Europe checks the payee’s name now. The liability did not move.
Europa prüft jetzt den Empfängernamen. Die Haftung ist geblieben, wo sie war.
Since 9 October 2025 a bank in the euro area must tell you, before you can authorise a transfer, whether the name you typed belongs to the account number you typed. Ten months on, the paragraph of that regulation which actually allocates the loss is addressed entirely to payment service providers. The payer who was shown “no match” and pressed send does not appear in it, and for that payer the older rule still governs: a transfer executed to the identifier supplied was correctly executed. The name check did not create a right. It removed an excuse.
What the obligation actually is
The rule lives in Article 5c of the Single Euro Payments Area Regulation, inserted there by the Instant Payments Regulation of March 2024. The European Central Bank states the obligation plainly on its own implementation page: providers “shall offer the payer a service ensuring verification of the payee to whom the payer intends to send a credit transfer”, the duty covers standard and instant credit transfers alike, and the service must be free to the payer. Providers in the euro area had to be live on 9 October 2025; those outside it have until 9 July 2027.
Mechanically it is a question asked between two banks. The payer’s bank sends the name and the account number to the bank holding the account, which compares them against its own records and answers within seconds. The European Central Bank lists the four possible answers as “match”, “close match”, “no match” or “other”. The answer reaches the payer before the payer is offered the chance to authorise — that sequencing is the whole design — and it does not stop anything. A payer told “no match” may still pay.
The plumbing is a scheme run by the European Payments Council, whose rulebook took effect on 5 October 2025, four days before the legal deadline. Its own description is more modest than the way the service is usually described: the scheme “provides PSPs with a messaging functionality … it allows the payer to verify certain data about a payee. It cannot be relied upon to identify a private or a legal person.”
Read the liability paragraph slowly
Article 5c(8) is the provision that moves money after something has gone wrong. Reproduced verbatim by the European Payments Council in its March 2026 consultation document, it reads:
“A PSP shall not be held liable for the execution of a credit transfer to an unintended payee on the basis of an incorrect unique identifier, as laid down in Article 88 of Directive (EU) 2015/2366, provided that it has fulfilled the requirements of this Article. Where the payer’s PSP fails to comply with paragraph 1 … the payer’s PSP shall without delay refund the payer the amount transferred … Where the failure to comply occurs because the payee’s PSP … failed to comply with its obligations under this Article, the payee’s PSP … shall compensate the payer’s PSP for the financial damage caused … Any further financial loss caused to the payer may be compensated in accordance with the law applicable to the contract concluded between the payer and the relevant PSP.”
Three limbs, every one about a provider: a safe harbour for providers who did the check, a refund duty owed by the payer’s provider when it failed, and a compensation claim between two providers. The last sentence hands anything else back to the contract.
The payer who was warned and paid anyway is in none of them, and that silence is the operative fact. Their position falls back to Article 88 of the second Payment Services Directive: where a payment order is executed in accordance with the unique identifier — in practice the IBAN — it is deemed correctly executed with respect to the payee that identifier designates, and where the identifier supplied was incorrect the provider is not liable for defective execution, though it must make reasonable efforts to recover the funds. Warning shown, payment authorised, account number as given, funds delivered to that account number: correctly executed. There is no claim to bring.
Law firms advising banks read it the same way. PwC Legal’s German practice, writing for payment institutions in August 2025: “Where a payer authorises a credit transfer following it having been warned by the PSP of an incorrect unique identifier, the payer is liable for the transfer to an unintended recipient.” That is a firm advising the industry on its own exposure — worth weighing, and worth attributing.
What changed was the evidence, not the allocation
The allocation itself is not new: German legal commentary describes case law holding that the receiving bank owed no duty to check the name against the account number at all. What is new is that the bank now holds a timestamped record of having told the customer. A dispute that used to be about what a reasonable bank should have spotted becomes a dispute about what the customer was shown and clicked past. That is not a small change; it is simply not the change the phrase “verification of payee” suggests to a member of the public.
The case for building it this way
The argument for the design is straightforward and it is not weak. Only the payer knows who they meant to pay. The bank sees a string and an account; the payer sees an invoice, a conversation, a relationship. A rule that made the provider refund a payer who had been shown “no match” and paid regardless would tell every payer that the warning carries no consequence — and the warning is the entire mechanism. Put the loss on the provider after a clear warning and you have not built a control, you have built a notification.
The design also refuses, deliberately, to block. Businesses trade under names that are not the names on their accounts; a landlord’s account may sit in a spouse’s name. A rule that stopped every mismatch would stop a very large number of correct payments, and the people it stopped would be those with unusual but legitimate arrangements.
