2018-12-19
Added
The Financial Conduct Authority proposes to create UK Regulatory Technical Standards (UK-RTS) substantially mirroring the EU SCA-RTS to apply from 14 September 2019 in the event of a no-deal Brexit. These standards would require payment service providers, including banks and third-party providers, to implement strong customer authentication and secure communication protocols. The proposal also includes minor amendments to sub-articles 30(3) and (5) of the SCA-RTS to ensure operability in the UK, such as replacing references to the EBA with the FCA and converting euro thresholds to sterling. Comments on these proposals are requested by 19 February 2019.
FCA published 8 documents in the last 30 days — get each new one by email the day it lands.
Consultation Paper
CP18/44
December 2018
Brexit – Regulatory Technical Standards for
Strong Customer Authentication and Common and Secure Open Standards of Communication
2
CP18/44 Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication We are asking for comments on this Consultation Paper (CP) by 19 February 2019. You can send them to us using the form on our website at: www.fca. org.uk/cp18-44-response-form Or in writing to:
Ross Studholme
Financial Conduct Authority
12 Endeavour Square
London E20 1JN
Telephone
020 7066 1000
Email:
cp18-44@fca.org.uk
How to respond Contents
1 Summary 3
2 The wider context 6
3 Our proposals to amend technical standards (sub-articles 30(3) and (5) of the SCA-RTS) 9 4 Our proposals to make technical standards (UK-RTS) 10
Annex 1
Questions in this paper 13
Annex 2
Cost benefit analysis 14
Annex 3
Compatibility statement 18
Annex 4
Abbreviations used in this paper 21
Appendix 1
Draft amendments to technical standards (sub-articles 30(3) and (5) of the SCA-RTS)
Appendix 2
Draft technical standards (UK-RTS)
Appendix 3
Draft changes to the Handbook returns you to the contents list takes you to helpful abbreviations How to navigate this document onscreen
3
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication 1 Summary Why we are consulting
1.1 On 14 March 2018, the EU Regulatory Technical Standards for strong customer
authentication and common and secure open standards of communication (SCARTS)1 came into force. The SCA-RTS support the security and safety of electronic payments. They form part of EU law, and supplement the Payment Services Directive 2015 (PSD2).
1.2 From 14 March 2019, firms will need to start following some of the provisions of the
SCA-RTS.2
However, the remainder of the standards will not take effect fully until 14 September 2019.
1.3 On 29 March 2019, the UK will leave the EU. If the UK leaves the EU without a
withdrawal agreement (a ‘no-deal exit’), the SCA-RTS will be left partially converted into UK law. This would leave a gap in the UK’s regulatory framework, causing potential disruption and considerable regulatory uncertainty. Despite the investments made by banks and other payment service providers to meet the 14 March 2019 deadline, consumer protections for the security and safety of payments would be at risk unless we made similar technical standards which would apply in the UK after exit day.
1.4 In this Consultation Paper (CP) we propose to make regulatory technical standards
for strong customer authentication and common and secure open standards of communication (UK-RTS) substantially the same as the SCA-RTS, which will apply in the UK from 14 September 2019 in the event of a no-deal exit.3 Who this applies to
1.5 The proposals apply to payment service providers, including banks, building societies,
e-money issuers, payment institutions, registered account information service providers and payment initiation service providers.
1.6 The paper will also be of interest to:
4
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
5
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
1.14 In this consultation, we are also proposing to make minor amendments to certain
provisions of the SCA-RTS. We are proposing to do this to maintain the current legal basis for API interfaces and access testing facilities, and to provide certainty for account servicing payment service providers and third party payment service providers. We will ensure these provisions will operate effectively by making the remainder of the UK-RTS. Next steps
1.15 Please consider our proposals and send us your comments on the questions in this CP
by 19 February 2019. Use the online response form on our website or write to us at the address on page 2 of this document.
1.16 We will consider your comments and publish our feedback, along with our rules, in a
Policy Statement in April 2019.
6
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication 2 The wider context Why we are proposing the UK-RTS
2.1 The EU Regulatory Technical Standards for strong customer authentication and
common and secure open standards of communication (SCA-RTS)6 set out how payment service providers (PSPs) must verify a customer’s identity where a customer accesses a payment account online, initiates an electronic payment transaction (such as when shopping online), or carries out any action through a remote channel which may create a risk of payment fraud. This verification is referred to in the SCA-RTS as strong customer authentication, and is based on the use of 2 or more elements, categorised as:
7
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
2.6 By making the proposed technical standards in the form set out in Appendix 2
(UK-RTS), we seek to:
Support consumer protections around strong customer authentication and security of payments
2.7 One of the aims of the PSRs 2017 is to prevent harm to consumers caused by payment
fraud. They introduce measures to combat unauthorised payments by strengthening the process for authorising a payment. From 14 September 2019, all PSPs will need to ask customers for more information to verify their identity before an electronic payment is made. This strong customer authentication will be a requirement under the PSRs 2017 unless an exemption is used or applies (for example, for low value payments).
2.8 Making the UK-RTS will support strong customer authentication by setting out certain
security measures. These include, for example, requirements for the number of consecutive failed authentication attempts which can be made before access must be blocked, and the time spent accessing a payment account online without activity after authentication. These types of security measures should further consumer protection, in line with our objectives. Support market integrity and provide certainty and clarity about requirements for firms to implement common and secure open standards of communication
2.9 The UK-RTS will include requirements addressing threats to the security of electronic
payments and payment data, and will support open banking (such as standards governing the security of communication sessions and data exchanges when TPPs are accessing customers’ current account data or initiating a payment). As a result, the UK-RTS should enhance market integrity, help to improve trust in the financial system, and allow competition and innovation. Proposal to make the UK-RTS substantially in the form of the SCA-RTS
2.10 At the time of publication of this consultation paper, ASPSPs will need to have decided
how they will implement the requirements of the SCA-RTS. Because the SCA-RTS require ASPSPs to have built testing interfaces for TPPs by 14 March 2019, ASPSPs will also need to have made certain investment decisions such as:
8
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
2.11 Having decided which type of access ASPSPs want to offer to TPPs, ASPSPs will need
to be able to rely on other requirements of the SCA-RTS still being in place to finish building interfaces for testing by March 2019. These include the provisions of the SCA-RTS regarding security of communication sessions between ASPSPs and TPPs.
2.12 Card schemes and payment service providers have also been preparing to implement
the SCA-RTS’s requirements on strong customer authentication. For remote electronic payments (such as when shopping online), additional authentication steps will be needed unless a transaction qualifies for one of the permitted exemptions. Card schemes have reported7 how they have been upgrading their platforms and related fraud identification and prevention tools to support the implementation of strong customer authentication in compliance with the SCA-RTS, and to allow early compliance by card issuers and banks.
2.13 The European Banking Authority (EBA) has already consulted on and finalised
the SCA-RTS. We believe that the SCA-RTS should be effective in protecting consumers, supporting market integrity, and promoting competition in the interests of consumers. While we acknowledge that some of the EBA’s proposals were subject to differing views from consultation respondents, we believe that it could cause significant uncertainty and potential disruption if we did not make technical standards substantially the same as the SCA-RTS.
2.14 The SCA-RTS have been in force since 14 March 2018. Industry participants have
invested considerable sums to build the processes needed based on the SCA-RTS. As outlined in paragraphs 2.10 and 2.11 above, ASPSPs must build testing facilities and make available technical specifications to TPPs by March 2019. Similarly, card schemes and payment service providers have been developing new processes to follow the strong customer authentication requirements of the SCA-RTS, as referred to in paragraph 2.12 above. Making technical standards in a materially different form from the SCA-RTS at this stage could cause firms to incur further significant costs and risk non-compliance.
2.15 Our view is that the cost and confusion that could arise out of making UK-RTS in a
different form from the SCA-RTS at this late stage of their implementation would be disproportionate to the benefits that any changes could bring. Why we are amending sub-articles 30(3) and (5) of the SCA-RTS
2.16 Sub-articles 30(3) and (5) of the SCA-RTS require ASPSPs to offer testing facilities and
technical specifications for their access interfaces for TPPs by 14 March 2019. Those provisions will become part of UK law under the European Union (Withdrawal) Act 2018 if the UK leaves the EU without an agreement. We propose to amend those provisions so that they are operable in the UK, using our powers in the Regulators’ Powers Financial Regulators’ Powers (Technical Standards etc.) (Amendment etc.) (EU Exit) Regulations 2018 (Regulators’ Powers SI) if no implementation period is agreed. 7 https://newsroom.mastercard.com/eu/files/2018/02/Security-Matters-Authentication-under-PSD2-and-SCA-MastercardWhite-Paper.pdf
9
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication 3 Our proposals to amend technical standards (sub-articles 30(3) and (5) of the SCA-RTS)
3.1 Sub-articles 30(3) and (5) of the EU Regulatory Technical Standards for strong
customer authentication and common and secure open standards of communication (SCA-RTS)8 will become UK law on exit day in line with the EU Withdrawal Act, if there is no implementation period.
3.2 We propose to use our power under section 7 of the Financial Regulators’ Powers
(Technical Standards etc.) Powers SI (Amendment etc.) (EU Exit) Regulations 2018 to make changes to sub-articles 30(3) and (5) of the SCA-RTS to ensure that they operate effectively in the UK once the UK has left the EU. For example, references in the SCA-RTS to the ‘EBA’ and ‘competent authorities’ will be replaced with ‘FCA’, and references to articles of the PSD2 will be replaced with references to the equivalent provisions of the PSRs 2017.
