2019-08-28
Added · Updated
Payment service providers opting for the exemption from strong customer authentication under Article 17 of Commission Delegated Regulation (EU) 2018/389 must submit specific information to DNB prior to implementation. This submission requires a statement confirming the procedure is available only to non-consumer payers, a detailed description of the authentication process, a risk analysis demonstrating security levels equivalent to Directive (EU) 2015/2366, and a step-by-step payer perspective. Institutions must also complete and submit an attached form with supporting documentation to their regular DNB supervisor to facilitate the assessment of the exemption.
Get DNB alerts — same-day email on every new publication.
Q&A
Read aloud
Question:
What does DNB expect from payment service providers that use dedicated secure business payment authentication procedures and protocols under the exemption from applying strong customer authentication?
Published: 28 August 2019
Answer:
Payment service providers can be exempted from applying strong customer authentication pursuant to Article 17 of Commission Delegated Regulation (EU) 2018/389 (RTS SCA CSC). The decision to opt for exemption is at the institution's discretion and subject to specific requirements. The security level of the authentication procedure or protocol the institution wishes to use instead must in any event be equivalent to the level described in Directive (EU) 2015/2366.
Read the rest free, and get an email when DNB publishes again
Source: De Nederlandsche Bank — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from DNB
We email you every new DNB publication the day it's published.