# PSD2: The Countdown is on
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-08-14
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: PSD2 Compliance Deadline: Strong Consumer Authentication
Meta Description: Learn about the upcoming PSD2 regulations, including the new Strong Customer Authentication requirement, and how to prepare your organisation to avoid financial
URL: https://financedigest.com/psd2-the-countdown-is-onhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/untitled-design-96-1736838865354-compressed.jpg)

With the second Payment Services Directive (PSD2) still set to take place on December the 31st, FS organisations across Europe are running out of time to ensure compliance.

It’s next round will include a new regulatory requirement; Strong Consumer Authentication (SCA) – designed to tackle fraud and make online payments more secure. It represents an essential step towards increased consumer protection. Payment Service Providers will become fully responsible for payments that are not correctly executed. As such, they will be responsible for refunding consumers. Only when payment services users act fraudulently, or out of gross negligence, are they fully liable.

In order to avoid the [potential](https://www.financedigest.com/delivering-on-the-potential-of-open-finance.html "Delivering on the potential of open finance") financial and reputational damage that non-compliance would bring, FS organisations need to be prepared. With less than 5 months to go until this round of PSD2 comes into effect, the team at _Finance Digest_ spoke with several industry experts to find out more about the directive and what it will mean for the industry [moving forward](https://www.financedigest.com/life-is-moving-forward-china-declares-new-covid-phase.html "‘Life is moving forward’: China declares new COVID phase").

**_Simon Marchand, Chief Fraud Prevention Officer at_** [**_Nuance Communications_**](https://www.nuance.com/en-gb/index.html)

_“The PSD2 not only seeks to reflect technological change, but to promote [digital innovation by facilitating the market](https://www.financedigest.com/the-hemoglobinopathy-market-to-get-digitally-innovative.html "The Hemoglobinopathy Market to get digitally innovative") entry of new types of service providers. It aims to provide greater transparency over transactions in order to improve [consumer protection and strengthen the security](https://www.financedigest.com/the-digital-finance-revolution-empowered-consumers-turn-digital-to-protect-financial-security.html "The digital finance revolution: empowered consumers turn digital to protect financial security") of payments._

_“In order to achieve this, in its next round, the legislation will include a new regulatory requirement aimed at making [online payments](https://www.financedigest.com/online-payment-gateway-market-to-witness-a-cagr-of-10-3.html "Online Payment Gateway Market to witness a CAGR of 10.3%") more secure; Strong Customer Authentication. This will call for the relevant parties to incorporate at least two of the following three elements: a password or PIN, smartphone or hardware token or [biometric authentication](https://www.financedigest.com/why-latin-america-chose-biometric-authentication-for-payment-cards.html "Why Latin America Chose Biometric Authentication for Payment Cards"). Today, organisations will be asking themselves, how do we maintain compliance and meet that December deadline while – at the same time – reducing friction for our customers?” The answer to that is, in our opinion, the “something you know” aspect should be avoided._

_“PINs or passwords can be forgotten, often leading to a bad experience. Using technologies – such as voice and [behavioural biometrics](https://www.financedigest.com/how-behavioural-biometrics-can-help-financial-organisations-tackle-complex-ato.html "How behavioural biometrics can help financial organisations tackle complex ATO") – makes for a seamless customer experience, whilst ensuring the highest levels of security. Users will not need to remember something specific and can simply speak a sentence to be authenticated. And their voice can’t be stolen, unlike passwords. Deploying biometrics provides an opportunity for FS organisations – and others that need to comply with the PSD2 – to clearly sign-point their commitment to tackling fraud and safeguarding their customers’ information.”_

**_Alberto Pan, Chief Technical Officer at_** [**_Denodo_**](https://www.denodo.com/en)

_“The [next phase of the PSD2 will signify another important step](https://www.financedigest.com/eu-leaders-to-discuss-next-steps-on-energy-ukraine.html "EU leaders to discuss next steps on energy, Ukraine") in terms of increased consumer protection. However, for financial organisations needing to comply with the [regulation](https://www.financedigest.com/uk-finance-regulators-should-pay-heed-to-energy-security-policy-says-sunak.html "UK finance regulators should pay heed to energy security policy, says Sunak"), it’s likely to create some challenges._