3.3 There is no change to the existing requirement that by 14 March 2019:
10
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication 4 Our proposals to make technical standards (UK-RTS)
4.1 As set out in Regulation 106A of the Electronic Money, Payment Services and Payment
Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018 (Exit SI) we may make certain technical standards specifying:
11
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
4.6 As a result, by 14 September 2019, we propose that payment service providers will
still need to have systems and processes in place that follow technical standards substantially in the same form as the SCA-RTS. Therefore, we would introduce provisions on strong customer authentication and common and secure open standards of communication as set out in Appendix 2, including:
12
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
13
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
Annex 1
Questions in this paper
Q1: Do you agree that we should make technical standards on strong customer authentication and common and secure open standards of communication, if there is no mplementation period after exit day? If not, please explain why. Q2: Do you agree with our making proposed amendments to sub-articles 30(3) and (5) of the SCA-RTS if there is no mplementation period after exit day? If not, please explain why. Q3: Do you agree with our proposed technical standards as set out in Appendix 2? If not, please explain why. Q4: Do you agree with our proposed changes to the Handbook as set out in Appendix 3? If not, please explain why. Q5: Do you agree with the costs and benefits we have identified? If not, please explain why.
14
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
Annex 2
Cost benefit analysis
Introduction
15
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
4. If the withdrawal agreement is not ratified, the Exit SI will amend the PSRs 2017 by
replacing provisions that refer to the SCA-RTS, with provisions that refer to technical standards (on strong customer authentication and common and secure open standards of communication) made by us using the power in Regulation 106A. These provisions will come into force on 14 September 2019. For example, account servicing payment service providers (ASPSPs) and third party payment service providers (TPPs) will be required under the Payment Services Regulations 2017(PSRs 2017)4 to comply with the FCA’s technical standards when communicating with each other. If we do not make technical standards, some provisions of the PSRs 2017 will need firms to comply with technical standards which will not have been made. This would cause regulatory uncertainty for firms and consumers, and be likely negatively to affect the implementation of consumer protections in the UK (such as strong customer authentication and security of payments, where a customer accesses their payment account online, initiates an electronic payment transaction, or carries out any action through a channel which may create the risk of payment fraud). Baseline
5. We will have the discretion to make the technical standards in the UK under the
amended PSRs 2017. The baseline for our proposals in this consultation paper is that if we decided to take no action, if the UK and EU do not agree and ratify a withdrawal agreement, there will be no technical standards on strong customer authentication and secure communication in the UK after exit day. This would cause significant uncertainty and potential disruption regarding the implementation of the technical standards referred to in the amended PSRs 2017.
6. It is also relevant to the baseline that industry has invested heavily to develop
interfaces to follow the common and secure standards of communication in the SCARTS. For example, we have received reports through discussions with some firms and industry bodies that individual credit institutions have estimated their implementation costs as being in excess of £100m, and smaller payment institutions have estimated spending up to £500k on implementation.5
7. We believe that many firms will have incurred costs in building systems and processes
to follow the SCA-RTS. The SCA-RTS have been in force since March 2018. Under these, ASPSPs must make access interfaces available for testing by TPPs by 14 March 2019. Therefore, ASPSPs will need to have started incurring costs to build those interfaces well in advance of 14 March 2019 (before exit day). Although firms are at different stages of implementation, the Open Banking Implementation Entity published a roadmap in July 2018 setting out the phased timelines for firms implementing open banking.6 The roadmap shows that those firms’ main implementation activity started in February 2018, and that most of their planned implementation would have been carried out by exit day. The costs of implementation incurred before exit day will relate to the SCA-RTS, and not to our proposal to make the UK-RTS. 4 Regulations 69(2)(a) and 70(2)(a) 5 Our information does not apply to all PSPs affected by our proposals. 6 www.openbanking.org.uk/wp-content/uploads/Open-Banking-Revised-Roadmap-July-2018.pdf
16
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication Costs
8. The costs of our proposals include firms’ familiarisation and gap analysis costs and
firms’ implementation and ongoing costs.
9. We estimate a total of 1,557 firms are affected by the proposals, comprising credit
institutions, payment institutions and e-money institutions.
10. UK payment firms support 74 million transactions with a total value of £229 billion
every day. All customers who make electronic payments in the UK will be affected by the new technical standards on strong customer authentication if the proposed technical standards in the form set out in Appendix 2 (UK-RTS) are made.
11. There would be limited costs to firms associated with familiarising themselves with the
proposals in this CP and carrying out a gap analysis on the differences between the UK-RTS and the SCA-RTS. Those differences would be minimal changes as set out in
Appendix 2, rather than differences of substance.
12. We estimate the total one-off familiarisation and gap analysis costs are around
£980,000. Based on our data, we anticipate a total of 1,557 firms are affected by the proposals (57 large, 193 medium and 1,307 small firms). Using data on salaries from the Willis Towers Watson UK Financial Services survey, the length of the consultation paper (CP) and the UK-RTS documents and a typical time spent by compliance and legal officers on reviewing the CP, we estimate the cost per firm will be: £4,900 for large, £1,630 for medium and £300 for small firms.7
13. If the UK-RTS are made substantially in the form of the SCA-RTS, we believe that the
cost of implementing the UK-RTS8
, and any ongoing costs of compliance, will be no greater than the remaining costs of following and implementing the existing SCA-RTS.
14. Many firms have already incurred costs in building systems and processes to comply
with the SCA-RTS. The implementation costs which firms have incurred to date relate to the SCA-RTS developed by the EBA. Implementation costs relating to the UK-RTS would be limited to costs incurred after exit day. On that basis, there would be relatively little cost saving if we did not make the UK-RTS. Moreover, unless we make the UKRTS, the benefits outlined below will not be realised.
15. We believe it would not be reasonably practicable to estimate the remaining costs
of following and implementing our proposals. Firms are at different stages of implementation of the SCA-RTS, have different solutions for implementation with different costs implications, and have different amounts of implementation costs remaining to be spent. We do not have full information about these amounts. The time in which to obtain information from firms, conduct a new analysis, and produce quantitative estimates has by necessity been constrained by external dependencies, and the deadline for finalising this work is fixed as we must make the UK-RTS in time for firms to implement by September 2019. 7 We assume that 20 compliance staff at large firms, 5 compliance staff at medium firms, and 2 compliance staff at small firms read the relevant documentation. The reading speed is assumed 100 words per minute. we have assumed that 4 legal staff at large firms, 2 legal staff at medium firms, and 1 member of legal staff at small firms will review our final technical standards. It is further assumed that each legal staff member can review 50 pages of legal text per day. Using data on salaries from the Willis Towers Watson UK Financial Services survey, the hourly compliance staff salary is assumed to be £57 at large firms, £60 at medium firms, and £42 at small firms, while the hourly legal staff salary is assumed to be £66 at large firms, £66 at medium firms, and £51 at small firms, including 30% overheads. 8 Except for familiarisation and gap analysis costs
17
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
16. In addition, we believe it is not reasonably practicable (given the time constraints
referred to above) and not proportionate to conduct another analysis of the ongoing costs of complying with our proposals (eg monitoring and maintaining systems and controls, IT system maintenance, etc.) given that the EBA has conducted the impact assessment and concluded that the SCA-RTS proposals will deliver net benefits. Benefits
17. Benefits resulting from our proposals include:
18
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
Annex 3
Compatibility statement
Compliance with legal requirements
Compliance with legal requirements
19
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication Securing and maintaining fair competition among all payment service providers
8. We believe that our proposals are aligned with this principle. The UK-RTS will allow the
access by TPPs to customers’ current account data needed under the PSRs 2017. Where developed according to common standards and using secure common infrastructure, this type of access can support competition by reducing barriers to entry, as TPPs will not have to integrate with different technology on a firm-by-firm basis. Ensuring technology and business-model neutrality
9. We believe that our proposals comply with this principle on the basis that they do not
discriminate against any particular business model or approach. We have considered specific requirements for PSPs conducting new payment services, ie account information services, payment initiation services and card based payment instrument issuers. Allowing for the development of user-friendly, accessible and innovative means of payment.
10. We believe that our proposals are aligned with this principle as the UK-RTS’ common
standards of communication are intended to support ASPSPs’ implementation of standardised APIs which support open banking. Open banking is designed to bring more competition and innovation to financial services by enabling customers to make payments directly and securely from their bank or building society without using a credit card or debit card. Also, the UK-RTS specify the same exemptions as the SCARTS where Payment Service Providers (PSPs) do not need to apply strong customer authentication. The need to use our resources in the most efficient and economic way
11. For the proposals in this CP, and in implementing Regulation 106A of the amended
PSRs 2017, we have considered the burden on the FCA of assessing how best to implement. The principle that a burden or restriction should be proportionate to the benefits
12. We believe the proposals in this consultation paper (CP) containing burdens or
restrictions are proportionate to the benefits, and set out our analysis of the costs and benefits of our proposals in our cost benefit analysis. The desirability of sustainable growth in the economy of the United Kingdom in the medium or long term.
