Payment Systems and Electronic Fund Transfers Act, 2007 (PS&EFT Act) and the Electronic Fund Transfers Regulations 2008

Last legally reviewed: 9 September 2026

The Payment Systems and Electronic Fund Transfers Act, 2007 (“PS&EFT Act”) is one of the most important pieces of financial legislation in Pakistan that most consumers have never heard of.

Every time a Pakistani customer transfers money through mobile or internet banking, challenges an allegedly unauthorised electronic transfer, uses an ATM or electronic payment instrument, or deals with a payment business operating within the State Bank of Pakistan’s regulatory perimeter, this legislation may become relevant.

Its importance has increased dramatically since 2007.

Pakistan’s payments economy now includes instant transfers through Raast, electronic-money wallets, payment gateways, fintech companies, QR payments, mobile applications, real-time interbank settlement, sophisticated payment switches and increasingly complex fraud and cybersecurity risks. In FY2024–25 alone, SBP reported approximately 9.1 billion retail payment transactions worth PKR 612 trillion, with continued rapid movement towards digital channels.

The remarkable feature of the PS&EFT Act is therefore not that it is an old statute.

It is that this 2007 statute remains the legal foundation upon which much of Pakistan’s modern payments infrastructure has subsequently been built.

An Important Correction: Pakistan’s EFT Regulations Are From 2018, Not 2008

Older discussions of the Act sometimes refer to “Electronic Fund Transfers Regulations, 2008”.

That description should not be relied upon.

The relevant current SBP instrument is the Electronic Fund Transfers (EFT) Regulations, 2018, issued through PSD Circular No. 03 of 2018 dated 9 May 2018 and applicable from 1 October 2018.

SBP issued the Regulations under sections 3(1) and 26 of the PS&EFT Act. They regulate, amongst other matters, information accompanying an EFT, responsibilities of originating and beneficiary institutions, pre-authorised transfers, compensation for unauthorised or delayed transfers, disclosures, periodic statements, disputes, retention of records and reporting.

This distinction matters because legislation should be cited by its actual instrument and date, particularly where consumer liability or regulatory compliance is being asserted.

What Does the Payment Systems and Electronic Fund Transfers Act 2007 Actually Do?

The Act was enacted to establish a regulatory framework for payment systems and electronic fund transfers in Pakistan, protect consumers, and define the respective rights and liabilities of financial institutions, service providers, consumers and participants.

Its architecture covers several different layers of the payment ecosystem.

At the institutional level, the Act empowers the State Bank to regulate payment systems, designate payment systems and instruments, supervise clearing arrangements and operate real-time gross settlement infrastructure.

At the transactional level, it regulates electronic transfers, documentation, disclosures, pre-authorised payments and error resolution.

At the consumer-protection level, it allocates liability for unauthorised transfers and — importantly — places particular evidential burdens upon financial institutions.

And at the enforcement level, it provides civil remedies, criminal provisions and regulatory powers.

Pakistan Code continues to publish the Payment Systems and Electronic Fund Transfers Act, 2007, Act IV of 2007, as the operative primary statute. We have not identified an enacted 2026 replacement of the Act.

That point deserves mention because proposals emerged in late 2025 to amend the Act so that businesses could be required to provide at least one digital means of payment, including QR-based payments. Those proposals were publicly reported as a draft amendment sent for governmental approval, rather than enacted legislation. One should therefore distinguish policy proposals from the law actually in force.

The State Bank’s Powers Under the Act Are Extremely Important

Section 3 gives SBP broad regulatory authority over payment systems and electronic fund transfers.

The importance of that provision becomes clear when looking at what has happened since 2007.

Rather than Parliament having to enact an entirely new statute every time payment technology changes, SBP has progressively constructed a substantial body of secondary regulation beneath the Act.

The contemporary legal regime therefore cannot be understood by reading the 2007 Act in isolation.

It must be read together with SBP’s later rules, regulations, circulars and frameworks.

Designated Payment Systems

Section 4 empowers SBP to designate a payment system.

Designation matters because a system considered important to the functioning, integrity or public interest of Pakistan’s financial system becomes subject to the special statutory framework contained in the Act.

This power is not merely theoretical.

SBP designated 1LINK (Private) Limited as a Designated Payment System with effect from 20 August 2025.

Even more recently, on 27 August 2026, SBP designated National Institutional Facilitation Technologies (Private) Limited — NIFT — as a Designated Payment System under section 4(1).

That latter development alone justifies updating any serious 2026 discussion of the Act.

It demonstrates that section 4 remains an actively used supervisory provision nearly nineteen years after the statute was enacted.

Settlement Finality and Why It Matters

Payment systems depend upon finality.

If every completed interbank payment could later be unwound merely because one participant encountered financial difficulty, a systemic payment network could become unstable very quickly.

Sections 21–23 of the Act therefore deal with settlement arrangements within designated payment systems.

Section 21 gives statutory effect to settlement rules and provides that where those rules make settlement through an account of a participant or clearing house at SBP final and irrevocable, the relevant entry or payment is not required to be reversed, repaid or set aside. Sections 22 and 23 provide associated protection for collateral and settlement arrangements.

These provisions are fundamentally concerned with systemic certainty rather than ordinary consumer complaints about an allegedly mistaken transfer.

The distinction is important.

Settlement finality between payment-system participants does not mean that an individual customer loses every statutory remedy for an error or unauthorised transaction.

The Act separately preserves consumer rights and creates error-resolution procedures.

Pakistan’s RTGS Has Become PRISM+

Section 6 permits SBP to establish and operate real-time gross settlement systems and issue rules governing their operation.

Pakistan’s large-value interbank settlement infrastructure has now evolved into PRISM+ — the Pakistan Real-Time Interbank Settlement Mechanism Plus.

SBP launched PRISM+ on 16 June 2025, replacing and substantially upgrading the earlier RTGS infrastructure. The system uses the ISO 20022 financial messaging standard and combines enhanced funds-settlement functionality with a Central Securities Depository module.

In April 2026, SBP then issued revised PRISM+ Operating Rules, governing matters including participation, settlement and finality, account management, operational continuity and the securities-depository component.

That development is a useful illustration of the PS&EFT Act’s continued relevance: the statutory power created in 2007 now supports financial infrastructure that bears little technological resemblance to Pakistan’s payment environment at the time Parliament passed the Act.

Raast and the Transformation of Retail Payments

For ordinary consumers, Raast is probably the most visible modern manifestation of Pakistan’s changing payment architecture.

Raast is Pakistan’s instant-payment system and supports use cases including bulk payments, person-to-person transfers and person-to-merchant payments.

SBP launched Raast P2P under its statutory powers in 2022, allowing consumers to transfer money using an IBAN or a Raast ID.

The framework has since matured considerably.

SBP issued Raast Participation Criteria on 21 February 2025, expressly under the PS&EFT Act, defining categories of participants and minimum requirements for existing and prospective participants.

Raast should therefore not be viewed merely as another mobile-app feature.

It is part of national payment infrastructure operating within SBP’s statutory supervisory framework.

PSO and PSP Regulation

Fintech terminology can become confusing because a technology company describing itself as a “payment platform” does not determine its own regulatory classification.

The Rules for Payment System Operators and Payment Service Providers, originally issued by SBP in 2014 under the PS&EFT framework, remain fundamental to understanding businesses which provide payment infrastructure.

SBP identifies PSOs/PSPs as potentially including electronic payment gateways for e-commerce, remittance or point-of-sale routing, clearing houses, ATM switches and other payment-system businesses permitted by SBP.

Authorisation is presently structured through three stages: in-principle approval, pilot-operation approval and commercial-operation approval.

SBP currently states a minimum capital requirement of PKR 200 million, unless another amount is prescribed, and specifically notes that PSOs/PSPs may not act as custodians of customer money or perform banking functions merely because they are authorised as payment operators.

That final distinction is commercially important.

A payment gateway and a wallet are not necessarily the same regulatory business.

Neither is automatically a bank.

Electronic Money Institutions: The Wallet Layer

Section 24 of the Act expressly contemplates Electronic Money Institutions (“EMIs”) and provides that an applicant wishing to undertake electronic-money activity must apply to SBP and may undertake only the activities specified in its licence.

SBP originally issued detailed EMI Regulations in 2019 and substantially revised them in June 2023.

The revised Regulations for Electronic Money Institutions, 2023 were intended to permit innovation and new business models while strengthening the regulatory framework governing electronic money.

EMIs may offer products such as electronic wallets, prepaid instruments and other forms of stored-value payment functionality within their authorised scope.

This means that a startup saying:

“We are not a bank; we are only a fintech wallet”

has not answered the regulatory question.

It may simply have identified the reason why EMI regulation needs to be examined.

PSO, PSP and EMI Are Not Interchangeable Licences

One of the more persistent mistakes in Pakistani fintech planning is treating PSO, PSP and EMI authorisations as if they were three names for substantially the same licence.

They are not.

A payment infrastructure provider that routes transactions presents a different regulatory proposition from an institution issuing stored electronic value to customers.

The correct licence therefore depends upon the actual flow of money, contractual structure, custody arrangement, settlement model and services provided.

This is why a fintech regulatory opinion should begin with a transaction-flow diagram rather than the client’s preferred marketing description.

The regulator is interested in what the platform does.

Not what the pitch deck calls it.

Cybersecurity Regulation Has Changed Substantially

An older criticism of Pakistan’s payment framework was that the 2007 Act itself did not contain the kind of detailed cybersecurity architecture required by modern payment technology.

That observation remains fair if directed strictly at the statutory text.

It is no longer fair if it is used to suggest that Pakistan’s payment institutions operate without contemporary cybersecurity requirements.

On 3 October 2025, SBP issued the Technology Risk Management Framework for Payment Institutions, specifically applicable to PSOs, PSPs and EMIs.

The Framework addresses technology governance, cyber risk and operational resilience on a risk-based basis, with regulated payment institutions required to achieve compliance by 31 March 2026. Failure to comply may attract regulatory enforcement.

Accordingly, as at September 2026, cyber-risk governance is not some desirable future reform.

It is already part of the operative regulatory environment.

Fair Treatment of Consumers Has Also Been Strengthened

Another major development occurred through SBP’s Business Conduct and Fair Treatment of Consumers Regulatory Framework (“BC&FRF”), issued on 17 October 2025.

SBP consolidated and strengthened a substantial body of earlier consumer-protection instructions into a single framework covering regulated financial institutions.

The framework became applicable immediately to most financial institutions, with specified governance requirements taking effect from 1 January 2026; for EMIs, the framework became effective from 1 January 2026.

This is important because the modern consumer-protection analysis is no longer simply:

“What does the 2007 Act say?”

It is:

“What does the Act say, what do the 2018 EFT Regulations require, and what additional contemporary SBP conduct requirements apply to this institution?”

The Most Important Part for Consumers: Unauthorised Electronic Transfers

For consumers, sections 36–43 are amongst the most valuable provisions of the entire legislation.

This is where the Act begins to matter when somebody discovers money missing from an account.

The statutory structure is more sophisticated than the often-heard response:

“An OTP was used, therefore the bank has no liability.”

That proposition is far too crude.

Notification and Investigation of an Error

Section 36 establishes the error-notification mechanism.

Once a qualifying alleged error is notified, the institution must investigate and communicate the results within the statutory framework.

Section 37 provides that where an error is found, the institution must correct it promptly and, in any event, no later than one business day after determining that the error occurred. The investigation itself is ordinarily to be completed within ten business days after receipt of the notice.

Section 38 is particularly useful where the bank denies the claim.

If the institution concludes that no error occurred, it must provide an explanation of its findings, and the consumer may request copies of the documents upon which the institution relied in reaching that conclusion.

Consumers frequently overlook this.

A conclusory email saying “your transaction was authenticated” should not necessarily be treated as the end of the evidential enquiry.

Section 39 and Triple Damages

The legislation contains an unusually strong remedial provision.

Section 39 provides for triple damages in defined circumstances where the institution fails to re-credit the account within the statutory period and has failed to conduct a good-faith investigation, lacks a reasonable basis for its conclusion, or knowingly and wilfully concludes that no error existed where that conclusion could not reasonably be drawn from the evidence.

This remedy is not automatic whenever a customer loses money.

Its statutory conditions must be proved.

But its very existence demonstrates how seriously Parliament treated dishonest or fundamentally defective handling of EFT disputes.

Section 41: Who Bears the Burden of Proof?

Section 41 is amongst the most significant provisions in contemporary electronic-banking litigation.

Where an action involves consumer liability for an unauthorised EFT, the burden lies upon the financial institution or authorised party to show that the transaction was authorised or otherwise establish the statutory conditions of liability and required disclosures.

This does not mean that every complainant automatically wins.

It does mean that the legal enquiry cannot simply stop because the bank’s computer records show that credentials were used.

A legal burden of proof requires evidence capable of satisfying the relevant statutory question.

And that principle has increasingly appeared in modern banking litigation.

The Banking Mohtasib and PS&EFT Act Are Not Mutually Exclusive

An important body of Pakistani case law has developed around the relationship between the PS&EFT Act and the jurisdiction of the Banking Mohtasib.

In Habib Bank Limited v Federation of Pakistan, 2018 CLD 1152 (Islamabad High Court), the Court considered complaints arising from unauthorised electronic transfers and rejected the proposition that the existence of the PS&EFT Act necessarily displaced the Banking Mohtasib’s jurisdiction over maladministration and failure to comply with SBP requirements.

The Sindh High Court subsequently addressed the relationship in Messrs Muslim Commercial Bank Ltd v Federation of Pakistan, PLD 2019 Sindh 624, again recognising that remedies under the PS&EFT Act do not simply oust the statutory jurisdiction of the Banking Mohtasib.

This is important for consumers because the regulatory landscape provides overlapping remedies serving somewhat different purposes.

The 2025 Lahore High Court Decision Is Particularly Important

The jurisprudence has become still more interesting.

In United Bank Limited v President of the Islamic Republic of Pakistan, 2025 CLD 834, the Lahore High Court, Rawalpindi Bench, dealt with Banking Mohtasib decisions concerning allegedly unauthorised EFTs arising from impersonation and social-engineering fraud.

The reported judgment recognises the Banking Mohtasib’s jurisdiction over complaints alleging banking malpractice, maladministration, fraud relating to transfers and unauthorised withdrawals, and expressly engages with section 41 of the PS&EFT Act and questions of contributory or comparative negligence.

This is highly relevant to the modern scam environment.

The legal question is increasingly not merely whether the customer interacted with a fraudster, but what each party did, what safeguards existed, what representations were made, whether the bank complied with its own regulatory obligations, and whether the evidential burden imposed by section 41 has been discharged.

And the Sindh High Court Has Already Revisited Section 41 in 2026

The subject did not stop developing in 2025.

In Bank Alfalah Limited v President of Pakistan and others, C.P. No. D-1081 of 2026, reported as 2026 SHC KHI 696, the Sindh High Court dealt with a challenge arising from a hacked joint account after the Banking Mohtasib and the President had ruled against the bank.

The bank sought to rely upon section 41, but the High Court noted both that the point had not properly been pleaded and that the forums below had already addressed the provision. The constitutional petition was dismissed. The Court reiterated that constitutional jurisdiction is not a substitute for another factual appeal against concurrent findings of specialised statutory forums.

For practitioners, there is a useful procedural lesson here alongside the banking law.

A good statutory argument raised too late may cease to be a good litigation strategy.

Section 43 and Bank Liability

Section 43 makes a financial institution or authorised party liable for damages proximately caused by specified failures to make an EFT correctly or in a timely manner when properly instructed, subject to statutory exceptions and section 44.

This provision should not be rewritten into a general rule that a bank is automatically liable for every disputed payment, every failed chargeback or every cyber-fraud loss.

The section means what its statutory language says.

Liability must be linked to the particular failure and the loss proximately caused by it.

Consumers Cannot Contract Away Their Statutory Rights

Section 49 contains an important protective rule: contractual language purporting to waive a consumer’s rights or causes of action under the Act is void.

This prevents a financial institution from solving statutory consumer protection by simply inserting a clause into its standard terms saying, in substance:

“Everything that happens electronically is your problem.”

The parties remain subject to the legislation.

Civil Damages and the Courts

Section 50 creates a civil damages remedy for failure to comply with the Act, subject to the statutory qualifications.

Section 55 then provides jurisdiction for civil actions under the Act and contains a strikingly ambitious procedural command: adjournments are restricted and the court is directed to pronounce judgment within ninety days after notice upon the defendant was first served.

Whether the ordinary litigation system consistently achieves that legislative aspiration is another matter entirely.

But Parliament’s intention is unmistakable.

Electronic payment disputes were not intended to disappear into indefinite litigation.

What About Phishing, OTP Fraud and Social Engineering?

The Act predates today’s industrial-scale phishing ecosystem.

That does not make it irrelevant.

Instead, modern fraud litigation requires the older statutory provisions to be applied alongside contemporary SBP cybersecurity and consumer-conduct requirements.

This is also why it is dangerous for a customer to send an improvised AI-generated complaint asserting every conceivable legal provision after a fraud.

The distinction between an unauthorised transaction, a transfer which the customer technically authorised because of deception, a credential-compromise case, bank-system compromise and simple contractual dispute can materially change the legal analysis.

So can the chronology.

Who initiated the transaction?

What authentication occurred?

What warnings were displayed?

What security controls existed?

Did transaction behaviour depart radically from the customer’s profile?

When did the customer notify the bank?

What did the bank do after receiving that notification?

What evidence does the bank actually possess?

Those are litigation questions.

Not merely technology questions.

The Technology Risk Framework Makes “Our System Worked” an Incomplete Answer

Banks and payment institutions often understandably rely upon system logs to show that their systems processed a payment correctly.

But a properly functioning transaction engine is not necessarily the same thing as a properly governed risk environment.

For PSOs, PSPs and EMIs, the 2025 Technology Risk Management Framework now places explicit regulatory emphasis upon technology governance, cybersecurity and operational resilience.

A modern dispute may therefore require analysis at several levels simultaneously: transaction authentication, customer conduct, institutional security controls, incident response and regulatory compliance.

Merchants and Pakistan’s Cashless-Payment Push

Pakistan’s policy trajectory is plainly towards wider digital-payment acceptance.

During 2025, SBP issued further measures concerning merchants, Raast P2M payments and digitalisation. Its PSP&OD circular record includes Facilitation of Merchants’ Operations, Raast P2M subsidy measures and the Raast Participation Criteria.

The Federal Government also developed proposals to amend the PS&EFT Act so as to require businesses to offer at least one digital payment facility, including QR codes. However, as noted earlier, public reporting described this as proposed legislation awaiting the governmental legislative process rather than a provision already inserted into the Act.

Businesses should therefore distinguish between the Government’s clear policy direction and presently enforceable statutory duties.

Does the PS&EFT Act Regulate Cryptocurrency?

Not in the manner older commentary sometimes suggests.

Pakistan now has a separate dedicated virtual-assets statute, the Virtual Assets Act, 2026, and a specialist regulator, PVARA.

The PS&EFT Act should therefore not be treated as Pakistan’s cryptocurrency licensing law.

However, the two regulatory universes can intersect.

A virtual-asset business may require PVARA authorisation for its virtual-asset activity while simultaneously depending upon ordinary Pakistani banking and payment infrastructure governed by SBP.

That intersection became particularly clear when SBP replaced its old 2018 virtual-currency banking prohibition in April 2026 and established a framework permitting bank accounts for appropriately authorised PVARA VASPs, subject to compliance requirements.

Thus:

virtual assets are principally a PVARA question; fiat payment infrastructure remains an SBP question.

A hybrid fintech business may therefore engage more than one regulator.

This is precisely why we intend to address Pakistan’s cryptocurrency regime separately rather than forcing crypto into the PS&EFT Act where it does not properly belong.

A Crypto Exchange Is Not Necessarily a PSP — and a PSP Is Not Necessarily a Crypto Exchange

This distinction will become increasingly important.

A company cannot safely reason:

“We move value electronically; therefore we need a PSP licence.”

Nor can it reason:

“We use USDT somewhere in our architecture; therefore PVARA is our only regulator.”

The correct regulatory characterisation depends upon the particular activities.

Does the platform issue electronic money?

Does it hold fiat customer funds?

Does it route payments?

Does it operate a payment gateway?

Does it exchange virtual assets?

Does it custody virtual assets?

Does it provide remittance functionality?

Does it facilitate foreign exchange?

Each question may bring a different statute or regulator into the analysis.

There is no single magical “fintech licence”.

Pakistan’s Payments Law in 2026 Is Now an Ecosystem

The most useful way to understand contemporary Pakistani payments law is therefore to abandon the idea that the 2007 Act stands alone.

The Act is the statutory spine.

Around it now sit the EFT Regulations 2018, PSO/PSP Rules, EMI Regulations 2023, payment-card regulation, Raast rules and participation requirements, PRISM+ operating rules, consumer-conduct regulation, technology-risk requirements, AML/CFT obligations and — where virtual assets become involved — a separate PVARA regime.

That accumulation of subordinate frameworks is not necessarily a defect.

Indeed, technology regulation often requires a certain degree of delegated adaptability.

Parliament establishes the architecture.

The specialist regulator adapts the technical rules as markets and risks evolve.

The danger arises only if market participants read one instrument in isolation and assume that it contains the entire answer.

The Practical Position for Fintech Founders

Anyone planning a payment, wallet or fintech service in Pakistan should identify the regulatory structure before substantial capital is committed to software development.

A properly constructed legal review should examine the transaction flow, custody of customer funds, settlement relationships, payment instruments, customer agreements, outsourcing model, data architecture, AML controls, cyber-security arrangements and intended cross-border functionality.

Where several regulated activities overlap, the analysis should also consider whether separate permissions or partnerships with already regulated institutions are required.

One of the most expensive sentences in fintech remains:

“We have already built the platform; now we just need the licence.”

Licensing architecture can determine how the platform should have been built in the first place.

The Practical Position for Consumers

For customers disputing an electronic transfer, the PS&EFT Act should be treated as an evidential framework rather than a slogan.

Prompt notice matters.

Preserving evidence matters.

Requesting the bank’s investigation and underlying documents matters.

Understanding section 41 matters.

And where Banking Mohtasib proceedings are available, the complaint should be drafted around the actual statutory and regulatory breaches rather than broad accusations that the bank was “negligent”.

The stronger case is generally the case capable of answering:

Which obligation existed? What happened? Who breached it? What evidence proves the breach? What loss did it cause?

Everything else is noise.

Frequently Asked Questions

Is the Payment Systems and Electronic Fund Transfers Act 2007 still in force in Pakistan?
Yes. It remains the principal federal statute governing payment systems and electronic fund transfers and continues to underpin modern SBP regulation. Pakistan Code presently lists the Act as operative.

Are the Electronic Fund Transfer Regulations from 2008 or 2018?
The relevant SBP Electronic Fund Transfers Regulations were issued in 2018, through PSD Circular No. 03 dated 9 May 2018, and became applicable on 1 October 2018.

What happens if I report an unauthorised electronic transaction?
Sections 36–38 create an investigation and error-correction framework. Where no error is found, the consumer may request the documents relied upon by the institution.

Who must prove whether an electronic transfer was authorised?
Section 41 places the statutory burden upon the financial institution or authorised party in an action involving consumer liability for an unauthorised EFT.

Can the Banking Mohtasib hear online banking fraud disputes?
Pakistani superior-court authority recognises the Banking Mohtasib’s jurisdiction over relevant complaints concerning banking maladministration and unauthorised electronic transfers. See, inter alia, Habib Bank Limited v Federation of Pakistan, 2018 CLD 1152; Messrs Muslim Commercial Bank Ltd v Federation of Pakistan, PLD 2019 Sindh 624; and United Bank Limited v President of the Islamic Republic of Pakistan, 2025 CLD 834.

Does an OTP automatically prove that a customer authorised the transaction?
Not as an abstract proposition of law. Authentication evidence is highly relevant, but section 41 still governs the burden of proof in unauthorised-EFT litigation, while the factual circumstances of social engineering, customer conduct and institutional compliance must be evaluated.

What is an EMI?
An Electronic Money Institution is an SBP-regulated entity authorised to undertake electronic-money activities within its licence. The detailed regime is now principally contained in the revised EMI Regulations issued in June 2023.

What is the minimum capital for a PSO/PSP?
SBP presently states that PSOs/PSPs must maintain at least PKR 200 million or such other amount as SBP may prescribe.

Is Raast governed by this legislation?
Yes. SBP has exercised powers under the PS&EFT Act in developing and regulating Raast, including its 2025 Participation Criteria.

Is cryptocurrency governed by the PS&EFT Act?
Not principally. Virtual assets now have their own statutory regime under the Virtual Assets Act, 2026 and PVARA. However, the ordinary banking or payment leg of a virtual-asset business may still engage SBP regulation.

Legal Assistance for Digital Payments, Fintech and Electronic Fund Transfer Disputes in Pakistan

Josh and Mak International advises Pakistani and international clients on payment-system regulation, PSO/PSP structures, EMI and digital-wallet models, electronic payment gateways, fintech transactions, SBP regulatory compliance, consumer electronic-fund disputes, Banking Mohtasib proceedings, online banking fraud, unauthorised transfers, AML/CFT issues and the interaction between Pakistan’s fiat-payment and virtual-asset regulatory regimes.

For fintech businesses, regulatory advice is most useful before the final technology and contractual architecture has been adopted.

For consumers and businesses affected by an allegedly unauthorised electronic transfer, the immediate priority should normally be preservation of evidence, prompt notification to the institution and careful review of the statutory complaint and error-resolution process.

