The Contingent Reimbursement Model Code, almost always shortened to the CRM Code, was a voluntary scheme that most high street banks signed up to, promising to reimburse customers who were tricked into paying a fraudster by bank transfer1. It came into force in May 2019 and was retired on 7 October 2024, when mandatory reimbursement rules replaced it2. If you authorised a fraudulent payment on or after 28 May 2019 and before 7 October 2024, and your bank or provider was a signatory, the code still governs how your claim is treated today3.
The code mattered because of the type of fraud it addressed. An authorised push payment (APP) scam is one where the victim themselves presses the button: they are deceived, by a fake invoice, a bogus investment, a fraudster posing as their bank, or a romance scam, into transferring money to an account the fraudster controls. Because the customer authorised the payment, ordinary unauthorised-fraud protections did not apply, and before the code many banks simply refused to refund. The code aimed to reduce both the occurrence and the impact of APP scams, and to give people the confidence that if they fell victim and had acted appropriately, they would be reimbursed1.
What the CRM Code was and who it protected
The code was born out of a problem the Payment Systems Regulator (PSR) had identified and could not solve alone. In 2018 the PSR set up a steering group of industry and consumer representatives, led by an independent chair, to develop a way of reimbursing APP scam victims1. The result was the CRM Code, which the Lending Standards Board then oversaw, setting standards for signatory payment service providers, a group including the largest banks in the UK1. An industry code had been available from September 2018 in an earlier form, which the Financial Ombudsman Service could already take into account when deciding complaints5, and the final code came into force in May 20191.
Who it protected is a distinctive feature. The code covered consumers, micro-businesses and small charities1, which is broader than many people assume. A sole trader tricked by a fake invoice, or a small charity deceived by a cloned supplier's bank details, could claim under the same framework as an individual. Larger businesses were outside it. The code's central promise was contingent reimbursement: signatory payment service providers voluntarily reimbursed APP scam victims2, provided the victim had met the standards the code expected of them.
The code applied to transfers between 28 May 2019 and 7 October 20246. That date range is the single most important fact on this page: it decides whether a claim today is assessed under the code or under the mandatory rules that followed. If the payment was made before 28 May 2019, neither the code nor its successor applies, though a complaint to the bank and then the ombudsman remains possible on other grounds.
Which payments it covered: Faster Payments, CHAPS and internal transfers
The code applied to APP fraud executed across three routes: the Faster Payments System, CHAPS, and an internal book transfer3. In plain terms, that covers almost every way of moving money between UK bank accounts: a standard online or app bank transfer (Faster Payments), a same-day high-value CHAPS payment, and a transfer between two accounts held at the same bank, which never leaves the bank's own books3. The code also had additional provisions around prevention, detection and commitments to improving customer education4.
What the code did not reach was everything else. Payments made by debit or credit card follow the card schemes' chargeback rules instead, and a card payment may give rise to a section 75 claim under the Consumer Credit Act 1974 for credit card purchases. International transfers sat outside the code too, as did payments to accounts outside the UK. The distinction between authorised and unauthorised payments also matters: the code was only ever about payments the customer was tricked into making themselves. Money taken from an account without permission is unauthorised fraud, and payment providers almost always reimburse victims of unauthorised fraud under separate rules7.
Confirmation of Payee, the name-checking service, arrived during the code's lifetime and changed how these scams worked. The PSR's work on Confirmation of Payee was expected to see nearly all transactions made via Faster Payments and CHAPS covered by the name check by October 20248, which is one reason the code's exclusions around warnings became a live issue in so many claims.
Which banks signed up: ten banking groups, about 90% of transactions
The code was voluntary, and that shaped everything about it. Most high street banks signed up6, but not every provider did. The government's policy statement recorded that the code had been signed by ten banking groups, covering 90% of relevant transactions2. A later PSR policy statement described the same picture in slightly different terms: ten payment service providers, representing 19 consumer brands and over 90% of authorised push payments, had signed up4.
What that meant in practice was that the protection a customer received depended on which bank sent the payment. Someone banking with a signatory could expect their claim to be assessed against the code's standards; someone whose bank had not signed was left arguing on general grounds, such as whether the bank had acted fairly or followed good industry practice. The ombudsman could still look at those cases, but the firm was not bound by the code's framework.
The voluntary nature of the code was also why the PSR eventually moved to mandatory rules. In its consultation on measures to protect APP scam victims, the PSR proposed that there should be mandatory reimbursement for victims of scams who have done nothing wrong9. The new reimbursement requirement that followed reaches over 1,500 payment service providers, a far wider net than the code's ten signatory groups4. For context on scale, the PSR's performance data direction named 14 payment service provider groups required to report APP scams data: AIB, Barclays, HSBC, Lloyds, Metro Bank, Monzo, NatWest group, Nationwide, Northern Bank, Santander UK, Starling, the Co-operative Bank, TSB and Virgin Money10.