13. The proposals support implementation of open banking, which seeks to improve
competition in payment services, and improve access for payment services businesses. The general principle that consumers should take responsibility for their decisions
14. We do not propose any requirements which are inconsistent with this principle.
The responsibilities of senior management
15. We believe the proposals in this CP are consistent with this principle. Senior managers
of PSPs will need to ensure compliance with the PSRs 2017, UK-RTS and the relevant parts of our Handbook. The desirability of exercising our functions in a way that recognises differences in the nature and objectives of businesses carried on by different persons
16. We do not believe that our proposals discriminate against any particular business
model or approach. We have considered specific requirements for PSPs conducting
20
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication new payment services (account information services (AIS) and payment initiation services (PIS)) and card based payment instrument issuers (CBPIIs). The desirability of publishing information relating to persons subject to requirements imposed under the Financial Services and Markets Act 2000 (FSMA), or requiring persons to publish information
17. This principle is not relevant to our proposals as they do not involve any requirements
imposed under FSMA, nor do we require persons subject to such requirements to publish information. The principle that we should exercise our functions as transparently as possible
18. We believe that by consulting on our proposals we are acting in line with this principle.
Expected effect on mutual societies
19. Section 138K of FSMA requires us to provide an opinion on whether the impact of
a proposed rule on mutual societies is significantly different to the impact on other authorised persons.
20. Our proposals are intended to increase consumer protection to make sure businesses
have secure systems in place to minimise the risk of fraud where online transactions are offered.
21. We are satisfied that the impact of our proposals on mutual societies, such as building
societies, are not significantly different to that on other authorised firms. Equality and diversity
22. We are required under the Equality Act 2010 in exercising our functions to ‘have
due regard’ to the need to eliminate discrimination, harassment, victimisation and any other conduct prohibited by or under the Act, advance equality of opportunity between persons who share a relevant protected characteristic and those who do not, and to foster good relations between people who share a protected characteristic and those who do not.
23. As part of this, we ensure the equality and diversity implications of any new policy
proposals are considered.
21
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
Annex 4
Abbreviations used in this paper
API Application Programme Interface
ASPSP Account servicing payment service provider CBA Cost benefit analysis EBA European Banking Authority Exit day The date on which the UK ceases to be a member of the European Union Exit SI The Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018 EUWA The European Union (Withdrawal) Act 2018 FSMA Financial Services and Markets Act 2000 PSD2 Payment Services Directive 2 PSP Payment Service Provider PSR Payment Systems Regulator PSRs 2017 Payment Services Regulations 2017 Regulators’ Powers SI Financial Regulators’ Powers (Technical Standards etc.) Powers SI (Amendment etc.) (EU Exit) Regulations 2018 SCA-RTS Commission Delegated Regulation (EU) 2018/389 TPP Third Party Payment Service Provider UK-RTS Technical standards proposed to be made by the FCA in the form set out in Appendix 2
22
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication We have developed the policy in this Consultation Paper in the context of the existing UK and EU regulatory framework. The Government has made clear that it will continue to implement and apply EU law until the UK has left the EU. We will keep the proposals under review to assess whether any amendments may be required in the event of changes in the UK regulatory framework in the future. We make all responses to formal consultation available for public inspection unless the respondent requests otherwise. We will not regard a standard confidentiality statement in an email message as a request for non-disclosure. Despite this, we may be asked to disclose a confidential response under the Freedom of Information Act 2000. We may consult you if we receive such a request. Any decision we make not to disclose the response is reviewable by the Information Commissioner and the Information Rights Tribunal. All our publications are available to download from www.fca.org.uk. If you would like to receive this paper in an alternative format, please call 020 7066 7948 or email: publications_graphics@fca.org.uk or write to: Editorial and Digital team, Financial Conduct Authority, 12 Endeavour Square, London E20 1JN
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
Appendix 1
Draft amendments to technical standards
(sub-articles 30(3) and (5) of the SCA-RTS)
FCA 201X/XX
TECHNICAL STANDARDS ON STRONG CUSTOMER AUTHENTICATION AND COMMON AND SECURE METHODS OF COMMUNICATION (AMENDMENT OF TESTING PROVISIONS) INSTRUMENT 201[9] Powers exercised A. The Financial Conduct Authority, being the appropriate regulator within the meaning of the Financial Regulators’ Powers (Technical Standards etc.) (Amendment etc.) (EU Exit) Regulations 2018 (“The Regulations”), with the approval of the Treasury, makes this instrument in exercise of the power conferred by Regulation 3 of the Regulations. Pre-conditions to making B. The FCA is the appropriate regulator for the EU Regulations specified in Part 1 of the
Schedule to the Regulations.
C. The FCA has consulted the Prudential Regulation Authority and the Bank of England
as appropriate in accordance with Regulation 5 of the Regulations. D. A draft of this instrument has been approved by the Treasury, the Minister considering that it makes appropriate provision to prevent, remedy or mitigate any failure of retained EU law to operate effectively, or any other deficiency in retained EU law, arising from the withdrawal of the United Kingdom from the European Union. Note: This instrument amends Article 30(3) and (5) only. They are the only Articles in the Commission Delegated Regulation that will be in force on exit day, and therefore will become part of UK law in accordance with the European Union (Withdrawal) Act 2018. Modifications E. The FCA makes the modifications contained in the Annex to Article 30(3) and (5) of the Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication. Commencement F. This instrument comes into force at 11 p.m. on the 29 March 2019. Citation
FCA 201X/XX
G. This instrument may be cited as the Technical Standards on Strong Customer Authentication and Common and Secure Methods of Communication (Amendment of Testing Provisions) Instrument 201[9]. By order of the Board [date]
FCA 201X/XX
Annex
Article 30(3) and (5) of the COMMISSION DELEGATED REGULATION (EU)
2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication In this Annex, underlining indicates new text and striking through indicates deleted text.
Article 30
General obligations for access interfaces
3. Account servicing payment service providers shall ensure that their interfaces follow
standards of communication which are issued by international or European standardisation organisations. Account servicing payment service providers shall also ensure that the technical specification of any of the interfaces is documented specifying a set of routines, protocols, and tools needed by payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments for allowing their software and applications to interoperate with the systems of the account servicing payment service providers. Account servicing payment service providers shall at a minimum, and no less than 6 months before the application date referred to in Article 38(2), 14 September 2019 or before the target date for the market launch of the access interface when the launch takes place after the date referred to in Article 38(2), 14 September 2019, make the documentation available, at no charge, upon request by authorised payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments or payment service providers that have applied to their competent authorities the FCA for the relevant authorisation, and shall make a summary of the documentation publicly available on their website.
5. Account servicing payment service providers shall make available a testing facility,
including support, for connection and functional testing to enable authorised payment initiation service providers, payment service providers issuing card-based payment instruments and account information service providers, or payment service providers that have applied for the relevant authorisation, to test their software and applications
FCA 201X/XX used for offering a payment service to users. This testing facility should be made available no later than 6 months before the application date referred to in Article 38(2) 14 September 2019 or before the target date for the market launch of the access interface when the launch takes place after the date referred to in Article 38(2). 14 September 2019. However, no sensitive information shall be shared through the testing facility.
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
Appendix 2
Draft technical standards (UK-RTS)
FCA 201X/XX
TECHNICAL STANDARDS ON STRONG CUSTOMER AUTHENTICATION AND COMMON AND SECURE METHODS OF COMMUNICATION INSTRUMENT 201[9] Powers exercised A. The Financial Conduct Authority makes this standards instrument, save for Article 30(3) and (5), in the exercise of the powers and related provisions in or under:
(1) the following Regulations of the Payment Services Regulations as amended by the Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018:
(a) Regulation 106A (Technical Standards); and (b) Regulation 120 (Guidance); and (2) the following sections of the Financial Services and Markets Act 2000 (“The Act”) as amended by the Financial Regulators’ Powers (Technical Standards etc.) (Amendment etc.) (EU Exit) Regulations 2018:
(a) section 138P (Technical Standards);
(b) section 138Q (Standards instruments);
(c) section 138S (Application of Chapters 1 and 2); (d) section 137T (General supplementary powers); (e) section 138F (Notification of rules); and (f) section 138I (Consultation by the FCA). Note: Article 30(3) and (5) are not made by the Board in this instrument, but are included in this instrument for clarity and completeness. Article 30(3) and (5) are copied out from the Technical Standards on Strong Customer Authentication and Common and Secure Methods of Communication (Amendment of Testing Provisions) Instrument 2019. Pre-conditions to making B. The FCA have consulted the Prudential Regulation Authority and the Bank of England as appropriate in accordance with section 138P of the Act.
C. A draft of this instrument has been approved by the Treasury, in accordance with
section 138R of the Act.
Modifications
FCA 201X/XX
D. The FCA thereafter makes the Technical Standards on Strong Customer Authentication and Common and Secure Methods of Communication in accordance with the Annex to this instrument, save for Article 30(3) and (5). Commencement E. This instrument comes into force on 14 September 2019. Citation F. This instrument may be cited as the Technical Standards on Strong Customer Authentication and Common and Secure Methods of Communication Instrument 201[9]. By order of the Board [date]
FCA 201X/XX
Annex
Technical standards regarding strong customer authentication and common and secure open standards of communication.
Chapter -2
Application and Definitions
Application
FCA 201X/XX
Definitions
References to the Payment Services Regulations 2017 (SI 2017/752) are references to the Payment Services Regulations as amended by the Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018. Where a term in these Standards is defined in the Payment Services Regulations 2017 (SI 2017/752), that definition shall apply for the purposes of these Standards unless the contrary intention appears.