And for anyone relying upon an old internet article describing Pakistan’s digital payments law as though the world stopped somewhere around the invention of the ATM, it may be time for an update.

Josh and Mak International
Islamabad, Pakistan
Email: aemen@joshandmak.com
Telephone: +92-304-8734889
Website: www.joshandmakinternational.com

Legal disclaimer: This article provides general legal information as reviewed on 9 September 2026. Payment and fintech regulation changes through legislation, State Bank rules, circulars, licence conditions and regulatory directions. Specific transactions should be independently reviewed before reliance is placed upon this article.

Payment Systems and Electronic Fund Transfers Act 2007 in Pakistan: The Complete 2026 Legal Guide to Digital Payments, Raast, Fintech, EMIs, PSOs/PSPs, Online Banking and Electronic Fund Transfers

Last legally reviewed: 9 September 2026

Pakistan’s digital payments economy in 2026 bears remarkably little resemblance to the financial landscape in which the Payment Systems and Electronic Fund Transfers Act, 2007 was originally enacted.

When Parliament passed the legislation on 30 June 2007, smartphones had not yet transformed everyday banking, QR payments were not a routine commercial instrument, electronic-money wallets were not a mainstream Pakistani financial product, instant retail payments through Raast did not exist, and the contemporary fintech industry was still largely beyond the regulatory imagination of most jurisdictions.

Yet the Payment Systems and Electronic Fund Transfers Act, 2007 commonly referred to as the PS&EFT Act remains the principal statutory foundation upon which a substantial part of Pakistan’s modern payment architecture rests.

That fact is more important than the age of the legislation might initially suggest.

The Act was deliberately framed at a level of generality that gave the State Bank of Pakistan (“SBP”) extensive authority to prescribe rules, standards, directions and operational requirements as payment technologies evolved. Section 3 is particularly important in this regard: it empowers SBP to issue rules, guidelines, circulars, bye-laws, standards and directions concerning payment systems, service providers, operators and payment instruments. The Act therefore functions less like a technological instruction manual frozen in 2007 and more like the statutory spine from which successive layers of specialised regulation have developed.

That delegated architecture has become considerably more sophisticated.

Pakistan now has specialised rules governing Payment System Operators and Payment Service Providers; modern regulations governing Electronic Money Institutions; a national instant-payment infrastructure through Raast; the PRISM+ real-time gross settlement and securities-settlement environment; designated payment systems such as 1LINK and, most recently, NIFT; a dedicated Technology Risk Management Framework for payment institutions; an updated consumer-conduct regime; payment-card security requirements; electronic know-your-customer infrastructure; merchant-payment initiatives; and increasingly extensive regulatory expectations concerning cyber resilience, transaction monitoring, operational continuity and consumer protection.

The figures demonstrate why this body of law can no longer be treated as an obscure banking niche.

According to SBP’s Payment Systems Review for FY2024–25, Pakistan recorded approximately 9.1 billion retail payment transactions with a value of PKR 612 trillion during that financial year. Digital channels accounted for more than 88 per cent of retail-payment transactions, compared with 78 per cent in FY2023 and 85 per cent in FY2024.

In other words, electronic payments are no longer peripheral to Pakistani commerce.

They are increasingly the commerce.

And as payments migrate from counters and cheques to phones, wallets, QR codes and instant settlement, legal questions that once appeared highly technical become ordinary questions of consumer rights, contractual liability, banking negligence, cybersecurity, fraud, regulatory licensing and commercial risk.

This article therefore examines the PS&EFT Act as it actually operates in 2026, rather than describing the statute as though Pakistan’s payment system stopped developing in 2007.

Why the 2007 Act Still Matters

The preamble to the Act identifies three central objectives: the supervision and regulation of payment systems and electronic fund transfers in Pakistan; the establishment of standards for consumer protection; and the determination of the respective rights and liabilities of financial institutions, service providers, consumers and participants.

Those objectives remain remarkably contemporary.

A modern payment system requires at least three forms of legal certainty.

First, the institutions operating the infrastructure must know the conditions under which they may participate, the risks they must manage and the standards they must satisfy.

Secondly, transactions moving through that infrastructure must achieve an appropriate degree of finality. A payment system cannot function efficiently if settled obligations remain perpetually vulnerable to reversal merely because a participant later becomes insolvent or disputes arise elsewhere in the transaction chain.

Thirdly, consumers need rules allocating responsibility when electronic payments fail, are processed incorrectly or are said to have been made without authority.

The PS&EFT Act addresses all three.

It regulates the infrastructure.

It protects settlement.

And it creates consumer remedies.

A recurrent mistake is to focus only upon the third function because disputes involving allegedly unauthorised transfers are the provisions most likely to reach consumers and lawyers.

The Act is considerably broader.

Its first four substantive chapters are concerned with the architecture of payment systems, designated systems, payment instruments, clearing houses, settlement rules and electronic-money institutions. Consumer disclosures, documentation, error notification and liability appear later.

Understanding that structure matters because the statute deliberately distinguishes between systemic payment law and individual consumer liability.

Those two levels interact, but they are not interchangeable.

What Counts as an Electronic Fund Transfer?

The statutory definition remains broad.

An “Electronic Fund Transfer” is, in essence, a transfer of funds other than one originating through a cheque, draft or similar paper instrument which is initiated through an electronic terminal, telephone instrument, point-of-sale terminal, stored-value-card terminal, debit card, ATM, computer or another electronic device in order to instruct or authorise a financial institution to debit or credit an account.

That definition was technologically sensible in 2007 because Parliament avoided tying the concept to one particular device.

It therefore accommodates many present-day payment mechanisms far more comfortably than might be expected from the statute’s age.

A transfer initiated through a mobile-banking application remains an electronic instruction to debit one account and credit another.

So does an internet-banking transfer.

So, ordinarily, does an instant bank transfer through infrastructure such as Raast where the transaction involves the movement of fiat funds between relevant accounts.

The physical form of the interface changes.

The legal function remains recognisable.

This is one reason the statute has survived technological change better than a law that might have attempted to enumerate every permitted payment device.

“Electronic Money” and “Virtual Assets” Must Not Be Confused

There is, however, an important terminological trap.

The PS&EFT Act contains concepts of electronic funds and electronic money. These should not automatically be equated with cryptocurrency or virtual assets.

Electronic money in the conventional payments-law sense is typically a digital representation of fiat monetary value issued against receipt of funds and accepted as payment within the regulated payment ecosystem.

A wallet containing electronically issued Pakistani-rupee value is conceptually different from a decentralised cryptoasset whose value arises independently of a claim against an issuer.

That distinction has become even more important in 2026 because Pakistan now regulates virtual assets through a separate statutory and regulatory architecture.

We shall return to that intersection later in this article.

For present purposes, the important point is that electronic money is not merely a synonym for any money-like thing that happens to exist electronically.

Legal classification depends upon the nature of the asset, the issuer, the redemption structure and the service being provided.

The State Bank of Pakistan Sits at the Centre of the Architecture

Section 3 is one of the most important provisions in the entire Act.

It gives SBP broad authority to regulate payment systems, payment-system operators, service providers and issuers of payment instruments through secondary instruments.

The significance of this power becomes obvious when one examines Pakistan’s present payment ecosystem.

The Act itself does not contain a chapter called “Raast”.

It does not contain a chapter called “Payment Gateway Regulation”.

It does not set out detailed technological requirements for modern electronic-money wallets.

It does not specify the architecture of PRISM+.

Yet all of these can exist within the wider framework because SBP possesses statutory powers to regulate the payment infrastructure and the actors participating within it.

That is an example of delegated financial regulation performing the function it was intended to perform.

Technology frequently changes faster than primary legislation.

A Parliament that attempted to rewrite a payments statute every time a new authentication protocol, settlement architecture or delivery channel appeared would permanently legislate several years behind the market.

The more practical legislative model is therefore to establish statutory principles and institutional competence, while leaving specialised technical standards to a regulator capable of adapting them.

That model has obvious constitutional limits an administrative regulator cannot invent powers Parliament never conferred but within the regulatory perimeter actually established by the Act, SBP enjoys considerable discretion.

What Factors Must SBP Consider?

The Act does not leave SBP entirely unconstrained when exercising its payment-system powers.

Among the considerations identified by section 3 are systemic risk; monetary stability and the soundness of the financial structure; the public interest; market conditions and behaviour; safety, integrity, efficiency and reliability; security and operational standards; existing users and participants; and prospective persons wishing to obtain access to the system.

Those considerations reveal the philosophy of the legislation.

Payment regulation is not concerned solely with preventing fraud.

It is also about ensuring that a failure inside one significant system does not spread through the wider financial system.

That is the meaning of systemic risk.

A payment-system failure can become economically dangerous long before an ordinary customer understands what has happened.

If a major participant cannot meet its payment obligations, other participants may themselves encounter liquidity problems. If settlement becomes uncertain, institutions may become unwilling to extend credit or release funds. If a clearing or settlement mechanism fails operationally, problems can propagate far beyond the institution in which they originated.

The law therefore treats critical payment infrastructure differently from an ordinary commercial technology platform.

Designated Payment Systems

Section 4 gives SBP power, where it considers designation necessary in the public interest, to designate a payment system as a Designated Payment System.

Designation is a significant regulatory act.

It signifies that the system has become sufficiently important to warrant enhanced statutory supervision.

The power is not merely historic or theoretical.

SBP issued a formal Payment Systems Designation Framework in July 2017, explaining that designated systems are generally systemically important infrastructures whose disruption can adversely affect financial markets. The Framework was expressly issued in exercise of powers under the PS&EFT Act.

The practical significance of designation became particularly visible during 2025 and 2026.

On 20 August 2025, SBP formally designated 1LINK (Private) Limited as a Designated Payment System under section 4(1).

Then, only days before the present 2026 update to this article, SBP issued another major designation.

On 27 August 2026, SBP designated National Institutional Facilitation Technologies (Private) Limited (“NIFT”) as a Designated Payment System under the same statutory provision.

That development is particularly useful in appreciating how alive the 2007 Act remains.

Section 4 is not a museum piece.

The State Bank was actively using it in August 2026.

What Does Designation Actually Change?

A Designated Payment System is subject to requirements extending beyond ordinary commercial operation.

The operator must maintain adequate governance arrangements.

Those arrangements must be effective, accountable and transparent.

The system must also maintain operational arrangements dealing with matters including rights and liabilities of operators and participants, financial risks, settlement finality, participation criteria and measures to safeguard security and operational reliability.

These provisions recognise an obvious truth about financial infrastructure: code alone is not governance.

A payment system can be technically impressive and still be legally or operationally dangerous if responsibility is unclear, settlement rules are uncertain, participants are poorly supervised or contingency arrangements are inadequate.

The Act therefore makes governance part of the infrastructure.

That principle has become still more important in a world of outsourced technology, APIs, cloud environments and interconnected financial-service providers.

Designation Is Not Permanent Immunity

Section 5 permits SBP to revoke designation in specified circumstances.

Those circumstances include ineffective operation, materially false or misleading information, winding-up or dissolution of the relevant operator or settlement institution, breach of the conditions of designation or requirements of the Act, and wider public-interest grounds.

Ordinarily, the operator must be given an opportunity to be heard.

However, the statute also permits immediate suspension where a systemic risk is involved.

The logic is straightforward.

Due process matters.

But the payment system cannot be required to remain exposed to an imminent systemic threat merely because a full adversarial regulatory process takes time.

Financial regulation frequently involves this balance between procedural fairness and preventive intervention.

Governance of Designated Systems

Section 10 requires the operator of a Designated Payment System to establish adequate governance arrangements capable of preserving the system’s integrity.

Section 11 goes further by requiring operational arrangements addressing rights and liabilities, credit risk, liquidity risk, settlement risk, participation criteria, safety, security, reliability and contingencies.

The distinction between governance and operational control is useful.

Governance asks who is responsible, who decides and who is accountable.

Operational control asks how the system actually manages risk in practice.

Neither substitutes for the other.

A beautifully drafted board charter cannot rescue an unstable settlement engine.

A technically resilient settlement engine cannot cure governance arrangements that obscure responsibility and permit conflicts of interest.

Modern payment regulation increasingly expects both.

Fit-and-Proper Concerns Are Embedded in the Act

Sections 8 and 9 contain personnel-disqualification provisions applicable to operators of Designated Payment Systems.

The statute disqualifies certain persons who have experienced specified bankruptcy-related events or convictions, and addresses misconduct or misuse of position by senior officers.

This may appear comparatively minor beside today’s sophisticated cybersecurity frameworks, but its underlying regulatory principle remains important.

Financial infrastructure is not regulated solely by examining systems.

It is also regulated by examining the people entrusted with them.

This concept now appears throughout financial regulation under various forms of “fit and proper” requirements.

The basic idea is one of institutional trust: persons controlling critical financial infrastructure should possess the integrity and competence appropriate to that responsibility.

Payment Instruments Are Separately Regulated

The Act makes a deliberate distinction between a Payment System and a Payment Instrument.

A payment system is the broader infrastructure through which payments may be processed, cleared or settled.

A payment instrument is the means by which a person can obtain money, goods or services or otherwise make payment.

The difference can be illustrated simply.

A card may be a payment instrument.

The network and settlement infrastructure through which that card transaction is routed form part of the payment system.

The two should not be conflated.

Designated Payment Instruments

Section 12 permits SBP to designate a Payment Instrument where it is, or may become, widely used and where designation is necessary to protect the public or preserve the integrity, efficiency and reliability of the payment environment.

Where an instrument is designated, the issuer becomes subject to the statutory approval regime.

Section 13 requires written SBP approval before issuing a Designated Payment Instrument and permits SBP to impose restrictions, limitations and conditions.

The statute also expressly requires such instruments to carry minimum security features consistent with current international standards.

Even in 2007, therefore, the legislature recognised that payment security could not sensibly be reduced to an immutable technical specification inside the Act itself.

The reference to contemporary international standards leaves room for security expectations to evolve.

SBP Can Prohibit Unsafe or Fraudulent Payment Instruments

Section 14 permits SBP to prohibit a person from issuing or using a payment instrument where the instrument threatens the reliable, safe, efficient or smooth operation of Pakistan’s payment systems; conflicts with public interest; has been issued with an object to entice or defraud the public; or where statutory requirements have not been satisfied.

This is a useful reminder that innovation is not itself a regulatory defence.

A payment instrument may be novel.

It may even be technologically impressive.

But if it creates unacceptable systemic or consumer risk, SBP can intervene.

The payments sector is therefore not governed by a general principle that anything not expressly prohibited is automatically safe to launch at scale.

Security Under Section 15

Section 15 requires financial institutions and other institutions providing EFT facilities to ensure that secure means are used for transfers in accordance with current international standards and such requirements as SBP may prescribe.

This provision deserves careful interpretation.

It does establish a statutory security obligation.

But it does not itself specify encryption algorithms, biometric standards, artificial-intelligence fraud engines, cloud-control architectures or penetration-testing schedules.

Those detailed subjects belong principally to later regulatory frameworks.

This distinction matters because earlier versions of this article repeatedly attributed elaborate modern technology requirements directly to the PS&EFT Act or to a supposed omnibus “Regulation 13”. The statute does not need to be stretched in that manner.

The contemporary security case is stronger when the correct instrument is cited.

In particular, modern PSOs, PSPs and EMIs are now subject to the Technology Risk Management Framework for Payment Institutions, issued by SBP on 3 October 2025. The Framework establishes baseline technology-governance and risk-management requirements and expressly addresses cyber risk. Payment institutions were required to achieve compliance by 31 March 2026, with non-compliance attracting regulatory consequences.

So, in September 2026, there is no reason to manufacture cybersecurity obligations from ambiguous wording.

Pakistan actually has a dedicated regulatory framework.

Third Parties Cannot Be Used to Evade Consumer Protection

Section 16 contains another useful principle.

Where a person other than a conventional financial institution holds a consumer’s account, SBP may extend relevant disclosure requirements, protections, responsibilities and remedies to that person or service.

That principle has become increasingly important as financial intermediation moves outside the traditional bank branch.

Modern consumers may interact with wallets, payment platforms, gateway providers, outsourced processors and other non-bank technology businesses.

A regulatory system would be easily defeated if consumer protections vanished merely because an account or payment service was structured through a non-bank intermediary.

The Act therefore anticipated the need to extend protections beyond classic banking institutions.

Cheque Truncation and the Transition From Paper to Electronic Clearing

The Act also contains provisions dealing with truncated cheques.

Cheque truncation replaces the physical movement of a cheque during the clearing process with electronic capture of the cheque image and relevant information.

At first sight this may seem less exciting than mobile banking or real-time payments.

Legally, however, it illustrates the same transition the Act was designed to accommodate: movement from paper-based financial processes to electronic representation, clearing and settlement.

The significance remains practical because NIFT historically played a central role in Pakistan’s clearing environment, and its August 2026 designation under section 4 further illustrates the continuing importance of regulated clearing infrastructure.

Clearing Houses

Section 18 permits SBP to nominate clearing houses to provide clearing or settlement services on terms and conditions determined by the regulator.

SBP may also audit and inspect clearing houses.

That regulatory power makes sense because clearing houses occupy a position of unusual systemic importance.

They stand between numerous institutions and transactions.

Operational failure at that level is not merely a dispute between two contracting businesses.

It can affect large numbers of participants simultaneously.

Significant Changes Must Be Reported

Section 19 requires a clearing house to give advance notice to SBP of specified significant changes concerning a Designated Payment System.

The matters identified by the statute include alterations to legal documents or bye-laws, operational changes, modifications to governing procedures, changes in board composition and changes of auditor.

The importance of such notification requirements is sometimes underestimated.

A regulator cannot supervise systemic infrastructure effectively if material structural changes occur without its knowledge.

Regulatory supervision is not merely retrospective punishment.

It is also prospective visibility.

Participant Responsibility Where a Clearing House Fails

Section 20 contains a particularly robust provision.

Where a clearing house fails to satisfy statutory obligations or otherwise contravenes the Act, participants may become jointly and severally responsible for compliance.

That approach reflects the systemic character of clearing arrangements.

Participants cannot necessarily wash their hands of infrastructure failure by saying that the clearing house was a separate entity.

Where Parliament has deliberately connected their responsibilities, the system is treated as a network rather than a collection of isolated contractual silos.

Settlement Finality: One of the Most Important Concepts in Payment Law

Amongst the most technically important provisions of the Act are sections 21 to 23.

These deal with settlement and finality.

The concept can sound abstract until one imagines the alternative.

Suppose Bank A owes Bank B substantial sums through thousands of payment transactions. Those obligations are processed and settled according to the rules of a designated payment system.

Now imagine that Bank A subsequently encounters insolvency.

If every payment made earlier that day could automatically be unravelled because insolvency proceedings had commenced, Bank B might suddenly find that assets it believed had finally settled no longer existed.

Bank B may itself have made payments in reliance upon those funds.

Other institutions may have done the same.

The uncertainty can spread.

Settlement-finality law seeks to prevent that domino effect.

Section 21 therefore gives statutory force to settlement rules and recognises final and irrevocable settlement where the relevant designated-system rules so provide.

Sections 22 and 23 reinforce that structure by protecting certain collateral rights and allowing SBP to establish settlement rules dealing with calculation, netting, settlement and participant default.

The legal policy is straightforward:

once a systemically important payment has crossed the legally defined point of finality, the system must be able to rely upon that finality.

Settlement Finality Does Not Mean Consumers Lose Every Remedy

This distinction is essential.

Finality within the settlement infrastructure does not mean that every consumer dispute becomes impossible once an underlying payment has technically settled.

Payment-system finality and consumer liability operate at different legal levels.

A transaction may be final between participating financial institutions while a customer may still possess a claim against the relevant institution for an unauthorised transfer, error, failure of duty or breach of statutory obligations.

The remedy need not necessarily consist of unwinding the system-wide settlement.

It may instead consist of a re-credit, damages or another obligation imposed upon the institution.

That distinction protects two important interests simultaneously.

The financial system receives settlement certainty.

The consumer retains substantive legal rights.

There is no contradiction.

Why Section 59 Should Not Be Confused With Settlement Finality

This is one of the points we are deliberately correcting from the older article.

Section 59 is concerned with the Act’s relationship with insolvency law.

It is not the principal statutory provision creating ordinary settlement finality.

The finality architecture appears earlier, principally in sections 21, 22 and 23.

Section 59 has its own important function in the insolvency context, but describing it as though it were the Act’s general settlement-finality provision muddles two related yet legally distinct questions.

This sort of section-level precision matters.

Financial regulation is already complicated enough without making the numbering more creative than Parliament did.

Electronic Money Institutions Under Section 24

Section 24 is concise but extremely important.

It provides the statutory basis for a person wishing to become an Electronic Money Institution (“EMI”) to apply to SBP for a licence and confines the institution to activities specified in that licence.

This is another provision that was frequently stretched too far in older commentary.

Section 24 is not Pakistan’s universal cross-border-payment section.

It is not the PS&EFT Act’s cryptocurrency section.

It is not, by itself, the statutory source of every AML obligation associated with digital payments.

It is the provision establishing the licensing concept for Electronic Money Institutions.

That concept has since been substantially developed through secondary regulation.

The 2019 EMI Regime and Its 2023 Revision

SBP first issued detailed Regulations for Electronic Money Institutions in 2019.

Those Regulations represented an important policy choice.

Instead of requiring every innovative stored-value or wallet business to become a conventional bank, Pakistan created a specialised non-bank regulatory category for e-money.

The regime was then comprehensively revised in June 2023.

SBP explained that the revisions were intended to increase adoption of electronic-money services, encourage both new and existing EMIs to develop new business models, use cases and technological solutions, and incorporate domestic experience and international best practice.

That evolution illustrates how the Act and secondary regulation interact.

Section 24 gives the statutory foothold.

The EMI Regulations supply the operational architecture.

What Do EMIs Actually Do?

SBP describes EMIs as entities capable of offering secure, low-value and interoperable digital payment instruments such as wallets, prepaid cards and contactless payment instruments.

This is commercially important because many founders use the expression “fintech” as though it were itself a legal category.

It is not.

“Fintech” is an industry description.

The law asks what activity the business actually performs.

If the company issues electronic monetary value that customers can store and use, EMI regulation may become relevant.

If it instead routes or switches transactions without holding customer funds, PSO/PSP regulation may be more relevant.

If it lends money, additional credit regulation may arise.

If it facilitates virtual-asset activity, the PVARA regime may arise.

The regulatory classification follows the function.

Not the pitch deck.

An EMI Is Not a Bank

Another commercially important distinction is that an EMI licence does not automatically transform a company into a bank.

The regulatory philosophy is narrower.

An EMI is authorised to conduct the electronic-money activities permitted by its licence and regulations.

It should therefore resist describing services in a manner suggesting broader banking powers that it does not possess.

This is part of a wider principle running through Pakistani financial law.

A licence to perform one regulated financial activity is not a general licence to perform every financially adjacent activity.

PSOs and PSPs: Payment Infrastructure Rather Than Customer Deposit Taking

Pakistan’s separate framework for Payment System Operators (“PSOs”) and Payment Service Providers (“PSPs”) further illustrates this point.

SBP issued the Rules for Payment System Operators and Payment Service Providers on 23 October 2014.

The Rules recognised that PSOs and PSPs form an important part of Pakistan’s financial-market infrastructure and identified potential activities including electronic payment gateways for e-commerce, remittances and point-of-sale routing; clearing services; ATM switches; and other payment-system functions permitted by SBP.

The authorisation structure presently operates through three stages:

in-principle approval → pilot-operation approval → commercial-operation approval.

SBP currently states that PSOs/PSPs are required to maintain capital of at least PKR 200 million, or another amount prescribed by the regulator, and expressly notes that such entities may not act as custodians of customer money or perform banking functions merely by virtue of their PSO/PSP authorisation.

That last restriction is critical.

Payment Gateway Does Not Mean Wallet

Consider two apparently similar fintech businesses.

Business A provides the technological gateway through which merchant transactions are routed between the customer, acquiring institution and relevant payment infrastructure.

Business B allows consumers to deposit or load value into an electronic wallet and subsequently spend that stored value.

Both may call themselves “digital payment companies”.

Their legal structures may nevertheless be entirely different.

Business A may primarily raise PSO/PSP questions.

Business B may raise EMI questions.

If Business A begins holding customer funds, or Business B begins performing activities outside its EMI authorisation, the regulatory analysis changes again.

This is why legal classification should precede product launch.

The Regulatory Mistake of Starting With the Licence Name

A common startup conversation goes something like this:

“We need a PSP licence. How much does it cost?”

The better first question is:

“What precisely happens to the customer’s money?”

The answer should identify who receives the funds, whose bank account holds them, whether value is stored, whether the business ever obtains possession or control of customer funds, how settlement occurs, which party contracts with the customer, which party contracts with the merchant, where the technology sits, what entity executes instructions and which institution ultimately carries the payment obligation.

Only after that transaction map is understood should the regulatory classification be selected.

In financial regulation, labels are cheap.

Money flows are evidence.

Electronic Fund Transfers Regulations 2018

Another essential correction concerns the date of the principal EFT Regulations.

The operative instrument is the Electronic Fund Transfers (EFT) Regulations, 2018, not “2008 Regulations”.

SBP issued them through PSD Circular No. 03 dated 9 May 2018, and they became applicable from 1 October 2018.

The Circular explains that the Regulations were issued under sections 3(1) and 26 of the PS&EFT Act and address minimum information requirements for EFT messages, responsibilities of originators and participating payment institutions, pre-authorised transfers, compensation for unauthorised or delayed EFTs, disclosures, periodic statements, dispute resolution, record retention and reporting.