And it is aimed at the fraud that is actually growing. The European Banking Authority and the European Central Bank, in their joint report on payment fraud published in December 2025, found that the largest share of fraudulent credit transfers, by value and by volume, came from manipulation of the payer into initiating the transaction — rising from 65% to 74% of value and from 55% to 71% of volume between 2023 and 2024. That is the category no authentication can reach, because the victim authenticates perfectly. When strong authentication closed the card channel, this is where the losses went. A name check placed immediately before authorisation is the cheapest thing that addresses the moment of the transfer itself.
Who is currently carrying the loss
The same EBA and ECB report makes the liability question concrete. Payment fraud reported across the European Economic Area amounted to €3.4 billion in 2022, €3.5 billion in 2023 and €4.2 billion in 2024, while the fraud rate stayed at roughly 0.002% of transaction value. Within the 2024 total, credit transfers accounted for €2.200 billion of reported losses and card payments for €1.329 billion.
Then the split. In 2024, according to the two authorities, payment service users bore 38% of losses from card payments, 53% from direct debits and cash withdrawals, and 26% from electronic money transactions. For credit transfers they bore around 85%.
The authorities offer their own explanation, and it is the sentence to sit with: the losses “were distributed differently among liability bearers depending on the payment instrument, possibly, due to the divergent applicable liability regimes and the effectiveness of redress mechanisms available to payment service users”. Cards are not harder to defraud than transfers. They are governed by a rule that puts the loss somewhere else. One caveat: the figures come from supervisory returns filed by providers, so the party reporting who bore the loss is the party that decided.
The experiment on the other side of the Channel
Britain ran the other version of this policy, long enough now to produce data. Since 7 October 2024 a sending firm must reimburse an in-scope authorised push payment scam claim, capped at £85,000 with an optional £100 excess, and may refuse only where the customer was grossly negligent — a standard the Payment Systems Regulator says sits above ordinary negligence and which the firm, not the customer, must prove.
The regulator’s dashboard, updated on 30 July 2026, covers the eighteen months to 31 March 2026. In that period 88% of the money lost to in-scope scams — £316 million — was reimbursed. Consumers reported around 438,300 claims, of which 301,500 were in scope. Firms closed 82% within five business days and 98% within thirty-five. And 3% were rejected because the customer had not taken enough care; in the first quarter of 2026 that was around 1,700 claims, or 2%.
An evaluation by Frontier Economics, published by the regulator on 1 July 2026, found that scam losses routed through Faster Payments fell by roughly 21%, about £73 million a year, with roughly 35,000 fewer scams, and estimated a short-run net benefit of £17 million to £29 million after firms’ costs. Frontier was commissioned by the regulator whose policy it evaluated. The dashboard is assembled from data supplied by sending firms to Pay.UK; the regulator states it has no receiving-firm data to validate it, excludes payments where both accounts sit at the same firm, and covers one payment system.
What the exercise establishes is narrower and more useful than the headline. The standard objection to moving the loss onto banks was that customers would stop being careful. The metric that would show it — claims refused for insufficient care — has sat at two or three per cent for six quarters. That is not proof that no such effect exists; it is the absence of the effect in the only place anyone is counting, which is more than the European design can currently say about anything. Britain’s decision to make reimbursement mandatory rather than advisory produced a measurement as a by-product, because a firm that pays counts what it pays.
The number the European rule turns on is not collected
The European allocation depends on a behaviour: whether the payer proceeded after a warning. Nobody publishes that number.
Before launch, the European Payments Council told the Euro Retail Payments Board in June 2025 what to expect, citing two markets that already ran such a service. In the Netherlands, voluntary and at 97% penetration, results ran at 90% match, 6% close match, 4% no match — attributed to SurePay, a company that sells the service. In France, also voluntary, 85% full match and 15% no match — attributed to SEPAmail. The EPC warned in the same breath of “relevant differences at PSP level in the % of close match versus no match, depending on tuning of the algorithms”. A spread from 4% to 15% is not a measurement; it is the distance between two countries and two sets of matching thresholds, offered by parties who sell matching.
Nor does anything published since. In the consultation on version 2.0 of the scheme rulebook, which ran from 1 April to 30 June 2026, the EPC’s own working group lists change request 25: “Add an obligation for PSPs not using a RVM to provide statistics.” Eight months after the obligation took effect, the body operating the scheme was proposing to start requiring statistics from the participants that connect to it directly. Whatever the aggregate picture is, the scheme operator did not have it — and the banks best placed to know how often a “no match” is overridden were not being asked.
The dispute machinery arrives after the liability
The second and third limbs of Article 5c(8) create claims between providers, and they have existed since 9 October 2025. The scheme through which those claims must travel had no process for handling them.
