APP fraud/romance scams: Isle of Man remedies
Round-up of Isle of Man law & practice, after Crown Dependencies' joint APP fraud initiative
The scale of the current issue on the Isle of Man
This update looks at current (and potentially future) Isle of Man remedies for recovering monies lost via APP (authorised push payment) fraud and romance scams.
In general terms, APP fraud involves a bank customer being tricked into sending money to a fraudster posing as a genuine payee.
Romance scams involve fraudsters convincing often vulnerable people to send money to them, by gaining their trust and convincing them that they are in a relationship.
The Cyber Security Centre for the Isle of Man reported a total of £1.04m in financial losses over the previous year in its 2025/26 Annual Cyber Threat Update, reporting losses from:
- invoice scam/fraud – £265,875 (including around £142,000 in an APP scam) (p. 2);
- vishing (voice phishing) – £259,604 (p. 12); and
- romance scams – £213,200 (p. 13).
The Threat Update notes (at p. 7): “it is anticipated that the actual values will prove to be notably higher as cyber crime is vastly unreported”.
What follows is a brief overview of complaints to the Isle of Man Ombudsman Service; the Manx common law position; and the new Crown Dependencies-wide APP fraud initiative.
(1) The Isle of Man Financial Services Ombudsman Scheme
A number of alleged victims of APP fraud and romance scams have, in recent years, complained to the Isle of Man Financial Services Ombudsman Scheme.
The Isle of Man’s Ombudsman Scheme operates under Schedule 4 of the Financial Services Act 2008.
The Ombudsman Scheme’s Annual Report 2025/2026 covers the period up to 31st March 2026.
In total in 2025/26, some 260 complaints across relevant sectors were received. Of these, 101 were banking complaints.
Of these 101 banking complaints, the report notes:
“Complaints relating to fraud and scams (26) represented 26% of banking complaints during 2025/26, a decrease of 11% compared with the previous year. Despite this reduction, the nature of fraudulent activity continues to evolve, with scammers employing increasingly sophisticated methods to target consumers.”
Awards by Ombudsman Adjudicators, if made, are capped at £150,000 (paragraph 6(2), Schedule 4).
Complaints to the Ombudsman Scheme are first referred to mediation (paragraph 1(3)).
The limitation period is: “2 years after the act or omission giving rise to it came, or ought reasonably have come, to the knowledge of the complainant; and, in any case… 6 years after that act or omission” (paragraph 2(2)).
The supplier is: “a person who, in or from the Island, has supplied the complainant with financial services” (paragraph 1(1)).
One of a team of mediators, working under the Office of Fair Trading, seeks to resolve the complaint via mediation. If mediation fails, the complaint is referred to an adjudicator.
The Ombudsman Scheme publishes procedural guidance notes. These cover matters such as provisional and final determinations, and whether an oral hearing should be held.
The test the Ombudsman Adjudicator applies is at paragraph 6(1)-(2), Schedule 4 [underlining added]:
“6. (1) The adjudicator may, if satisfied that the complainant has suffered loss or damage by reason of any wrongful or improper act or omission by the supplier, make such award within [sub-para] (2) as the adjudicator considers proper.
(2) An award under [sub-para] (1) may comprise either or both of… —
(a) a direction to the supplier… to take such steps as the adjudicator considers appropriate to remedy the act or omission and are so specified, and
(b) an award of compensation, to be paid by the supplier to the complainant, of such amount (not exceeding… £150,000) as the adjudicator considers just and equitable…”.
APP fraud – some recent Isle of Man Ombudsman decisions
The Scheme publishes case summaries of adjudicated complaints, going back to 2014. These include some 8 adjudications involving frauds/scams.
Unlike decisions of the higher Manx courts, Ombudsman Adjudicator decisions are not binding precedents. Typically, they also turn on their own facts.
Recent examples where a financial award was made, in cases of APP fraud, include:
- Summary of the determination dated 26 January 2026 regarding a fraud involving declined debit card transactions and processed online banking transactions; and
- Summary of the determination dated 14 November 2025 in relation to fraudulent withdrawals from a bank account.
Recent examples where a financial award was not made include:
- Summary of the determination dated 21 August 2026 regarding fraudulent debit card transactions; and
- Summary of the determination dated 18 December 2025 regarding fraudulent transactions from a bank account.
