-scope fraud losses by around 21%, or roughly £73 million a year. On its face, that’s a clean win.
The lesson. Look closer and a different pattern appears. Fraud losses on international transfers rose from £21 million in 2023 to £60 million in 2025. Losses routed through crypto exchanges rose from an estimated £59 million to £153 million over the same period — both channels sitting outside the rule’s scope. The total amount of fraud didn’t shrink to match the reduction inside the regulated perimeter. It moved to wherever the perimeter didn’t reach.
This is a general property of any rule that governs a channel rather than a behaviour. Tighten the front door and pressure finds the window. It shows up in cybersecurity, where blocking one attack vector shifts effort to another. It shows up in tax policy, where closing one loophole often opens demand for the next. It shows up inside a business, too — cap spending on one line item with no oversight elsewhere and the spend resurfaces somewhere less visible.
The second layer. The review also found reimbursement rates varying from 21% to 94% across providers, largely because firms apply a key discretionary exception at very different rates. A rule that looks uniform on paper can still produce wildly uneven outcomes in practice, because the enforcement of a rule is itself a variable — not a constant.
The transferable principle. Before treating any control as solved, ask two questions: what does this rule not cover, and who decides how strictly it’s applied. A policy’s published success rate tells you how it performs inside its own boundary. It tells you nothing about what’s happening just outside it, or how consistently the people enforcing it are actually doing so. The gap between those two things is usually where the real exposure sits.