In the same consultation, the Italian Banking Association filed change request 11, proposing a harmonised dispute-management process. Its statement of the problem is the most candid document I found in this research: the current rulebook contains no dispute framework, and the consequences it names are “fragmentation of practices across PSPs and countries”, “inconsistent timelines and expectations”, “operational frictions in resolving liability cases”, and “financial risk in case disputes are not handled appropriately”. The proposal sets out an initiation, acknowledgement, assessment, outcome and closure sequence with mandatory deadlines, and suggests “a default liability matrix”. The working group recommends incorporating it; version 2.0 of the rulebook is due at the end of November 2026. The proposer is a banking association whose members sit on both sides of every such claim: it is not arguing for an allocation, it is asking for a procedure.
The instrument was carrying a legal consequence before it had finished being an instrument: the same working group counted 24 major change requests to a rulebook six months old.
The false “no match”, and who pays for it
The European Commission saw the central practical problem early. In its published questions and answers on implementation, it told providers they must collect the commercial names under which their business customers trade, because doing so “will be key to minimise the rate of false ‘no match’ notifications, which otherwise would dissuade payers to proceed with the placement of ‘safe’ payment orders”. Change request 16 in the June 2026 consultation is titled “Support Commercial Trade Name in VOP”, and the working group recommends incorporating it — into version 2.0, due in November 2026. So the gap between the name a business trades under and the name on its account, the same gap that makes the line on a card statement unrecognisable, is scheduled to close thirteen months after the obligation began.
Every false “no match” in the meantime is a cost paid by someone who did nothing wrong. It appears in no fraud statistic, for the same reason the customers a control turns away never appear in the numbers used to justify the control. It is also the cost the liability rule quietly relies on: a warning that fires too often trains people to click past it, and a payer trained to click past warnings is a payer who bears the loss.
What the next law does, and what it does not
On 27 November 2025 the Council and the European Parliament reached a provisional political agreement on a new payment services regulation. According to the Council’s statement, account numbers “will have to be checked against a corresponding bank account name before any transfer can take place, as is already the case for instant payment transfers taking place in euro”, and where a customer informs the police and the provider about impersonation fraud — a scammer posing as the provider’s own staff — “the PSP is supposed to refund the full amount”.
That is a real extension: the name check leaves the euro-instant corner and applies to transfers generally, and one named scam pattern acquires a refund right. What the Council’s statement does not mention, anywhere, is the payer who was warned and paid anyway. The agreement is provisional and the text not adopted, so nothing can be concluded about the final wording. But the direction announced is more provider liability for provider failures and for one specific deception — not a reallocation of the loss Article 5c(8) currently leaves with the customer.
Degrees of confidence
Firmly held: the provision quoted above allocates loss between providers and says nothing about the warned payer; and users bore around 85% of credit transfer fraud losses in 2024, on the EBA and ECB’s figures.
With reasonable confidence: that the missing dispute framework will show up as slow and inconsistent settlement of inter-provider claims — the reasoning of the banking association that filed the change request, not mine.
Cautiously: the size of the British effect. One market, roughly one year, an evaluation commissioned by the authority being evaluated.
What this does not tell you
There is no European figure for how often a payer proceeds past a warning, so the argument here is about incentives, not observed behaviour. If almost everyone stops, the allocation rarely bites and the design is close to costless.
The British reimbursement rule arrived alongside other measures and a redefinition of what counts as a scam. Frontier Economics attributes the reduction to the policy; I have not reproduced that attribution.
And the legal position of the warned payer as set out here is derived from the texts, not from a decision. I found no judgment since October 2025 dealing with a payer who proceeded past a “no match”. A court could read the duty to warn as carrying more content than the regulation spells out, and the first such judgment would change the analysis.
What the case teaches
A disclosure duty and a liability rule look similar on paper and behave nothing alike. Both can be described as consumer protection; only one changes who is out of pocket, and only the one that changes who is out of pocket changes who invests in prevention. Europe built an instrument, put it in front of every credit transfer, made it free, and left the residual loss exactly where it had always been. Britain moved the residual loss and let the instruments follow.
The measurement follows the money too, which is the part that is easy to miss. Britain publishes quarterly figures on how often firms blame the customer, because a firm that must pay counts what it pays. Europe has a change request proposing that participants might be asked for statistics. That is not a difference in administrative competence. It is what happens when a rule generates information without moving money: nobody downstream needs it badly enough to collect it, so the rule ends up judged on whether it was implemented rather than on what it did.
The name check is a good idea, cheaply delivered, aimed at the right fraud, and it will stop losses nothing else could. It is also the clearest recent example of a habit worth acquiring: read past the obligation to the paragraph saying who pays when the obligation was met and the money is gone anyway. That paragraph is the policy. Everything before it is the interface.
