Legislation is online and written in some pretty clear English, knock yourself out[0].
But broadly the bank is completely responsible for any transaction the account owner claims is “unauthorised” unless the bank can demonstrate the account owner was “grossly negligent” with their payment credentials, or can demonstrate the account owner is making a fraudulent claim. The standard of “grossly negligent” is something you need to look to case law to understand, but it’s generally very hard to prove gross negligence, and the account owners personal situation must be considered.
A relevant example of non-gross negligence, was an older individual who entrusted their debit card and PIN number to their carer so they could buy them groceries. The carer used the card and PIN to steal money from the account holder, and bank claimed that sharing their PIN with a carer was gross negligence, but the FOS and courts disagreed on the grounds the individual needed to provide their card and PIN because their personal situation made buying groceries themselves effectively impossible.
But the TL;DR is that law places the burden on banks to prove that any transaction a customer claims is “unauthorised” was actually “authorised” by the customer, that the customer isn’t acting fraudulently, and wasn’t grossly negligent. There is no assumption of fault on the customer part.
[0] https://www.legislation.gov.uk/uksi/2017/752/part/7/crosshea...