PSD3, PSR and the Rise of Privacy-Preserving Behavioural Analytics
25 August 2026
Jump to
Why Regulation Matters in Fraud Prevention
Fraud has changed. Controls for a world of stolen credentials, compromised accounts, and unauthorised transactions need to be revisited, because today's reality is different. Customers are manipulated into authorising payments themselves through scams, social engineering, remote access tools (RATs), malware, and impersonation attacks.
This shift is driving a corresponding change in regulation. Across Europe, regulators are moving beyond transaction security and authentication towards consumer protection. PSD3 and the Payment Services Regulation (PSR) make it clear that banks are expected not only to authenticate payments securely, but also to demonstrate that they have taken reasonable steps to detect and prevent fraud before losses occur.
The challenge is that most fraud starts long before the payment is signed. Effective fraud prevention therefore requires visibility into the entire customer journey, not just the transaction itself. At the same time, banks must operate within increasingly strict requirements around privacy, transparency, and responsible use of AI. The future of fraud prevention sits at the intersection of these three requirements.
PSD3, PSR and the Move Towards Proactive Protection
PSD3 and PSR represent an important evolution in European payments regulation. While PSD2 introduced Strong Customer Authentication, the newer framework places much greater emphasis on fraud prevention and reimbursement obligations, particularly around Authorised Push Payment fraud and bank impersonation scams.
The implication is significant. A payment can be technically secure, correctly authenticated, and still be fraudulent. Regulators increasingly recognise that authentication alone does not protect customers against deception.
This is why fraud prevention is moving upstream. Rather than analysing only the payment itself, banks need technologies capable of identifying scam indicators, behavioural anomalies, account takeover attempts, device compromise, and customer manipulation earlier in the banking journey. The objective is no longer simply detecting fraud after the event but preventing it altogether.
Behavioural Analytics plays a critical role in this shift because it enables institutions to detect signs of fraud while the scam is unfolding, creating opportunities to intervene before funds leave the account.
Privacy and Fraud Prevention Can Coexist
One of the biggest misconceptions surrounding Behavioural Analytics is that better fraud detection requires more personal data. In practice, the opposite is increasingly true.
GDPR is built around principles such as data minimisation, necessity, proportionality, and transparency. Fraud prevention is recognised as a legitimate objective, but organisations are expected to achieve that objective while limiting the amount of personal information they process.
Equally important is the distinction between fraud detection and biometric identification. The purpose of Behavioural Analytics is not to uniquely identify an individual. It is to detect behavioural patterns associated with fraud, scams, account takeover, or customer manipulation. Understanding whether a session appears risky is fundamentally different from determining who a person is.
As fraud continues to evolve, the industry's focus is shifting from collecting more personal data towards extracting more intelligence from fewer data points. This produces better privacy outcomes and often stronger fraud detection.
Behavioural Analytics and Consumer Payment Protection
Modern fraud prevention should answer a simple question: is this customer currently at risk?
Traditional transaction monitoring systems typically assess risk when a payment is initiated. By that stage, the customer may already have spent hours interacting with fraudsters, installing malware, allowing remote access, or being manipulated through a scam.
Behavioural Analytics provides visibility earlier in the process by continuously analysing the customer journey. It can identify indicators associated with social engineering, bank impersonation scams, account takeover, device takeover, remote access abuse, and other forms of fraud before a transaction is authorised.
This enables banks to move from a reactive reimbursement model to a proactive protection model. Rather than investigating losses after they occur, institutions can identify vulnerable customers and intervene before the payment is completed.
That objective aligns directly with the direction of PSD3 and PSR: protecting customers before fraud becomes a financial loss.
Privacy Preservation by Design
At ThreatFabric, privacy preservation is not a compliance exercise. It is a design principle.
The Fraud Risk Suite was built to detect fraud without relying on large-scale collections of sensitive personal information. The platform focuses on behavioural indicators relevant to fraud while avoiding unnecessary exposure to personal data. It does not require access to personal messages, user files, camera content, microphone recordings, or other highly intrusive sources of information.
This architecture reflects a broader reality. As privacy regulations continue to evolve, solutions that minimise data collection while maximising fraud detection effectiveness will increasingly become the standard. Strong fraud prevention and strong privacy protection are no longer opposing goals; they are complementary requirements.
Transparency Matters
As AI becomes more deeply embedded in fraud prevention, transparency becomes just as important as detection accuracy.
Fraud analysts, auditors, regulators, and customers increasingly expect to understand why a particular decision was made. Black-box models may generate effective alerts, but they often create operational and regulatory challenges because the reasoning behind the decision remains unclear.
ThreatFabric's approach is built around model transparency. Risk decisions should be explainable, auditable, and understandable. Analysts should be able to see which indicators contributed to a risk score and why a session was classified as suspicious. This not only improves trust in the technology but also supports governance, compliance, and customer communication requirements.
Transparency is rapidly becoming a regulatory expectation. It is also becoming an operational necessity.
Conclusion: Beyond First-Generation Behavioural Analytics
First-generation behavioural solutions were primarily designed to answer the question: "Is this the legitimate user?" In a world dominated by credential theft and account takeover, that was sufficient.
Today's fraud landscape requires a different approach. Customers are increasingly authenticated, but still defrauded. Criminals exploit trust, manipulate behaviour, and weaponise social engineering rather than simply stealing passwords.
As regulatory expectations evolve under PSD3 and PSR, fraud prevention must evolve as well. The goal is no longer just identity verification. The goal is consumer protection.
This is where third-generation Behavioural Analytics differs. It combines behavioural intelligence, device intelligence, and fraud intelligence to identify scams and fraud earlier in the customer journey while maintaining privacy and transparency. The result is a model built around three principles: Consumer Payment Protection, Privacy Preservation, and Model Transparency.
As the industry moves towards greater accountability for fraud outcomes, these principles are becoming more than differentiators. They are becoming the blueprint for the next generation of fraud prevention.