Seit dem 9. Oktober 2025 muss eine Bank im Euroraum ihren Kunden vor der Freigabe einer Überweisung sagen, ob der eingetippte Name zur eingetippten Kontonummer gehört. Zehn Monate später richtet sich der Absatz dieser Verordnung, der den Schaden tatsächlich verteilt, ausschließlich an Zahlungsdienstleister. Der Zahler, dem „keine Übereinstimmung” angezeigt wurde und der trotzdem auf Senden gedrückt hat, kommt darin nicht vor — und für ihn gilt weiter die ältere Regel: Eine Überweisung, die auf die angegebene Kennung ausgeführt wurde, ist ordnungsgemäß ausgeführt. Die Namensprüfung hat kein Recht geschaffen. Sie hat eine Ausrede beseitigt.
Was die Pflicht tatsächlich verlangt
Die Regel steht in Artikel 5c der SEPA-Verordnung, eingefügt durch die Echtzeitüberweisungsverordnung vom März 2024. Die Europäische Zentralbank formuliert die Pflicht auf ihrer eigenen Umsetzungsseite nüchtern: Zahlungsdienstleister „shall offer the payer a service ensuring verification of the payee to whom the payer intends to send a credit transfer”. Die Pflicht gilt für gewöhnliche wie für Echtzeitüberweisungen, und der Dienst muss für den Zahler kostenlos sein. Häuser im Euroraum mussten am 9. Oktober 2025 liefern; Häuser außerhalb haben bis zum 9. Juli 2027 Zeit.
Technisch ist es eine Frage zwischen zwei Banken. Die Bank des Zahlers schickt Name und Kontonummer an die kontoführende Bank; die vergleicht beides mit ihren eigenen Stammdaten und antwortet in Sekunden. Die Europäische Zentralbank nennt vier mögliche Antworten: „match”, „close match”, „no match” oder „other”. Die Antwort erreicht den Zahler, bevor ihm die Freigabe angeboten wird — diese Reihenfolge ist der ganze Entwurf — und sie hält nichts auf. Wer „keine Übereinstimmung” gelesen hat, darf trotzdem zahlen.
Darunter liegt ein Regelwerk des European Payments Council, in Kraft seit dem 5. Oktober 2025, vier Tage vor der gesetzlichen Frist. Dessen eigene Beschreibung ist bescheidener als die übliche Rede vom Sicherheitscheck: Das Verfahren „provides PSPs with a messaging functionality … it allows the payer to verify certain data about a payee. It cannot be relied upon to identify a private or a legal person.”
Den Haftungsabsatz langsam lesen
Artikel 5c Absatz 8 ist die Vorschrift, die nach einem Schaden Geld bewegt. Der European Payments Council gibt sie in seinem Konsultationsdokument vom März 2026 wörtlich wieder:
„A PSP shall not be held liable for the execution of a credit transfer to an unintended payee on the basis of an incorrect unique identifier, as laid down in Article 88 of Directive (EU) 2015/2366, provided that it has fulfilled the requirements of this Article. Where the payer’s PSP fails to comply with paragraph 1 … the payer’s PSP shall without delay refund the payer the amount transferred … Where the failure to comply occurs because the payee’s PSP … failed to comply with its obligations under this Article, the payee’s PSP … shall compensate the payer’s PSP for the financial damage caused … Any further financial loss caused to the payer may be compensated in accordance with the law applicable to the contract concluded between the payer and the relevant PSP.”
Drei Glieder, jedes davon über einen Zahlungsdienstleister: ein Haftungsschutz für den, der geprüft hat; eine Erstattungspflicht der Zahlerbank, wenn sie versagt hat; ein Ausgleichsanspruch zwischen zwei Instituten. Der letzte Satz verweist alles Weitere auf den Vertrag.
Der gewarnte Zahler steht in keinem dieser Glieder, und dieses Schweigen ist die eigentliche Regelung. Für ihn gilt Artikel 88 der zweiten Zahlungsdiensterichtlinie: Wird ein Zahlungsauftrag entsprechend der Kundenkennung — praktisch der IBAN — ausgeführt, gilt er hinsichtlich des damit bezeichneten Empfängers als ordnungsgemäß ausgeführt; war die angegebene Kennung falsch, haftet der Dienstleister nicht für fehlerhafte Ausführung, muss sich aber um die Wiederbeschaffung bemühen. Warnung angezeigt, Zahlung freigegeben, Kontonummer wie eingegeben, Geld auf genau diesem Konto: ordnungsgemäß ausgeführt. Es gibt keinen Anspruch.