Chapter -1
Guidance
FCA 201X/XX of such transactions, ensuring that the elements dynamically link the transaction to an amount and a payee specified by the payer when initiating the transaction.
4. Dynamic linking is possible through the generation of authentication codes which is
subject to a set of strict security requirements. To remain technologically neutral a specific technology for the implementation of authentication codes should not be required. Therefore authentication codes should be based on solutions such as generating and validating one-time passwords, digital signatures or other cryptographically underpinned validity assertions using keys or cryptographic material stored in the authentication elements, as long as the security requirements are fulfilled.
5. It is necessary to lay down specific requirements for the situation where the final
amount is not known at the moment the payer initiates an electronic remote payment transaction, in order to ensure that the strong customer authentication is specific to the maximum amount that the payer has given consent for as referred to in the Payment Services Regulations 2017 (SI 2017/752).
6. In order to ensure the application of strong customer authentication, it is also
necessary to require adequate security features for the elements of strong customer authentication categorised as knowledge (something only the user knows), such as length or complexity, for the elements categorised as possession (something only the user possesses), such as algorithm specifications, key length and information entropy, and for the devices and software that read elements categorized as inherence (something the user is) such as algorithm specifications, biometric sensor and template protection features, in particular to mitigate the risk that those elements are uncovered, disclosed to and used by unauthorised parties. It is also necessary to lay down the requirements to ensure that those elements are independent, so that the breach of one does not compromise the reliability of the others, in particular when any of these elements are used through a multi-purpose device, namely a device such as a tablet or a mobile phone which can be used both for giving the instruction to make the payment and in the authentication process.
7. The requirements of strong customer authentication apply to payments initiated by the
payer, regardless of whether the payer is a natural person or a legal entity.
8. Due to their very nature, payments made through the use of an anonymous payment
instrument are not subject to the obligation of strong customer authentication. Where the anonymity of such instruments is lifted on contractual or legislative grounds, payments are subject to the security requirements that follow from the Payment Services Regulations 2017 (SI 2017/752) and this Regulatory Technical Standard.
9. In accordance with the Payment Services Regulations 2017 (SI 2017/752) exemptions
to the principle of strong customer authentication have been defined based on the level of risk, amount, recurrence and the payment channel used for the execution of the payment transaction
10. Actions which imply access to the balance and the recent transactions of a payment
account without disclosure of sensitive payment data, recurring payments to the same payees which have been previously set up or confirmed by the payer through the use of strong customer authentication, and payments to and from the same natural or legal
FCA 201X/XX person with accounts with the same payment service provider, pose a low level of risk, thus allowing payment service providers not to apply strong customer authentication. This leaves aside that in accordance with Regulations 68, 69 and 70 of the Payment Services Regulations 2017 (SI 2017/752), payment initiation service providers, payment service providers issuing card-based payment instruments and account information service providers should only seek and obtain the necessary and essential information from the account servicing payment service provider for the provision of a given payment service with the consent of the payment service user. Such consent can be given individually for each request of information or for each payment to be initiated or, for account information service providers, as a mandate for designated payment accounts and associated payment transactions as established in the contractual agreement with the payment service user.
11. Exemptions for low-value contactless payments at points of sale, which also take into
account a maximum number of consecutive transactions or a certain fixed maximum value of consecutive transactions without applying strong customer authentication, allow for the development of user friendly and low risk payment services and should therefore be provided for. It is also appropriate to establish an exemption for the case of electronic payment transactions initiated at unattended terminals where the use of strong customer authentication may not always be easy to apply due to operational reasons (e.g. to avoid queues and potential accidents at toll gates or for other safety or security risks).
12. Similar to the exemption for low value contactless payments at the point of sale, a
proper balance needs to be struck between the interest in enhanced security in remote payments and the needs of user-friendliness and accessibility of payments in the area of e-commerce. In line with those principles, thresholds below which no strong customer authentication needs to be applied should be set in a prudent manner, to cover only online purchases of low value. The thresholds for online purchases should be set more prudently, considering that the fact that the person is not physically present when making the purchase is posing a slightly higher security risk.
13. The requirements of strong customer authentication apply to payments initiated by the
payer, regardless of whether the payer is a natural person or a legal entity. Many corporate payments are initiated through dedicated processes or protocols which guarantee the high levels of payment security that the Payment Services Regulations 2017 (SI 2017/752) aims to achieve through strong customer authentication. Where the FCA establishes that those payment processes and protocols that are only made available to payers who are not consumers achieve the objectives of The Payment Services Regulations 2017 (SI 2017/752) in terms of security, payment service providers may, in relation to those processes or protocols, be exempted from the strong customer authentication requirements.
14. In the case of real-time transaction risk analysis that categorise a payment transaction
as low risk, it is also appropriate to introduce an exemption for the payment service provider that intends not to apply strong customer authentication through the adoption of effective and risk-based requirements which ensure the safety of the payment service user’s funds and personal data. Those risk-based requirements should combine the scores of the risk analysis, confirming that no abnormal spending or behavioural pattern of the payer has been identified, taking into account other risk factors including information on the location of the payer and of the payee with monetary
FCA 201X/XX thresholds based on fraud rates calculated for remote payments. Where, on the basis of the real-time transaction risk analysis, a payment cannot be qualified as posing a low level of risk, the payment service provider should revert to strong customer authentication. The maximum value of such risk based exemption should be set in a manner ensuring a very low corresponding fraud rate, also by comparison to the fraud rates of all the payment transactions of the payment service provider, including those authenticated through strong customer authentication, within a certain period of time and on a rolling basis.
15. For the purpose of ensuring an effective enforcement, payment service providers, that
wish to benefit from the exemptions from strong customer authentication should regularly monitor and make available to the FCA upon its request, for each payment transaction type, the value of fraudulent or unauthorised payment transactions and the observed fraud rates for all their payment transactions, whether authenticated through strong customer authentication or executed under a relevant exemption.
16. The collection of this new historical evidence on the fraud rates of electronic payment
transactions will also contribute to an effective review by the FCA of the thresholds for an exemption to strong customer authentication based on a real-time transaction risk analysis. The FCA should review and if appropriate update these Standards, including where appropriate the thresholds and fraud rates, with the aim of enhancing the security of remote electronic payments, on a regular basis to take account of innovation and technical developments as well as other relevant matters.
17. Payment service providers that make use of any of the exemptions to be provided for
should be allowed at any time to choose to apply strong customer authentication to the actions and to the payment transactions referred to in those provisions.
18. The measures that protect the confidentiality and integrity of personalised security
credentials, as well as authentication devices and software, should limit the risks relating to fraud through unauthorised or fraudulent use of payment instruments and unauthorised access to payment accounts. To this end it is necessary to introduce requirements on the secure creation and delivery of the personalised security credentials and their association with the payment service user, and to provide conditions for the renewal and deactivation of those credentials.
19. In order to ensure effective and secure communication between the relevant actors in
the context of account information services, payment initiation services and confirmation on the availability of funds, it is necessary to specify the requirements of common and secure open standards of communication to be met by all relevant payment service providers. The Payment Services Regulations 2017 (SI 2017/752) provide for the access and use of payment account information by account information service providers. These Standards therefore do not change the rules of access to accounts other than payment accounts.
20. Each account servicing payment service provider with payment accounts that are
accessible online should offer at least one access interface enabling secure communication with account information service providers, payment initiation service providers and payment service providers issuing card-based payment instruments. The interface should enable the account information service providers, payment initiation service providers and payment service providers issuing card-based payment
FCA 201X/XX instruments to identify themselves to the account servicing payment service provider. It should also allow account information service providers and payment initiation service providers to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user. To ensure technology and business-model neutrality, the account servicing payment service providers should be free to decide whether to offer an interface that is dedicated to the communication with account information service providers, payment initiation service providers, and payment service providers issuing card-based payment instruments, or to allow, for that communication, the use of the interface for the identification and communication with the account servicing payment service providers’ payment service users.
21. In order to allow account information service providers, payment initiation service
providers, and payment service providers issuing card-based payment instruments to develop their technical solutions, the technical specification of the interface should be adequately documented and made publicly available. The effect of Articles 30(3) and (5) which have been in force since the 14 March 2019 and modified by the Technical Standards on Strong Customer Authentication and Common and Secure Methods of Communication (Amendment of testing provisions) Instrument 2019 is that the account servicing payment service provider should offer a facility enabling the payment service providers to test the technical solutions at least six months before 14 September 2019 or, if the launch takes place after the application date of these Standards, prior to the date on which the interface will be launched to the market. To ensure the interoperability of different technological communication solutions, the interface should use standards of communication which are developed by international standardisation organisations.
22. The quality of the services provided by account information service providers and
payment initiation service providers will be dependent on the proper functioning of the interfaces put in place or adapted by account servicing payment service providers. It is therefore important that in case of non-compliance of such interfaces with the provisions included in these Standards, measures are taken to guarantee business continuity for the benefit of the users of those services. It is the responsibility of the FCA to ensure that account information service providers and payment initiation service providers are not blocked or obstructed in the provision of their services.