Blameless victims were usually reimbursed in full
The code's core test was whether the customer had acted appropriately. If the CRM Code covered a payment you, or your business, made to a fraudster, the bank involved would usually reimburse you6. The code set out what it expected of customers and what it expected of firms, and where both had met their side, a blameless victim was normally refunded in full. The Financial Ombudsman Service, in its response to a review of the code, said it believed the CRM Code set clear expectations of and standards for firms to meet, as well as a clear framework for determining when they should reimburse victims of APP scams11.
How well this worked in practice is harder to say, and the figures vary. In 2022, 66% of APP fraud losses within scope of the CRM Code were reimbursed to the victim4. That is a substantial share, but it also means roughly a third of in-scope losses were not refunded, and the outcome depended heavily on which bank a customer happened to use. The ombudsman's casework found that some firms were not providing a clear rationale for their conclusions, and in some cases firms did not mention the code at all in their final response letters to customers11, which made it harder for people to understand, or challenge, a refusal.
Broader statistics give a sense of how often fraud victims get their money back. The Crime Survey for England and Wales found that, in the year ending March 2025, the victim was fully reimbursed in 70% of cases, amounting to 2.1 million incidents, compared with 40% of all other fraud12. Those figures cover all fraud, not just APP scams, but they show the same pattern: reimbursement is common but not guaranteed, and the difference often turns on the rules that apply to the particular payment.
When a bank could refuse: the exclusions
The code was contingent reimbursement, not unconditional reimbursement, and the exclusions were where most disputes landed. The Financial Ombudsman Service sets out the main exceptions: a bank could refuse where the customer did not pay attention to effective warnings, or had reason to suspect they were falling victim to a scam6. In other words, if the bank showed the customer a scam warning at the point of payment and the customer carried on regardless, or if the circumstances were such that a reasonable person would have suspected fraud, the bank could conclude the customer had not met the standard expected of them.
Two things are worth knowing about how this worked in practice. First, the test was about effective warnings, not just any warning. A generic message that flashed up briefly might not count; the ombudsman looked at whether the warning was clear enough to put an ordinary person on alert. Second, the code also expected firms to meet their own standards, on prevention, detection and education4, and a firm that had failed on its side of the bargain was in a weaker position to blame the customer. The ombudsman's finding that some firms did not explain their reasoning, or even mention the code, in final response letters11 suggests refusals were not always as well founded as they appeared.
Partial refunds were also possible. In one ombudsman case study, a bank considered a complaint under the CRM Code and refunded 50% of the customer's loss, having accepted it had not provided a scam warning before the payment was made13. Where both sides fell short of the code's standards, splitting the loss was one way the framework produced outcomes.
Where the CRM Code does not apply
The code's boundaries are as important as its protections. It did not apply to:
- Payments made before 28 May 2019 or on or after 7 October 2024. Earlier payments fall outside it entirely; later ones fall under the mandatory rules3.
- Payments by card. Debit and credit card payments are covered by the card schemes' chargeback process and, for credit cards, potentially section 75 of the Consumer Credit Act 1974, not by the code. With chargeback, you ask your card provider to attempt to recover the payment, and it is worth checking with your card provider how the scheme rules apply to your card, whether internet transactions are covered and what the time limit for making a claim is14.
- Unauthorised transactions. Money taken without the customer's permission is unauthorised fraud, which payment providers almost always reimburse7, under different rules from the code.
- International payments. The code covered transfers between UK accounts through Faster Payments, CHAPS and internal transfers3.
- Larger businesses. Only consumers, micro-businesses and small charities were covered by the code1.
The distinction between authorised and unauthorised payments is the one that catches most people out, and it is worth being clear about it before making any claim. If you gave the fraudster your card details, or clicked a link and entered a code, the analysis may be different again. The guides on authorised and unauthorised payments and on what to do if you gave your card details to a fraudster explain the differences.
How to claim for a scam payment made while the code applied
A claim for a payment made while the code applied starts, as it always did, with the bank. The process is straightforward in outline:
- Contact your bank as soon as you realise you have been scammed. The guide to first steps for victims covers what to do straight away, including reporting to the police.
- Explain that you were the victim of an APP scam and ask for the claim to be considered under the CRM Code. The code applied to payments made on or after 28 May 2019 and before 7 October 20243, so state the date of the payment.
- Give the bank the details it needs: the payment reference, the account the money went to, and how the scam unfolded. The code set a 15-day time limit for reimbursement4, so a properly handled claim should not drag on indefinitely.
- Ask for a final response letter if the bank refuses, or offers only a partial refund. The ombudsman's casework found some firms did not mention the code in these letters11, so check whether the bank has actually engaged with the code's tests.
- Take the complaint to the Financial Ombudsman Service if you remain unhappy. You can do this within six months of the final response letter.