The older article correctly recognised the importance of the 2018 instrument at the beginning, but later repeatedly reverted to calling it the “2008 Regulations”.

That inconsistency should disappear entirely from the replacement.

Why EFT Information Requirements Matter

Electronic payments operate through messages.

Those messages must contain enough information to identify and process the transaction reliably.

This may sound administratively mundane, but it sits at the heart of traceability.

Where something goes wrong, lawyers, financial institutions and investigators commonly reconstruct the transaction by examining identifiers, timestamps, account information, channel information and the participating institutions.

A poorly documented payment is harder to reconcile.

It is harder to investigate.

And it is harder to litigate.

The 2018 Regulations therefore sit at the intersection of operational efficiency and evidential accountability.

The Difference Between a Payment Instruction and a Payment Outcome

Another useful conceptual distinction is between instruction, processing, settlement and customer outcome.

A customer may issue a valid instruction.

The originating institution may process it.

A payment system may clear and settle the transaction.

Yet an error may still arise at another point in the chain.

Conversely, a customer may assert that a payment was never authorised at all.

Those scenarios engage different legal questions.

The phrase “the system shows the transaction succeeded” therefore does not necessarily answer every dispute.

It may prove one part of the transaction lifecycle.

It does not automatically prove every contested fact concerning authority, identity, disclosures or institutional conduct.

That distinction becomes especially important in the consumer-liability section of this article, which we shall address in Part II.

Pakistan’s Instant Payment System: Raast

Perhaps the most visible transformation of Pakistan’s retail-payment landscape has been Raast.

Raast is Pakistan’s national instant-payment system.

Its purpose is not merely to make transfers faster.

The infrastructure is intended to lower friction, improve interoperability, widen access to digital payments and support multiple use cases across individuals, businesses and government.

SBP’s current Raast Participation Criteria describe the system as being built on ISO 20022 and supporting use cases including Bulk Payments, Person-to-Person payments, Person-to-Merchant payments and Payment Initiation Service transactions.

The importance of ISO 20022 should not be exaggerated into marketing mysticism.

It is essentially a modern financial messaging standard designed to facilitate richer and more structured payment information and interoperability.

Its adoption reflects Pakistan’s increasing integration into contemporary payment-system architecture.

Raast Person-to-Person Payments

SBP launched the person-to-person phase of Raast in 2022.

This allowed customers to make transfers using mechanisms including account identifiers and Raast IDs.

The practical consequence was substantial.

Instant bank-to-bank transfer ceased to be merely an optional proprietary feature of particular institutions and became part of a national infrastructure.

The legal consequence was equally important.

Raast operates within SBP’s statutory payment-system powers rather than as a private messaging application standing outside financial regulation.

Raast Person-to-Merchant Payments

The next significant stage came with the Raast Person-to-Merchant (“P2M”) service.

SBP formally launched the P2M framework in December 2023.

The service permits merchant-payment acceptance through mechanisms including QR codes, Raast Alias, IBAN and Request to Pay, and SBP directed regulated entities to develop merchant-acceptance capabilities across their relevant channels.

That has significant implications for Pakistan’s broader cashless-policy trajectory.

QR payment is no longer merely a novelty displayed at a handful of technology-forward shops.

It is becoming part of regulated national payment infrastructure.

Raast Participation Criteria 2025

On 21 February 2025, SBP issued dedicated Raast Participation Criteria under the PS&EFT Act.

The Criteria apply to existing and future participants and establish categories of participation and minimum eligibility requirements.

The architecture is deliberately broader than banks alone.

Eligible entities can include banks, microfinance banks, qualifying non-bank financial institutions, government bodies, public-sector entities, corporates, SMEs, business platforms, payment aggregators, educational institutions, fintechs and other service providers, subject to the relevant participation category and regulatory requirements.

This is an important development.

It indicates that Raast is evolving from a bank-transfer utility into wider national payment infrastructure.

Raast Participation Does Not Eliminate Other Licensing Requirements

This point deserves emphasis.

An entity obtaining some form of access to Raast does not thereby acquire permission to conduct every financial business imaginable.

Raast participation and regulatory licensing answer different questions.

An EMI may participate within its regulatory perimeter.

A PSO/PSP may participate within its authorised functions.

A bank participates under banking regulation.

A fintech cannot normally transform an otherwise unlicensed financial activity into a lawful one merely by connecting that activity to Raast.

Infrastructure access is not regulatory absolution.

Merchant Digitisation in 2025

SBP’s payments policy continued to move strongly towards merchant digitisation during 2025.

Its published circular record includes Facilitation of Merchants’ Operations in July 2025, allocation of subsidy for Raast P2M QR payments in September 2025 and further measures directed towards expanding digital payment adoption.

This policy direction has broader legal significance.

As digital payment acceptance becomes increasingly normal, businesses need to understand that payment architecture is no longer merely a banking-side concern.

Merchant onboarding, acquiring arrangements, QR issuance, settlement, fees, fraud controls, customer complaints and the handling of transaction data all increasingly sit within regulated commercial relationships.

Proposed Mandatory Digital Payment Acceptance

During 2025, proposals were also reported for legislative changes that would require businesses to provide at least one digital payment option.

Care is needed here.

A policy proposal, draft amendment or governmental announcement is not the same thing as enacted law.

Legal articles should resist the temptation to report the Government’s desired future as though Parliament has already supplied it.

The safer approach is to distinguish three stages:

policy intention;

draft legislation;

enacted law.

That distinction becomes particularly important in fast-moving fintech regulation, where press releases frequently arrive before final statutory text.

PRISM+ and Pakistan’s High-Value Settlement Infrastructure

Retail payments are only one layer of the financial system.

At the wholesale and institutional level, Pakistan operates real-time gross settlement infrastructure.

The PS&EFT Act expressly authorises SBP to establish and operate one or more Real Time Gross Settlement (“RTGS”) systems.

In June 2025, SBP launched PRISM+ Pakistan Real-Time Interbank Settlement Mechanism Plus.

PRISM+ replaced and expanded the previous RTGS infrastructure and integrates a Central Securities Depository module alongside enhanced funds-settlement functionality.

The development is important because high-value interbank settlement is the plumbing beneath much of the visible financial system.

Consumers may never see PRISM+.

Financial stability depends upon systems like it working.

The April 2026 PRISM+ Operating Rules

On 16 April 2026, SBP issued revised Operating Rules for PRISM+.

The Rules superseded the earlier PRISM Operating Rules issued in 2018 and govern matters including participation, Central Securities Depository operations, account management, settlement and finality, efficiency, effectiveness and operational continuity.

This is another excellent illustration of the relationship between primary and secondary law.

Section 6 of the 2007 Act authorises the RTGS architecture.

The 2026 Rules specify how the modern system operates.

Anyone analysing settlement obligations in 2026 therefore needs both.

Why PRISM+ Matters to Lawyers Who Never Advise Banks

It might be tempting for an ordinary commercial lawyer to dismiss RTGS regulation as relevant only to central bankers.

That would be a mistake.

Settlement rules affect questions involving finality, insolvency, securities transactions, institutional payment obligations and the legal consequences of operational failure.

They also illustrate the wider principle that the visible customer transaction is frequently only the outermost layer of a far more complex settlement chain.

When litigation asks whether money “moved”, lawyers should ask what stage of the payment process is actually being discussed.

Instruction?

Authorisation?

Clearing?

Settlement?

Customer credit?

Each has legal significance.

Pakistan’s Payment-System Regulation Is Increasingly Risk-Based

The modern direction of SBP regulation is visibly risk-based.

This can be seen clearly in the 2025 Technology Risk Management Framework for Payment Institutions.

SBP expressly stated that the framework is not “one size fits all”. Instead, implementation must be proportionate to the size, nature and type of payment services and the complexity of the institution’s technology operations.

This is sensible regulatory design.

A small EMI operating a limited wallet product does not necessarily present the same technology-risk profile as a nationally significant switching infrastructure.

The principles may overlap.

The controls should respond to actual risk.

Technology Risk Is Now a Legal Risk

For fintech founders, this is a crucial conceptual shift.

Cybersecurity used to be treated as an IT problem that the lawyers could safely leave to somebody in a server room.

That approach is becoming increasingly untenable.

Where the regulator prescribes technology governance, cybersecurity controls, incident management, resilience and accountability, failure of technology controls can become a regulatory breach.

Cyber risk therefore becomes legal risk.

The board cannot simply say:

“Our vendor handles that.”

Outsourcing the function does not necessarily outsource accountability.

The March 2026 Technology-Risk Deadline Has Passed

The Technology Risk Management Framework gave payment institutions until 31 March 2026 to comply with the relevant requirements.

That date has now passed.

This matters for legal opinions issued after that date.

The framework should no longer be described merely as an impending regulatory expectation.

For the payment institutions within its scope, it is part of the present compliance environment.

A due-diligence review of an EMI, PSO or PSP should therefore consider technology-risk compliance as a current matter.

Consumer Conduct Regulation Has Also Changed

SBP has simultaneously strengthened its consumer-protection architecture.

On 17 October 2025, it issued the Business Conduct and Fair Treatment of Consumers Regulatory Framework (“BC&FRF”).

The framework consolidates and strengthens earlier regulatory instructions concerning responsible business conduct and fair treatment of consumers.

It became immediately effective for most covered financial institutions, while the governance component took effect from 1 January 2026; for EMIs, the framework became effective from 1 January 2026.

This is a major development for the interpretation of contemporary payment disputes.

The 2007 Act Is No Longer the Whole Consumer-Protection Story

A customer complaining about an electronic payment in 2026 should not automatically assume that every relevant obligation appears inside the text of the PS&EFT Act.

The Act remains foundational.

But applicable duties may also arise from:

the EFT Regulations;

product-specific SBP requirements;

the BC&FRF;

technology-risk rules;

payment-card rules;

AML/CFT requirements;

the customer’s contract;

and, depending upon the institution, other banking or financial-sector regulation.

The legal analysis must therefore identify the institution, the product, the transaction and the applicable regulatory layer.

This is more work than typing “section 40 PS&EFT Act” into a complaint.

It is also considerably more likely to produce a legally coherent result.

Why Fair Treatment Matters in Payment Products

Digital financial services create particular consumer vulnerabilities.

Customers often interact with automated interfaces rather than human staff.

Terms are accepted by clicking screens.

Fees may be embedded within workflows.

Authentication can occur in seconds.

Fraud can happen remotely.

Disputes may initially be processed by automated complaint systems.

That environment makes fair-treatment principles especially important.

A contractual term can be technically disclosed yet practically incomprehensible.

A complaint procedure can formally exist yet be unusable.

A bank can issue hundreds of security warnings while still failing to respond meaningfully to a particular suspicious transaction pattern.

Modern conduct regulation therefore looks beyond mere formal documentation.

It increasingly asks whether the customer’s treatment was substantively fair.

A Payment System Is an Ecosystem, Not a Single Institution

Perhaps the most useful conceptual change for understanding the PS&EFT Act in 2026 is to stop imagining an electronic payment as a simple line from Bank A to Bank B.

Modern payment transactions may involve:

the customer’s device;

the customer’s bank or wallet provider;

an authentication layer;

a payment gateway;

a switch;

a payment-system operator;

a clearing arrangement;

a settlement institution;

the beneficiary’s institution;

and sometimes further processors or technology vendors.

Each participant may perform a different legal function.

That fragmentation creates enormous convenience.

It also creates enormous scope for parties to point at one another when something fails.

The law’s task is to preserve responsibility across the chain.

Outsourcing Does Not Necessarily Eliminate Responsibility

A financial institution may outsource a technological function.

That does not automatically allow it to outsource every legal duty owed to the customer or regulator.

The precise result depends upon the applicable rule, contract and factual structure.

But the broader regulatory direction is clear: institutions must exercise appropriate oversight over critical services and technology upon which regulated functions depend.

Otherwise, consumer protection would become illusory.

Every regulated entity could simply outsource the inconvenient part of its obligations and then explain that the problem belonged to the vendor.

Financial regulation generally does not permit responsibility to evaporate so easily.

Payments Law and the Principle of Technological Neutrality

One reason the 2007 Act remains workable is that many of its core concepts are technologically neutral.

Authorisation.

Account.

Payment instrument.

Payment system.

Clearing.

Settlement.

Electronic transfer.

Security.

Disclosure.

Error.

Liability.

These concepts survive changes in interface.

A fingerprint can replace a PIN.

A phone can replace an ATM.

A QR code can replace manual account entry.

An instant-payment switch can replace slower interbank processes.

The legal questions remain recognisable.

Who gave the instruction?

Was it authorised?

Which institution processed it?

What rules governed the transaction?

When did settlement become final?

What information was disclosed?

What happens if an error occurred?

Who bears the loss?

These are not obsolete questions.

They are payment law.

The Limits of Technological Neutrality

Technological neutrality does, however, have limits.

New technologies can create risks that an older statute addresses only at a high level.

Artificial-intelligence-enabled fraud detection, biometric databases, cloud concentration risk, API vulnerabilities, tokenisation, sophisticated social engineering and real-time payment scams require detailed operational rules that a 2007 Parliament could not realistically have drafted.

This is precisely why the later SBP frameworks matter.

The correct response is not to pretend that the 2007 Act specifically mandates every modern control.

The correct response is to read the statute together with the modern regulatory instruments that actually address them.

That approach is both more legally accurate and intellectually cleaner.

Pakistan’s Modern Payments Framework Is Layered

The legal architecture can therefore be visualised as a series of layers.

At the base sits the Payment Systems and Electronic Fund Transfers Act, 2007.

Upon that foundation sit specialised regulatory regimes such as the PSO/PSP Rules, EFT Regulations, EMI Regulations, payment-card requirements, Raast rules and PRISM+ rules.

Around those sit cross-cutting regulatory frameworks governing technology risk, consumer conduct, AML/CFT, operational resilience, data handling and other financial-sector obligations.

And beyond them sit separate legal regimes that may be triggered by the particular business model banking law, foreign-exchange law, credit regulation, PECA, corporate law, taxation and, since 2026, virtual-asset regulation.

No single circular answers every question.

The Great “Fintech Licence” Myth

There is accordingly no single Pakistani licence called:

The Fintech Licence.

A fintech might require EMI authorisation.

Another may require PSO/PSP authorisation.

A lending fintech may fall within an entirely different regulatory perimeter.

A virtual-asset business may require PVARA authorisation.

An entity may instead operate as a technology vendor to a licensed financial institution without itself performing the regulated financial function although that arrangement requires careful analysis rather than assumption.

The word “fintech” describes the commercial species.

It does not identify the regulatory genus.

Why This Matters Before Investment Is Raised

The regulatory classification can fundamentally alter a company’s economics.

Capital requirements may apply.

Customer-fund safeguarding may apply.

Governance standards may apply.

Fit-and-proper requirements may apply.

Cybersecurity obligations may apply.

Restrictions may exist on activities.

Approval may take place in stages.

Partnerships with banks may be required.

Some revenue models may be impermissible under the proposed licence.

Some customer-fund flows may need redesign.

That means legal architecture can affect the valuation model before the first investor cheque is signed.

A founder who spends a year building a product and only then asks what licence it requires has approached the problem backwards.

Regulatory Approval Is a Process, Not a Logo

The staged PSO/PSP model is particularly useful in illustrating another point.

Financial authorisation is not merely a badge placed in the website footer.

In-principle approval, pilot approval and commercial-operation approval represent different stages of regulatory confidence.

A business should describe its regulatory status accurately.

“Approved by SBP” can be materially misleading if what the company possesses is only an early-stage permission subject to further requirements.

This principle will become increasingly relevant across Pakistan’s fintech and virtual-asset sectors.

When regulatory approval is staged, the stage matters.

Financial Inclusion and the Law

Pakistan’s payment regulation is also closely connected with financial inclusion.

Raast, EMIs, digital wallets and merchant QR payments can reduce the need for expensive physical branch infrastructure.

They can make low-value transactions commercially viable.

They can facilitate government disbursements.

They can improve access for consumers and small businesses previously excluded from conventional financial services.

But inclusion is not achieved merely by digitising exclusion.

A payment service that is inaccessible, opaque, insecure or impossible to complain about does not become inclusive because it exists on a phone.

This is why consumer protection and financial inclusion should be understood as complementary rather than competing objectives.

Trust is infrastructure.

Cash Still Matters But the Direction of Travel Is Clear

Pakistan remains a society in which cash continues to play an enormous economic role.

The existence of a sophisticated payment law does not eliminate cultural, infrastructure or documentation barriers to digitisation.

Yet the direction of travel is unmistakable.

The FY2024–25 payment data, Raast expansion, merchant initiatives, EMI growth and payment-system designations demonstrate an increasingly digital financial economy.

This makes the quality of payment regulation more important with every year that passes.

When only a small minority use digital payments, a regulatory failure harms a minority.

When most retail-payment transactions are digital, a regulatory failure can become an economy-wide problem.

What the 2007 Act Got Surprisingly Right

With nearly two decades of hindsight, several structural choices in the Act have aged reasonably well.

It gave SBP substantial rule-making power.

It distinguished systems from instruments.

It recognised electronic money.

It addressed clearing and settlement finality.

It contemplated non-bank service providers.

It required secure transfer mechanisms.

It established documentation and disclosure rules.

It created an error-resolution process.

It allocated burdens in unauthorised-transfer disputes.

It anticipated systemic risk.

The statute is by no means perfect.

But it was not drafted merely as a law of ATMs.

That matters.

Where the Act Shows Its Age

The weaknesses are equally real.

Its drafting reflects an earlier technological era.

Some terminology is awkward.

Certain provisions require interpretation alongside later regulations.

Cybersecurity is dealt with at a highly general statutory level.

Contemporary questions concerning platform architecture, cloud outsourcing, biometric risks, open APIs, sophisticated digital identity, instant-payment scams and emerging forms of financial intermediation cannot sensibly be resolved from the Act alone.

The statutory text also predates Pakistan’s dedicated modern virtual-asset regime.

These weaknesses do not necessarily mean the Act has failed.

They mean the Act has increasingly become a framework statute whose effectiveness depends upon the quality of secondary regulation.

Should Pakistan Replace the Act?

There is a respectable case for eventual legislative consolidation.

A modern payments statute could rationalise terminology, explicitly incorporate contemporary payment-service categories, clarify regulatory boundaries, modernise enforcement provisions and integrate principles concerning operational resilience and digital financial infrastructure.

But repeal should not be confused with reform.

The existing Act already supports substantial modern infrastructure.

Any replacement would need to preserve settlement certainty, regulatory continuity and existing authorisations.

A poorly managed legislative transition could create more uncertainty than the ageing terminology it sought to cure.

Financial-system reform requires continuity as well as novelty.

The Better Question in 2026

The most useful question is therefore no longer:

“Is the Payment Systems and Electronic Fund Transfers Act 2007 outdated?”

A better question is:

“How does the 2007 Act interact with the modern regulatory ecosystem that now sits beneath and around it?”

That is the question this article seeks to answer.

And the answer is considerably more interesting than simply calling the statute old.

The law has become an ecosystem.

The Act remains its statutory foundation.

Consumer Rights, Unauthorised Electronic Transfers, Banking Fraud and Financial Institution Liability Under the PS&EFT Act

The systemic provisions discussed above explain how Pakistan’s payment infrastructure is regulated.

For most consumers, however, the Payment Systems and Electronic Fund Transfers Act, 2007 becomes important for a very different reason.

Money has gone somewhere it was not supposed to go.

Perhaps an internet-banking transfer appears which the customer says he never made.

Perhaps the customer was deceived by somebody impersonating a bank official and disclosed an OTP.

Perhaps a mobile-banking account was compromised.

Perhaps the wrong amount was transferred.

Perhaps funds were debited but never properly credited to the beneficiary.

Perhaps a standing instruction continued after the customer attempted to stop it.

Or perhaps the financial institution simply responds to the complaint with the increasingly familiar sentence:

“Our system shows that the transaction was successfully authenticated.”

That sentence may be relevant.

It is not necessarily the legal answer.

The PS&EFT Act creates a considerably more structured framework for determining what the institution was required to disclose, what evidence should exist, what constitutes an error, how an alleged error should be investigated, who bears the burden of proof and what remedies may follow.

Those statutory provisions become especially important in contemporary banking-fraud disputes.

Section 29: A Consumer Must Know About the Fee Before Paying It

Section 29 deals specifically with fees imposed by an ATM operator or other service provider.

Where a fee is imposed upon a consumer for providing the relevant service, the statutory framework requires notice both of the fact that a fee will be charged and of its amount.

The notice must be conspicuous at the ATM or electronic terminal.

More importantly, the service provider cannot impose the fee unless the consumer receives the required notice and elects to continue with the transaction afterwards. (pakistancode.gov.pk)

The underlying principle remains relevant far beyond ATMs.

A financial charge should not be discovered after the transaction where the consumer was entitled to know about it beforehand.

That idea reappears throughout modern financial-consumer regulation.

Section 30: Terms and Conditions of Electronic Transfers

Section 30 is considerably more important than its comparatively modest heading suggests.

It requires the terms and conditions governing Electronic Fund Transfers involving a consumer account to be disclosed when the consumer contracts for the EFT service.

The statute contemplates disclosure of matters including the consumer’s potential liability for unauthorised transfers, how and where an allegedly unauthorised transfer should be reported, the kinds of transfers available, transaction limits, charges, stop-payment rights in relation to pre-authorised transfers, error-resolution rights, institutional liability and the circumstances in which account information may be disclosed to third parties.

This matters because legal liability should not be reconstructed solely from whatever a financial institution says after a dispute has already arisen.

The consumer relationship begins before the disputed transaction.

What was disclosed when the service was offered?

What terms applied?

What risks were communicated?

What limitations were imposed?

What complaint mechanism was identified?

These matters can become evidentially important.

“Terms and Conditions Apply” Is Not a Complete Legal Argument

Banks understandably rely upon their contractual terms.

But a standard-form customer agreement cannot simply displace mandatory statutory rights.

Indeed, section 49 later makes any purported waiver of rights or causes of action created under the Act void.

The contract therefore matters.

But it matters within the statutory framework.

A financial institution cannot create its own private version of the PS&EFT Act through boilerplate.

This becomes particularly important where a term attempts to allocate every possible loss to the customer once an OTP, PIN or password has been used.

Authentication evidence may be extremely significant.

The contractual proposition that such evidence makes every transaction legally incontestable is quite another matter.

Section 31: Material Changes Require Advance Notice

Section 31 generally requires a financial institution or authorised party to notify consumers at least twenty-one days before a material change to relevant account terms or conditions.

There is an exception where immediate change is necessary to maintain or restore the security of the EFT system or consumer account; if the change becomes permanent, the statute then requires subsequent notification.

This is a sensible balance.

Consumers should ordinarily receive advance notice of material contractual changes.

But a financial institution should not be forced to leave a known security vulnerability open for three weeks merely because customer notices have not yet completed their journey.

Security can justify immediate action.

Permanent alteration still requires transparency.

Documentation Is Not Administrative Clutter

Chapter VI concerns documentation of transfers.

Its importance has increased rather than diminished as banking has become digital.

Section 32 requires documentation or proof to be made available for an EFT initiated from an electronic terminal, identifying matters such as the amount, date, type of transfer, relevant account, third-party recipient or originator, terminal identification and account-holder information.

In litigation, those details are often not clerical trivia.

They are the transaction.

A disputed electronic payment cannot be adequately analysed merely by saying that PKR 500,000 “went out”.

The evidential questions are more granular.

At what time?

Through which channel?

From which device or terminal?

Using which account?

To whom?

Under which transaction identifier?

Was there a new beneficiary?

Was the transaction preceded by a password reset?

Was a mobile device newly registered?

Was a transaction limit altered?

Did the login originate from an unusual location or device?

Was an OTP issued?

To which number?

At what time?

What occurred immediately before and immediately afterwards?

The modern evidential trail is digital.

The legal reasoning still depends upon reconstructing chronology.

Section 33: Periodic Statements

Section 33 requires a financial institution to provide periodic statements for electronically accessible consumer accounts.

The statute contemplates statements at least monthly, unless another period is prescribed or requested, and requires relevant information including opening and closing balances, fees and an address and telephone number for enquiries or error notifications.

Periodic statements serve two functions.

They are informational.

They are also evidential.

A customer who never looks at an account for twelve months may find it more difficult factually to explain delayed discovery of repeated unauthorised transactions.

Conversely, a bank cannot reasonably complain that customers failed to detect irregularities if it did not provide the information it was itself obliged to provide.

Rights and responsibilities operate in both directions.

Section 34: Evidence That a Transfer Occurred Is Not Necessarily Evidence That It Was Authorised

Section 34 provides that statutory documentation indicating that an electronic transfer was made may be admissible and constitute prima facie proof that the transfer occurred.

The distinction in that sentence is extraordinarily important.

Proof that a transfer occurred is not necessarily proof that the customer authorised it.

These propositions are easily confused because digital records are persuasive.

A system log may establish that a transfer was executed.

It may establish the amount.

It may establish the beneficiary.

It may establish the device session.

It may establish that an OTP was correctly entered.

Those facts can be highly relevant to authorisation.

But the statutory burden concerning an allegedly unauthorised EFT is separately addressed by section 41.

A bank cannot therefore necessarily win an unauthorised-transfer dispute merely by proving the uncontroversial fact that its computer executed the transfer.

The real question may be who legally authorised it and under what circumstances.

Section 35: Pre-authorised Electronic Fund Transfers

Section 35 is short.

A pre-authorised EFT may be authorised by the consumer in writing or another accepted form.

The consumer may stop the pre-authorised transfer by notifying the financial institution.

It is worth stating what the statutory section does not say.