Kanzleien, die Banken beraten, lesen es genauso. PwC Legal Deutschland schrieb im August 2025 für Zahlungsinstitute: „Where a payer authorises a credit transfer following it having been warned by the PSP of an incorrect unique identifier, the payer is liable for the transfer to an unintended recipient.” Das ist eine Kanzlei, die der Branche ihr eigenes Risiko erklärt — Grund genug, es ernst zu nehmen, und Grund genug, dazuzusagen, wessen Lesart es ist.
Verändert hat sich der Beweis, nicht die Verteilung
Die Verteilung selbst ist nicht neu. Die deutsche Kommentarliteratur beschreibt eine Rechtsprechung, nach der die Empfängerbank nicht verpflichtet war, den Namen mit der Kontonummer abzugleichen, weil allein die zwischen Kunde und Bank vereinbarte Kennung — seit dem 1. Februar 2014 die IBAN — die Ausführung bestimmt. Neu ist, dass die Bank nun einen maschinell erzeugten, mit Zeitstempel versehenen Nachweis besitzt, den Kunden gewarnt zu haben. Aus dem Streit darüber, was eine sorgfältige Bank hätte auffallen müssen, wird ein Streit darüber, was dem Kunden angezeigt wurde und was er weggeklickt hat. Das ist keine Kleinigkeit. Es ist nur nicht die Veränderung, die der Begriff „Empfängerüberprüfung” beim Publikum auslöst.
Was für diesen Entwurf spricht
Das Argument dafür ist geradlinig und nicht schwach. Nur der Zahler weiß, wen er bezahlen wollte. Die Bank sieht eine Zeichenkette und ein Konto; der Zahler sieht eine Rechnung, ein Gespräch, eine Geschäftsbeziehung. Eine Regel, die den Dienstleister zur Erstattung zwingt, obwohl er gewarnt hat, sagt jedem Zahler, dass die Warnung folgenlos bleibt — und die Warnung ist der gesamte Mechanismus. Wer den Schaden nach einer klaren Warnung beim Institut ablädt, hat keine Kontrolle gebaut, sondern eine Benachrichtigung.
Der Entwurf verzichtet außerdem bewusst darauf, zu blockieren. Unternehmen firmieren unter Namen, die nicht auf ihren Konten stehen; das Konto eines Vermieters kann auf den Ehepartner lauten. Eine Regel, die jede Abweichung stoppt, stoppt sehr viele richtige Zahlungen — und trifft genau die Leute mit ungewöhnlichen, aber legitimen Verhältnissen.
Und sie zielt auf den Betrug, der tatsächlich wächst. Die Europäische Bankenaufsichtsbehörde und die Europäische Zentralbank stellten in ihrem gemeinsamen Betrugsbericht vom Dezember 2025 fest, dass der größte Anteil betrügerischer Überweisungen — nach Wert wie nach Stückzahl — auf die Manipulation des Zahlers zur Auslösung der Zahlung entfällt: von 65 auf 74 Prozent des Wertes und von 55 auf 71 Prozent der Stückzahl zwischen 2023 und 2024. Diese Gattung erreicht keine Authentifizierung, weil das Opfer sich einwandfrei authentifiziert. Als die starke Kundenauthentifizierung den Kartenkanal schloss, wanderten die Verluste hierher. Eine Namensprüfung unmittelbar vor der Freigabe ist das Billigste, was am Moment der Überweisung selbst ansetzt.
Wer den Schaden derzeit trägt
Derselbe Bericht macht die Haftungsfrage konkret. Der im Europäischen Wirtschaftsraum gemeldete Zahlungsbetrug belief sich auf 3,4 Milliarden Euro (2022), 3,5 Milliarden (2023) und 4,2 Milliarden (2024), bei einer stabilen Betrugsquote von rund 0,002 Prozent des Transaktionswertes. Auf Überweisungen entfielen 2024 gemeldete Verluste von 2,200 Milliarden Euro, auf Kartenzahlungen 1,329 Milliarden.
Dann die Aufteilung. 2024 trugen die Zahlungsdienstnutzer nach Angaben beider Behörden 38 Prozent der Schäden bei Kartenzahlungen, 53 Prozent bei Lastschriften und Bargeldabhebungen und 26 Prozent bei E-Geld-Transaktionen. Bei Überweisungen waren es rund 85 Prozent.
Die Behörden liefern die Erklärung selbst mit, und das ist der Satz, bei dem man verweilen sollte: Die Schäden seien je nach Zahlungsinstrument unterschiedlich verteilt, „possibly, due to the divergent applicable liability regimes and the effectiveness of redress mechanisms available to payment service users”. Karten sind nicht schwerer zu betrügen als Überweisungen. Für sie gilt eine Regel, die den Schaden anderswo ablegt. Eine Einschränkung: Die Zahlen stammen aus Aufsichtsmeldungen der Institute — wer meldet, wer den Schaden trug, ist derjenige, der es entschieden hat. Das macht sie nicht falsch, aber niemand mit einem Interesse an einer anderen Antwort war in der Lage, eine zu berechnen.
