EBA欧洲银行-Opinion-on-the-implementation-of-the-RTS-on-SCA-and-CSC-28EBA-2018-Op-0429_11页_290kb
报告摘要
Summary of EBA-Op-2018-04: Opinion of the European Banking Authority on the Implementation of the RTS on SCA and CSC
Core Content
The European Banking Authority (EBA) issued an opinion on the implementation of the Regulatory Technical Standards (RTS) on Strong Customer Authentication (SCA) and Common and Secure Communication (CSC) under Directive (EU) 2015/2366 (PSD2). The RTS were published in the Official Journal on 13 March 2018 and will legally apply from 14 September 2019. This opinion aims to provide clarity to competent authorities (CAs) and other market participants on the interpretation and implementation of the RTS, ensuring consistent supervisory practices across the EU.
Main Views and Key Information
1. EBA's Statutory Role and Objectives
- The EBA is empowered to issue this opinion under Article 29(1)(a) of Regulation (EU) No 1093/2010.
- The opinion supports the objectives of PSD2, including enhancing competition, facilitating innovation, protecting consumers, increasing security, and contributing to a single EU market in retail payments.
- It is intended for CAs and is also useful for payment service providers (PSPs), payment schemes, technical service providers, and industry initiatives such as API platforms.
2. General Comments
- PSPs must be prepared to comply with the RTS by 14 September 2019, which requires them to adapt systems, interfaces, and infrastructures.
- ASPSPs must ensure that their dedicated interfaces meet all RTS and PSD2 requirements, regardless of whether they modify the customer interface or develop a new one.
- The EBA encourages the development of common API standards to ensure consistency and standardisation across the EU.
- The EBA supports the use of API toolboxes and standards to help ASPSPs implement the RTS efficiently.
3. Scope of Data and Access Limits
- AISPs can access the same data as customers, excluding sensitive payment data.
- The EBA clarifies that the data scope is determined by the ASPSP, and that AISPs may access varying data depending on the channel used (web or app).
- The four-times-daily limit on AISP access applies only when the customer is not directly involved in the request.
- The ASPSP may contractually agree to allow higher frequency access with the customer's consent.
4. SCA and Two-Factor Authentication
- SCA is required for all payment transactions initiated by a payer, including card payments, unless an exemption applies.
- SCA must be based on two elements from two different categories: knowledge, possession, or inheritance.
- Biometric elements (such as fingerprints) are acceptable as inheritance elements, provided they meet the RTS requirements.
- The card number with CVV and expiry date is not considered a knowledge element, as it is not something the user knows.
5. Who Can Apply SCA and Who Can Decide on Exemptions
- The ASPSP is responsible for issuing SCA credentials and applying exemptions.
- Only the ASPSP can decide whether to apply an exemption for a PSU's payment account in the context of AIS and PIS.
- PISPs and AISPs may have access to the PSU's list of trusted beneficiaries, but the decision on exemptions remains with the ASPSP.
6. Exemptions from the SCA Requirement
- The EBA clarifies that exemptions are either for general access to data (Article 10) or for specific payment transactions (Articles 11–18).
- Exemptions for payment transactions are independent and only one exemption is required per transaction.
- The 90-day reauthentication period for AISPs is separate from the 90-day period for direct PSU access.
- The fraud rate for determining SCA exemptions is calculated based on transactions executed or acquired by the PSP, not on the merchant's transactions.
7. Methods of Carrying Out SCA
- The EBA outlines three main methods for SCA: redirection, embedded approaches, and decoupled approaches.
- Redirection involves direct exchange of authentication data between the PSU and ASPSP.
- Embedded approaches involve TPPs (third-party providers) acting on behalf of the PSU, with authentication data exchanged between TPPs and ASPSPs.
- The EBA encourages the development of consistent and secure methods to ensure compliance with the RTS.
Key Requirements for Dedicated Interfaces and API Initiatives
| Requirement | Article |
|---|---|
| Access to payment account data | Articles 65, 66, 67 PSD2; Article 30 RTS |
| Conform to standard communication protocols | Article 30(3) RTS |
| Authorisation via PISP | Article 64(2) PSD2; Article 30(1)(c) RTS |
| Secure transmission of credentials | Articles 66(3)(b) and 67(2)(b) PSD2 |
| Identification of AISP/PISP/CBPII and eIDAS certificates | Articles 65(2)(c), 66(2)(d), 67(2)(c) PSD2; Articles 30(1)(a), 34 RTS |
| 90-day reauthentication for AISPs | Article 10(2)(b) RTS |
| Counting access requests | Article 36(5) RTS |
| Change control process | Article 30(4) RTS |
| Cancel initiated transactions | Articles 64(2), 80(2), 80(4) PSD2 |
| Error messages | Article 36(2) RTS |
| Access via technology service providers | Article 19(6) PSD2 |
| Reliance on ASPSP authentication procedures | Article 97(5) PSD2; Article 30(2) RTS |
| Secure data exchange | Articles 28 and 35 RTS |
| Security at transport and application levels | Article 97(3) PSD2; Articles 30(2)(c), 35 RTS |
| Fraud mitigation and monitoring | Articles 3, 22, 35 RTS |
| Traceability | Article 29 RTS |
| Availability and performance of ASPSP interfaces | Article 32 RTS |
Conclusion
The EBA opinion aims to support the implementation of the RTS on SCA and CSC, ensuring that all market participants and competent authorities have a clear understanding of the requirements. It highlights the importance of technical standards, secure communication, and consistent supervisory practices across the EU. The EBA encourages the development of common API standards and clarifies the roles and responsibilities of ASPSPs, AISPs, and PISPs in meeting these requirements.
试读结束,高清完整版pdf/doc/ppt,请点下载