23. Where access to payment accounts is offered by means of a dedicated interface, in
order to ensure the right of payment service users to make use of payment initiation service providers and of services enabling access to account information, as provided for in the Payment Services Regulations 2017 (SI 2017/752), it is necessary to require that dedicated interfaces have the same level of availability and performance as the interface available to the payment service user. Account servicing payment service providers should also define transparent key performance indicators and service level targets for the availability and performance of dedicated interfaces that are at least as stringent as those for the interface used for their payment service users. Those interfaces should be tested by the payment service providers who will use them, and should be stress-tested and monitored by the FCA.
24. To ensure that payment service providers who rely on the dedicated interface can
continue to provide their services in case of problems of availability or inadequate performance, it is necessary to provide, subject to strict conditions, a fallback
FCA 201X/XX mechanism that will allow such providers to use the interface that the account servicing payment service provider maintains for the identification of, and communication with, its own payment service users. Certain account servicing payment service providers will be exempted from having to provide such a fallback mechanism through their customer facing interfaces where the FCA establishes that the dedicated interfaces comply with specific conditions that ensure unhampered competition. In the event that the exempted dedicated interfaces fail to comply with the required conditions, the granted exemptions shall be revoked by the FCA.
25. In order to allow the FCA to effectively supervise and monitor the implementation
and management of the communication interfaces, the account servicing payment service providers should make a summary of the relevant documentation available on their website, and provide, upon request, the FCA with documentation of the solutions in case of emergencies. The account servicing payment service providers should also make publicly available the statistics on the availability and performance of that interface.
26. In order to safeguard the confidentiality and the integrity of data, it is necessary to
ensure the security of communication sessions between account servicing payment service providers, account information service providers, payment initiation service providers and payment service providers issuing card-based payment instruments. It is in particular, necessary to require that secure encryption is applied between account information service providers, payment initiation service providers, payment service providers issuing card-based payment instruments and account servicing payment service providers when exchanging data.
27. To improve user confidence and ensure strong customer authentication, the use of
electronic identification means and trust services as set out in Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust service for electronic transactions in the internal market as amended by Electronic Identification and Trust Services for Electronic Transactions (Amendment etc.) (EU Exit) Regulations 2018 should be taken into account, in particular with regard to notified electronic identification schemes.
FCA 201X/XX
Technical Standards
Chapter 1
General Provisions
Article 1
Subject matter
These Standards establish the requirements to be complied with by payment service providers for the purpose of implementing security measures which enable them to do the following:
(a) apply the procedure of strong customer authentication in accordance with Regulation 100 of the Payment Services Regulations 2017 (SI 2017/752); (b) exempt the application of the security requirements of strong customer authentication, subject to specified and limited conditions based on the level of risk, the amount and the recurrence of the payment transaction and of the payment channel used for its execution; (c) protect the confidentiality and the integrity of the payment service user’s personalised security credentials; (d) establish common and secure open standards for the communication between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers in relation to the provision and use of payment services in application of Part 7 of the Payment Services Regulations 2017 (SI 2017/752).
Article 2
General Authentication Requirements
FCA 201X/XX
(a) lists of compromised or stolen authentication elements; (b) the amount of each payment transaction; (c) known fraud scenarios in the provision of payment services; (d) signs of malware infection in any sessions of the authentication procedure; (e) in case the access device or the software is provided by the payment service provider, a log of the use of the access device or the software provided to the payment service user and the abnormal use of the access device or the software.
Article 3
Review of the security measures
FCA 201X/XX
Chapter 2
Security Measures for the Application of Strong Customer Authentication
Article 4
Authentication code
FCA 201X/XX
4. Where the block referred to in paragraph 3(b) is temporary, the duration of that block
and the number of retries shall be established based on the characteristics of the service provided to the payer and all the relevant risks involved, taking into account, at a minimum, the factors referred to in Article 2(2). The payer shall be alerted before the block is made permanent. Where the block has been made permanent, a secure procedure shall be established allowing the payer to regain use of the blocked electronic payment instruments.
Article 5
Dynamic linking
FCA 201X/XX
(a) in relation to a card-based payment transaction for which the payer has given consent to the exact amount of the funds to be blocked pursuant to Regulation 78 of the Payment Services Regulations 2017 (SI 2017/752), the authentication code shall be specific to the amount that the payer has given consent to be blocked and agreed to by the payer when initiating the transaction; (b) in relation to payment transactions for which the payer has given consent to execute a batch of remote electronic payment transactions to one or several payees, the authentication code shall be specific to the total amount of the batch of payment transactions and to the specified payees.
Article 6
Requirements of the elements categorised as knowledge
FCA 201X/XX the payment service providers shall ensure that those access devices and software have a very low probability of an unauthorised party being authenticated as the payer.
2. The use by the payer of those elements shall be subject to measures ensuring that
those devices and the software guarantee resistance against unauthorised use of the elements through access to the devices and the software.
Article 9
Independence of the elements
FCA 201X/XX accessing either or both of the following items online without disclosure of sensitive payment data:
(a) the balance of one or more designated payment accounts; (b) the payment transactions executed in the last 90 days through one or more designated payment accounts.
2. For the purpose of paragraph 1, payment service providers shall not be exempted from
the application of strong customer authentication where either of the following conditions are met:
(a) the payment service user is accessing online the information specified in paragraph 1 for the first time; (b) more than 90 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1(b) and strong customer authentication was applied.
Article 11
Contactless payments at point of sale
Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where the payer initiates a contactless electronic payment transaction provided that the following conditions are met:
(a) the individual amount of the contactless electronic payment transaction does not exceed £40; and (b) the cumulative amount of previous contactless electronic payment transactions initiated by means of a payment instrument with a contactless functionality from the date of the last application of strong customer authentication does not exceed £130; or (c) the number of consecutive contactless electronic payment transactions initiated via the payment instrument offering a contactless functionality since the last application of strong customer authentication does not exceed five.
Article 12
Unattended terminals for transport fares and parking fees Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where the payer initiates
FCA 201X/XX an electronic payment transaction at an unattended payment terminal for the purpose of paying a transport fare or a parking fee.
Article 13
Trusted beneficiaries
FCA 201X/XX
Article 16
Low-value transactions
Payment service providers shall be allowed not to apply strong customer authentication, where the payer initiates a remote electronic payment transaction provided that the following conditions are met:
(a) the amount of the remote electronic payment transaction does not exceed £25; and (b) the cumulative amount of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed £85; or (c) the number of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed 5 consecutive individual remote electronic payment transactions.
Article 17
Secure corporate payment processes and protocols Payment service providers shall be allowed not to apply strong customer authentication, in respect of legal persons initiating electronic payment transactions through the use of dedicated payment processes or protocols that are only made available to payers who are not consumers, where the FCA is satisfied that those processes or protocols guarantee at least equivalent levels of security to those provided for by the Payment Services Regulations 2017 (SI 2017/752).
Article 18
Transaction risk analysis
FCA 201X/XX
(a) the fraud rate for that type of transaction, reported by the payment service provider and calculated in accordance with Article 19, is equivalent to or below the reference fraud rates specified in the table set out in the Annex for ‘remote electronic card-based payments’ and ‘remote electronic credit transfers’ respectively; (b) the amount of the transaction does not exceed the relevant Exemption Threshold Value (‘ETV’) specified in the table set out in the Appendix; (c) payment service providers as a result of performing a real time risk analysis have not identified any of the following:
(i) abnormal spending or behavioural pattern of the payer; (ii) unusual information about the payer’s device/software access; (iii) malware infection in any session of the authentication procedure; (iv) known fraud scenario in the provision of payment services; (v) abnormal location of the payer; (vi) high risk location of the payee.
3. Payment service providers that intend to exempt electronic remote payment
transactions from strong customer authentication on the ground that they pose a low risk shall take into account at a minimum, the following risk-based factors:
(a) the previous spending patterns of the individual payment service user; (b) the payment transaction history of each of the payment service provider’s payment service users; (c) the location of the payer and of the payee at the time of the payment transaction in cases where the access device or the software is provided by the payment service provider; (d) the identification of abnormal payment patterns of the payment service user in relation to the user’s payment transaction history. The assessment made by a payment service provider shall combine all those risk-based factors into a risk scoring for each individual transaction to determine whether a specific payment should be allowed without strong customer authentication.
FCA 201X/XX
Article 19
Calculation of fraud rates
FCA 201X/XX
3. Following the cessation of the exemption referred to in Article 18 in accordance with
paragraph 2 of this Article, payment service providers shall not use that exemption again, until their calculated fraud rate equals to, or is below, the reference fraud rates applicable for that type of payment transaction in that exemption threshold range for one quarter.
4. Where payment service providers intend to make use again of the exemption referred
to in Article 18, they shall notify the FCA in a reasonable timeframe and shall before making use again of the exemption, provide evidence of the restoration of compliance of their monitored fraud rate with the applicable reference fraud rate for that exemption threshold range in accordance with paragraph 3 of this Article.
Article 21
Monitoring
FCA 201X/XX
Chapter 4
Confidentiality and Integrity of the Payment Service Users’ Personalised Security Credentials
Article 22
General requirements
FCA 201X/XX
Article 24
Association with the payment service user
FCA 201X/XX
(c) arrangements ensuring that, where the delivery of personalised security credentials is executed outside the premises of the payment service provider or through a remote channel:
(i) no unauthorised party can obtain more than one feature of the personalised security credentials, the authentication devices or software when delivered through the same channel; (ii) the delivered personalised security credentials, authentication devices or software require activation before usage; (d) arrangements ensuring that, in cases where the personalised security credentials, the authentication devices or software have to be activated before their first use, the activation shall take place in a secure environment in accordance with the association procedures referred to in Article 24.
