Money Left Your Account and You Did Not Authorise It: What the Law Requires
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
An unauthorised payment is not a dispute about a purchase that disappointed you. It is a transaction you did not consent to at all, and the rules that govern it are much faster and much more favourable than most people realise — with two exceptions that decide the majority of contested cases.
The deadline is the next business day
Under regulation 76 of the Payment Services Regulations 2017, where an executed payment transaction was not authorised, the payment service provider must refund the amount to the payer and, where applicable, restore the debited account "to the state it would have been in had the unauthorised payment transaction not taken place".
The timing is the part worth memorising: the refund is due by the end of the business day following the day on which the provider becomes aware of the unauthorised transaction.
Two things follow from that wording. The clock starts when the provider becomes aware, which is why reporting promptly and provably matters more than anything else you do. And "restore the account to the state it would have been in" is broader than returning the money — it reaches the consequences, such as charges or interest that the missing money caused.
Your liability is capped at £35, and then it is not
Regulation 77 sets the customer's share. The payer may be liable up to a maximum of £35 for losses arising from unauthorised transactions resulting from the use of a lost or stolen payment instrument, or from misappropriation of it.
Then come the exceptions that decide real cases. The cap does not protect a payer who has acted fraudulently, or who has with gross negligence failed to comply with regulation 72 — the obligations to use the instrument in accordance with its terms and to keep personalised security credentials safe.
Gross negligence is a high bar and a genuinely contested one. It is not the same as carelessness. But it is where a bank that does not want to refund will argue, and it is why the specific facts of how credentials were disclosed matter far more than the amount involved.
Unauthorised is not the same as "I regret this"
Three situations look similar to a customer and are handled under completely different rules. Getting the category right is the difference between a next-business-day refund and a months-long argument.
- Unauthorised transaction. You did not consent. Regulation 76 applies, and the refund timetable above is the standard.
- Authorised push payment fraud. You were deceived into instructing the payment yourself. You did authorise it, so regulation 76 does not apply on its face, and reimbursement runs through a separate regime with its own tests and limits.
- A purchase that went wrong. You authorised it and the seller failed you. That is a chargeback or, on a credit card, a statutory claim — a different mechanism entirely.
The second category is where most losses now sit, and the fact that you pressed the buttons yourself is precisely what makes it a different legal question. Being clear about which of the three you are in, before you report it, prevents a claim being assessed under the wrong test.
What to do, in order
- Report it the moment you see it. The provider's obligation is timed from when it becomes aware. Every hour before you tell them is an hour the clock is not running.
- Report through a channel that creates a record. In-app messaging and written confirmation are worth more later than a phone call you cannot evidence.
- Say the word "unauthorised" and say why. Describe what you did not do. If you never saw the transaction, never approved a code, and never shared a credential, say each of those explicitly — they are the elements of regulation 72 in reverse.
- Do not repay or "return" anything to anyone who contacts you about it. A follow-up call offering to help recover the money is a common second stage of the same fraud.
- Ask for the reason in writing if the refund is refused. A refusal is normally an assertion of fraud or gross negligence, and the provider should be willing to say which.
The refund can be provisional, and that is normal
A refund made under regulation 76 is not always the end of the matter. A provider that refunds first and investigates afterwards may, if its investigation concludes the transaction was in fact authorised or that the exceptions in regulation 77 apply, seek to reverse the credit.
That is not a trick, and it is the direct consequence of a rule that requires payment by the end of the next business day: a deadline that short means the money often moves before the facts are established. The practical implication is simply not to treat a fast refund as a final adjudication. Keep the correspondence, keep the reference number, and do not spend a refund you may be asked about.
If a reversal does come, it should come with a reason, and that reason is what a complaint attaches to. Ask which limb is being relied on — fraud, or gross negligence under regulation 72 — because they are different allegations requiring different evidence.
What "gross negligence" arguments usually turn on
Refusals cluster around a small number of factual patterns, and knowing them helps you describe what happened accurately rather than defensively.
- Whether a one-time code was disclosed, and what the message said. Codes normally arrive with text stating what they authorise. Whether that text was displayed, and what it said, is often the whole case.
- Whether the credential was shared with someone claiming to be the bank. Being deceived is not automatically gross negligence, and the distinction between being tricked and being careless is exactly what is in dispute.
- How the device was secured, and whether the instrument was reported promptly once noticed. Regulation 72 is about using the instrument in accordance with its terms and keeping credentials safe.
Describe the sequence plainly and in order. A precise account of what you were shown and what you did is more persuasive than an assertion that you did nothing wrong.
Why the structure of your accounts matters more than the rules
Rules decide who ultimately bears a loss. They do not decide whether your rent goes out on time while the argument runs. That is a structural question, and it is answered by not keeping everything in one place.
Holding the balance you actually need across more than one provider, and keeping the account that receives your income separate from the one you spend from day to day, converts a frozen account from a crisis into an inconvenience. Our guide to comparing accounts covers picking the second one, and the neobank safety guide covers which institution is actually holding the money in each case.
One thing this does not cover
These are UK regulations. Equivalent protections exist across the EEA under the corresponding EU framework, and the two are now separate instruments that can drift apart. If your provider is licensed in another country — which for a great many app-based accounts it is — the rules that bind it are that country's, not the ones above. How to check a bank licence is the way to find out which set applies to you before you need to know.
This is general information, not legal advice. The regulations linked above are the authority.