The section itself does not contain the elaborate subscription-management rules sometimes attributed to it in online commentary.

It does not enact a detailed BNPL regime.

It does not prescribe dynamic-pricing algorithms.

It does not require health clubs, streaming services or insurance providers to follow a bespoke PS&EFT subscription code.

Those matters may be affected by contracts, SBP regulations, consumer law and product-specific rules.

But the primary statutory proposition in section 35 is considerably simpler: prior authorisation is required, and a consumer possesses a right to stop a pre-authorised EFT by notifying the institution.

Why Standing Instructions and Recurring Payments Still Matter

The simplicity of section 35 does not make it unimportant.

Recurring payments are now ubiquitous.

Insurance premiums.

Utility bills.

Subscriptions.

Loan instalments.

Card-linked services.

Charitable donations.

Investment contributions.

Digital services.

Where an EFT is genuinely pre-authorised, the institution must be able to identify the authority upon which it relies.

If the customer has effectively withdrawn that authority and the transfer nevertheless continues, section 43 expressly contemplates institutional liability for failure to stop a pre-authorised transfer when properly instructed.

This is a much cleaner legal route than attempting to turn every recurring-payment dispute into an “unauthorised fraud” case.

The correct legal characterisation matters.

Chapter VII: The Error-Resolution Machinery

Sections 36 to 39 form one of the most consumer-significant parts of the entire Act.

They create a statutory procedure dealing with errors.

That word is deliberately broad.

Section 36 defines an error to include:

an unauthorised Electronic Fund Transfer;

an incorrect EFT to or from the consumer’s account;

omission of an EFT from a periodic statement;

a computational or bookkeeping error;

receipt of an incorrect amount from an electronic terminal;

and another error recognised by SBP.

An allegedly unauthorised transfer is therefore not some legally exotic event lying outside the statute.

It is expressly one of the statutory forms of error.

Ten Business Days Matter

Once an alleged error is notified, the financial institution or authorised party must investigate and report the result of its investigation to the consumer in writing within ten business days.

Where the notification was oral, the institution may require written confirmation within ten business days.

This is an important practical point for customers.

Telephone notification may be valuable for speed.

Written notification is valuable for evidence.

Where substantial money is involved, a consumer should ordinarily preserve proof of the date and substance of the complaint.

That may include email.

Complaint numbers.

Courier receipts.

Branch acknowledgements.

Screenshots of in-app complaints.

Recorded reference numbers.

A legal dispute several months later should not begin with an argument about whether the bank was ever informed.

The Customer Should Not Send a Novel Instead of a Complaint

There is, however, an opposite mistake.

Some fraud victims now respond to an unauthorised transaction by generating a six-page complaint containing every financial statute they can find.

That can be counterproductive.

A good first notification should establish the essential facts:

the disputed transaction;

the amount;

the date;

the account;

the fact that authority is denied or error alleged;

when the customer discovered the transaction;

what immediate protective action was taken;

and the remedy requested.

Legal submissions can follow.

The initial priority is to trigger the proper investigation and preserve the record.

A complaint does not become stronger because it accuses the bank simultaneously of fraud, breach of trust, terrorism financing, constitutional violations and crimes against humanity.

Precision generally survives scrutiny better than indignation.

Section 37: Once Error Is Found, Correction Must Be Prompt

If the institution determines that an error occurred, section 37 requires correction promptly and no later than one business day after that determination, including re-crediting the consumer’s account with mark-up where applicable.

The section further requires the investigation to conclude within ten business days after receipt of notice.

This is a relatively strict statutory timetable.

It reflects an important policy judgment.

If a consumer has genuinely lost access to funds because of an institutional error, delay itself can become part of the injury.

Rent still falls due.

Businesses still require working capital.

Employees still need wages.

A bank balance is not merely an abstract number.

It represents economic ability.

Section 38: “No Error Found” Must Be Explained

Section 38 becomes crucial when the institution rejects the complaint.

If the institution determines after investigation that no error occurred, it must send the consumer an explanation of its findings within three business days after concluding the investigation.

More importantly, upon the consumer’s request, the institution must promptly provide copies of the documents upon which it relied in reaching that conclusion.

That statutory right is remarkably useful.

If a bank says:

“Our investigation confirms that the transaction was genuine.”

the next question can be:

“What documents did your investigation rely upon?”

This can expose the real evidential basis of the decision.

Sometimes that basis is strong.

Sometimes it consists of little more than a system entry stating that credentials were accepted.

The strength of the legal position should be assessed from the evidence actually available, not the confidence of the conclusion.

What Documents Might Matter in an Unauthorised EFT Case?

Depending upon the payment channel and the dispute, relevant material may include:

transaction logs;

IP records;

device registration records;

login history;

beneficiary-addition records;

OTP generation and delivery logs;

SMS or push-notification records;

password-reset records;

call-centre recordings;

branch records;

customer-notification records;

fraud-monitoring alerts;

transaction-limit changes;

internal investigation reports;

beneficiary-account details;

and records concerning the receiving institution.

The Act does not enumerate every one of these modern data points.

Technology has changed.

The evidential principle has not.

An investigation must have evidence behind it.

Section 39: Triple Damages Powerful, But Not Automatic

Section 39 is one of the most dramatic provisions in the Act.

It provides for triple damages in specified circumstances.

That phrase understandably attracts attention.

But it should not be converted into:

“Banking fraud = three times your money.”

The statutory remedy is conditional.

It arises in a case filed under section 50 where the court makes the relevant finding.

Amongst the circumstances identified are failure to re-credit within the statutory period combined with failure to conduct a good-faith investigation or lack of a reasonable basis for believing that the account was not in error.

Triple damages may also arise where the institution knowingly and wilfully concludes that no error occurred when that conclusion could not reasonably be drawn from the evidence available at the time.

The remedy is therefore directed particularly at bad investigation, unreasonable denial and wilful disregard of evidence.

That is a very different proposition from automatic punitive damages every time a transaction is disputed.

Good-Faith Investigation Is More Than a Checkbox Exercise

Section 39 makes the quality of the institution’s investigation legally important.

A bank therefore exposes itself to unnecessary risk if its complaint procedure degenerates into:

OTP used → customer liable → complaint closed.

That may sometimes be the ultimate conclusion.

It should ordinarily be the result of an investigation rather than its substitute.

A proper investigation should engage with the allegation actually made.

If the customer says a phone was replaced without authority, examine device-registration evidence.

If the customer says no OTP arrived, examine delivery records.

If the customer says a caller impersonated the bank and the transaction immediately followed unusual account activity, consider the fraud indicators relevant to the institution’s systems and applicable rules.

If the bank believes the customer voluntarily authorised the payment, explain why.

Reasoned decision-making is not bureaucracy.

It is risk control.

Section 40: Consumer Liability Is Often Misquoted

Section 40 is frequently oversimplified.

The statutory language provides that a consumer shall be liable for an unauthorised EFT only where the card or other means of access used was an accepted card or other means of access and the issuer provided a method by which the user could be identified as the person authorised to use it, including by signature, photograph, fingerprint or electronic or mechanical confirmation.

The section is somewhat awkwardly drafted.

What it does not expressly say is equally important.

It does not establish a simple rule that:

“if an OTP was entered, customer loses.”

Nor does it state:

“the bank is automatically liable whenever the customer says the transaction was unauthorised.”

The statutory allocation must be read together with section 41.

Section 41: The Burden of Proof

Section 41 is one of the most significant provisions in Pakistan’s electronic-banking law.

In an action involving consumer liability for an unauthorised Electronic Fund Transfer, the burden of proof lies upon the financial institution or authorised party to show that the EFT was authorised.

Where authorisation is established, the institution must also establish that the conditions of liability under the Act were met and that required disclosures were actually made.

That is a deliberate evidential allocation.

It makes practical sense.

The financial institution controls the core transactional infrastructure.

It controls the logs.

It controls much of the authentication evidence.

It controls security architecture that the customer cannot independently inspect.

Requiring the consumer to prove a negative that he did not authorise a digital transaction processed inside systems controlled by somebody else would frequently be unrealistic.

So Parliament places the evidential burden on the institution.

But Section 41 Does Not Create Automatic Bank Liability

This qualification became particularly important in United Bank Limited v President of the Islamic Republic of Pakistan, reported as 2025 CLD 834, decided by the Lahore High Court, Rawalpindi Bench, on 2 May 2025.

The connected petitions involved customers who said they had been deceived by callers impersonating bank or government officials and induced to disclose personal information, access codes and OTPs.

The Banking Mohtasib had directed the banks to reimburse or compensate the customers.

Justice Asim Hafeez held that the Banking Mohtasib had jurisdiction over the relevant complaints, but criticised the manner in which absolute responsibility had effectively been shifted to the banks merely by reliance upon section 41.

The Court considered that principles of contributory and comparative negligence also required examination and remanded the complaints for fresh determination after allowing the parties to produce appropriate documentary and other evidence. (Alwakeelo AI)

That judgment adds an important layer of nuance.

A Fraud Victim Can Be Deceived and Still Have Contributed to the Loss

The modern social-engineering problem is difficult precisely because it often involves genuine deception combined with genuine customer action.

Consider a fraudster who telephones a customer while impersonating a bank employee.

The fraudster knows the customer’s name.

Perhaps part of the account number.

Perhaps a CNIC fragment.

The customer is persuaded that the bank is conducting security verification.

The customer then reads out an OTP.

Minutes later money disappears.

Was the eventual EFT authorised?

The customer says no: he never intended to transfer money to the fraudster.

The bank says its authentication requirements were satisfied because the OTP was correctly entered.

The fraudster says nothing because, ideally, he has disappeared.

This is not always a question capable of sensible resolution by one slogan.

The Difference Between Authentication and Intention

Authentication establishes that a particular credential or security mechanism was successfully used.

Authorisation asks whether the transaction was legally authorised.

Those concepts overlap.

They are not necessarily identical.

A signature can be forged.

A password can be stolen.

A phone can be cloned.

An OTP can be socially engineered.

A biometric can theoretically be compromised.

Conversely, a customer can voluntarily issue instructions and later regret them.

The legal task is therefore to determine what occurred on the evidence.

Section 41 matters because it allocates the burden.

The 2025 Lahore High Court decision matters because it warns against converting that burden into strict and automatic institutional liability regardless of customer conduct. (Alwakeelo AI)

The 2025 Judgment Is Not a Licence for Banks to Blame Every Fraud Victim

The opposite overreading would be equally mistaken.

United Bank Limited v President did not establish a universal rule that anyone who discloses an OTP must bear the entire loss.

The Court remanded the disputes for proper consideration of evidence and comparative responsibility.

That is fundamentally different from declaring that OTP disclosure is always a complete defence for the bank.

Relevant questions may include:

What information did the fraudster already possess?

Did that information appear capable of having come from the bank or an associated channel?

What security warnings had the customer received?

How clear were they?

Was the disputed transaction unusual in amount, destination or pattern?

Were new devices or beneficiaries involved?

Did the bank’s risk controls respond?

Did the customer receive transaction alerts?

How quickly did the customer notify the bank?

Could subsequent transfers have been stopped?

Did the institution comply with all applicable security requirements?

These are fact-sensitive questions.

Good legal analysis resists converting a fact-sensitive judgment into another internet slogan.

Habib Bank Limited v Federation of Pakistan: A Foundational EFT Decision

One of the leading earlier cases is Habib Bank Limited through Litigation Officer v Federation of Pakistan, reported as 2018 CLD 1152, decided by Justice Athar Minallah of the Islamabad High Court.

The litigation concerned customers who alleged unauthorised electronic transfers from accounts for which HBL had provided internet-banking services.

The bank challenged orders made by the Banking Mohtasib and upheld by the President.

A central issue concerned the bank’s non-compliance at the relevant time with SBP’s 2015 security requirements for internet banking, which required at least two-factor authentication.

The Court treated compliance with SBP’s security directions as a statutory obligation flowing from sections 3 and 15 of the PS&EFT Act.

It concluded that the bank owed a duty of care to its customers and that failure to implement the required security controls or adequately warn customers about resulting risk constituted maladministration in the circumstances before it. (Pakistan Case Law)

What Habib Bank Actually Establishes

The case is important for several propositions.

First, section 15 is not merely aspirational.

Security requirements prescribed by SBP can acquire real legal significance.

Secondly, a bank can owe both regulatory and ordinary duties of care to customers using electronic-payment facilities.

Thirdly, the Banking Mohtasib’s jurisdiction is not automatically excluded simply because the dispute also falls within the PS&EFT Act.

And fourthly, compliance has to be assessed against the regulatory standard actually applicable at the relevant time.

The Court noted that the disputed transfers had taken place before the bank implemented the relevant SBP security directions. (Pakistan Case Law)

That factual chronology was essential.

A 2018 Judgment Should Not Be Applied Without Its Facts

This qualification matters.

Habib Bank does not mean that a bank is liable for every fraudulent electronic payment forever because two-factor authentication exists.

The case dealt with a specific regulatory failure during a specific period.

Modern banks operate under materially different security infrastructure.

Conversely, banks should not assume that modernisation ends their legal obligations.

The applicable regulatory baseline has itself become more demanding.

The question in a current case is:

What obligations applied when this transaction occurred, and did this institution satisfy them?

The applicable standard moves with regulation.

The Banking Mohtasib and the PS&EFT Act Can Coexist

The jurisdictional issue raised in Habib Bank is commercially significant.

Banks argued that the PS&EFT Act was a special law governing EFTs and therefore displaced the Banking Mohtasib’s jurisdiction.

The Islamabad High Court rejected that proposition in the circumstances before it.

The Court held that the Banking Mohtasib’s jurisdiction over violations of SBP regulations, directions and forms of maladministration could coexist with the PS&EFT Act; there was no irreconcilable inconsistency requiring implied repeal. (Pakistan Case Law)

The practical consequence is important.

A consumer complaint involving an electronic transfer can engage more than one legal regime.

The mere existence of a civil remedy under the PS&EFT Act does not automatically eliminate the statutory banking-ombudsman route.

MCB Bank v Federation of Pakistan: The Sindh High Court Takes the Same Broad View

The Sindh High Court addressed overlapping questions in Messrs Muslim Commercial Bank Limited v Federation of Pakistan, reported as PLD 2019 Sindh 624 and 2020 CLD 829.

The petitions challenged concurrent decisions of the Banking Mohtasib and the President.

The Division Bench examined the structure and jurisdiction of the Banking Mohtasib under the Banking Companies Ordinance, 1962 and rejected arguments seeking to reduce the institution to a merely conciliatory mechanism incapable of adjudication.

The decision confirms the substantial statutory role of the Banking Mohtasib in dealing with banking maladministration and related customer grievances. (Alwakeelo AI)

This line of jurisprudence is important because Pakistani consumers often assume that a dispute must be either a “bank complaint” or a “court case”.

The remedial architecture can be more layered.

The Banking Mohtasib Is Not Merely a Complaint Inbox

The Banking Mohtasib is a statutory institution possessing quasi-judicial functions within its prescribed jurisdiction.

That does not mean it possesses unlimited jurisdiction over every financial dispute.

Nor does it mean that ordinary civil remedies disappear.

But treating Mohtasib proceedings as an informal customer-service escalation misunderstands their legal significance.

A properly prepared complaint should therefore identify:

the factual grievance;

the relevant banking or regulatory obligation;

the disputed transaction;

the documentary evidence;

the institution’s response;

and the relief sought.

It should not merely reproduce angry correspondence already ignored by the bank.

The 2025 Lahore High Court Decision Strengthens the Mohtasib’s Role While Requiring Better Analysis

United Bank Limited v President is particularly interesting because it simultaneously does two things.

It confirms that the Banking Mohtasib possesses jurisdiction over complaints alleging banking malpractice, violations of banking law or regulation, maladministration, fraud relating to fund transfers and fraudulent or unauthorised withdrawals.

Yet it also insists that the merits must be analysed properly.

The Court did not approve a simplistic model in which section 41 automatically determines liability without considering contributory or comparative negligence.

That balance is jurisprudentially healthy.

Consumer protection should not mean dispensing with evidence.

Institutional protection should not mean dispensing with responsibility.

Justice usually lies in the facts between those extremes.

Bank Alfalah Limited v President of Pakistan: The 2026 Development

The issue returned before the Sindh High Court in Bank Alfalah Limited v President of Pakistan and others, C.P. No. D-1081 of 2026, reported as 2026 SHC KHI 696, decided on 11 March 2026.

The underlying complaint concerned alleged misappropriation from a hacked joint account.

The Banking Mohtasib had ruled against the bank, and the President had dismissed the bank’s representation.

Before the High Court, counsel attempted to rely upon section 41 and the Lahore High Court’s decision reported as 2025 CLD 834.

The Sindh High Court noted that the section 41 point had not been pleaded in the constitutional petition and that both forums below had already dealt with section 41.

It further emphasised that constitutional jurisdiction is not a vehicle for reappraising factual evidence as though the High Court were exercising a second appeal.

The petition was dismissed. (Caselaw)

The Procedural Lesson From Bank Alfalah

The case contains a lesson reaching beyond banking law.

A potentially useful legal argument raised at the wrong procedural stage may be practically worthless.

The bank attempted to pivot towards section 41 during argument after questions arose regarding the maintainability of its constitutional challenge.

The Court treated that point as inadequately pleaded and, in any event, insufficient to justify reopening factual findings already made by the statutory forums. (Caselaw)

For litigants, this is important.

The statutory burden of proof should be addressed before the original decision-maker.

Evidence should be produced there.

Relevant objections should be pleaded there.

The constitutional jurisdiction of the High Court is not ordinarily designed to repair litigation strategy after the evidential record has closed.

The 2025 and 2026 Cases Are Not Necessarily Contradictory

At first glance, someone might say:

“Lahore High Court set the Mohtasib orders aside in 2025, while Sindh High Court upheld them in 2026. Which court is right?”

That is too crude.

The factual and procedural contexts were different.

The Lahore High Court considered connected cases where the Mohtasib had, in the Court’s assessment, failed sufficiently to engage with contributory and comparative negligence.

The Sindh High Court in Bank Alfalah was dealing with a constitutional petition in which the relevant section 41 argument was not properly pleaded and the Court declined to reappraise concurrent factual findings.

The judgments therefore illustrate different propositions.

One concerns the quality of the original liability analysis.

The other concerns the limits of constitutional review.

Both matter.

The Emerging 2026 Position on Banking Fraud

Taken together, the authorities suggest a more mature analytical model.

A bank is not automatically liable merely because a customer says:

“I was defrauded.”

A customer is not automatically liable merely because the bank says:

“An OTP was used.”

The relevant enquiry should examine statutory burden, customer conduct, institutional conduct, regulatory compliance, transaction evidence and causation.

That is a better framework than either form of strict liability.

Phishing and Social Engineering

Phishing and social-engineering fraud create particular difficulty because the attacker often weaponises trust rather than defeating the bank’s encryption directly.

The fraudster may impersonate:

a bank officer;

SBP;

NADRA;

FIA;

a courier company;

a telecom operator;

a merchant;

a government benefits scheme;

a tax authority;

or even a relative.

The victim may voluntarily disclose information without voluntarily intending the resulting transfer.

That distinction is central.

Cybersecurity is not solely about whether a firewall was breached.

Humans can themselves become the attack surface.

Does Sharing an OTP Make the Customer Negligent?

It can be compelling evidence of negligence.

It is not necessarily the end of every legal enquiry.

The exact circumstances matter.

An unsophisticated customer who receives an unsolicited call and reads out an OTP despite a clear message saying:

“Do not share this OTP with anyone. Bank staff will never ask for it.”

may have materially contributed to the loss.

But imagine instead that the customer’s banking credentials were first compromised through an institutional breach, the fraudster already possessed substantial confidential data, the customer received misleading transaction notifications, and the bank’s monitoring system ignored highly anomalous transfers.

The apportionment question becomes different.

The virtue of comparative-negligence analysis is precisely that it permits more than one party to have failed.

Banks Also Have Information Advantages

Financial institutions possess capabilities individual consumers do not.

They can detect patterns across millions of accounts.

They know whether a beneficiary is newly added.

They know whether a device is new.

They can identify rapid changes to contact information.

They may recognise a destination account already implicated in fraud reports.

They can establish transaction velocity.

They can assess deviations from a customer’s normal profile.

Not every unusual transaction must be blocked.

Excessive friction can itself damage payment services.

But modern fraud prevention requires risk-based analysis.

The regulatory question increasingly becomes whether controls were appropriate to the risk.

The Customer Has Responsibilities Too

Consumer protection does not justify pretending that customers are passive objects with no responsibilities.

A customer should protect access credentials.

Security warnings should be read.

Passwords should not be shared.

OTP codes should not normally be disclosed.

Suspicious calls should be treated cautiously.

Unauthorised activity should be reported promptly.

Devices should be protected.

Fraud complaints should be truthful.

The law works poorly when responsibility is treated as morally offensive.

Fairness requires protecting customers from institutions with vastly greater power without pretending that customer conduct can never matter.

“I Sent the Money Myself Because I Was Scammed” Is Legally Different From “I Never Sent It”

This distinction is particularly important.

Suppose a fraudster persuades a customer to transfer PKR 500,000 voluntarily to an account controlled by the fraudster.

The customer knowingly presses “send”.

The fraud lies in the inducement.

That is different from a fraudster taking over the customer’s account and initiating a transfer without the customer’s knowledge.

Both are fraud scenarios.

They are not necessarily the same unauthorised EFT scenario.

In the first case, the transfer instruction may technically have been authorised even though the underlying reason for making it was fraudulent.

In the second, the transfer itself may have been unauthorised.

Legal analysis should identify which case actually exists.

Authorised Push Payment Fraud and Pakistan

Internationally, this distinction is sometimes discussed under the label authorised push payment fraud.

The victim is deceived into personally authorising a payment.

Pakistan’s PS&EFT Act does not contain a bespoke modern APP-fraud regime comparable to approaches being developed in some other jurisdictions.

That creates difficult questions.

The mere fact that the customer’s instruction was obtained by fraud does not necessarily transform the bank into the insurer of every payment the customer consciously executed.

Yet a bank may still face regulatory or negligence questions where obvious warning signs existed or applicable obligations were breached.

Again, the facts matter.

Mule Accounts and Receiving Banks

Electronic fraud often involves another party entirely: the account receiving stolen funds.

Fraudsters rarely keep proceeds in the victim’s account.

Money is transferred through “mule” accounts, sometimes opened by willing participants and sometimes controlled through stolen identities or deceptively recruited account holders.

This creates questions concerning the receiving institution.

Were proper KYC procedures followed?

Was the account activity consistent with the customer’s profile?

Were suspicious transactions detected?

Had complaints already been received?

Were funds rapidly dispersed?

Did authorities issue a freeze instruction?

These issues may engage AML, banking regulation, criminal law and evidential questions beyond the PS&EFT Act itself.

An Innocent Recipient Can Become Entangled in the Fraud Chain

The receiving account holder is not always a conspirator.

This is particularly relevant in P2P transactions and online commerce.

Suppose a genuine trader sells an asset to A.

A pays from funds stolen from B.

The trader sees cleared funds and delivers the asset.

Investigators later trace B’s money to the trader.

The banking trail initially identifies the trader as recipient of stolen money.

That does not establish criminal knowledge.

But it explains why accounts can be frozen while facts are investigated.

Contemporaneous documentation becomes vital.

The law ultimately cares about knowledge, conduct and evidence.

Transaction chains do not explain themselves.

Wrong-Beneficiary Transfers

Another common problem involves genuine mistakes rather than fraud.

A customer enters the wrong account or selects the wrong beneficiary and authorises the transfer.

The customer’s instinct is often:

“The bank must reverse it.”

The legal position is more difficult once the payment has settled.

Settlement infrastructure requires certainty.

The beneficiary may also have received funds without entitlement, giving rise to restitutionary issues between the parties.

Whether the sending institution can retrieve the funds depends upon the system, timing, consent, applicable rules and circumstances.

The PS&EFT error-resolution provisions should not be read as an unlimited statutory power allowing banks casually to confiscate money from a recipient whenever a sender says:

“I made a mistake.”

Rights exist on both sides of the ledger.

Section 43: What Financial Institution Liability Actually Covers

Section 43 is another provision which is routinely given more work than Parliament assigned to it.

The section provides liability for damages proximately caused by specified institutional failures.

These include failure to make a properly instructed EFT in accordance with account terms, in the correct amount or in a timely manner, subject to identified exceptions.

It also addresses a failure to make a transfer because of insufficient funds where the institution itself failed properly to credit a deposit that would have provided sufficient funds.

And it addresses failure to stop a pre-authorised transfer after being properly instructed to do so.

That is the statutory text.

Section 43 is not a universal clause saying:

“Anything unpleasant involving electronic money is the bank’s liability.”

Proximate Causation Matters

The words “damages proximately caused” matter.

A claimant ordinarily needs a causal relationship between the institutional failure and the loss claimed.

Suppose a bank delays a PKR 50,000 transfer by one hour.

A customer then claims PKR 100 million because he says the delay caused him emotional distress, ruined a speculative business opportunity and destroyed his reputation.

Section 43 does not automatically make those claims recoverable.

Loss must still be connected to the relevant breach according to legal principles of causation and proof.

Statutory liability does not abolish ordinary evidential discipline.

The Exceptions in Section 43 Matter Too

Section 43 itself recognises circumstances in which failure to make a transfer does not produce the ordinary liability, including insufficient funds, legal process or encumbrance restricting transfer, an exceeded credit limit and other circumstances prescribed by SBP.

So if an account is lawfully frozen pursuant to legal process, a bank’s refusal to execute the customer’s transfer is not automatically an EFT breach.