Article 26
Renewal of personalised security credentials Payment service providers shall ensure that the renewal or re-activation of personalised security credentials adhere to the procedures for the creation, association and delivery of the credentials and of the authentication devices in accordance with Articles 23, 24 and 25.
Article 27
Destruction, deactivation and revocation
Payment service providers shall ensure that they have effective processes in place to apply each of the following security measures:
(a) the secure destruction, deactivation or revocation of the personalised security credentials, authentication devices and software; (b) where the payment service provider distributes reusable authentication devices and software, the secure re-use of a device or software is established, documented and implemented before making it available to another payment services user; (c) the deactivation or revocation of information related to personalised security credentials stored in the payment service provider’s systems and databases and, where relevant, in public repositories.
FCA 201X/XX
Chapter 5
Common and Secure Open Standards of Communication
Section 1
General requirements for communication
Article 28
Requirements for identification
FCA 201X/XX
Section 2
Specific requirements for the common and secure open standards of communication
Article 30
General obligations for access interfaces
FCA 201X/XX
3. Account servicing payment service providers shall ensure that their interfaces follow
standards of communication which are issued by international standardisation organisations. Account servicing payment service providers shall also ensure that the technical specification of any of the interfaces is documented specifying a set of routines, protocols, and tools needed by payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments for allowing their software and applications to interoperate with the systems of the account servicing payment service providers. Account servicing payment service providers shall at a minimum, and no less than six months before 14 September 2019, or before the target date for the market launch of the access interface when the launch takes place after 14 September 2019, make the documentation available, at no charge, upon request by authorised payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments or payment service providers that have applied to the FCA for the relevant authorisation, and shall make a summary of the documentation publicly available on their website.
4. In addition to paragraph 3, account servicing payment service providers shall ensure
that, except for emergency situations, any change to the technical specification of their interface is made available to authorised payment initiation service providers, account information service providers and payment service providers issuing cardbased payment instruments, or payment service providers that have applied to the FCA for the relevant authorisation, in advance as soon as possible and not less than 3 months before the change is implemented. Payment service providers shall document emergency situations where changes were implemented and make the documentation available to the FCA on request.
5. Account servicing payment service providers shall make available a testing facility,
including support, for connection and functional testing to enable authorised payment initiation service providers, payment service providers issuing card-based payment instruments and account information service providers, or payment service providers that have applied for the relevant authorisation, to test their software and applications used for offering a payment service to users. This testing facility should be made available no later than six months before 14 September 2019 or before the target date for the market launch of the access interface when the launch takes place after 14 September 2019. However, no sensitive information shall be shared through the testing facility.
6. The FCA shall ensure that account servicing payment service providers comply at all
times with the obligations included in these Standards in relation to the interface(s) that they put in place. In the event that an account servicing payment services provider fails to comply with the requirements for interfaces laid down in these Standards, the FCA shall ensure that the provision of payment initiation services and account information services is not prevented or disrupted to the extent that the respective providers of such services comply with the conditions defined under
Article 33(5).
FCA 201X/XX
Article 31
Access interface options
Account servicing payment service providers shall establish the interface(s) referred to in
Article 30 by means of a dedicated interface or by allowing the use by the payment service
providers referred to in Article 30(1) of the interfaces used for authentication and communication with the account servicing payment service provider’s payment services users.
Article 32
Obligations for a dedicated interface
FCA 201X/XX
Article 33
Contingency measures for a dedicated interface
FCA 201X/XX
6. The exemption will apply to the Account servicing payment service providers that
have opted for a dedicated interface from the obligation to set up the contingency mechanism described under paragraph 4 where the dedicated interface meets all of the following conditions:
(a) it complies with all the obligations for dedicated interfaces as set out in Article 32; (b) it has been designed and tested in accordance with Article 30(5) to the satisfaction of the payment service providers referred to therein; (c) it has been widely used for at least three months by payment service providers to offer account information services, payment initiation services and to provide confirmation on the availability of funds for card-based payments; (d) any problem related to the dedicated interface has been resolved without undue delay.
7. The exemption referred to in paragraph 6 will be revoked where the conditions (a) and
(d) are not met by the account servicing payment service providers for more than two consecutive calendar weeks. The FCA will ensure that the account servicing payment service provider establishes, within the shortest possible time and at the latest within two months, the contingency mechanism referred to in paragraph 4.
Article 34
Certificates
FCA 201X/XX
Services Regulations (SI 2017/752) or section 347 of the Financial Services and Markets Act 2000, or in the case of such payment service providers incorporated and registered or authorised in Gibraltar, their incorporation number available in the Regulated Entities Register of the Gibraltar Financial Services Commission.
3. For the purposes of this Regulation, qualified certificates for electronic seals or for
website authentication referred to in paragraph 1 shall include, in a language customary in the sphere of international finance, additional specific attributes in relation to each of the following:
(a) the role of the payment service provider, which maybe one or more of the following:
(i) account servicing;
(ii) payment initiation;
(iii) account information;
(iv) issuing of card-based payment instruments; (b) the name of the competent authorities where the payment service provider is registered.
4. The attributes referred to in paragraph 3 shall not affect the interoperability and
recognition of qualified certificates for electronic seals or website authentication.
Article 35
Security of communication session
FCA 201X/XX established with the payment service user(s) in order to prevent the possibility that any message or information communicated between them could be misrouted.
4. Account information service providers, payment initiation service providers and
payment service providers issuing card-based payment instruments with the account servicing payment service provider shall contain unambiguous references to each of the following items:
(a) the payment service user or users and the corresponding communication session in order to distinguish several requests from the same payment service user or users; (b) for payment initiation services, the uniquely identified payment transaction initiated; (c) for confirmation on the availability of funds, the uniquely identified request related to the amount necessary for the execution of the card-based payment transaction.
5. Account servicing payment service providers, account information service providers,
payment initiation service providers and payment service providers issuing card-based payment instruments shall ensure that where they communicate personalised security credentials and authentication codes, these are not readable, directly or indirectly, by any staff at any time. In case of loss of confidentiality of personalised security credentials under their sphere of competence, those providers shall inform without undue delay the payment services user associated with them and the issuer of the personalised security credentials.
Article 36
Data exchanges
FCA 201X/XX
(c) they shall, upon request, immediately provide payment service providers with a confirmation in a simple 'yes' or 'no' format, whether the amount necessary for the execution of a payment transaction is available on the payment account of the payer.
2. In case of an unexpected event or error occurring during the process of identification,
authentication, or the exchange of the data elements, the account servicing payment service provider shall send a notification message to the payment initiation service provider or the account information service provider and the payment service provider issuing card-based payment instruments which explains the reason for the unexpected event or error. Where the account servicing payment service provider offers a dedicated interface in accordance with Article 32, the interface shall provide for notification messages concerning unexpected events or errors to be communicated by any payment service provider that detects the event or error to the other payment service providers participating in the communication session.
3. Account information service providers shall have in place suitable and effective
mechanisms that prevent access to information other than from designated payment accounts and associated payment transactions, in accordance with the user’s explicit consent.
4. Payment initiation service providers shall provide account servicing payment service
providers with the same information as requested from the payment service user when initiating the payment transaction directly.
5. Account information service providers shall be able to access information from
designated payment accounts and associated payment transactions held by account servicing payment service providers for the purposes of performing the account information service in either of the following circumstances:
(a) whenever the payment service user is actively requesting such information; (b) where the payment service user does not actively request such information, no more than four times in a 24 hour period, unless a higher frequency is agreed between the account information service provider and the account servicing payment service provider, with the payment service user’s consent.
Chapter 6
Final Provisions
Article 37
Review
FCA 201X/XX
The FCA will review by 14 March 2021 the fraud rates referred to in the Appendix to this Regulation as well as the exemptions granted under Article 33(6) in relation to dedicated interfaces.
FCA 201X/XX
Appendix
Reference Fraud Rate (%) for:
ETV Remote electronic card-based payments Remote electronic credit transfers £440 0.01 0.005 £220 0.06 0.01 £85 0.13 0.015
CP18/44
Chapter 1
Financial Conduct Authority
Brexit - Regulatory Technical Standards for Strong Customer Authentication and Common and Secure Open Standards of Communication
Appendix 3
Draft changes to the Handbook
FCA 201X/XX
PAYMENT SERVICES (AMENDMENT No 2) INSTRUMENT 201[9] Powers exercised A. The Financial Conduct Authority makes this instrument in the exercise of the powers and related provisions in or under:
(1) the following regulations of the Payment Services Regulations 2017:
(a) regulation 98(3) (Management of operational and security risks); (b) regulation 109 (Reporting requirements); and (c) regulation 120 (Guidance); and (2) section 3 (Delegation) of the Financial Regulators’ Powers (Technical Standards etc.) (Amendment etc.) (EU Exit) Regulations 2018. Commencement B. This instrument comes into force at 11 p.m. on 29 March 2019, except for part 2 of
Annex B which comes into force on 14 September 2019.
Amendments to the Handbook
C. The Glossary of definitions is amended in accordance with Annex A to this
instrument.
