Financial Services
PSD2 | EBA Opinion on the implementation of the RTS on SCA and CSC
Published on 13th July 2021
The payments industry is presently grappling with the EBA's regulatory technical standards (RTS) on strong customer authentication (SCA) and common and secure communication (CSC) – understanding them, assessing their impact and working out how best to implement them. And the deadlines are now not far away, with the main deadline 14 September 2019, and certain provisions applying from 14 March 2019.
Helpfully, the EBA has recently (13 June 2018) published an Opinion on implementation of the RTS, which while addressed to competent authorities, is also useful for PSPs, as it sets out supervisory expectations. In addition, the FCA has publicly stated its support for the Opinion.
On the same day, the EBA also published for consultation Guidelines on the conditions to be met to benefit from an exemption from the contingency measures PSPs are required to put in place in relation to dedicated interfaces for third party access.
Opinion
In the Opinion, the EBA seeks to clarify issues surrounding the RTS in relation to CSC (between TPPs (CBPIIs, AISPs and PISPs) and ASPSPs) and SCA. It contains both general and specific comments, but focusses on those where clarity is required sooner to facilitate early readiness to comply with the RTS. The EBA implies that there may be further clarifications, but that the primary source for these will be its Single Rulebook Q&A tool. Key points in relation to CSC include the following:- The dedicated interface provided by ASPSPs should ensure that TPPs can comply with all their obligations under PSD2. PSPs should therefore ensure that their interfaces permit this.
- ASPSPs do not need to check a user's consent to the provision of AIS or PIS. The Interface should not therefore include such a check.
- AISPs must be able to access the maximum amount of data available to PSUs.
- The data to be shared with an AISP/PISP must not include the PSU's identity.
- A PISP has the right to initiate the same transactions that the ASPSP offers to its own PSUs, such as instant payments, batch payments, international payments, recurring transactions, payments set by national schemes and future-dated payments.
- The exemptions are separate and independent from one another, and only one exemption needs to be applied for any given transaction, even if it could qualify for more than one.
- SCA applies only on a 'best-effort' basis for cross-border OLO (non-EEA) transactions.
- The authentication method must use two elements from two different categories.
- For a device to be considered in possession, there needs to be a reliable means to confirm possession through the generation or receipt of a dynamic validation element on the device.
- It is for the PSP that issues the personalised security credentials to determine whether or not to apply an exemption in the context of AIS or PIS.
- It is for an AISP or PISP to decide whether or not to perform authentication procedures for users to access their platforms (there is no SCA requirement otherwise).