_“One of those challenges will come in the form of managing and controlling APIs. The PSD2 normative forces financial organisations to create [open APIs](https://www.financedigest.com/apis-open-banking-and-new-business-models.html "APIs, Open Banking and New Business Models") in order to expose consumer data to authorised third-parties. These authorised parties can utilise the APIs to initiate payments from customer [accounts](https://www.financedigest.com/covid-19-has-made-your-customer-accounts-more-valuable.html "Covid-19 has made your customer accounts more valuable") and to aggregate customer’s financial data.With thousands of users and applications needing access in order to make these transactions, it’s imperative that these APIs are both secure and able to perform, especially with PSD2 making Payment Service Providers fully responsible for refunding [consumers](https://www.financedigest.com/unfolding-the-great-payments-disruption-how-consumers-can-navigate-this-new-financial-world-and-how-financial-institutions-can-rise-to-the-challenge.html "Unfolding the Great Payments Disruption – how consumers can navigate this new financial world and how financial institutions can rise to the challenge") when payments are not correctly executed._

_“However, ensuring this high level of performance and security using traditional methods can be a long and costly process, not helped by the fact that financial organisations often store [data](https://www.financedigest.com/how-to-drive-a-data-culture-in-the-finance-industry.html "How to drive a data culture in the finance industry") across many different disparate systems. This is where modern technologies, such as data virtualisation, could help. By providing [unified data views across multiple data origins and automatically generating secure](https://www.financedigest.com/how-finance-firms-can-unify-two-data-approaches-to-improve-both-compliance-and-security.html "How finance firms can unify two data approaches to improve both compliance and security") APIs to access them without needing to manually create complex custom codes, data virtualisation could be one answer for financial organisations looking to prepare for the newest chapter of PSD2.”_

**Monica Hovsepian Global Industry Strategist, Financial Services at** [**OpenText**](https://www.opentext.com/)

_“The global pressure for [open banking](https://www.financedigest.com/how-accountants-can-improve-financial-planning-and-results-through-open-banking-to-help-smes.html "How accountants can improve financial planning and results through Open Banking to help SMEs") is clear. Regulatory bodies around the world are looking for ways to de-monopolise the financial [industry to stimulate innovation and provide more options for consumers](https://www.financedigest.com/uk-consumer-industries-warn-curbing-energy-support-will-hit-demand.html "UK consumer industries warn curbing energy support will hit demand")._

_“The introduction of PSD2 means, with customer consent, their [data is released in a secure](https://www.financedigest.com/normalizing-advanced-cloud-data-security-with-normalyze-from-amer-deeba-and-ravi-ithal.html "Normalizing Advanced Cloud Data Security with Normalyze from Amer Deeba and Ravi Ithal"), standardised form, so that it can be shared between authorised organisations online. The purpose is that this information can be used to make more relevant and personalised offers quicker when switching between banks, rather than having to build up a long history with each institution._

_“Whilst the_ _FCA_ _recently_ [_announced_](https://urldefense.com/v3/__https:/www.fca.org.uk/news/statements/strong-customer-authentication-and-coronavirus__;!!Obbck6kTJA!NcWZCJkoUVCZoR8ODBiQcFSX7L0W_sYkd8GY6aWVEN0c4em6o1AVU4SIGZP5CPz7bw$) _an additional six month delay for_ _PSD2_ _SCA enforcement_ _,_ _due to the exceptional circumstances of the COVID-19 crisis_ _,_ _PSD2 should no longer be seen as an option; it is something that is on the critical roadmap of every financial institution that wants to stay competitive._

_“Globally, some traditional financial institutions are embracing open banking already, such as_ [_BBVA_](https://urldefense.com/v3/__https:/www.bbva.com/en/everything-need-know-psd2/__;!!Obbck6kTJA!NcWZCJkoUVCZoR8ODBiQcFSX7L0W_sYkd8GY6aWVEN0c4em6o1AVU4SIGZMe1e9Ydg$) _, Citi Bank and JPMC. However, others are at risk of [falling behind](https://www.financedigest.com/behind-ftxs-fall-battling-billionaires-and-a-failed-bid-to-save-crypto.html "Behind FTX’s fall, battling billionaires and a failed bid to save crypto"). They are risking the unpleasant possibility of losing customers to newer or more agile competitors._

