2019-08-28

Added · Updated

Q&A – Secure business payment procedures and protocols

Payment service providers opting for the exemption from strong customer authentication under Article 17 of Commission Delegated Regulation (EU) 2018/389 must submit specific information to DNB prior to implementation. This submission requires a statement confirming the procedure is available only to non-consumer payers, a detailed description of the authentication process, a risk analysis demonstrating security levels equivalent to Directive (EU) 2015/2366, and a step-by-step payer perspective. Institutions must also complete and submit an attached form with supporting documentation to their regular DNB supervisor to facilitate the assessment of the exemption.

De Nederlandsche Bank logo

Netherlands

De Nederlandsche Bank

Click to view thumbnail

Q&A

Read aloud

Question:

What does DNB expect from payment service providers that use dedicated secure business payment authentication procedures and protocols under the exemption from applying strong customer authentication?

Published: 28 August 2019

Answer:

Payment service providers can be exempted from applying strong customer authentication pursuant to Article 17 of Commission Delegated Regulation (EU) 2018/389 (RTS SCA CSC). The decision to opt for exemption is at the institution's discretion and subject to specific requirements. The security level of the authentication procedure or protocol the institution wishes to use instead must in any event be equivalent to the level described in Directive (EU) 2015/2366.

Institutions wishing to opt for exemption pursuant to Article 17 must first in advance submit the following information to DNB:

A statement that the dedicated payment authentication procedure or protocol is only available to non-consumer payers

A description of the relevant authentication procedure or protocol, including at least the following:

A description of the authentication procedure for payers (including any multiple authentication procedures and the underlying process with compensatory measures)

A risk analysis and security measures to prevent unauthorised payments, the level of which must be equivalent to the level described in Directive (EU) 2015/2366

A step-by-step description of the actions required to make a payment, from the payer’s perspective

We will assess the effectiveness of the authentication procedure as part of our regular supervision of the institution.

To further support the assessment of the article 17 exemption, the institution is required to submit the attached form . This form serves to further specify the abovementioned bullet points. This form, including all supporting documentation and –information is to be submitted to the regular contact person (supervisor) of the institution at DNB.

Related Q&A

Q&A Further interpretation of the exception to the 20% bonus cap for the parent company of a group

Discover related articles

Q&A

Payment services

Banks

Electronic money institutions

Payment institutions

Share:

Share on LinkedIn

Share on X

Share on Facebook

Share via Email

Interesting articles

Fine for CCV Group B.V. for lack of SIRA

21 July 2026

Enforcement measures

De Nederlandsche Bank (DNB) discloses its decision of 9 July 2020 to impose an administrative fine on CCV Group B.V. (CCV). DNB also discloses its decisions on CCV’s objection of 13 April 2022 and CCV’s subsequent appeal and higher appeal.

Read more Fine for CCV Group B.V. for lack of SIRA

Enforcement measures

21 July 2026

Prudential rules do not hinder bank financing for EU priorities

17 July 2026

News item supervision

Europe faces historic investment challenges, in which banks will play an important financing role. Prudential requirements strengthen banks’ resilience, without posing a major obstacle to their financing. Unlocking more private finance requires better risk-sharing and deeper financial integration.

Read more Prudential rules do not hinder bank financing for EU priorities

News item supervision

17 July 2026

DNB Inhouse Day for the Dutch banking sector: financial crime supervision

16 July 2026

News item supervision

Following last year’s successful event, De Nederlandsche Bank (DNB) will again host an Inhouse Day for AML/CFT professionals in the Dutch banking sector. The event is designed to encourage dialogue and provide further insight into DNB’s AML/CFT supervision.

Read more DNB Inhouse Day for the Dutch banking sector: financial crime supervision

News item supervision

16 July 2026

Administrative fine imposed on CCV for inadequate customer due diligence

13 July 2026

Enforcement measures

De Nederlandsche Bank (DNB) imposed an administrative fine of €2.65 million on payment institution CCV Netherlands B.V. (CCV). We have imposed the fine because CCV failed to adequately and continuously monitor transactions.

Read more Administrative fine imposed on CCV for inadequate customer due diligence

Enforcement measures

13 July 2026

Necessary cookies

To ensure the proper operation of the website, De Nederlandsche Bank (DNB) uses functional cookies and analytics cookies, and has taken measures to ensure that these cookies have little or no impact on the privacy of website users.

Optional cookies

Some pages include embedded content from external websites. These websites may use proprietary (tracking) cookies. This allows third parties to track visitor statistics, show personalised content and display targeted ads, for example.

You can make your choice about allowing these optional cookies both when you first visit the website and when you navigate to a page with embedded content.