

- David Voss
- Head of Payments and Receivables, GPS EMEA, Bank of America

- Elliott Blissett
- Co-Head of UK Corporate Sales, Bank of America

- Tom Alford
- Deputy Editor, Treasury Management International
PSD3 and PSR Taking European Payments to the Next Level
PSD3 and the accompanying PSR are cited as a system-wide upgrade of Europe’s payments infrastructure, driving improvements in performance, consistency and accountability. Bank of America’s David Voss, Head of Payments and Receivables, GPS EMEA, and Elliott Blissett, Co-Head of UK Corporate Sales, explain how corporate treasurers can make the most out of the changes.
The promise of major improvements in performance, consistency, and accountability across the European payments ecosystem positions the European Union’s (EU) Third Payment Services Directive (PSD3), and its companion piece, the Payment Services Regulation (PSR), as more than just a regulatory update. If they deliver what the industry expects, then treasurers in the region have something worth appreciating.
As the new regulation shifts from ‘rules-based compliance’ to ‘outcome-based supervision’, regulators will be focusing on how the region’s payment service providers (PSPs) perform, not just whether they have met technical requirements. This means the likes of API reliability, customer experience, and operational resilience become key measures of success. For treasurers, it places usability and service delivery at the forefront.
A quick PSD3 and PSR primer
There are two key legislative measures to consider here. PSD3 is a directive that focuses purely on prudential matters within payments, such as licensing, authorisation, capital requirements, and supervision of PSPs. As a directive, every EU member state will need to transpose PSD3 requirements into their own local national law.
PSR is the framework that governs day-to-day rules in the EU payments space. It covers matter such as transparency, open banking, customer authentication and fraud liability. It will apply identically across all EU member states with no variable transposition into local law.
PSD3 final compromise texts were published in April 2026. With the rules expected to formally apply 21 months after publication, this suggests a full compliance and enforcement date of late 2027. By this stage, all EU member states must have transposed the Directive into their national law.
PSR will apply across the EU 21 months after entering into force. With formal adoption of the text and its publication being finalised in 2026, PSR is expected to come into full effect in early to mid-2028 (subject to change).
While the general take on the shift from PSD2 to PSD3 is that it is an evolution, for Voss, there are aspects of it that he says could be seen as “revolutionary”. With PSD3 operating alongside PSR, he sees “an interesting phenomenon” in that PSR’s direct applicability will “reduce the opportunity for different implementations between countries”. This, he believes, “should help with the harmonisation of PSR as it approaches across borders”.
Another key impact of this tandem regulation will also “raise the bar for open banking and how data is shared”, comments Voss. He believes that PSD3 and PSR will have a positive impact on corporates by adding weight to open banking, and introducing measurable standards for API performance, availability, and access. Here, regulators and users alike will be able to rely more on metrics, reporting, and real-world performance data.
This will almost certainly increase transparency around areas such as service availability, fees, and customer outcomes. It positively signals a clearer outlook on reliability, driving how APIs are supported and how they perform, adds Voss. “Additionally, it places a greater expectation on all participants to strengthen their fraud prevention measures.”
Indeed, where PSD2 introduced open banking and security concepts such as strong customer authentication, this was “just a door opener”, continues Voss. “PSD3 matures those concepts, bringing a more uniform approach that overlaps with other measures such as the EU’s digital identity wallet and instant payment regulations. These are now more formally and distinctly linked.”
Seeing the benefits
Corporate treasurers will begin to realise a much stronger proposition in terms of connectivity and security in APIs. Whereas there was some leeway previously for banks in terms of the nature and delivery of their solutions, Voss states that PSD3 and PSR now place more obligations on banks to support a “more standardised, higher performing, more resilient API offering”.
By increasing responsibilities towards transparency, where banks will be required to openly publish their API performance data, it will help clients make informed decisions on API adoption, providing more confidence in data exchanges that use these tools.
As part of the anticipated increase in confidence in APIs, PSD3 and PSR coincidentally support the continued adoption of, and new use cases for, real-time payments, says Blissett.
A challenge that corporates can experience when working with multiple banks across the region is that of meeting the industry standards those institutions are required to meet depending on the location of their business, The new framework aims to reduce fragmentation in national implementation, creating a more consistent operating environment for PSPs, thus making it easier for all providers to scale services across borders.
As those PSPs are increasingly held to equivalent standards, it closes regulatory gaps and supports fairer competition. Harmonisation also reduces adoption costs for corporates, lowering a barrier to entry, as many seek to become API-first organisations. In turn, this opens the door to what Blissett refers to as “on-time” data and payments.
On-time places the idea of real-time in the context of client necessity. Data exchanges are executed as and when they are needed by the client, not when the systems and structures they are using dictate that they can be made. “PSD3 and PSR create a more constructive environment for corporates to think about the value of on-time data and reporting,” he explains.
Understand and align
The new regulatory package attracts some caveats. The expansion of verification of payee (VoP), for example, has the potential to introduce increased friction, suggests Blissett. At present, the brakes are applied in a targeted way, in that if the account name and account number don't match, it creates an appropriate moment to pause and check.
One of the unintended consequences of PSD3 and PSR – or as Blissett puts it, “an aspect we weighed carefully as an institution” – is that the deployment of tools to support VoP must be considered and intentional, to avoid an increase in unnecessary payment failures.
“We’ve taken a path that enables our clients to perform that account validation step both as a part of the payment process, and as part of their supplier onboarding,” he explains. “We recommend, and will continue to under PSD3 and PSR, that corporates ask their banks how they are deploying VoP, so they understand and can align with those processes.”
Corporates should now be thinking about other ways in which PSD3 and PSR will impact their business and treasury function, says Blissett. “Actual impact will depend to a degree on their business type, sector, and region,” he notes. “But corporates either using or about to use APIs will be affected by the regulatory changes. We think strong customer authentication, VoP, for example, will also impact most companies. To avoid some of those extra false positives, they should ensure they have the right master vendor data for their outbound payments.”
Likewise, corporates, Blissett says, should ensure that their customers have the correct account details for them. “And when a situation such as a legal name change arises, to avoid that additional friction, companies will need to co-ordinate between their customers and banks, ensuring all data is in sync.”
But Blissett notes that a number of companies, predominantly within the technology sector, not only initiate payments but also store value on behalf of their customers. Harmonisation of the licensing regime may create an impact here, he suggests.
PSD3 replaces the old E-Money Directive. This eliminates separate regulations for electronic money institutions (EMIs) by merging them into payment Institutions (PIs) and establishing a uniform set of rules. While this effectively makes it easier for payment companies to work across borders, all existing EMIs and PIs must submit new applications to their national regulators. A circa. 24-month grace period to transition to the new PSD3 authorisation will be offered once it becomes fully active.
Now is the time
The companion pieces of PSD3 and PSR push open banking to the fore, but demand increased reliability and scalability, as clients prioritise security and transparency. This will mean banks and other providers will have to invest more in technology, resilience, and operational controls. There is a possibility that as standards rise, increased market consolidation occurs, especially as some smaller players may struggle in the face of increased pressure to deliver.
By and large, the forthcoming rule changes favour payment services end users. The regulation clearly places more control and visibility with the corporate user. “Now is a good time to be reviewing accounts payable data,” suggests Voss.
“But it’s actually a good time to be reviewing internal processes and approvals too, looking at how these can be made to operate in an end-to-end way, because once the new rules come into play, there will be additional types of payments, and new opportunities for managing them in real-time. And that means new opportunities for treasury teams to move even closer to their data.”



