Skip to main content
Version status: In force | Document consolidation status: Updated to reflect all known changes
Version date: 14 September 2019 - onwards
Version 2 of 2

Regulation 120 Authentication

(1) A payment service provider shall apply strong customer authentication where a payer -

(a) accesses its payment account online,

(b) initiates an electronic payment transaction, or

(c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses.

(2) Where a payer initiates an electronic remote payment transaction, a payment service provider shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.

(3) Where paragraph (1) applies, a payment service provider shall have in place adequate security measures to protect the confidentiality and integrity of the personalised security credentials of the payment service user concerned.

(4) Paragraphs (2) and (3) also apply where a payment is initiated through a payment initiation service provider.

(5) Paragraphs (1) and (3) also apply where information is requested through an account information service provider.