Guidance · PSR Article 83a
Intelligence sharing for fraud prevention
PSR Article 83a turns cross-institution fraud intelligence sharing into a formal supervisory expectation. Built on five years of running live networks, this guide translates the regulation and distils our operational experience.
Get the guideInside this guidance
Foreword
The shift from optional to expected
Financial crime moves faster than the controls most teams have in place to catch it. Most fincrime teams still work in silos — not by choice, but because collaboration is operationally and technically complex. We built Salv Bridge to fix that.
We have been building cross-border intelligence sharing networks and stress-testing them against the regulatory standards they must meet. Today, Salv Bridge connects more than 100 financial institutions across the EU and UK, running live exchanges every day. In one market, the median fraud response time has dropped to 14 minutes. Across the same network, participating banks have prevented an estimated €3 million in customer losses.
The shift this guide covers, from optional collaboration to a formal obligation under the EU Payment Services Regulation (PSR) Article 83a, is both operational and legal. The PSPs reading it will need to act on both fronts. The direction of regulatory travel is clear. Regulators will ask: show us exactly how you share intelligence.
PSR Article 83a is the legislative answer to a question many fraud and payments teams have been carrying for years: when can we share what we know about a fraud with another payment service provider, and on what basis? The framework is clear in direction. It is, in places, still being clarified in practice, particularly on the forthcoming EBA technical standards, on the precise contours of "strictly necessary", and on how the arrangement interacts with GDPR and the broader PSD3/PSR package.
Two practical points sit at the centre of this guidance. The first is that anchoring the arrangement within a formalised Article 83a framework substantially strengthens the GDPR position: the processing remains under Article 6(1)(f), but the EU legislator's express recognition of fraud-specific sharing does much of the heavy lifting on the necessity and balancing prongs of the legitimate-interests assessment that PSPs otherwise carry alone. The second is that participation is becoming a supervisory baseline — non-participation is increasingly treated as a gap finding rather than a neutral position.
This is the working document we use with the institutions joining Salv Bridge, formed over five years of operation. Where the rules are still evolving, we have flagged it. Where they are settled, we have said so plainly. For institutions whose remit also covers AML obligations under AMLR Article 75, our companion guide treats that framework in the same depth. If you have questions, or want us to sense-check your approach, get in touch.
Executive summary
Seven things institutions need to understand
Intelligence sharing is shifting from optional to a structured, enforceable obligation
PSR Article 83a establishes the framework for PSPs. Informal cooperation will not meet supervisory expectations.
The legal foundation is multi-layered
PSR creates a fraud-sharing duty; AMLR Article 75 creates a parallel AML/CTF framework; both anchor GDPR lawfulness with their own governance requirements.
More data sharing is not better
Article 83a is anchored in the strictly necessary standard. Scalable solutions depend on standardisation and clear suspicion thresholds, not volume.
Consortium-based models are structurally necessary, not just efficient
Only coordinated approaches deliver consistent rules, shared governance, and scalable network effects.
Fraud prevention is extending beyond the banking perimeter
The PSR–DSA interaction points toward cross-sector cooperation with digital platforms where fraud originates.
Data sharing is becoming core to liability management
It supplies the evidentiary basis for reimbursement decisions under Article 59 and for recourse claims between providers.
The framework is directionally clear, operationally still evolving
Institutions that establish well-governed, adaptable frameworks now will be best positioned to comply as standards mature.
Section 03
The legal foundation
The EU Payment Services Regulation (PSR), specifically Article 83a, will require payment service providers to exchange fraud-related information through formalised, technology-enabled arrangements, on terms developed in forthcoming EBA technical standards. The political agreement on the PSD3/PSR package was concluded in November 2025; the PSR has not yet been published in the Official Journal.
Non-participation is no longer a neutral position.
Supervisory expectations are hardening in parallel. Regulatory authorities are already asking, in the course of routine examinations, whether institutions have implemented structured intelligence sharing arrangements. Institutions that cannot demonstrate a formalised, auditable sharing capability will find that position progressively harder to defend.
