The EU’s payment services framework is being rebuilt from the ground up and PSD3 and PSR compliance is high on the agenda. The operational function that sits at the center of every new obligation is one most institutions have never treated as a compliance instrument.
In November 2025, representatives of the European Commission, Parliament, and Council reached political agreement on the Payment Services Regulation (PSR) and the Third Payment Services Directive (PSD3) — the most consequential overhaul of EU payment services law since PSD2 came into force in 2018. Publication in the Official Journal is expected in H2 2026. Full compliance will be mandatory by late 2027 to mid-2028.
For most regulated institutions, the first question is: what changes towards PSD3 and PSR compliance obligations? Several things change simultaneously — fraud liability, open banking standards, licensing, consumer rights — and the changes interact. But there is one function inside every payment institution, bank, and fintech that sits at the intersection of all of them.
That function is reconciliation.
The obligations that PSD3 and PSR introduces are, at the operational level, primarily obligations to produce evidence: evidence that funds were protected, that fraud was detected, that a warning was delivered, that a suspicious payment was reviewed before it cleared. Reconciliation is the process by which that evidence is either generated or not.
This article examines what PSD3 and PSR compliance demands of reconciliation infrastructure, where current practice falls short, and what adequate looks like, starting from the mechanics.
The PSD3 and PSR compliance framework: Why it matters for payment operations
PSD2 was a directive. It set minimum requirements and left EU member states to transpose them into national law — a process that produced seventeen meaningfully different national interpretations and the fragmentation that regulators spent eight years trying to correct. PSD3 is also a directive, and it governs licensing: who can operate as a payment institution or e-money institution, what capital they must hold, how they are supervised.
The PSR, by contrast, is a regulation. Under EU law, regulations do not require national transposition. They apply directly across all member states from the moment they enter into force — which, for the PSR, is twenty days after publication in the Official Journal.
The PSR is where the conduct rules live: strong customer authentication, open banking API standards, fraud prevention and detection obligations, transparency requirements, consumer refund rights, and the liability framework that determines who bears the cost when a payment goes wrong. These are the rules that will be felt first in operations, compliance functions, and finance teams.
The practical implication: institutions cannot wait for their national regulator to transpose PSD3 before beginning PSR compliance work. The PSR conduct obligations apply directly and uniformly from entry into force. Member states that are slow to transpose PSD3 provide no cover for PSR non-compliance.
Together, the two instruments repeal and replace PSD2 and the Electronic Money Directive (EMD2) in full. Every payment institution and e-money institution currently operating under PSD2 or EMD2 authorization must re-authorize under the PSD3 framework within 24 months of entry into force. That re-authorization requires institutions to demonstrate compliance with updated capital requirements, governance standards, safeguarding procedures, and digital resilience obligations under DORA, the EU’s Digital Operational Resilience Act.
Five key regulatory objectives and their impact on reconciliation
The Commission’s stated goals for the package address four documented failures of the PSD2 era — fragmented national transposition, an escalating fraud environment, underperforming open banking APIs, and incomplete consumer protection — plus a fifth objective around creating a level playing field between banks and non-bank payment service providers. Each objective, examined closely, has a reconciliation-visible consequence.
Harmonization across EU payment services
The PSR eliminates national discretion on conduct rules. For institutions operating across multiple EU member states, this means a single compliance baseline — but also means that reconciliation processes adequate in one jurisdiction may not meet PSR’s directly applicable standard. The lowest-common-denominator approach some institutions quietly relied on under PSD2 is no longer available.
Fraud prevention and extended liability under PSR
PSR extends fraud liability to payment service providers who fail to implement adequate detection mechanisms. The critical word is adequate. Adequacy will be determined by what the institution’s systems were capable of detecting, and whether they detected it in time. That determination rests, in part, on the completeness and timeliness of transaction-level records — which is to say, on the quality of the reconciliation that generates them.
The new liability framework also extends, for the first time, to large online platforms that fail to remove fraud content after notification. For those entities, the compliance obligation is newly created and the operational infrastructure to support it often does not exist.
Open banking and data integrity to achieve PSD3 and PSR compliance
PSR introduces prescriptive API performance standards and requires account-servicing payment service providers to offer dedicated APIs that meet specified quality thresholds. It also mandates consent management dashboards, giving users visible control over their data-sharing permissions with third parties.
For account information service providers, the data integrity implication is direct: the account data they relay to users must accurately reflect what account-servicing institutions return via their APIs. Discrepancies between what an API reports and what a third-party provider presents are a regulatory risk, not merely an operational inconvenience. Verifying that accuracy systematically is, in essence, a reconciliation obligation.
Consumer protection and refund rights under PSD3 and PSR compliance
PSR strengthens refund rights significantly. Where a fraudster has impersonated a payment service provider — a spoofing attack — the victim is entitled to a full refund, subject to prompt reporting. The burden of proof then shifts to the PSP to demonstrate that the customer acted fraudulently or with gross negligence.
That burden of proof requires an evidential trail: records showing what the institution’s systems observed, when they observed it, and what action was taken. Therefore, institutions that cannot produce a complete, timestamped account of how a disputed transaction was processed and reviewed are poorly positioned to discharge that burden — regardless of the actual quality of their fraud controls.