One warning belongs here. Scammers may contact you by email, post or a phone call and claim to be from the PSR, or use the name of an employee, to trick you into giving information or money15. A genuine claim under the code runs through your bank and, if needed, the ombudsman. Nobody from the regulator will contact you out of the blue about a refund. The guide on how to check your bank is really contacting you covers the same risk from the bank's side, and recovery room scams covers the firms that promise to get lost money back for a fee.
Complaints and the Financial Ombudsman if a bank said no
If a signatory bank refused a claim under the code, the Financial Ombudsman Service was, and remains, the next step. The ombudsman decides individual cases on the basis of what is fair and reasonable in all the circumstances, taking into account the relevant law and regulations, regulators' rules, guidance and standards, codes of practice including industry codes such as the CRM Code, and what it considers to have been good industry practice at the time11. In its guidance on scam payments, the ombudsman lists what it considers: the relevant law, regulations including the CRM Code and the Faster Payments Scheme and CHAPS reimbursement rules, good industry practice and relevant regulatory guidance, and the account's terms and conditions6.
That matters for older claims in a specific way. The ombudsman does not simply check whether the bank followed the code; it asks what was fair at the time, and the code is one input among several. A bank that refused reimbursement under the code can still be found to have acted unfairly, and a bank that followed the code's letter can still be found to have fallen short of good practice. The ombudsman's view of the code was broadly supportive: it saw clear expectations and standards for firms, and a clear framework for deciding when reimbursement was due11.
The ombudsman's casework also flagged a practical problem worth knowing about if you are complaining now: some firms did not provide a clear rationale for their conclusions, and in some cases did not mention the code in final response letters to customers11. If your final response letter does not engage with the code's tests, that is worth pointing out when you escalate. The guides on complaining to your bank about a scam refund and taking a refused scam refund to the ombudsman walk through the process in more detail.
The code has been retired: new rules for payments from 7 October 2024
On 7 October 2024 the CRM Code was retired and a statutory reimbursement framework took its place1. The Lending Standards Board provided oversight of the code until 7 October 2024, to ensure its protections were maintained in the interim1, and from that date the new rules govern payments instead. The shift was from voluntary to mandatory: the new reimbursement requirement applies to Faster Payments and CHAPS payments sent and received by payment service providers in the UK, and everyone making a payment via Faster Payments or CHAPS from one UK bank account to another is covered16.
The new rules also changed the practicalities of claiming. To be eligible under the rules that replaced the code, you must have made a transfer as part of a scam on or after 7 October 2024, made the transfer to another UK account, and told your bank or payment service provider no more than 13 months after the last payment6. Sending payment service providers can deny APP scam claims submitted more than 13 months after the final payment in a given claim4. The PSR also noted the new framework would provide victims with reimbursement more quickly than the 15-day time limit under the CRM Code4.
For a payment made on or after 7 October 2024, the code is irrelevant and the APP reimbursement rules apply instead. For a payment made before 28 May 2019, neither regime applies, though a complaint on general fairness grounds remains possible. The code's continuing relevance is entirely for the in-between cases: payments made between 28 May 2019 and 7 October 2024, where it still frames how a bank, and the ombudsman, should assess the claim3. The wider guide to scams and fraud covers the current rules, and the pages on the maximum refund and the £100 excess explain what the new scheme pays.
Sources17 cited
- The Contingent Reimbursement Model (CRM) Code Payment Systems Regulator
- Government approach to authorised push payment scam reimbursement HM Government, 10 May 2022
- Scams where you've been tricked into making a payment Financial Ombudsman Service
- APP fraud reimbursement policy statement, June 2023 Payment Systems Regulator, May 2025
- Outcome of consultation on the development of a contingent reimbursement model Payment Systems Regulator
- Fraudulent payments Financial Conduct Authority
- APP scams Payment Systems Regulator
- Confirmation of Payee Payment Systems Regulator
- CP21/10: APP scams consultation on measures Payment Systems Regulator
- PS23/1: collection and publication of APP scams performance data Payment Systems Regulator
- LSB CRM Code Review: Financial Ombudsman Service response Financial Ombudsman Service, 2 October 2020
- Fraud and computer misuse in England and Wales, year ending March 2025 Office for National Statistics, 2025
- Helped complaint following a vehicle purchase scam Financial Ombudsman Service
- Chargeback and disputes Trading Standards Wales
- Warning: fraudsters posing as PSR employees Payment Systems Regulator
- Fraud and scams research briefing House of Commons Library
- PS23/3: APP fraud reimbursement policy statement Payment Systems Regulator, 2023-06







FCA Warning ListCheck whether a firm is authorised before you deal with it
Financial Ombudsman ServiceFree, independent help when a complaint about a firm is not put right
Citizens AdviceFree advice on money, consumer and legal problems in England and Wales
MoneyHelperFree, impartial money and pensions guidance, set up by government