I KPSD-regi er svig alle uberettigede overførsler, som er iværksat og gennemført.
Konkret fremgår det af EBA Guideline pkt. 1.1., at:
“For the purposes of reporting statistical data on fraud in accordance with these Guidelines, the payment service provider should report for each reporting period:
a. unauthorised payment transactions made, including as a result of he loss, theft or misappropriation of sensitive payment data or a payment instrument, whether detectable or not to the payer prior
to a payment and whether or not caused by gross negligence of the payer or executed in the absence of consent by the payer (‘unauthorised payment transactions’); and
b. payment transactions made as a result of the payer being manipulated by the fraudster to issue a payment order, or to give the instruction to do so to the payment service provider, in good-faith, to a payment account it believes belongs to a legitimate payee (‘manipulation of the payer’). “
Det fremgår af EBA Guideline pkt. 1.2., at:
“For the purposes of Guideline 1.1, the payment service provider (including the payment instrument issuer where applicable) should report only payment transactions that have been initiated and executed (including acquired where applicable). The payment service provider should not report data on payment transactions that, however linked to any of the circumstances referred to in Guideline 1.1, have not been executed and have not resulted in a transfer of funds in accordance with PSD2 provisions.”
Indberetning af svig skal dermed ske, uagtet om det efterfølgende har vist sig muligt at inddrive hele eller dele af beløbet.
Konkret fremgår det af EBA Guideline pkt. 1.6(a), at:
“Total fraudulent payment transactions’ refer to all transactions mentioned in Guideline 1.1, regardless of whether the amount of the fraudulent payment transaction has been recovered.”
Det betyder, at det fulde beløb, som på svigagtig vis forlader f.eks. en kundes betalingskonto, skal indberettes i den korrekte fane som del af det halvårlige svigagtige beløb. Bliver en overførsel derimod blokeret af f.eks. en banks interne fraud monitorering, skal beløbet ikke tælle med i opgørelsen af svig.
Dette sidste punkt følger af EBA Guideline pkt. 2.4:
“The payment service provider should report only payment transactions that have been executed, including those transactions that have been initiated by a payment initiation service provider. Prevented fraudulent transactions that are blocked before they are executed due to suspicion of fraud should not be included.”
Til illustration følger her et hypotetisk eksempel:
En kunde får uberettiget anvendt sit betalingskort for 10.000 kr. Kunden skal selv dække 375 kr. som følge af selvrisikoen, jf. § 100, stk. 3, i lov om betalinger. Efterfølgende er det muligt for kortudstederen at inddrive 5.000 kr. Uanset, at kundens tab er 375 kr., og bankens tab er 4.625 kr., skal det fulde beløb på 10.000 kr. indberettes.