The bank may be performing another legal obligation.

The correct question is whether the restriction itself has lawful foundation.

Section 44: Force Majeure Is Not a Magic Phrase

Section 44 protects financial institutions, authorised parties, operators and participants from aspects of section 43 liability where they establish by a preponderance of evidence that the relevant act or omission resulted from force majeure or circumstances beyond their control, provided reasonable care was exercised to prevent the occurrence and the diligence required by the circumstances was exercised.

It also addresses a technical malfunction known to the consumer when the transfer was attempted.

This is narrower than:

“System was down, therefore no liability.”

The party invoking force majeure must show more.

The event must genuinely have been beyond control.

Reasonable preventative care matters.

Diligence after the event matters.

Resilience is part of responsibility.

A Foreseeable Technology Failure Is Not Necessarily Force Majeure

A server failing because nobody installed routine updates is not conceptually the same as an unforeseeable catastrophe.

A payment platform crashing because capacity planning was inadequate is not automatically an act of God.

A cybersecurity incident resulting from ignored vulnerabilities may be technically dramatic without being legally unforeseeable.

Modern technology-risk regulation makes this distinction increasingly important.

The more a risk is foreseeable and manageable, the more difficult it becomes to characterise failure as something wholly beyond institutional control.

Section 45: Bona Fide Error and Actual Damages

Section 45 recognises situations where relevant failures were not intentional and resulted from bona fide error despite reasonable procedures designed to avoid them.

In such circumstances the statutory provision limits liability to actual damages proved.

This reflects another sensible balance.

Not every operational error is misconduct.

Complex payment systems will occasionally fail despite reasonable controls.

The law can compensate actual loss without necessarily treating every mistake as punitive wrongdoing.

Bad faith and innocent error should not carry identical consequences.

Improper Issuance of Payment Instruments

Section 46 prohibits the unsolicited issuance of cards, codes or other means of account access except in response to a request or application, or as renewal or substitution of an existing accepted access instrument.

Section 47 creates a limited exception for unsolicited distribution where the instrument is not validated, proper disclosures accompany it and activation occurs only after consumer request and identity verification.

These provisions embody a simple consumer-security idea.

An institution should not create usable access to someone’s funds and then leave the consumer to discover that access instrument after the event.

Activation and identity verification matter.

Section 48: When Technology Prevents Payment

Section 48 provides that where a technical malfunction prevents completion of an EFT initiated by the consumer to another person who had agreed to accept payment electronically, the consumer’s obligation to that person is suspended until the malfunction is corrected and the EFT can be completed, unless the payee subsequently demands payment through another means.

This is a subtle but useful provision.

A customer should not necessarily be placed immediately in default merely because the agreed electronic payment channel failed.

The law recognises that payment technology can become temporarily unavailable.

Section 49: Statutory Rights Cannot Simply Be Waived Away

Section 49 is emphatic.

No agreement may contain a provision waiving a right conferred or cause of action created by the Act.

Any such waiver is void.

For financial institutions, this means customer contracts should be drafted around the statute rather than against it.

For consumers, it means a heavily drafted disclaimer is not necessarily the final word.

Where Parliament has created a mandatory right, private contracting cannot simply erase it.

Section 50: Civil Damages

Section 50 creates a civil damages remedy where a person fails to comply with the Act, subject to the statutory qualifications.

The recoverable amount includes actual damage sustained because of the failure.

This provision should be read together with section 39 where triple damages are sought and with the statutory defences in the following sections.

The architecture is therefore not:

breach → automatic windfall.

It is:

breach → proved loss → applicable statutory remedy, subject to statutory conditions and defences.

Section 51: Bona Fide Error Defence

Section 51 protects a defendant in specified circumstances where the violation was unintentional and resulted from a bona fide error despite procedures reasonably adopted to avoid it.

The existence of this defence again shows that the Act distinguishes between culpable and non-culpable failures.

An institution which made a genuine isolated error despite robust procedures occupies a different legal position from an institution which operated an inadequate system, ignored warnings or conducted a sham investigation.

The law is entitled to recognise that moral and operational distinction.

Section 52: Good-Faith Reliance on SBP

Section 52 protects certain actions or omissions taken in good faith in conformity with applicable SBP rules, instructions, authorised interpretations or approvals.

It also protects institutions that used appropriate model disclosure clauses issued by SBP even where the underlying regulatory interpretation or model was later changed or invalidated.

This is important for regulatory certainty.

An institution should generally be able to rely upon official regulatory guidance without facing retrospective punishment because the guidance later changes.

Financial regulation would become unworkable otherwise.

Section 53: Correcting the Failure Before Litigation

Section 53 provides another incentive for early remediation.

A person may avoid liability for certain failures where, before litigation is instituted, it notifies the consumer, complies with the Act, makes the appropriate account adjustment and pays actual or otherwise applicable damages.

The policy is sensible.

The law should encourage institutions to correct genuine mistakes promptly rather than forcing every customer into litigation simply to obtain what the institution already knows is due.

Litigation should be a remedy.

It should not become a customer-service workflow.

Section 54: Consumers Can Also Litigate in Bad Faith

The consumer-protection structure is not entirely one-sided.

Section 54 allows a court, where an unsuccessful action was brought in bad faith or for harassment, to award litigation costs and reasonable attorney’s fees to the defendant.

This matters because fraud disputes can themselves be fraudulent.

A customer can knowingly make a transaction and later deny it.

A merchant can manufacture a dispute.

A claimant can abuse statutory language in an attempt to pressure a bank.

Consumer protection requires compassion for genuine victims.

Justice also requires consequences for dishonest claims.

Section 55: Parliament Intended EFT Litigation to Be Fast

Section 55 contains one of the most striking procedural provisions in the Act.

A civil action may be brought before a court of competent jurisdiction.

The court should not adjourn the matter for more than ten days at a time, and aggregate adjournments granted to the defendant should not exceed three.

Most remarkably, the statute directs the court to pronounce judgment within ninety days after notice was first served upon the defendant.

The legislative intention is unmistakable.

Electronic-fund disputes were supposed to move quickly.

Whether litigation practice always honours that aspiration is a different question.

Delay Can Defeat the Remedy Even Where the Claim Ultimately Succeeds

The reason for statutory expedition is obvious.

Financial loss compounds with time.

A business deprived of working capital today may not be restored merely because it receives the same nominal amount three years later.

Inflation intervenes.

Commercial opportunities disappear.

Legal costs accumulate.

Relationships change.

Evidence deteriorates.

A remedy delayed can become mathematically and practically inferior to the right originally lost.

The ninety-day legislative command therefore reflects more than procedural tidiness.

It reflects an understanding that money has a temporal value.

The Criminal Side of the PS&EFT Act

The Act also contains criminal provisions.

Section 56 criminalises knowingly and wilfully providing false or inaccurate information, failing to provide information required by the Act, or otherwise knowingly and wilfully failing to comply with the statute, with imprisonment potentially extending to three years, a fine potentially extending to PKR 3 million, or both.

Sections 57 and 58 address more direct forms of electronic-payment fraud.

Section 57 deals with knowing use of counterfeit, fictitious, altered, forged, lost, stolen or fraudulently obtained debit instruments in electronic commerce and associated receipt or handling of property obtained through such instruments.

Section 58 criminalises cheating by impersonation and dishonest use of credit cards, debit cards, codes or other means of access to EFT devices where wrongful gain or loss results.

These provisions demonstrate that the PS&EFT Act is not merely a regulatory statute.

It also contains its own criminal offences.

The PS&EFT Act Does Not Replace PECA or the Penal Code

Electronic fraud may simultaneously engage other criminal statutes.

The Prevention of Electronic Crimes Act, 2016 (“PECA”) may apply where unauthorised access, interference with systems, electronic fraud or identity-related cyber offences are involved.

The Pakistan Penal Code may apply where cheating, forgery, criminal breach of trust or related offences are made out.

Money laundering legislation may become relevant where proceeds are concealed or transformed.

The correct criminal charge depends upon the conduct.

The existence of a PS&EFT offence does not magically displace every other applicable criminal provision.

Nor should investigators mechanically add every possible offence merely because a transaction happened online.

Each statutory ingredient still requires proof.

Civil Liability and Criminal Liability Are Different Questions

A bank can bear civil or regulatory responsibility without anyone at the bank having committed a crime.

A fraudster can commit a crime without the bank being civilly liable for the loss.

A customer can contribute negligently to the loss while the fraudster remains criminally responsible.

An institution can breach a regulatory obligation without becoming criminally fraudulent.

These propositions can coexist.

One of the recurring failures in public discussion of electronic banking fraud is to treat every dispute as though only one party can be legally wrong.

Law is rarely so obliging.

What Should a Customer Do Immediately After Discovering an Unauthorised EFT?

The legal framework suggests a practical sequence.

The customer should notify the financial institution immediately and obtain documentary proof of the complaint.

Access credentials should be changed.

Compromised cards, devices or channels should be blocked where appropriate.

Relevant messages, emails, call logs and screenshots should be preserved rather than deleted.

The customer should identify each disputed transaction precisely.

If the bank later rejects the claim, the customer should consider requesting the evidence relied upon under section 38.

Where fraud is involved, timely reporting to the relevant investigative authority may also be necessary.

A lawyer should ideally receive the evidence before the customer begins sending contradictory explanations to multiple agencies.

Why Contradictory Complaints Cause Problems

A customer might tell the bank:

“I never received any OTP.”

Then tell FIA:

“I received an OTP but accidentally shared it.”

Then tell the Banking Mohtasib:

“My phone was hacked and I never saw the OTP.”

Then send an AI-generated legal notice stating:

“The bank itself executed the fraudulent transfer.”

Four versions of one event can destroy an otherwise arguable case.

Consistency matters.

Where the facts are uncertain, say they are uncertain.

A lawyer can help reconstruct the chronology from records before committing the client to a theory.

Facts should generate the legal argument.

The legal argument should not manufacture facts.

What Should a Bank Preserve?

The same principle applies to institutions.

Once a substantial EFT dispute arises, the institution should preserve the complete relevant audit trail.

Deleting logs under ordinary retention schedules while litigation is reasonably foreseeable can create obvious evidential difficulty.

Relevant staff should preserve communications.

Fraud-risk findings should be documented.

Receiving institutions may need to be contacted promptly.

Where funds remain recoverable, time can be decisive.

A technically sophisticated organisation should be expected to understand preservation obligations better than the average consumer.

Bank Account Freezes After Fraud

Fraud investigations frequently result in bank accounts being restricted or frozen.

The legal basis of the restriction matters.

A customer should determine:

which institution imposed the restriction;

whether it arose from the bank’s internal compliance process;

whether FIA or another investigating agency issued an instruction;

whether a court order exists;

whether the entire account or only a disputed amount is affected;

and whether the restriction is temporary, investigative or pursuant to formal proceedings.

“Your account is frozen” describes the consequence.

It does not identify the legal authority.

Source of Funds Is Becoming Increasingly Important

Modern payment disputes increasingly overlap with AML and source-of-funds scrutiny.

A customer receiving large sums from numerous unrelated persons may be conducting perfectly lawful business.

The bank may still ask what the business is.

That is not necessarily harassment.

A regulated institution is expected to understand customer activity.

Problems arise where the customer has no coherent documentary explanation.

A lawful transaction poorly documented can initially resemble an unlawful transaction.

This is especially common in informal P2P businesses.

Businesses Should Not Use Personal Accounts as Permanent Payment Infrastructure

A persistent risk in Pakistan’s digital economy is the use of ordinary personal accounts to conduct substantial commercial payment activity.

This may create tax issues.

AML issues.

Account-profile mismatches.

Evidence problems.

Consumer disputes.

And difficulties when the bank asks why hundreds of unrelated persons are sending money into an account opened for personal use.

The legal question is not merely whether the underlying business is lawful.

It is whether the financial infrastructure being used is appropriate to the activity.

Good structuring begins before the account is frozen.

The Same Lesson Applies to Fintech Companies

A fintech business should understand where customer complaints will land before launching.

Who investigates failed transactions?

Who handles chargeback-like disputes?

Who has access to payment logs?

Who is responsible for consumer communications?

What happens if an outsourced processor fails?

Which entity re-credits the customer?

What records are retained?

What contract governs inter-institutional responsibility?

A platform which answers those questions only after its first serious fraud event is already late.

Modern Consumer Protection Requires Both Prevention and Redress

The old model of payment regulation concentrated heavily on correcting errors after they occurred.

Modern regulatory thinking increasingly emphasises preventing predictable harm.

That includes:

security-by-design;

transaction monitoring;

customer warnings;

appropriate authentication;

incident response;

rapid complaint handling;

and fair treatment.

This is why the PS&EFT Act should now be read alongside SBP’s newer technology-risk and consumer-conduct frameworks.

The statute supplies rights and liabilities.

Modern regulation increasingly supplies the operational expectations capable of preventing those rights from being violated in the first place.

The Myth of the Perfectly Secure Payment System

No payment system can eliminate fraud entirely.

Higher security can create higher friction.

Every additional verification step can make legitimate payments slower.

If controls become intolerably burdensome, consumers seek alternatives.

Regulation therefore attempts to optimise rather than abolish risk.

The proper legal standard is rarely:

“Did fraud ever occur?”

A more useful question is:

“Were the controls, disclosures, investigation and response appropriate to the risk and applicable regulatory requirements?”

Perfection is not the legal standard.

Reasonable and compliant systems are.

Equally, “Fraud Happens” Is Not a Defence

The impossibility of eliminating all fraud does not absolve institutions from preventable failures.

If a bank knew of a vulnerability and ignored it, the fact that fraud exists everywhere is irrelevant.

If an institution failed to implement mandatory security controls, the sophistication of the fraudster does not erase the regulatory breach.

If the bank received a prompt fraud notification and took no prudent steps while further transfers continued, causation may arise in relation to subsequent loss.

Risk is inevitable.

Negligence is not.

The Ethical Foundation of Consumer Banking Law

There is a deeper reason this area of law matters.

Banking depends upon entrusted property.

The customer does not merely purchase an ordinary product.

He entrusts the institution with money representing work, savings, business capital, medical security, school fees, retirement and sometimes an entire family’s financial stability.

That relationship creates responsibility.

But responsibility is reciprocal.

A customer entrusted with security credentials also possesses obligations of care.

A fair payments system therefore cannot proceed from either extreme:

that institutions are infallible and customers bear all technological risk;

or that customers bear no responsibility for their own deliberate acts.

The law’s task is to allocate responsibility according to evidence.

That is a less dramatic proposition than social-media outrage.

It is also more just.

The Current Legal Position on Unauthorised EFTs in Pakistan

As at September 2026, several propositions can safely be drawn.

An unauthorised EFT is expressly treated as an “error” under section 36.

The financial institution must investigate notified errors within the statutory timetable.

Where error is established, correction must follow promptly.

Where no error is found, the customer is entitled to an explanation and may request the documents relied upon.

Triple damages are possible only in defined circumstances and are not automatic.

Section 41 places the evidential burden concerning authorisation upon the financial institution or authorised party.

But the Lahore High Court has made clear that this burden should not necessarily be converted into absolute bank liability where customer contributory or comparative negligence may also require consideration.

The Banking Mohtasib has jurisdiction over relevant banking maladministration and unauthorised-transfer complaints, and that jurisdiction is not automatically excluded by the PS&EFT Act.

Superior courts will nevertheless scrutinise the legality of Mohtasib decisions within the limits of constitutional jurisdiction.

And a constitutional petition should not be treated as an opportunity to conduct a fresh factual trial after the statutory forums have already made concurrent findings.

That is a considerably more nuanced legal position than:

“If there was an OTP, the customer loses.”

It is also more nuanced than:

“Section 41 means banks always refund fraud.”

The law is inconveniently fond of facts.

Payment Card Security, Fintech Regulation, Cybersecurity, Raast, EMIs, PSOs/PSPs and the Future of Pakistan’s Payment Law

The consumer-liability provisions discussed above tell us what happens when an Electronic Fund Transfer goes wrong.

Modern payment regulation must also ask a more preventive question:

What should institutions be doing before something goes wrong?

That question has become far more important since the PS&EFT Act was enacted.

A payment ecosystem in which billions of digital transactions move annually cannot depend exclusively upon remedies after loss has occurred. Regulation must also address authentication, payment-card security, technology governance, operational resilience, outsourcing, customer-fund protection, fraud monitoring, merchant acceptance and the licensing of institutions that increasingly sit between conventional banks and consumers.

Pakistan’s modern regulatory architecture now does so through a series of instruments issued under or alongside the PS&EFT Act.

The Regulations for Payment Card Security 2016

One of the earliest major modernisation measures came through the Regulations for Payment Card Security, issued by SBP on 10 June 2016 under section 3 read with section 15 of the PS&EFT Act.

The Regulations became effective on 1 January 2017 and apply to financial institutions and Payment System Operators and Payment Service Providers involved in issuing, acquiring and processing payment cards in Pakistan, subject to the scope and exclusions stated in the instrument. (sbp.org.pk)

The Regulations were designed to establish minimum operational, administrative, technical and physical safeguards for payment-card operations.

That formulation is important.

Security is not merely an encryption question.

It involves people.

Processes.

Technology.

Physical controls.

Governance.

Merchant arrangements.

Fraud management.

Incident response.

And the manner in which cardholder data passes through the payment ecosystem.

EMV and International Card-Security Standards

SBP’s 2016 framework also mandated adoption of the Europay, MasterCard and Visa (“EMV”) standard, thereby moving Pakistan towards international chip-card standards intended to reduce vulnerabilities associated with magnetic-stripe cards and counterfeit fraud. SBP’s contemporaneous statement described the Regulations as requiring Card Service Providers to develop comprehensive card-security frameworks and align operations with international best practice.

The Regulations themselves expressly recognise standards including PCI DSS and related payment-card security concepts.

These requirements matter because card-security litigation often involves more than the customer’s conduct at the point of transaction.

There may also be questions concerning:

the issuer;

the acquirer;

the merchant;

the card processor;

the payment network;

the authentication mechanism;

the security of stored card data;

and whether regulatory controls were properly implemented.

The card is only the visible object.

The payment architecture behind it is considerably more complex.

Card-Present and Card-Not-Present Fraud Are Different Risks

A traditional counterfeit-card fraud may involve copying data from a physical card and reproducing it.

An online card-not-present transaction creates different risks because the merchant does not physically inspect the customer or card.

The regulatory response must therefore be risk-sensitive.

A control appropriate for an ATM withdrawal may not be adequate for e-commerce.

Similarly, measures appropriate for a low-value contactless transaction may not be adequate for a high-value remote transaction involving a newly registered device.

Modern payment security is therefore increasingly based upon layers rather than one universal credential.

Two-Factor Authentication Is Not a Magic Shield

Two-factor authentication materially improves security.

It does not establish perfection.

The Islamabad High Court’s decision in Habib Bank Limited v Federation of Pakistan, discussed earlier, became important precisely because regulatory requirements for two-factor authentication had not been properly implemented at the relevant time.

Once implemented, two-factor authentication strengthens the institution’s evidential case.

It does not necessarily eliminate every possibility of social engineering, SIM compromise, account takeover or credential theft.

The appropriate legal question remains whether the transaction was authorised and whether the institution complied with the applicable security framework.

Technology strengthens evidence.

It does not abolish legal analysis.

Card Data Has Value Even When the Physical Card Never Leaves the Customer

Fraud victims sometimes say:

“My card was still in my wallet, therefore the bank must have been hacked.”

That conclusion does not necessarily follow.

Card credentials can be compromised without physical possession of the card.

They may be obtained through phishing.

Compromised merchant databases.

Malware.

Skimming.

Social engineering.

Insecure storage.

Or fraudulent websites.

This is why payment-card regulation focuses upon the entire lifecycle of payment information rather than merely possession of plastic.

The Technology Risk Management Framework for Payment Institutions

Pakistan’s most important recent development in this field is the Technology Risk Management Framework for Payment Institutions, issued by SBP on 3 October 2025.

The Framework applies to Electronic Money Institutions and Payment System Operators/Payment Service Providers.

SBP explained that the rapid technological transformation of payment services had increased exposure to cyber and other technology risks and that the Framework was intended to provide baseline technology-governance and risk-management requirements.

Payment institutions were required to comply with the relevant requirements by 31 March 2026.

That deadline has now passed.

The Framework is therefore part of the current compliance environment rather than a future policy aspiration.

A Risk-Based Framework Is More Sensible Than a Checklist

One of the strengths of the 2025 Framework is SBP’s express recognition that technology-risk management should not operate as a one-size-fits-all exercise.

Implementation must be commensurate with the size, nature and type of payment services provided and the complexity of the institution’s technology operations.

This is regulatory proportionality.

The same principle appears increasingly across international financial regulation.

A systemically important switch processing enormous transactional volumes poses different risks from a small electronic-money business serving a limited consumer segment.

Both require security.

The controls appropriate to each need not be identical.

Board Responsibility Cannot Be Delegated to the IT Department

A mature technology-risk framework necessarily treats cyber risk as a governance issue.

This is because cyber incidents can create:

financial losses;

regulatory breaches;

customer harm;

data exposure;

operational interruption;

reputational damage;

and systemic consequences.

Those are not merely technical outcomes.

They are enterprise risks.

A board therefore cannot sensibly treat technology risk as:

“something the IT people handle.”

Specialists should implement controls.

Governance bodies must understand the risk those controls are intended to manage.

Outsourcing Creates Risk Rather Than Making Risk Disappear

Modern payment companies outsource extensively.

Cloud hosting.

Call centres.

Software development.

Cybersecurity monitoring.

Payment processing.

Identity verification.

Customer support.

Data storage.

Disaster recovery.

The commercial reasons are obvious.

Specialist vendors can provide expertise and scale more efficiently than every institution building everything internally.

But outsourcing can create concentration and dependency risk.

If a critical vendor fails, the payment institution may fail with it.

A regulated entity therefore cannot safely regard outsourcing as a means of exporting accountability.

“Our Vendor Did It” Is Usually the Beginning of the Investigation, Not the End

Suppose an EMI outsources a critical function to a technology provider.

A security failure occurs.

Thousands of customers lose access to wallets.

The EMI says:

“This was the vendor’s system.”

That may be contractually relevant between the EMI and vendor.

It does not necessarily answer the regulator or consumer.

Who selected the vendor?

What due diligence was undertaken?

What contractual controls existed?

Was the arrangement supervised?

Were contingency plans tested?

Could service be migrated?

Was customer data adequately protected?

Those questions concern the regulated entity’s own governance.

Outsourcing can allocate contractual risk.

It cannot automatically erase regulatory responsibility.

Cybersecurity Should Be Built Into the Product

A recurring mistake among early-stage fintech businesses is to treat cybersecurity as something added shortly before commercial launch.

The legal and technical architecture should develop together.

If strong identity controls are required, the user journey should reflect them from the beginning.

If transactions must be traceable, logging architecture should be designed accordingly.

If access privileges must be restricted, the software architecture must make that possible.

If customer funds require segregation, the financial architecture must support it.

If incidents must be detected quickly, monitoring needs to exist before the attack.

Retrofitting regulation into finished technology is often substantially more expensive than building compliance into the product.

Operational Resilience Is Different From Cybersecurity

Cybersecurity asks whether systems can resist malicious attack.

Operational resilience asks the wider question:

Can the service continue or recover when something goes wrong?

The disruptive event may be a cyberattack.

It may equally be:

hardware failure;

power interruption;

telecommunication failure;

data corruption;

software malfunction;

vendor collapse;

natural disaster;

human error;

or capacity overload.

A well-secured system that cannot recover from a mundane database failure is not resilient.

Payment regulation increasingly recognises both dimensions.

Backups Are Not Enough Unless Recovery Actually Works

Many organisations proudly state:

“We have backups.”

The meaningful question is:

Can you restore the system from them?

A backup that has never been tested may provide psychological comfort rather than operational resilience.

The same applies to disaster-recovery plans.

A document stating that operations will move to a secondary site is useful only if:

the site exists;

the data are available;

staff know what to do;

communications function;

and the process has been tested.

Regulators increasingly care about evidence of resilience rather than declarations of resilience.

Incident Response Can Affect Legal Liability

What an institution does after discovering an incident may matter almost as much as what occurred before it.

Was the vulnerability contained?

Were affected credentials invalidated?

Were customers warned?

Were further losses prevented?

Were regulators notified where required?

Were logs preserved?

Was forensic evidence contaminated?

Were counterpart institutions contacted?

A delayed or chaotic response can transform a contained incident into a wider loss.

Causation does not stop at the first breach.

The Payment Card Regulations and the 2025 Technology Framework Now Operate Together

The 2016 card-security regime remains important for card-specific risks.

The 2025 Technology Risk Management Framework addresses broader technology governance across payment institutions.

These instruments should not be treated as competitors.

They are layers.

The specific card environment sits within the wider technology-risk environment.

This is characteristic of contemporary financial regulation.

One framework may govern the product.

Another may govern the institution.

Another may govern consumer treatment.

Another may govern AML obligations.

The same transaction can engage all four.

Electronic Money Institutions in More Detail

The 2023 EMI Regulations are now central to Pakistan’s non-bank digital-payments sector.

SBP expressly revised the earlier 2019 regime to encourage new business models, use cases and technological solutions while incorporating domestic experience and international practice.

The policy objective is therefore not prohibition of fintech innovation.

It is innovation within a regulated perimeter.

That distinction is important.

Regulation can impose cost.

It also creates legitimacy.

A well-regulated wallet provider can integrate with banks, merchants, payment networks and national infrastructure in a way that a wholly informal payment business cannot.