Der Gegenversuch auf der Insel
Großbritannien hat die andere Fassung dieser Politik gebaut, und sie läuft lange genug für Daten. Seit dem 7. Oktober 2024 muss die sendende Bank eine erfasste Betrugsmeldung erstatten, gedeckelt bei 85.000 Pfund, mit einem optionalen Selbstbehalt von 100 Pfund, und darf nur bei grober Fahrlässigkeit ablehnen — einem Maßstab, der nach Aussage des Payment Systems Regulator oberhalb einfacher Fahrlässigkeit liegt und den die Bank, nicht der Kunde, beweisen muss.
Das Dashboard der Aufsicht, aktualisiert am 30. Juli 2026, deckt die achtzehn Monate bis zum 31. März 2026 ab. In diesem Zeitraum wurden 88 Prozent des verlorenen Geldes — 316 Millionen Pfund — erstattet. Verbraucher meldeten rund 438.300 Fälle, davon 301.500 im Anwendungsbereich. Die Institute schlossen 82 Prozent innerhalb von fünf und 98 Prozent innerhalb von 35 Geschäftstagen ab. Und drei Prozent wurden abgelehnt, weil der Kunde nicht sorgfältig genug war; im ersten Quartal 2026 waren es rund 1.700 Fälle oder zwei Prozent. Zum Vergleich verweist die Aufsicht auf UK Finance, den Bankenverband, der für 2024 eine Erstattungsquote von 61 Prozent auf Privatkonten meldete — andere Definition, andere Grundgesamtheit, worauf die Aufsicht selbst hinweist.
Eine Auswertung von Frontier Economics, veröffentlicht von der Aufsicht am 1. Juli 2026, ermittelte einen Rückgang der über Faster Payments abgewickelten Betrugsschäden um rund 21 Prozent oder etwa 73 Millionen Pfund im Jahr, rund 35.000 Fälle weniger, und einen kurzfristigen Nettonutzen von 17 bis 29 Millionen Pfund nach Abzug der Kosten der Institute. Frontier wurde von der Behörde beauftragt, deren Politik es bewertete. Das Dashboard wiederum beruht auf Meldungen der sendenden Institute an Pay.UK; die Aufsicht schreibt selbst, dass ihr keine Daten der Empfängerbanken zur Gegenprüfung vorliegen, dass hausinterne Zahlungen fehlen und dass nur ein Zahlungssystem erfasst ist.
Was der Versuch belegt, ist enger und nützlicher als die Schlagzeile. Der Standardeinwand gegen die Verlagerung des Schadens auf die Banken lautete, die Kunden würden unvorsichtig. Die Kennzahl, die das zeigen würde — abgelehnte Fälle wegen unzureichender Sorgfalt —, liegt seit sechs Quartalen bei zwei bis drei Prozent. Das ist kein Beweis, dass es den Effekt nicht gibt. Es ist sein Ausbleiben an der einzigen Stelle, an der jemand zählt, und das ist mehr, als der europäische Entwurf derzeit über irgendetwas sagen kann. Die britische Entscheidung, die Erstattung verpflichtend statt empfohlen zu machen, hat die Messung als Nebenprodukt erzeugt: Wer zahlen muss, zählt, was er zahlt.
Die Zahl, auf die die europäische Regel ankommt, wird nicht erhoben
Die europäische Verteilung hängt an einem Verhalten: ob der Zahler nach der Warnung weitergemacht hat. Diese Zahl veröffentlicht niemand.
Vor dem Start nannte der European Payments Council dem Euro Retail Payments Board im Juni 2025 Erwartungswerte aus zwei Märkten, die den Dienst schon kannten. In den Niederlanden, freiwillig und mit 97 Prozent Verbreitung, ergaben sich 90 Prozent Übereinstimmung, 6 Prozent teilweise und 4 Prozent keine — zugeschrieben SurePay, einem Unternehmen, das diesen Dienst verkauft. In Frankreich, ebenfalls freiwillig, 85 Prozent volle Übereinstimmung und 15 Prozent keine — zugeschrieben SEPAmail. Im selben Atemzug warnte der EPC vor „relevant differences at PSP level in the % of close match versus no match, depending on tuning of the algorithms”. Eine Spanne von 4 bis 15 Prozent ist keine Messung, sondern der Abstand zwischen zwei Ländern und zwei Schwellenwerteinstellungen, geliefert von Anbietern, die Abgleich verkaufen — und über die Zahl der Zahler, die eine Warnung durchschreiten, sagt sie nichts.