PSR Article 83a and AMLR Article 75 — complementary, not sequential
PSR Article 83a addresses a narrower, fraud-specific perimeter: mandatory participation in formalised fraud intelligence sharing arrangements for PSPs. AMLR Article 75 authorises broader AML/CTF partnership sharing on a permissive basis. The two regimes are complementary rather than sequential; both may apply to the same institution, and supervisors will scrutinise which framework each exchange is conducted under.
At the European level, supervisors and policymakers are converging on a "hub and spoke" or "network of networks" model, with a European layer interlinking national or bank-consortia data sharing setups. Each existing and newly developed national or regional arrangement is expected to contribute to that landscape.
TIMELINE
The PSR political agreement was reached in November 2025. Publication in the Official Journal is expected Q4 2026; the regulation enters into force 20 days later. Substantive obligations, including Article 83a, are expected to apply from early 2028. References in this guidance to obligations and powers under Article 83a are forward-looking; institutions building governance now will be in position to operate compliantly from that date.
Section 04
Five guiding principles
PSR Article 83a creates a direct obligation for PSPs to participate in formalised fraud intelligence sharing arrangements. It does not tell institutions how to share intelligence well. These are the principles that make the difference between an arrangement that satisfies Article 83a in form and one that holds up under examination.
Suspicion-led collaboration
Compliant sharing relates to a specific case in which there is reasonable suspicion of fraud. It is not triggered by general curiosity; it is request-based and case-specific, articulable ex ante in a request another institution could not reasonably read as fishing.
Proportionality and strict necessity
Each request must be limited to the data strictly necessary for the specific investigation at hand — defined and scoped before the request is sent, not justified after.
Reciprocal duty to act
Each institution commits to responding to valid requests within agreed timelines. A partnership in which only some members respond is not a functioning partnership — the network only delivers value if all members treat this seriously.
Security-first design
Exchanges take place on a secure, encrypted platform with role-based access. Pseudonymisation, activity recording, and information minimisation are enforced by architecture rather than by user restraint.
Auditability and transparency
Every exchange is captured in a complete, timestamped, traceable record — the functional test being whether the institution can produce, at short notice, a full account of every request sent, every response received, and every necessity assessment made.
Section 05
When and why to collaborate
Financial crime is not contained within a single institution. Organised fraud networks move funds across banks, EMIs, PSPs, and CASPs before any one institution can respond. No single institution has the full picture from its own transaction data alone. PSR Article 83a creates a direct obligation for PSPs to address this through formalised sharing arrangements. Structured intelligence sharing allows institutions to confirm or rule out suspicions faster, identify cross-institution patterns, and act before funds are moved beyond recovery. The obstacles today are no longer legal or technical — they are governance-related.
Why intelligence sharing is best organised at consortium level
Consortium-based approaches provide structural governance advantages that bilateral arrangements cannot replicate: network effects that increase detection value with each additional participant; standardisation of data formats and definitions; legal efficiency through shared DPIAs and partnership agreements that substantially reduce the compliance lift on each individual participant; and cost efficiency through shared infrastructure. An institution that participates in a consortium-level arrangement — with its DPIA, partnership agreement, and supervisory notification all in order — is in a materially stronger position under regulatory examination than one relying on a series of bilateral arrangements stitched together.
Patterns that will not meet supervisory expectations
- Bulk data sharing — sharing large datasets without linkage to specific cases or articulated suspicion. Directly inconsistent with the strict-necessity standard and GDPR Article 5(1)(c).
- No audit trail — insufficient documentation of what was shared, when, by whom, and on what basis.
- Informal collaboration channels — email-based intelligence exchange is not a compliant alternative. It is precisely the practice Article 83a is designed to replace.
- No documented suspicion threshold — the absence of defined criteria for what constitutes reasonable suspicion of fraud leads to inconsistent over- and under-sharing across analysts. Consortium-level agreement on a sufficient suspicion standard, documented in shared SOPs and consistently applied, is what supervisors expect.
The full guidance document tells you what to do next
Fill in the form and someone from our team will be in touch. We'll talk through where you are, what to do next, and then send you the full guide.