D. The Supervision manual (SUP) is amended in accordance with Annex B to this instrument. Notes E. In this instrument, the “notes” (indicated by “Note:”) are included for the convenience of readers but do not form part of the legislative text. Citation F. This instrument may be cited as the Payment Services (Amendment No 2) Instrument 201[9]. By order of the Board [date]
FCA 201X/XX
Annex A
Amendments to the Glossary of definitions
In this Annex, underlining indicates new text and striking through indicates deleted text. SCA RTS Regulation (EU) 2018/389 (RTS) Technical standards made by the FCA on strong customer authentication and common and secure open standards of communication under Regulation 106A of the Payment Services Regulations 2017 as amended by the Electronic Money, Payment Services and Payment Systems (Amendment and Transitional Provisions) (EU Exit) Regulations 2018.
FCA 201X/XX
Annex B
Amendments to the Supervision manual (SUP)
In this Annex, underlining indicates new text and striking through indicates deleted text.
Part 1: Comes into force 11 p.m. on 29 March 2019
15C Applications under the Payment Services Regulations … 15C.2 Request for exemption from the obligation to set up a contingency mechanism (Article 33(6) of the SCA RTS) … 15C.2.3 G The EBA issued the Guidelines on the conditions to be met to benefit from an exemption from the contingency measures mechanism under article 33(6) of Regulation (EU) 2018/389 (RTS on SCA and CSC) (EBA/GL/2018/07) on the 4 December 2018 the SCA RTS. The Guidelines clarify the requirements account servicing payment service providers need to meet to obtain an exemption and the information competent authorities should consider to ensure the consistent application of these requirements across jurisdictions. The FCA provides further guidance on making an exemption request in chapter 17 of the FCA’s Approach Document. [Note: see [insert link to final EBA guidelines] and https://www.fca.org.uk/publication/finalised-guidance/fca-approachpayment-services-electronic-money-2017.pdf] … 15C.2.5 G Account servicing payment service providers should note that article 16(3) of Regulation (EU) 1093/2010 also requires them to make every effort to comply with the EBA’s Guidelines on the conditions to be met to benefit from an exemption from contingency measures under article 33(6) of the SCA RTS. … 15C
Annex
1D
Form: Request for exemption from the obligation to set up a contingency mechanism
FCA 201X/XX
…
ASPSPs completing the form should also comply with apply the Guidelines on the conditions to be met to benefit from an exemption from the contingency measures mechanism under
article 33(6) of Regulation (EU) 2018/389 (RTS on SCA & CSC) (EBA Guidelines).
[Note: see https://eba.europa.eu/documents/10180/2250578/Final+Report+on+Guidelines+on+the+exe mption+to+the+fall+back.pdf/4e3b9449-ecf9-4756-8006-cbbe74db6d03.] …
FCA 201X/XX
Form B: (EBA Guideline 6) design of the dedicated interface Column A Column B Column C
Article Requirement … Summary
of how the implemen tation of these specificati ons fulfils the requirem ents of PSD2 the Payment Services Regulatio ns, SCA RTS and FCA Guideline s … PSD2 Article 65,66 &67 Regulations 68, 69 and 70 Payment Services Regulations SCA RTS SCA RTS
Article 30 RTS
Enabling AISPs to access the necessary data from payment accounts accessible online
PSD2 Article 65 & 66 &
67 Regulations 68, 69 and
70 Payment Services
Regulations SCA-RTS
SCA RTS
Article 30
Enabling provision or availability to the PISP, immediately after receipt of the payment order, of all the information on the initiation of the payment transaction and all information accessible to the ASPSP regarding the execution of the payment transaction
FCA 201X/XX
…
PSD2 Article 64(2)
Regulation 67(2) Payment
Services Regulations
SCA-RTS SCA RTS
Article 30(1)(c)
Allowing the payment service user to authorise and consent to a payment transaction via a PISP
PSD2 Article 66(3)(b) and
67(2)(b) Regulations
69(3)(b) and 70(3)(b) of the Payment Services Regulations Enabling PISPs and AISPs to ensure that when they transmit the personalised security credentials issued by the ASPSP, they do so through safe and efficient channels.
PSD2 Article 65(2)(c),
66(2)(d) and 67(2)(c)
Regulations 68(3)(c),
69(3)(d) and 70(3)(c)
Payment Services
Regulations SCA-RTS
SCA RTS
Article 30(1)(a) and 34
Enabling the identification of the
AISP/PISP/CBPII and support eIDAS for certificates
…
PSD2 Article 64(2) and
80(2) and 80(4)
Regulations 67(2), 83(2) and 83(4) Payment
Services Regulations
Allowing for the possibility for an initiated transaction to be cancelled in accordance with PSD2 the Payment Services Regulations, including recurring transactions
…
PSD2 Article 19(6)
Regulation 25(1) Payment
Services Regulations
Supporting access via technology service providers on behalf of authorised actors
FCA 201X/XX
PSD2 Article 97(5)
Regulation 100(4)
Payment Services
Regulations and SCARTS SCA RTS Article
30(2)
Allowing AISPs and
PISPs to rely on all authentication procedures issued by the ASPSP to its customers
PSD2 Article 67 (2) (d)
Regulation 70(3)(d)
Payment Services
Regulations and 30 (1)(b) and SCA-RTS SCA RTS
Article 36(1)(a)
Enabling the AISP to access the same information as accessible to the payment servicer user in relation to their designated payment accounts and associated payment transactions
…
PSD2 Article 97(2)
Regulation 100(2)
Payment Services
Regulations and SCARTS SCA RTS
Article 5
Enabling the dynamic linking to a specific amount and payee, including batch payments
…
PSD2 Article 97(3)
Regulation 100(3)
Payment Services
Regulations SCA-RTS
SCA RTS
Articles 30(2)(c) and 35
Ensuring security at transport and application level
PSD2 Article 97(3)
Regulation 100(3)
Payment Services
Regulations SCA-RTS
SCA RTS
Articles 22, 35 and 3
Supporting the needs to mitigate the risk for fraud, have reliable and auditable exchanges and enable providers to monitor payment transactions
…
FCA 201X/XX
…
16 Reporting requirements
…
16.13 Reporting under the Payment Services Regulations
…
16.13.8A G Payment service providers should use the The return in SUP 16 Annex 27ED to comply with reflects the EBA’s Guidelines on fraud reporting under the Payment Services Directive 2 (PSD2), published on 18 July 2018 (EBA/GL/2018/05). Payment service providers should note that article 16(3) of Regulation (EU) 1093/2010 requires them to make every effort to comply with the EBA’s Guidelines. The return also includes fraud reporting for registered account information service providers, as required by regulation 109 of the Payment Services Regulations. [Note: see https://eba.europa.eu/documents/10180/2281937/Guidelines+on+fraud+repo rting+under+Article+96%286%29%20PSD2+%28EBA-GL-2018- 05%29.pdf … 16 Annex 27FG Notes on completing REP017 Payments Fraud Report These notes contain guidance for payment service providers that are required to complete the Payments Fraud Report in accordance with Regulation 109(4) of the Payment Services Regulations 2017, SUP 16.13.7D and. The notes also build on the EBA Guidelines on fraud reporting under the Second Payment Services Directive 2 (PSD2) (EBA/GL/2018/05) (“the EBA Guidelines”). The following completion notes should be read in conjunction with the EBA Guidelines. …
Table 1 - Payment transactions and fraudulent payment transactions for payment
services
FCA 201X/XX
The form provides the means for PSPs to provide the FCA with statistical data on fraud related to different means of payment. In turn, the FCA is required to aggregate this data and share it with the EBA and the ECB. …
Table 1 -What is a fraudulent transaction?
…
The payment service provider should not report data on payment transactions that, however linked to any of the circumstances referred to in the definition of fraudulent transaction (EBA Guideline 1.1), have not been executed and have not resulted in a transfer of funds in accordance with PSD2 the provisions in the Payment Services Regulations. … Data elements
Table 1 – Payment transactions and fraudulent payment transactions for payment services
Value should be reported in pounds sterling throughout (£) … 2A-2L 38A–38L 48A–48L 103A–103L 155A–155L 167A–167L 199A–199L 200A–200L total domestic transaction volume (i.e. the number of transactions) for payment type – Column A; total domestic transaction value for payment type Column B; total transaction volume for payments made crossborder within the EEA – Column C; total transaction value for payments made crossborder within the EEA – Column D; total transaction volume for payments made crossborder outside the EEA – Column E; total transaction value for payments made crossborder outside the EEA – Column F; total domestic fraudulent transaction volume (i.e. the number of transactions) for payment type – Column G; total domestic fraudulent transaction value for payment type Column H; total fraudulent transaction volume for payments made cross-border within the EEA – Column I;
FCA 201X/XX
total fraudulent transaction value for payments made cross-border within the EEA – Column J; total fraudulent transaction volume for payments made cross-border outside the EEA – Column K; and total fraudulent transaction value for payments made cross-border outside the EEA – Column L. PSPs should continue to report fraud data broken down into domestic, cross border within EEA, and cross border outside EEA as set out in Columns A-F, notwithstanding the UK’s withdrawal from the EU. … Payment initiation channel – initiated non-electronically 4A–4L (credit transfers) 49A–49L (card payments) 104A-104L (card payments acquired) Of the total transaction and total fraudulent transaction volumes and values for credit transfers and card payments only, PSPs should report the volume and value of those initiated non-electronically. Transactions initiated non-electronically include payment transactions initiated and executed with modalities other than the use of electronic platforms or devices. This includes paper-based payment transactions, mail orders or telephone orders Recital 95 of the revised Payment Services Directive. … Remote transactions 6A-6L (credit transfers) 51A–51L (card payments) 106A–106L (card payments acquired) 168A–168L (e-money payment transactions) Of the total transaction and total fraudulent transaction volumes and values for credit transfers, card payments and E-money payment transactions only PSPs should report the volume and value of those that are remote transactions. A ‘remote transaction’ means a payment transaction initiated via the internet or through a device that can be used for distance communication (revised Payment Services Directive
FCA 201X/XX
article 4(1)(6)) (Regulation 2 of the Payment Services
Regulations).
