Authorised Push Payment (APP) fraud has become one of the most difficult financial crime threats facing the UK because the customer, not the criminal, appears to authorise the payment. That makes APP fraud fundamentally different from many other fraud typologies: the failure point is often not the payment rail or the monitoring rule, but the way a victim has been persuaded to act.
An independent report commissioned by the Payment Systems Regulator (PSR), Using Behavioural Economics to Understand and Prevent APP Fraud, argues that this is not a marginal point but the central issue. Its core insight is that criminals do not merely exploit gaps in systems or controls; they exploit predictable features of human decision-making, from trust in authority to the tendency to act quickly under pressure. For MLROs, compliance officers and broader financial crime teams, that matters because it reframes APP fraud from a narrow fraud-operations problem into a wider behavioural risk challenge.
Fraudsters target decisions
Traditional financial crime controls are built to identify unusual transactions, suspicious patterns and anomalous account activity. APP fraud often slips through those controls because, on the surface, the transaction can look entirely legitimate: the customer logs in, passes security checks and instructs the payment themselves.
The PSR report suggests that asking why intelligent people “fall for scams” is the wrong starting point. A better question is how offenders systematically create the conditions in which normal, sensible people make decisions they would reject under calmer circumstances. Behavioural economics is useful here because it explains how people rely on mental shortcuts, emotional cues and social signals when making decisions quickly.
Seen through that lens, APP fraud is not simply a payments issue. It is a form of behavioural manipulation delivered through convincing stories, emotional pressure and carefully designed prompts that keep the victim moving forward. Criminals are not defeating controls in the traditional sense; they are redirecting the customer’s judgement.
The biases behind the scam
The report identifies several behavioural tendencies that repeatedly feature in APP fraud cases. Four are especially relevant for firms designing customer-facing interventions.
The first is scarcity and urgency. People tend to assign greater importance to opportunities or threats that appear time-limited. Fraudsters exploit this by insisting that action is needed immediately to “protect” an account, secure an investment, stop a payment, avoid arrest or prevent further loss. Once the sense of urgency is established, the victim is less likely to pause, verify the request independently or consult somebody else.
The second is trust. People are generally socialised to trust familiar organisations, authority figures and apparently legitimate communications. That is why impersonation fraud is so effective: criminals present themselves as bank staff, police officers, HMRC representatives, solicitors, conveyancers or even relatives in distress. Victims are often not behaving irrationally when they respond to these cues; they are behaving in line with the norms of everyday life.
The third is representativeness, sometimes described as the tendency to treat something as genuine because it resembles previous genuine experiences. A spoofed number, recognisable branding, plausible account information or a professional-sounding email can all trigger that response. The result is that familiarity is mistaken for authenticity, particularly when the customer is already distracted or anxious.
The fourth is the dominance of fast thinking over reflective thinking. The report draws on the distinction popularised by Daniel Kahneman between rapid, intuitive judgement and slower, more analytical reasoning. Fraudsters work hard to keep victims in the first mode by escalating fear, excitement or confusion. If the customer never pauses, reflective thought has little chance to reassert itself.
Why generic warnings miss the mark
This behavioural framing also helps explain why many standard anti-scam messages have limited effect. Warnings such as “be aware of scams” or “your bank will never ask you to move money” may be correct, but by the time they appear the customer may already be committed to the fraudster’s narrative.[psr.org]
The PSR report notes that once individuals believe they are doing the right thing, they often discount information that conflicts with that belief. In practice, that means a generic pop-up warning may be competing with hours or days of grooming, reassurance and emotional pressure from the criminal. A vague alert is unlikely to outweigh a story the victim has already accepted as true.
This is where many firms still underestimate the sophistication of APP fraud. The scammer has often built a highly personalised script, tailored to the victim’s fears, expectations and circumstances. Against that, generic education campaigns and standardised payment prompts can feel detached, badly timed and too easy to dismiss.
Designing behaviourally informed controls
The report therefore points towards a more practical response: interventions designed around how people actually make decisions, rather than how firms would like them to behave. One of the most important ideas is the use of carefully timed friction in payment journeys.
In many areas of financial services, speed and convenience are treated as unqualified goods. For APP fraud prevention, however, the right amount of delay can be protective. A short pause, a second confirmation step or a well-phrased challenge question may create the cognitive space needed for a customer to reconsider what they are doing.
The point is not to frustrate legitimate users, but to interrupt automatic behaviour when risk indicators suggest manipulation may be under way. The report highlights the value of interventions that encourage independent verification, tailor warnings to the scam type and prompt reflection rather than mere confirmation. In behavioural terms, the aim is to re-engage slower, more deliberate thinking before the payment becomes irrevocable.
For practitioners, this has wider governance implications. Controls should not be assessed only on whether they exist, but on whether they are likely to work on real customers under stress. That means testing warnings, prompts and journeys with actual user behaviour in mind rather than assuming that rational information alone will change outcomes.
Why this matters for firms
Although APP fraud often sits operationally within fraud teams, the lessons from the report extend well beyond the fraud function. MLROs and compliance leaders are increasingly expected to oversee financial crime frameworks that reflect customer outcomes, conduct risk and control effectiveness as well as formal policy compliance.
First, behavioural insight should inform risk assessment. Vulnerability is not limited to age or obvious customer segmentation; it can arise from context, emotion, distraction, life events and the persuasive tactics used in a particular scam. Firms that define risk too narrowly may miss the situational factors that make a customer more susceptible at the point of payment.
Second, staff training needs to move beyond transaction red flags alone. Front-line colleagues, investigators and customer support teams benefit from understanding the manipulation techniques used by criminals, including urgency, social proof, authority and emotional overload. This makes escalation decisions more effective and improves the chances of intervening before funds are lost.
Third, governance should reflect the reality that APP fraud prevention is cross-functional. Behaviourally informed controls sit at the intersection of fraud prevention, compliance, customer experience, communications, operations and product design. Firms are likely to be more effective where these disciplines work together, rather than treating APP fraud as a siloed issue for a single team.
There is also a broader lesson for financial crime prevention. Many forms of misconduct and control failure depend on human judgement being distorted, rushed or misplaced. Behavioural science therefore has relevance not only to APP fraud, but also to issues such as insider risk, sanctions screening, whistleblowing culture and escalation of suspicious activity.
The most useful contribution of the PSR report is that it changes the terms of the debate. It suggests that the question is not whether customers should know better, but whether firms have designed controls around the reality of human behaviour.
That is an important distinction. A control framework that assumes calm, rational, fully informed decision-making may look sound on paper and still fail in the real world. By contrast, a framework built with behavioural evidence in mind is more likely to recognise how fraud actually works: through trust, pressure, familiarity and emotional manipulation.
As APP fraud continues to evolve, especially through increasingly convincing impersonation techniques and digital deception, this behavioural perspective is likely to become more important rather than less. For MLROs and financial crime professionals, behavioural science is not an academic add-on to existing controls. It is becoming an essential part of understanding risk, shaping intervention and protecting customers more effectively.
Sources
- Axiom Economics (2025) Using Behavioural Economics to Understand and Prevent Authorised Push Payments Fraud
- Colin Parsons (2025) Behavioral Intelligence: The New Frontier in Financial Crime Prevention
Dr Mario Menz is the deputy chair of the Institute of Money Laundering Prevention Officers. He is an experienced MLRO and Head of Compliance with more than 20 years' experience in financial services compliance and money laundering prevention.


