Skip to main content
Version status: In force | Document consolidation status: Updated to reflect all known changes
Version date: 31 December 2020 - onwards
Version 3 of 3

Regulation 100 Authentication

(1) A payment service provider must apply strong customer authentication where a payment service user -

(a) accesses its payment account online, whether directly or through an account information service provider;

(b) initiates an electronic payment transaction; or

(c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses.

(2) Where a payer initiates an electronic remote payment transaction directly or through a payment initiation service provider, the payment service provider must apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.

(3) A payment service provider must maintain adequate security measures to protect the confidentiality and integrity of payment service users' personalised security credentials.