Nichts Späteres tut es. In der Konsultation zur Fassung 2.0 des Regelwerks, die vom 1. April bis 30. Juni 2026 lief, führt die Arbeitsgruppe des EPC den Änderungswunsch 25 auf: „Add an obligation for PSPs not using a RVM to provide statistics.” Acht Monate nach Inkrafttreten der Pflicht schlug die Stelle, die das Verfahren betreibt, vor, überhaupt erst Statistiken von den direkt angebundenen Teilnehmern zu verlangen. Wie das Gesamtbild aussieht, wusste der Betreiber des Verfahrens also nicht — und die Banken, die am besten wissen, wie oft ein „no match” übergangen wird, wurden nicht gefragt.
Das Streitverfahren kommt nach der Haftung
Das zweite und dritte Glied von Artikel 5c Absatz 8 begründen Ansprüche zwischen Instituten, und die bestehen seit dem 9. Oktober 2025. Das Verfahren, über das diese Ansprüche laufen müssen, hatte dafür keinen Prozess.
In derselben Konsultation reichte der italienische Bankenverband den Änderungswunsch 11 ein: ein einheitliches Streitmanagement. Seine Problembeschreibung ist das offenste Dokument dieser Recherche. Das geltende Regelwerk enthalte kein Streitverfahren, und die Folgen, die er benennt, sind „fragmentation of practices across PSPs and countries”, „inconsistent timelines and expectations”, „operational frictions in resolving liability cases” und „financial risk in case disputes are not handled appropriately”. Vorgeschlagen werden Einleitung, Empfangsbestätigung, Prüfung, Ergebnis und Abschluss mit verbindlichen Fristen sowie „a default liability matrix”. Die Arbeitsgruppe empfiehlt die Aufnahme; Fassung 2.0 ist für Ende November 2026 vorgesehen. Der Antragsteller ist ein Verband, dessen Mitglieder auf beiden Seiten jedes solchen Anspruchs sitzen — genau deshalb ist die Eingabe glaubwürdig: Sie verlangt keine Verteilung, sie verlangt ein Verfahren.
Es ist nicht die einzige Lücke: Die Arbeitsgruppe zählte 24 größere und 3 kleinere Änderungswünsche zu einem ein halbes Jahr alten Regelwerk. Das Instrument trug eine Rechtsfolge, bevor es fertig war.
Das falsche „keine Übereinstimmung” — und wer dafür zahlt
Die Europäische Kommission hat das praktische Kernproblem früh gesehen. In ihren veröffentlichten Fragen und Antworten zur Umsetzung schreibt sie den Instituten vor, die Handelsnamen ihrer Firmenkunden zu erfassen, weil das „will be key to minimise the rate of false ‘no match’ notifications, which otherwise would dissuade payers to proceed with the placement of ‘safe’ payment orders”. Der Änderungswunsch 16 der Konsultation heißt „Support Commercial Trade Name in VOP”, und die Arbeitsgruppe empfiehlt die Aufnahme — in Fassung 2.0, fällig im November 2026. Die Kluft zwischen dem Namen, unter dem ein Unternehmen auftritt, und dem Namen auf seinem Konto — dieselbe Kluft, die den Zahlungstext auf der Kartenabrechnung unlesbar macht — soll also dreizehn Monate nach Beginn der Pflicht geschlossen werden.
Jedes falsche „keine Übereinstimmung” in der Zwischenzeit ist ein Aufwand, den jemand trägt, der nichts falsch gemacht hat. In keiner Betrugsstatistik taucht er auf, aus demselben Grund, aus dem die von einer Kontrolle abgewiesenen Kunden nie in den Zahlen erscheinen, mit denen die Kontrolle begründet wird. Es ist auch der Aufwand, auf den sich die Haftungsregel still verlässt: Eine Warnung, die zu oft anspringt, erzieht Menschen dazu, sie wegzuklicken — und wer Warnungen wegklickt, trägt den Schaden.
Was das nächste Gesetz tut und was nicht
Am 27. November 2025 erzielten Rat und Europäisches Parlament eine vorläufige politische Einigung über eine neue Zahlungsdiensteverordnung. Nach der Mitteilung des Rates müssen Kontonummern künftig „be checked against a corresponding bank account name before any transfer can take place, as is already the case for instant payment transfers taking place in euro”; Institute „will be held liable should they not fulfil their obligations in terms of using some of the preventive tools”; und wenn ein Kunde Polizei und Institut über einen Betrug informiert, bei dem sich der Täter als Mitarbeiter des Instituts ausgibt, „the PSP is supposed to refund the full amount”.
