Strong Customer Authentication: EBA shares its latest proposed amendments of the PSD2 RTS

The European Banking Authority just published its report on the amendment of its Regulatory technical standards (RTS) on strong customer authentication and secure communication (SCA&CSC) under PSD2. The changes introduce a new mandatory exemption to SCA that will require account providers not to apply SCA when customers use an account information service provider (AISP) to access their payment account information, provided certain conditions are met.
Following a public consultation that has attracted a total of 1,278 responses as well as an extensive analysis of such feedback, the EBA has introduced some changes to the draft amending RTS, while retaining the mandatory exemption and the extension of the frequency for the renewal of SCA from every 90 days to every 180 days proposed in the Consultation Paper.
The amendment’s goal is to reduce frictions for customers using such services and to mitigate the impact that the frequent application of SCA and the inconsistent application of the current exemption have on AISPs’ services.
The draft amending RTS will be submitted to the Commission for endorsement following which it will be subject to scrutiny by the European Parliament and the Council before being published in the Official Journal of the European Union. The amending RTS will apply 7 months after entry into force.
Source: EBA