A level playing field for payment providers
PSD3 merges the payment institution and e-money institution licensing regimes into a single framework. For finance and operations teams at firms that currently operate both activities under separate licences, the practical consequence is a consolidation of previously parallel reconciliation workflows — client fund reconciliation under the PI framework and e-money position reconciliation under the EMD2 framework — into a single, unified process. Many firms built those workflows independently, and the consolidation is not a simple task.
Higher standards for reconciliation: the implied requirement for PSD3 and PSR compliance
The five objectives above each have a specific regulatory mechanism. PSR mandates daily safeguarding reconciliation with a documented evidence pack. It requires real-time transaction monitoring. It imposes liability for misdirected payments where a name-to-IBAN verification was not performed or not logged. Additionally, it creates obligations to share fraud intelligence across the industry via a standardized platform. Each of these is concrete and specific.
What is less explicit, but clearly implied, is the standard by which compliance will be assessed. Under PSD2, the operative question was: did the institution follow the process? A process existed. An institution could point to it. That was generally sufficient.
Evidence, audit trails, and the shift to proactive compliance
Under PSR, the questions are different: can the institution prove it followed the process, and can it prove the process was adequate to the risk? That is not the same question. A reconciliation process that performs correctly but does not log its outputs, timestamp its decisions, or link its exceptions to downstream resolution is, from a regulatory standpoint, invisible. It offers no protection in a fraud liability dispute, no evidence in a re-authorization review, and no defense in a consumer complaint adjudication.
The gap this creates is not theoretical. The most common finding in current PSD2 supervisory audits is not that institutions failed to reconcile their safeguarding accounts — it is that they performed the reconciliation but did not retain the evidence. Under PSD3, evidence retention is a formal regulatory obligation with a documented pack required for supervisory inspection. The distinction between performing a process and being able to prove it has moved from best practice to compliance requirement.
From batch to real-time: What adequate reconciliation looks like under PSD3
This is why the impact of PSD3 and PSR compliance lands in reconciliation functions first. The regulation does not introduce reconciliation as a new concept — it upgrades the standard that reconciliation must meet. Continuous rather than batch. Evidenced rather than assumed. Integrated across fraud detection, safeguarding, and transaction monitoring rather than siloed in the finance back office.
For institutions that already operate automated, audit-trail-generating, always-on reconciliation infrastructure, the distance to compliance is short. For those still running batch processes with manual exception handling and no systematic evidence retention, the gap is architectural — and the transition window is shorter than the headline dates suggest.
PSD3 and PSR compliance timelines: key deadlines and milestones
The transition period of 18 to 21 months from Official Journal publication sounds generous. In practice, it is not. Several factors compress the effective working time.
First, the PSR enters into force 20 days after publication — not at the end of the transition period. From that date, supervisors will expect to see contemporaneous compliance records being generated. Institutions that wait until the final months before the compliance deadline to build reconciliation infrastructure will have no historical record to present when the first supervisory inspection or fraud liability dispute arises.
Second, the re-authorization process for existing payment institutions and e-money institutions runs in parallel with compliance implementation. Applications must include a documented safeguarding and reconciliation framework. Assembling that documentation — for an institution that needs to redesign its reconciliation architecture before it can describe it — is a multi-quarter project.
Third, reconciliation infrastructure changes are not deployable overnight. Migrating from batch processing to continuous matching, from single-bank safeguarding reconciliation to multi-bank coverage, from siloed exception management to integrated fraud-signal workflows — each of these requires system procurement, implementation, testing, staff training, and operational validation. Institutions beginning that work now are not being early adopters. They are giving themselves a realistic chance to secure PSD3 and PSR compliance.
Frequently asked questions
What is the difference between PSD3 and the PSR?
PSD3 is a directive governing the licensing and supervision of payment institutions and e-money institutions. It requires national transposition by each EU member state. The PSR is a regulation governing conduct — fraud prevention, strong customer authentication, open banking, consumer rights — and applies directly across all member states without national transposition, from the day it enters into force.
When do PSD3 and PSR come into force?
Publication in the Official Journal is expected in H2 2026. The PSR enters into force 20 days after publication. PSD3 requires national transposition within 18 months of entry into force, with applicability targeted at Q2/Q3 2028. Full compliance with PSR conduct obligations is expected by late 2027.
Who is in scope for PSD3 and PSR?
Banks and credit institutions offering payment services, payment institutions and e-money institutions, account information and payment initiation service providers, technical service providers supporting payment processes, large online platforms in certain fraud liability contexts, and crypto-asset service providers handling e-money tokens that constitute payment services.
Why does reconciliation matter for PSD3 and PSR compliance?
The PSR creates compliance obligations that are, at the operational level, obligations to produce evidence: that client funds were protected, that fraud was detected in time, that a payee verification was performed and logged, that a consumer was warned of a mismatch. Reconciliation is the process that either generates that evidence as a systematic by-product of operations or fails to — leaving the institution without the documentation it needs to demonstrate compliance or discharge liability.
What does daily reconciliation with evidence retention mean under PSD3?
PSD3 formalizes the obligation to reconcile safeguarded client funds daily and to retain the output — the reconciliation record, exception log, and sign-off documentation — in a form available for supervisory inspection on demand. The most common finding in current PSD2 audits is that institutions perform the reconciliation but do not retain the evidence. Under PSD3, however, that gap is a formal compliance failure.
ReconArt is an enterprise reconciliation platform built for high-volume, compliance-critical financial environments. Find out more about the solution here and contact us to book a demo.





