Das ist eine echte Erweiterung: Die Namensprüfung verlässt die Euro-Echtzeit-Ecke und gilt für Überweisungen allgemein, und ein benanntes Betrugsmuster bekommt einen Erstattungsanspruch. Was die Mitteilung des Rates an keiner Stelle erwähnt, ist der Zahler, der gewarnt wurde und trotzdem zahlte. Die Einigung ist vorläufig, der Text nicht verabschiedet, über die endgültige Formulierung lässt sich nichts sagen. Die angekündigte Richtung ist aber mehr Institutshaftung für Institutsversagen und für eine bestimmte Täuschung — keine Neuverteilung des Schadens, den Artikel 5c Absatz 8 derzeit beim Kunden lässt.
Sicherheitsgrade
Fest vertreten: Die zitierte Vorschrift verteilt den Schaden zwischen Instituten und legt ihn der Zahlerbank bei eigenem Versagen auf, sagt aber nichts über den gewarnten Zahler; und die Nutzer trugen 2024 nach Zahlen von EBA und EZB rund 85 Prozent der Überweisungsbetrugsschäden.
Mit vernünftiger Sicherheit: Das Fehlen eines Streitverfahrens im Regelwerk wird sich als langsame und uneinheitliche Abwicklung der Ansprüche zwischen Instituten zeigen. Das ist nicht mein Schluss, sondern die Begründung des Verbandes, der den Änderungswunsch eingereicht hat.
Vorsichtig: die Größe des britischen Effekts. Ein Markt, etwa ein Jahr Daten, eine Auswertung im Auftrag der bewerteten Behörde.
Was daraus nicht folgt
Es gibt keine europäische Zahl dazu, wie oft ein Zahler eine Warnung übergeht. Das Argument hier ist eines über Anreize, nicht über beobachtetes Verhalten. Wenn fast alle abbrechen, greift die Verteilung selten und der Entwurf ist beinahe kostenlos — und der Änderungswunsch, der Statistiken einfordert, ist genau der Grund, warum das derzeit niemand sagen kann.
Die britische Erstattungspflicht kam zusammen mit anderen Maßnahmen und einer neuen Definition dessen, was als Betrug zählt. Frontier Economics schreibt den Rückgang der Politik zu; ich habe diese Zuschreibung nicht nachvollzogen.
Und die hier dargestellte Rechtslage des gewarnten Zahlers folgt aus den Texten, nicht aus einer Entscheidung. Ich habe seit Oktober 2025 kein Urteil zu einem Zahler gefunden, der ein „no match” übergangen hat. Ein Gericht könnte die Warnpflicht als Sorgfaltspflicht mit mehr Inhalt lesen, als die Verordnung ausformuliert — etwa mit Anforderungen daran, wie die Warnung dargestellt sein muss —, und das erste solche Urteil würde die Analyse ändern.
Was der Fall lehrt
Eine Informationspflicht und eine Haftungsregel sehen auf dem Papier ähnlich aus und verhalten sich völlig verschieden. Beide lassen sich Verbraucherschutz nennen; nur eine ändert, wer am Ende ärmer ist, und nur die, die das ändert, ändert auch, wer in Vorbeugung investiert. Europa hat ein Instrument gebaut, es vor jede Überweisung gesetzt, kostenlos gestellt — und den Restschaden genau dort gelassen, wo er immer lag. Großbritannien hat den Restschaden verschoben und die Instrumente folgen lassen.
Die Messung folgt ebenfalls dem Geld, und das ist der Teil, den man leicht übersieht. Großbritannien veröffentlicht vierteljährlich, wie oft Institute dem Kunden die Schuld geben, weil ein Haus, das zahlen muss, zählt, was es zahlt. Europa hat einen Änderungswunsch, der vorschlägt, Teilnehmer künftig nach Statistiken zu fragen. Das ist kein Unterschied in der Verwaltungsqualität. Es ist das, was passiert, wenn eine Regel Information erzeugt, ohne Geld zu bewegen: Niemand weiter unten braucht die Information dringend genug, um sie zu erheben — und am Ende wird die Regel danach beurteilt, ob sie umgesetzt wurde, nicht danach, was sie bewirkt hat.
Die Namensprüfung ist eine gute Idee, billig geliefert, auf den richtigen Betrug gerichtet, und sie wird Schäden verhindern, die sonst nichts verhindert hätte. Sie ist zugleich das klarste jüngere Beispiel für eine Lesegewohnheit, die sich lohnt: über die Pflicht hinweg bis zu dem Absatz lesen, der sagt, wer zahlt, wenn die Pflicht erfüllt war und das Geld trotzdem weg ist. Dieser Absatz ist die Politik. Alles davor ist die Bedienoberfläche.