But broadly the bank is completely responsible for any transaction the account owner claims is “unauthorised” unless the bank can demonstrate the account owner was “grossly negligent” with their payment credentials, or can demonstrate the account owner is making a fraudulent claim. The standard of “grossly negligent” is something you need to look to case law to understand, but it’s generally very hard to prove gross negligence, and the account owners personal situation must be considered.
A relevant example of non-gross negligence, was an older individual who entrusted their debit card and PIN number to their carer so they could buy them groceries. The carer used the card and PIN to steal money from the account holder, and bank claimed that sharing their PIN with a carer was gross negligence, but the FOS and courts disagreed on the grounds the individual needed to provide their card and PIN because their personal situation made buying groceries themselves effectively impossible.
But the TL;DR is that law places the burden on banks to prove that any transaction a customer claims is “unauthorised” was actually “authorised” by the customer, that the customer isn’t acting fraudulently, and wasn’t grossly negligent. There is no assumption of fault on the customer part.
[0] https://www.legislation.gov.uk/uksi/2017/752/part/7/crosshea...
In the Swedish supreme court case I quoted above:
Background information:
- Sweden has a public personal identification number for every citizen (except for like 10k people with protected identities)
- The four main banks in Sweden have collaborated to create something called "Bank Id". It's often used as a secure authentication tool combined with the personal identification number (something you have - the cert in the mobile app, something you know - PIN or face id).
Someone convinced an elderly person over the phone to authorize the creation of a new Bank Id on the attacker's phone. This was fairly complicated and required the old person to use their physical RSA SecurID token. The court found that the elderly person had behaved reasonably well and that the attacker was very competent.
Still, the supreme court felt that the bank should have been more careful about letting strangers steal their money.
As this case shows, this isn't always true.
If you’re house bound, entirely dependent on a trusted third party help for your day-to-day living, and your bank only provides a debit card and PIN facility to authorise your transactions, then what choice do you have but to share those credentials with a trusted third party so they can buy food for you?
The bank chooses the authentication mechanism, their customers don’t get a choice. If that mechanism doesn’t work as intended when faced with common and entirely reasonable living situations, that’s the banks failure, not the customers failure.
So yes, because we afford massive protections and rights to banks in exchange for the necessary but largely low-risk activity (holding cash then returning it in exchange for a fee) - laws holding them responsible for failing to prevent theft do exist.