A Consultation the UK Didn't Need to Have
On 30 July 2026, the UK's Payment Systems Regulator published CP26/2, a consultation proposing two changes to Specific Direction 17, the rule underpinning Confirmation of Payee (CoP) — the check that confirms a payee's name matches their account before a bank transfer goes through. First, remove SD17's scheduled expiry of 1 November 2026 so the obligation becomes permanent. Second, and more consequentially, fold every payment provider currently offering CoP voluntarily — mostly fintechs — into a new mandatory "Group 3," ending the two-tier system in which banks were directed to run checks and challengers were merely encouraged to. According to the PSR, more than 320 organisations already run CoP, processing over 2 million checks a day; the consultation closed on 20 August 2026.
It's a sensible, incremental fix to a gap that shouldn't have existed this long. It's also five years behind where India's payments regulator started.
India Never Had a Voluntary Tier
When NPCI mandated payee-name verification for UPI, it applied to every app on the rail from day one — banks, PhonePe, Google Pay, Paytm, all of it, no opt-in category to later graduate out of. The operative circular, NPCI/UPI/OC No-101A/2025-26, issued 24 April 2025, required that "only the ultimate beneficiary's name (Banking name as fetched from Validate Address API)" appear on the pre-transaction screen, banned custom aliases and QR-code display names, and disabled any app feature letting users edit the beneficiary label. Enforcement phased in through 2025 into full effect across the ecosystem by mid-2026.
The structural reason India could move faster is architectural, not just regulatory will. UPI runs on a single NPCI-operated switch with one shared Validate Address API that every bank and every third-party app must call. Mandating a name check meant flipping a switch at the rail level. The UK's Faster Payments and CHAPS network has no equivalent single chokepoint — CoP has to be implemented separately inside hundreds of individual banks' and fintechs' systems, which is exactly why the PSR built a phased, voluntary-then-mandatory on-ramp instead of a single directive. That's a fair account of why London got here later: it isn't regulatory timidity, it's a more fragmented rail.
What the Fraud Numbers Say
The RBI's FY26 data gives the mandate a real before-and-after. Fraud value in cards and digital payments fell to ₹29 crore across 293 cases in FY26, against ₹517 crore (13,332 cases) in FY25 and ₹1,452 crore (28,836 cases) in FY24 — a roughly 98% collapse over two years. That coincides with, but isn't proven solely caused by, the name-check mandate; NPCI also raised P2M transaction-limit thresholds and RBI-backed initiatives like MuleHunter.AI expanded mule-account detection over the same window. Digital-payment fraud is also a small slice of a bigger, worse picture: total banking fraud value actually rose 46% to ₹48,021 crore in FY26, driven almost entirely by large legacy advances-related cases, not consumer payments. The lesson isn't "one control fixed everything" — it's that a narrowly targeted, rail-level intervention produced a measurable, isolated improvement in exactly the fraud category it was built for.
The Case for Not Over-Reading the Win
The steelman for the PSR's cautious, consultation-first approach deserves more credit than "India was faster" implies. A one-size-fits-all mandate imposed abruptly on hundreds of independently-built systems risks disproportionate compliance cost on smaller PSPs that don't share India's centralized rail — a fintech running CoP against its own bespoke integration faces a materially different build than a UPI app calling one standardized API NPCI already operates. Forcing Group 3 firms onto the same direction as major banks without differentiated timelines could entrench incumbents by pricing out smaller challengers, the opposite of what a pro-competition regulator should want. The PSR is right to consult rather than direct by fiat.
But the direction of travel is correct, and India's experience is the strongest available evidence for it: centralizing identity verification at the rail level, rather than leaving it to each participant's discretion, is where the fraud reduction actually comes from — not from a patchwork of voluntary best practice. The RBI is now trying to extend that logic further with the Digital Payments Intelligence Platform, a cross-bank real-time intelligence-sharing layer being piloted with a small cohort of banks under RBI Innovation Hub, though its rollout has itself been slower than the finance ministry would like.
The Right Takeaway for the PSR
CP26/2 should pass, and Group 3 firms should be brought in — but the PSR should borrow India's phasing discipline as much as its policy substance: a defined circular with a compliance runway, not an abrupt switch, and proportionality for smaller PSPs genuinely building from scratch rather than calling a shared API. Mandatory fraud-prevention infrastructure works best when it's built into the rail everyone already depends on, not bolted onto each participant separately after the fact.