…
Losses due to fraud per liability bearer
35A, 36A, 37A, 45A, 46A, 47A,
100A, 101A,102A, 152A, 153A,
154A
PSPs are required to report the general value of losses borne by them and by the relevant payment service user, not net fraud figures. The figure that should be reported as ‘losses borne’ is understood as the residual loss that is finally registered in the PSP’s books after any recovery of funds has taken place. The final fraud losses should be reported in the period when they are recorded in the payment service provider’s books. We expect one single figure for any given period, unrelated to the payment transactions reported during that period. Since refunds by insurance agencies are not related to fraud prevention for the purposes of PSD2 the Payment Services Regulations, the final fraud loss figures should not take into account such refunds. …
Part 2: Comes into force on 14 September 2019
15 Notifications to the FCA
…
FCA 201X/XX
15 Annex
12D
Form NOT004 Notification that the fraud rate exceeds the reference fraud rate under SCA-RTS article 20 NOT004 - Notification that the fraud rate exceeds the reference fraud rate under SCA-RTS
Article 20
Name of service provider
FRN
…
Notification that the reference fraud rate is exceeded … Q4 Please provide the PSP’s fraud rate(s), where they exceed the applicable reference fraud rate Remote electronic card-based payments Remote electronic credit transfers EUR 500 GBP 440
EUR
250
GBP
220
EUR
100
GBP 85
Q5 For how many consecutive quarters has the fraud rate exceeded the applicable reference rate (if more than 1 quarter, please continue to question 6; otherwise, go to question 7)? Remote electronic card-based payments Remote electronic credit transfers EUR 500 GBP 440
FCA 201X/XX
EUR
250
GBP
220
EUR
100
GBP 85
Q6 Please provide the date on which the PSP ceased to apply the transactional risk analysis exemption for the type(s) of transaction which exceeded the applicable reference fraud rate ( DD/MM/YYYY) Remote electronic card-based payments Remote electronic credit transfers EUR 500 GBP 440
EUR
250
GBP
220
EUR
100
GBP 85
...
Notification that you intend to make use again of the transaction risk analysis exemption Q8 Please provide the PSP’s fraud rate(s) from the last quarter that have been restored to compliance with the applicable reference fraud rate. Remote electronic card-based payments Remote electronic credit transfers EUR 500 GBP 440
EUR
250
GBP
220
FCA 201X/XX
EUR
100
GBP 85
15 Annex
13D
Form NOT005 Notification that there are problems with a dedicated interface under SCA-RTS article 33(3) … NOT005 - Notification that there are problems with a dedicated interface under SCA RTS
Article 33(3)
Name of service provider
FRN
…
…
Details of the problem with the dedicated interface … Q3 In what way is the dedicated interface failing to comply with
Article 32? (select the
option which best describes the problem)
[ ] The uptime of the dedicated interface, as measured by the key performance indicators described in Guidelines 2.2 and 2.4 of the EBA Guidelines on the conditions to be met to benefit from an exemption from contingency measures under Article 33(6) of the SCA_RTS SCA RTS, falls below the uptime of the interface used by the ASPSP’s payment service users. [ ] There isn’t the same level of support offered to AISPs and PISPs using the ASPSP’s dedicated interface, in comparison to the customer interface. [ ] The dedicated interface poses obstacles to the provision of payment initiation and account information services (see SCA-RTS SCA RTS Article 32(3) and the EBA Guidelines on the conditions to
FCA 201X/XX benefit from an exemption from the contingency mechanism under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA and CSC) published on 4 December 2018 (EBA/GL/2018/07) and Opinion on the implementation of the RTS on SCA and CSC (EBA-2018-Op-04)). [ ] Other failure to comply with Article 32. … 16 Reporting requirements …
16.13 Reporting under the Payment Services Regulations
…
16.13.18 G Article 17 of the SCA RTS permits payment service providers not to
apply strong customer authentication in respect of legal persons initiating electronic payment transactions through the use of dedicated payment processes or protocols that are only made available to payers who are not consumers, where the FCA is satisfied that those processes and protocols guarantee at least equivalent levels of security to those provided for by the Payment Services Directive Payment Services Regulations.
16.13.19 D …
…
(2) an explanation of how the payment service provider’s processes and protocols achieve at least equivalent levels of security to those provided for by the Payment Services Directive Payment Services Regulations. … 16 Annex 46BG Notes on completing REP020 Statistics on the availability and performance of a dedicated interface These notes contain guidance for quarterly reporting by Account Servicing Payment Service Providers (ASPSPs) with payment accounts accessible online that are required to publish on
FCA 201X/XX their website quarterly statistics on the availability and performance of the dedicated interface and of the interface used by its payment service users under article 32(4) EBA Regulator Technical Standards on Strong Customer Authentication and Common and Secure Communication (“the SCA-RTS”) SCA RTS. … Performance Performance should be reported for each interface based on the daily average time in milliseconds. At column F, ASPSPs should report daily statistics for each payment service user interface on the daily average time (in milliseconds) taken, per request, for the ASPSP to respond to payment service user requests in that interface. At column G, ASPSPs should report daily statistics for each dedicated interface on the daily average time (in milliseconds) taken, per request, for the ASPSP to provide to the account information service provider (AISP) all the information requested in accordance with article 66(4)(b) of PSD2 Regulation 69(2)(b) of the Payment Services Regulations and article 36(1)(b) of the SCA RTS. At column H, ASPSPs should report daily statistics for each dedicated interface on the daily average time (in milliseconds) taken, per request, for the ASPSP to provide to the payment initiation service provider (PISP) all the information requested in accordance with article 36(1)(a) of the SCA-RTS SCA RTS. At column I, ASPSPs should report daily statistics for each dedicated interface on the daily average time (in milliseconds) taken, per request, for the ASPSP to provide to the card based payment instrument issuer (CBPII) or to the PISP a ‘yes/no’ confirmation in accordance with
article 65(3) of PSD2 Regulation 68(4), (7) and (8) of the Payment Services Regulations and
article 36(1)(c) of the SCA_RTS SCA RTS.
At column J, ASPSPs should report daily statistics for each dedicated interface on the daily error response rate as a percentage – calculated as the number of error messages concerning errors attributable to the ASPSP sent by the ASPSP to the PISPs, AISPs and CBPIIs in accordance with article 36(2) of the SCA RTS per day, divided by the number of requests received by the ASPSP from AISPs, PISPs and CBPIIs in the same day and multiplied by 100. Data elements Quarterly statistics on availability and performance of dedicated interfaces … Dedicated interface
FCA 201X/XX
2G – AISP response
(millisecs)
Only to be completed if “Dedicated interface” has been selected at 2B. ASPSPs should provide the daily average time (in milliseconds expressed as a whole number, e.g. 1.5 seconds is represented as 1500 milliseconds) taken, per request, for the ASPSP to provide to the account information service provider (AISP) all the information requested in accordance with article 66(4)(b) of PSD2 Regulation 69(2)(b) of the Payment Services Regulations and article 36(1)(b) of the SCA RTS. 2H – PISP response (millisecs) Only to be completed if “Dedicated interface” has been selected at 2B. ASPSPs should provide the daily average time (in milliseconds expressed as a whole number, e.g. 1.5 seconds is represented as 1500 milliseconds) taken, per request, for the ASPSP to provide to the payment initiation service provider (PISP) all the information requested in accordance with article 36(1)(a) of the SCA RTS. 2I – CBPII response (millisecs) Only to be completed if “Dedicated interface” has been selected at 2B. ASPSPs should provide the daily average time (in milliseconds expressed as a whole number, e.g. 1.5 seconds is represented as 1500 milliseconds) taken, per request, for the ASPSP to provide to the card based payment instrument issuer (CBPII) or to the PISP a ‘yes/no’ confirmation in accordance with article 65(3) of PSD2 Regulation 68(4), (7) and (8) of the Payment Services Regulations and article 36(1)(c) of the RTS SCA RTS. 2J – Error response rate Only to be completed if “Dedicated interface” has been selected at 2B. ASPSPs should provide the daily error response rate – calculated as the number of error messages concerning errors attributable to the ASPSP sent by the ASPSP to the PISPs, AISPs and CBPIIs in accordance with article 36(2) of the RTS SCA RTS per day, divided
FCA 201X/XX by the number of requests received by the ASPSP from AISPs, PISPs and CBPIIs in the same day. Percentage figure should be provided to two decimal places.
© Financial Conduct Authority 2018
12 Endeavour Square London E20 1JN
Telephone: +44 (0)20 7066 1000
Website: www.fca.org.uk
All rights reserved
Pub ref: 005871
Read the rest free
Source: Financial Conduct Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works