In the cases where a financial award was made, Ombudsman Adjudicators found a: “wrongful or improper act or omission by the supplier”, citing one or more of:
- Rule 6.1 of the Financial Services Rule Book 2016 (“A licenceholder must act with due skill, care and diligence in carrying on regulated activities”);
- Rule 8.3(f) of the Financial Services Rule Book 2016 (the requirement on licenceholders to: “establish and maintain appropriate internal and operational controls, systems, policies and procedures… to ensure – … (f) appropriate safeguards to prevent and detect any abuse of the licenceholder’s services for… financial crime”); and
- Appendix 2 of the Isle of Man Financial Services Authority’s Regulatory Guidance on Cyber Security (December 2016) (which states: “… verification procedures should establish appropriate triggers, [eg] transfers to unfamiliar accounts. Also, when establishing triggers (e.g. amount thresholds), regulated entities should also consider that sometimes frauds may be carried out as a series of transactions and the value of each individual transaction may be relatively low…”).
In the cases where a financial award was not made, Ombudsman Adjudicators referred to factors including:
- “the losses resulted from the disclosure of security credentials to the fraudsters” (Summary of the determination dated 21 August 2026); and
- “In circumstances where the payment was made using valid security credentials and where those credentials were disclosed to the fraudster, the bank was entitled to rely on the provisions allocating responsibility where a customer acts carelessly or is grossly negligent” (Summary of the determination dated 18 December 2025).
Romance scam decision
A complaint by an alleged victim of a romance scam Summary of the determination dated 23rd August 2024 regarding a romance scam which resulted in purchasing cryptocurrency was rejected.
(2) The Manx common law position
The Manx common law position on APP fraud is not entirely straightforward.
In Barclays Bank v Quincecare Ltd [1992] 4 All ER 363, Steyn J held (at § 376) that:
“… a banker must refrain from executing an order if and for as long as the banker is ‘put on inquiry’ in the sense that he has reasonable grounds (although not necessarily proof) for believing that the order is an attempt to misappropriate the funds of the company … And, the external standard of the likely perception of an ordinary prudent banker is the governing one. That in my judgment is not too high a standard”.
Steyn J opined (at § 376) that:
“The law should not impose too burdensome an obligation on bankers, which hampers the effective transacting of banking business unnecessarily. On the other hand, the law should guard against the facilitation of fraud, and exact a reasonable standard of care in order to combat fraud and to protect bank customers and innocent third parties.”
The scope of the ‘Quincecare’ duty’ has been considered in recent years, including by the Privy Council (notably, on appeal from the Isle of Man Appeal Division) in JP SPC 4 v RBSI Ltd [2022] UKPC 18.
In Philipp v Barclays Bank UK PLC [2023] UKSC 318, the Supreme Court held the Quincecare duty generally inapplicable in cases of APP fraud.
Lord Leggatt (with whom Lords Reed, Hodge, Sales and Hamblen agreed) held [underlining added]:
“97. In summary, the duty of a bank which has come to be referred to as the “Quincecare duty” is not, as that epithet might suggest, some special or idiosyncratic rule of law. Properly understood, it is simply an application of the general duty of care owed by a bank to interpret, ascertain and act in accordance with its customer’s instructions. Where a bank is “put on inquiry” in the sense of having reasonable grounds for believing that a payment instruction given by an agent purportedly on behalf of the customer is an attempt to defraud the customer, this duty requires the bank to refrain from executing the instruction without first making inquiries to verify that the instruction has actually been authorised by the customer. If the bank executes the instruction without making such inquiries and the instruction proves to have been given without the customer’s authority, the bank will be in breach of duty. It will also in making the payment be acting outside the scope of its own authority from the customer and will therefore not be entitled to debit the payment to the customer’s account…
100. On the other hand, these principles have no application to a situation where, as in the present case, the customer is a victim of APP fraud. In this situation the validity of the instruction is not in doubt. Provided the instruction is clear and is given by the customer personally or by an agent acting with apparent authority, no inquiries are needed to clarify or verify what the bank must do. The bank’s duty is to execute the instruction and any refusal or failure to do so will prima facie be a breach of duty by the bank”.
