PSD3 and PSR: What Changes for Strong Customer Authentication (SCA)? (Part 3)
- Sigita Zavišienė

- Jun 4
- 2 min read
Updated: Jun 8

SCA: two inherence elements may be allowed
PSD3/PSR keeps the core SCA framework largely unchanged.
SCA must still be based on two or more independent elements: knowledge, possession and inherence.
The general rule remains: at least two elements should come from different categories.
However, PSD3 introduces an exception: two elements from the inherence category may be used, provided this does not reduce the overall level of security.
SCA: no major change in scope
PSR keeps the core SCA application perimeter largely unchanged.
SCA applies when the payer:
accesses a payment account online;
initiates an electronic payment transaction; or
performs a remote action that may create a fraud or abuse risk.
This may include actions such as increasing spending limits, changing a password or updating contact information online.
SCA exemptions: payer status may become relevant
PSR does not create a blanket SCA exemption for corporate clients.
However, the EBA will be able to design exemptions by considering, among other factors, whether the payer is a consumer or a non-consumer.
Other criteria may include:
fraud risk;
transaction amount and recurrence;
payment channel used.
SCA must be accessible - not smartphone-only
PSR strengthens the accessibility dimension of SCA.
Authentication methods must be available to users who may not be able to rely on smartphones or digital channels, including persons with disabilities, elderly users and users with low digital skills.
This means SCA should not depend exclusively on one device or technology.
PSPs may need to support alternatives such as hardware tokens, smart cards or voice-based authentication free of charge.
Further details will be set by the EBA in regulatory technical standards.
Delegation of SCA: third-party liability
PSPs may delegate the performance of SCA to third-party providers.
Where technical service providers (TSPs) fail to provide the services necessary to enable SCA, they may be liable for direct financial damage caused to:
the payee;
the payee’s PSP; or
the payer’s PSP.
This liability is proportionate to the failure, limited to the relevant contractual relationship, and should not exceed the amount of the transaction in question.
This makes proper outsourcing and contractual arrangements essential.
The EBA will further specify requirements for PSPs and TSPs on the provision and verification of SCA elements by third parties.
Need advice on PSD3/PSR requirements? Contact us: Sigita Zavišienė