An EMI Is a Financial Institution With a Limited Mandate

An EMI should be understood as a specialised payment institution.

It is not merely a software company.

Once the institution issues stored electronic monetary value and interacts with customer funds, the regulator becomes concerned with matters including:

capital;

governance;

safeguarding;

customer identification;

operational controls;

technology risk;

consumer complaints;

redemption;

and permissible business activities.

SBP presently describes EMIs as non-bank entities offering low-value interoperable digital payment instruments including wallets, prepaid cards and contactless payment instruments.

That regulatory classification distinguishes an EMI from a bank while recognising that consumers are nevertheless entrusting money to it.

Why Customer-Fund Protection Is Fundamental

A wallet balance may appear to a consumer exactly like a bank balance.

Legally, the structures can be very different.

That makes safeguarding mechanisms particularly important.

Consumers should not need to understand insolvency law every time they load PKR 5,000 into a mobile wallet.

The regulatory framework therefore has to ensure that customer money is appropriately protected and accounted for within the authorised EMI structure.

The core policy is straightforward:

money entrusted for payment purposes should not casually become working capital available for unrelated speculation by the issuer.

A Wallet Balance Is Not Venture Capital

Imagine an EMI receives PKR 1 billion from customers.

The founders decide that idle customer balances could generate better returns if invested in a speculative property project.

The customers did not invest in the company.

They loaded payment value.

Those are legally and ethically different relationships.

The integrity of electronic-money regulation depends upon preserving that distinction.

Innovation in payments should not become involuntary investment by customers.

PSOs and PSPs Serve a Different Function

As discussed in Part I, PSOs and PSPs primarily provide payment-system infrastructure and intermediary services such as gateways, switching, clearing and related functions.

SBP’s 2014 Rules expressly recognise electronic-payment gateways supporting e-commerce, remittances and POS networks, clearing houses, ATM switches and other permitted payment-system operations.

Current SBP guidance confirms that PSO/PSP authorisation proceeds through three stages:

in-principle approval; pilot-operation approval; and commercial-operation approval.

The current minimum capital requirement stated by SBP is PKR 200 million, unless another amount is prescribed, and PSOs/PSPs may not act as custodians of customer money or perform banking functions merely because they hold PSO/PSP approval.

That restriction deserves to be written in very large letters on some fintech pitch decks.

Routing Money Is Not the Same as Holding Money

A payment gateway can transmit instructions between parties.

That does not necessarily entitle it to hold customers’ balances.

A switch can route payment messages.

That does not automatically make it a bank.

A PSP can provide infrastructure.

That does not make every financially adjacent activity lawful.

The distinction is not pedantic.

Custody of customer funds materially alters risk.

The more control an entity has over customers’ money, the more serious the consequences if the entity fails.

Fintech Partnerships Need Regulatory Mapping

A modern payment product may involve several entities.

For example:

a fintech develops the mobile application;

an EMI issues the wallet;

a bank maintains settlement accounts;

a PSP provides the gateway;

Raast moves funds;

a merchant receives payment;

and an outsourced vendor performs digital identity verification.

One brand may appear on the customer’s screen.

Several regulated relationships exist underneath.

The customer may reasonably believe “Company X” is providing the whole service.

Contractually and legally, the structure can be fragmented.

Good product documentation should make those relationships sufficiently clear.

White-Labelling Does Not Change the Underlying Legal Activity

A technology provider may allow another brand to present its payment service under a white-labelled interface.

That arrangement can be commercially useful.

It does not change the regulatory substance.

If one entity is the regulated wallet issuer, another company’s logo cannot transfer the licence.

If a third party is merely a distributor or technology interface, it should not hold itself out as performing regulated functions it does not perform.

Branding must not create regulatory fiction.

The Raast Merchant Revolution

One of the most important commercial developments in Pakistan’s payment ecosystem is the expansion of Raast Person-to-Merchant (“P2M”) payments.

Merchant acceptance historically represented one of the greatest practical obstacles to payment digitisation.

People may possess digital accounts.

But if shops continue demanding cash, those accounts remain partly isolated from everyday commerce.

Raast P2M addresses this by allowing merchants to receive interoperable digital payments through infrastructure including QR codes and other Raast payment mechanisms.

The 2025 Merchant Push

During 2025 SBP issued several measures directed towards merchant digitisation.

Its payment circulars included Facilitation of Merchants’ Operations on 25 July 2025, further digitisation measures in September and a dedicated subsidy for Raast P2M QR payments.

The policy direction is unmistakable.

Merchant acceptance is being treated as a national financial-infrastructure objective rather than merely a private competition between card acquirers.

PKR 3.5 Billion Was Allocated to Encourage Raast QR Payments

On 23 September 2025, SBP announced a government-funded support scheme under the Prime Minister’s Cashless Economy initiative.

The Government allocated PKR 3.5 billion for Raast P2M QR-code transactions conducted from 1 September 2025 to 30 June 2026.

The subsidy mechanism provided support calculated at 0.5 per cent of transaction value or PKR 100, whichever was lower, subject to the stated allocation and mechanism.

The subsidy period has now concluded.

Its policy significance remains.

The State actively subsidised merchant adoption of interoperable instant payments.

That is a strong indication of the direction in which Pakistan’s retail-payment environment is moving.

QR Codes Are Convenient and Fraudsters Know It

QR payments introduce their own risk profile.

A consumer can be directed to a fraudulent QR code.

A legitimate merchant’s printed QR can be physically replaced.

A scammer can send a QR code which directs payment to an unexpected account.

The technology is convenient because complex payment information can be embedded within a simple image.

That same convenience means users may not appreciate where funds are actually going.

Payment applications should therefore display sufficient beneficiary information before final confirmation.

And consumers should look at it.

“Scan and Pay” Does Not Mean “Scan and Stop Thinking”

Fast payments reduce friction.

Fraudsters benefit from friction reduction too.

The safest instant-payment interface is therefore not necessarily the one requiring the fewest possible seconds.

An effective payment system needs enough friction to allow informed confirmation without destroying convenience.

That balance is difficult.

It is also where good user-interface design becomes part of risk management.

Instant Payments Change the Fraud Timeline

Traditional bank transfers often involved delays during which mistakes or suspicious transactions could occasionally be intercepted.

Real-time payments can become final within seconds.

The legal consequence is profound.

Prevention becomes more valuable because post-transfer recovery becomes harder.

Fraud-detection systems must therefore act quickly.

Customers must report quickly.

Receiving institutions must react quickly.

Investigators must preserve records quickly.

Speed creates enormous consumer value.

It also compresses the time available to prevent loss.

Payments Law, AML and CFT

Electronic payment regulation operates alongside Pakistan’s wider anti-money-laundering and counter-financing-of-terrorism framework.

It is important not to attribute every AML obligation directly to section 24 of the PS&EFT Act, as older commentary sometimes did.

Section 24 concerns EMIs.

AML/CFT obligations arise through the dedicated statutory and regulatory framework applicable to the relevant financial institution and activity.

What matters operationally is that regulated payment institutions must understand who their customers are, monitor transactions according to applicable risk standards and report suspicious activity where legally required.

AML Is Not the Same Thing as Proving a Crime

A transaction can be suspicious without being criminal.

This distinction is frequently misunderstood.

Financial institutions operate preventive monitoring systems.

They often must act before criminal guilt is established.

An unusual transaction may therefore trigger:

enhanced review;

source-of-funds questions;

temporary restrictions;

or suspicious-transaction reporting.

That does not necessarily mean the institution has concluded the customer is guilty of money laundering.

It means the risk required examination.

Source of Funds Is an Evidential Question

Consider a customer receiving PKR 25 million.

The bank asks where it came from.

Possible answers include:

sale of property;

inheritance;

business revenue;

foreign remittance;

investment redemption;

loan repayment;

gift;

crypto liquidation;

or fraud.

The amount alone does not establish which explanation is true.

Documents do.

A sensible compliance strategy therefore asks:

What evidence would I produce if this transaction were questioned six months from now?

That is usually easier to answer before the documents disappear.

Small Businesses Often Create Their Own Compliance Problems

A legitimate Pakistani SME might route turnover through a personal account because it appears convenient.

Payments arrive from hundreds of unrelated people.

The owner later complains that the bank has “randomly” questioned the account.

From the bank’s perspective, the pattern may be substantially inconsistent with the account profile.

The better solution is not indignation.

It is proper commercial banking structure.

Good compliance sometimes means making lawful activity look like lawful activity.

Cross-Border Payments Engage Foreign-Exchange Law

The PS&EFT Act should likewise not be treated as a complete cross-border-payment code.

Where foreign currency or international remittance is involved, Pakistan’s foreign-exchange legislation and SBP’s foreign-exchange framework may become central.

The fact that payment instructions are transmitted electronically does not eliminate foreign-exchange regulation.

A transfer can simultaneously be:

an electronic payment;

a foreign-exchange transaction;

an AML-regulated transaction;

and a contractual payment.

One event can have several legal classifications.

Remittance Businesses Need More Than a Payment Gateway

A startup may say:

“We merely connect Pakistanis overseas to recipients at home through an app.”

That description is not enough.

The legal analysis must determine:

who receives the foreign currency;

who converts it;

who has authority to deal in foreign exchange;

who transmits the funds;

who settles the rupees;

what regulatory permission applies;

and whether the arrangement constitutes remittance or another regulated financial activity.

A beautiful app does not regularise an unlawful money flow.

Cryptocurrency Has Changed the Cross-Border Conversation

This brings us to one of the most important 2026 intersections.

For years, Pakistani fintech discussions sometimes attempted to shoehorn cryptocurrency into the PS&EFT Act.

That is no longer intellectually defensible.

Pakistan now has the Virtual Assets Act, 2026 and the dedicated Pakistan Virtual Assets Regulatory Authority (“PVARA”).

Virtual-asset services now fall principally within that dedicated regulatory architecture.

Fiat payment infrastructure remains principally within the SBP ecosystem.

Where the two intersect, both regimes may become relevant.

SBP Replaced Its 2018 Crypto Banking Prohibition in April 2026

On 14 April 2026, SBP issued BPRD Circular Letter No. 10 of 2026.

The Circular expressly replaced the old 2018 prohibition applicable to SBP-regulated entities and created a framework under which regulated institutions may open bank accounts for VASPs licensed by PVARA, subject to specified compliance conditions.

SBP requires a regulated institution, before onboarding a licensed VASP, to obtain the relevant PVARA licence and independently verify its authenticity.

The new framework therefore does not deregulate crypto-banking relationships.

It regularises them.

That distinction is important.

A PVARA Licence Does Not Replace an SBP Licence

Suppose a company operates a virtual-asset exchange and also wishes to provide a rupee wallet.

The company cannot necessarily reason:

“We are regulated by PVARA, therefore our fiat wallet is covered.”

The PVARA licence governs the authorised virtual-asset activity.

If the company separately conducts regulated payment or electronic-money activity, the SBP framework may also become relevant.

Similarly, an EMI cannot begin running a cryptocurrency exchange merely because it possesses an SBP authorisation.

Financial licences are activity-specific.

Stablecoins Can Engage More Than One Regulatory Perimeter

Stablecoins make this interaction particularly interesting.

A token may represent a virtual asset for PVARA purposes.

A business using that token as part of a cross-border payment or remittance structure may also engage:

foreign-exchange law;

payment regulation;

AML/CFT;

banking relationships;

and contractual requirements.

The presence of blockchain technology does not collapse those regimes into one.

The better legal question is not:

“Is this crypto?”

It is:

“What legally regulated activities occur at every stage of the transaction?”

The Regulation Follows the Function

This principle should become the central rule for Pakistani fintech structuring.

Do not begin with the technology.

Begin with the function.

If the business stores fiat monetary value, examine EMI regulation.

If it routes or switches payments, examine PSO/PSP regulation.

If it lends, examine credit regulation.

If it moves foreign currency, examine foreign-exchange law.

If it deals professionally in virtual assets, examine PVARA.

If it performs several functions, examine several regimes.

A complicated business model does not become simpler merely because the user interface presents one button.

Artificial Intelligence in Payments

The PS&EFT Act does not contain an artificial-intelligence chapter.

Nor should lawyers pretend that it does.

AI can nevertheless be used within payment systems for:

fraud detection;

transaction monitoring;

customer support;

credit decisioning;

behavioural analytics;

cybersecurity;

identity verification;

and operational forecasting.

Its use remains subject to the legal obligations governing the underlying activity.

If an AI fraud model causes a bank to freeze an account incorrectly, the question is not whether the algorithm is called “AI”.

The question is whether the institution’s conduct complied with applicable law and regulation.

Automated Decisions Do Not Eliminate Human Accountability

“Computer says no” is not a complete legal reason.

If an institution takes consequential action against a customer, it should be capable of explaining the basis sufficiently for legal and regulatory scrutiny.

Automated decisioning can increase consistency.

It can also reproduce bad assumptions at scale.

A flawed human decision harms one customer.

A flawed automated rule may harm ten thousand.

That is why governance becomes more rather than less important as automation increases.

Biometrics

Biometric authentication can significantly strengthen identity verification.

It also creates risks.

A password can be changed.

A fingerprint cannot.

Compromise of biometric information is therefore potentially more serious than compromise of an ordinary credential.

Again, the PS&EFT Act should not be distorted into a detailed biometric-data statute.

Biometrics used within financial services must be considered through the applicable technology-security, identity, privacy and sectoral requirements.

The technology changes.

The legal principles of security, necessity and accountability remain.

Blockchain

Blockchain is another subject that older articles often inserted into the PS&EFT Act without adequate legal foundation.

The Act neither endorses nor prohibits blockchain merely as a technology.

A permissioned ledger used internally by a regulated institution may simply be infrastructure.

A public-chain cryptocurrency service may fall under the Virtual Assets Act.

A blockchain remittance product may also engage foreign-exchange and payment law.

A tokenised payment claim may raise still other questions.

The word “blockchain” tells us surprisingly little about the regulatory answer.

Smart Contracts

The same applies to smart contracts.

A smart contract is code capable of performing predefined operations when conditions are met.

That does not mean ordinary law disappears.

Questions may still arise concerning:

contract formation;

mistake;

authority;

fraud;

consumer rights;

regulatory permissions;

and liability when code behaves differently from what parties intended.

Automation changes execution.

It does not abolish legal relationships.

Buy-Now-Pay-Later Is Primarily a Credit Question, Not an EFT Question

The earlier version of this article repeatedly attempted to make BNPL a direct PS&EFT subject.

That should be corrected conceptually.

Electronic collection of instalments may involve EFT rules.

But the commercial substance of a BNPL product is credit.

Its regulation therefore depends upon who extends the credit, under what legal authority, at what price and subject to what consumer-finance requirements.

Payment regulation deals with how money moves.

Credit regulation deals with why money is advanced and repaid.

The two may overlap.

They are not identical.

Crowdfunding Is Not Automatically a Payment Business

A platform that merely processes donations through a regulated payment provider differs from a platform that:

holds investor funds;

operates an investment scheme;

issues securities;

offers lending;

or pools money for investment.

The latter activities may engage entirely different laws.

Again, a payment gateway does not provide regulatory camouflage.

The legal character of the underlying commercial arrangement remains relevant.

Subscription Payments

Recurring digital subscriptions do engage payment law where they involve pre-authorised EFTs.

But the PS&EFT Act does not prescribe bespoke legal regimes for:

gyms;

news websites;

health applications;

streaming platforms;

or online gaming subscriptions.

The payment institution must process the payment lawfully.

The merchant’s wider relationship with the consumer remains governed by applicable contract and consumer law.

This distinction allows us to retain useful SEO search terms without inventing legislation.

E-Commerce Refunds and Chargebacks

The PS&EFT Act provides error-resolution and institutional-liability mechanisms.

It should not be described as a comprehensive statutory chargeback code.

Card-scheme chargebacks often arise under payment-scheme rules and contractual arrangements involving issuers, acquirers and merchants.

A customer’s statutory rights can interact with those arrangements.

They should not be confused.

Similarly, a refund arising because a merchant accepted a return is commercially different from reversal of an unauthorised EFT.

The fact that both result in money moving back to the customer does not make them legally identical.

Merchant Disputes Require Their Own Evidence

Merchants should preserve:

proof of transaction;

order information;

delivery evidence;

customer communications;

authorisation data;

refund policy;

and relevant payment records.

Consumer protection does not mean merchants must simply accept every disputed payment as fraudulent.

A fair system protects both sides from abuse.

Payment Acceptance at Physical Businesses Continues to Evolve

SBP’s current 2026 circular record also shows continued intervention in merchant card acceptance, including an August 2026 circular concerning payment-card acceptance at fuel stations.

The broader point is more important than the particular industry.

Pakistan’s payment regulator continues to use its supervisory powers to push practical adoption of digital payment infrastructure in sectors where acceptance friction persists.

That is likely to continue.

The Future of Pakistan’s Payment Economy Is Probably Hybrid

It would be unrealistic to predict that cash will disappear quickly.

Pakistan has geographic, socioeconomic and infrastructure differences that make a fully cashless economy unlikely in the immediate future.

The more realistic trajectory is hybrid.

Cash remains.

Digital payments become increasingly dominant in formal commerce.

Instant payments expand.

Wallets grow.

QR acceptance widens.

Banks and fintechs integrate.

Virtual-asset businesses obtain formal banking access.

The law must therefore regulate coexistence rather than imagine an overnight technological revolution.

What Pakistan’s Payment Law Still Needs

Despite substantial progress, reform remains necessary.

The PS&EFT Act is nearly two decades old.

Much of the modern regulatory framework now sits in numerous circulars, rules, regulations and separate instruments.

That creates flexibility.

It also creates fragmentation.

A sophisticated institution can employ compliance teams to map the framework.

A small fintech founder may struggle simply to identify which documents apply.

Consolidation would improve accessibility.

A Modern Payments Act Could Clarify Regulatory Categories

Future legislation could more expressly define modern categories such as:

payment initiation services;

account-information services;

payment aggregators;

e-money issuers;

merchant acquirers;

payment gateways;

digital wallets;

and other non-bank payment intermediaries.

The current system can regulate many of these through delegated authority.

Clearer statutory terminology would nevertheless improve certainty.

Consumer Liability Could Be Modernised for Social-Engineering Fraud

The most pressing substantive reform may concern fraud.

The 2007 Act was drafted before today’s epidemic of remote social-engineering scams.

The distinction between:

unauthorised account takeover;

credential compromise;

and authorised push-payment fraud

could benefit from legislative clarification.

The law should specify more clearly how losses are allocated where both the institution and customer may have contributed.

The Lahore High Court’s 2025 comparative-negligence reasoning provides an intelligent starting point.

Statutory guidance would improve predictability.

Payment Fraud Should Not Become a Moral Competition

Fraud disputes sometimes degenerate into:

“The customer was stupid.”

Or:

“The bank is greedy.”

Neither is a legal standard.

A better statutory framework would permit proportionate allocation based upon:

customer conduct;

institutional controls;

warnings;

transaction anomalies;

response time;

and causation.

That would recognise reality.

Fraudsters exploit whichever weakness is easiest.

Sometimes that weakness belongs to the institution.

Sometimes the customer.

Sometimes both.

Data Protection Deserves Clearer Treatment

The PS&EFT Act should not be misrepresented as containing a modern comprehensive data-protection code.

It does not.

Yet payment institutions process some of the most sensitive information possessed by private entities.

Account balances.

Transaction histories.

Identity documents.

Telephone numbers.

Biometrics.

Location and device data.

Behavioural patterns.

A mature digital economy requires clear rules governing collection, retention, disclosure and security of such information.

Payment regulation can cover part of that terrain.

A coherent general data-protection framework remains important.

Regulatory Coordination Will Become More Important

Pakistan now has several regulators whose jurisdictions can intersect with fintech.

SBP.

SECP.

PVARA.

Competition authorities.

Tax authorities.

AML institutions.

Cybercrime authorities.

Sector regulators.

A single innovative product may touch several.

Regulatory coordination therefore becomes increasingly important.

The worst outcome for innovation is not strict regulation.

It is contradictory regulation.

A business should be able to determine which regulator leads, where permissions overlap and how conflicting requirements are resolved.

Frequently Asked Questions About Pakistan’s Payment Systems and Electronic Fund Transfer Law

Is the Payment Systems and Electronic Fund Transfers Act, 2007 still in force?

Yes. It remains Pakistan’s principal federal statute governing payment systems and electronic fund transfers and continues to provide the statutory basis for substantial SBP regulation.

Were Pakistan’s Electronic Fund Transfer Regulations issued in 2008?

No. The relevant SBP instrument is the Electronic Fund Transfers Regulations, 2018, issued on 9 May 2018 and effective from 1 October 2018.

What does the PS&EFT Act regulate?

It regulates matters including payment systems, designated payment systems and instruments, clearing and settlement, Electronic Money Institutions, EFT disclosures and documentation, pre-authorised transfers, error resolution, unauthorised EFT liability, institutional liability, civil remedies and certain criminal offences.

Does the Act apply to internet banking?

Internet-banking fund transfers can fall within the statutory concept of Electronic Fund Transfers.

Does the Act apply to mobile banking?

Yes, where the mobile application is used to initiate qualifying electronic transfers.

Does the Act apply to Raast?

Raast operates within the wider statutory authority exercised by SBP under the PS&EFT Act. SBP has separately issued participation and operational requirements for Raast.

Is Raast a private banking application?

No. It is Pakistan’s national instant-payment infrastructure administered within SBP’s payment-system framework.

What is Raast P2M?

Raast Person-to-Merchant enables consumers to make interoperable payments to merchants, including through QR-based payment mechanisms.

Is every Pakistani business legally required under the PS&EFT Act to accept QR payments?

The Government has strongly promoted digital merchant acceptance, but policy initiatives and proposed legislative changes should not be confused with provisions actually enacted in the PS&EFT Act.

What is a Designated Payment System?

It is a payment system formally designated by SBP under section 4 because enhanced statutory oversight is considered necessary.

Is 1LINK a Designated Payment System?

Yes. SBP designated 1LINK in August 2025.

Is NIFT a Designated Payment System?

Yes. SBP formally designated NIFT on 27 August 2026.

What is PRISM+?

PRISM+ is Pakistan’s modern real-time interbank settlement infrastructure used for high-value institutional settlement and related financial-market functions.

What is settlement finality?

Settlement finality means that where the statutory and system rules provide for final and irrevocable settlement, completed settlement cannot casually be unwound merely because a participant later encounters insolvency or another dispute.

Does settlement finality mean a customer cannot challenge an unauthorised payment?

No. Inter-institutional settlement finality and consumer liability are different legal questions. A consumer may still possess statutory remedies against the relevant institution.

What is an Electronic Money Institution?

An EMI is an SBP-authorised non-bank entity permitted to issue electronic monetary value and provide authorised e-money services under the applicable regulatory regime.

Is an EMI a bank?

No. EMI authorisation does not confer general banking powers.

Can an EMI provide wallets?

Yes, subject to its authorisation and applicable EMI Regulations. SBP expressly identifies wallets as a core type of electronic-money product.

Can an EMI provide prepaid cards?

EMIs may provide authorised electronic-money instruments such as prepaid cards, subject to the applicable regulatory conditions.

What is a PSO?

A Payment System Operator operates payment infrastructure or related payment-system functionality within its authorised scope.

What is a PSP?

A Payment Service Provider provides payment-system related services within the scope permitted by SBP.

Can a PSP hold customer deposits?

SBP presently states that PSOs/PSPs may not act as custodians of customer money or perform banking functions merely by reason of their PSO/PSP authorisation.

What is the minimum capital for a PSO/PSP?

SBP presently states a minimum requirement of PKR 200 million, unless another amount is prescribed.

How is PSO/PSP approval granted?

SBP presently uses three stages: in-principle approval, pilot-operation approval and commercial-operation approval.

What is the difference between an EMI and PSP?

An EMI may issue and manage authorised electronic monetary value. A PSP or PSO generally provides payment-system infrastructure or intermediary services. The precise answer depends upon the business model and regulatory approval.

Does a payment gateway automatically require an EMI licence?

Not necessarily. A payment gateway and an e-money wallet perform different functions. The regulatory classification depends upon whether the entity merely routes payments or also holds and issues customer value.

Can a fintech avoid regulation by partnering with a bank?

Not necessarily. Partnerships can allocate regulated functions to appropriately authorised entities, but the fintech’s own activities must still be examined.

Does white-labelling avoid financial regulation?

No. Branding does not change the legal substance of the underlying activity.

Are payment cards regulated under the PS&EFT framework?

Yes. SBP issued dedicated Payment Card Security Regulations in 2016 under sections 3 and 15 of the PS&EFT Act.

When did the Payment Card Security Regulations become effective?

They became effective on 1 January 2017.

Do the card-security rules require international security standards?

The regulations were designed around international best practice and mandated adoption of EMV, amongst other payment-card security requirements.

What is PCI DSS?

PCI DSS is an international payment-card data-security standard relevant to entities processing, storing or transmitting cardholder data. SBP’s card-security framework recognises it.

Does use of a correct PIN automatically prove a transaction was authorised?

Not necessarily. It is important authentication evidence. The statutory question of authorisation and section 41’s evidential burden must still be considered in the circumstances of the case.

Does use of an OTP automatically make a customer liable?

No universal statutory rule says so.

OTP use can be powerful evidence and customer disclosure of an OTP can amount to significant contributory negligence, but liability remains fact-sensitive.

Who bears the burden of proving an allegedly unauthorised EFT?

Section 41 places the burden upon the financial institution or authorised party to establish authorisation in an action involving consumer liability for an unauthorised EFT.

What happens after a consumer reports an EFT error?

