Payment processors operating in the UK face a monitoring challenge that most transaction surveillance literature does not address squarely: the obligations imposed by the Payment Services Regulations 2017 (PSRs 2017) and those imposed by the Money Laundering Regulations 2017 (MLR 2017) are not the same obligation, are supervised by different bodies, and address different risks — but in practice they generate alerts from the same transaction data, reviewed by compliance teams that rarely have the headcount to treat them as entirely separate workstreams.
Understanding where these obligations converge and where they diverge is not an academic exercise. Payment firms that conflate their PSRs fraud monitoring function with their AML transaction monitoring function run the risk of satisfying neither regulator — or of building duplicate infrastructure that increases cost and complexity without improving detection quality.
Two Distinct Regulatory Regimes
The PSRs 2017 implement the second Payment Services Directive (PSD2) in the UK. They impose obligations on payment service providers relating to fraud prevention, Strong Customer Authentication (SCA), and the monitoring and reporting of operational and security incidents. For fraud monitoring specifically, PSRs 2017 Regulation 96 requires payment service providers to maintain internal procedures adequate to detect, manage and report fraud — including reporting fraud incidents to the FCA under the Payment Services and Electronic Money Approach Document (PSEMAD) guidance.
The MLR 2017 implement the fourth and fifth EU Anti-Money Laundering Directives in UK law (as retained post-Brexit). They impose obligations on regulated firms — including most payment service providers — relating to customer due diligence, transaction monitoring, SAR filing to the NCA, and record-keeping. The supervised by the FCA for most payment firms, but the reporting destination for SAR disclosures is the NCA, not the FCA.
The key distinction: PSRs fraud monitoring is designed to detect and prevent payment fraud — unauthorised transactions, account takeover, social engineering fraud. MLR transaction monitoring is designed to detect proceeds of crime being moved through the payment system — money laundering, terrorism financing. The predicate behaviours are different; the detection heuristics are different; the reporting obligations and destinations are different.
Where the Overlap Creates Risk
Despite the regime distinction, the alert signals frequently overlap. Consider a push payment made from a business account to a counterparty in a high-risk jurisdiction for an amount that is unusual for that customer. This single transaction could trigger both a PSRs fraud monitoring alert (is this a business email compromise?) and an AML transaction monitoring alert (is this proceeds of crime being layered through the business account?). The underlying transaction is the same; the investigation required differs.
Payment firms that have built their transaction surveillance as a single combined queue — regardless of whether the alert was generated by fraud rules or AML rules — face three operational risks.
Investigation focus mismatch. Fraud investigations ask: was this transaction authorised? By whom? Is there evidence of account compromise? AML investigations ask: does this transaction pattern suggest proceeds of crime? What is the customer's risk profile? Is there a SAR obligation? A single analyst queue processing both alert types needs analysts trained and mandated to apply the correct investigative framework to each — which is harder to ensure when the alerts are presented identically.
Reporting obligation confusion. PSRs fraud incidents are reported to the FCA under PSEMAD thresholds. AML suspicions are reported to the NCA as SARs. Where an analyst conflates the two — for example, filing an FCA incident report for what should have been a SAR, or treating a PSRs fraud flag as satisfying the AML reporting obligation — the firm is exposed on both obligations simultaneously.
SCA interaction with AML monitoring. PSD2's Strong Customer Authentication requirements mandate two-factor authentication for electronic payments above specified thresholds. The SCA exemptions — including the transaction risk analysis (TRA) exemption — allow payment firms to bypass SCA for low-risk transactions assessed against documented fraud rate benchmarks. The problem arises when the TRA exemption is applied to transactions that may represent money laundering activity: a transaction that passes SCA fraud risk scoring is not thereby assessed as low AML risk. These are separate assessments and must not be collapsed into one.
The UK Post-Brexit Position
For UK payment firms with EU group entities or EU cross-border transaction flows, the post-Brexit divergence between UK and EU frameworks is directly relevant to fraud and AML monitoring. The UK's retained version of PSD2 — now incorporated into the PSRs 2017 — has diverged from the EU's PSD2 as the EU has progressed towards PSD3 and PSR. UK SCA technical standards under FCA CP21/3 differ from EBA RTS on SCA in ways that affect how cross-border transaction fraud assessments are conducted.
UK firms with EU subsidiary entities must operate monitoring systems that can differentiate between the applicable regime for each transaction, rather than applying a single UK-calibrated ruleset to EU-originated transactions or vice versa. Failure to account for these differences has been noted in FCA correspondence as an area of concern for firms that expanded into EU markets following the UK's departure from the Single Market.
Building a Unified but Distinct Monitoring Architecture
The practical response to the overlap challenge is not to create two entirely separate monitoring systems — that is operationally expensive and creates its own coordination risks. Rather, the approach that regulatorily-mature payment firms are using is a unified transaction data layer with distinct alert categorisation and distinct investigation workflows.
In this architecture, all transactions flow through a single ingestion and evaluation layer. Rules are tagged at the point of creation as AML rules, fraud rules, or dual-purpose rules. Alerts generated by AML rules route to the AML alert queue and are subject to the SAR investigation process. Alerts generated by fraud rules route to the fraud investigation queue and are subject to the PSRs reporting process. Where a transaction triggers both rule categories, it appears in both queues and both investigations proceed independently — though the investigators are permitted and encouraged to share information through documented information-sharing procedures.
This architecture has three compliance advantages: it maintains the integrity of each regulatory obligation; it generates clean audit trails demonstrating that each obligation was addressed; and it allows the monitoring system to be tuned separately for each risk type without calibration changes for one regime inadvertently affecting detection coverage under the other.
Practical Steps for Payment Processors
For MLROs at payment processors reviewing their current monitoring posture against these considerations, four questions are worth addressing explicitly in your next compliance risk assessment.
First, have you mapped each transaction monitoring rule in your current system to either the MLR 2017 or PSRs 2017 obligation (or both)? If not, that mapping exercise will reveal where your coverage may have gaps or where investigation procedures may be misapplied.
Second, does your investigation workflow clearly distinguish between the AML suspicion investigation (leading to a SAR decision) and the PSRs fraud investigation (leading to a PSRs incident report decision)? Are analysts trained on the distinct analytical frameworks required for each?
Third, have you reviewed your SCA TRA exemption criteria against your AML customer risk scoring? The two assessments should use distinct criteria and should be independently documented.
Fourth, if you have EU group entities, have you reviewed whether your transaction monitoring configuration accounts for the UK/EU regulatory divergence that has developed since the end of the Brexit transition period?
This article is published for informational purposes. RegSynq Ltd is not authorised or regulated by the Financial Conduct Authority. Nothing in this article constitutes legal advice. Firms should seek qualified legal and regulatory counsel specific to their business and jurisdiction.