There were some interesting features to Philipp (also, it may be noted, a Supreme Court decision, rather than a Privy Council decision on appeal from the Isle of Man):
- the bank telephoned the customer twice before each of the relevant transactions to fraudsters were said to have been authorised by the customer (see § 12);
- the issue as to the extent of the bank’s post-execution ‘retrieval duty’ to trace / recover two fraudulent payments was ordered to go to trial (§ 120): at § 118, it was held arguable: “that, when she reported that [the customer] had been induced to make the payments by fraud, the Bank’s staff should have sought her instructions” on an attempt to recall the payments);
- Lord Leggatt referred (at §§ 20-21) to recent (UK) initiatives to tackle APP fraud, including the CRM Code, and to the Financial Services and Markets Act 2023 (of Parliament) (Tynwald does not appear to have intervened similarly as yet); and
- Lord Leggatt emphasised (at §§ 22-24) the distinct role of the courts, as compared to legislators and regulators.
Not all practitioner commentary on Philipp has been enthusiastic (see, for example, Guildhall Chambers, Philipp v Barclays Bank plc [2023] UKSC 25).
The ‘retrieval duty’ identified in Philipp has also been considered in CCP Graduate School v Natwest and Santander [2024] EWHC 581 (KB).
Some or all of the above points would, no doubt, feature in any civil claim, in the Isle of Man High Court, seeking redress for APP fraud/a romance scam, over (or indeed under) the value of £150,000.
(3) Crown Dependencies: joint approach
More recently, on 8th July 2026, it was announced that financial regulators in the Crown Dependencies had agreed: “a common set of principles to underpin the development of a new Authorised Push Payment (APP) fraud framework”.
The overall position states:
“We are aligned on the benefits of a practical pan-Crown Dependency approach to APP fraud.
The aim of the framework is to support a coordinated and broadly consistent approach across the Crown Dependencies, while recognising jurisdictional differences where relevant. The focus is on retail-customer banking activity and sterling payments over Faster Payments and CHAPS, so that the work can move forward in a proportionate and workable way.
For the purposes of this work, APP fraud refers broadly to cases where a customer is deceived or manipulated into authorising a payment. The detailed definition, including its boundary with unauthorised fraud and other payment/fraud scenarios, will need to be developed and tested further to ensure clarity and consistent treatment in practice.
These messages reflect the areas of common direction between the Crown Dependency regulators. They are intended to support engagement on the emerging approach, while recognising that some detailed calibration points will need to be tested further with industry, government and Ombudsman colleagues.”
On reimbursement, the following is stated:
“The framework will need to address reimbursement, but the detailed approach remains to be settled. This includes the potential scope of eligible claims, any cap, customer responsibility, vulnerability, and the circumstances in which any reimbursement may be reduced or refused. Any approach should support meaningful customer protection while remaining proportionate, pragmatic and workable in practice.”
Coren Law’s Legal Updates will report on further developments in this dynamic area.
Note for practitioners: Alleged victims of APP fraud /romance scams, which involve accounts of Isle of Man regulated entities, typically complain to the Ombudsman Scheme. Awards, if made, are capped at £150,000. Awards are only made where there is a: “wrongful or improper act or omission by the supplier”. Whether an award is made will turn on the facts of the case. Where the alleged loss is higher than £150,000 (ie. the Ombudsman Scheme cap), redress may be sought via the High Court (although redress may be sought separately via the High Court for a lower sum). The current Manx common law position appears to point against a general remedy for APP fraud, save where a ‘retrieval duty’ may be said to arise. Meantime, the Crown Dependencies are moving towards an offshore standard regulatory framework for APP fraud.
Disclaimer: professional advice should be sought before applying any information in a given case.
For advice on civil remedies in relation to APP fraud or romance scams (or civil fraud more generally), contact Coren Law.
See also Coren Law’s Isle of Man civil procedure portal: Click On | Coren Law.
More News
Stay up to date with more of our latest news updates.
Cryptocurrency fraud, civil law & the Isle of Man
Isle of Man likely to be impacted by recent English decisions in Smithers and Yuen
Just my Lux: unlawful means conspiracy claims, after Lux Films
Isle of Man implications, as sole director found capable of conspiring with own company