The institution must investigate the error in accordance with sections 36–38 and applicable regulations.

How long does the bank have to investigate?

Section 37 generally contemplates completion within ten business days after receipt of the error notice.

What happens if the bank finds an error?

The bank must correct the error promptly and no later than one business day after determining that an error occurred, subject to the statutory framework.

What happens if the bank says there was no error?

Section 38 requires an explanation of the findings and permits the consumer to request the documents relied upon.

Can a customer demand the bank’s investigation documents?

Section 38 provides a statutory basis for requesting copies of documents relied upon in concluding that no error occurred.

Does the Act provide triple damages?

Section 39 permits triple damages in defined circumstances involving defective or bad-faith handling of an error claim. Triple damages are not automatic.

Can a bank escape liability because the system failure was force majeure?

Section 44 provides a defence in specified circumstances, but the institution must satisfy the statutory requirements, including reasonable care and appropriate diligence.

Can banks contract out of consumer rights under the Act?

Section 49 renders a contractual waiver of rights or causes of action conferred by the Act void.

Can a consumer sue under the Act?

Section 50 provides a civil-damages remedy subject to the statute’s conditions and defences.

Does the Act require quick court proceedings?

Section 55 contains unusually strict expedition provisions and directs judgment within ninety days after first service of notice upon the defendant.

Can the Banking Mohtasib hear EFT disputes?

Yes, superior-court jurisprudence recognises the Banking Mohtasib’s jurisdiction over relevant banking maladministration and unauthorised-transfer disputes.

Does approaching the Banking Mohtasib eliminate every civil remedy?

Not necessarily. The remedial regimes can coexist, depending upon jurisdiction, relief and the facts.

Does the Lahore High Court’s 2025 decision mean customers must always bear phishing losses?

No. United Bank Limited v President emphasised contributory and comparative negligence rather than establishing an automatic customer-liability rule.

Does section 41 mean banks always bear phishing losses?

No. Section 41 governs burden of proof. The 2025 Lahore High Court judgment makes clear that liability analysis may still require consideration of customer conduct and comparative negligence.

Can the High Court re-hear all banking evidence in constitutional jurisdiction?

Ordinarily no. The Sindh High Court’s 2026 decision in Bank Alfalah Limited v President of Pakistan emphasises the limited role of constitutional review where specialised forums have already reached factual findings.

Is phishing covered by the PS&EFT Act?

An unauthorised EFT resulting from phishing may engage the Act’s error-resolution and liability provisions, but the precise legal character depends upon whether the customer actually authorised the transaction and upon the wider facts.

Is an account-takeover case the same as a scam-induced payment?

No. A transfer initiated by a criminal without customer authority differs from a payment which the customer deliberately initiates because he has been deceived. The latter is sometimes described internationally as authorised push-payment fraud.

Can FIA investigate electronic banking fraud?

Yes. Electronic-payment fraud may engage criminal offences under the PS&EFT Act, PECA and other applicable laws depending upon the conduct alleged.

Does the PS&EFT Act replace PECA?

No.

Does the Act itself comprehensively regulate cybersecurity?

No. It establishes statutory security principles, while detailed modern technology-risk requirements arise through later SBP frameworks, including the 2025 Technology Risk Management Framework.

Who does the Technology Risk Management Framework apply to?

SBP issued it for PSOs/PSPs and EMIs.

When was compliance required?

By 31 March 2026.

Is cybersecurity compliance risk-based?

Yes. SBP expressly states that implementation should be commensurate with the institution’s size, nature, services and technology complexity.

Can a payment institution outsource cybersecurity?

It may outsource relevant functions subject to applicable requirements, but outsourcing does not necessarily remove the regulated institution’s governance responsibility.

Is cryptocurrency regulated under the PS&EFT Act?

Not principally in 2026. Virtual assets now have a separate statutory regime under the Virtual Assets Act, 2026 and PVARA.

Can banks now deal with PVARA-licensed crypto businesses?

SBP’s Circular Letter No. 10 of 2026 permits defined banking relationships with appropriately authorised VASPs, subject to regulatory conditions.

Did SBP’s April 2026 circular simply “legalise crypto”?

No. It replaced the previous banking restriction with a regulated banking-access framework for authorised VASPs.

Does a PVARA licence permit a company to issue a rupee wallet?

Not automatically. Fiat electronic-money activity may separately engage SBP regulation.

Does an EMI licence permit a company to run a cryptocurrency exchange?

Not automatically. Professional virtual-asset services may separately require PVARA authorisation.

Can USDT be used to avoid remittance regulation?

Using a virtual asset does not necessarily remove foreign-exchange, remittance, AML or PVARA issues from the underlying transaction.

Does the PS&EFT Act directly regulate blockchain?

No. Blockchain is technology. Regulation depends upon the financial activity implemented through it.

Does the PS&EFT Act regulate smart contracts?

It does not contain a bespoke smart-contract regime. Payment obligations implemented through smart-contract technology remain subject to the relevant underlying law.

Does the Act regulate AI?

Not expressly. Use of AI by payment institutions remains subject to the legal and regulatory requirements governing the underlying payment service.

Does the Act regulate biometric authentication?

Not through a comprehensive biometric code. Biometrics can form part of modern authentication architecture governed by applicable security and sectoral regulation.

Is BNPL governed by the PS&EFT Act?

The payment leg of a BNPL arrangement may involve electronic-transfer rules, but BNPL is fundamentally a credit product and may engage additional financial regulation.

Are e-commerce refunds governed entirely by the PS&EFT Act?

No. EFT law can become relevant to payment errors, but merchant refund obligations may also arise from contract, scheme rules and other consumer-law principles.

Are chargebacks created by section 43?

No. Section 43 is an institutional-liability provision. Card-scheme chargebacks arise through separate payment-scheme and contractual mechanisms, although statutory rights may overlap.

Can a bank freeze an account because transactions look suspicious?

Banks may impose or comply with restrictions where lawful AML, compliance, investigative or judicial grounds exist. The legal basis of the restriction should be identified.

Does a freeze mean the customer is guilty of money laundering?

No. Preventive financial regulation operates before criminal guilt is established.

Can personal bank accounts be used for business?

The practical and regulatory appropriateness depends upon the account terms and banking framework. Heavy commercial activity through a personal account can create significant compliance and evidential problems.

Why should businesses keep payment records?

Because source of funds, transaction purpose, tax treatment, fraud allegations and regulatory enquiries may arise long after the payment occurred.

Is a screenshot enough evidence of a transaction?

It may be useful, but authoritative bank records, transaction identifiers, platform records and other contemporaneous evidence are usually more reliable.

Can digital-payment records be used in court?

Electronic payment records can form important evidence subject to the applicable evidential law and proof of authenticity.

Should a fraud victim immediately send a lengthy legal notice?

Immediate notification and preservation of evidence are usually more urgent. The legal theory should follow a careful reconstruction of the facts.

Can contradictory complaints damage a fraud case?

Very substantially. Inconsistency regarding OTP receipt, transaction authority, device access or communication with fraudsters can undermine credibility.

Should a bank preserve logs once a dispute arises?

Yes, relevant transaction and security evidence should be preserved where litigation, investigation or regulatory review is reasonably foreseeable.

What is the most important practical rule for fintech founders?

Map the flow of money before deciding what licence the business requires.

What is the most important rule for consumers?

Report suspicious or unauthorised activity quickly and preserve the complete evidential trail.

What is the most important rule for financial institutions?

Treat compliance, cybersecurity and consumer treatment as part of the product rather than post-event legal administration.

Recommendations for Reform of Pakistan’s Payment Systems Law

The PS&EFT Act has survived technological change surprisingly well because Parliament gave SBP broad delegated regulatory powers.

That strength is also becoming a weakness.

The increasingly elaborate framework now exists across numerous statutory provisions, regulations, circulars, frameworks, operating rules and sector-specific requirements.

A comprehensive future reform should therefore focus less upon reinventing everything and more upon consolidation, clarification and modernisation.

Pakistan Should Consider a Modern Consolidated Payments Statute

A replacement statute could preserve the functional strengths of the PS&EFT Act while incorporating terminology appropriate to modern digital finance.

The legislation could expressly identify the main categories of regulated payment service.

It could clarify when particular activities require authorisation.

It could codify payment-institution safeguarding principles.

It could modernise consumer fraud liability.

It could recognise open banking and payment-initiation services.

It could explicitly deal with operational resilience and critical outsourcing.

And it could clarify coordination with PVARA and other regulators.

The goal should not be greater regulation merely for the sake of greater regulation.

It should be better organised regulation.

Consumer Fraud Needs the Most Urgent Legislative Attention

The 2007 distinction between authorised and unauthorised EFTs remains useful.

Modern social engineering has exposed its limits.

The law now needs a clearer treatment of scenarios where the customer technically initiates the transfer but does so because a sophisticated fraudster has induced the payment.

The appropriate answer should not necessarily be automatic institutional reimbursement.

Nor should it be automatic customer loss.

A proportionate statutory regime could allocate responsibility by examining both parties’ compliance with clearly defined obligations.

Regulation Should Reward Good Behaviour on Both Sides

A customer who ignores explicit security warnings and voluntarily transfers money to a stranger should not necessarily enjoy the same position as a customer whose account was remotely compromised despite reasonable precautions.

Similarly, an institution operating effective fraud controls should not necessarily occupy the same position as one that ignored mandatory security requirements.

The law should create incentives for good conduct.

That is one of the principal functions of liability rules.

Payment-System Reform Must Protect Innovation

Pakistan has substantial potential for fintech growth.

A large young population.

Extensive mobile use.

Significant remittance flows.

A growing freelance economy.

Underbanked communities.

Rapid merchant digitisation.

Raast infrastructure.

An emerging regulated virtual-asset sector.

These conditions create opportunities.

But firms will invest only where regulation is sufficiently predictable.

A system in which businesses discover their legal obligations through enforcement after launch deters serious investment and rewards recklessness.

Clarity is itself an economic asset.

Regulatory Sandboxes Can Help If Used Properly

A sandbox can permit innovative products to be tested within controlled limits while regulators observe actual risks.

But a sandbox should not become a place where obvious regulatory obligations are temporarily ignored.

The most useful candidates are products that genuinely do not fit comfortably within existing categories.

A conventional payment gateway does not become innovative simply because it uses an attractive font.

Sandbox policy should distinguish technological novelty from regulatory avoidance.

Consumer Education Must Become More Intelligent

Financial institutions frequently satisfy consumer-education obligations through generic warnings:

“Never share your OTP.”

Useful.

But insufficient.

Modern scams increasingly impersonate institutions convincingly.

Consumers need examples of how fraud actually works.

Why a caller may know their name.

Why caller ID can be spoofed.

Why urgency is suspicious.

Why remote-access applications are dangerous.

Why QR codes should be verified.

Why legitimate bank staff should not request passwords.

Education works best when it explains the attack rather than merely commands vigilance.

Institutions Should Make Security Warnings Contextual

A warning appearing every time the app opens becomes invisible.

A warning displayed exactly when a customer:

adds a new beneficiary;

increases a transfer limit;

registers a new device;

or transfers a large amount

is more meaningful.

Human attention is finite.

Good security design uses it carefully.

Regulators Should Encourage Inter-Institutional Fraud Cooperation

Fraud proceeds move quickly.

The sending bank may detect the complaint.

The receiving bank controls the destination account.

A third institution may receive onward transfers.

If information flows slowly between institutions, the fraudster benefits.

Faster lawful information-sharing and coordinated freezing or tracing mechanisms can materially improve recovery prospects while still requiring safeguards against arbitrary restrictions.

Payment-system interoperability should include fraud-response interoperability.

Pakistan Should Continue to Expand Merchant Acceptance

The value of instant-payment infrastructure increases as more people can use it in ordinary commerce.

Merchant QR adoption therefore has value beyond convenience.

It can reduce cash-handling risk.

Create better transaction records.

Improve tax documentation.

Facilitate remote commerce.

And lower payment-acceptance barriers for small businesses.

The challenge will be to keep merchant charges low enough that businesses do not return to cash.

Competition Matters

A payment ecosystem dominated by one or two intermediaries can create concentration risk.

Competition can improve prices and innovation.

But excessive fragmentation can undermine interoperability.

The regulatory objective should therefore be open and fair access to common infrastructure subject to sensible technical and prudential standards.

Competition at the service layer.

Interoperability at the infrastructure layer.

That combination is generally healthier than isolated proprietary silos.

Financial Inclusion Must Be Measured by Useful Access

Opening an account is not the same thing as financial inclusion.

The account must be usable.

Merchants must accept digital payment.

Customers must trust the system.

Complaints must be resolvable.

Transactions must be affordable.

Interfaces must be intelligible.

Services must work outside major cities.

Fraud must not make customers afraid to use the product.

Financial inclusion is therefore a legal, technological and behavioural problem simultaneously.

The Broader Legal Significance of the PS&EFT Act

The Payment Systems and Electronic Fund Transfers Act, 2007 ultimately tells a larger story about law and technology.

Good legislation does not necessarily predict every future technology.

It creates principles capable of surviving technological change.

The PS&EFT Act could not predict:

smartphones;

instant QR payments;

AI fraud models;

large-scale e-wallet ecosystems;

modern cloud computing;

stablecoins;

or contemporary fintech platforms.

Yet its central concepts authorisation, payment systems, electronic transfers, institutional responsibility, settlement finality, disclosure and consumer remedies remain relevant.

The weakness appears where the principles are stretched into detailed rules they were never intended to contain.

That is why the secondary regulatory architecture matters so much.

Pakistan’s Payment Law in September 2026

The legal position can now be stated with far greater precision than older articles suggested.

The PS&EFT Act 2007 remains the statutory foundation.

The Electronic Fund Transfers Regulations are from 2018, not 2008.

Payment-card security is governed through dedicated regulations issued in 2016 and effective from 2017.

PSO/PSP operations are governed through their own SBP authorisation regime.

EMIs operate under the revised 2023 regulations.

Raast now forms core national instant-payment infrastructure.

1LINK and NIFT have been formally designated as Designated Payment Systems.

PRISM+ now provides modern institutional real-time settlement infrastructure.

The Technology Risk Management Framework applies to payment institutions, with its compliance deadline having passed on 31 March 2026.

SBP’s modern consumer-conduct framework adds another layer of fair-treatment obligations.

And virtual assets now occupy their own separate legal regime, while interacting with ordinary banking and payment infrastructure where fiat services are involved.

This is no longer a simple statute.

It is a legal ecosystem.

Practitioner and Industry FAQ: Payment Systems, Fintech, Digital Banking and Electronic Transfers in Pakistan

The following questions address practical issues that arise when businesses, financial institutions, fintech founders, merchants and consumers attempt to apply Pakistan’s payment laws to real transactions.

They are deliberately more detailed than an ordinary consumer FAQ.

The objective is to distinguish the legal character of the underlying activity before deciding which statute, licence, regulator or remedy applies.

Merchant Acquiring and Payment Acceptance

What is merchant acquiring?

Merchant acquiring is the function through which a financial institution or appropriately authorised payment participant enables a merchant to accept electronic payments.

Depending upon the architecture, the acquiring side may involve merchant onboarding, provision of POS or QR acceptance facilities, routing of payment instructions, settlement and reconciliation.

The merchant’s acquiring institution should not be confused with the customer’s issuing institution.

They sit on different sides of the transaction.

What is the difference between an issuing institution and an acquiring institution?

The issuer is generally the institution that provides the customer’s payment account, card, wallet or other payment instrument.

The acquirer serves the merchant side of the payment relationship and facilitates acceptance and settlement of customer payments.

One transaction can therefore involve both.

This distinction becomes important when determining which institution caused an error, which institution holds particular records and how liability is allocated between participants.

Can a non-bank company become a merchant acquirer?

Potentially, but the precise regulatory structure depends upon the activities actually undertaken and the relevant SBP authorisation.

A technology company cannot assume that describing itself as a “merchant acquirer” creates regulatory permission.

If it operates payment infrastructure, routes transactions, holds funds or provides another regulated function, the corresponding SBP regime must be examined.

What is a payment aggregator?

A payment aggregator typically facilitates payment acceptance for multiple merchants through a common technological or contractual arrangement.

But “aggregator” is a commercial description rather than a universal Pakistani statutory licence.

The real regulatory questions include whether the entity handles customer funds, operates payment infrastructure, provides merchant acquiring functionality, contracts with the merchant and settles transactions.

Can a payment aggregator hold merchant money overnight?

That should never be assumed merely because the business calls itself an aggregator.

PSO/PSP authorisation does not itself permit custody of customer money or banking functions. SBP presently states expressly that PSOs/PSPs may not act as custodians of consumers’ money merely by virtue of their authorisation.

If an aggregator’s proposed structure involves possession or control of funds, the precise custody and settlement model should be legally reviewed.

Is a payment gateway the same thing as a PSO/PSP?

Not necessarily.

A payment gateway describes a technological function.

Depending upon what the gateway actually does, it may fall within PSO/PSP regulation or operate within another regulated entity’s infrastructure.

SBP’s PSO/PSP framework expressly contemplates electronic payment gateways amongst relevant payment-system activities, but the legal classification still turns upon the actual business model.

Can a software company simply plug into banks and become a payment gateway?

Not merely by technical integration.

Bank connectivity does not itself confer regulatory permission.

The software company’s role, contractual position, access to funds, processing functions and regulatory status must be considered.

A bank partnership is evidence of a commercial relationship.

It is not a substitute for whatever authorisation the fintech itself requires.

Can an e-commerce marketplace collect payments for hundreds of sellers?

It can potentially structure such an arrangement, but the payment flow becomes legally significant.

If the marketplace collects money into its own account and later distributes it to vendors, questions arise concerning custody, merchant acquiring, settlement, tax, AML and contractual responsibility.

A marketplace should therefore distinguish its commercial commission from money belonging economically to third-party sellers.

Are split payments regulated?

There is no single PS&EFT provision entitled “Split Payment Regulation”.

However, a platform allocating a customer’s payment amongst several beneficiaries raises payment-processing, settlement, record-keeping and contractual issues.

The important questions are who receives the customer’s funds initially, whether the platform ever controls them and which authorised institution performs the settlement.

Can a marketplace call customer funds “platform balances” to avoid payment regulation?

Terminology will not determine the answer.

If, in substance, the customer has paid money which the business holds and later transfers or redeems, regulators can examine that economic reality.

Calling money “credits”, “points”, “balances” or “tokens” does not necessarily alter its legal character.

Raast, QR Payments and Instant Settlement

Is Raast now part of Pakistan’s mainstream payment infrastructure?

Yes.

SBP describes Raast as Pakistan’s instant-payment system supporting bulk payments, P2P and P2M payments, and its 2025 Participation Criteria were expressly issued under the PS&EFT Act.

Who can participate in Raast?

The 2025 Participation Criteria contemplate participation by banks, microfinance banks, qualifying non-bank financial institutions, government bodies, corporates, SMEs, business platforms, payment aggregators, educational institutions, fintechs and other service providers, subject to the applicable participation category and regulatory requirements.

Does eligibility for Raast participation mean a fintech is licensed to operate a payment business?

No.

Raast participation and regulatory licensing are distinct concepts.

An entity may qualify technically or institutionally for a form of Raast participation while still needing separate authority for the underlying financial service it provides.

What are the different forms of Raast participation?

SBP’s 2025 criteria identify four categories: Direct Settlement Participants, Direct Non-Settlement Participants, Payment Initiation Service Providers and Indirect Participants.

The appropriate category depends upon the entity and the role it performs.

Is Raast P2M limited to QR codes?

No.

When SBP launched Raast P2M, it expressly identified payment acceptance through QR Codes, Raast Alias, IBAN and Request to Pay.

The QR code is therefore one interface within a broader merchant-payment architecture.

Were banks and payment institutions required to enable merchants for Raast P2M?

SBP’s November 2024 instructions required regulated entities to ensure that existing account holders providing in-store or online shopping services were enabled with Raast P2M digital payment acceptance by 31 March 2025, while new-to-bank merchants were to be enabled as part of onboarding. Regulated entities could provide the service directly or through partnership with an SBP-regulated EMI, PSO or PSP.

Does a merchant need its own direct Raast integration?

Not necessarily.

SBP expressly contemplated merchant services being provided directly by a regulated entity or through an appropriately regulated EMI/PSO/PSP relationship.

What happened to the Raast QR subsidy?

The Federal Government allocated PKR 3.5 billion to subsidise qualifying Raast P2M QR transactions from 1 September 2025 until 30 June 2026. That stated subsidy period has now ended.

The underlying P2M infrastructure continues; the temporary subsidy and the payment system itself should not be confused.

Can a merchant charge customers extra for paying electronically?

That question cannot safely be answered from the PS&EFT Act alone.

Applicable acquiring agreements, card-scheme rules, SBP instructions and specific product arrangements may restrict or regulate merchant charging practices.

The legal position should therefore be checked against the payment method actually being used.

Can a merchant refuse a Raast payment after displaying a QR code?

The existence of a QR code does not independently resolve every contractual issue between merchant and customer.

However, regulated institutions are operating within SBP’s merchant-digitisation framework, and merchants provided digital acceptance facilities should use them consistently with their agreements.

What if a fraudster replaces a merchant’s QR code?

The payment may be redirected to an unintended beneficiary.

Liability will depend upon the facts, including the customer’s confirmation screen, merchant controls, payment records and whether the fraudulent substitution could reasonably have been detected.

A merchant displaying physical QR material should therefore treat it as payment infrastructure rather than stationery.

What evidence should be preserved in a QR-payment dispute?

The transaction reference, merchant identifier, beneficiary name or account, timestamp, amount, screenshot or receipt, QR source and subsequent communications can all become relevant.

Where fraud is suspected, the original QR image or physical display should also be preserved if possible.

Electronic Money Institutions and Digital Wallets

What exactly does an EMI licence permit?

The answer depends upon the licence and the EMI Regulations.

SBP currently describes EMIs as non-bank entities authorised to issue e-money and provide digital payment instruments including wallets, P2P payments, merchant payments, bill payments, QR payments and prepaid cards within the permitted scope.

Is an EMI licence granted immediately?

No.

Historically and under the regulatory framework, EMI authorisation involves staged approval rather than a single instantaneous licence.

The relevant approval stage should therefore always be verified rather than assuming that an entity describing itself as an “approved EMI” has completed every stage.

Are EMI Regulations still based on the 2019 rules?

The original EMI Regulations were issued in 2019, but SBP revised them in June 2023. The 2023 Regulations are therefore essential to current analysis.

Can an EMI lend customer wallet balances?

An EMI should not assume that customer e-money can simply be converted into lending capital.

E-money regulation is built around issuance and safeguarding of payment value, not unrestricted deposit-taking and lending like a commercial bank.

If an EMI wants to enter credit activity, the proposed structure requires separate legal and regulatory analysis.

Can an EMI pay interest on a wallet balance?

That should not be assumed.

An e-money wallet is not automatically a deposit account.

Any remuneration, investment or return feature can alter the economic character of the product and should be assessed against the EMI Regulations and any other applicable financial-law regime before launch.

Can an EMI offer physical and virtual prepaid cards?

SBP currently recognises prepaid cards physical and virtual within the EMI payment ecosystem, subject to the EMI’s permissible scope and relevant card requirements.

Can a teenager open an electronic wallet in Pakistan?

SBP introduced a Teenager Account / Wallet framework in 2026 for resident Pakistani teenagers aged 13 to 18, applicable to banks, microfinance banks and EMIs. The framework permits local-currency accounts/wallets subject to its conditions.

This is a good example of the payment ecosystem continuing to evolve well beyond the language of the 2007 statute.

Can a teenage wallet receive foreign remittances?

SBP’s 2026 framework states that the account/wallet may receive the PKR equivalent of foreign remittances, subject to the framework and other applicable rules.

Is money in an EMI wallet identical in law to money deposited in a bank account?

No.

The user experience may look similar, but the institutions, regulatory permissions and legal structure differ.

An EMI is a non-bank e-money issuer.

A bank deposit sits within banking law.

That distinction matters particularly for permissible activities, safeguarding and insolvency analysis.

PSO/PSP Authorisation and Infrastructure

What is the present minimum capital requirement for a PSO/PSP?

SBP currently states that PSOs/PSPs must maintain at least PKR 200 million, or such other amount as SBP may prescribe.

Does PKR 200 million guarantee a licence?

No.

Capital is only one component of regulatory fitness.

Business model, ownership, governance, technology, controls, management and other statutory and regulatory requirements also matter.

What are the three PSO/PSP approval stages?

SBP presently identifies:

In-Principle Approval → Pilot Operation Approval → Commercial Operations Approval.

An applicant should describe its status using the actual stage achieved.

Can a company commercially launch after in-principle approval?

It should not assume so.

The existence of separate pilot and commercial-operation stages demonstrates that in-principle approval is not the same thing as final authority for unrestricted commercial operations.

Can a PSO/PSP provide banking services?

Not merely because it is a PSO/PSP.

SBP expressly states that PSOs/PSPs will not act as custodians of consumers’ money or perform banking functions as defined under the Banking Companies Ordinance merely under that authorisation.

Can a PSP issue a stored-value wallet?

That activity may move the business into EMI territory.

The answer turns upon whether the entity is merely facilitating payment processing or is issuing and storing monetary value for the customer.

Can a PSP operate an ATM switch?

ATM switching is amongst the kinds of payment-system infrastructure contemplated within Pakistan’s PSO/PSP framework, subject to authorisation.

Can a white-label ATM operator operate without SBP regulation?

No assumption should be made merely because it does not operate as a traditional bank.