_“They would be well served by embracing change and collaborating with new entrants to build a more open ecosystem. This requires incumbents to modernise legacy systems, develop open APIs for information sharing and easy integrations, and to embrace the new products and [services that consumers expect](https://www.financedigest.com/keeping-up-with-heightened-consumer-expectations-in-financial-services.html "Keeping up with heightened consumer expectations in financial services"). These changes are critical to expedite and increase engagements in the new [digital](https://www.financedigest.com/six-reasons-why-digital-world-classtm-finance-organizations-outperform-peers.html "Six Reasons Why Digital World ClassTM Finance Organizations Outperform Peers") and connected world.”_

**Jonathan Jensen, Director of Identity Verification at** [**GBG**](https://www.gbgplc.com/)

_“The premise behind SCA is to protect consumers and merchants from fraudsters. But as with many good intentions, the outcome risks being something different. The danger the [industry faces](https://www.financedigest.com/peel-off-face-mask-market-2022-outlook-current-and-future-industry-landscape-analysis-2029.html "Peel off Face Mask Market 2022 Outlook, Current and Future Industry Landscape Analysis 2029") is that its implementation will lead to the three “F’s” – friction, frustration and fraud among consumers. And when this leads to abandoned transactions, merchants have a problem._

_“SCA [requires an additional level of authentication in certain ecommerce and online banking](https://www.financedigest.com/building-a-relationship-led-bank-requires-a-more-human-touch.html "Building a relationship led bank requires a more human touch") transactions, by providing two out of three elements; something you know, something you have, or something you are. (For example: a [phone number](https://www.financedigest.com/your-phone-number-on-google-search-giant-now-takes-removal-demands.html "Your phone number on Google? Search giant now takes removal demands") combined with a one-time passcode or Face ID)._

_“SCA is usually implemented for ecommerce via 3DS v2.1 or v2.2. The way SCA is currently deployed for ecommerce typically involves [sending a one-time code via text message](https://www.financedigest.com/covid-hit-queen-elizabeth-sends-message-to-brazil.html "COVID-hit Queen Elizabeth sends message to Brazil") or email to verify online purchases. However, regulators do not see this method as compliant, so alternatives like biometrics are required. One-time codes can likewise pose problems for consumers when there’s [poor mobile](https://www.financedigest.com/feature-africas-mobile-money-taxes-risk-driving-poor-out-of-digital-economy.html "FEATURE-Africa’s mobile money taxes risk driving poor out of digital economy") coverage or limited WiFi availability, leading to a poor consumer experience overall._

_“Furthermore, guidance being given by banks can be vague – I once received an email stating that when using online banking I would ‘sometimes’ be sent a code to login, and I ‘may’ be asked to use my card reader when carrying out certain transactions. This will likely leave many consumers wondering what’s legitimate and what’s a smishing (SMS phishing) attempt by a bad actor.”_

_“Dynamic linking between an authentication token for an individual transaction, a set amount and a named merchant is another SCA requirement. However, merchant names often do not exactly match within authorisation and authentication systems and final transaction amounts can vary. These variables can make dynamic linking a challenge._

_“But it’s not all bad news; technology is helping to overcome these problems. [Digital banks](https://www.financedigest.com/key-considerations-for-building-an-inclusive-digital-banking-experience-fit-for-the-future.html "Key considerations for building an inclusive Digital Banking Experience fit for the Future") are already exploiting the smart functionality in their apps to present consumers with notifications that require a simple tap to authorise the transaction, combined with a biometric. And there’s [technology available](https://www.financedigest.com/advertys-multi-patented-and-industry-leading-in-game-viewability-technology-brainimpression-now-available-within-oracle-moat.html "Adverty’s Multi-patented and Industry-leading In-game Viewability Technology BrainImpression™ Now Available Within Oracle Moat") that seamlessly carries out the authentication on the consumer’s handset in the background, without them needing to do anything. Payment methods like Apple Pay, for example, [don’t require any additional authentication and still let you pay with your usual debit or credit](https://www.financedigest.com/12-things-that-dont-hurt-your-credit-score.html "12 Things That Don’t Hurt Your Credit Score") card, as the consumer has already authenticated via Face ID or Touch ID. Innovation will be crucial to the successful implementation of SCA, and ultimately, the ability of merchants and consumers to carry on transacting.”_


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