SBP has issued dedicated guidelines for White Label ATM Operators within the payment-system framework. Its 2018 payment circular record confirms the existence of those guidelines.

API Banking, Outsourcing and Technology Vendors

Does exposing a banking API create a new financial licence?

Not automatically.

An API is a technological interface.

Regulation depends upon what functionality is exposed and which entity performs the underlying financial service.

A company using a bank’s API to display data may occupy a different legal position from a company initiating payments or holding customer funds.

Is “open banking” expressly regulated as a standalone activity under the 2007 Act?

Not in the way some more recent international payment statutes expressly define account-information and payment-initiation providers.

However, Pakistan’s developing payment infrastructure and Raast Participation Criteria already contemplate Payment Initiation Service participants.

Future statutory reform may sensibly clarify this area further.

Can a fintech outsource customer verification?

Operational functions can be outsourced subject to applicable regulatory requirements, but the regulated institution should not assume that responsibility for compliant onboarding disappears.

Outsourcing changes who performs the task.

It does not necessarily change who answers to the regulator.

Can an EMI host all its infrastructure on a foreign cloud provider?

This requires examination of the applicable technology-risk, outsourcing, data and regulatory requirements.

The fact that cloud infrastructure is commercially standard does not remove obligations concerning access, security, resilience, regulatory oversight and recovery.

Who is responsible if an outsourced cloud provider goes down?

Contractual responsibility between the regulated institution and cloud provider is one question.

Regulatory responsibility to customers and SBP is another.

An institution relying upon a critical third party should therefore plan for vendor failure rather than assuming that contractual indemnity keeps payment services operating.

Does the Technology Risk Management Framework apply to banks?

The October 2025 Technology Risk Management Framework for Payment Institutions specifically addresses EMIs, PSOs and PSPs. Banks are subject to their own broader SBP technology and cybersecurity requirements.

The payment-institution Framework should therefore not be casually applied to every financial institution simply because it concerns technology.

When did payment institutions have to comply with the Technology Risk Management Framework?

By 31 March 2026. SBP expressly states that non-compliance can attract penal action under the relevant law and regulations.

Is the technology framework prescriptive or risk-based?

SBP expressly states that it is not one-size-fits-all and should be implemented according to the size, nature, services and technology complexity of the payment institution.

Does a small fintech therefore have no cybersecurity obligations?

No.

Proportionality means controls are adapted to risk.

It does not mean a small institution can dispense with security.

Indeed, a small fintech handling customer payments can inflict significant harm even with comparatively modest transactional volume.

Downtime, Failed Transfers and Operational Problems

What happens when a mobile banking service goes down?

The legal consequences depend upon the cause, duration, transaction status, applicable SBP requirements and losses.

SBP has also issued dedicated Guidelines for Downtime of Digital Channels/Services, demonstrating that service interruption is treated as a regulatory matter rather than merely a customer-service inconvenience.

Is every failed transfer a breach of section 43?

No.

Section 43 must be applied to its statutory conditions and exceptions.

A failed transaction caused by insufficient funds, legal restraint or another recognised exception differs from one caused by institutional processing failure.

What if the sender is debited but the beneficiary is not credited?

The transaction should be traced through the institutions and relevant payment infrastructure.

The consumer should preserve the transaction reference and obtain the originating institution’s written position.

The issue may involve a processing error, delayed settlement, reconciliation problem or other failure.

What if the customer is debited twice?

A duplicate debit can constitute an EFT error requiring investigation.

The consumer should identify both transaction references rather than simply asserting that the account balance is wrong.

Does a bank have to reverse a mistaken transfer to the wrong beneficiary?

Not automatically.

Where the customer correctly authenticated and instructed payment to the wrong account, the transaction may not be “unauthorised”.

Recovery can involve the receiving institution, beneficiary rights and restitutionary principles.

Instant settlement makes speed of notification particularly important.

Can the bank simply take money back from the recipient?

That should not be assumed.

Once funds have settled, the recipient has legal interests too.

Any reversal must rest upon a lawful contractual, payment-system or legal basis.

What is the difference between reversal and refund?

A reversal commonly refers to undoing or correcting a payment entry within the payment process.

A refund may involve a fresh payment by a merchant or other party returning money after the original transaction was validly completed.

The economic result can look similar.

The legal basis can be different.

Card Payments, Chargebacks and Merchants

Is a chargeback a statutory right under section 43?

No.

Section 43 creates specified institutional liability.

Card chargeback mechanisms generally arise from payment-network rules and contracts amongst issuers, acquirers, merchants and card schemes.

Statutory rights may overlap with those mechanisms, but they should not be conflated.

Can a merchant contest a chargeback?

Depending upon the relevant card-scheme and acquiring rules, a merchant can often produce evidence supporting the transaction.

That evidence may include authentication, order records, proof of delivery and customer communications.

Does proof of delivery defeat every chargeback?

No.

Proof of delivery may answer a “goods not received” allegation.

It does not necessarily answer an allegation that the card itself was used without authority.

The reason for the dispute determines the relevant evidence.

What is card-not-present fraud?

It involves a transaction conducted without the physical card being presented to the merchant, commonly in e-commerce or remote transactions.

This creates different authentication and fraud risks from traditional card-present transactions.

Does possession of the physical card prove that an online transaction was fraudulent?

No.

Card information can be compromised while the card remains physically with the customer.

The evidence must therefore address the payment credentials and authentication process, not simply physical possession.

Can a merchant store card numbers?

Any storage or processing of cardholder information must comply with applicable payment-card security requirements, contractual network standards and other relevant law.

SBP’s card-security framework recognises international payment-card security standards, including PCI-DSS concepts.

Payroll, Bulk Payments and Corporate Transfers

Does the PS&EFT Act regulate electronic salary payments?

Where salary is paid through an EFT, the payment leg can fall within electronic-fund-transfer law.

The employer’s substantive obligation to pay wages, however, arises from employment and contract law rather than the PS&EFT Act.

Who is responsible if a payroll batch fails?

That depends upon the cause.

The employer may have submitted incorrect data.

The bank may have failed to process valid instructions.

The payment system may have experienced an operational problem.

The payroll provider may have transmitted an incorrect file.

Each link should be investigated before liability is assigned.

Are corporate bulk payments part of Raast?

Raast expressly supports Bulk Payments as one of its use cases.

Can a corporation use Raast directly?

Potentially, depending upon the participation structure.

The 2025 Participation Criteria expressly contemplate corporates and private-sector entities among those eligible to apply for participation, subject to the applicable category and requirements.

Is a corporate treasury transfer treated exactly like a consumer EFT?

Not necessarily.

Several consumer-protection provisions of the PS&EFT Act are specifically framed around consumer accounts.

A commercial or institutional payment may therefore engage different contractual and statutory considerations.

Should corporate payment authority be documented separately from bank authentication?

Yes.

A company’s internal authority to approve payment and the bank’s technical authentication of the payment are different matters.

A payment may be technically authenticated by an employee who lacked corporate authority to make it.

That can create disputes involving agency, employment, corporate governance and banking law simultaneously.

What about joint-signature corporate accounts?

The bank should process transactions according to the mandate recorded for the account and applicable electronic-banking arrangements.

If electronic channels permit an instruction inconsistent with the documented mandate, the evidential and contractual questions can be significant.

Joint Accounts and Shared Access

Can one joint account holder make an electronic transfer without the other?

That depends upon the account mandate.

A joint account may be operated singly, jointly or according to another agreed signing structure.

The bank’s electronic-payment system should reflect the legally operative mandate.

What if one joint account holder says the other stole the money?

The fact that money was transferred by another account holder does not automatically make the transfer unauthorised vis-à-vis the bank.

The authority contained in the account mandate and any internal dispute between the holders must be distinguished.

Can a bank be liable if its digital system ignores a joint-signature requirement?

Potentially, depending upon the facts and contractual mandate.

If the institution’s system permits a transaction that the account’s governing authority expressly prohibited, the institution’s compliance with instructions becomes central.

Remittances and Cross-Border Payments

Does the PS&EFT Act itself authorise international remittance businesses?

No.

A business cannot rely upon the PS&EFT Act as a standalone remittance licence.

Cross-border remittances can also engage Pakistan’s foreign-exchange regime and specific SBP permissions.

Can an EMI receive international remittances?

The precise scope depends upon current EMI rules, permitted products and the remittance architecture.

One should distinguish receiving a lawful rupee payout of a foreign remittance from independently operating an unauthorised cross-border remittance business.

Can a Pakistani fintech collect dollars abroad and pay rupees locally?

Not simply because the collection and payout are electronically connected.

Who receives foreign currency, who converts it and under whose foreign-exchange authority are fundamental regulatory questions.

Does using an overseas payment processor solve the Pakistan regulatory issue?

No.

Outsourcing part of the transaction overseas does not necessarily remove Pakistani regulation from services offered in Pakistan or the domestic settlement leg.

Are SWIFT transfers governed by the same rules as Raast transfers?

They use different infrastructure and may involve different regulatory layers.

A cross-border SWIFT payment may engage foreign-exchange and correspondent-banking rules in addition to electronic-payment law, whereas Raast is primarily domestic instant-payment infrastructure.

Non-Profits, Donations and Charitable Payments

Can a Section 42 company receive donations electronically?

Yes, subject to its constitutional objects, banking arrangements, tax position and applicable financial regulation.

The mere fact that a donation is electronic does not alter the organisation’s corporate and regulatory obligations.

Are electronic charitable donations automatically treated as suspicious?

No.

Legitimate charitable activity is lawful.

However, banks may apply enhanced AML/CFT scrutiny depending upon the organisation, geography, transactional pattern and applicable risk factors.

Should an NGO use personal bank accounts for donations?

That is generally an unattractive governance structure.

Organisational funds should ordinarily be traceable through the organisation’s properly maintained accounts and banking arrangements.

Mixing personal and charitable money can create serious audit, governance, tax and AML problems.

Can a crowdfunding platform collect charitable donations?

Potentially, but the platform’s own role should be analysed.

A site merely directing payments into a charity’s regulated account is different from a platform holding funds itself before distributing them.

Custody changes the regulatory question.

Digital Lending and BNPL

Can a PSO/PSP operate a lending app merely because it can process repayments?

No.

Payment processing and lending are different regulated activities.

The ability to collect repayment electronically does not confer authority to extend credit.

Has SBP addressed payment services to unauthorised digital lending apps?

Yes.

SBP issued specific instructions concerning Digital Payment Services to Unauthorized Digital Lending Apps in June 2023.

This is a good illustration of payment regulation being used to prevent regulated payment infrastructure from supporting unauthorised financial activity.

Is BNPL simply an EMI product?

No.

BNPL involves credit.

An EMI may potentially participate in the payment leg of a properly structured product, but the underlying extension of credit must have its own lawful regulatory basis.

Can a fintech call credit “deferred payment” to avoid lending regulation?

Changing the label will not necessarily change the economic substance.

If one party finances another party’s purchase and expects repayment later, the legal character of that arrangement must be examined regardless of branding.

Crypto, PVARA and Fiat Payment Rails

Does the PS&EFT Act now licence crypto exchanges?

No.

Pakistan now has a separate virtual-assets framework under the Virtual Assets Act, 2026 and PVARA.

The PS&EFT regime becomes relevant principally where the virtual-asset business interacts with ordinary fiat payment infrastructure.

Can a PVARA-regulated exchange obtain a Pakistani bank account?

SBP replaced its 2018 prohibition in 2026 and now permits regulated entities to open bank accounts for VASPs duly licensed by PVARA, subject to strict conditions and independent licence verification.

What about a PVARA NOC holder that does not yet have the full licence?

SBP’s 2026 framework also addresses limited-purpose banking arrangements for PVARA NOC holders during the licensing process.

The exact scope should be checked against the current circular rather than treating an NOC as equivalent to a VASP licence.

Can a crypto exchange use an EMI wallet to collect rupees?

Potentially only through a properly structured and authorised relationship.

The VASP’s PVARA permissions do not enlarge the EMI’s SBP permissions, and the EMI’s licence does not enlarge the VASP’s PVARA permissions.

Both sides of the relationship require regulatory compliance.

Can a stablecoin business describe itself as a payment company instead of a VASP?

Labels do not determine regulatory classification.

Where the business professionally provides regulated virtual-asset services, PVARA can be relevant even if the commercial use case is payments.

Fiat payment components can additionally engage SBP regulation.

Can Binance P2P payments cause a Pakistani bank account to be questioned?

Yes.

A bank may see frequent incoming transfers from unrelated persons without seeing the virtual-asset leg of the P2P transaction.

That pattern can generate AML or source-of-funds questions even though the underlying crypto transaction is not automatically unlawful.

Does a bank freeze prove that the P2P trader committed an offence?

No.

A freeze or restriction may be preventive or investigative.

Criminal liability requires proof of the relevant offence and mental element.

A transaction trail can implicate an innocent intermediary before the commercial explanation is reconstructed.

Payment Evidence, Investigations and Litigation

What is the single most important record in an electronic-payment dispute?

There is rarely only one.

The strongest case usually combines the bank’s authoritative transaction record with the surrounding chronology authentication, device activity, messages, beneficiary creation, alerts and customer complaint history.

Are screenshots useful?

Yes, but they should not be the only evidence where authoritative records are available.

Screenshots can be edited, incomplete or devoid of metadata.

They are best preserved alongside source records.

Should customers preserve the original mobile phone after serious fraud?

Where device compromise is genuinely alleged and the amount is substantial, preserving the device can be sensible.

Factory-resetting, replacing or deleting applications may destroy potentially relevant evidence.

Should banks preserve call recordings?

Where the call is relevant to an active or reasonably anticipated dispute and recordings exist, preservation is prudent.

A fraud complaint can turn upon what the customer told the bank and when.

Does section 38 allow a consumer to ask what evidence the bank relied upon?

Yes.

Where the institution concludes that no error occurred, section 38 provides an important mechanism for the consumer to request documents relied upon in reaching that conclusion.

Can a bank simply answer “OTP authenticated” and refuse everything else?

Whether that satisfies the statutory and regulatory requirements depends upon the case.

Authentication may be strong evidence, but the institution’s obligation to investigate an alleged EFT error should not be reduced automatically to a single system flag where the surrounding allegations raise additional issues.

What if the customer lied in the complaint?

That can seriously damage the claim and potentially create separate legal consequences.

The statutory consumer-protection regime is not intended to insure dishonest denial of genuine transactions.

Does section 41 place the burden of proof on the bank?

In an action involving consumer liability for an unauthorised EFT, yes: the Act places the burden concerning authorisation upon the financial institution or authorised party.

However, Pakistani jurisprudence also indicates that contributory or comparative negligence can become relevant in scam cases.

Does section 41 mean the bank must prove who physically typed the OTP?

Not necessarily in that literal formulation.

The institution must satisfy the legal burden concerning authorisation using the evidence available.

What evidence is sufficient depends upon the transaction, system and facts.

Can the Banking Mohtasib order compensation in EFT disputes?

Within its statutory jurisdiction, the Banking Mohtasib can adjudicate relevant complaints concerning banking maladministration and unauthorised transfers.

Superior-court jurisprudence has repeatedly recognised that the PS&EFT Act does not simply abolish the Mohtasib’s role.

Is the Banking Mohtasib the only forum?

No.

The precise forum depends upon the institution, dispute and relief sought.

The PS&EFT Act itself creates civil remedies, while Banking Mohtasib jurisdiction and potentially other proceedings may also arise.

Can a complainant pursue every forum simultaneously?

Multiple remedies do not necessarily mean unrestricted parallel litigation.

Issues of jurisdiction, maintainability, election, finality and procedural fairness may arise.

Strategic forum selection should therefore occur before proceedings are multiplied.

Can the High Court simply rehear a Banking Mohtasib dispute?

Constitutional jurisdiction is not ordinarily another factual appeal.

The Sindh High Court’s 2026 Bank Alfalah decision illustrates the difficulty of trying to re-litigate concurrent factual findings through constitutional proceedings.

When should a lawyer become involved in an EFT fraud case?

Ideally before the client’s factual narrative becomes fragmented across multiple complaints.

Once a substantial loss has occurred, early legal review can help preserve evidence, identify the correct transaction theory and avoid unnecessary admissions.

Systemic Infrastructure and Insolvency

Why were 1LINK and NIFT designated as payment systems?

Designation reflects SBP’s statutory oversight of payment systems considered important to the integrity of Pakistan’s payment environment.

1LINK was designated with effect from 20 August 2025, while NIFT was designated with effect from 27 August 2026.

Does designation mean SBP owns the company?

No.

Designation is regulatory status.

It should not be confused with ownership.

Why does payment-system insolvency need special rules?

Because unwinding settled payments after a participant becomes insolvent can transmit financial instability through the system.

Settlement-finality protections therefore seek to ensure that qualifying completed settlement remains reliable.

Can an insolvency administrator simply reverse every payment made before insolvency?

Not where statutory settlement-finality protections apply.

The point of those provisions is precisely to protect qualifying settlement and netting arrangements against destabilising unwinding.

What is PRISM+?

PRISM+ is Pakistan’s current Real-Time Interbank Settlement Mechanism Plus, launched in June 2025 and governed by revised operating rules issued on 16 April 2026.

It integrates enhanced funds-settlement functionality with a Central Securities Depository module.

Did the 2026 PRISM+ Rules replace the old 2018 PRISM Rules?

Yes.

SBP’s April 2026 circular states expressly that the new PRISM+ Operating Rules supersede the earlier 2018 PRISM Operating Rules and apply to existing and future PRISM+ participants.

Regulatory Due Diligence for Fintech Investors and Founders

What should an investor ask before investing in a Pakistani fintech?

The first question should not be:

“Is the app good?”

It should be:

“What regulated activities does this company actually perform, and what permission does it possess for each?”

A beautiful product with the wrong regulatory architecture can be a very expensive prototype.

Should investors verify regulatory approvals directly?

Yes.

Where approval or licensing is material to the investment thesis, documentary verification should form part of due diligence.

Marketing material saying “regulated”, “approved”, “registered” or “working with SBP” should not substitute for the actual regulatory instrument.

Does in-principle approval have value?

Certainly.

It can represent a meaningful regulatory milestone.

But it should be valued as in-principle approval, not represented as final commercial authorisation.

What should be reviewed in a fintech’s transaction-flow diagram?

At minimum, one should understand who initiates payment, who receives funds, who holds them, who records customer value, who performs settlement, who can reverse or freeze the transaction, who contracts with the merchant and customer, and what entity earns each fee.

If nobody can explain the money flow without saying “the platform handles it”, the regulatory analysis is not ready.

What regulatory red flag deserves immediate attention?

A particularly serious warning sign is:

“We are not holding customer funds; they just pass through our account.”

Money passing through an account is still money in that account.

The duration may affect risk.

It does not make custody conceptually disappear.

Is a disclaimer saying “we are only a technology company” enough?

No.

Regulators classify activity by substance.

A technology company genuinely providing only software may indeed sit outside certain financial licensing requirements.

A company taking customer money cannot necessarily transform itself into a pure software vendor by adding a disclaimer.

Does incorporation with SECP amount to financial-sector approval?

No.

Corporate incorporation creates a legal entity.

It does not confer regulated financial permissions that belong to SBP, SECP in another regulatory capacity, PVARA or another competent authority.

Should fintech legal review happen before software development?

Ideally, yes.

Where the regulated structure influences custody, customer onboarding, payment flow, APIs, settlement and reporting, legal design is part of system design.

What is the most expensive fintech legal mistake?

Building an entire commercial platform around a money flow which the intended licence does not permit.

The second most expensive is discovering that after launch.

Final Practitioner Note

Pakistan’s payment system is no longer accurately described by reading the Payment Systems and Electronic Fund Transfers Act, 2007 in isolation.

The Act remains the foundation.

But the modern framework now includes the Electronic Fund Transfers Regulations, 2018, revised EMI Regulations 2023, PSO/PSP rules, Raast participation and merchant-payment arrangements, PRISM+ rules, payment-card security requirements, business-conduct regulation and the Technology Risk Management Framework for Payment Institutions. The latter became a present compliance obligation for affected payment institutions after its 31 March 2026 deadline.

The ecosystem is also continuing to change in real time. SBP designated NIFT on 27 August 2026, only days before this article was revised, while its 2026 banking framework now expressly accommodates appropriately authorised PVARA virtual-asset businesses.

That is why a transaction should be analysed functionally.

Not:

“Is this fintech?”

But:

What is being issued?

Whose money is being held?

Who moves it?

Who settles it?

Who bears the risk?

Which regulator has jurisdiction over that particular function?

Once those questions are answered, the legal architecture usually becomes much easier to see.

Conclusion: The 2007 Act Has Aged But Pakistan’s Payments Law Has Not Stood Still

The Payment Systems and Electronic Fund Transfers Act, 2007 was enacted before Pakistan’s modern digital-payment economy existed.

It would therefore be surprising if its statutory language perfectly anticipated every technology now used by consumers.

It did not.

What matters is what happened next.

The State Bank used the statutory framework to regulate card security.

Payment gateways.

Payment System Operators.

Payment Service Providers.

Electronic Money Institutions.

Instant payments.

Merchant QR infrastructure.

Systemically important payment systems.

Real-time institutional settlement.

Technology risk.

And consumer conduct.

The courts, meanwhile, have begun applying the Act to the difficult realities of electronic fraud, phishing, social engineering and unauthorised transfers.

The resulting framework is imperfect.

It is also considerably more sophisticated than the recurring internet description:

“Pakistan has an Electronic Fund Transfer Act from 2007.”

The date is only the beginning of the analysis.

For consumers, the most important provisions remain those governing disclosure, error investigation, unauthorised transfers, evidential burden and remedies.

For banks and payment institutions, compliance increasingly requires attention not merely to the statutory text but to the full SBP regulatory architecture.

For fintech founders, the central question is no longer whether Pakistan regulates digital payments.

It plainly does.

The question is which regulatory category the proposed business actually falls within.

And for lawyers, perhaps the most important discipline is the simplest one:

cite the provision that actually says what you claim it says.

A statute does not become more modern because we persuade section 24 to regulate cryptocurrency, section 31 to regulate BNPL and an imaginary Regulation 13 to govern everything from artificial intelligence to the metaverse.

Pakistan now has real regulations for many of these modern risks.

We should use them.

Legal Assistance With Payment Systems, Fintech and Electronic Fund Transfer Disputes in Pakistan

Josh and Mak International advises Pakistani and international clients concerning the Payment Systems and Electronic Fund Transfers Act, 2007, SBP payment regulation, electronic-money structures, PSO/PSP authorisation, fintech business models, payment gateways, digital wallets, merchant-payment systems, Raast-related regulatory questions, online banking disputes, unauthorised Electronic Fund Transfers, Banking Mohtasib proceedings, cyber-fraud matters, source-of-funds questions and the regulatory interaction between fiat payment systems and virtual assets.

For businesses planning a new fintech product, legal review is most effective before the final transaction architecture, custody model and technology stack have been fixed.

The first legal exercise should ordinarily be a functional map showing:

who contracts with whom;

who receives the customer’s money;

who holds it;

who issues value;

who routes the transaction;

who settles it;

which institution is licensed for each function;

and what happens if the transaction fails.

For consumers and companies affected by banking fraud or disputed transfers, evidence should be preserved before legal theories are finalised.

Bank statements.

Transaction IDs.

SMS alerts.

OTP records.

Call histories.

Email.

Platform records.

Screenshots.

Device information.

Complaint acknowledgements.

And correspondence with the institution.

The strongest banking-fraud case is rarely the one with the angriest complaint.

It is the one whose chronology can be proved.

Josh and Mak International
Islamabad, Pakistan
Email: aemen@joshandmak.com
Telephone: +92-304-8734889
Website: www.joshandmakinternational.com

Legal Disclaimer: This article provides general legal and regulatory information reviewed as at 9 September 2026. Payment-system regulation develops through legislation, SBP rules, circulars, operating rules, regulatory directions, licence conditions and judicial decisions. The legal position applicable to a particular payment product, fraud dispute or financial institution should therefore be reviewed against the instruments and facts applicable at the relevant time.

By The Josh and Mak Team

Josh and Mak International is a distinguished law firm with a rich legacy that sets us apart in the legal profession. With years of experience and expertise, we have earned a reputation as a trusted and reputable name in the field. Our firm is built on the pillars of professionalism, integrity, and an unwavering commitment to providing excellent legal services. We have a profound understanding of the law and its complexities, enabling us to deliver tailored legal solutions to meet the unique needs of each client. As a virtual law firm, we offer affordable, high-quality legal advice delivered with the same dedication and work ethic as traditional firms. Choose Josh and Mak International as your legal partner and gain an unfair strategic advantage over your competitors.

error: Content is Copyright protected !!
Josh and Mak International
Privacy Overview

Dear website visitor,

We use third-party cookies on our law firm website to enhance your browsing experience and provide you with relevant content and services. Third-party cookies are created by domains other than our website and are used for various purposes, such as tracking website analytics and serving targeted ads. The third-party cookies we use on our website are provided by Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses cookies to analyze how visitors use our website and provide us with reports on website activity. The information generated by these cookies is transmitted to and stored by Google on servers in the United States. We also use third-party cookies to serve targeted advertisements to website visitors. These cookies are provided by advertising networks and allow us to deliver advertisements that are relevant to your interests. By using our website, you consent to our use of third-party cookies as described in this policy. If you do not wish to accept cookies from our website, you can disable or delete them through your browser settings. However, please note that disabling or deleting cookies may affect your browsing experience and prevent you from accessing certain features of our website. If you have any questions or concerns about our use of cookies, please contact us using the contact details provided on our website. Thank you for visiting our website.

Best regards,

The Josh and Mak Team